# Data Processing Agreement (DPA) **Between:** - **Processor:** Niall Dunne, sole trader, trading as **exactbench** ("exactbench") - **Address:** Sweden *(full postal address provided on signed copy)* - **Contact:** niall@exactbench.com **And:** - **Controller:** \_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_ ("Customer") - **Address:** \_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_ - **Contact:** \_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_ **Effective date:** \_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_ This Data Processing Agreement ("DPA") forms part of the agreement between Customer and exactbench under which exactbench provides the exactbench service ("Services"). It governs the processing of personal data by exactbench on behalf of Customer in connection with the Services. --- ## 1. Definitions Terms not defined here have the meaning given in the EU General Data Protection Regulation 2016/679 ("GDPR"). "Personal Data", "Data Subject", "Processing", "Controller", "Processor", "Subprocessor", and "Personal Data Breach" have their GDPR meanings. --- ## 2. Roles - Customer is the **Controller** of Personal Data submitted to the Services. - exactbench is the **Processor**, processing Personal Data only on documented instructions from Customer. - The use of the Services as documented at exactbench.com constitutes Customer's documented instructions. --- ## 3. Scope and purpose of processing | Item | Description | |---|---| | **Subject matter** | Provision of the exactbench manual-Q&A service to Customer | | **Duration** | The term of the subscription, plus 30 days for deletion | | **Nature and purpose** | Ingestion, indexing, and retrieval of Customer-supplied documents; generation of answers to Customer-supplied questions, with citations | | **Types of Personal Data** | (a) Customer's named users' contact details (email, name, role); (b) any Personal Data incidentally contained in documents Customer uploads; (c) usage and feedback logs tied to users | | **Categories of Data Subjects** | Customer's employees, named contractors, and any individuals identifiable in uploaded content | Customer warrants it has the lawful basis to upload all content submitted to the Services. --- ## 4. exactbench's obligations as Processor exactbench shall: 1. Process Personal Data only on documented instructions from Customer, including with regard to international transfers (except where required by applicable law, in which case exactbench will inform Customer in advance unless prohibited). 2. Ensure that personnel authorised to process Personal Data are bound by confidentiality obligations. 3. Implement appropriate technical and organisational measures as described in **Schedule A — Security Measures**. 4. Assist Customer (taking into account the nature of processing) with: - Responding to Data Subject requests (access, rectification, erasure, restriction, portability, objection); - Demonstrating compliance with security, breach notification, and Data Protection Impact Assessment obligations under GDPR Articles 32–36. 5. Make available to Customer all information reasonably necessary to demonstrate compliance with this DPA, and allow for and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer, subject to reasonable notice and confidentiality. --- ## 5. Subprocessors 5.1 Customer authorises exactbench to engage subprocessors. The current list of subprocessors is maintained at . 5.2 exactbench shall: - Impose data protection obligations on each subprocessor that are no less protective than this DPA; - Remain fully liable to Customer for the subprocessor's performance. 5.3 exactbench shall notify Customer at least **14 days** in advance of adding or replacing a subprocessor by updating the subprocessors page and emailing Customer's notified contact. Customer may object on reasonable data protection grounds within 14 days. If exactbench cannot accommodate the objection, Customer may terminate the affected Services and receive a pro-rated refund. --- ## 6. International transfers Where exactbench transfers Personal Data outside the EU/EEA, exactbench shall ensure the transfer is covered by: - The **EU-US Data Privacy Framework** (where the receiving party is certified), and/or - The **EU Standard Contractual Clauses** (Module Two: Controller to Processor; or Module Three: Processor to Subprocessor) adopted by the European Commission, which are incorporated by reference into the relevant subprocessor agreement. For Customers requiring EU-only data residency, EU-region deployments of Pinecone and Render are available on request. --- ## 7. Personal Data Breach notification exactbench shall notify Customer of a Personal Data Breach affecting Customer's data **without undue delay** after becoming aware, and in any case within **72 hours**. The notification shall include, to the extent known: - Nature of the breach, categories and approximate number of affected Data Subjects and records; - Likely consequences; - Measures taken or proposed to address the breach. --- ## 8. Return and deletion On termination of the Services, exactbench shall, at Customer's choice: - Return all Personal Data to Customer in a structured, commonly used, machine-readable format; or - Delete all Personal Data (including from backups within the standard backup rotation, normally within 30 days). exactbench shall certify deletion in writing on request. --- ## 9. Liability The limitation of liability in the main Terms of Service applies to claims arising under this DPA. Nothing in this DPA limits a Data Subject's rights under GDPR or applicable consumer law. --- ## 10. Governing law This DPA is governed by the laws of **Sweden**. The Standard Contractual Clauses, where incorporated, are governed as set out in those Clauses. --- ## 11. Order of precedence In the event of conflict between this DPA and the main Terms of Service, **this DPA prevails** in matters of data protection. The Standard Contractual Clauses prevail over both in matters they govern. --- ## Schedule A — Security Measures exactbench implements the following technical and organisational measures: **Encryption** - TLS 1.2+ for all data in transit - Encryption at rest for the PostgreSQL database (managed by Render) - Access keys stored as hashes, not plaintext **Access control** - Role-based access; only Niall Dunne has administrative access to production systems - Multi-factor authentication on the GitHub repository, Render dashboard, OpenAI and Pinecone accounts - Periodic review of access **Data segregation** - Each Customer's vectors namespaced separately in Pinecone - Customer manuals stored under per-customer scoping in PostgreSQL **Logging and monitoring** - Application and access logs retained for 30 days - Alerts on authentication anomalies and error spikes **Backup and recovery** - Managed PostgreSQL daily backups with 7-day retention (Render) - Documented restore procedure **Incident response** - Breach detection and notification procedures (see Section 7) - Post-incident review on every confirmed incident **Vendor security** - All subprocessors selected for documented security practices and signed DPAs - Annual review of subprocessor security posture **Personnel** - Confidentiality obligations on any contractors granted access (currently none) - Security training for any future hires --- ## Signed for and on behalf of Customer Name: \_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_ Title: \_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_ Date: \_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_ Signature: \_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_ --- ## Signed for exactbench Name: Niall Dunne Title: Sole trader, trading as exactbench Date: \_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_ Signature: \_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_ --- *Version 1.0 · 26 May 2026 · This template is a working draft. For high-value enterprise pilots, have your or our legal counsel review before signing.*