Home

Careers

Log in

Book my demo

Contents

Data Processing Addendum

Version 1.1 · Takes effect · Last updated

This Data Processing Addendum (“DPA”) forms part of the agreement between Solesca Energy, Inc. (“Solesca,” “Processor,” “we,” “us,” or “our”) and the customer (“Customer” or “Controller”) using the Services.

This DPA applies when Solesca processes Personal Data on behalf of Customer in connection with the Services.

Version 1.1 updates version 1.0 (June 2026), including subprocessor notices, transfer arrangements and document precedence. A separately signed agreement continues to control the processing it covers, subject to applicable data-transfer requirements.


1. Definitions

Applicable Data Protection Law means all laws and regulations applicable to the processing of Personal Data, including where applicable the GDPR, UK GDPR, Swiss data protection laws, and applicable U.S. state privacy laws.

Personal Data, Processing, Controller, Processor, Data Subject, and Subprocessor have the meanings assigned under applicable law.

2. Roles of the Parties

Customer acts as Controller (or equivalent legal role). Solesca acts as Processor (or equivalent legal role) with respect to Personal Data processed through the Services.

3. Scope and Purpose of Processing

Solesca will process Personal Data only on Customer’s documented instructions to provide, maintain, support and secure the Services, or as required by applicable law. Any service-improvement or model-training use permitted under the Terms remains subject to these instructions, this DPA, confidentiality obligations and any separately signed agreement; it does not provide independent permission to use Personal Data for training.

Solesca will not sell Personal Data or share Personal Data for cross-context behavioral advertising.

4. Customer Responsibilities

Customer is responsible for ensuring it has all required rights, notices, consents, and legal bases for Personal Data submitted to the Services and for complying with Applicable Data Protection Law.

5. Processor Obligations

Solesca shall process Personal Data only on documented instructions from Customer unless otherwise required by law; ensure authorized personnel are bound by confidentiality obligations; maintain appropriate technical and organizational measures; assist Customer with data subject requests and compliance obligations taking into account the nature of the processing and information available to Solesca; and make available information reasonably necessary to demonstrate compliance with this DPA.

6. Security Measures

Solesca will maintain reasonable and appropriate administrative, technical, and organizational safeguards designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access.

7. Subprocessors

7.1 General authorization:

Customer provides a general authorization for Solesca to engage Subprocessors to process Personal Data in connection with the Services. Solesca maintains the current list of Subprocessors at solesca.com/legal/subprocessors.

7.2 Notice of changes:

Before a new Subprocessor processes Customer Personal Data, Solesca will update that list and give at least thirty (30) days’ notice by email to the Owners and Admins of Customer’s organization.

7.3 Objection:

Customer may object in writing within the notice period on reasonable data-protection grounds. Solesca will work with Customer in good faith to address the objection. If Solesca cannot reasonably accommodate it, Customer may terminate the affected Services by written notice before the change takes effect, and Solesca will refund any prepaid subscription fees for the unused remainder of the term on a pro-rata basis. SOL Credits are not refundable.

7.4 Emergency replacement:

Where a Subprocessor must be replaced without advance notice to keep the Services secure or available, Solesca may do so to the extent permitted by Applicable Data Protection Law and any applicable transfer clauses, and will notify Customer as soon as practicable. Customer has thirty (30) days from that notice to object on reasonable data-protection grounds. If Solesca cannot reasonably accommodate the objection, Customer may terminate the affected Services by written notice within thirty (30) days after Solesca communicates that outcome, even though the replacement has already taken effect. The same pro-rata refund of unused prepaid subscription fees applies. SOL Credits remain non-refundable except where applicable law requires otherwise.

7.5 Responsibility:

Solesca shall impose data protection obligations on Subprocessors that are substantially similar to those in this DPA and remains responsible for the performance of its Subprocessors’ obligations to the extent required by law.

8. Security Incidents

Solesca will notify Customer without undue delay after becoming aware of a personal data breach affecting Personal Data processed under this DPA. The initial notice will include the information then available about the nature of the breach and mitigation measures; Solesca will provide further information as it becomes available without waiting for the investigation to be complete.

