Cost Catch — Data Processing Addendum (DPA)
This Data Processing Addendum ("DPA") supplements and forms part of the agreement between RemoDone, Inc. ("RemoDone," "Processor" where applicable) and the customer ("Customer," "Controller") for the use of Cost Catch (the "Agreement" / Terms of Service). Where this DPA conflicts with the Agreement on the subject of personal-data processing, this DPA controls.
Effective date: August 9, 2026
Last updated: August 10, 2026
1. Scope — read this first
Cost Catch is a Snowflake Native Application that operates inside Customer's own Snowflake account. Its application objects, scheduled jobs, configuration, and ingested billing and usage data reside within Customer's Snowflake environment. Where a connector retrieves data from an external vendor, Customer configures and approves the applicable Snowflake integration, credential, and permitted endpoint. Apart from diagnostic data Customer chooses to share under Section 1(b), RemoDone does not receive, access, store, or process Customer's ingested billing and usage data.
As a result:
(a) For ingested data, RemoDone is not a processor. Customer is the sole controller of the ingested data. The Customer executes and controls the processing within its own Snowflake account: RemoDone does not receive the data, operate on the data, or have technical access to it. Because Customer — not RemoDone — carries out and controls that processing, RemoDone does not process it on Customer's behalf, and the processor obligations in this DPA do not attach to it. Customer is responsible for that data's lawful ingestion, security, retention, and deletion within its own account, using the app's controls and Snowflake's own capabilities.
(b) RemoDone acts as a processor only for "Ancillary Personal Data." The limited personal data RemoDone actually processes on Customer's behalf is:
- Diagnostic data the Customer chooses to share — operational and error metadata (not billing/usage data) that Customer's administrator elects to share with RemoDone, at Customer's discretion, from the in-account diagnostics schema to support troubleshooting; there is no automatic transmission of this data to RemoDone; and
- any other limited personal data the parties expressly agree in writing that RemoDone processes on Customer's behalf.
(c) RemoDone acts as a controller — governed by the Privacy Policy, not this processor DPA — for personal data relating to the business relationship (Customer's contacts, purchasing, account administration, and support correspondence).
This DPA's processor terms (Sections 2–11) apply only to Ancillary Personal Data.
2. Definitions
"Personal Data," "Processing," "Controller," "Processor," "Data Subject," and "Personal Data Breach" have the meanings given in applicable data protection law, including the CCPA/CPRA and, where applicable, the EU GDPR and UK GDPR. "Ancillary Personal Data" has the meaning in Section 1(b). "Subprocessor" means a third party engaged by RemoDone to process Ancillary Personal Data.
3. Roles and instructions
For Ancillary Personal Data, Customer is the Controller and RemoDone is the Processor. RemoDone will process Ancillary Personal Data only:
- on Customer's documented instructions, including as set out in this DPA and the Agreement;
- as necessary to comply with law (RemoDone will notify Customer of such a requirement unless legally prohibited).
Where Customer chooses to share diagnostic data with RemoDone for troubleshooting, that act constitutes Customer's instruction to process the shared data to provide and improve support and reliability. RemoDone will inform Customer if, in its opinion, an instruction infringes applicable data protection law.
4. Details of processing (Annex A)
- Subject matter: provision of troubleshooting and reliability support for Cost Catch.
- Duration: for the term of the Agreement and as described in Section 9.
- Nature and purpose: receiving and analyzing operational/error metadata that Customer chooses to share, to diagnose issues and improve the application.
- Types of Personal Data: limited technical and operational metadata that may include identifiers such as a user or account reference, error context, and connector run information. Excludes Customer's billing and usage data.
- Categories of Data Subjects: Customer's administrators and authorized users whose actions generate diagnostic events.
The parties agree the volume and sensitivity of Ancillary Personal Data is low by design, because sharing is at Customer's discretion, admin-controlled, ad hoc (tied to troubleshooting), and scoped to operational metadata.
5. CCPA / CPRA (service provider)
With respect to Ancillary Personal Data of California residents, RemoDone acts as a "service provider." RemoDone will not: (a) sell or share such Personal Data; (b) retain, use, or disclose it except as necessary to perform the services or as permitted by the CCPA; (c) retain, use, or disclose it outside the direct business relationship; or (d) combine it with other data except as the CCPA permits. RemoDone certifies it understands and will comply with these restrictions.
6. Confidentiality and security
RemoDone will ensure persons authorized to process Ancillary Personal Data are bound by confidentiality. RemoDone will implement appropriate technical and organizational measures to protect Ancillary Personal Data appropriate to the risk, including access controls, encryption in transit, and least-privilege access. Customer's core billing and usage data resides within Customer's Snowflake environment; RemoDone's measures under this Section apply to the limited Ancillary Personal Data it receives.
7. Subprocessors
As of the effective date, RemoDone engages no Subprocessors to process Ancillary Personal Data; troubleshooting is performed directly with Customer's team. Customer authorizes RemoDone to engage Subprocessors in the future, provided RemoDone: (a) imposes data-protection obligations no less protective than this DPA; (b) remains liable for their performance; and (c) maintains a current list of Subprocessors available on request and gives Customer reasonable prior notice of changes, with an opportunity to object on reasonable data-protection grounds.
8. Data subject requests and assistance
Taking into account the nature of the processing, RemoDone will assist Customer, by appropriate technical and organizational measures and insofar as possible, to respond to Data Subject requests and to meet Customer's obligations regarding security, breach notification, data protection impact assessments, and prior consultation. For requests concerning ingested data, RemoDone cannot assist because it has no access — Customer handles those directly within its own account.
If RemoDone receives a Data Subject request relating to Ancillary Personal Data, it will, where legally permitted, direct the Data Subject to Customer or forward the request.
9. Return and deletion
On termination of the Agreement or on Customer's request, RemoDone will delete or return Ancillary Personal Data in its possession and delete existing copies, unless law requires retention. Ingested data is unaffected — it resides in Customer's account and is deleted or retained by Customer.
10. Personal Data Breach
RemoDone will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Ancillary Personal Data, with information reasonably available to assist Customer's obligations. Because RemoDone holds no ingested data, a breach of RemoDone's systems cannot expose Customer's billing and usage data.
11. Audits
RemoDone will make available information reasonably necessary to demonstrate compliance with this DPA and, on reasonable prior notice and subject to confidentiality, allow for and contribute to audits of its processing of Ancillary Personal Data, not more than once per year except as required by a supervisory authority.
12. International transfers
If Ancillary Personal Data of individuals protected by the EU GDPR or UK GDPR is transferred to a country without an adequacy decision, the parties will put in place a lawful transfer mechanism (e.g., the EU Standard Contractual Clauses and the UK Addendum), which are incorporated by reference where applicable.
13. Liability and precedence
Each party's liability under this DPA is subject to the limitations of liability in the Agreement. This DPA does not expand the parties' obligations with respect to data RemoDone does not process. In case of conflict on data-protection matters, this DPA prevails over the Agreement; on all other matters, the Agreement prevails.
RemoDone, Inc. (offering Cost Catch)
Data protection contact: [email protected]
This DPA is intentionally narrow because Cost Catch's architecture keeps Customer data inside Customer's own Snowflake account.