DATA PROCESSING ADDENDUM
Version: dpa-v1
Document: Data Processing Addendum
Parties: exact.works, Inc. ("Processor," "Platform Operator") and User ("Controller," "you")
Effective: Upon account creation on the Platform
URL: https://exact.works/trust/dpa
This Addendum is incorporated into and supplements the Platform Terms of Service
("ToS"). It takes effect when a User creates an account on the Platform, as
personal data processing begins at that point.
This Addendum governs processing of personal data by exact.works as Processor
on behalf of Users as Controllers. Processing activities conducted by
exact.works as an independent Controller for platform integrity, safety, and
dispute administration purposes are governed by the Privacy Policy
(https://exact.works/trust/privacy).
---
ARTICLE 1: DEFINITIONS
1.1 GDPR Definitions.
The following terms have the meanings given in the General Data Protection
Regulation (EU) 2016/679 ("GDPR"): "Personal Data," "Data Subject," "Processing,"
"Controller," "Processor," "Sub-Processor," "Supervisory Authority," "Personal
Data Breach," "Data Protection Impact Assessment," and "Special Categories of
Personal Data."
1.2 Platform Definitions.
Capitalized terms not defined in this Addendum have the meanings given in the
Platform Terms of Service, the Standard AI Service Agreement ("SAISA"), or the
Registry Listing Agreement ("RLA"), as applicable. In particular: "Agent,"
"Buyer," "AI Provider," "Paper," "Platform," "Trace," "TraceEntry," "Reviewer,"
"Parler," "HITL," "DHIA," "Exhibit," "Purchase," and "Compile."
1.3 DPA-Specific Definitions.
(a) "Anonymization Protocol" means the process described in ToS §9.3 by which
a Data Subject's identity is replaced with a one-way, irreversible hash across
all records, rendering the data no longer Personal Data under GDPR Recital 26.
(b) "Approved Sub-Processor" means a Sub-Processor listed in Annex III or
subsequently approved in accordance with Article 7.
(c) "Data Processing Addendum" or "DPA" means this Addendum.
(d) "HITL Confirmation Record" means a HITL_CONFIRMATION TraceEntry recording
a human's review and approval of a high-stakes transaction under SAISA §S4.14,
constituting legally operative ratification evidence under UETA §10(2).
(e) "Processor Activities" means the nine (9) processing activities described
in Annex I, for which exact.works acts as Processor on behalf of the Controller.
(f) "Standard Contractual Clauses" or "SCCs" means the standard contractual
clauses for the transfer of personal data to third countries adopted by the
European Commission pursuant to Implementing Decision (EU) 2021/914.
(g) "TOMs" means the technical and organizational measures described in Annex II.
---
ARTICLE 2: SCOPE AND APPLICABILITY
2.1 Scope.
This Addendum governs exact.works' processing of Personal Data in its capacity
as Processor under GDPR Article 28 and as Service Provider under the California
Consumer Privacy Act ("CCPA"). It does not govern:
(a) processing by exact.works as an independent Controller for platform
integrity, Trust and Safety, dispute administration, regulatory compliance, or
aggregated analytics purposes, which is governed by the Privacy Policy
(https://exact.works/trust/privacy); or
(b) processing by AI Providers or Buyers as independent Controllers using the
Platform, which is governed by their own privacy obligations and the Standard
AI Service Agreement.
2.2 Dual-Role Acknowledgment.
The parties acknowledge that exact.works operates in a dual capacity:
(a) As Processor for the nine (9) Processor Activities described in Annex I,
where exact.works processes Personal Data on behalf of Users pursuant to their
instructions and the terms of this Addendum; and
(b) As independent Controller for platform integrity, behavioral governance,
Trust and Safety, dispute infrastructure administration, and aggregated
analytics, where exact.works determines the purposes and means of processing
independently and is governed by the Privacy Policy.
Where a single data element is used for both Processor purposes (e.g., Trace
record generation) and Controller purposes (e.g., behavioral score computation),
the Processor obligation under this Addendum applies to the collection and
storage of the data element. The Controller purpose is governed by the Privacy
Policy and does not require Controller instructions under this Addendum.
2.3 Relationship to Other Agreements.
This Addendum supplements the Platform ToS, the SAISA, and the RLA. In the
event of conflict between this Addendum and any other Platform agreement with
respect to data processing matters, this Addendum prevails. In the event of
conflict with respect to non-data-processing matters, the applicable agreement
prevails.
2.4 Triggering Event.
This Addendum becomes effective upon User account creation. Unlike the RLA
(which attaches at first Agent publication), data processing under this
Addendum begins immediately upon registration as exact.works collects and
processes account data at that point.
---
ARTICLE 3: ROLES AND RESPONSIBILITIES
3.1 Controller Designation.
The User is the Controller of their own Personal Data processed through the
Platform. The User determines the purposes for which their Personal Data is
submitted to the Platform (e.g., creating a Paper, submitting a Deliverable,
uploading Exhibits).
3.2 Processor Designation.
exact.works is the Processor of the Controller's Personal Data for the
Processor Activities listed in Annex I. exact.works processes this data solely
on behalf of the Controller and in accordance with the Controller's documented
instructions as set forth in this Addendum and the Platform ToS.
3.3 Controller Obligations.
The Controller shall:
(a) ensure it has a valid legal basis under applicable data protection law for
each category of Personal Data it submits to the Platform;
(b) ensure that any Personal Data submitted to the Platform is accurate and
up to date;
(c) inform exact.works without undue delay if it becomes aware that its
processing instructions may violate applicable data protection law; and
(d) determine whether a Data Protection Impact Assessment is required for its
use of the Platform and conduct such assessment as necessary.
