Privacy & LegalData Processing Addendum

Data Processing Addendum

Last Updated: November 30, 2025Effective Date: December 1, 2025Version: 1.0.020 min read

1. Purpose

This Data Processing Addendum ("DPA") forms part of the Terms of Service or other written agreement (the "Agreement") between ExactlyHow ("Processor") and the Customer ("Controller") utilizing the Operational Knowledge Platform. It establishes the rights and obligations of both parties regarding the processing of Personal Data in accordance with Applicable Data Protection Laws, including the GDPR.

2. Definitions

Capitalized terms not defined herein shall have the meaning set forth in the Agreement. "Personal Data", "Data Subject", "Processing", "Controller", and "Processor" shall have the meanings given in the GDPR (Article 4).

3. Roles

For the purposes of this DPA, the Customer is the Controller of the Personal Data contained within their Process Library, Attachments, and Organization Workspaces. ExactlyHow acts as the Processor, processing the data solely on behalf of the Controller.

4. Controller

The Controller instructs the Processor to process Personal Data for the purpose of providing the Services. The Controller is responsible for ensuring its processing instructions comply with Applicable Data Protection Laws and that it has obtained all necessary consents to transfer Personal Data to the Processor.

5. Processor

ExactlyHow will process Personal Data only in accordance with the Controller's documented instructions, unless required to do otherwise by applicable law. The Processor will immediately inform the Controller if, in its opinion, an instruction infringes on Applicable Data Protection Laws.

6. Subprocessors

The Controller provides general authorization for ExactlyHow to engage Subprocessors to assist in delivering the Services. A current list of Subprocessors is available at exactlyhow.app/legal. ExactlyHow will impose data protection obligations upon its Subprocessors that are no less protective than those included in this DPA.

7. Security Measures

ExactlyHow will implement and maintain appropriate technical and organizational security measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures include encryption at rest and in transit, access controls, and regular application monitoring.

8. Confidentiality

ExactlyHow ensures that its personnel engaged in the Processing of Personal Data are informed of the confidential nature of the Personal Data and have executed written confidentiality agreements.

9. International Transfers

If the Processing involves transferring Personal Data originating from the EEA, UK, or Switzerland to countries not recognized as providing adequate protection, ExactlyHow agrees to abide by the Standard Contractual Clauses (SCCs) or other valid transfer mechanisms recognized by applicable authorities.

10. Data Subject Rights

ExactlyHow provides the Controller with the tools necessary to fulfill Data Subject requests (e.g., access, rectification, erasure). If ExactlyHow receives a request directly from a Data Subject, it will promptly redirect the request to the Controller without responding to the Data Subject, unless legally required to do so.

11. Deletion

Upon termination or expiration of the Agreement, ExactlyHow will, at the choice of the Controller, delete or return all Personal Data processed on behalf of the Controller, and delete existing copies unless applicable law requires continued storage.

12. Retention

ExactlyHow will retain Personal Data for the duration of the Agreement or as long as necessary to provide the Services. Customers may request deletion of their Organization Workspace, which triggers a secure deletion process within standard backup cycles.

13. Audits

Upon reasonable request, ExactlyHow will make available to the Controller information necessary to demonstrate compliance with this DPA. ExactlyHow may satisfy this obligation by providing recent third-party audit reports (e.g., SOC 2 Type II) to prevent disruption of its security posture.

14. Incident Notification

ExactlyHow will notify the Controller without undue delay after becoming aware of any accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of, or access to, Personal Data processed under this DPA.

15. Breach Notification

The notification will include, to the extent known, the nature of the breach, the categories and approximate number of Data Subjects concerned, the likely consequences, and the measures taken or proposed to mitigate the breach.

16. Cooperation

ExactlyHow will provide reasonable assistance to the Controller in ensuring compliance with obligations pursuant to GDPR Articles 32 to 36 (Security, Breach Notification, Data Protection Impact Assessments, and Prior Consultation), taking into account the nature of the processing and the information available.

17. Liability

The liability of each party under this DPA shall be subject to the exclusions and limitations of liability set forth in the underlying Agreement.

18. Termination

This DPA shall remain in effect until the later of (a) termination of the Agreement, or (b) ExactlyHow ceases to process Personal Data on behalf of the Controller.

19. Contact

For questions or notices regarding this DPA, please contact our privacy and legal team at privacy@exactlyhow.io.

Questions about our legal policies?

If you have questions regarding our privacy practices, legal terms, data processing, or enterprise procurement requirements, contact the ExactlyHow team.

Trust Center