ExclusionWatch Data Processing Addendum
Version 1.0
Effective date: September 16, 2025
This Data Processing Addendum (“DPA”) forms part of the ExclusionWatch Terms of Service or other agreement governing Customer’s use of ExclusionWatch (“Agreement”) between Customer and ExclusionWatch.
1. Definitions
“Applicable Data Protection Law” means a law applicable to the processing of Customer Personal Data under the Agreement.
“Customer Personal Data” means personal information or personal data contained in Customer Data that ExclusionWatch processes on Customer’s behalf.
“Data Subject,” “personal data,” “personal information,” “process,” “processor,” “controller,” “business,” “service provider,” and “subprocessor” have the meanings given by Applicable Data Protection Law.
“Security Incident” means unauthorized access to, acquisition of, or disclosure of Customer Personal Data in ExclusionWatch’s possession or control. It does not include unsuccessful attempts that do not compromise Customer Personal Data, such as blocked scans, failed login attempts, or prevented attacks.
2. Scope and Roles
Customer determines the purposes and means of processing Customer Personal Data and acts as controller or business. ExclusionWatch acts as processor or service provider for that information.
ExclusionWatch may act as an independent controller for account administration, security, billing, legal compliance, and direct business communications as described in the Privacy Notice.
The processing details are described in Schedule 1.
3. Customer Instructions
ExclusionWatch will process Customer Personal Data:
- to provide, secure, support, and maintain the Service;
- according to Customer’s configuration and Authorized Users’ documented use;
- as described by the Agreement and this DPA; and
- as otherwise documented by Customer and accepted by ExclusionWatch.
ExclusionWatch will notify Customer if, in ExclusionWatch’s reasonable opinion, an instruction violates Applicable Data Protection Law, unless legally prohibited. ExclusionWatch may suspend the affected processing while the parties resolve the issue.
Customer will ensure its instructions are lawful and that it has provided required notices and obtained required rights and authorizations.
4. Processing Restrictions
ExclusionWatch will not:
- sell or share Customer Personal Data for cross-context behavioral advertising;
- retain, use, or disclose Customer Personal Data outside the direct business relationship except as permitted by the Agreement or law;
- combine Customer Personal Data with personal information obtained from unrelated sources except as permitted by law and necessary to provide the Service; or
- use Customer Personal Data for targeted advertising.
ExclusionWatch may use aggregated or deidentified information to operate, secure, and improve the Service if it cannot reasonably identify Customer or a Data Subject and ExclusionWatch does not attempt to reidentify it.
5. Confidentiality
ExclusionWatch will ensure that personnel authorized to process Customer Personal Data are subject to confidentiality obligations and receive privacy and security training appropriate to their responsibilities.
6. Security
ExclusionWatch will maintain reasonable administrative, technical, and physical safeguards appropriate to the nature of Customer Personal Data and processing risk. Current measures are summarized in Schedule 2.
Customer remains responsible for its endpoints, identity provider, Authorized Users, role assignments, data minimization, exports, and lawful review and use of screening results.
7. Subprocessors
Customer generally authorizes ExclusionWatch to use subprocessors to provide the Service. ExclusionWatch will:
- maintain a current subprocessor list;
- impose data-protection obligations appropriate to each subprocessor’s services;
- remain responsible for its obligations under this DPA; and
- provide at least 30 days’ advance notice of a new subprocessor that will materially process Customer Personal Data, when practicable.
Customer may object on reasonable data-protection grounds during the notice period. The parties will work in good faith on a reasonable alternative. If no alternative is reasonably available, Customer may stop the affected feature or terminate the affected Service and receive a refund of prepaid fees for the unused period.
The current subprocessor schedule appears in Schedule 3.
8. Data Subject Requests
If ExclusionWatch receives a request concerning Customer Personal Data, ExclusionWatch will direct the requester to Customer unless prohibited by law. Taking into account the nature of processing, ExclusionWatch will provide reasonable assistance through available Service functionality or other appropriate measures so Customer can respond to verified requests.
Customer is responsible for evaluating and responding to the request. ExclusionWatch may charge reasonable fees for extraordinary assistance beyond standard functionality after giving Customer advance notice.
9. Security Incidents
ExclusionWatch will notify Customer without undue delay after confirming a Security Incident affecting Customer Personal Data and, when reasonably practicable, within 72 hours after confirmation.
Notice will include available information concerning:
- the nature and approximate timing of the incident;
- affected data and Data Subjects;
- likely consequences;
- containment and remediation measures; and
- a contact for follow-up.
ExclusionWatch may provide information in phases as the investigation develops. Notice is not an admission of fault or liability. Customer is responsible for determining whether notification to individuals, regulators, or other parties is required, and ExclusionWatch will provide reasonable assistance.
10. Government Requests
Unless prohibited by law, ExclusionWatch will notify Customer of a legally binding request for Customer Personal Data. ExclusionWatch will review the request for facial validity, disclose only information legally required, and direct the requesting authority to Customer when appropriate.
11. Return and Deletion
During the subscription, Customer may use available export functions. Upon termination, Customer may request an export during the retrieval period stated in the Agreement.
