Metrica Power BI Connector for SAP
Metrica Software Inc.
Last Updated: June 18th, 2026
This Data Processing Agreement (“DPA”) forms part of, and is incorporated by reference into, the End User License Agreement between Metrica Software Inc. (“Metrica”, “we”, or “us”) and the customer (“Customer”, “you”) governing the Power BI Connector for SAP (the “App” or “Connector”). This DPA applies to the extent Metrica processes Customer Personal Data on Customer’s behalf in connection with the Connector. Capitalized terms not defined here have the meanings given in the EULA.
In the event of a conflict between this DPA and the EULA regarding the processing of Customer Personal Data, this DPA controls.
1. DEFINITIONS #
“Customer Personal Data” means Personal Data that Metrica processes on Customer’s behalf in connection with the Connector, as described in Annex I.
“Data Protection Laws” means all laws and regulations applicable to the processing of Personal Data under this DPA, including, as applicable, the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK GDPR and the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection, and applicable U.S. state privacy laws.
“Personal Data”, “Controller”, “Processor”, “Data Subject”, “process/processing”, “Personal Data Breach”, and “Supervisory Authority” have the meanings given in the GDPR (or the equivalent terms under other applicable Data Protection Laws).
“SAP Business Data” means the Customer’s records, business data, and other content residing in the Customer’s SAP S/4HANA system.
“SAP BTP” means SAP Business Technology Platform, the SAP-operated platform on which the Connector is deployed.
“Standard Contractual Clauses” or “SCCs” means the standard contractual clauses for the transfer of Personal Data to third countries approved by the European Commission (Decision 2021/914), Module Two (Controller to Processor).
“Sub-processor” means any third party engaged by Metrica to process Customer Personal Data.
“License Data” has the meaning given in the EULA (name and email of the license holder and associated license metadata).
2. ROLES AND SCOPE #
2.1 Roles. For Customer Personal Data processed in connection with the Connector, Customer is the Controller (or a Processor acting on behalf of a third-party Controller) and Metrica is the Processor. Where Customer is itself a Processor, Metrica is a sub-processor and the instructions referenced in this DPA are those of Customer’s own controller.
2.2 License Data. Metrica processes License Data as an independent Controller for licensing, billing, and support purposes, as described in Metrica’s Privacy Policy. License Data is outside the scope of Metrica’s Processor obligations under this DPA, except that Metrica will process it in accordance with applicable Data Protection Laws.
2.3 Scope of Processing. The subject matter, duration, nature and purpose of the processing, the types of Customer Personal Data, and the categories of Data Subjects are described in Annex I.
3. PROCESSING OF CUSTOMER PERSONAL DATA #
3.1 Documented Instructions. Metrica will process Customer Personal Data only on documented instructions from Customer, including with regard to international transfers, unless required to do otherwise by applicable law (in which case Metrica will, where legally permitted, inform Customer of that requirement before processing). Customer’s instructions are set out in this DPA, the EULA, and Customer’s configuration and use of the Connector. Customer’s instructions will comply with Data Protection Laws.
3.2 SAP Business Data Is Not Stored. Metrica does not copy, cache, or persist SAP Business Data at any point. The OData feed exposed to Power BI is a live passthrough: every Power BI refresh re-queries the Customer’s SAP S/4HANA system directly through the SAP Destination Service and the SAP Cloud Connector (for on-premise systems) or direct HTTPS (for public-cloud systems), and streams the result back without storing the rows. Metrica does not use SAP Business Data, or any Customer Personal Data, to train, fine-tune, or improve any artificial intelligence or machine-learning model, or for any purpose other than providing and supporting the Connector and as instructed by Customer.
3.3 Confidentiality. Metrica will ensure that persons authorized to process Customer Personal Data are bound by appropriate obligations of confidentiality.
3.4 Customer Responsibilities. Customer is responsible for the accuracy, quality, and legality of Customer Personal Data, for establishing a lawful basis for the processing, and for its configuration choices (including which SAP services, objects, fields, and recipients it exposes through the Connector, and which users it authorizes).
4. SECURITY #
4.1 Security Measures. Metrica will implement and maintain the technical and organizational measures set out in Annex II, designed to ensure a level of security appropriate to the risk, taking into account the state of the art, costs of implementation, and the nature, scope, context, and purposes of processing.
