Data Processing Agreement

Last updated: 5 August 2026

1. Parties and roles

This Data Processing Agreement ("DPA") is between the customer identified on the account ("Customer", the controller) and Costcreep Ltd (company number 17369484) ("CostCreep", the processor), and forms part of the Terms of Service. It applies whenever CostCreep processes personal data on the Customer's behalf, and is governed by UK GDPR and the Data Protection Act 2018.

2. What the processing is

Subject matterChecking the Customer's supplier invoices, identifying overcharges and unused credits, preparing evidence, corresponding with suppliers on the Customer's instructions, and matching recoveries.
DurationThe term of the Terms of Service, plus the export and deletion period below.
Nature and purposeIngesting accounting and document data; detection and reporting; sending, receiving and threading email correspondence with the Customer's suppliers as a declared cost-review function acting on the Customer's documented instructions — this agency is a named purpose of the processing, not incidental to it.
Data subjectsThe Customer's personnel and advisers; personnel of the Customer's suppliers (accounts and sales contacts).
Categories of dataBusiness contact details (names, business email addresses, phone numbers, job roles); invoice and transaction data that may contain names; correspondence content. No special-category data is sought or required, and none should be submitted.

3. CostCreep's obligations

4. Sub-processors

The Customer authorises the sub-processors below. We'll give at least 30 days' notice before adding or replacing one; if the Customer reasonably objects and we can't resolve it, they may terminate the affected service. We remain responsible for our sub-processors' performance.

ProviderPurposeLocation / safeguard
SupabaseDatabase, authentication, file storageEU — Frankfurt, Germany (UK adequacy for the EEA; UK Addendum / SCCs with the provider)
RenderApplication hostingEU — Frankfurt, Germany (UK adequacy for the EEA; UK Addendum / SCCs with the provider)
Postmark (ActiveCampaign)Transactional email sending and inbound processingUS — UK Addendum / SCCs
Microsoft AzureDocument reading (OCR)UK — UK South region
CloudflareEncrypted off-site database backups (R2 object storage)EU jurisdiction (UK adequacy for the EEA; UK Addendum / SCCs with the provider)
Functional Software, Inc. (Sentry)Application error monitoring — diagnostic reports that may incidentally contain personal data present in a failed requestEU — Germany (UK adequacy for the EEA; UK Addendum / SCCs with the provider)
StripePayment processingUS — UK Addendum / SCCs

Xero and Intuit (QuickBooks) are not our sub-processors: they are the Customer's own providers, from which we read data under the Customer's authorisation.

5. International transfers

Where processing involves a transfer outside the UK, it relies on an adequacy decision or on the EU Standard Contractual Clauses together with the UK International Data Transfer Addendum, plus supplementary measures where appropriate.

6. Liability and precedence

Liability under this DPA is subject to the limitations in the Terms of Service, except where UK GDPR doesn't permit that. If this DPA conflicts with the Terms on a data-protection matter, this DPA wins.