Data Protection Agreement
DATA PROCESSING AGREEMENT (DPA)
Last Updated: July 2026
1. DEFINITIONS
Any capitalised term not defined in this DPA shall have the meaning given to it in the main Terms & Conditions.
-
“Applicable Data Protection Law” means the General Data Protection Regulation (GDPR) (EU) 2016/679, the Irish Data Protection Acts 1988–2018, and any other applicable European Union or national legislation relating to personal data and privacy in force from time to time.
-
“Controller” means the Customer.
-
“Data Subject” and “Personal Data” shall have the respective meanings given to them under the GDPR.
-
“DPA” means this Data Processing Agreement, including Exhibit A and Exhibit B.
-
“Processor” means Ground Up Software Ltd (trading as LiveCosts.com).
-
“Security Policy” means the Company’s information security documentation, as updated from time to time and accessible upon reasonable written request.
-
“Standard Contractual Clauses (SCCs)” means the contractual clauses approved by the European Commission in Commission Implementing Decision (EU) 2021/914 for the transfer of personal data to third countries, as updated or replaced from time to time.
-
“Sub-Processor” means any third party or Affiliate engaged by the Processor to process Personal Data in connection with the provision of the Services.
2. PURPOSE & SCOPE
The Processor provides the Services to the Controller in accordance with the Agreement. In doing so, the Processor shall process Customer Data (which may include Personal Data) solely on behalf of the Controller and in accordance with the Controller’s documented instructions, the Agreement, and this DPA.
3. PROCESSOR OBLIGATIONS
-
Instruction Compliance: The Processor shall process Personal Data only within the scope of this DPA and on the documented instructions of the Controller. The Processor shall promptly inform the Controller if, in its reasonable opinion, an instruction breaches Applicable Data Protection Law.
-
Confidentiality: The Processor shall ensure that all personnel authorized to handle Personal Data are contractually bound by strict confidentiality obligations and have received appropriate training on data protection responsibilities.
-
Security Measures: The Processor shall implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as detailed in Exhibit B.
-
Data Subject Rights Assistance: Taking into account the nature of the processing, the Processor shall assist the Controller by appropriate technical and organisational measures, insofar as possible, to fulfill the Controller’s obligation to respond to Data Subjects exercising their rights under the GDPR.
-
Data Protection Officer: The Processor has designated a data protection contact who can be reached directly at dataprotection@livecosts.com.
4. CONTROLLER OBLIGATIONS
-
Lawful Processing: The Controller represents and warrants that it has obtained all necessary permissions, lawful bases, and authorisations required to permit the Processor, its Affiliates, and Sub-Processors to lawfully process Personal Data under this DPA.
-
Security Responsibilities: The Controller shall implement appropriate technical and organisational measures to secure its own environment, systems, and devices used to access the Services, including maintaining robust access management policies.
-
Cost Reimbursement: The Controller acknowledges and agrees that certain instructions (including custom data destruction formats, bespoke audits, or extensive assistance with Data Protection Impact Assessments) may incur additional fees. The Processor will notify the Controller of such fees on a Time and Materials Basis in advance.
5. SUB-PROCESSORS
-
Authorization: The Controller grants a general written authorisation to the Processor to engage Sub-Processors to deliver the Services. All Sub-Processors shall be bound by data protection obligations materially equivalent to those set out in this DPA.
-
International Transfers: Where Sub-Processors are located outside the EEA, the Processor shall ensure data transfers are protected by recognized legal mechanisms, including the EU-US Data Privacy Framework (DPF) or the execution of standard Standard Contractual Clauses (SCCs).
-
Notification of Changes: The Processor shall maintain an up-to-date list of Sub-Processors and provide the Controller with prior notification via email of any intended additions or replacements.
-
Objection Process: The Controller may object to a new Sub-Processor on legitimate data protection grounds by notifying the Processor in writing within ten (10) Business Days of receiving notice. Following an objection, the parties shall consult in good faith for a period of thirty (30) days to find a mutually agreeable alternative. If no alternative is feasible, either party may terminate the affected portion of the Services, and the Processor shall provide a pro-rata refund of any prepaid fees for the remainder of the Term.
6. LIABILITY & AUDIT
-
Liability Cap: The limitations and caps on liability set out in the main Terms & Conditions apply fully to all claims, breaches, and indemnities made pursuant to this DPA.
