Version 2026-08-05 · Effective Aug 5, 2026

Knowledge ERP Data Processing Addendum

Effective Date: August 5, 2026 Last Updated: August 5, 2026


1. Background and Scope

This Data Processing Addendum ("DPA") supplements and forms part of the Knowledge ERP Terms of Service (the "Agreement") between Pelton Solutions LLC d/b/a Knowledge ERP ("Knowledge ERP") and the customer that has accepted the Agreement ("Customer," "you"). It applies where Knowledge ERP processes Customer Business Data (defined below) on your behalf in providing the Service.

This DPA governs only Knowledge ERP's processing of personal information contained in the business records that you and your Authorized Users put into the platform — information about your customers, vendors, contacts, borrowers, appointment bookers, survey respondents, and email correspondents. For that data, you are the Business / Controller and Knowledge ERP is the Service Provider / Processor.

This DPA does not apply to personal information for which Knowledge ERP is itself the business/controller — your account, Authorized User, and billing information — which is governed by the Knowledge ERP Privacy Policy.

If you accept the Agreement and use the Service to Process personal information of your Business Contacts, this DPA is incorporated into the Agreement. Where a separate signed DPA is required, the signature block in Section 14 applies.


2. Definitions

Capitalized terms not defined here have the meaning given in the Agreement.


3. Roles and Instructions

3.1 As between the parties, you are the Business/Controller and determine the purposes and means of Processing Customer Business Data, and Knowledge ERP is the Service Provider/Processor acting on your behalf.

3.2 Knowledge ERP will Process Customer Business Data only (a) to provide, maintain, secure, and support the Service in accordance with the Agreement; (b) in accordance with your documented lawful instructions (which include the Agreement, this DPA, and your configuration and use of the Service — including the integrations you connect, the automations you enable, and the fields you define); and (c) as otherwise required by applicable law, in which case Knowledge ERP will inform you of that requirement unless legally prohibited.

3.3 You are responsible for the lawfulness of Customer Business Data and of your collection of it, including providing any required privacy notice to, and obtaining any required consent from, your Business Contacts — including individuals who submit information through your public booking, questionnaire, and survey forms, individuals whose email messages are synced from a mailbox you connect, and recipients of email and SMS messages you send or trigger through the Service — and for ensuring you have the right to transfer Customer Business Data to Knowledge ERP for Processing under this DPA.

3.4 Tenant-directed disclosures. When you connect a third-party integration (for example QuickBooks Online, Shopify, WooCommerce, ShipStation, Gmail, Microsoft Outlook, Twilio, or your own Stripe or Square account), configure an outbound webhook, or grant API access, you instruct Knowledge ERP to disclose Customer Business Data to that destination on your behalf. Those disclosures are made at your direction, the recipient's own terms and privacy practices govern its handling of the data, and you are responsible for the destination — including any URL you nominate for an outbound webhook. See Section 7.4 and Annex 1.


4. Service Provider / Processor Obligations and Certification

Knowledge ERP certifies that it understands and will comply with the restrictions in this Section. With respect to Customer Business Data, Knowledge ERP will:

You may take reasonable and appropriate steps to help ensure that Knowledge ERP uses Customer Business Data in a manner consistent with your obligations under Applicable Privacy Laws, and to stop and remediate any unauthorized use, as described in Section 10 (Audits).


5. Confidentiality

Knowledge ERP will ensure that personnel authorized to Process Customer Business Data are subject to a duty of confidentiality and Process the data only as necessary to provide the Service. Pelton Solutions staff access to tenant data is limited to the least access necessary for support, maintenance, and security purposes, and administrative access is logged.

Customer approval. Staff access to Customer Business Data through the Service's administrative interface additionally requires your approval, granted by one of your users holding account-administration permission, for a duration that user chooses, revocable by you at any time, and expiring automatically. The exception is emergency access taken by a senior engineer to restore a materially impaired or inoperable Service where your administrators cannot respond; that access is notified to your administrators by email when it occurs, identified as emergency access in the record available to you, time-limited, and revocable by you. This is described in full in the Privacy Policy (Section 7.3) and Section 8.6 of the Terms of Service. It governs the administrative interface and does not limit Processing performed by the Service itself, access by personnel administering the underlying infrastructure, or Knowledge ERP's rights under Sections 8.5 and 17 of the Terms of Service.


6. Security

Knowledge ERP will implement and maintain reasonable and appropriate administrative, technical, and physical safeguards designed to protect Customer Business Data, as described in Annex 2 and in the Privacy Policy (Security). Knowledge ERP may update its security measures from time to time provided that the updates do not materially reduce the overall level of protection.


7. Sub-Processors

7.1 You authorize Knowledge ERP to engage the Sub-Processors listed in the Knowledge ERP Sub-Processor List to Process Customer Business Data in connection with the Service.

7.2 Knowledge ERP will impose on each Sub-Processor data-protection obligations that are substantially consistent with those in this DPA, to the extent applicable to the nature of the Sub-Processor's services, and Knowledge ERP remains responsible to you for each Sub-Processor's performance of its obligations.

