Data Processing Agreement

Last updated: October 2, 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between the customer organization ("Customer") and Incisive Platforms, Inc. ("Incisive") for Guidelite ("the Service"). It applies when Incisive processes personal data on the Customer's behalf. Where this DPA and the Terms conflict on data protection, this DPA governs. Enterprise customers may sign a countersigned copy on request.

1. Roles

The Customer is the controller of personal data it enters into the Service, and Incisive is its processor. Incisive processes that data only on the Customer's documented instructions. The Terms, this DPA, and the Customer's use of the Service's features are those instructions. If Incisive believes an instruction violates applicable data protection law, it will tell the Customer.

2. Details of processing

  • Subject matter and purpose: providing the Service, a strategic planning platform, and the support, security, and billing that go with it.
  • Duration: the Customer's subscription, plus the deletion period in Section 8.
  • Data subjects: the Customer's users, and people named in content the Customer enters (for example, owners of targets, plans, actions, and risks).
  • Personal data: names, work email addresses, roles and team membership, phone numbers if provided, sign-in and activity records, and personal data within content the Customer enters.
  • Special categories: none are required. The Customer should not enter special-category data (such as health data) into the Service.

3. Confidentiality

Incisive ensures that anyone it authorizes to process Customer personal data is bound by confidentiality obligations.

4. Security

Incisive maintains the technical and organizational measures in Annex 1, and may update them provided the overall level of protection does not decrease.

5. Subprocessors

The Customer authorizes Incisive to use the subprocessors listed on our Data Processors page. Incisive will update that page at least 30 days before adding or replacing a subprocessor that processes Customer personal data. The Customer may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection, the Customer may terminate the affected Service and receive a refund of prepaid fees for the remaining term. Incisive imposes data protection obligations on each subprocessor that are no less protective than this DPA, and remains responsible for its subprocessors' performance.

6. Assistance

Taking into account the nature of the processing, Incisive will help the Customer respond to requests from data subjects exercising their rights, and provide reasonable information the Customer needs for data protection impact assessments and consultations with supervisory authorities. Incisive will forward any request it receives directly from a Customer's data subject to the Customer.

7. Personal data breaches

Incisive will notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer personal data. The notice will describe the breach, its likely consequences, and the measures taken or proposed, as far as that information is then available.

8. Return and deletion

During the subscription the Customer can request an export of its data. Within 30 days after the subscription ends, or after a verified deletion request, Incisive will delete Customer personal data from its live systems, unless the law requires it to keep the data. Copies in backups expire on the backup provider's normal rotation schedule and are not restored except for disaster recovery.

9. Audits

Incisive will make available the information reasonably necessary to demonstrate compliance with this DPA, including written responses to reasonable security questionnaires no more than once a year. Further audits, including on-site audits, may be agreed in an Enterprise order form at the Customer's expense.

10. International transfers

Incisive and its subprocessors process data in the United States and in other locations listed on the Data Processors page. Where Customer personal data originates in the European Economic Area, the United Kingdom, or Switzerland, the parties agree that the European Commission's Standard Contractual Clauses (Module 2, controller to processor), with the UK International Data Transfer Addendum and Swiss amendments where applicable, apply to that transfer and are incorporated by reference.

11. Liability

Each party's liability under this DPA is subject to the limitations in the Terms.

Annex 1: Security measures

  • Tenant isolation: every organization's data is separated by database row-level security, enforced by the database for every query, and tested by automated isolation checks before each release.
  • Encryption: data is encrypted in transit (TLS) and at rest by our database and hosting providers.
  • Access control: role-based permissions within each organization, multi-factor authentication for users, and mandatory multi-factor authentication for Incisive platform administrators.
  • Least privilege: privileged database operations run only in server-side code; every user's permissions are enforced by the database itself, not only by the application.
  • Logging and monitoring: an audit trail of significant changes; error monitoring that masks on-screen text and form inputs and removes logged personal data before sending; logs designed not to record email addresses.
  • Abuse prevention: rate limiting on sign-in and other sensitive endpoints.
  • Backups and recovery: managed database backups by our database provider, and a documented disaster recovery procedure.
  • Change control: all code changes go through reviewed pull requests and automated security, permission, and data-integrity checks before release.