-
Sub-Processor Liability: The Processor remains liable to the Controller for the performance of its Sub-Processors’ obligations to the same extent it would be liable under the Agreement.
-
Audit Procedures: The Processor shall provide the Controller with independent auditor reports, certificates, or extracts reasonably necessary to demonstrate compliance. If further inspection is reasonably required by the Controller:
-
It shall be conducted at the Controller’s sole expense.
-
It requires a minimum of four (4) weeks’ prior written notice.
-
It must be carried out during standard Irish Business Hours and conducted in a manner that does not disrupt the Processor’s day-to-day operations.
-
7. DATA BREACH NOTIFICATION
The Processor shall notify the Controller without undue delay, and in any event within 72 hours, after becoming aware of any accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of, or access to, Personal Data (a “Data Breach”). The Processor will take immediate, commercially reasonable measures to mitigate the breach and secure the data.
8. TERM AND TERMINATION
This DPA shall automatically terminate upon the expiry or termination of the main Agreement. Within sixty (60) days of termination, the Processor shall delete or return all Personal Data stored within its databases at the choice of the Controller, unless applicable law requires continued retention. Personal Data contained within server backups shall be securely overwritten in accordance with the Processor’s standard backup lifecycle up to one (1) year post-termination.
EXHIBIT A: OVERVIEW OF PROCESSING ACTIVITIES
Categories of Data Subjects
-
Employees, freelancers, independent contractors, and representatives of the Controller.
-
Authorized Users and participants granted access to the platform by the Controller.
-
Clients and service providers of the Controller whose administrative or transactional data is uploaded to the system.
Categories of Personal Data
-
Identity & Access Data: Names, usernames, business email addresses, passwords.
-
Metadata: Email and financial metadata (timestamps, sent/received status, routing data).
-
Financial Data: Names, addresses, and transaction details extracted from bank statements, invoices, credit notes, and quotations.
-
Professional Data: Corporate job titles, company departments, system usage metrics, and support history information.
Special Categories of Data
-
Strictly Prohibited: No sensitive or special categories of data (e.g., health data, trade union membership, criminal records) are permitted to be processed within the system.
Core Processing Operations
-
Provision of the cloud SaaS platform, project cost tracking, Optical Character Recognition (OCR) pre-processing of financial documents, manual validation verification of OCR text outputs, system maintenance, virus filtering, database backup services, and inbound technical troubleshooting.
EXHIBIT B: TECHNICAL & ORGANISATIONAL SECURITY MEASURES
The Processor aligns its corporate technical and organizational frameworks with international security methodologies, including ISO 27001, ISO 27017, and ISO 27018, and maintains internal controls materially as protective as these standards.
1. Physical Access Control
The Processor utilizes premier, third-party tier-1 data centres (including AWS) that maintain global compliance certifications (ISO 27001, SOC 1/2/3, PCI DSS Level 1). Physical facilities feature strict biometric controls, automated access logging, 24/7 CCTV surveillance, and designated security zones accessible only by authorized facility engineers.
2. System Access Control
-
Remote administrative access to production systems by the Processor’s engineering team is restricted to secure Virtual Private Network (VPN) tunnels.
-
Authentication requires complex, unique user IDs coupled with centralized directory validation.
-
All successful and unsuccessful administrative log-in attempts are tracked, monitored, and audited.
3. Data Access & Separation Control
-
Least Privilege: Access to internal application data is governed by strict role-based access controls (RBAC) under the principle of “need-to-know.”
-
Multi-Tenancy Isolation: Customer environments are logically isolated at the software layer to prevent cross-contamination of data between distinct corporate clients.
-
Testing, staging, and production environments are kept completely separate.
4. Transmission & Storage Encryption
-
Data in Transit: All connections into the LiveCosts platform are encrypted using Transport Layer Security (TLS) version 1.2 or higher utilizing strong 4096-bit RSA public keys.
-
Data at Rest: Archived data and customer database assets are encrypted at rest using the AES-256 (Advanced Encryption Standard) block cipher. Encryption keys are managed inside dedicated, restricted cryptographic vaults.
5. Availability & Recovery Controls
-
Production databases are architecture-engineered for 99.999% durability, featuring real-time logical replication across a minimum of three geographically isolated availability zones.
-
Automated daily backup systems are maintained to facilitate rapid system restoration and point-in-time recovery in the event of local infrastructure disruptions or regional utility failures.