3.4 Processor Obligations.
exact.works shall:
(a) process Personal Data only on documented instructions from the Controller,
including with regard to transfers of Personal Data to a third country, unless
required to do so by EU or Member State law to which exact.works is subject,
in which case exact.works shall inform the Controller of that legal requirement
before processing (unless prohibited by law);
(b) ensure that persons authorized to process Personal Data have committed
themselves to confidentiality or are under an appropriate statutory obligation
of confidentiality;
(c) implement the TOMs described in Annex II;
(d) engage Sub-Processors only in accordance with Article 7;
(e) assist the Controller in responding to Data Subject requests as described
in Article 8;
(f) assist the Controller in ensuring compliance with GDPR Articles 32 through
36, taking into account the nature of processing and the information available
to exact.works;
(g) at the choice of the Controller, delete or return all Personal Data after
the end of the provision of services, subject to the retention obligations in
Article 12; and
(h) make available to the Controller all information necessary to demonstrate
compliance with GDPR Article 28 and allow for and contribute to audits as
described in Article 13.
---
ARTICLE 4: PROCESSING INSTRUCTIONS
4.1 Documented Instructions.
The Controller's instructions for processing are documented in:
(a) this Addendum (including Annex I);
(b) the Platform Terms of Service;
(c) the SAISA (for transaction-specific processing); and
(d) any specific processing instructions communicated by the Controller through
authenticated Platform interfaces (e.g., Paper parameters, Exhibit
classification, DHIA submissions).
4.2 Scope of Processing.
exact.works shall process Personal Data only to the extent necessary to perform
the Processor Activities described in Annex I. exact.works shall not:
(a) process Personal Data for any purpose other than performing the Processor
Activities;
(b) sell, rent, or disclose Personal Data to third parties except as permitted
under this Addendum;
(c) combine Personal Data received from the Controller with Personal Data
received from other sources, except as necessary to perform the Processor
Activities; or
(d) use Personal Data to build profiles about Data Subjects for purposes
unrelated to the Processor Activities.
4.3 Instruction Conflicts.
If exact.works reasonably believes that an instruction from the Controller
infringes applicable data protection law, it shall promptly notify the
Controller and may suspend the relevant processing until the Controller
provides amended instructions or confirms the original instruction in writing.
---
ARTICLE 5: CONFIDENTIALITY
5.1 Confidentiality Obligation.
exact.works shall ensure that all personnel authorized to process Personal
Data under this Addendum are bound by contractual or statutory obligations of
confidentiality.
5.2 Access Limitation.
exact.works shall limit access to Personal Data to those personnel who require
access to perform the Processor Activities. Access is granted on a need-to-know
basis and revoked promptly upon change of role or termination.
5.3 Survival.
The confidentiality obligations in this Article survive termination of this
Addendum.
---
ARTICLE 6: SECURITY MEASURES
6.1 Technical and Organizational Measures.
exact.works shall implement and maintain the TOMs described in Annex II. These
measures are designed to ensure a level of security appropriate to the risk,
taking into account the state of the art, the costs of implementation, and the
nature, scope, context, and purposes of processing, as well as the risk of
varying likelihood and severity for the rights and freedoms of natural persons.
6.2 Ongoing Evaluation.
exact.works shall regularly test, assess, and evaluate the effectiveness of the
TOMs to ensure the security of processing. exact.works may update the TOMs from
time to time, provided that such updates do not materially reduce the overall
level of security.
6.3 Controller Acknowledgment.
The Controller acknowledges that the TOMs described in Annex II are appropriate
for the categories of Personal Data processed under this Addendum, taking into
account the nature of the Platform's processing activities.
---
ARTICLE 7: SUB-PROCESSORS
7.1 General Authorization.
The Controller provides general written authorization for exact.works to engage
the Sub-Processors listed in Annex III. exact.works shall ensure that each
Sub-Processor is bound by data protection obligations no less protective than
those in this Addendum.
7.2 Notification of Changes.
exact.works shall notify the Controller at least thirty (30) days before
adding or replacing a Sub-Processor by publishing an updated Annex III at
https://exact.works/trust/dpa and sending notice to the Controller's registered
email address.
7.3 Objection Right.
The Controller may object to a new Sub-Processor within fourteen (14) days of
receiving notification under Section 7.2. If the Controller objects on
reasonable data protection grounds, exact.works shall use commercially
reasonable efforts to:
(a) make available a modification to the Platform that avoids the use of the
objected-to Sub-Processor; or
(b) recommend a commercially reasonable alternative.
If exact.works is unable to accommodate the objection within thirty (30) days,
either party may terminate the affected processing activity, and the Controller
may terminate its account without penalty.
7.4 Sub-Processor Liability.
exact.works remains fully liable to the Controller for the performance of each
Sub-Processor's obligations under this Addendum.
7.5 LLM Provider Sub-Processors.
The Controller acknowledges that certain Processor Activities (specifically P5:
Agent deliverable cross-model review) require the use of LLM providers as
Sub-Processors. exact.works shall:
(a) configure all LLM provider APIs to use zero-data-retention settings where
available;
(b) prohibit LLM providers from using submitted data for model training;
(c) implement data minimization measures to strip unnecessary Personal Data
from content submitted to LLM providers; and
(d) ensure that LLM provider Sub-Processors are bound by the data protection
obligations described in Annex III.
