← Trust Center

Data Processing Addendum

Version: dpa-v1

View Privacy PolicyView Platform TOS

This Data Processing Addendum (“DPA”) governs the processing of personal data by exact.works, Inc. as Processor on behalf of Users as Controllers. It is incorporated into and supplements the Platform Terms of Service and takes effect on account creation.

Key Data Protections

Dual-Role Transparency

Article 2.2

exact.works explicitly delineates its Processor role (9 activities under your control) from its Controller role (platform integrity, governed by Privacy Policy). No ambiguity.

Trace Erasure Resolution

Article 16.2

GDPR Art. 17 erasure implemented via irreversible anonymization protocol. Hash chain integrity preserved. Anonymized records are no longer Personal Data under Recital 26.

HITL Evidence Integrity

Article 16.3

HITL confirmation records retained as legally operative evidence under UETA §10(2). 7-year retention with legal obligation basis. Anonymization preserves evidentiary integrity.

LLM Sub-Processor Controls

Article 7.5

All LLM providers configured for zero data retention. No training on submitted data. Data minimization strips PII before LLM submission.

Sub-Processor Objection Right

Article 7.3

30-day advance notice of new Sub-Processors. 14-day objection window. Right to terminate without penalty if objection cannot be accommodated.

EU AI Act Ready

Article 15

Trace retention meets Art. 20 log requirements. Conformity File exports assist Art. 21 cooperation. Incident reporting infrastructure supports Art. 62 obligations.

