Data Processing Agreement
Last updated: June 24, 2026 (v1.0)
This Data Processing Addendum (including the annexes, this “DPA”) applies between the customer that is party to the Services Agreement (“Company”) and Aurora Solar Inc. (“Provider”). This DPA is incorporated by reference into, and forms part of, the Services Agreement (“Services Agreement”) and any service order(s), order form(s) or statement(s) of work thereunder (collectively, “Agreement”) between the parties under which Provider will provide certain services (collectively, “Services”) to Company.
Table of Contents
- Definitions
- Duration and Scope of DPA
- Company Instructions
- Security
- Data Subject Rights
- Subprocessors
- Data Protection Assessment; Reviews and Audits of Compliance
- Company Responsibilities
- Account Data
- Miscellaneous
Annex 1 to DPA: EEA, Switzerland, and UK Annex
Annex 1-A to DPA: Additional Terms for the Standard Contractual Clauses
Annex 2 to DPA: California Annex
Annex 3 to DPA: Security Measures
1. Definitions
For purposes of this DPA, the terms below have the meanings set forth below. Capitalized terms that are used but not defined in this DPA have the meanings given in the Agreement.
- Administrator has the meaning given to it in the Agreement or, if not set forth in the Agreement, means the Authorized User designated by Company who administers the access and use of Services under the Agreement to End Users on Company’s behalf.
- Affiliate means any entity that directly or indirectly controls, is controlled by, or is under common control with the subject entity, where “control” refers to the power to direct or cause the direction of the subject entity, whether through ownership of voting securities, by contract or otherwise.
- Applicable Data Protection Laws means the privacy, data protection and data security laws and regulations of any jurisdiction applicable to the Processing of Personal Data under the Agreement (in each case, as amended, adopted, or superseded from time to time). Applicable Data Protection Laws may include, but are not limited to, the CCPA, the Colorado Privacy Act, the Connecticut Data Privacy Act, European Data Protection Laws, and the Virginia Consumer Data Protection Act.
- CCPA means the California Consumer Privacy Act of 2018 (as amended by the California Privacy Rights Act) and any regulations promulgated thereunder.
- Company Data has the meaning given to it in the Agreement or, if not set forth in the Agreement, means any data, content, code, video, images or other materials of any type that Company or its End Users submit to the Services. In this context, “submit” (and any similar term) includes submitting, uploading, transmitting or otherwise making available Company Data to or through the Services.
- EEA means the European Economic Area.
- End User has the meaning given to it in the Agreement or, if not set forth in the Agreement, means an individual Company or its Affiliate permits or invites to use the Services. For the avoidance of doubt: (i) Authorized Users, (ii) individuals invited by Company’s End Users (including Administrator), (iii) individuals under accounts managed by Company’s Administrator, and (iv) individuals interacting with the Services as Company’s end-customers are also considered End Users.
- European Data Protection Laws means the GDPR, the Swiss Federal Act on Data Protection, the United Kingdom General Data Protection Regulation (“UK GDPR”), the United Kingdom Data Protection Act 2018, and other data protection laws and regulations of the European Union, its Member States, Switzerland, Iceland, Liechtenstein, Norway and the United Kingdom, in each case, to the extent applicable to the Processing of Personal Data under the Agreement.
- GDPR means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, as amended from time to time.
- Information Security Incident means a breach of Provider’s security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data in Provider’s possession, custody or control. Information Security Incidents do not include unsuccessful attempts or activities that do not compromise the security of Personal Data, including unsuccessful log-in attempts, pings, port scans, denial of service attacks, or other network attacks on firewalls or networked systems.
- Personal Data means Company Data that constitutes “personal data,” “personal information,” or “personally identifiable information” defined in Applicable Data Protection Law, or information of a similar character regulated thereby. For the avoidance of doubt, Personal Data does not include any data that does not identify or relate to an identified or identifiable individual or household, including data that has been aggregated, anonymized, or deidentified.
- Process or Processing means any operation or set of operations that is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
- Security Measures has the meaning given in Section 4(a) (Provider’s Security Measures).
- Standard Contractual Clauses means the Annex to the Commission Implementing Decision (EU) 2021/914 of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council.
- Subprocessors means third parties that Provider engages to Process Personal Data in relation to the Services.
- Third Party Subprocessors has the meaning given in Section 6 (Subprocessors).
- The terms controller, data subject, processor and supervisory authority as used in this DPA have the meanings given in the GDPR.
2. Duration and Scope of DPA
- The effective date of this DPA is the effective date of the Services Agreement. This DPA will remain in effect so long as Provider Processes Company Personal Data, notwithstanding the expiration or termination of the Agreement.
-
Specific Jurisdictional Application:
Annex 1 (EEA, Switzerland, and UK Annex) to this DPA applies solely to Processing subject to European Data Protection Laws.
Annex 2 (California Annex) to this DPA applies solely to Processing subject to the CCPA if Company is a “business” or “service provider” (as defined in CCPA) with respect to such Processing.
- Updates to this DPA. Provider may update this DPA from time to time by posting the updated version at [URL https://trust.aurorasolar.com/dpa], identified by its version number and “Last updated” date, provided that no update will materially diminish the overall protection of Personal Data. Each update is an amendment to and continuation of this DPA (and not a new agreement, substituted contract, or novation), takes effect prospectively from its “Last updated” date, and does not reset the original effective date of this DPA, which remains the effective date of the Services Agreement. Unless prescribed otherwise by applicable laws, Company’s continued use of the Services after an update’s effective date constitutes acceptance of such amendment. Changes to Subprocessors are governed by Section 6(c) and not by this Section 2(c).