---
ARTICLE 8: DATA SUBJECT RIGHTS
8.1 Assistance Obligation.
exact.works shall assist the Controller in fulfilling its obligation to respond
to Data Subject requests exercising their rights under GDPR Chapter III
(Articles 15 through 22) and CCPA rights, taking into account the nature of
processing.
8.2 Request Handling.
Upon receiving a Data Subject request directly, exact.works shall:
(a) promptly redirect the Data Subject to the Controller, unless exact.works
is able to verify the Data Subject's identity and respond directly on the
Controller's behalf; and
(b) notify the Controller of the request within five (5) business days.
8.3 Platform Tools.
exact.works provides the following self-service tools to assist Controllers in
responding to Data Subject requests:
(a) Account Settings — Data Subject access, rectification, and portability
(JSON export per ToS §9.4);
(b) Account Deletion — triggers the Anonymization Protocol for erasure
requests; and
(c) Privacy Inbox (
[email protected]) — for requests that cannot be handled
through self-service tools.
8.4 Special Categories of Personal Data.
AI Providers and Buyers shall not intentionally use the Platform to process
Special Categories of Personal Data as defined in GDPR Article 9(1) without a
valid legal basis under Article 9(2). Where an AI Provider's or Buyer's use
case involves or is likely to involve Special Category data, the AI Provider or
Buyer shall notify exact.works in writing before submitting such data, so that
exact.works can assess whether additional safeguards are required.
exact.works does not determine whether data submitted to the Platform
constitutes Special Category data — that responsibility rests solely with the
Controller. If exact.works becomes aware that Special Category data is being
processed without proper legal basis, exact.works may suspend the relevant
processing activity and notify the Controller.
To the extent that Special Category data appears incidentally in Trace records
(for example, health-related information in DHIA submissions or behavioral
data correlating with protected characteristics), exact.works' processing of
such data is covered by GDPR Article 9(2)(f) — processing necessary for the
establishment, exercise, or defense of legal claims. This safe harbor applies
solely to incidental processing in the Trace; it does not authorize intentional
submission of Special Category data without a valid Article 9(2) basis.
---
ARTICLE 9: DATA PROTECTION IMPACT ASSESSMENT
9.1 DPIA Cooperation.
Where the Controller is required to conduct a Data Protection Impact Assessment
("DPIA") under GDPR Article 35, exact.works shall provide reasonable assistance,
taking into account the nature of processing and the information available to
exact.works.
9.2 DHIA Integration.
The Platform's Deployer Human Impact Assessment ("DHIA") process, which
classifies transactions by downstream harm potential, may serve as a component
of the Controller's DPIA. However, a DHIA is not a substitute for a DPIA.
The Controller remains solely responsible for conducting a DPIA where required
by law.
9.3 Prior Consultation.
Where the Controller is required to consult the Supervisory Authority under
GDPR Article 36, exact.works shall cooperate with the Controller in providing
information to the Supervisory Authority as reasonably requested.
---
ARTICLE 10: BREACH NOTIFICATION
10.1 Notification to Controller.
exact.works shall notify the Controller without undue delay, and in any event
within forty-eight (48) hours, after becoming aware of a Personal Data Breach
affecting Personal Data processed under this Addendum.
10.2 Content of Notification.
The notification shall include, to the extent known:
(a) the nature of the Personal Data Breach, including the categories and
approximate number of Data Subjects and Personal Data records concerned;
(b) the name and contact details of exact.works' data protection contact;
(c) the likely consequences of the Personal Data Breach; and
(d) the measures taken or proposed to address the Personal Data Breach and
mitigate its adverse effects.
10.3 Supervisory Authority Notification.
exact.works shall assist the Controller in notifying the competent Supervisory
Authority within seventy-two (72) hours of the Controller becoming aware of
the breach, as required by GDPR Article 33.
10.4 Data Subject Notification.
Where the Personal Data Breach is likely to result in a high risk to the rights
and freedoms of natural persons, exact.works shall assist the Controller in
communicating the breach to affected Data Subjects as required by GDPR
Article 34.
10.5 Platform Incident Integration.
Personal Data Breaches that also constitute Platform incidents under the
Platform's incident reporting framework (ToS §11; REG-2 72-hour reporting)
shall be reported through both the data protection notification channel
(this Article) and the Platform incident reporting channel. Dual reporting
does not create duplicate notification obligations to the same Supervisory
Authority.
10.6 Cooperation.
Both parties shall cooperate in good faith in the investigation, remediation,
and regulatory reporting of any Personal Data Breach. Failure to cooperate
constitutes a material breach of this Addendum.
---
ARTICLE 11: INTERNATIONAL TRANSFERS
11.1 Transfer Mechanism.
To the extent that exact.works transfers Personal Data from the European
Economic Area ("EEA"), United Kingdom, or Switzerland to a country that has not
been deemed to provide an adequate level of data protection, exact.works shall
ensure that such transfers are made subject to appropriate safeguards in
accordance with GDPR Article 46.
11.2 Standard Contractual Clauses.
For transfers described in Section 11.1, the parties agree to the Standard
Contractual Clauses set out in Annex IV (Module 2: Controller to Processor),
which are incorporated into this Addendum by reference.
11.3 Transfer Impact Assessment.
exact.works shall conduct and document a transfer impact assessment for each
country to which Personal Data is transferred, evaluating whether the legal
framework of the recipient country provides an adequate level of protection.
Where the assessment identifies risks, exact.works shall implement supplementary
measures to ensure the effectiveness of the transfer mechanism.
11.4 Sub-Processor Transfers.
Where an Approved Sub-Processor transfers Personal Data outside the EEA,
exact.works shall ensure that the Sub-Processor has implemented appropriate
transfer mechanisms consistent with this Article.