Table of Contents

Article 1: DefinitionsArticle 2: Scope and ApplicabilityArticle 3: Roles and ResponsibilitiesArticle 4: Processing InstructionsArticle 5: ConfidentialityArticle 6: Security MeasuresArticle 7: Sub-ProcessorsArticle 8: Data Subject RightsArticle 9: Data Protection Impact AssessmentArticle 10: Breach NotificationArticle 11: International TransfersArticle 12: Data Retention and DeletionArticle 13: Audit RightsArticle 14: CCPA ComplianceArticle 15: EU AI Act IntegrationArticle 16: Trace-Specific ProcessingArticle 17: Term and TerminationArticle 18: General Provisions
DATA PROCESSING ADDENDUM Version: dpa-v1 Document: Data Processing Addendum Parties: exact.works, Inc. ("Processor," "Platform Operator") and User ("Controller," "you") Effective: Upon account creation on the Platform URL: https://exact.works/trust/dpa This Addendum is incorporated into and supplements the Platform Terms of Service ("ToS"). It takes effect when a User creates an account on the Platform, as personal data processing begins at that point. This Addendum governs processing of personal data by exact.works as Processor on behalf of Users as Controllers. Processing activities conducted by exact.works as an independent Controller for platform integrity, safety, and dispute administration purposes are governed by the Privacy Policy (https://exact.works/trust/privacy). --- ARTICLE 1: DEFINITIONS 1.1 GDPR Definitions. The following terms have the meanings given in the General Data Protection Regulation (EU) 2016/679 ("GDPR"): "Personal Data," "Data Subject," "Processing," "Controller," "Processor," "Sub-Processor," "Supervisory Authority," "Personal Data Breach," "Data Protection Impact Assessment," and "Special Categories of Personal Data." 1.2 Platform Definitions. Capitalized terms not defined in this Addendum have the meanings given in the Platform Terms of Service, the Standard AI Service Agreement ("SAISA"), or the Registry Listing Agreement ("RLA"), as applicable. In particular: "Agent," "Buyer," "AI Provider," "Paper," "Platform," "Trace," "TraceEntry," "Reviewer," "Parler," "HITL," "DHIA," "Exhibit," "Purchase," and "Compile." 1.3 DPA-Specific Definitions. (a) "Anonymization Protocol" means the process described in ToS §9.3 by which a Data Subject's identity is replaced with a one-way, irreversible hash across all records, rendering the data no longer Personal Data under GDPR Recital 26. (b) "Approved Sub-Processor" means a Sub-Processor listed in Annex III or subsequently approved in accordance with Article 7. (c) "Data Processing Addendum" or "DPA" means this Addendum. (d) "HITL Confirmation Record" means a HITL_CONFIRMATION TraceEntry recording a human's review and approval of a high-stakes transaction under SAISA §S4.14, constituting legally operative ratification evidence under UETA §10(2). (e) "Processor Activities" means the nine (9) processing activities described in Annex I, for which exact.works acts as Processor on behalf of the Controller. (f) "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission pursuant to Implementing Decision (EU) 2021/914. (g) "TOMs" means the technical and organizational measures described in Annex II. --- ARTICLE 2: SCOPE AND APPLICABILITY 2.1 Scope. This Addendum governs exact.works' processing of Personal Data in its capacity as Processor under GDPR Article 28 and as Service Provider under the California Consumer Privacy Act ("CCPA"). It does not govern: (a) processing by exact.works as an independent Controller for platform integrity, Trust and Safety, dispute administration, regulatory compliance, or aggregated analytics purposes, which is governed by the Privacy Policy (https://exact.works/trust/privacy); or (b) processing by AI Providers or Buyers as independent Controllers using the Platform, which is governed by their own privacy obligations and the Standard AI Service Agreement. 2.2 Dual-Role Acknowledgment. The parties acknowledge that exact.works operates in a dual capacity: (a) As Processor for the nine (9) Processor Activities described in Annex I, where exact.works processes Personal Data on behalf of Users pursuant to their instructions and the terms of this Addendum; and (b) As independent Controller for platform integrity, behavioral governance, Trust and Safety, dispute infrastructure administration, and aggregated analytics, where exact.works determines the purposes and means of processing independently and is governed by the Privacy Policy. Where a single data element is used for both Processor purposes (e.g., Trace record generation) and Controller purposes (e.g., behavioral score computation), the Processor obligation under this Addendum applies to the collection and storage of the data element. The Controller purpose is governed by the Privacy Policy and does not require Controller instructions under this Addendum. 2.3 Relationship to Other Agreements. This Addendum supplements the Platform ToS, the SAISA, and the RLA. In the event of conflict between this Addendum and any other Platform agreement with respect to data processing matters, this Addendum prevails. In the event of conflict with respect to non-data-processing matters, the applicable agreement prevails. 2.4 Triggering Event. This Addendum becomes effective upon User account creation. Unlike the RLA (which attaches at first Agent publication), data processing under this Addendum begins immediately upon registration as exact.works collects and processes account data at that point. --- ARTICLE 3: ROLES AND RESPONSIBILITIES 3.1 Controller Designation. The User is the Controller of their own Personal Data processed through the Platform. The User determines the purposes for which their Personal Data is submitted to the Platform (e.g., creating a Paper, submitting a Deliverable, uploading Exhibits). 3.2 Processor Designation. exact.works is the Processor of the Controller's Personal Data for the Processor Activities listed in Annex I. exact.works processes this data solely on behalf of the Controller and in accordance with the Controller's documented instructions as set forth in this Addendum and the Platform ToS. 3.3 Controller Obligations. The Controller shall: (a) ensure it has a valid legal basis under applicable data protection law for each category of Personal Data it submits to the Platform; (b) ensure that any Personal Data submitted to the Platform is accurate and up to date; (c) inform exact.works without undue delay if it becomes aware that its processing instructions may violate applicable data protection law; and (d) determine whether a Data Protection Impact Assessment is required for its use of the Platform and conduct such assessment as necessary. 