Contents
Version 1.1 · Takes effect · Last updated
This Data Processing Addendum (“DPA”) forms part of the agreement between Solesca Energy, Inc. (“Solesca,” “Processor,” “we,” “us,” or “our”) and the customer (“Customer” or “Controller”) using the Services.
This DPA applies when Solesca processes Personal Data on behalf of Customer in connection with the Services.
Version 1.1 updates version 1.0 (June 2026), including subprocessor notices, transfer arrangements and document precedence. A separately signed agreement continues to control the processing it covers, subject to applicable data-transfer requirements.
Applicable Data Protection Law means all laws and regulations applicable to the processing of Personal Data, including where applicable the GDPR, UK GDPR, Swiss data protection laws, and applicable U.S. state privacy laws.
Personal Data, Processing, Controller, Processor, Data Subject, and Subprocessor have the meanings assigned under applicable law.
Customer acts as Controller (or equivalent legal role). Solesca acts as Processor (or equivalent legal role) with respect to Personal Data processed through the Services.
Solesca will process Personal Data only on Customer’s documented instructions to provide, maintain, support and secure the Services, or as required by applicable law. Any service-improvement or model-training use permitted under the Terms remains subject to these instructions, this DPA, confidentiality obligations and any separately signed agreement; it does not provide independent permission to use Personal Data for training.
Solesca will not sell Personal Data or share Personal Data for cross-context behavioral advertising.
Customer is responsible for ensuring it has all required rights, notices, consents, and legal bases for Personal Data submitted to the Services and for complying with Applicable Data Protection Law.
Solesca shall process Personal Data only on documented instructions from Customer unless otherwise required by law; ensure authorized personnel are bound by confidentiality obligations; maintain appropriate technical and organizational measures; assist Customer with data subject requests and compliance obligations taking into account the nature of the processing and information available to Solesca; and make available information reasonably necessary to demonstrate compliance with this DPA.
Solesca will maintain reasonable and appropriate administrative, technical, and organizational safeguards designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access.
Customer provides a general authorization for Solesca to engage Subprocessors to process Personal Data in connection with the Services. Solesca maintains the current list of Subprocessors at solesca.com/legal/subprocessors.
Before a new Subprocessor processes Customer Personal Data, Solesca will update that list and give at least thirty (30) days’ notice by email to the Owners and Admins of Customer’s organization.
Customer may object in writing within the notice period on reasonable data-protection grounds. Solesca will work with Customer in good faith to address the objection. If Solesca cannot reasonably accommodate it, Customer may terminate the affected Services by written notice before the change takes effect, and Solesca will refund any prepaid subscription fees for the unused remainder of the term on a pro-rata basis. SOL Credits are not refundable.
Where a Subprocessor must be replaced without advance notice to keep the Services secure or available, Solesca may do so to the extent permitted by Applicable Data Protection Law and any applicable transfer clauses, and will notify Customer as soon as practicable. Customer has thirty (30) days from that notice to object on reasonable data-protection grounds. If Solesca cannot reasonably accommodate the objection, Customer may terminate the affected Services by written notice within thirty (30) days after Solesca communicates that outcome, even though the replacement has already taken effect. The same pro-rata refund of unused prepaid subscription fees applies. SOL Credits remain non-refundable except where applicable law requires otherwise.
Solesca shall impose data protection obligations on Subprocessors that are substantially similar to those in this DPA and remains responsible for the performance of its Subprocessors’ obligations to the extent required by law.
Solesca will notify Customer without undue delay after becoming aware of a personal data breach affecting Personal Data processed under this DPA. The initial notice will include the information then available about the nature of the breach and mitigation measures; Solesca will provide further information as it becomes available without waiting for the investigation to be complete.
Taking into account the nature of the processing and information available to Solesca, Solesca will provide reasonable assistance to Customer in responding to lawful requests from Data Subjects.
Upon reasonable written request, Customer may request documentation reasonably necessary to demonstrate Solesca’s compliance with this DPA. Routine reviews ordinarily occur no more than once annually; this limit does not apply where an additional review is required by law, a competent authority or a relevant personal data breach. Solesca will allow and contribute to audits, including inspections, as required by Applicable Data Protection Law. Where documentation is insufficient, the parties will arrange an appropriate further review subject to reasonable confidentiality and security measures.
Before a transfer of Personal Data that requires additional safeguards, the parties will put in place the applicable transfer arrangement. If the parties rely on the European Commission’s Standard Contractual Clauses under Decision (EU) 2021/914, that arrangement must identify the parties, the applicable module and optional clauses, the competent supervisory authority and governing law, and complete the required annexes describing the transfers and security measures. UK transfers must also include the applicable UK transfer instrument, with its required tables completed; Swiss transfers must include the applicable Swiss adaptations. This DPA does not represent that those customer-specific arrangements have already been completed. Solesca will provide the applicable transfer terms on request at privacy@solesca.com. Applicable transfer clauses prevail over any conflicting provision of the Agreement or this DPA, including liability limitations.
Following termination, Solesca will, at Customer’s choice, return or delete Personal Data processed on Customer’s behalf and delete existing copies, unless applicable law requires retention. The parties will coordinate retrieval and deletion, including retained backup copies. Account closure alone does not erase all copies. Copies awaiting deletion remain protected under this DPA; backup retention is not an unrestricted right to retain Personal Data indefinitely.
To the extent applicable, Solesca acts as a Service Provider or Processor and will comply with obligations applicable to service providers and processors under relevant U.S. privacy laws.
The liability of each party under this DPA is subject to the limitations of liability contained in the Agreement, except to the extent those limitations conflict with applicable law or binding data-transfer clauses.
Applicable binding data-transfer clauses prevail over conflicting provisions. Subject to those requirements, a separately signed agreement controls the processing and subject matter it covers. Otherwise, this DPA controls conflicts regarding Personal Data processing with the standard Terms, Orders, Privacy Policy or Cookie Policy. Publication of this DPA does not amend a separately signed agreement contrary to its amendment provisions.
Book a demo
Email: contact@solesca.com
Phone: (312) 899 - 6750
Chicago, IL 60640
Email: contact@solesca.com
Phone: (312) 899 - 6750
Chicago, IL 60640
© 2026 Solesca Energy, Inc.