4.2 Hosting and Data Residency. The Connector is deployed on SAP BTP, Cloud Foundry environment, in the region `cf.us10-001` (which is hosted on AWS infrastructure in the United States, region `us-east-1`). All data the Connector persists is stored in SAP-managed BTP services within that region — namely the SAP HANA HDI container, the SAP Credential Store, and the SAP Audit Log Service. No part of the Connector’s data is stored on Metrica-controlled infrastructure outside SAP BTP. Each Customer tenant has its own SAP HANA HDI container, isolated at the HANA schema level. Customer acknowledges that persistent data is hosted in the United States.
5. SUB-PROCESSING #
5.1 Authorized Sub-processors. Customer provides general authorization for Metrica to engage the Sub-processors listed in Annex III. Metrica’s Sub-processor for hosting and storage is SAP SE and its affiliates, which provide the SAP BTP managed services on which the Connector runs.
5.2 Sub-processor Obligations. Metrica will impose on each Sub-processor data protection obligations no less protective than those in this DPA and remains responsible for each Sub-processor’s performance of its obligations.
5.3 Changes. Metrica will inform Customer of any intended addition or replacement of a Sub-processor with reasonable advance notice, giving Customer the opportunity to object on reasonable data-protection grounds. If Customer reasonably objects and the parties cannot agree on a resolution, Customer may terminate the Connector subscription as its exclusive remedy.
6. ASSISTANCE TO CUSTOMER #
6.1 Data Subject Requests. Taking into account the nature of the processing, Metrica will assist Customer by appropriate technical and organizational measures, insofar as possible, to respond to requests from Data Subjects exercising their rights under Data Protection Laws. If Metrica receives such a request directly, it will, unless legally prohibited, promptly inform the Data Subject to direct the request to Customer and notify Customer.
6.2 Right to Erasure. The Connector provides an administrator function to erase an identified individual’s Personal Data within the Customer’s tenant. On erasure, access-token records (and their Credential Store secrets) and sharing-list entries are hard-deleted, and identity fields in the configuration and history records are anonymized to a non-identifying marker so that the audit trail required under Article 30 GDPR remains complete. An erasure event is recorded in the SAP Audit Log Service.
6.3 DPIAs and Consultation. Metrica will provide reasonable assistance to Customer with data protection impact assessments and prior consultations with Supervisory Authorities, taking into account the nature of the processing and the information available to Metrica.
7. PERSONAL DATA BREACH #
Metrica will notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification will describe, to the extent known, the nature of the breach, the likely consequences, and the measures taken or proposed to address it. Metrica will provide reasonable cooperation and information to assist Customer in meeting its breach-notification obligations.
8. INTERNATIONAL TRANSFERS #
8.1 Transfer Mechanism. Persistent Customer Personal Data is hosted in the United States (Section 4.2). To the extent Metrica’s processing involves a transfer of Customer Personal Data from the European Economic Area, the United Kingdom, or Switzerland to a country that does not provide an adequate level of protection, the SCCs are incorporated into this DPA by reference, with Metrica as data importer and Customer as data exporter, completed as follows:
– Module Two (Controller to Processor) applies (or Module Three, Processor to Processor, where Customer acts as a Processor);
– the optional docking clause applies;
– for Clause 9, Option 2 (general written authorization) applies, with the notice period in Section 5.3;
– for Clause 17, the governing law is the law of Ireland;
– for Clause 18, the courts of Ireland have jurisdiction;
– Annexes I, II, and III to this DPA populate the corresponding Annexes of the SCCs.
8.2 UK and Swiss Transfers. For UK transfers, the UK International Data Transfer Addendum to the SCCs applies; for Swiss transfers, the SCCs apply with the adaptations required by Swiss law.