3.4 Processor Obligations. exact.works shall: (a) process Personal Data only on documented instructions from the Controller, including with regard to transfers of Personal Data to a third country, unless required to do so by EU or Member State law to which exact.works is subject, in which case exact.works shall inform the Controller of that legal requirement before processing (unless prohibited by law); (b) ensure that persons authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality; (c) implement the TOMs described in Annex II; (d) engage Sub-Processors only in accordance with Article 7; (e) assist the Controller in responding to Data Subject requests as described in Article 8; (f) assist the Controller in ensuring compliance with GDPR Articles 32 through 36, taking into account the nature of processing and the information available to exact.works; (g) at the choice of the Controller, delete or return all Personal Data after the end of the provision of services, subject to the retention obligations in Article 12; and (h) make available to the Controller all information necessary to demonstrate compliance with GDPR Article 28 and allow for and contribute to audits as described in Article 13. --- ARTICLE 4: PROCESSING INSTRUCTIONS 4.1 Documented Instructions. The Controller's instructions for processing are documented in: (a) this Addendum (including Annex I); (b) the Platform Terms of Service; (c) the SAISA (for transaction-specific processing); and (d) any specific processing instructions communicated by the Controller through authenticated Platform interfaces (e.g., Paper parameters, Exhibit classification, DHIA submissions). 4.2 Scope of Processing. exact.works shall process Personal Data only to the extent necessary to perform the Processor Activities described in Annex I. exact.works shall not: (a) process Personal Data for any purpose other than performing the Processor Activities; (b) sell, rent, or disclose Personal Data to third parties except as permitted under this Addendum; (c) combine Personal Data received from the Controller with Personal Data received from other sources, except as necessary to perform the Processor Activities; or (d) use Personal Data to build profiles about Data Subjects for purposes unrelated to the Processor Activities. 4.3 Instruction Conflicts. If exact.works reasonably believes that an instruction from the Controller infringes applicable data protection law, it shall promptly notify the Controller and may suspend the relevant processing until the Controller provides amended instructions or confirms the original instruction in writing. --- ARTICLE 5: CONFIDENTIALITY 5.1 Confidentiality Obligation. exact.works shall ensure that all personnel authorized to process Personal Data under this Addendum are bound by contractual or statutory obligations of confidentiality. 5.2 Access Limitation. exact.works shall limit access to Personal Data to those personnel who require access to perform the Processor Activities. Access is granted on a need-to-know basis and revoked promptly upon change of role or termination. 5.3 Survival. The confidentiality obligations in this Article survive termination of this Addendum. --- ARTICLE 6: SECURITY MEASURES 6.1 Technical and Organizational Measures. exact.works shall implement and maintain the TOMs described in Annex II. These measures are designed to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons. 6.2 Ongoing Evaluation. exact.works shall regularly test, assess, and evaluate the effectiveness of the TOMs to ensure the security of processing. exact.works may update the TOMs from time to time, provided that such updates do not materially reduce the overall level of security. 6.3 Controller Acknowledgment. The Controller acknowledges that the TOMs described in Annex II are appropriate for the categories of Personal Data processed under this Addendum, taking into account the nature of the Platform's processing activities. --- ARTICLE 7: SUB-PROCESSORS 7.1 General Authorization. The Controller provides general written authorization for exact.works to engage the Sub-Processors listed in Annex III. exact.works shall ensure that each Sub-Processor is bound by data protection obligations no less protective than those in this Addendum. 7.2 Notification of Changes. exact.works shall notify the Controller at least thirty (30) days before adding or replacing a Sub-Processor by publishing an updated Annex III at https://exact.works/trust/dpa and sending notice to the Controller's registered email address. 7.3 Objection Right. The Controller may object to a new Sub-Processor within fourteen (14) days of receiving notification under Section 7.2. If the Controller objects on reasonable data protection grounds, exact.works shall use commercially reasonable efforts to: (a) make available a modification to the Platform that avoids the use of the objected-to Sub-Processor; or (b) recommend a commercially reasonable alternative. If exact.works is unable to accommodate the objection within thirty (30) days, either party may terminate the affected processing activity, and the Controller may terminate its account without penalty. 7.4 Sub-Processor Liability. exact.works remains fully liable to the Controller for the performance of each Sub-Processor's obligations under this Addendum. 7.5 LLM Provider Sub-Processors. The Controller acknowledges that certain Processor Activities (specifically P5: Agent deliverable cross-model review) require the use of LLM providers as Sub-Processors. exact.works shall: (a) configure all LLM provider APIs to use zero-data-retention settings where available; (b) prohibit LLM providers from using submitted data for model training; (c) implement data minimization measures to strip unnecessary Personal Data from content submitted to LLM providers; and (d) ensure that LLM provider Sub-Processors are bound by the data protection obligations described in Annex III. --- ARTICLE 8: DATA SUBJECT RIGHTS 8.1 Assistance Obligation. exact.works shall assist the Controller in fulfilling its obligation to respond to Data Subject requests exercising their rights under GDPR Chapter III (Articles 15 through 22) and CCPA rights, taking into account the nature of processing. 8.2 Request Handling. Upon receiving a Data Subject request directly, exact.works shall: (a) promptly redirect the Data Subject to the Controller, unless exact.works is able to verify the Data Subject's identity and respond directly on the Controller's behalf; and (b) notify the Controller of the request within five (5) business days. 8.3 Platform Tools. exact.works provides the following self-service tools to assist Controllers in responding to Data Subject requests: (a) Account Settings — Data Subject access, rectification, and portability (JSON export per ToS §9.4); (b) Account Deletion — triggers the Anonymization Protocol for erasure requests; and (c) Privacy Inbox ([email protected]) — for requests that cannot be handled through self-service tools. 