Data processing agreement
Effective 27 August 2026 · UK GDPR, EU GDPR, CCPA service-provider terms
Draft pending legal review. This page is published so that the terms are visible and can be evaluated, but it has not yet been reviewed by counsel.
This DPA is between the CostSlice customer (“you”, the controller) and Media Yard LLC (“we”, the processor), the United States company that operates CostSlice. It is incorporated into the Terms when you use the proxy or the P&L. You do not need a wet signature for it to apply. For a countersigned copy, email hello@costslice.com from the work email that owns the account.
It is meant to satisfy Article 28 UK GDPR (as defined in the UK Data Protection Act 2018), Article 28 EU GDPR, and, where California law applies to that processing, CCPA/CPRA service-provider terms.
Roles
For usage metadata you send through the proxy (opaque tenant, feature, and env tags, plus model, tokens, latency, status, timestamps), you are the controller and Media Yard LLC is the processor. For your work email, workspace membership, and Stripe billing identifiers (Pro and Scale only; Stripe is not used on Starter), Media Yard LLC is the controller; that pile is described in Privacy, not here. We do not store prompt or completion bodies, so those are not processor data.
Subject matter
running the CostSlice proxy and customer P&L. Duration: the life of the workspace plus the retention window. Nature: recording, storing, displaying, exporting CSV. Purpose: so you can see AI cost by customer and feature. Types of data: usage metadata and opaque tags you choose. Data subjects: whoever those tags refer to, which should not be a named person. You instruct us not to interpret tags as personal data. Do not put names, emails, or medical record numbers in them.
Instructions
You instruct us to process processor data only to proxy the call, attach the tags you send, keep the P&L for the plan window (7 days Starter, 90 days Pro, 365 days Scale), and export CSV when you ask. We will not process it for another purpose unless UK or EU law requires it. If an instruction would make us break the law, we will say so in writing to hello@ on the account.
Confidentiality and security
People who can see processor data are limited to those who run CostSlice, under confidentiality. We encrypt data in transit. We do not claim SOC 2 or HIPAA. Fail-open means a missing tag or a slow control plane does not drop the completion. That is a product choice, not a promise that nothing will fail. We will notify you without undue delay, and where UK or EU GDPR applies within 72 hours of becoming aware, of a personal-data breach affecting processor data.
Subprocessors
- Vercel, Inc. — hosting the site and the proxy, United States
- Resend — transactional email (magic links)
- Stripe, Inc. — paid-plan billing only. Stripe is not used on Starter.
OpenAI is not our subprocessor for prompt or completion content. That call uses your OpenAI API key under your OpenAI agreement. We will email the account owner before we add a subprocessor that sees processor data. You may object by writing hello@ within 14 days. If we cannot accommodate the objection, you may stop sending traffic and close the workspace.
International transfers
Processor data is hosted in the United States. For UK restricted transfers, the UK IDTA or the UK Addendum to the EU SCCs applies (EU SCCs alone are not valid for a UK transfer). For EEA transfers, the 2021 EU SCCs (processor module) apply. Swiss transfers use the SCCs as adapted for Switzerland. We will execute those modules on request at hello@. We are not certified under the UK–US Data Bridge or the EU–US Data Privacy Framework.
Assistance, deletion, audits
Email hello@ to export or delete a workspace, or to pass on a data-subject request about processor data. We will answer using the work email that owns the account, within one month where UK or EU GDPR requires it. On deletion we remove processor data from live systems; backups age out. We will give you the security information we actually have. We do not run customer-directed penetration tests on shared infrastructure. Supervisory authorities: ICO in the UK; the competent EU authority where EU GDPR applies.
CCPA
Where the CCPA/CPRA applies to processor data, Media Yard LLC is a service provider / contractor. We will not sell it, share it for cross-context advertising, or retain it for any purpose other than the CostSlice service.
Liability and law
Liability follows the Terms, except where UK GDPR Article 82, EU GDPR Article 82, or a similar rule requires a different split. New York law for the contract, without limiting those mandatory rules.