9. AUDITS #
Metrica will make available to Customer the information reasonably necessary to demonstrate compliance with this DPA and Article 28 GDPR, primarily through current third-party certifications or audit reports for the underlying SAP BTP infrastructure (such as SOC 2 or ISO 27001) and Metrica’s responses to a reasonable written data-protection questionnaire no more than once per twelve (12) months. The parties agree that provision of this documentation will ordinarily satisfy Customer’s audit rights. An on-site inspection may be conducted only (a) where required by a Supervisory Authority, (b) following a confirmed Personal Data Breach affecting Customer Personal Data, or (c) where Metrica fails to provide the documentation described above; and then only by an independent third-party auditor mandated by Customer and bound by confidentiality, on at least thirty (30) days’ prior written notice, during business hours, at Customer’s expense, subject to Metrica’s security and confidentiality requirements, limited to information relevant to Customer, and without access to other customers’ data or to any data center operated by a Sub-processor.
10. DELETION AND RETURN #
10.1 On Termination / Unsubscribe. Upon termination or expiration of the Connector subscription, or when the Customer’s tenant unsubscribes, the Customer’s entire SAP HANA HDI container is dropped — a hard delete of all tenant data, with no soft-delete and no grace period — and the per-tenant SAP Credential Store secrets are deleted. Because SAP Business Data is never stored (Section 3.2), no business records require deletion. Where Customer instead requests return of the persisted configuration data before deletion, Metrica will use commercially reasonable efforts to provide it in a structured format.
10.2 Backend Credentials. The Customer’s S/4HANA credentials are not held by Metrica at any time; they remain in the SAP Destination Service under the Customer’s own BTP subaccount (Annex I) and are unaffected by deletion under this DPA.
11. LIABILITY #
Each party’s liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the EULA, and any reference to a party’s aggregate liability includes liability under this DPA and the EULA combined. Nothing in this DPA limits liability that cannot be limited under Data Protection Laws.
12. GENERAL #
12.1 Term. This DPA takes effect when the EULA takes effect and continues for as long as Metrica processes Customer Personal Data, after which the deletion and return obligations apply.
12.2 Precedence. This DPA supplements the EULA. In case of conflict regarding Customer Personal Data, this DPA controls; where the SCCs apply, the SCCs control over this DPA to the extent of any conflict.
12.3 Governing Law. Except where the SCCs or Data Protection Laws require otherwise, this DPA is governed by the governing law of the EULA.
ANNEX I — DESCRIPTION OF PROCESSING
A. List of Parties
Data Exporter (Controller): Customer, as identified in the EULA / order.
Data Importer (Processor): Metrica Software Inc., 9353 Tangerine Coast Dr, Boca Raton, FL 33434-5919, USA. Contact: legal@metricasoftware.com.
B. Description of Processing
*Categories of Data Subjects:* Customer’s authorized users of the Connector and of Power BI; individuals identified in the SAP records the Customer elects to expose through the Connector; and individuals named in Customer’s sharing/recipient lists.
Categories of Personal Data — persisted by Metrica (in the Customer’s dedicated SAP HANA HDI container on SAP BTP, `cf.us10-001` / AWS `us-east-1`):
1. Configuration data — data-source name, the selected SAP services, objects, and fields, and the filter (OData `$filter`) expressions (the Customer’s choices about what to expose to Power BI).
2. Identity and sharing data — the owner identity of each data source (annotated in the schema as a data-subject identifier) and sharing-list entries (recipient emails, annotated as personal data).
3. Personal Access Token records — a hashed reference to each token stored in the HANA HDI container, with the corresponding plaintext token value stored separately in the SAP Credential Store (namespaced per tenant). The plaintext is shown to the user once at issuance and is never retrievable again — not via the UI, any API, an administrator, or Metrica staff; a lost token can only be revoked and re-created.
4. History / audit records — data-source change history and access-token issue/revoke history (retained for the life of the subscription), and export history (default retention 30 days, configurable), together with security events recorded in the SAP Audit Log Service.
5. Per-tenant subscription metadata — subscription date, plan, and plan-change timestamps.
*Categories of Personal Data — processed transiently only (not stored):* Personal Data contained in SAP Business Data returned in response to a Power BI refresh. This data is streamed live from S/4HANA to Power BI and is never copied, cached, or persisted by Metrica.
*Backend credentials:* The Customer’s S/4HANA credentials (Basic auth, OAuth, or principal propagation) are configured in the SAP Destination Service under the Customer’s own BTP subscriber subaccount. The Connector reads them via the BTP Destination API at request time and never sees, copies, or persists them.