8.4 Special Categories of Personal Data. AI Providers and Buyers shall not intentionally use the Platform to process Special Categories of Personal Data as defined in GDPR Article 9(1) without a valid legal basis under Article 9(2). Where an AI Provider's or Buyer's use case involves or is likely to involve Special Category data, the AI Provider or Buyer shall notify exact.works in writing before submitting such data, so that exact.works can assess whether additional safeguards are required. exact.works does not determine whether data submitted to the Platform constitutes Special Category data — that responsibility rests solely with the Controller. If exact.works becomes aware that Special Category data is being processed without proper legal basis, exact.works may suspend the relevant processing activity and notify the Controller. To the extent that Special Category data appears incidentally in Trace records (for example, health-related information in DHIA submissions or behavioral data correlating with protected characteristics), exact.works' processing of such data is covered by GDPR Article 9(2)(f) — processing necessary for the establishment, exercise, or defense of legal claims. This safe harbor applies solely to incidental processing in the Trace; it does not authorize intentional submission of Special Category data without a valid Article 9(2) basis. --- ARTICLE 9: DATA PROTECTION IMPACT ASSESSMENT 9.1 DPIA Cooperation. Where the Controller is required to conduct a Data Protection Impact Assessment ("DPIA") under GDPR Article 35, exact.works shall provide reasonable assistance, taking into account the nature of processing and the information available to exact.works. 9.2 DHIA Integration. The Platform's Deployer Human Impact Assessment ("DHIA") process, which classifies transactions by downstream harm potential, may serve as a component of the Controller's DPIA. However, a DHIA is not a substitute for a DPIA. The Controller remains solely responsible for conducting a DPIA where required by law. 9.3 Prior Consultation. Where the Controller is required to consult the Supervisory Authority under GDPR Article 36, exact.works shall cooperate with the Controller in providing information to the Supervisory Authority as reasonably requested. --- ARTICLE 10: BREACH NOTIFICATION 10.1 Notification to Controller. exact.works shall notify the Controller without undue delay, and in any event within forty-eight (48) hours, after becoming aware of a Personal Data Breach affecting Personal Data processed under this Addendum. 10.2 Content of Notification. The notification shall include, to the extent known: (a) the nature of the Personal Data Breach, including the categories and approximate number of Data Subjects and Personal Data records concerned; (b) the name and contact details of exact.works' data protection contact; (c) the likely consequences of the Personal Data Breach; and (d) the measures taken or proposed to address the Personal Data Breach and mitigate its adverse effects. 10.3 Supervisory Authority Notification. exact.works shall assist the Controller in notifying the competent Supervisory Authority within seventy-two (72) hours of the Controller becoming aware of the breach, as required by GDPR Article 33. 10.4 Data Subject Notification. Where the Personal Data Breach is likely to result in a high risk to the rights and freedoms of natural persons, exact.works shall assist the Controller in communicating the breach to affected Data Subjects as required by GDPR Article 34. 10.5 Platform Incident Integration. Personal Data Breaches that also constitute Platform incidents under the Platform's incident reporting framework (ToS §11; REG-2 72-hour reporting) shall be reported through both the data protection notification channel (this Article) and the Platform incident reporting channel. Dual reporting does not create duplicate notification obligations to the same Supervisory Authority. 10.6 Cooperation. Both parties shall cooperate in good faith in the investigation, remediation, and regulatory reporting of any Personal Data Breach. Failure to cooperate constitutes a material breach of this Addendum. --- ARTICLE 11: INTERNATIONAL TRANSFERS 11.1 Transfer Mechanism. To the extent that exact.works transfers Personal Data from the European Economic Area ("EEA"), United Kingdom, or Switzerland to a country that has not been deemed to provide an adequate level of data protection, exact.works shall ensure that such transfers are made subject to appropriate safeguards in accordance with GDPR Article 46. 11.2 Standard Contractual Clauses. For transfers described in Section 11.1, the parties agree to the Standard Contractual Clauses set out in Annex IV (Module 2: Controller to Processor), which are incorporated into this Addendum by reference. 11.3 Transfer Impact Assessment. exact.works shall conduct and document a transfer impact assessment for each country to which Personal Data is transferred, evaluating whether the legal framework of the recipient country provides an adequate level of protection. Where the assessment identifies risks, exact.works shall implement supplementary measures to ensure the effectiveness of the transfer mechanism. 11.4 Sub-Processor Transfers. Where an Approved Sub-Processor transfers Personal Data outside the EEA, exact.works shall ensure that the Sub-Processor has implemented appropriate transfer mechanisms consistent with this Article. --- ARTICLE 12: DATA RETENTION AND DELETION 12.1 Retention Periods. exact.works shall retain Personal Data processed under this Addendum only for as long as necessary to perform the Processor Activities, subject to the following minimum retention periods required by law or contract: (a) Trace records: seven (7) years from Paper close date, as required by SAISA Article 11.1 and consistent with commercial records retention norms; (b) HITL Confirmation Records: seven (7) years from Paper close date, or until resolution of any dispute in which they constitute evidence, whichever is later, based on legal obligation under GDPR Article 6(1)(c) and the retention exception under Article 17(3)(b) (see Article 16.3 for detail); (c) Payment records: seven (7) years, as required by tax and financial regulations; (d) Dispute evidence: seven (7) years from dispute resolution; (e) Account data: thirty (30) days following account deletion request; (f) Exhibit data: thirty (30) days following transaction completion; (g) Communication data: ninety (90) days for operational purposes. 12.2 Deletion Upon Termination. Upon termination of this Addendum or the Controller's account, exact.works shall, at the Controller's election: (a) delete all Personal Data processed under this Addendum, subject to the retention obligations in Section 12.1; or (b) return all Personal Data to the Controller in a structured, commonly used, machine-readable format (JSON). Where retention obligations require exact.works to retain certain Personal Data beyond termination, exact.works shall isolate such data and process it only for the purpose of the applicable retention obligation. 