Data Processing Agreement
Last updated: 5 August 2026
1. Parties and roles
This Data Processing Agreement ("DPA") is between the customer identified on the account ("Customer", the controller) and Costcreep Ltd (company number 17369484) ("CostCreep", the processor), and forms part of the Terms of Service. It applies whenever CostCreep processes personal data on the Customer's behalf, and is governed by UK GDPR and the Data Protection Act 2018.
2. What the processing is
| Subject matter | Checking the Customer's supplier invoices, identifying overcharges and unused credits, preparing evidence, corresponding with suppliers on the Customer's instructions, and matching recoveries. |
|---|---|
| Duration | The term of the Terms of Service, plus the export and deletion period below. |
| Nature and purpose | Ingesting accounting and document data; detection and reporting; sending, receiving and threading email correspondence with the Customer's suppliers as a declared cost-review function acting on the Customer's documented instructions — this agency is a named purpose of the processing, not incidental to it. |
| Data subjects | The Customer's personnel and advisers; personnel of the Customer's suppliers (accounts and sales contacts). |
| Categories of data | Business contact details (names, business email addresses, phone numbers, job roles); invoice and transaction data that may contain names; correspondence content. No special-category data is sought or required, and none should be submitted. |
3. CostCreep's obligations
- Instructions. We process personal data only on the Customer's documented instructions — including each approval to send a challenge and each automation policy the Customer enables — unless UK law requires otherwise, in which case we tell the Customer first where the law allows.
- Identity in correspondence. Every email to a supplier identifies the Customer, states that CostCreep's cost-review function is acting for the Customer, and never presents a fictitious person as the sender.
- Confidentiality. Everyone we authorise to process the data is bound by confidentiality obligations.
- Security. Appropriate technical and organisational measures, including: encryption in transit and at rest; per-company tenant isolation enforced in the application and tested; read-only accounting connections; role-based access; suppression lists honoured on all outbound email; and audit logging of actions taken on the Customer's behalf.
- Assistance. We help the Customer respond to data-subject rights requests, and with security, breach notification, DPIAs and consultations, as UK GDPR arts. 32–36 require.
- Breach. We notify the Customer without undue delay after becoming aware of a personal data breach affecting their data, with enough detail to meet their own obligations.
- Return and deletion. The Customer can export all their data at any time from within the product. On termination or on request we delete the Customer's personal data from the live service — including files in storage — within 30 days, unless law requires retention. Encrypted off-site backups are taken daily and are not selectively editable; a deleted Customer's data therefore persists in backups until each one expires on its own retention schedule, which is a maximum of 35 days. Backups are used only to restore the service after a failure, are never read for any other purpose, and are held under the same safeguards as the live data.
- Audit. We make available information reasonably necessary to demonstrate compliance, and allow audits on reasonable notice, no more than once per year unless required by a regulator or following a breach.
4. Sub-processors
The Customer authorises the sub-processors below. We'll give at least 30 days' notice before adding or replacing one; if the Customer reasonably objects and we can't resolve it, they may terminate the affected service. We remain responsible for our sub-processors' performance.
| Provider | Purpose | Location / safeguard |
|---|---|---|
| Supabase | Database, authentication, file storage | EU — Frankfurt, Germany (UK adequacy for the EEA; UK Addendum / SCCs with the provider) |
| Render | Application hosting | EU — Frankfurt, Germany (UK adequacy for the EEA; UK Addendum / SCCs with the provider) |
| Postmark (ActiveCampaign) | Transactional email sending and inbound processing | US — UK Addendum / SCCs |
| Microsoft Azure | Document reading (OCR) | UK — UK South region |
| Cloudflare | Encrypted off-site database backups (R2 object storage) | EU jurisdiction (UK adequacy for the EEA; UK Addendum / SCCs with the provider) |
| Functional Software, Inc. (Sentry) | Application error monitoring — diagnostic reports that may incidentally contain personal data present in a failed request | EU — Germany (UK adequacy for the EEA; UK Addendum / SCCs with the provider) |
| Stripe | Payment processing | US — UK Addendum / SCCs |
Xero and Intuit (QuickBooks) are not our sub-processors: they are the Customer's own providers, from which we read data under the Customer's authorisation.
5. International transfers
Where processing involves a transfer outside the UK, it relies on an adequacy decision or on the EU Standard Contractual Clauses together with the UK International Data Transfer Addendum, plus supplementary measures where appropriate.
6. Liability and precedence
Liability under this DPA is subject to the limitations in the Terms of Service, except where UK GDPR doesn't permit that. If this DPA conflicts with the Terms on a data-protection matter, this DPA wins.