Skip to main content
Security & Privacy5 min read

GDPR Compliance

How MeasureLLM complies with GDPR and protects your data rights

Overview

MeasureLLM is fully compliant with the General Data Protection Regulation (GDPR). We are committed to protecting the privacy and data rights of our users in the European Union and globally.

Data Protection

Your data is protected by design and by default

Your Rights

Full support for all GDPR data subject rights

Documentation

Clear policies and data processing agreements

Global Standards

GDPR compliance applied to all users worldwide

Your GDPR Rights

Under GDPR, you have the following rights regarding your personal data:

Right to Access

You can request a copy of all personal data we hold about you:

  1. Go to Settings → Data & Privacy
  2. Click "Export All Data"
  3. Receive a downloadable copy within 30 days

Right to Rectification

You can update or correct your personal data at any time:

  1. Go to Settings → Profile
  2. Update your information
  3. Changes take effect immediately

Right to Erasure

You can request deletion of your personal data:

  1. Go to Settings → Data & Privacy
  2. Click "Delete Account"
  3. All data deleted within 30 days

Right to Data Portability

Export your data in a machine-readable format (JSON/CSV) and take it to another service.

Right to Restrict Processing

Contact us to restrict how your data is processed while maintaining your account.

Right to Object

You can object to certain types of data processing, including marketing communications.

📸 Screenshot: Data Privacy Settings

Shows privacy controls and data export options

How We Process Your Data

Legal Basis for Processing

We process personal data based on:

  • Contract: To provide the service you signed up for
  • Legitimate Interest: To improve our services and prevent fraud
  • Consent: For marketing communications and analytics
  • Legal Obligation: To comply with applicable laws

Data We Collect

Data TypePurposeLegal Basis
Account infoProvide serviceContract
KeywordsCore functionalityContract
Usage dataService improvementLegitimate interest
Payment infoProcess paymentsContract
Marketing prefsCommunicationsConsent

Data Transfers

EU Data Hosting

For EU customers, data can be stored in EU data centers:

  • Primary: AWS EU (Frankfurt)
  • Backup: AWS EU (Ireland)

International Transfers

When data is transferred outside the EU, we ensure protection through:

  • Standard Contractual Clauses (SCCs)
  • Adequacy decisions where applicable
  • Data Processing Agreements with all processors

Sub-Processors

We use the following sub-processors to provide our service:

ProcessorPurposeLocation
AWSCloud hostingEU/US
StripePayment processingUS
SendGridEmail deliveryUS
IntercomCustomer supportUS

Data Processing Agreement

If your organization needs a Data Processing Agreement (DPA):

  1. Contact us at [email protected]
  2. Request a DPA
  3. Review and sign electronically
  4. We countersign and return

Enterprise customers have DPAs included in their contracts.

Cookie Policy

We use cookies for:

  • Essential: Required for the service to function
  • Functional: Remember your preferences
  • Analytics: Understand how you use the service (with consent)
  • Marketing: Only with explicit consent

Manage your cookie preferences in Settings → Privacy or through the cookie banner.

Data Breach Notification

In the unlikely event of a data breach:

  • We notify affected users within 72 hours
  • We report to relevant supervisory authorities
  • We provide details of the breach and remediation steps
  • We offer support for affected users

Contact Our DPO

For GDPR-related questions or to exercise your rights:

  • Email: [email protected]
  • Response time: Within 30 days
  • Supervisory Authority: You can also contact your local data protection authority

More Information: Read our full Privacy Policy for complete details on how we handle your data.

Related Documentation