Draft DPA Summary

This is a public beta summary of the data processing terms CostLayers expects to support for enterprise review. It is not a signed data processing addendum and does not replace negotiated terms.

Effective draft date: July 9, 2026. Contact: rishabh@costlayers.com.

Review status: every control and service level below is proposed or source-observed, not a current contractual commitment. Production hosted API use should wait for a signed DPA, named subprocessor schedule, deployment evidence, and agreed terms.

Roles

ContextExpected role
Local audit and proof commandsCustomer controls local artifacts on customer systems. CostLayers does not receive source code by default.
Hosted dashboard and meteringCustomer is controller or business. CostLayers acts as processor or service provider for hosted account, keyed dashboard, usage, and proof metadata.
Hosted API invoice modeCostLayers acts as processor or service provider for gateway processing needed to meter and forward customer-authorized provider traffic. Customer remains responsible for its provider account and provider terms.
Customer-selected model providerThe provider processes traffic under the customer's provider account and terms. Provider-side retention and deletion are outside CostLayers control.

Processing Scope

Data Categories

Retention and Deletion

ItemBeta target
Hosted account/access rows and usage metadataUnverified target: active key lifetime plus no more than 180 days after inactivity.
Response-cache opt-in bodiesSource-observed opt-in and 30-day default; deployment, purge-race, and backup evidence missing.
Security and abuse logsUnverified 90-day target; deployed log inventory and job missing.
Support/security correspondenceUnverified 24-month target subject to documented exceptions.
Deletion requestsTargets: immediate revocation and primary-row deletion for reachable API requests, 2-business-day manual acknowledgement, 30-day validated primary deletion, and 30-day controlled-backup expiry. No operating-history SLA or backup proof is attached.

Proposed Security Measures

Subprocessors

The current beta subprocessor list is maintained in the public security artifacts at /docs/security-artifacts.html. Enterprise review should finalize a named infrastructure subprocessor schedule before production hosted API use.

Incident and Assistance Targets

Current Exclusions

CostLayers does not claim SOC 2, ISO 27001, HIPAA, PCI, FedRAMP, or BAA readiness in the beta. Customers that require those controls, private deployment, SSO/SAML, enterprise RBAC, custom retention, audit logs with contractual support SLAs, or named subprocessor commitments should complete enterprise review before production use.