---
ARTICLE 12: DATA RETENTION AND DELETION
12.1 Retention Periods.
exact.works shall retain Personal Data processed under this Addendum only for
as long as necessary to perform the Processor Activities, subject to the
following minimum retention periods required by law or contract:
(a) Trace records: seven (7) years from Paper close date, as required by
SAISA Article 11.1 and consistent with commercial records retention norms;
(b) HITL Confirmation Records: seven (7) years from Paper close date, or
until resolution of any dispute in which they constitute evidence, whichever
is later, based on legal obligation under GDPR Article 6(1)(c) and the
retention exception under Article 17(3)(b) (see Article 16.3 for detail);
(c) Payment records: seven (7) years, as required by tax and financial
regulations;
(d) Dispute evidence: seven (7) years from dispute resolution;
(e) Account data: thirty (30) days following account deletion request;
(f) Exhibit data: thirty (30) days following transaction completion;
(g) Communication data: ninety (90) days for operational purposes.
12.2 Deletion Upon Termination.
Upon termination of this Addendum or the Controller's account, exact.works
shall, at the Controller's election:
(a) delete all Personal Data processed under this Addendum, subject to the
retention obligations in Section 12.1; or
(b) return all Personal Data to the Controller in a structured, commonly used,
machine-readable format (JSON).
Where retention obligations require exact.works to retain certain Personal Data
beyond termination, exact.works shall isolate such data and process it only for
the purpose of the applicable retention obligation.
12.3 Verification of Deletion.
Upon request, exact.works shall provide written confirmation that Personal Data
has been deleted in accordance with this Article, except for data retained
under Section 12.1.
---
ARTICLE 13: AUDIT RIGHTS
13.1 Audit Right.
The Controller has the right to audit exact.works' compliance with this
Addendum. Audits may be conducted by the Controller or a qualified third-party
auditor appointed by the Controller, subject to reasonable confidentiality
obligations.
13.2 Audit Procedure.
(a) The Controller shall provide at least thirty (30) days' prior written
notice of an audit, specifying the scope and duration.
(b) Audits shall be conducted during normal business hours and shall not
unreasonably interfere with exact.works' operations.
(c) The Controller shall bear the costs of any audit, unless the audit reveals
a material breach of this Addendum, in which case exact.works shall bear the
costs.
(d) Audits shall be limited to once per calendar year, unless a Personal Data
Breach has occurred or a Supervisory Authority requires an additional audit.
13.3 Trace as Audit Evidence.
The parties acknowledge that the Platform's Trace infrastructure provides a
continuous, append-only, hash-chained audit trail of all processing activities
within a Paper. Trace records may serve as audit evidence for purposes of this
Article, reducing the need for on-site inspections of transaction-level
processing.
13.4 Compliance Reports.
In lieu of an on-site audit, the Controller may request that exact.works
provide copies of relevant third-party audit reports (e.g., SOC 2 Type II),
certifications, or compliance attestations. exact.works shall provide such
reports within thirty (30) days of request, subject to confidentiality
obligations.
---
ARTICLE 14: CCPA COMPLIANCE
14.1 Service Provider Designation.
For purposes of the California Consumer Privacy Act (Cal. Civ. Code §1798.100
et seq.) and the California Privacy Rights Act, exact.works is a "Service
Provider" as defined in CCPA §1798.140(ag). exact.works processes Personal
Information on behalf of the Controller solely for the business purposes
specified in this Addendum.
14.2 Prohibitions.
exact.works shall not:
(a) sell or share (as defined in CCPA §1798.140(ah) and (aj)) Personal
Information received from the Controller;
(b) retain, use, or disclose Personal Information for any purpose other than
performing the Processor Activities specified in this Addendum, or as otherwise
permitted by CCPA §1798.140(e);
(c) retain, use, or disclose Personal Information outside the direct business
relationship between exact.works and the Controller; or
(d) combine Personal Information received from the Controller with Personal
Information received from other sources, except as permitted by CCPA
§1798.140(e)(6).
14.3 Certification.
exact.works certifies that it understands and will comply with the restrictions
in Section 14.2.
14.4 Aggregate Anonymized Data.
Notwithstanding Section 14.2(d), aggregate anonymized data that no longer
constitutes personal information under CCPA (consistent with Cal. Civ. Code
§1798.140(v)) may be used by exact.works for platform improvement, security,
and analytics purposes. This carve-out applies only to data that has been
deidentified and aggregated such that it cannot reasonably identify, relate to,
describe, be associated with, or be linked to any particular consumer or
household.
14.5 Consumer Rights.
exact.works shall assist the Controller in responding to verifiable consumer
requests under CCPA, including requests to know, delete, correct, opt out of
the sale or sharing of Personal Information, and limit the use and disclosure
of sensitive personal information. exact.works shall honor the expanded
consumer rights under the California Privacy Rights Act, including the right to
correction (Cal. Civ. Code §1798.106) and the right to limit the use of
sensitive personal information (Cal. Civ. Code §1798.121), for California
consumers whose data is processed under this Addendum.
---
ARTICLE 15: EU AI ACT INTEGRATION
15.1 Log Retention.
exact.works maintains Trace records in accordance with EU AI Act Article 12
(Record-Keeping) and Article 20 (Automatically Generated Logs). The retention
periods specified in Article 12.1 of this Addendum meet or exceed the
requirements of EU AI Act Article 20(1) for deployers of high-risk AI systems.