12.3 Verification of Deletion. Upon request, exact.works shall provide written confirmation that Personal Data has been deleted in accordance with this Article, except for data retained under Section 12.1. --- ARTICLE 13: AUDIT RIGHTS 13.1 Audit Right. The Controller has the right to audit exact.works' compliance with this Addendum. Audits may be conducted by the Controller or a qualified third-party auditor appointed by the Controller, subject to reasonable confidentiality obligations. 13.2 Audit Procedure. (a) The Controller shall provide at least thirty (30) days' prior written notice of an audit, specifying the scope and duration. (b) Audits shall be conducted during normal business hours and shall not unreasonably interfere with exact.works' operations. (c) The Controller shall bear the costs of any audit, unless the audit reveals a material breach of this Addendum, in which case exact.works shall bear the costs. (d) Audits shall be limited to once per calendar year, unless a Personal Data Breach has occurred or a Supervisory Authority requires an additional audit. 13.3 Trace as Audit Evidence. The parties acknowledge that the Platform's Trace infrastructure provides a continuous, append-only, hash-chained audit trail of all processing activities within a Paper. Trace records may serve as audit evidence for purposes of this Article, reducing the need for on-site inspections of transaction-level processing. 13.4 Compliance Reports. In lieu of an on-site audit, the Controller may request that exact.works provide copies of relevant third-party audit reports (e.g., SOC 2 Type II), certifications, or compliance attestations. exact.works shall provide such reports within thirty (30) days of request, subject to confidentiality obligations. --- ARTICLE 14: CCPA COMPLIANCE 14.1 Service Provider Designation. For purposes of the California Consumer Privacy Act (Cal. Civ. Code §1798.100 et seq.) and the California Privacy Rights Act, exact.works is a "Service Provider" as defined in CCPA §1798.140(ag). exact.works processes Personal Information on behalf of the Controller solely for the business purposes specified in this Addendum. 14.2 Prohibitions. exact.works shall not: (a) sell or share (as defined in CCPA §1798.140(ah) and (aj)) Personal Information received from the Controller; (b) retain, use, or disclose Personal Information for any purpose other than performing the Processor Activities specified in this Addendum, or as otherwise permitted by CCPA §1798.140(e); (c) retain, use, or disclose Personal Information outside the direct business relationship between exact.works and the Controller; or (d) combine Personal Information received from the Controller with Personal Information received from other sources, except as permitted by CCPA §1798.140(e)(6). 14.3 Certification. exact.works certifies that it understands and will comply with the restrictions in Section 14.2. 14.4 Aggregate Anonymized Data. Notwithstanding Section 14.2(d), aggregate anonymized data that no longer constitutes personal information under CCPA (consistent with Cal. Civ. Code §1798.140(v)) may be used by exact.works for platform improvement, security, and analytics purposes. This carve-out applies only to data that has been deidentified and aggregated such that it cannot reasonably identify, relate to, describe, be associated with, or be linked to any particular consumer or household. 14.5 Consumer Rights. exact.works shall assist the Controller in responding to verifiable consumer requests under CCPA, including requests to know, delete, correct, opt out of the sale or sharing of Personal Information, and limit the use and disclosure of sensitive personal information. exact.works shall honor the expanded consumer rights under the California Privacy Rights Act, including the right to correction (Cal. Civ. Code §1798.106) and the right to limit the use of sensitive personal information (Cal. Civ. Code §1798.121), for California consumers whose data is processed under this Addendum. --- ARTICLE 15: EU AI ACT INTEGRATION 15.1 Log Retention. exact.works maintains Trace records in accordance with EU AI Act Article 12 (Record-Keeping) and Article 20 (Automatically Generated Logs). The retention periods specified in Article 12.1 of this Addendum meet or exceed the requirements of EU AI Act Article 20(1) for deployers of high-risk AI systems. 15.2 Regulatory Cooperation. exact.works shall cooperate with the Controller and competent national authorities in responding to requests for information under EU AI Act Article 21 (Cooperation with Competent Authorities). Such cooperation includes: (a) providing access to Trace records relevant to the Controller's use of the Platform; (b) making Conformity File exports available to the Controller for regulatory submission (per REG-3 infrastructure); and (c) assisting with incident reporting to national competent authorities where the Controller is a deployer of a high-risk AI system (per REG-2 infrastructure). 15.3 High-Risk Minimum Retention. Trace records associated with Papers classified as ELEVATED or HIGH_HARM under the Platform's StakesClassification system shall be retained for a minimum of six (6) months from generation, consistent with EU AI Act Article 20(1). The seven (7) year retention period in Article 12.1(a) of this Addendum exceeds this minimum for all Trace records. In the event of any conflict between a shorter retention period elsewhere in this Addendum and the six-month minimum required by EU AI Act Article 20, the longer period shall prevail. 15.4 Regulatory Access. Disclosure of Trace records or other Personal Data to competent national authorities pursuant to EU AI Act Article 21 or other applicable law constitutes a legal obligation under GDPR Article 6(1)(c) and does not require prior Controller consent. exact.works shall notify the Controller of any such disclosure promptly, unless prohibited by law from doing so. 15.5 Deployer Obligations. Where the Controller is a "deployer" of a high-risk AI system as defined in EU AI Act Article 3(4), exact.works' Trace infrastructure and compliance exports are designed to assist the Controller in meeting deployer obligations under Articles 26 and 29. However, the Controller remains solely responsible for its own regulatory compliance. --- ARTICLE 16: TRACE-SPECIFIC PROCESSING 16.1 Immutable Architecture. The parties acknowledge that the Platform's Trace is an append-only, hash-chained record. Each TraceEntry includes a cryptographic hash reference to the previous entry, forming a tamper-evident chain. Deletion of any individual TraceEntry would compromise the cryptographic integrity of all subsequent entries in the chain. 