After that period, ExclusionWatch will delete Customer Personal Data from active systems within a commercially reasonable period unless retention is required by law or the Agreement. Residual copies may remain in protected backups until overwritten through the ordinary backup cycle. Retained information remains protected by this DPA.
Historical screening evidence, audit records, billing records, and records needed to establish compliance may be retained for the period stated in the Agreement or retention schedule. Customer must identify any different legally required retention period before termination.
12. Assessments and Audit Information
On reasonable written request, ExclusionWatch will provide information reasonably necessary to demonstrate compliance with this DPA, such as relevant policy summaries, security documentation, subprocessor information, and available assessment results.
If that information is insufficient and Applicable Data Protection Law requires an audit, Customer may request an audit no more than once annually, except following a Security Incident or regulator request. Audits must:
- be conducted by an independent qualified auditor;
- protect other customers and ExclusionWatch confidential information;
- avoid unreasonable disruption;
- be scoped to processing under this DPA; and
- be at Customer’s expense unless the audit identifies a material breach by ExclusionWatch.
13. No PHI
Customer Personal Data must not include Protected Health Information. This DPA is not a Business Associate Agreement and does not authorize PHI processing. The ExclusionWatch No-PHI Policy is incorporated by reference.
14. Liability and Priority
The Agreement’s limitation-of-liability provisions apply to this DPA. If this DPA conflicts with the Agreement concerning processing of Customer Personal Data, this DPA controls. All other Agreement provisions remain effective.
15. Term
This DPA remains effective while ExclusionWatch processes Customer Personal Data.
Schedule 1 — Processing Details
Subject matter
Operation of a multi-tenant exclusion and sanction screening, roster management, match-review, compliance-reporting, and audit service.
Duration
The subscription term plus the retrieval, deletion, backup, and legally required retention periods.
Nature and purpose
- maintaining workforce and vendor rosters;
- comparing roster subjects with selected official-source records;
- identifying candidate matches;
- recording reviews and dispositions;
- generating reports and exports;
- administering accounts, roles, SSO, and organization settings;
- providing security, support, notifications, and audit evidence; and
- performing Customer’s documented instructions.
Categories of Data Subjects
- Customer employees, workforce members, providers, applicants, contractors, owners, and vendor representatives;
- Customer Authorized Users and administrators;
- Customer contacts; and
- individuals appearing in official public exclusion or sanction sources.
Categories of Customer Personal Data
- name, former name, date of birth, position, and employment dates;
- NPI and professional license information;
- internal workforce or vendor identifiers;
- business name, address, organization NPI, vendor type, contract dates, and optional EIN last four;
- match results, decisions, reviewer notes, and audit records;
- user identity, work contact, role, SSO, and authentication metadata; and
- import, export, support, and operational metadata.
Sensitive data
Dates of birth, account credentials, authentication metadata, and screening decisions may be sensitive. Social Security numbers, PHI, patient information, financial-account data, payment-card data, biometric data, and genetic data are prohibited.
Processing frequency
Continuous for account and roster hosting; event-driven for imports, edits, screening, review, reporting, authentication, and support; scheduled for source refreshes and automated screening.
Schedule 2 — Security Measures
ExclusionWatch maintains measures including:
Governance
- designated operational and security responsibility;
- documented access, incident-response, backup, vulnerability, and change practices;
- workforce confidentiality and security awareness;
- least-privilege administration and periodic access review; and
- vendor and subprocessor review appropriate to risk.
Identity and access
- unique user accounts;
- role-based organization access;
- required application-based multifactor authentication for local accounts;
- optional customer OIDC SSO and SSO enforcement;
- secure password hashing and recovery controls;
- security throttling for identifier, password, OTP, and signup endpoints; and
- emergency administrative access controls.
Application and infrastructure
- HTTPS/TLS for browser traffic;
- restricted secrets and certificate/key file permissions;
- tenant-aware access controls;
- database and public network segmentation;
- isolated browser-based source-fetching service without database access;
- allowlisted source-fetching destinations;
- health checks and operational monitoring;
- security headers and secure session-cookie settings; and
- dependency, static-analysis, and vulnerability review practices.
Data protection and resilience
- infrastructure storage protections;
- database backups and recovery procedures;
- source-file integrity hashes and source snapshot evidence;
- audit logging of material user and administrative actions;
- controlled export functions; and
- documented deletion and retention processes.
Incident handling
- investigation, containment, remediation, recovery, and communication procedures;
- preservation of relevant evidence; and
- post-incident review appropriate to severity.
Schedule 3 — Subprocessors
| Provider | Purpose | Processing location | Data involved |
|---|---|---|---|
| Akamai Connected Cloud / Linode | Application, database, storage, networking, and backups | United States | Customer Data hosted in the Service |
| Microsoft 365 / Microsoft Graph | Transactional email delivery | United States or contracted Microsoft region | Recipient, subject, and message contents |
| Stripe, when enabled | Payment, subscription, tax, and tax-exemption processing | Per Stripe terms | Customer contact, billing, payment, and tax information |
| Customer’s OIDC provider, such as Okta | Customer-configured authentication | Per Customer’s provider configuration | User identity and authentication assertions |
Official government-source publishers supply public records to ExclusionWatch. Customer roster data is not sent to those publishers merely to perform local matching.