GOVERNANCE & TRUST
Data Processing Agreement
Current published version. For executed terms or procurement review, contact legal@costframe.co. See the legal and trust directory.
1. Scope & Purpose
This Data Processing Agreement (DPA) describes how Costframe processes personal data as a processor or service provider on behalf of the customer, where the customer acts as controller or business, in connection with the cloud cost control services provided by Slingo Marbella SL under the Costframe product name.
Costframe provides read-only cloud cost analysis and related reporting across connected cloud providers such as AWS, Azure, and Google Cloud. In doing so, we retrieve and process metadata associated with cloud environment configurations, billing profiles, usage records, invoices, and account access.
2. Data Categories & Processing
Our processing activities are confined to data needed to operate the platform: cloud configuration metadata, usage indicators, billing logs, invoice and subscription records, organization identifiers, audit logs, and essential user identification attributes such as emails, roles, usernames, and session metadata.
We do not intentionally ingest, query, store, or process raw customer application data, SQL databases, customer workload payloads, or end-user identity profiles residing inside your cloud workloads.
3. Technical & Organizational Safeguards
Costframe implements robust security mechanisms to protect metadata and keys:
- Strict Read-Only Access: Provider scopes are limited to least-privilege read access, such as Azure Reader and Cost Management Reader, AWS read-only IAM roles, or GCP read-only billing/resource access. Our codebase does not support mutating cloud resources.
- Credential Encryption: Connected secrets are encrypted using AES-256-GCM and are not rendered back in clear-text inside our application interface after setup.
- Tenant Isolation: Database queries partition data by verified Clerk organization IDs to prevent cross-tenant leakage, supported by database-level security policies (RLS).
4. Subprocessor Directory
We use trusted subprocessors for hosting, database, authentication, billing, email, analytics, observability, and infrastructure services. All subprocessors are bound by written data-processing obligations. The current list, purposes, and configured region notes are published at /subprocessors.
5. Transfers & Customer Instructions
Costframe processes customer data only to provide, secure, support, and improve the service, or as otherwise instructed by the customer. Where personal data is transferred internationally, we rely on vendor data-processing terms, standard contractual clauses, adequacy decisions, or other lawful transfer mechanisms as applicable.
6. Security Incidents & Audit Assistance
Costframe will notify the customer without undue delay after becoming aware of a confirmed personal-data breach affecting customer personal data, provide information reasonably available to support the customer's obligations, and take appropriate steps to contain and remediate the incident. Notification does not constitute an admission of fault or liability.
On reasonable request and subject to confidentiality, security, and frequency limits, Costframe will provide information needed to demonstrate compliance with this DPA. Where documentation is insufficient, the parties may agree a scoped audit process that avoids exposing other customers' data or compromising the service.
7. Deletion & Assistance
On request and subject to legal, security, and billing retention requirements, Costframe will delete or return customer personal data in a commercially reasonable manner and assist customers with data-subject requests, security reviews, and regulatory inquiries related to the service.
8. Processing Details
- Subject and duration
- Provision of Costframe for the subscription term and any limited return, deletion, backup, legal, or security-retention period.
- Data subjects
- Customer users, administrators, support contacts, billing contacts, and people identified in connected cloud metadata.
- Personal-data types
- Identity and contact data, organization and role data, account/session metadata, audit logs, billing records, and identifiers or tags contained in cloud metadata.
- Processing operations
- Collection, hosting, organization, analysis, retrieval, support access, transmission to authorized subprocessors, security monitoring, export, and deletion.
- Customer instructions
- The applicable agreement, configured product features, authorized support requests, and other documented lawful instructions agreed by the parties.
Contact Us
For privacy, security, DPA, or data-processing questions, contact us at legal@costframe.co.