9. Data Subject Requests

Taking into account the nature of the processing and information available to Solesca, Solesca will provide reasonable assistance to Customer in responding to lawful requests from Data Subjects.

10. Audits

Upon reasonable written request, Customer may request documentation reasonably necessary to demonstrate Solesca’s compliance with this DPA. Routine reviews ordinarily occur no more than once annually; this limit does not apply where an additional review is required by law, a competent authority or a relevant personal data breach. Solesca will allow and contribute to audits, including inspections, as required by Applicable Data Protection Law. Where documentation is insufficient, the parties will arrange an appropriate further review subject to reasonable confidentiality and security measures.

11. International Transfers

Before a transfer of Personal Data that requires additional safeguards, the parties will put in place the applicable transfer arrangement. If the parties rely on the European Commission’s Standard Contractual Clauses under Decision (EU) 2021/914, that arrangement must identify the parties, the applicable module and optional clauses, the competent supervisory authority and governing law, and complete the required annexes describing the transfers and security measures. UK transfers must also include the applicable UK transfer instrument, with its required tables completed; Swiss transfers must include the applicable Swiss adaptations. This DPA does not represent that those customer-specific arrangements have already been completed. Solesca will provide the applicable transfer terms on request at privacy@solesca.com. Applicable transfer clauses prevail over any conflicting provision of the Agreement or this DPA, including liability limitations.

12. Return and Deletion of Data

Following termination, Solesca will, at Customer’s choice, return or delete Personal Data processed on Customer’s behalf and delete existing copies, unless applicable law requires retention. The parties will coordinate retrieval and deletion, including retained backup copies. Account closure alone does not erase all copies. Copies awaiting deletion remain protected under this DPA; backup retention is not an unrestricted right to retain Personal Data indefinitely.

13. U.S. Privacy Laws

To the extent applicable, Solesca acts as a Service Provider or Processor and will comply with obligations applicable to service providers and processors under relevant U.S. privacy laws.

14. Liability

The liability of each party under this DPA is subject to the limitations of liability contained in the Agreement, except to the extent those limitations conflict with applicable law or binding data-transfer clauses.

15. Order of Precedence

Applicable binding data-transfer clauses prevail over conflicting provisions. Subject to those requirements, a separately signed agreement controls the processing and subject matter it covers. Otherwise, this DPA controls conflicts regarding Personal Data processing with the standard Terms, Orders, Privacy Policy or Cookie Policy. Publication of this DPA does not amend a separately signed agreement contrary to its amendment provisions.

16. Annex 1 – Description of Processing

Subject Matter
Provision of Solesca’s software and related services.
Duration
For the duration of the Agreement and any applicable retention period.
Categories of Data Subjects
Customer personnel, end users, contractors, business contacts, and other individuals whose Personal Data is submitted to the Services.
Categories of Personal Data
Names, email addresses, usernames, account identifiers, business contact information, customer-generated content, and other Personal Data submitted by Customer.
Nature and Purpose
Hosting, storage, analysis, support, maintenance, transmission, and other processing necessary to provide the Services.
Sensitive Data
Customer shall not provide special categories of personal data unless expressly authorized by Solesca in writing.

17. Annex 2 – Technical and Organizational Measures

  • Role-based access controls
  • Multi-factor authentication for administrative accounts
  • Encryption in transit using TLS
  • Encryption at rest where supported by infrastructure providers
  • Logging and monitoring of production systems
  • Vulnerability and patch management processes
  • Personnel confidentiality obligations
  • Backup and disaster recovery procedures
  • Security incident response procedures
  • Vendor and subprocessor review processes

LEGAL

Terms of Service

Legal

CONTACT

Email: contact@solesca.com

Phone: (312) 899 - 6750

Chicago, IL 60640

SOCIAL

Book a demo



Email: contact@solesca.com

Phone: (312) 899 - 6750

Chicago, IL 60640


© 2026 Solesca Energy, Inc.