1. Purpose
This Data Processing Addendum ("DPA") forms part of the Terms of Service or other written agreement (the "Agreement") between ExactlyHow ("Processor") and the Customer ("Controller") utilizing the Operational Knowledge Platform. It establishes the rights and obligations of both parties regarding the processing of Personal Data in accordance with Applicable Data Protection Laws, including the GDPR.
2. Definitions
Capitalized terms not defined herein shall have the meaning set forth in the Agreement. "Personal Data", "Data Subject", "Processing", "Controller", and "Processor" shall have the meanings given in the GDPR (Article 4).
3. Roles
For the purposes of this DPA, the Customer is the Controller of the Personal Data contained within their Process Library, Attachments, and Organization Workspaces. ExactlyHow acts as the Processor, processing the data solely on behalf of the Controller.
4. Controller
The Controller instructs the Processor to process Personal Data for the purpose of providing the Services. The Controller is responsible for ensuring its processing instructions comply with Applicable Data Protection Laws and that it has obtained all necessary consents to transfer Personal Data to the Processor.
5. Processor
ExactlyHow will process Personal Data only in accordance with the Controller's documented instructions, unless required to do otherwise by applicable law. The Processor will immediately inform the Controller if, in its opinion, an instruction infringes on Applicable Data Protection Laws.
6. Subprocessors
The Controller provides general authorization for ExactlyHow to engage Subprocessors to assist in delivering the Services. A current list of Subprocessors is available at exactlyhow.app/legal. ExactlyHow will impose data protection obligations upon its Subprocessors that are no less protective than those included in this DPA.
7. Security Measures
ExactlyHow will implement and maintain appropriate technical and organizational security measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures include encryption at rest and in transit, access controls, and regular application monitoring.
8. Confidentiality
ExactlyHow ensures that its personnel engaged in the Processing of Personal Data are informed of the confidential nature of the Personal Data and have executed written confidentiality agreements.
9. International Transfers
If the Processing involves transferring Personal Data originating from the EEA, UK, or Switzerland to countries not recognized as providing adequate protection, ExactlyHow agrees to abide by the Standard Contractual Clauses (SCCs) or other valid transfer mechanisms recognized by applicable authorities.
10. Data Subject Rights
ExactlyHow provides the Controller with the tools necessary to fulfill Data Subject requests (e.g., access, rectification, erasure). If ExactlyHow receives a request directly from a Data Subject, it will promptly redirect the request to the Controller without responding to the Data Subject, unless legally required to do so.
11. Deletion
Upon termination or expiration of the Agreement, ExactlyHow will, at the choice of the Controller, delete or return all Personal Data processed on behalf of the Controller, and delete existing copies unless applicable law requires continued storage.
12. Retention
ExactlyHow will retain Personal Data for the duration of the Agreement or as long as necessary to provide the Services. Customers may request deletion of their Organization Workspace, which triggers a secure deletion process within standard backup cycles.
13. Audits
Upon reasonable request, ExactlyHow will make available to the Controller information necessary to demonstrate compliance with this DPA. ExactlyHow may satisfy this obligation by providing recent third-party audit reports (e.g., SOC 2 Type II) to prevent disruption of its security posture.
14. Incident Notification
ExactlyHow will notify the Controller without undue delay after becoming aware of any accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of, or access to, Personal Data processed under this DPA.
15. Breach Notification
The notification will include, to the extent known, the nature of the breach, the categories and approximate number of Data Subjects concerned, the likely consequences, and the measures taken or proposed to mitigate the breach.
16. Cooperation
ExactlyHow will provide reasonable assistance to the Controller in ensuring compliance with obligations pursuant to GDPR Articles 32 to 36 (Security, Breach Notification, Data Protection Impact Assessments, and Prior Consultation), taking into account the nature of the processing and the information available.
17. Liability
The liability of each party under this DPA shall be subject to the exclusions and limitations of liability set forth in the underlying Agreement.
18. Termination
This DPA shall remain in effect until the later of (a) termination of the Agreement, or (b) ExactlyHow ceases to process Personal Data on behalf of the Controller.
19. Contact
For questions or notices regarding this DPA, please contact our privacy and legal team at privacy@exactlyhow.io.