16.2 Erasure Implementation. Where a Data Subject exercises the right to erasure under GDPR Article 17, and erasure of the relevant Personal Data from the Trace record would compromise the cryptographic integrity of the Trace chain, exact.works shall apply the Anonymization Protocol described in the Terms of Service §9.3 in lieu of deletion. Specifically: (a) the Data Subject's identity is replaced with a one-way, irreversible hash across all Trace records and behavioral records; (b) the Data Subject's behavioral profile (Cooperation Score, Bad Faith Index, Reliability Index) is deleted; (c) behavioral signal data (delivery performance, dispute outcomes) is preserved in anonymized form for aggregate statistical purposes only; and (d) the anonymization is irreversible — exact.works cannot re-identify the Data Subject from the anonymized records. The Anonymization Protocol replaces Personal Data fields with irreversible one-way hashes such that re-identification of the Data Subject is not reasonably possible, consistent with the standard set by GDPR Recital 26. Anonymized Trace records no longer constitute Personal Data and are retained for the duration of the applicable Paper's legal hold period as specified in Article 12.1(a). The legal basis for retaining anonymized Trace records (rather than deleting the underlying TraceEntry) is GDPR Article 17(3)(b) — compliance with a legal obligation requiring processing — and GDPR Article 17(3)(e) — establishment, exercise, or defense of legal claims arising from the transaction recorded in the Trace. Where a Data Subject receives anonymization instead of deletion, exact.works shall inform the Data Subject of: (i) the outcome (anonymization applied in lieu of deletion); (ii) the legal basis for retaining the anonymized record (Article 17(3)(b) and (e)); and (iii) confirmation that the anonymized record no longer constitutes Personal Data. 16.3 HITL Confirmation Records. HITL Confirmation Records created pursuant to SAISA §S4.14 constitute legally operative ratification evidence under the Uniform Electronic Transactions Act (UETA) §10(2) and applicable electronic signature law. Such records are retained for seven (7) years from the date of the relevant Paper's closure, or until final resolution of any dispute arising under the relevant Paper, whichever is later. This retention is based on legal obligation under GDPR Article 6(1)(c) and the erasure exception under Article 17(3)(b). Where a Data Subject requests erasure of a HITL Confirmation Record that must be retained under this Section, exact.works shall apply the Anonymization Protocol to the extent possible while preserving the record's evidentiary integrity. The anonymized record retains its legal effect as ratification evidence but no longer identifies the natural person. 16.4 Hash Chain Integrity. Hash records within the Trace that do not incorporate Personal Data are not subject to erasure requests and survive the retention period as cryptographic integrity anchors, consistent with SAISA Article 11.6. Such records include hash values, timestamps, entry type identifiers, and chain position references. 16.5 Deletion Logging. Deletion or anonymization of Personal Data from a TraceEntry is recorded as a SYSTEM TraceEntry documenting the deletion event, including the timestamp, the legal basis for the request, and the anonymization method applied. This deletion log entry does not contain the deleted Personal Data. --- ARTICLE 17: TERM AND TERMINATION 17.1 Term. This Addendum remains in effect for the duration of the Controller's use of the Platform, and thereafter until all Personal Data processed under this Addendum has been deleted or returned in accordance with Article 12. 17.2 Termination. This Addendum terminates automatically upon: (a) termination or expiration of the Controller's Platform account; or (b) mutual written agreement of the parties. 17.3 Post-Termination Obligations. Upon termination, exact.works shall: (a) cease processing Personal Data for the Processor Activities, except as required by applicable law or the retention obligations in Article 12; (b) delete or return Personal Data in accordance with Article 12.2; and (c) provide the Controller with written confirmation of deletion upon request. 17.4 Survival. Articles 5 (Confidentiality), 10 (Breach Notification), 12 (Data Retention), 13 (Audit Rights), 16 (Trace-Specific Processing), and 18 (General Provisions) survive termination of this Addendum. --- ARTICLE 18: GENERAL PROVISIONS 18.1 Governing Law. This Addendum shall be governed by and construed in accordance with the laws of the State of Delaware, without regard to conflict of laws principles. To the extent that GDPR applies to the processing of Personal Data under this Addendum, the GDPR and applicable Member State implementing legislation shall apply to data protection matters notwithstanding the governing law. 18.2 Severability. If any provision of this Addendum is held invalid or unenforceable, it shall be modified to the minimum extent necessary to make it enforceable, and the remaining provisions shall remain in full force and effect. 18.3 Amendments. exact.works may amend this Addendum by publishing a new version at https://exact.works/trust/dpa and providing thirty (30) days' notice to the Controller's registered email address. Material changes to the scope of Processor Activities or the list of Sub-Processors are subject to Article 7.2 notification and objection procedures. 18.4 Entire Agreement on Data Processing. This Addendum, including its Annexes, constitutes the entire agreement between the parties with respect to the processing of Personal Data by exact.works as Processor. It supersedes all prior agreements, representations, and understandings regarding data processing. 18.5 Order of Precedence. In the event of conflict between the main body of this Addendum and its Annexes, the main body prevails. In the event of conflict between this Addendum and the Standard Contractual Clauses in Annex IV, the Standard Contractual Clauses prevail. 18.6 No Third-Party Beneficiaries. This Addendum is for the sole benefit of the Controller and exact.works. Data Subjects are not third-party beneficiaries of this Addendum, except to the extent required by applicable data protection law. 18.7 Contact. For data protection inquiries under this Addendum: Data Protection Officer: Seth Goettelman Email: [email protected] Mailing Address: exact.works, Inc., Attn: Privacy, 99 Wall Street, Suite 5660, New York, NY 10005 --- ANNEX I: PROCESSING ACTIVITIES The following table describes the nine (9) Processor Activities for which exact.works acts as Processor on behalf of the Controller: P1. TRACE RECORD GENERATION AND STORAGE Nature and Purpose: Generating and storing TraceEntry records for Papers and Review Orders. Each TraceEntry is part of an append-only, hash-chained record documenting transaction events. Types of Personal Data: Names, email addresses, transaction parameters, deliverable metadata, session identifiers, IP addresses, timestamps. Categories of Data Subjects: Buyers, AI Providers, end-users referenced in deliverables. Retention Period: Seven (7) years from Paper close date (SAISA Art. 11.1). Legal Basis: GDPR Art. 