Knowledge ERP Data Processing Addendum
Effective Date: August 5, 2026 Last Updated: August 5, 2026
1. Background and Scope
This Data Processing Addendum ("DPA") supplements and forms part of the Knowledge ERP Terms of Service (the "Agreement") between Pelton Solutions LLC d/b/a Knowledge ERP ("Knowledge ERP") and the customer that has accepted the Agreement ("Customer," "you"). It applies where Knowledge ERP processes Customer Business Data (defined below) on your behalf in providing the Service.
This DPA governs only Knowledge ERP's processing of personal information contained in the business records that you and your Authorized Users put into the platform — information about your customers, vendors, contacts, borrowers, appointment bookers, survey respondents, and email correspondents. For that data, you are the Business / Controller and Knowledge ERP is the Service Provider / Processor.
This DPA does not apply to personal information for which Knowledge ERP is itself the business/controller — your account, Authorized User, and billing information — which is governed by the Knowledge ERP Privacy Policy.
If you accept the Agreement and use the Service to Process personal information of your Business Contacts, this DPA is incorporated into the Agreement. Where a separate signed DPA is required, the signature block in Section 14 applies.
2. Definitions
Capitalized terms not defined here have the meaning given in the Agreement.
- "Applicable Privacy Laws" means U.S. state privacy laws applicable to the processing under this DPA, including the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), and the comparable laws of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states with similar laws, as each is in effect and applicable.
- "Business," "Controller," "Service Provider," "Processor," "Consumer," "Sell," "Share," "Personal Information," and "Process" have the meanings given under Applicable Privacy Laws. "Business" and "Controller" are used interchangeably for Customer; "Service Provider" and "Processor" are used interchangeably for Knowledge ERP.
- "Business Contact" means a person whose Personal Information you or your Authorized Users enter into, upload to, or cause to be collected by the Service, including your customers, customer and vendor contacts, borrowers, and equipment renters; members of the public who book appointments or answer questionnaires or surveys through your forms; and the correspondents in email messages synced from a mailbox you connect.
- "Customer Business Data" means Personal Information of Business Contacts that Knowledge ERP Processes on your behalf in providing the Service, as described in Annex 1.
- "Sub-Processor" means a third party engaged by Knowledge ERP to Process Customer Business Data. The current Sub-Processors are listed in the Knowledge ERP Sub-Processor List. Third-party services that you connect to your account (Section 7.4) are not Sub-Processors.
- "Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Business Data Processed by Knowledge ERP.
3. Roles and Instructions
3.1 As between the parties, you are the Business/Controller and determine the purposes and means of Processing Customer Business Data, and Knowledge ERP is the Service Provider/Processor acting on your behalf.
3.2 Knowledge ERP will Process Customer Business Data only (a) to provide, maintain, secure, and support the Service in accordance with the Agreement; (b) in accordance with your documented lawful instructions (which include the Agreement, this DPA, and your configuration and use of the Service — including the integrations you connect, the automations you enable, and the fields you define); and (c) as otherwise required by applicable law, in which case Knowledge ERP will inform you of that requirement unless legally prohibited.
3.3 You are responsible for the lawfulness of Customer Business Data and of your collection of it, including providing any required privacy notice to, and obtaining any required consent from, your Business Contacts — including individuals who submit information through your public booking, questionnaire, and survey forms, individuals whose email messages are synced from a mailbox you connect, and recipients of email and SMS messages you send or trigger through the Service — and for ensuring you have the right to transfer Customer Business Data to Knowledge ERP for Processing under this DPA.
3.4 Tenant-directed disclosures. When you connect a third-party integration (for example QuickBooks Online, Shopify, WooCommerce, ShipStation, Gmail, Microsoft Outlook, Twilio, or your own Stripe or Square account), configure an outbound webhook, or grant API access, you instruct Knowledge ERP to disclose Customer Business Data to that destination on your behalf. Those disclosures are made at your direction, the recipient's own terms and privacy practices govern its handling of the data, and you are responsible for the destination — including any URL you nominate for an outbound webhook. See Section 7.4 and Annex 1.
