Data Processing Agreement

Last updated: July 2, 2026
Please have this reviewed by legal counsel. This DPA is offered to business customers who require one; have qualified legal counsel review it before entering into it. To execute a DPA, contact [email protected].

This Data Processing Agreement ("DPA") forms part of the agreement between Exact Cabinets Ltd. ("Processor", "CabShopSoft") and the customer identified in the account ("Controller", "you") for use of the Service, and reflects the parties' obligations regarding the processing of personal data under PIPEDA and, where applicable, the GDPR.

1. Roles

For personal data that you or your users enter about your own clients, employees, and projects ("Controller Personal Data"), you are the Controller and CabShopSoft is the Processor. CabShopSoft processes Controller Personal Data only on your documented instructions, which include your configuration and use of the Service and this DPA.

2. Subject matter & details of processing

ItemDetails
Subject matterProvision of the CabShopSoft platform
DurationThe term of your subscription, plus the retention periods described below
Nature & purposeHosting, storage, and processing to deliver cabinet-shop management functions
Categories of data subjectsYour clients, your staff/employees, your installers and field workers, your contacts
Categories of personal dataNames, contact details, addresses; job/quote/invoice records; employee time and attendance; optional employee location (GPS); uploaded documents
Special categoriesNone intended. You must not enter special-category data except as lawfully permitted

3. Processor obligations

4. Sub-processors

You authorize CabShopSoft to engage the sub-processors listed in our Privacy Policy to process Controller Personal Data. We impose data-protection obligations on sub-processors substantially similar to those in this DPA and remain responsible for their performance. We will give notice of intended additions or replacements and give you an opportunity to object on reasonable data-protection grounds.

5. International transfers

Controller Personal Data may be hosted and processed in the United States and other countries. Where the GDPR applies, the parties agree that the European Commission's Standard Contractual Clauses (and UK/Swiss addenda where relevant) are incorporated by reference to cover such transfers. Under PIPEDA, CabShopSoft remains accountable for data transferred to sub-processors for processing.

6. Retention

7. Liability & order of precedence

Each party's liability under this DPA is subject to the limitations of liability in the Terms of Service. If there is a conflict between this DPA and the Terms regarding the processing of Controller Personal Data, this DPA controls.

Annex A — Security measures

CabShopSoft maintains safeguards including: encryption in transit (TLS/HTTPS); salted password hashing; optional multi-factor authentication; role-based access controls and tenant isolation; network firewalling and restricted administrative access; intrusion mitigation and rate limiting; audit logging; and a documented process for security incident response and breach notification.

To request an executed copy of this DPA for your organization, contact [email protected].