Data Processing Addendum template
Legal entity: CostCare AI Limited • Address: 2301, 23/F BAYFIELD BLDG 99
HENNESSY RD WAN CHAI
HONG KONG
Contact: support@costcare.ai • Privacy: privacy@costcare.ai
This Data Processing Addendum (“DPA”) forms part of the agreement between CostCare AI Limited (“Processor”) and the business customer using CostCare AI (“Controller”).
This template is intended to be practical for B2B SaaS and GDPR-aligned. Parties may execute a signed version upon request.
Terms such as “personal data”, “processing”, “controller”, and “processor” have the meanings given in the GDPR (and equivalent laws). “Customer Content” means the data Controller provides to the Service or that is collected via Controller’s configured integrations.
Processor uses measures such as encryption in transit (TLS), access controls, logging, and secure infrastructure practices. More detail may be provided on request and may evolve over time.
Controller authorizes Processor to use subprocessors to provide the Service, including categories such as:
Processor will ensure subprocessors are bound by data protection obligations no less protective than this DPA. Processor will provide an updated subprocessor list upon request via privacy@costcare.ai.
Processor hosts primary infrastructure in the EU (Frankfurt, Germany). If personal data is transferred outside the EEA/UK/Switzerland, Processor will use appropriate safeguards (e.g., Standard Contractual Clauses) where required.
Processor will notify Controller without undue delay after becoming aware of a personal data breach affecting Customer Content and will provide information reasonably required for Controller’s notifications.
Upon termination, Processor will delete or return Customer Content as instructed by Controller. Unless otherwise agreed, Processor will delete Customer Content within a reasonable period (typically within 90 days), subject to backup retention and legal obligations.
Upon reasonable written request, Processor will provide information necessary to demonstrate compliance and will allow audits under reasonable confidentiality and security conditions.
Liability under this DPA is subject to the limitations set out in the main Terms/Agreement, except to the extent prohibited by applicable law.