GDPR & Data Protection

Last updated: November 22, 2025

Deadbro APM is committed to protecting your data and complying with the General Data Protection Regulation (GDPR). This page explains our data practices, responsibilities, and the measures we take to keep your information secure.

1. Who Is Responsible for Your Data?

Controller:

Ruby Dev SRL

p-ta, Victoriei/2, cladire IPH, Deva 330085, Romania

Email: [email protected]

Ruby Dev SRL is the controller for account data.

You (the customer) are the controller for any data you send from your applications.

2. What Data Does Deadbro Process?

Account Data (personal data)

  • Name
  • Email address
  • Billing location
  • Payment details (processed by payment provider)

APM Data (non-personal)

Deadbro processes technical data you send, such as:

  • Request metrics
  • Performance traces
  • Application logs (optional)
  • Error details
  • User identifiers if you send them (typically numeric IDs)

Deadbro does not process:

  • Usernames
  • Email addresses
  • IP addresses of your customers
  • Sensitive personal data

3. Data Processing Purposes

We process data to:

  • Provide the APM service
  • Display performance dashboards
  • Improve stability and security
  • Support billing and account management
  • Provide customer support

We do not use your data for advertising or profiling.

4. Data Location

All production data is stored on servers located in Germany.

Traffic to the website and dashboard is protected using Cloudflare.

5. Sub-Processors

We currently use:

Sub-processor Purpose Location
Hosting provider Dedicated servers Germany
Cloudflare DDoS protection & caching EU/Global
Payment processor Billing & transactions EU/US depending on provider

We maintain agreements ensuring GDPR compliance with all sub-processors.

6. International Transfers

We avoid transferring personal data outside the EU.

If future processors require transfers, they will rely on:

  • Standard Contractual Clauses (SCCs)
  • Adequacy decisions
  • Additional safeguards

7. Data Retention

Data Type Retention
Account data While account is active + limited period for tax obligations
APM request data According to your pricing plan (e.g., X days)
Backups Automatically rotated and purged

8. Security Measures

We use multiple layers of security, including:

  • TLS encryption
  • Firewalls
  • Secure hosting
  • Limited employee access
  • Monitoring and threat detection
  • Regular updates and patching

9. Your GDPR Rights

You can request at any time:

  • Access to your personal data
  • Correction
  • Deletion
  • Restriction or objection
  • Export (data portability)

Contact: [email protected]

We respond within 30 days.

10. Data Processing Addendum (DPA)

We provide a DPA upon request.

Contact: [email protected]

11. Questions

If you have questions or privacy concerns, contact us:

Email: [email protected]