Data Processing Agreement (DPA)
Last updated: September 13, 2026
1. Scope and roles
Where you use the Service to process personal data relating to your personnel, end users, or other individuals ("Personal Data"), you act as the data controller and TMRW MADE LTD acts as your processor. PurgeOps processes Personal Data only to provide the Service described in the Terms of Service and your documented configuration (IAM scope, approvals, integrations).
PurgeOps remains an independent controller for its own account administration, billing relationship with you, product security, and compliance activities.
2. Subject matter and duration
Subject matter: cloud cost optimization, resource analysis, optional automated remediation, notifications, and related support.
Duration: for the term of your subscription or account, plus retention periods described in the Privacy Policy.
Categories of data subjects: your authorized users, billing contacts, and individuals identifiable from AWS resource metadata (e.g. names or emails in resource tags).
Types of Personal Data: identification and contact data, account credentials (hashed), AWS resource metadata, usage logs, chat content, and Slack integration data where enabled.
3. Processor instructions
PurgeOps processes Personal Data only on your documented instructions as expressed through: (i) use of the Service and its settings, (ii) IAM permissions you grant, (iii) approval workflows, and (iv) written instructions that do not conflict with the Terms or applicable law. If PurgeOps believes an instruction infringes GDPR or other applicable data protection law, we will inform you without undue delay.
4. Sub-processors
You authorize PurgeOps to engage sub-processors to support the Service. Current sub-processors include:
| Sub-processor | Processing activity |
|---|---|
| Supabase, Inc. | Database, authentication, storage |
| Vercel, Inc. | Application hosting |
| Stripe, Inc. | Payments and billing |
| Anthropic, PBC | AI inference (chat and analysis) |
| Amazon Web Services | Customer infrastructure (under customer AWS account) |
| Slack Technologies | Optional notifications and approvals |
We will provide notice of material sub-processor changes via email or in-app notice where practicable. You may object on reasonable grounds relating to data protection; if we cannot accommodate the objection, you may terminate the affected Service component.
5. International transfers
Personal Data may be transferred to countries outside the UK/EEA, including the United States, where sub-processors operate. For such transfers, the parties rely on applicable safeguards, including the UK International Data Transfer Addendum and/or EU Commission Standard Contractual Clauses (Module Two: Controller to Processor), as updated from time to time, incorporated by reference into this DPA where required by law.
6. Security measures
PurgeOps implements appropriate technical and organizational measures, including:
- Encryption in transit (TLS) and encryption at rest provided by our infrastructure providers.
- Role-based access and row-level security for multi-tenant data separation.
- No storage of long-lived AWS access keys; short-lived STS credentials only.
- Least-privilege IAM guidance and external ID for cross-account role assumption.
- Logging and monitoring of administrative access to production systems.
- Vendor review for subprocessors handling Personal Data.
Details may be supplemented in security documentation provided to Scale and Custom customers upon request.
7. Personal data breaches
PurgeOps will notify you without undue delay and in any event within seventy-two (72) hours after becoming aware of a Personal Data breach affecting your data, where feasible and required by GDPR. Notification will include, to the extent known, the nature of the breach, likely consequences, and measures taken or proposed. PurgeOps will cooperate with your regulatory notification obligations.
8. Assistance to controller
PurgeOps will assist you, taking into account the nature of processing and information available to us, with: data subject requests, DPIAs where applicable, and consultations with supervisory authorities — provided you reimburse reasonable costs for extensive assistance beyond standard Service operations.
9. Deletion and return
Upon termination of the Service, PurgeOps will delete or return Personal Data per your instructions within a reasonable period, except where retention is required by law or for legitimate backup cycles (typically up to 30 days), after which backups are overwritten.
10. Audit
Upon reasonable written request no more than once per year, PurgeOps will provide information necessary to demonstrate compliance with this DPA, or allow audits by a mutually agreed third-party auditor bound by confidentiality, subject to security and confidentiality restrictions and excluding access to other customers' data.
11. How to execute this DPA
This DPA is available to all customers using the Service. By using PurgeOps to process Personal Data on behalf of your organization, you agree to this DPA. Scale and Custom customers may request a countersigned PDF for vendor security reviews — email contact@purgeops.com with your company name and billing contact.
Starter and Growth customers are covered by this online DPA; no separate signature is required unless agreed in an order form.
12. Contact
TMRW MADE LTD, Company No. 17275374 · contact@purgeops.com