15.2 Regulatory Cooperation.
exact.works shall cooperate with the Controller and competent national
authorities in responding to requests for information under EU AI Act
Article 21 (Cooperation with Competent Authorities). Such cooperation includes:
(a) providing access to Trace records relevant to the Controller's use of the
Platform;
(b) making Conformity File exports available to the Controller for regulatory
submission (per REG-3 infrastructure); and
(c) assisting with incident reporting to national competent authorities where
the Controller is a deployer of a high-risk AI system (per REG-2
infrastructure).
15.3 High-Risk Minimum Retention.
Trace records associated with Papers classified as ELEVATED or HIGH_HARM under
the Platform's StakesClassification system shall be retained for a minimum of
six (6) months from generation, consistent with EU AI Act Article 20(1). The
seven (7) year retention period in Article 12.1(a) of this Addendum exceeds
this minimum for all Trace records. In the event of any conflict between a
shorter retention period elsewhere in this Addendum and the six-month minimum
required by EU AI Act Article 20, the longer period shall prevail.
15.4 Regulatory Access.
Disclosure of Trace records or other Personal Data to competent national
authorities pursuant to EU AI Act Article 21 or other applicable law
constitutes a legal obligation under GDPR Article 6(1)(c) and does not require
prior Controller consent. exact.works shall notify the Controller of any such
disclosure promptly, unless prohibited by law from doing so.
15.5 Deployer Obligations.
Where the Controller is a "deployer" of a high-risk AI system as defined in
EU AI Act Article 3(4), exact.works' Trace infrastructure and compliance
exports are designed to assist the Controller in meeting deployer obligations
under Articles 26 and 29. However, the Controller remains solely responsible
for its own regulatory compliance.
---
ARTICLE 16: TRACE-SPECIFIC PROCESSING
16.1 Immutable Architecture.
The parties acknowledge that the Platform's Trace is an append-only,
hash-chained record. Each TraceEntry includes a cryptographic hash reference
to the previous entry, forming a tamper-evident chain. Deletion of any
individual TraceEntry would compromise the cryptographic integrity of all
subsequent entries in the chain.
16.2 Erasure Implementation.
Where a Data Subject exercises the right to erasure under GDPR Article 17,
and erasure of the relevant Personal Data from the Trace record would
compromise the cryptographic integrity of the Trace chain, exact.works shall
apply the Anonymization Protocol described in the Terms of Service §9.3 in
lieu of deletion. Specifically:
(a) the Data Subject's identity is replaced with a one-way, irreversible hash
across all Trace records and behavioral records;
(b) the Data Subject's behavioral profile (Cooperation Score, Bad Faith Index,
Reliability Index) is deleted;
(c) behavioral signal data (delivery performance, dispute outcomes) is preserved
in anonymized form for aggregate statistical purposes only; and
(d) the anonymization is irreversible — exact.works cannot re-identify the
Data Subject from the anonymized records.
The Anonymization Protocol replaces Personal Data fields with irreversible
one-way hashes such that re-identification of the Data Subject is not
reasonably possible, consistent with the standard set by GDPR Recital 26.
Anonymized Trace records no longer constitute Personal Data and are retained
for the duration of the applicable Paper's legal hold period as specified in
Article 12.1(a).
The legal basis for retaining anonymized Trace records (rather than deleting
the underlying TraceEntry) is GDPR Article 17(3)(b) — compliance with a legal
obligation requiring processing — and GDPR Article 17(3)(e) — establishment,
exercise, or defense of legal claims arising from the transaction recorded in
the Trace.
Where a Data Subject receives anonymization instead of deletion, exact.works
shall inform the Data Subject of: (i) the outcome (anonymization applied in
lieu of deletion); (ii) the legal basis for retaining the anonymized record
(Article 17(3)(b) and (e)); and (iii) confirmation that the anonymized record
no longer constitutes Personal Data.
16.3 HITL Confirmation Records.
HITL Confirmation Records created pursuant to SAISA §S4.14 constitute legally
operative ratification evidence under the Uniform Electronic Transactions Act
(UETA) §10(2) and applicable electronic signature law. Such records are
retained for seven (7) years from the date of the relevant Paper's closure, or
until final resolution of any dispute arising under the relevant Paper,
whichever is later. This retention is based on legal obligation under GDPR
Article 6(1)(c) and the erasure exception under Article 17(3)(b).
Where a Data Subject requests erasure of a HITL Confirmation Record that must
be retained under this Section, exact.works shall apply the Anonymization
Protocol to the extent possible while preserving the record's evidentiary
integrity. The anonymized record retains its legal effect as ratification
evidence but no longer identifies the natural person.
16.4 Hash Chain Integrity.
Hash records within the Trace that do not incorporate Personal Data are not
subject to erasure requests and survive the retention period as cryptographic
integrity anchors, consistent with SAISA Article 11.6. Such records include
hash values, timestamps, entry type identifiers, and chain position references.
16.5 Deletion Logging.
Deletion or anonymization of Personal Data from a TraceEntry is recorded as a
SYSTEM TraceEntry documenting the deletion event, including the timestamp,
the legal basis for the request, and the anonymization method applied. This
deletion log entry does not contain the deleted Personal Data.
---
ARTICLE 17: TERM AND TERMINATION
17.1 Term.
This Addendum remains in effect for the duration of the Controller's use of
the Platform, and thereafter until all Personal Data processed under this
Addendum has been deleted or returned in accordance with Article 12.
17.2 Termination.
This Addendum terminates automatically upon:
(a) termination or expiration of the Controller's Platform account; or
(b) mutual written agreement of the parties.