*Isolation:* Each tenant has its own SAP HANA HDI container; cross-tenant access is not possible from a tenant session. Within a tenant, per-user row-level visibility is enforced so that a regular user can read only rows they own or that are shared with them, while a Administrator can read all rows in that tenant.
*Special categories of data:* None intended. Customer is responsible for not exposing special-category data through the Connector except as permitted by applicable law.
*Nature and purpose of processing:* Provision of the Connector — enabling the Customer to query its SAP S/4HANA system live and load the resulting data into Microsoft Power BI for analytics and reporting, and to manage configuration, authentication, sharing, and audit.
*Duration / Retention:* Configuration, token, and subscription records are retained for the term of the subscription and removed when the tenant unsubscribes (Section 10.1). Export history defaults to 30 days (configurable). Data-source and access-token history are retained for the life of the subscription and removed when the tenant unsubscribes; identity fields are anonymized on an erasure request (Section 6.2).
ANNEX II — TECHNICAL AND ORGANIZATIONAL MEASURES
Hosting and infrastructure. The Connector is deployed on SAP BTP, Cloud Foundry environment, region `cf.us10-001` (AWS `us-east-1`, United States). All persisted Customer Personal Data resides in SAP-managed BTP services — the SAP HANA HDI container, the SAP Credential Store, and the SAP Audit Log Service. No Customer Personal Data is stored on Metrica-controlled infrastructure outside SAP BTP.
Encryption in transit — external. All external traffic terminates at the SAP BTP application router (`approuter`) over TLS. Security headers are set on every UI response, including HSTS, X-Frame-Options DENY, a strict Content-Security-Policy, X-Content-Type-Options nosniff, and a `no-referrer` referrer policy.
Encryption in transit — internal. Every internal hop is TLS-encrypted through SAP BTP service bindings: approuter to backend; backend to the SAP Credential Store (mutual TLS plus JSON Web Encryption); backend to the SAP Destination Service; backend to the SAP HANA HDI container; and backend to the SAP Audit Log Service.
Encryption at rest. SAP HANA HDI data-at-rest encryption is provided by SAP HANA Cloud per SAP BTP defaults. SAP Credential Store secrets are encrypted with customer-isolated keys managed by SAP.
Tenant isolation. Each tenant has its own SAP HANA HDI container, isolated at the HANA schema level; cross-tenant access is not possible from a tenant session. SAP Credential Store entries are namespaced per tenant. Within a tenant, per-user row-level visibility is enforced through CDS authorization annotations.
Authentication and authorization. Power BI authenticates with a per-user Personal Access Token, validated against the stored hashed reference. Role checks within the management UI gate who may create, edit, share, or administer data sources and tokens.
Token handling. Personal Access Token storage is split between two SAP-managed services: the plaintext value is held only in the SAP Credential Store (reached over mTLS plus JWE), and only a hashed reference is held in the HANA HDI container. The plaintext is shown once at issuance and never retrievable thereafter. Token secret material is generated from a cryptographically secure random source and carries a stable prefix so that platform and code-repository secret scanners can detect a leaked token. On issuance, the Credential Store write is committed before the database row, and the database row is rolled back if the Credential Store is unreachable, so a hashed reference cannot exist without a matching secret.
Backend credentials. The Customer’s S/4HANA credentials remain in the SAP Destination Service under the Customer’s own BTP subaccount and are read at request time only; they are never persisted by the Connector.
Audit logging. Security-relevant events (for example, authentication, token issuance and revocation, tenant subscription changes, and personal-data erasure) are emitted to the SAP Audit Log Service, a BTP-managed service.
Data minimization by design. SAP Business Data is never copied, cached, or persisted; each Power BI refresh re-queries S/4HANA live and streams the result without storing the rows.
Off-boarding. When a tenant unsubscribes, its entire HANA HDI container is dropped and its per-tenant Credential Store secrets are deleted.
ANNEX III — SUB-PROCESSORS
The Customer’s SAP S/4HANA system and Microsoft Power BI are the Customer’s own environments and are not Sub-processors of Metrica. SAP’s own infrastructure sub-processors (including the underlying cloud infrastructure provider for the `us10` region) are engaged by SAP under the Customer’s BTP and SAP agreements.