4. Service Provider / Processor Obligations and Certification
Knowledge ERP certifies that it understands and will comply with the restrictions in this Section. With respect to Customer Business Data, Knowledge ERP will:
- (a) Process it only on your behalf and for the limited and specified purpose of providing the Service (the "Business Purpose"), and not for any other purpose;
- (b) not Sell and not Share Customer Business Data;
- (c) not retain, use, or disclose Customer Business Data for any purpose other than the Business Purpose, including not for any commercial purpose other than providing the Service, except as permitted by Applicable Privacy Laws;
- (d) not retain, use, or disclose Customer Business Data outside the direct business relationship between you and Knowledge ERP;
- (e) not combine Customer Business Data with personal information it receives from, or on behalf of, another person, or collects from its own interactions with the Consumer, except as permitted by Applicable Privacy Laws to perform the Service;
- (f) provide the same level of privacy protection as is required of businesses under Applicable Privacy Laws;
- (g) notify you promptly if it makes a determination that it can no longer meet its obligations under Applicable Privacy Laws; and
- (h) comply with applicable obligations under Applicable Privacy Laws and provide reasonable assistance to enable your compliance, as further described below.
You may take reasonable and appropriate steps to help ensure that Knowledge ERP uses Customer Business Data in a manner consistent with your obligations under Applicable Privacy Laws, and to stop and remediate any unauthorized use, as described in Section 10 (Audits).
5. Confidentiality
Knowledge ERP will ensure that personnel authorized to Process Customer Business Data are subject to a duty of confidentiality and Process the data only as necessary to provide the Service. Pelton Solutions staff access to tenant data is limited to the least access necessary for support, maintenance, and security purposes, and administrative access is logged.
Customer approval. Staff access to Customer Business Data through the Service's administrative interface additionally requires your approval, granted by one of your users holding account-administration permission, for a duration that user chooses, revocable by you at any time, and expiring automatically. The exception is emergency access taken by a senior engineer to restore a materially impaired or inoperable Service where your administrators cannot respond; that access is notified to your administrators by email when it occurs, identified as emergency access in the record available to you, time-limited, and revocable by you. This is described in full in the Privacy Policy (Section 7.3) and Section 8.6 of the Terms of Service. It governs the administrative interface and does not limit Processing performed by the Service itself, access by personnel administering the underlying infrastructure, or Knowledge ERP's rights under Sections 8.5 and 17 of the Terms of Service.
6. Security
Knowledge ERP will implement and maintain reasonable and appropriate administrative, technical, and physical safeguards designed to protect Customer Business Data, as described in Annex 2 and in the Privacy Policy (Security). Knowledge ERP may update its security measures from time to time provided that the updates do not materially reduce the overall level of protection.
7. Sub-Processors
7.1 You authorize Knowledge ERP to engage the Sub-Processors listed in the Knowledge ERP Sub-Processor List to Process Customer Business Data in connection with the Service.
7.2 Knowledge ERP will impose on each Sub-Processor data-protection obligations that are substantially consistent with those in this DPA, to the extent applicable to the nature of the Sub-Processor's services, and Knowledge ERP remains responsible to you for each Sub-Processor's performance of its obligations.
7.3 Knowledge ERP will maintain the Sub-Processor List and will provide notice (by updating the list and/or by email or in-product notice) before adding a new Sub-Processor that Processes Customer Business Data. If you reasonably object to a new Sub-Processor on data-protection grounds, you may notify Knowledge ERP within the notice period stated on the list (or, if none is stated, within fourteen (14) days); the parties will work in good faith to address the objection, and if they cannot, your sole remedy is to stop using the affected feature or to terminate the affected Service.
7.4 Integrations you connect are not Sub-Processors. Third-party services that you choose to connect to your account, outbound webhook destinations you configure, and API clients you authorize receive Customer Business Data as tenant-directed disclosures under Section 3.4, not as Sub-Processors engaged by Knowledge ERP. Knowledge ERP does not impose data-protection terms on those recipients, and disconnecting the integration stops future disclosures but does not retrieve data already transmitted.