7.3 Knowledge ERP will maintain the Sub-Processor List and will provide notice (by updating the list and/or by email or in-product notice) before adding a new Sub-Processor that Processes Customer Business Data. If you reasonably object to a new Sub-Processor on data-protection grounds, you may notify Knowledge ERP within the notice period stated on the list (or, if none is stated, within fourteen (14) days); the parties will work in good faith to address the objection, and if they cannot, your sole remedy is to stop using the affected feature or to terminate the affected Service.

7.4 Integrations you connect are not Sub-Processors. Third-party services that you choose to connect to your account, outbound webhook destinations you configure, and API clients you authorize receive Customer Business Data as tenant-directed disclosures under Section 3.4, not as Sub-Processors engaged by Knowledge ERP. Knowledge ERP does not impose data-protection terms on those recipients, and disconnecting the integration stops future disclosures but does not retrieve data already transmitted.


8. Assistance — Consumer Requests and Compliance

8.1 Consumer rights requests. Taking into account the nature of the Processing, Knowledge ERP will provide reasonable assistance through appropriate technical and organizational measures (including the search, edit, export, and deletion features of the Service, which allow you to locate, correct, and delete a Business Contact's records yourself) to help you respond to verifiable requests from Business Contacts to exercise their rights under Applicable Privacy Laws (such as access, deletion, correction, portability, and opt-out). If Knowledge ERP receives such a request directly from a Business Contact relating to data Processed on your behalf, Knowledge ERP will, where lawful, forward it to you or instruct the individual to contact you, and will not respond on your behalf except on your instruction or as legally required. Requests requiring Knowledge ERP's assistance may be sent to legal@peltonsolutions.com.

8.2 Audit and change history. While your account is active, correcting or deleting a record through the Service does not remove prior values of that record from your account's audit and change-history trail, which is retained for integrity, security, and fraud-prevention purposes; the audit trail is deleted along with the account. If a rights request requires removal of data from the change history, contact Knowledge ERP under Section 8.1.

8.3 Other assistance. Knowledge ERP will provide you with reasonable information and assistance necessary for you to meet your obligations under Applicable Privacy Laws in relation to the Processing, including with respect to security of Processing, Security Incident notification, and any required risk assessments, taking into account the information available to Knowledge ERP.


9. Security Incidents

Knowledge ERP will notify you without undue delay after becoming aware of a Security Incident affecting Customer Business Data, and will provide information reasonably available to it to help you assess the incident and meet any notification obligations you may have under Applicable Privacy Laws. Knowledge ERP will take reasonable steps to mitigate and, where possible, remediate the Security Incident. Knowledge ERP's notification is not an acknowledgment of fault or liability.


10. Audits

Knowledge ERP will make available to you information reasonably necessary to demonstrate its compliance with this DPA. No more than once per twelve (12) months (unless required by a regulator or following a Security Incident), and subject to reasonable advance notice, confidentiality obligations, and Knowledge ERP's security and operational requirements, Knowledge ERP will respond to a reasonable written assessment questionnaire and, where genuinely necessary, allow a remote review of relevant documentation. Audits must not unreasonably disrupt Knowledge ERP's business or compromise the security or confidentiality of other customers' data.


11. Deletion and Return

Upon termination or expiration of the Agreement, Knowledge ERP will delete Customer Business Data in accordance with the Agreement and the Privacy Policy. As described in the Terms of Service (Termination; Effect of Termination) and the Privacy Policy (Data Retention), on cancellation or termination your access to the Service ends, you have an approximately 30-day period to export your data, and Knowledge ERP then permanently deletes Customer Business Data — including the account's audit and change-history trail — from active systems, with residual backup copies aging out on the normal rotation cycle, except where retention is required by law. Knowledge ERP encourages you to export your data before cancelling.


12. Liability and Conflict

12.1 Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Agreement (Terms of Service, Limitation of Liability).

12.2 In the event of a conflict between this DPA and the Agreement with respect to the Processing of Customer Business Data, this DPA controls. In all other respects, the Agreement remains in full force and effect.


13. Term and Governing Law

This DPA takes effect on the Effective Date (or on execution, if signed) and continues for as long as Knowledge ERP Processes Customer Business Data on your behalf. This DPA is governed by the laws of the State of Michigan, consistent with the Agreement, without regard to conflict-of-laws principles.


14. Signatures (if executed as a standalone document)

By signing below, or by accepting the Agreement and using the Service to Process Personal Information of Business Contacts, the parties agree to this DPA.

Customer (Business / Controller) Name: ______________________________ Title: ______________________________ Entity: _____________________________ Date: _______________________________

Pelton Solutions LLC d/b/a Knowledge ERP (Service Provider / Processor) Name: Nathanael Pelton Title: Owner Date: _______________________________


Annex 1 — Details of Processing


Annex 2 — Security Measures

Knowledge ERP maintains safeguards including, as described in the Privacy Policy (Security):


Annex 3 — Sub-Processors

The current Sub-Processors authorized to Process Customer Business Data are listed in the Knowledge ERP Sub-Processor List, which is incorporated into this DPA by reference and includes Amazon Web Services (all hosting, storage, email delivery, and network infrastructure, United States). Stripe processes Customer account billing only, not Customer Business Data. Sentry (error monitoring) and GitHub (source control and deployment) are used for diagnostics and deployment and may incidentally process limited request data. Services you connect yourself are tenant-directed disclosures, not Sub-Processors (Section 7.4).