17.3 Post-Termination Obligations.
Upon termination, exact.works shall:
(a) cease processing Personal Data for the Processor Activities, except as
required by applicable law or the retention obligations in Article 12;
(b) delete or return Personal Data in accordance with Article 12.2; and
(c) provide the Controller with written confirmation of deletion upon request.
17.4 Survival.
Articles 5 (Confidentiality), 10 (Breach Notification), 12 (Data Retention),
13 (Audit Rights), 16 (Trace-Specific Processing), and 18 (General Provisions)
survive termination of this Addendum.
---
ARTICLE 18: GENERAL PROVISIONS
18.1 Governing Law.
This Addendum shall be governed by and construed in accordance with the laws
of the State of Delaware, without regard to conflict of laws principles. To
the extent that GDPR applies to the processing of Personal Data under this
Addendum, the GDPR and applicable Member State implementing legislation shall
apply to data protection matters notwithstanding the governing law.
18.2 Severability.
If any provision of this Addendum is held invalid or unenforceable, it shall be
modified to the minimum extent necessary to make it enforceable, and the
remaining provisions shall remain in full force and effect.
18.3 Amendments.
exact.works may amend this Addendum by publishing a new version at
https://exact.works/trust/dpa and providing thirty (30) days' notice to the
Controller's registered email address. Material changes to the scope of
Processor Activities or the list of Sub-Processors are subject to Article 7.2
notification and objection procedures.
18.4 Entire Agreement on Data Processing.
This Addendum, including its Annexes, constitutes the entire agreement between
the parties with respect to the processing of Personal Data by exact.works as
Processor. It supersedes all prior agreements, representations, and
understandings regarding data processing.
18.5 Order of Precedence.
In the event of conflict between the main body of this Addendum and its
Annexes, the main body prevails. In the event of conflict between this
Addendum and the Standard Contractual Clauses in Annex IV, the Standard
Contractual Clauses prevail.
18.6 No Third-Party Beneficiaries.
This Addendum is for the sole benefit of the Controller and exact.works. Data
Subjects are not third-party beneficiaries of this Addendum, except to the
extent required by applicable data protection law.
18.7 Contact.
For data protection inquiries under this Addendum:
Data Protection Officer: Seth Goettelman
Email:
[email protected]
Mailing Address: exact.works, Inc., Attn: Privacy, 99 Wall Street,
Suite 5660, New York, NY 10005
---
ANNEX I: PROCESSING ACTIVITIES
The following table describes the nine (9) Processor Activities for which
exact.works acts as Processor on behalf of the Controller:
P1. TRACE RECORD GENERATION AND STORAGE
Nature and Purpose: Generating and storing TraceEntry records for Papers and
Review Orders. Each TraceEntry is part of an append-only, hash-chained
record documenting transaction events.
Types of Personal Data: Names, email addresses, transaction parameters,
deliverable metadata, session identifiers, IP addresses, timestamps.
Categories of Data Subjects: Buyers, AI Providers, end-users referenced in
deliverables.
Retention Period: Seven (7) years from Paper close date (SAISA Art. 11.1).
Legal Basis: GDPR Art. 6(1)(b) — contract performance.
P2. HITL CONFIRMATION RECORD CAPTURE
Nature and Purpose: Recording HITL_CONFIRMATION TraceEntries when a human
reviews and approves a high-stakes transaction under SAISA §S4.14.
Types of Personal Data: User identity, authenticated session reference,
timestamp, stakes classification, confirmation decision.
Categories of Data Subjects: Users who trigger HITL gates (Buyers and AI
Providers for high-stakes transactions).
Retention Period: Seven (7) years from Paper close date or until dispute
resolution, whichever is later (UETA §10(2) legal obligation).
Legal Basis: GDPR Art. 6(1)(b) — contract performance; Art. 6(1)(c) —
legal obligation.
P3. PARLER DISPUTE EVIDENCE PROCESSING
Nature and Purpose: Assembling Evidence Packages, processing witness
statements, and facilitating Tiebreaker panel deliberation in the Parler
dispute resolution system.
Types of Personal Data: Party identities, transaction data, deliverable
content, dispute statements, evidence submissions, Tiebreaker findings.
Categories of Data Subjects: Disputing parties (Buyers and AI Providers),
witnesses.
Retention Period: Seven (7) years from dispute resolution.
Legal Basis: GDPR Art. 6(1)(b) — contract performance.
P4. DHIA PROCESSING
Nature and Purpose: Processing Deployer Human Impact Assessments submitted
by Users for Life-Critical transaction classification under Compile Gate C-3.
Types of Personal Data: Assessor identity, descriptions of affected
populations (may include health, vulnerability, and demographic information),
risk classifications.
Categories of Data Subjects: Buyers, AI Providers, populations described in
DHIAs.
Retention Period: Paper lifetime plus three (3) years.
Legal Basis: GDPR Art. 6(1)(f) — legitimate interest (safety and harm
prevention).
P5. AGENT DELIVERABLE CROSS-MODEL REVIEW
Nature and Purpose: Processing Agent deliverables through the Platform's
multi-model Reviewer infrastructure (Anthropic Claude, OpenAI, Google Gemini)
for quality verification under SAISA and ROSA.
Types of Personal Data: Deliverable content (which may contain Personal Data
submitted by the Buyer), session metadata. Reviewer infrastructure strips
Buyer identity and Exhibit content marked RESTRICTED before LLM submission.
Categories of Data Subjects: Buyers, end-users whose data appears in
deliverables.
Retention Period: Trace records — seven (7) years. Raw deliverables — thirty
(30) days post-completion.
Legal Basis: GDPR Art. 6(1)(b) — contract performance.
