Cost Catch — Data Processing Addendum (DPA)
This Data Processing Addendum ("DPA") supplements and forms part of the agreement between RemoDone, Inc. ("RemoDone," "Processor" where applicable) and the customer ("Customer," "Controller") for the use of Cost Catch (the "Agreement" / Terms of Service). Where this DPA conflicts with the Agreement on the subject of personal-data processing, this DPA controls.
Effective date: August 9, 2026
1. Scope — read this first
Cost Catch is a Snowflake Native Application that runs entirely inside Customer's own Snowflake account. The billing and usage data Cost Catch ingests — including any personal data it may contain, such as per-user usage detail — is not transmitted outside Customer's Snowflake account, except for information the Customer expressly enables for diagnostic sharing (Section 1(b)). Apart from that diagnostic data the Customer chooses to share, RemoDone does not receive, access, store, or process Customer's billing and usage data. Cost Catch runs entirely as code inside Customer's Snowflake account; there is no Cost Catch server and no egress of that data out of Customer's account — to RemoDone or to any third party.
As a result:
(a) For ingested data, RemoDone is not a processor. Customer is the sole controller of the ingested data. The Customer executes and controls the processing within its own Snowflake account: RemoDone does not receive the data, operate on the data, or have technical access to it. Because Customer — not RemoDone — carries out and controls that processing, RemoDone does not process it on Customer's behalf, and the processor obligations in this DPA do not attach to it. Customer is responsible for that data's lawful ingestion, security, retention, and deletion within its own account, using the app's controls and Snowflake's own capabilities.
(b) RemoDone acts as a processor only for "Ancillary Personal Data." The limited personal data RemoDone actually processes on Customer's behalf is:
- Diagnostic data the Customer chooses to share — operational and error metadata (not billing/usage data) that Customer's administrator elects to share with RemoDone, at Customer's discretion, from the in-account diagnostics schema to support troubleshooting; there is no automatic transmission of this data to RemoDone; and
- any other limited personal data the parties expressly agree in writing that RemoDone processes on Customer's behalf.
(c) RemoDone acts as a controller — governed by the Privacy Policy, not this processor DPA — for personal data relating to the business relationship (Customer's contacts, purchasing, account administration, and support correspondence).
This DPA's processor terms (Sections 2–11) apply only to Ancillary Personal Data.
2. Definitions
"Personal Data," "Processing," "Controller," "Processor," "Data Subject," and "Personal Data Breach" have the meanings given in applicable data protection law, including the CCPA/CPRA and, where applicable, the EU GDPR and UK GDPR. "Ancillary Personal Data" has the meaning in Section 1(b). "Subprocessor" means a third party engaged by RemoDone to process Ancillary Personal Data.
3. Roles and instructions
For Ancillary Personal Data, Customer is the Controller and RemoDone is the Processor. RemoDone will process Ancillary Personal Data only:
- on Customer's documented instructions, including as set out in this DPA and the Agreement;
- as necessary to comply with law (RemoDone will notify Customer of such a requirement unless legally prohibited).
Where Customer chooses to share diagnostic data with RemoDone for troubleshooting, that act constitutes Customer's instruction to process the shared data to provide and improve support and reliability. RemoDone will inform Customer if, in its opinion, an instruction infringes applicable data protection law.
4. Details of processing (Annex A)
- Subject matter: provision of troubleshooting and reliability support for Cost Catch.
- Duration: for the term of the Agreement and as described in Section 9.
- Nature and purpose: receiving and analyzing operational/error metadata that Customer chooses to share, to diagnose issues and improve the application.
- Types of Personal Data: limited technical and operational metadata that may include identifiers such as a user or account reference, error context, and connector run information. Excludes Customer's billing and usage data.
- Categories of Data Subjects: Customer's administrators and authorized users whose actions generate diagnostic events.
The parties agree the volume and sensitivity of Ancillary Personal Data is low by design, because sharing is at Customer's discretion, admin-controlled, ad hoc (tied to troubleshooting), and scoped to operational metadata.
5. CCPA / CPRA (service provider)
With respect to Ancillary Personal Data of California residents, RemoDone acts as a "service provider." RemoDone will not: (a) sell or share such Personal Data; (b) retain, use, or disclose it except as necessary to perform the services or as permitted by the CCPA; (c) retain, use, or disclose it outside the direct business relationship; or (d) combine it with other data except as the CCPA permits. RemoDone certifies it understands and will comply with these restrictions.
6. Confidentiality and security
RemoDone will ensure persons authorized to process Ancillary Personal Data are bound by confidentiality. RemoDone will implement appropriate technical and organizational measures to protect Ancillary Personal Data appropriate to the risk, including access controls, encryption in transit, and least-privilege access. Given the no-egress architecture, the primary security control for Customer's core data is that it never leaves Customer's account — RemoDone's measures under this Section apply to the limited Ancillary Personal Data it receives.
7. Subprocessors
As of the effective date, RemoDone engages no Subprocessors to process Ancillary Personal Data — troubleshooting is performed directly with Customer's team, and Cost Catch has no backend to which data is exported. Customer authorizes RemoDone to engage Subprocessors in the future, provided RemoDone: (a) imposes data-protection obligations no less protective than this DPA; (b) remains liable for their performance; and (c) maintains a current list of Subprocessors available on request and gives Customer reasonable prior notice of changes, with an opportunity to object on reasonable data-protection grounds.
8. Data subject requests and assistance
Taking into account the nature of the processing, RemoDone will assist Customer, by appropriate technical and organizational measures and insofar as possible, to respond to Data Subject requests and to meet Customer's obligations regarding security, breach notification, data protection impact assessments, and prior consultation. For requests concerning ingested data, RemoDone cannot assist because it has no access — Customer handles those directly within its own account.
If RemoDone receives a Data Subject request relating to Ancillary Personal Data, it will, where legally permitted, direct the Data Subject to Customer or forward the request.
9. Return and deletion
On termination of the Agreement or on Customer's request, RemoDone will delete or return Ancillary Personal Data in its possession and delete existing copies, unless law requires retention. Ingested data is unaffected — it resides in Customer's account and is deleted or retained by Customer.
10. Personal Data Breach
RemoDone will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Ancillary Personal Data, with information reasonably available to assist Customer's obligations. Because RemoDone holds no ingested data, a breach of RemoDone's systems cannot expose Customer's billing and usage data.
11. Audits
RemoDone will make available information reasonably necessary to demonstrate compliance with this DPA and, on reasonable prior notice and subject to confidentiality, allow for and contribute to audits of its processing of Ancillary Personal Data, not more than once per year except as required by a supervisory authority.
12. International transfers
If Ancillary Personal Data of individuals protected by the EU GDPR or UK GDPR is transferred to a country without an adequacy decision, the parties will put in place a lawful transfer mechanism (e.g., the EU Standard Contractual Clauses and the UK Addendum), which are incorporated by reference where applicable.
13. Liability and precedence
Each party's liability under this DPA is subject to the limitations of liability in the Agreement. This DPA does not expand the parties' obligations with respect to data RemoDone does not process. In case of conflict on data-protection matters, this DPA prevails over the Agreement; on all other matters, the Agreement prevails.
RemoDone, Inc. (offering Cost Catch)
Data protection contact: team@costcatch.ai
This DPA is intentionally narrow because Cost Catch's architecture keeps Customer data inside Customer's own Snowflake account.