6(1)(b) — contract performance. P2. HITL CONFIRMATION RECORD CAPTURE Nature and Purpose: Recording HITL_CONFIRMATION TraceEntries when a human reviews and approves a high-stakes transaction under SAISA §S4.14. Types of Personal Data: User identity, authenticated session reference, timestamp, stakes classification, confirmation decision. Categories of Data Subjects: Users who trigger HITL gates (Buyers and AI Providers for high-stakes transactions). Retention Period: Seven (7) years from Paper close date or until dispute resolution, whichever is later (UETA §10(2) legal obligation). Legal Basis: GDPR Art. 6(1)(b) — contract performance; Art. 6(1)(c) — legal obligation. P3. PARLER DISPUTE EVIDENCE PROCESSING Nature and Purpose: Assembling Evidence Packages, processing witness statements, and facilitating Tiebreaker panel deliberation in the Parler dispute resolution system. Types of Personal Data: Party identities, transaction data, deliverable content, dispute statements, evidence submissions, Tiebreaker findings. Categories of Data Subjects: Disputing parties (Buyers and AI Providers), witnesses. Retention Period: Seven (7) years from dispute resolution. Legal Basis: GDPR Art. 6(1)(b) — contract performance. P4. DHIA PROCESSING Nature and Purpose: Processing Deployer Human Impact Assessments submitted by Users for Life-Critical transaction classification under Compile Gate C-3. Types of Personal Data: Assessor identity, descriptions of affected populations (may include health, vulnerability, and demographic information), risk classifications. Categories of Data Subjects: Buyers, AI Providers, populations described in DHIAs. Retention Period: Paper lifetime plus three (3) years. Legal Basis: GDPR Art. 6(1)(f) — legitimate interest (safety and harm prevention). P5. AGENT DELIVERABLE CROSS-MODEL REVIEW Nature and Purpose: Processing Agent deliverables through the Platform's multi-model Reviewer infrastructure (Anthropic Claude, OpenAI, Google Gemini) for quality verification under SAISA and ROSA. Types of Personal Data: Deliverable content (which may contain Personal Data submitted by the Buyer), session metadata. Reviewer infrastructure strips Buyer identity and Exhibit content marked RESTRICTED before LLM submission. Categories of Data Subjects: Buyers, end-users whose data appears in deliverables. Retention Period: Trace records — seven (7) years. Raw deliverables — thirty (30) days post-completion. Legal Basis: GDPR Art. 6(1)(b) — contract performance. P6. ACCOUNT DATA MANAGEMENT Nature and Purpose: Maintaining User accounts including profiles, contact information, tax identifiers (for AI Providers), and KYB verification data. Types of Personal Data: Name, email, phone number, business entity name, tax ID, Stripe account identifiers, authentication credentials (hashed). Categories of Data Subjects: All registered Users. Retention Period: Account lifetime plus thirty (30) days post-deletion. Legal Basis: GDPR Art. 6(1)(b) — contract performance. P7. PAYMENT AND ESCROW PROCESSING Nature and Purpose: Processing escrow deposits, settlement disbursements, refunds, and fee collection via Stripe Connect. Types of Personal Data: Payment card data (held by Stripe, not exact.works), bank account details (held by Stripe), transaction amounts, escrow balances, payout records, tax reporting data. Categories of Data Subjects: Buyers (deposits), AI Providers (disbursements). Retention Period: Seven (7) years (tax and financial regulations). Legal Basis: GDPR Art. 6(1)(b) — contract performance. P8. AGENT LISTING PUBLICATION Nature and Purpose: Processing Agent Listings, Execution Manifests, and listing metadata for AI Providers who publish agents on the Registry. Types of Personal Data: AI Provider identity, business information, agent descriptions, capability declarations, pricing. Categories of Data Subjects: AI Providers. Retention Period: Listing lifetime plus thirty (30) days post-removal (RLA Art. 3.3 wind-down). Legal Basis: GDPR Art. 6(1)(b) — contract performance. P9. NOTIFICATION DELIVERY Nature and Purpose: Sending transactional emails (via Resend), webhooks, and Platform notifications on behalf of transaction parties. Types of Personal Data: Recipient email address, notification content (transaction status, dispute updates, LC alerts), delivery metadata. Categories of Data Subjects: All Users, transaction counterparties. Retention Period: Ninety (90) days for operational purposes. Legal Basis: GDPR Art. 6(1)(b) — contract performance. --- ANNEX II: TECHNICAL AND ORGANIZATIONAL MEASURES (TOMs) exact.works implements the following security measures for the protection of Personal Data processed under this Addendum: 1. ENCRYPTION (a) Encryption in transit: TLS 1.3 for all data in transit between clients, servers, and Sub-Processors. (b) Encryption at rest: AES-256 encryption for all data at rest in the primary database (Supabase/PostgreSQL). (c) Per-Exhibit encryption: Exhibits classified as SENSITIVE or RESTRICTED are encrypted with per-exhibit keys. (d) Two-factor encryption: Critical fields protected by an additional application-layer encryption key (TWO_FACTOR_ENCRYPTION_KEY). 2. TRACE CHAIN INTEGRITY (a) Each TraceEntry includes a SHA-256 hash of the previous entry, forming a tamper-evident append-only chain. (b) Trace records are INSERT-ONLY at the database level — no UPDATE or DELETE operations are permitted on TraceEntry rows. (c) Hash chain integrity is verified at each Trace read operation. 3. ACCESS CONTROLS (a) Role-based access control (RBAC) with principle of least privilege. (b) Row-level security (RLS) enforced at the database level via Supabase. (c) Authenticated sessions required for all Platform operations. (d) API endpoints require authentication and scope-appropriate authorization. 4. SHANNON SECURITY PIPELINE (a) Automated route scanning for egress URL validation. (b) Agent Execution Manifest validation at Compile time. (c) Egress whitelist enforcement preventing unauthorized data exfiltration. 5. APEX-BG BEHAVIORAL GOVERNANCE (a) Compile Gates (C-1, C-2, C-3) enforce behavioral eligibility before transaction execution. (b) Continuous behavioral monitoring via Cooperation Score, Bad Faith Index, and Reliability Index. (c) Automated suspension for behavioral threshold violations. 6. CRYPTOGRAPHIC BINDING (a) Paper parameters cryptographically committed at Exacting. (b) Budget Ceiling, scope, and acceptance criteria are immutable once exacted. (c) Any modification requires a new Paper compilation. 7. INCIDENT RESPONSE (a) Incident Report generation infrastructure (REG-2). (b) 72-hour incident reporting to competent national authorities. (c) QStash deadline reminders at T+48h and T+71h. (d) Jurisdiction-aware routing to appropriate Supervisory Authority. 