8. Assistance — Consumer Requests and Compliance
8.1 Consumer rights requests. Taking into account the nature of the Processing, Knowledge ERP will provide reasonable assistance through appropriate technical and organizational measures (including the search, edit, export, and deletion features of the Service, which allow you to locate, correct, and delete a Business Contact's records yourself) to help you respond to verifiable requests from Business Contacts to exercise their rights under Applicable Privacy Laws (such as access, deletion, correction, portability, and opt-out). If Knowledge ERP receives such a request directly from a Business Contact relating to data Processed on your behalf, Knowledge ERP will, where lawful, forward it to you or instruct the individual to contact you, and will not respond on your behalf except on your instruction or as legally required. Requests requiring Knowledge ERP's assistance may be sent to legal@peltonsolutions.com.
8.2 Audit and change history. While your account is active, correcting or deleting a record through the Service does not remove prior values of that record from your account's audit and change-history trail, which is retained for integrity, security, and fraud-prevention purposes; the audit trail is deleted along with the account. If a rights request requires removal of data from the change history, contact Knowledge ERP under Section 8.1.
8.3 Other assistance. Knowledge ERP will provide you with reasonable information and assistance necessary for you to meet your obligations under Applicable Privacy Laws in relation to the Processing, including with respect to security of Processing, Security Incident notification, and any required risk assessments, taking into account the information available to Knowledge ERP.
9. Security Incidents
Knowledge ERP will notify you without undue delay after becoming aware of a Security Incident affecting Customer Business Data, and will provide information reasonably available to it to help you assess the incident and meet any notification obligations you may have under Applicable Privacy Laws. Knowledge ERP will take reasonable steps to mitigate and, where possible, remediate the Security Incident. Knowledge ERP's notification is not an acknowledgment of fault or liability.
10. Audits
Knowledge ERP will make available to you information reasonably necessary to demonstrate its compliance with this DPA. No more than once per twelve (12) months (unless required by a regulator or following a Security Incident), and subject to reasonable advance notice, confidentiality obligations, and Knowledge ERP's security and operational requirements, Knowledge ERP will respond to a reasonable written assessment questionnaire and, where genuinely necessary, allow a remote review of relevant documentation. Audits must not unreasonably disrupt Knowledge ERP's business or compromise the security or confidentiality of other customers' data.
11. Deletion and Return
Upon termination or expiration of the Agreement, Knowledge ERP will delete Customer Business Data in accordance with the Agreement and the Privacy Policy. As described in the Terms of Service (Termination; Effect of Termination) and the Privacy Policy (Data Retention), on cancellation or termination your access to the Service ends, you have an approximately 30-day period to export your data, and Knowledge ERP then permanently deletes Customer Business Data — including the account's audit and change-history trail — from active systems, with residual backup copies aging out on the normal rotation cycle, except where retention is required by law. Knowledge ERP encourages you to export your data before cancelling.
12. Liability and Conflict
12.1 Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Agreement (Terms of Service, Limitation of Liability).
12.2 In the event of a conflict between this DPA and the Agreement with respect to the Processing of Customer Business Data, this DPA controls. In all other respects, the Agreement remains in full force and effect.
13. Term and Governing Law
This DPA takes effect on the Effective Date (or on execution, if signed) and continues for as long as Knowledge ERP Processes Customer Business Data on your behalf. This DPA is governed by the laws of the State of Michigan, consistent with the Agreement, without regard to conflict-of-laws principles.
14. Signatures (if executed as a standalone document)
By signing below, or by accepting the Agreement and using the Service to Process Personal Information of Business Contacts, the parties agree to this DPA.
Customer (Business / Controller) Name: ______________________________ Title: ______________________________ Entity: _____________________________ Date: _______________________________
Pelton Solutions LLC d/b/a Knowledge ERP (Service Provider / Processor) Name: Nathanael Pelton Title: Owner Date: _______________________________
Annex 1 — Details of Processing
- Subject matter: Provision of the Knowledge ERP multi-tenant business-management (ERP/CRM) Service, including inventory, sales, purchasing, manufacturing, appointments, surveys, rentals and loans, email and SMS automation, and related support and security.
- Duration: For the term of the Agreement and until deletion in accordance with Section 11.
- Nature and purpose: Hosting and storing the business records you and your Authorized Users enter into or collect through the Service; generating documents (quotes, invoices, agreements) from them; sending communications you configure or trigger; syncing data with integrations you connect; and related support and security.
