This Data Processing Agreement forms part of the contract between Costapp Ltd and each customer where Costapp processes personal data in customer project content on the customer’s behalf.
1. Parties and roles
The customer named in the relevant Costapp account, order or invoice is the Customer. Costapp Ltd is Costapp. For customer project personal data, the Customer is the controller and Costapp is the processor unless the parties agree otherwise in writing.
Each party must comply with UK data protection law, including the UK GDPR and Data Protection Act 2018. Costapp is separately a controller for its own account, security, support and billing data as explained in the Privacy Notice.
2. Processing instructions
Costapp will process customer personal data only on the Customer’s documented instructions, including the instructions in the agreement and the Customer’s use and configuration of the service, unless law requires otherwise. If law requires processing outside those instructions, Costapp will inform the Customer beforehand unless prohibited by law.
Costapp will promptly tell the Customer if, in its opinion, an instruction infringes applicable data protection law and may pause the affected processing while the parties resolve it.
3. Details of processing
Subject matter and purpose
Hosting and operating customer project workspaces, collaboration, contractual communications, quotations, cost planning, file storage, exports, support, security, backup and related Costapp functions.
Duration
For the term of the Costapp agreement and the limited return, deletion and backup period described below.
Data subjects
Customer personnel and authorised users; project team members; subcontractors and suppliers; employers, contractors, consultants and their representatives; recipients and respondents to notices or quotations; and people named in customer-provided correspondence or documents.
Personal data
Names, work email addresses, organisations, roles, project permissions, project and contract information, correspondence, notices and responses, commercial records, comments, attachments, technical identifiers, timestamps and audit activity.
Sensitive data
The service is not intended for special category or criminal-offence data. The Customer must not submit it unless necessary, lawful, appropriately protected and expressly agreed with Costapp where additional measures are needed.
4. Confidentiality and personnel
Costapp will ensure that people authorised to process customer personal data are bound by confidentiality obligations, receive appropriate instructions and access the data only as needed for their work.
5. Security
Taking account of the nature of the processing, risks and available technology, Costapp will maintain proportionate technical and organisational measures, including:
- authenticated access, account membership and project-level permissions;
- least-privilege administrative access and confidentiality controls;
- provider-managed encryption in transit and protective infrastructure controls;
- database and object-storage controls, service monitoring and recovery arrangements;
- security logging, vulnerability and incident handling procedures; and
- regular review of appropriate service and provider safeguards.
The Customer is responsible for its user lifecycle, recipient selection, device security, lawful instructions and appropriate copies or exports of critical records.
6. Subprocessors
The Customer gives general written authorisation for Costapp to use the following subprocessors to provide the service:
- OpenAI / ChatGPT Sites: authentication and application hosting or orchestration services;
- Cloudflare: content delivery, security, compute, database and object-storage infrastructure;
- Stripe: subscription billing and payments. Stripe may act as an independent controller for some payment processing;
- Resend: transactional email delivery.
Costapp will contractually require each subprocessor that processes customer personal data to meet data-protection obligations equivalent to those imposed on Costapp by this DPA. Costapp remains fully liable to the Customer for the performance of each subprocessor’s data-protection obligations. We will give at least 30 days’ notice of a material new subprocessor where practicable. The Customer may object on reasonable data-protection grounds during that period. The parties will work in good faith on a solution; if none is reasonably available, either party may end the affected service without penalty.
7. International transfers
Costapp will not transfer customer personal data outside the United Kingdom unless the transfer is permitted by UK data protection law. Where required, Costapp will use an adequacy regulation, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or another lawful safeguard, together with supplementary measures where appropriate.
8. Assistance
Taking account of the nature of processing and information available, Costapp will reasonably assist the Customer with:
- requests by data subjects to exercise their rights;
- security, personal-data breach notification and communications;
- data protection impact assessments and prior consultation with regulators; and
- information reasonably needed to demonstrate compliance with the Customer’s controller obligations.
If Costapp receives a request concerning customer project data, it will normally direct the requester to the Customer and notify the Customer unless prohibited by law.
9. Personal-data breaches
Costapp will notify the Customer without undue delay after becoming aware of a personal-data breach affecting customer personal data. As information becomes available, the notice will describe the nature of the incident, likely consequences, affected data and subjects, and measures taken or proposed. Costapp’s notice is not an admission of fault.
10. Return and deletion
At the end of the service, Costapp will, at the Customer’s choice, return or make available for export all customer personal data and delete existing copies, unless UK law requires continued storage. Unless the Customer instructs earlier return or deletion, Costapp may keep the workspace read-only for up to 12 months to support controlled export or reinstatement. A Customer instruction to delete takes priority over that default period, subject only to a documented legal retention requirement.
Residual protected backup copies may remain until securely overwritten in the ordinary backup cycle. They will be isolated from routine use, retained only for recovery and deleted when that cycle completes. Costapp will confirm completion of the controlled deletion process on request.
11. Information and audits
Costapp will make available all information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits and inspections by the Customer or its appointed auditor. Except after a material incident or where a regulator or law requires otherwise, audits should normally be limited to once a year, use reasonable notice, avoid unnecessary disruption and protect other customers and confidential systems. Existing independent reports or remote evidence may be used first where adequate, but do not remove the Customer’s statutory audit rights. The Customer bears its reasonable audit costs unless the audit identifies a material breach by Costapp.
12. Liability, priority and law
The liability limits and exclusions in the Terms of Service or relevant order apply to this DPA to the extent permitted by law. If this DPA conflicts with other terms about processing customer personal data, this DPA takes priority. It is governed by the laws of England and Wales and the courts of England and Wales have jurisdiction.
13. Contact
Data-protection notices, subprocessor objections and requests under this DPA should be sent to kevin.morley@costapp.co.uk.
Return to Costapp