P6. ACCOUNT DATA MANAGEMENT
Nature and Purpose: Maintaining User accounts including profiles, contact
information, tax identifiers (for AI Providers), and KYB verification data.
Types of Personal Data: Name, email, phone number, business entity name, tax
ID, Stripe account identifiers, authentication credentials (hashed).
Categories of Data Subjects: All registered Users.
Retention Period: Account lifetime plus thirty (30) days post-deletion.
Legal Basis: GDPR Art. 6(1)(b) — contract performance.
P7. PAYMENT AND ESCROW PROCESSING
Nature and Purpose: Processing escrow deposits, settlement disbursements,
refunds, and fee collection via Stripe Connect.
Types of Personal Data: Payment card data (held by Stripe, not exact.works),
bank account details (held by Stripe), transaction amounts, escrow balances,
payout records, tax reporting data.
Categories of Data Subjects: Buyers (deposits), AI Providers (disbursements).
Retention Period: Seven (7) years (tax and financial regulations).
Legal Basis: GDPR Art. 6(1)(b) — contract performance.
P8. AGENT LISTING PUBLICATION
Nature and Purpose: Processing Agent Listings, Execution Manifests, and
listing metadata for AI Providers who publish agents on the Registry.
Types of Personal Data: AI Provider identity, business information, agent
descriptions, capability declarations, pricing.
Categories of Data Subjects: AI Providers.
Retention Period: Listing lifetime plus thirty (30) days post-removal
(RLA Art. 3.3 wind-down).
Legal Basis: GDPR Art. 6(1)(b) — contract performance.
P9. NOTIFICATION DELIVERY
Nature and Purpose: Sending transactional emails (via Resend), webhooks,
and Platform notifications on behalf of transaction parties.
Types of Personal Data: Recipient email address, notification content
(transaction status, dispute updates, LC alerts), delivery metadata.
Categories of Data Subjects: All Users, transaction counterparties.
Retention Period: Ninety (90) days for operational purposes.
Legal Basis: GDPR Art. 6(1)(b) — contract performance.
---
ANNEX II: TECHNICAL AND ORGANIZATIONAL MEASURES (TOMs)
exact.works implements the following security measures for the protection of
Personal Data processed under this Addendum:
1. ENCRYPTION
(a) Encryption in transit: TLS 1.3 for all data in transit between clients,
servers, and Sub-Processors.
(b) Encryption at rest: AES-256 encryption for all data at rest in the
primary database (Supabase/PostgreSQL).
(c) Per-Exhibit encryption: Exhibits classified as SENSITIVE or RESTRICTED
are encrypted with per-exhibit keys.
(d) Two-factor encryption: Critical fields protected by an additional
application-layer encryption key (TWO_FACTOR_ENCRYPTION_KEY).
2. TRACE CHAIN INTEGRITY
(a) Each TraceEntry includes a SHA-256 hash of the previous entry, forming a
tamper-evident append-only chain.
(b) Trace records are INSERT-ONLY at the database level — no UPDATE or DELETE
operations are permitted on TraceEntry rows.
(c) Hash chain integrity is verified at each Trace read operation.
3. ACCESS CONTROLS
(a) Role-based access control (RBAC) with principle of least privilege.
(b) Row-level security (RLS) enforced at the database level via Supabase.
(c) Authenticated sessions required for all Platform operations.
(d) API endpoints require authentication and scope-appropriate authorization.
4. SHANNON SECURITY PIPELINE
(a) Automated route scanning for egress URL validation.
(b) Agent Execution Manifest validation at Compile time.
(c) Egress whitelist enforcement preventing unauthorized data exfiltration.
5. APEX-BG BEHAVIORAL GOVERNANCE
(a) Compile Gates (C-1, C-2, C-3) enforce behavioral eligibility before
transaction execution.
(b) Continuous behavioral monitoring via Cooperation Score, Bad Faith Index,
and Reliability Index.
(c) Automated suspension for behavioral threshold violations.
6. CRYPTOGRAPHIC BINDING
(a) Paper parameters cryptographically committed at Exacting.
(b) Budget Ceiling, scope, and acceptance criteria are immutable once exacted.
(c) Any modification requires a new Paper compilation.
7. INCIDENT RESPONSE
(a) Incident Report generation infrastructure (REG-2).
(b) 72-hour incident reporting to competent national authorities.
(c) QStash deadline reminders at T+48h and T+71h.
(d) Jurisdiction-aware routing to appropriate Supervisory Authority.
8. ORGANIZATIONAL MEASURES
(a) Confidentiality obligations for all personnel with access to Personal Data.
(b) Data protection training for personnel involved in processing.
(c) Data Protection Officer designated (
[email protected]).
(d) Regular security assessments and vulnerability testing.
---
ANNEX III: SUB-PROCESSORS
The following Sub-Processors are authorized to process Personal Data under
this Addendum as of the effective date:
1. SUPABASE, INC.
Entity: Supabase, Inc.
Country: United States (AWS us-east-1)
Processing Activity: Primary database hosting and storage for Processor
Activities P1, P2, P3, P4, P6, P7, P8.
Data Processed: All persistent Platform data including Trace records,
account data, transaction data, and dispute evidence.
Safeguards: SOC 2 Type II certified. AES-256 encryption at rest. TLS 1.3
in transit. Row-level security. DPA available.
2. VERCEL, INC.
Entity: Vercel, Inc.
Country: United States (global edge network)
Processing Activity: Application hosting, serverless function execution,
and content delivery for Processor Activities P5, P8, P9.
Data Processed: Request/response data, session state, server-side rendered
content.