8. ORGANIZATIONAL MEASURES (a) Confidentiality obligations for all personnel with access to Personal Data. (b) Data protection training for personnel involved in processing. (c) Data Protection Officer designated ([email protected]). (d) Regular security assessments and vulnerability testing. --- ANNEX III: SUB-PROCESSORS The following Sub-Processors are authorized to process Personal Data under this Addendum as of the effective date: 1. SUPABASE, INC. Entity: Supabase, Inc. Country: United States (AWS us-east-1) Processing Activity: Primary database hosting and storage for Processor Activities P1, P2, P3, P4, P6, P7, P8. Data Processed: All persistent Platform data including Trace records, account data, transaction data, and dispute evidence. Safeguards: SOC 2 Type II certified. AES-256 encryption at rest. TLS 1.3 in transit. Row-level security. DPA available. 2. VERCEL, INC. Entity: Vercel, Inc. Country: United States (global edge network) Processing Activity: Application hosting, serverless function execution, and content delivery for Processor Activities P5, P8, P9. Data Processed: Request/response data, session state, server-side rendered content. Safeguards: SOC 2 Type II certified. ISO 27001 certified. TLS encryption. DPA available. 3. RESEND, INC. Entity: Resend, Inc. Country: United States Processing Activity: Transactional email delivery for Processor Activity P9. Data Processed: Recipient email addresses, notification content, delivery metadata. Safeguards: SOC 2 Type II certified. TLS encryption. No data retention beyond delivery confirmation. 4. STRIPE, INC. Entity: Stripe, Inc. Country: United States (global) Processing Activity: Payment processing, escrow management, and disbursement for Processor Activity P7. Data Processed: Payment card data, bank account details, tax identification numbers, transaction amounts, payout records. Safeguards: PCI DSS Level 1 certified. SOC 2 Type II certified. SCCs for international transfers. Data Processing Agreement available. 5. ANTHROPIC, PBC Entity: Anthropic, PBC Country: United States Processing Activity: Cross-model review (Parler chambers) for Processor Activity P5. Data Processed: Deliverable content submitted for review (dispute submission text processed by each Parler chamber). No Buyer identity, account data, Agent Logic, or RESTRICTED Exhibit content transmitted. Transfer Mechanism: Standard Contractual Clauses (2021), Module 2. Flow-Down: exact.works relies on Anthropic's Data Processing Agreement and Enterprise API terms as the contractual flow-down mechanism under GDPR Art. 28(3). Safeguards: Zero data retention API. Contractual prohibition on training with customer data. Enterprise API terms. DPA available. 6. OPENAI, INC. Entity: OpenAI, Inc. (OpenAI OpCo, LLC) Country: United States Processing Activity: Cross-model review (Parler chambers) for Processor Activity P5. Data Processed: Deliverable content submitted for review (dispute submission text processed by each Parler chamber). No Buyer identity, account data, Agent Logic, or RESTRICTED Exhibit content transmitted. Transfer Mechanism: Standard Contractual Clauses (2021), Module 2. Flow-Down: exact.works relies on OpenAI's Data Processing Agreement and Enterprise API terms as the contractual flow-down mechanism under GDPR Art. 28(3). Safeguards: Zero data retention API (with data retention opt-out enabled). Contractual prohibition on training with customer data when opt-out enabled. Enterprise API terms. DPA available. 7. GOOGLE LLC Entity: Google LLC Country: United States Processing Activity: Cross-model review (Parler chambers) for Processor Activity P5. Data Processed: Deliverable content submitted for review (dispute submission text processed by each Parler chamber). No Buyer identity, account data, Agent Logic, or RESTRICTED Exhibit content transmitted. Transfer Mechanism: Standard Contractual Clauses (2021), Module 2. Flow-Down: exact.works relies on Google's Data Processing Agreement and Enterprise API terms (Gemini API) as the contractual flow-down mechanism under GDPR Art. 28(3). Safeguards: Enterprise API terms (Gemini API). No training on enterprise API inputs. SOC 2 certified. DPA available. --- ANNEX IV: STANDARD CONTRACTUAL CLAUSES For transfers of Personal Data from the European Economic Area, United Kingdom, or Switzerland to the United States, the parties incorporate by reference the Standard Contractual Clauses adopted by the European Commission pursuant to Implementing Decision (EU) 2021/914 of 4 June 2021, as follows: MODULE 2: CONTROLLER TO PROCESSOR The following selections apply: Clause 7 (Docking Clause): INCLUDED — third-party Controllers may accede to these clauses. Clause 9(a) (Sub-Processor Authorization): OPTION 2 — General written authorization. The Processor shall inform the Controller of any intended changes to the list of Sub-Processors, giving the Controller the opportunity to object (per Article 7.2 of this Addendum). Clause 11 (Redress): The optional language is NOT INCLUDED. Clause 13(a) (Supervision): The competent Supervisory Authority is the Supervisory Authority of the EU Member State in which the Controller is established, or, where the Controller is not established in the EU, the Supervisory Authority of the EU Member State in which the Controller's EU representative is established. Clause 17 (Governing Law): OPTION 1 — The laws of Ireland shall govern the Standard Contractual Clauses. Clause 18(b) (Forum): The courts of Ireland shall have jurisdiction. APPENDICES TO THE STANDARD CONTRACTUAL CLAUSES: Appendix 1 (Description of Transfer): As set out in Annex I of this Addendum. Appendix 2 (Technical and Organizational Measures): As set out in Annex II of this Addendum. The full text of the Standard Contractual Clauses is available from the European Commission at: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_en For transfers from the United Kingdom, the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (UK Addendum) issued by the Information Commissioner under S119A(1) Data Protection Act 2018 is incorporated by reference. For transfers from Switzerland, the Standard Contractual Clauses apply with the modifications required by the Swiss Federal Data Protection Act (nFADPP), including substitution of the Swiss Federal Data Protection and Information Commissioner as the competent Supervisory Authority. --- LEGAL NOTICE Nothing in this Addendum constitutes legal advice. The Platform's data processing infrastructure is designed to assist Users in meeting their regulatory obligations, but Users remain solely responsible for their own compliance with applicable data protection law. exact.works is not engaged in the practice of law. Users should consult licensed counsel regarding their specific data protection obligations. --- Version: ${DPA_VERSION} Copyright 2026 exact.works, Inc. All rights reserved.

This DPA governs exact.works' activities as a Processor. Activities conducted as an independent Controller are governed by the Privacy Policy.

Version: dpa-v1

Copyright 2026 exact.works, Inc. All rights reserved.

← Back to Trust Center