- Categories of data subjects: Business Contacts — your customers, customer and vendor contacts, borrowers, and equipment renters; members of the public who book appointments or answer questionnaires or surveys through your forms; and the senders and recipients of email messages synced from mailboxes you connect.
- Categories of Customer Business Data:
- CRM records — names, job titles, email addresses, phone numbers, websites, full billing and shipping addresses, payment terms, free-text notes, activities, tasks, opportunities, and segment membership.
- Transactional records — quotes, sales orders, invoices, credit memos, customer payments (amount, method, date — never card numbers), returns, purchase orders, and vendor bills and payments.
- Captured e-signatures — signatures collected on equipment checkouts, associated with the identified individual taking the equipment.
- Loan and rental agreements — equipment loans and rentals attributed to named individuals, including due dates and extension requests.
- Appointment and survey data — contact details, selected services or equipment, free-text notes, and questionnaire and survey answers collected from members of the public through your public booking, questionnaire, and survey forms, including invitation open and response timestamps.
- Synced email content — for mailboxes you connect via Gmail or Microsoft Outlook: subject lines, sender and recipient addresses, and full message bodies, including messages involving individuals who are not (or are not yet) matched to a customer record.
- Custom fields — any data you or your Authorized Users choose to store in tenant-defined custom fields or free-text fields.
- Uploaded files — attachments and media you or your Authorized Users upload, and their contents.
- Sensitive data: Not requested or required by Knowledge ERP. You must not store special categories of Personal Information — such as health information, government identification numbers, precise geolocation, biometric identifiers, or payment card numbers — in free-text fields, notes, custom fields, or uploaded files (see Acceptable Use Policy). Knowledge ERP is not a HIPAA-compliant platform and will not sign a Business Associate Agreement (BAA); you must not use the Service to Process Protected Health Information (PHI) subject to HIPAA.
- Tenant-directed disclosures: Data sent to integrations you connect (QuickBooks Online, Shopify, WooCommerce, ShipStation, Gmail, Microsoft Outlook, Twilio, your own Stripe or Square account), to outbound webhook URLs you configure, and to API clients you authorize is disclosed at your direction under Sections 3.4 and 7.4 and is outside the scope of Knowledge ERP's Sub-Processor commitments.
- Frequency: Continuous, as you and your Authorized Users use the Service, as your Business Contacts interact with your public forms and portal, and as connected mailboxes and integrations sync.
Annex 2 — Security Measures
Knowledge ERP maintains safeguards including, as described in the Privacy Policy (Security):
- HTTPS/TLS encryption in transit for all connections to the Service.
- Encryption at rest at the infrastructure layer for databases, caches, and object storage.
- Logical per-tenant isolation within shared infrastructure, enforced by tenant-scoped queries and verified by an automated cross-tenant isolation test suite.
- A web application firewall (WAF) with managed rule sets and rate limiting in front of the Service.
- Application servers in private network subnets, not directly reachable from the internet.
- Credentials and secrets held in a managed secrets store.
- A per-account audit trail recording changes to business records and the acting user.
- Least-access staff administration: Pelton Solutions staff access tenant data only as needed for support, maintenance, and security, and administrative access is logged.
- Customer-approved support access: viewing tenant data through the administrative interface requires the Customer's approval, is granted to a named staff member for a Customer-chosen duration, expires automatically, and is revocable by the Customer at any time; emergency access by a senior engineer during an outage is notified to the Customer at the time and permanently flagged as such (Section 5).
- Error monitoring configured not to capture personal data by default.
Annex 3 — Sub-Processors
The current Sub-Processors authorized to Process Customer Business Data are listed in the Knowledge ERP Sub-Processor List, which is incorporated into this DPA by reference and includes Amazon Web Services (all hosting, storage, email delivery, and network infrastructure, United States). Stripe processes Customer account billing only, not Customer Business Data. Sentry (error monitoring) and GitHub (source control and deployment) are used for diagnostics and deployment and may incidentally process limited request data. Services you connect yourself are tenant-directed disclosures, not Sub-Processors (Section 7.4).