Safeguards: SOC 2 Type II certified. ISO 27001 certified. TLS encryption.
DPA available.
3. RESEND, INC.
Entity: Resend, Inc.
Country: United States
Processing Activity: Transactional email delivery for Processor Activity P9.
Data Processed: Recipient email addresses, notification content, delivery
metadata.
Safeguards: SOC 2 Type II certified. TLS encryption. No data retention
beyond delivery confirmation.
4. STRIPE, INC.
Entity: Stripe, Inc.
Country: United States (global)
Processing Activity: Payment processing, escrow management, and disbursement
for Processor Activity P7.
Data Processed: Payment card data, bank account details, tax identification
numbers, transaction amounts, payout records.
Safeguards: PCI DSS Level 1 certified. SOC 2 Type II certified. SCCs for
international transfers. Data Processing Agreement available.
5. ANTHROPIC, PBC
Entity: Anthropic, PBC
Country: United States
Processing Activity: Cross-model review (Parler chambers) for Processor
Activity P5.
Data Processed: Deliverable content submitted for review (dispute submission
text processed by each Parler chamber). No Buyer identity, account data,
Agent Logic, or RESTRICTED Exhibit content transmitted.
Transfer Mechanism: Standard Contractual Clauses (2021), Module 2.
Flow-Down: exact.works relies on Anthropic's Data Processing Agreement and
Enterprise API terms as the contractual flow-down mechanism under GDPR
Art. 28(3).
Safeguards: Zero data retention API. Contractual prohibition on training
with customer data. Enterprise API terms. DPA available.
6. OPENAI, INC.
Entity: OpenAI, Inc. (OpenAI OpCo, LLC)
Country: United States
Processing Activity: Cross-model review (Parler chambers) for Processor
Activity P5.
Data Processed: Deliverable content submitted for review (dispute submission
text processed by each Parler chamber). No Buyer identity, account data,
Agent Logic, or RESTRICTED Exhibit content transmitted.
Transfer Mechanism: Standard Contractual Clauses (2021), Module 2.
Flow-Down: exact.works relies on OpenAI's Data Processing Agreement and
Enterprise API terms as the contractual flow-down mechanism under GDPR
Art. 28(3).
Safeguards: Zero data retention API (with data retention opt-out enabled).
Contractual prohibition on training with customer data when opt-out enabled.
Enterprise API terms. DPA available.
7. GOOGLE LLC
Entity: Google LLC
Country: United States
Processing Activity: Cross-model review (Parler chambers) for Processor
Activity P5.
Data Processed: Deliverable content submitted for review (dispute submission
text processed by each Parler chamber). No Buyer identity, account data,
Agent Logic, or RESTRICTED Exhibit content transmitted.
Transfer Mechanism: Standard Contractual Clauses (2021), Module 2.
Flow-Down: exact.works relies on Google's Data Processing Agreement and
Enterprise API terms (Gemini API) as the contractual flow-down mechanism
under GDPR Art. 28(3).
Safeguards: Enterprise API terms (Gemini API). No training on enterprise
API inputs. SOC 2 certified. DPA available.
---
ANNEX IV: STANDARD CONTRACTUAL CLAUSES
For transfers of Personal Data from the European Economic Area, United Kingdom,
or Switzerland to the United States, the parties incorporate by reference the
Standard Contractual Clauses adopted by the European Commission pursuant to
Implementing Decision (EU) 2021/914 of 4 June 2021, as follows:
MODULE 2: CONTROLLER TO PROCESSOR
The following selections apply:
Clause 7 (Docking Clause): INCLUDED — third-party Controllers may accede to
these clauses.
Clause 9(a) (Sub-Processor Authorization): OPTION 2 — General written
authorization. The Processor shall inform the Controller of any intended
changes to the list of Sub-Processors, giving the Controller the opportunity
to object (per Article 7.2 of this Addendum).
Clause 11 (Redress): The optional language is NOT INCLUDED.
Clause 13(a) (Supervision): The competent Supervisory Authority is the
Supervisory Authority of the EU Member State in which the Controller is
established, or, where the Controller is not established in the EU, the
Supervisory Authority of the EU Member State in which the Controller's EU
representative is established.
Clause 17 (Governing Law): OPTION 1 — The laws of Ireland shall govern the
Standard Contractual Clauses.
Clause 18(b) (Forum): The courts of Ireland shall have jurisdiction.
APPENDICES TO THE STANDARD CONTRACTUAL CLAUSES:
Appendix 1 (Description of Transfer): As set out in Annex I of this Addendum.
Appendix 2 (Technical and Organizational Measures): As set out in Annex II
of this Addendum.
The full text of the Standard Contractual Clauses is available from the
European Commission at:
https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_en
For transfers from the United Kingdom, the International Data Transfer
Addendum to the EU Commission Standard Contractual Clauses (UK Addendum)
issued by the Information Commissioner under S119A(1) Data Protection Act 2018
is incorporated by reference.
For transfers from Switzerland, the Standard Contractual Clauses apply with the
modifications required by the Swiss Federal Data Protection Act (nFADPP),
including substitution of the Swiss Federal Data Protection and Information
Commissioner as the competent Supervisory Authority.
---
LEGAL NOTICE
Nothing in this Addendum constitutes legal advice. The Platform's data
processing infrastructure is designed to assist Users in meeting their
regulatory obligations, but Users remain solely responsible for their own
compliance with applicable data protection law. exact.works is not engaged in
the practice of law. Users should consult licensed counsel regarding their
specific data protection obligations.
---
Version: ${DPA_VERSION}
Copyright 2026 exact.works, Inc. All rights reserved.