Skip to content
Privacy & LegalData Processing Addendum

Data Processing Addendum

Last Updated: September 23, 2026Effective Date: September 23, 2026Version: 2026.110 min read

1. Purpose

This Data Processing Addendum ("DPA") is part of the Terms of Service or other written agreement (the "Agreement") between ExactlyHow, Inc. ("Processor") and the Customer ("Controller") that uses the Services. It applies only to personal data in Customer Content that ExactlyHow processes on the Customer's behalf.

2. Definitions

Capitalized terms not defined here have the meaning in the Agreement. "Personal Data", "Data Subject", "Processing", "Controller", "Processor", and "Subprocessor" have the meanings in the GDPR. "Applicable Data Protection Law" means the GDPR, UK GDPR, and other laws that apply to this processing.

3. Roles

The Customer is the Controller of Personal Data in its processes, attachments, comments, and workspace. ExactlyHow is the Processor and processes that data only to provide the Services. ExactlyHow is an independent controller of account, billing, and support data, which is covered by the Privacy Policy rather than this DPA.

4. Controller

The Controller instructs the Processor to process Personal Data to provide the Services. The Controller is responsible for the lawfulness of Customer Content, for the instructions it gives, and for notices or consents its Data Subjects require.

5. Processor

ExactlyHow will process Personal Data only on the Controller's documented instructions (including the Agreement and product configuration) unless law requires otherwise. If we believe an instruction violates Applicable Data Protection Law, we will tell the Controller when we are legally allowed to do so.

6. Subprocessors

The Controller authorizes ExactlyHow to use Subprocessors that are necessary to deliver the Services. The current list is published at exactlyhow.io/legal#subprocessors. We will impose data-protection terms on Subprocessors that are no less protective than this DPA. Stripe processes subscription billing for ExactlyHow. Card and bank details are Stripe's responsibility and are not Customer Content stored in a workspace. If a member chooses Google or Microsoft sign-in, that provider authenticates the member and receives the sign-in request. If a payer chooses Apple Pay or Google Pay, that wallet provider takes part in the payment through Stripe. We will update the list when we add a Subprocessor that processes Customer Personal Data. If the Controller objects to a new Subprocessor on reasonable data-protection grounds, the Controller may stop using the affected Services or terminate the Agreement as its sole remedy.

7. Security Measures

ExactlyHow will maintain commercially reasonable technical and organizational measures appropriate to the nature of the Services, including encryption in transit, encryption at rest provided by our infrastructure vendors, role-based access controls, and application monitoring. These measures may change as we improve the Service, as long as they do not materially reduce overall protection.

8. Confidentiality

Personnel who process Personal Data are bound to keep it confidential and may access it only as needed to provide, secure, or support the Services.

9. International Transfers

Personal Data may be processed in the United States and in other countries where ExactlyHow or its Subprocessors operate. Where a transfer from the EEA, UK, or Switzerland requires a transfer mechanism, the parties will rely on Standard Contractual Clauses or another valid mechanism, including those our Subprocessors already have in place. We will enter additional transfer terms when legally required.

10. Data Subject Rights

The Controller is responsible for Data Subject requests about Customer Content. ExactlyHow will provide reasonable assistance using the product features available on the Controller's plan (for example, access, edit, and delete inside a workspace). If we receive a request that identifies the Controller, we will redirect it to the Controller unless law requires us to respond.

11. Deletion

When the Agreement ends, or upon the Controller's written request, ExactlyHow will delete Customer Personal Data from active systems within a commercially reasonable period, unless law requires us to keep a copy. Residual copies in encrypted backups are removed on the backup rotation cycle.

12. Retention

We retain Customer Personal Data for the life of the workspace and as needed to provide the Services. The Controller may delete content in the product or request deletion of the workspace.

13. Audits

Upon reasonable written request, no more than once per 12 months except after a Personal Data breach, ExactlyHow will provide information reasonably necessary to demonstrate compliance with this DPA. We may satisfy this by sharing available security summaries, architecture overviews, or completed questionnaires. We do not currently hold a SOC 2 or ISO 27001 certification. On-site audits are not offered unless required by Applicable Data Protection Law and agreed in writing, at the Controller's expense, and without unreasonable disruption.

14. Incident Notification

ExactlyHow will notify the Controller without undue delay after becoming aware of a Personal Data breach affecting Customer Personal Data we process under this DPA, and will give the Controller the information reasonably available to help it meet its own notification duties.

15. Breach Notification

To the extent known at the time, the notice will describe the nature of the breach, the categories and approximate number of Data Subjects and records concerned, likely consequences, and measures taken or planned. We may provide information in phases as we investigate. The Controller is responsible for notices to Data Subjects and regulators unless law assigns that duty to us.

16. Cooperation

Taking into account the nature of processing and the information available to us, we will provide reasonable assistance with the Controller's obligations under GDPR Articles 32 to 36. We may charge reasonable fees for assistance that goes beyond the ordinary operation of the Services.

17. Liability

Each party's liability under this DPA is subject to the exclusions and limits in the Agreement. Nothing in this DPA expands ExactlyHow's liability beyond those limits except where Applicable Data Protection Law forbids the limit.

18. Termination

This DPA lasts until the later of (a) the end of the Agreement or (b) the date ExactlyHow stops processing Personal Data for the Controller.

19. Contact

Notices under this DPA: exactlyhowsaas@gmail.com.

Questions about our legal policies?

If you have questions regarding our privacy practices, legal terms, data processing, or enterprise procurement requirements, contact the ExactlyHow team at exactlyhowsaas@gmail.com.