Stakeholders: marketing, product, engineering, data/analytics, and leadership.
Outputs: high-level requirements, success metrics, data sources, event taxonomy, timeline, and a rough cost estimate.
Contracting and setup planning
Finalize terms: licenses, data processing/privacy considerations, service levels (SLA), support levels, and any onboarding commitments.
Plan critical milestones: data integrations, event mapping, test plan, and go-live date.
Account configuration and access provisioning
Create Kochava accounts, user roles, and permissions.
Connect partner networks (ad networks, DSPs, DMPs) as required.
Configure dashboards, reports, and alerts tailored to your team.
Data integration and event taxonomy
Define and map in-app events to Kochava’s event schema (e.g., install, session, purchase, level-up, sign-up).
Instrument apps or websites to emit the required events. This often involves SDK integration for mobile apps (iOS/Android) and possibly server-to-server (S2S) events for web or backend systems.
Validate data flow and ensure event payloads include required parameters (e.g., revenue, currency, product IDs, marketing source).
SDK integration and instrumentation
Install Kochava SDKs in mobile apps (and any other relevant platforms: web, TV, connected devices).
Implement or adjust attribution parameters, postbacks, and deep linking (if applicable).
Perform basic QA to verify events fire correctly and at the expected times.
Customisation
Event taxonomy and schema: define custom in-app events and parameters; map them to Kochava’s standard fields for reporting.
Attribution models: choice of last-touch vs. multi-touch attribution, time-to-install windows, view-through vs. click-through logic, and offline attribution handling.
Postbacks and integrations: customize partner postbacks, event-level postbacks, and data sharing formats (CSV, JSON, API endpoints).
Audience creation and activation: build cohorts based on user behavior and trigger audience exports to partners or campaigns.
Support for data warehouses and BI tools: export schemas, data connectors, and integration with data lakes, warehouses, or downstream analytics (e.g., BigQuery, Snowflake, Redshift) via API or FTP/SFTP.
Deep linking and attribution paths: consistent attribution across organic, paid, and organic post-install paths; configure Deferred Deep Linking and orchestration with campaigns.
Automation and rules: lifecycle automations, event-based triggers, and alerting based on KPI thresholds.
Reporting and dashboards: custom dashboards, scheduled reports, and cross-device/ cross-platform views.
Additional Costs
Setup / onboarding fees: one-time or phased fees for initial integration, configuration, and training.
License / platform access: recurring fees based on app count, events or events per user, monthly active users, or concurrent projects. Some announcements reference flat-rate tiers or usage-based pricing.
Implementation services: professional services for SDK integration, event taxonomy design, data pipeline setup, custom dashboards, and onboarding assistance.
Support levels: tiered support (Standard, Premium/Enterprise, etc.) with different response times and SLAs; some contracts include certain hours of support per month and optional 24/7 coverage.
Maintenance and upgrades: ongoing maintenance fees for platform updates, compatibility, and security patching.
Data export and processing charges: potential fees for large data exports, data warehouse integrations, or real-time postbacks beyond baseline agreements.
Training and enablement: customer training sessions, workshops, and enablement materials.
Professional services for advanced analytics: bespoke dashboards, custom models, or data science support.
Training
Onboarding sessions: Guided walkthroughs tailored to your role (marketing, sales, customer success, product). Typical focuses: platform navigation, core workflows, reporting, dashboards.
Product tutorials: Self-paced modules covering key features, best practices, and common use cases.
Live webinars: Regular sessions on topics like pipeline management, forecasting, and automation capabilities.
Documentation and knowledge base: Comprehensive guides, FAQs, and how-to articles.
Hands-on workshops: Deep dives into advanced features, integrations, and customization.
Customer-specific training: Custom training for enterprise customers, aligned with your internal processes.
Security Measures
Data encryption: In transit (TLS) and at rest (AES or equivalent) for stored data.
Access controls: Role-based access control (RBAC), least-privilege principles, and multi-factor authentication (MFA) for user accounts.
Identity and access management: Centralized IAM with audit trails of user activity, logins, and configuration changes.
Data residency and privacy: Support for regional data residency requirements and adherence to applicable privacy laws (e.g., GDPR, CCPA) per contract and region.
Data minimization and handling: Clear guidelines on the collection, storage, and usage of personal data; configurable data retention policies.
Updates
Regular product releases: Kochava typically releases updates on a scheduled cadence (e.g., quarterly or semi-annual), with smaller patches as needed.
Feature drops and enhancements: Major features may arrive in planned release cycles; minor improvements and bug fixes appear in ongoing updates.
Critical fixes: Urgent security or stability fixes are deployed as needed outside the regular release window.
Data Ownership and Portability
Customer-owned data: In most engagements, the data you generate and send to Kochava (e.g., user events, cohort data, raw event payloads) remains your property or is owned by you under the data processing agreement (DPA). Kochava acts as a processor to store, process, and deliver insights on your data.
Data control and usage rights: Kochava typically uses your data to provide the service (attribution, reporting, analytics) and to improve product quality, with limitations defined in the DPA and privacy terms. Any usage beyond the scope (e.g., training models with your data) requires explicit consent or a separate agreement.
Subprocessor transparency: You should have visibility into subprocessors handling your data, with DPAs in place to govern data protection and incident response.
Scaling Up / Down
Incremental licensing/workloads: You can usually scale by increasing app count, events, or network/partner connections. Pricing is often tiered by usage (apps, events, MAU, or per-install/event) and may involve a mid-cycle adjustment or a new quote.
Resource impacts: Scaling may require additional onboarding, expanded support levels, or extra professional services for complex data integrations or custom dashboards.
Scaling down
Flexible downsizing: Most arrangements support reducing scope (fewer apps, lower event volume), though there may be minimum commitments or notice periods. Some contracts implement a minimum term or phased reductions to avoid sudden service discontinuities
Pricing adjustments: Downscaling typically results in lower ongoing fees, with potential adjustments to SLAs or support tiers aligned with the new usage.
The terms & conditions for contract renewal and cancellation
Automatic vs. manual renewal: Contracts may auto-renew for defined periods (monthly, quarterly, yearly) unless canceled within a renewal window.
Price adjustments: Renewals can include price escalators or volume-based adjustments; you may be given a renewal quote with expected changes.
SLA and support continuity: Renewals typically preserve existing SLAs, with potential upgrades if you opt for higher tiers.
Early termination: Some contracts allow termination for convenience with notice and potentially a early-termination fee or payback of discounted amounts.
Termination for cause: Typically, contracts can be terminated for material breach that isn’t cured within a defined period, or for regulatory/privacy non-compliance if not remedied.
Data return and deletion: Upon termination, Kochava usually provides a data export; you’ll have a data deletion window to request erasure of remaining data, subject to legal retention requirements.
Compliance
SOC 2 Type II: Often referenced for controls around security, availability, processing integrity, confidentiality, and privacy.
ISO/IEC 27001: Information security management system (ISMS) certification is common in enterprise data platforms.
GDPR/CCPA readiness: Data processing terms, data residency options, and consent/processing commitments to meet regional privacy laws
HIPAA considerations: If handling protected health information through analytics workflows, bilateral agreements may be required (less common for typical mobile attribution but possible for health-adjacent use cases).
DPAs and data processing terms: Standard contractual clauses (SCCs) for cross-border data transfers when required.
Vulnerability management and incident response: Documented processes, with defined RFOs, 24/7 monitoring in higher tiers, and escalation procedures.