3. Company Instructions
Provider will Process Personal Data only in accordance with Company’s instructions to Provider. The Agreement and this DPA, together with Company’s configuration of, and use of, the Services, is a complete expression of such instructions, and Company’s additional instructions will be binding on Provider only pursuant to an amendment to this DPA signed by both parties. Company instructs Provider to Process Personal Data to provide the Services as contemplated by the Agreement and this DPA.
4. Security
- Provider Security Measures. Provider will implement and maintain technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure of or access to Personal Data (the “Security Measures”) as described in Annex 3 (Security Measures). Provider may update the Security Measures from time to time, so long as the updated measures do not materially decrease the overall protection of Personal Data.
- Security Compliance by Provider Staff. Provider will ensure that its personnel who are authorized to access Personal Data are subject to appropriate confidentiality obligations.
- Provider Security Assistance. Provider will (taking into account the nature of the Processing of Personal Data and the information available to Provider) provide Company with reasonable assistance necessary for Company to comply with its obligations in respect of Personal Data under Applicable Data Protection Laws, including Articles 32 to 34 (inclusive) of the GDPR, by (a) implementing and maintaining the Security Measures; and (b) complying with the terms of Section 4(d) (Information Security Incidents) of this DPA.
- Information Security Incidents. Provider will notify Company without undue delay of any Information Security Incident of which Provider becomes aware. Where possible, such notice will include all available details required under Applicable Data Protection Laws for Company to comply with its own notification obligations to supervisory authorities or individuals affected by the Information Security Incident. Provider’s notification of or response to an Information Security Incident will not be construed as Provider’s acknowledgment of any fault or liability with respect to the Information Security Incident.
-
Company’s Security Responsibilities and Assessment
- Company’s Security Responsibilities. Company agrees that, without limitation of Provider’s obligations under Section 4 (Security), Company is solely responsible for its use of the Services, including (a) making appropriate use of the Services to ensure a level of security appropriate to the risk in respect of the Personal Data; (b) securing the account authentication credentials, systems and devices Company uses to access the Services; (c) securing Company’s systems and devices that Provider uses to provide the Services; and (d) backing up Personal Data.
- Company’s Security Assessment. Company agrees that the Services, the Security Measures and Provider’s commitments under this DPA are adequate to meet Company’s needs, including with respect to any security obligations of Company under Applicable Data Protection Laws, and provide a level of security appropriate to the risk in respect of the Personal Data.
- Data Deletion. At the expiry or termination of the Agreement, Provider will delete all Company Personal Data (excluding any aggregated or deidentified data which Provider may retain and any back-up or archival copies which shall be deleted in accordance with Provider’s data retention schedule), except where Provider is required to retain copies under applicable laws, in which case Provider will isolate and protect that Company Personal Data from any further Processing except to the extent required by applicable laws. For purposes of this DPA and the Agreement, “deletion” means deletion, anonymization, or de-identification such that the data subject concerned by such data is not identifiable.
5. Data Subject Rights
- Provider’s Data Subject Request Assistance. Provider will (taking into account the nature of the Processing of Personal Data) provide Company with assistance reasonably necessary for Company to perform its obligations under Applicable Data Protection Laws to fulfill requests by data subjects to exercise their rights under Applicable Data Protection Laws (“Data Subject Requests”) with respect to Personal Data in Provider’s possession or control. Company shall compensate Provider for any such assistance at Provider’s then-current professional services rates, which shall be made available to Company upon request.
- Company’s Responsibility for Requests. If Provider receives a Data Subject Request, Provider will advise the data subject to submit the request to Company and Company will be responsible for responding to the request.
6. Subprocessors
- Consent to Subprocessor Engagement. Company specifically authorizes the engagement of Provider’s Affiliates as Subprocessors and generally authorizes the engagement of other third parties as Subprocessors (“Third Party Subprocessors”).
- Requirements for Subprocessor Engagement. When engaging any Subprocessor, Provider will enter into a written contract with such Subprocessor containing data protection obligations consistent with those in this DPA with respect to Personal Data to the extent applicable to the nature of the services provided by such Subprocessor. Provider shall be liable for all obligations under the Agreement related to Personal Data that are subcontracted to the Subprocessor and its actions and omissions related thereto.
- Opportunity to Object to Subprocessor Changes. Provider’s Subprocessors as of the effective date of the Services Agreement are located at https://trust.aurorasolar.com/subprocessors. Where required by Applicable Data Protection Laws, when Provider engages any new Third Party Subprocessor after the effective date of the Services Agreement, Provider will notify Company of the engagement (including the name and location of the relevant Subprocessor and the activities it will perform) by updating the Subprocessor website or, where applicable, by other reasonable means selected by Provider. If Company objects to such engagement on reasonable grounds relating to the protection of Personal Data in a written notice to Provider within 10 days after Provider’s notice of the engagement has been provided, Company and Provider will work together in good faith to find a mutually acceptable resolution to address such objection. If the parties are unable to reach a mutually acceptable resolution within a reasonable timeframe, Company may, as its sole and exclusive remedy, terminate the applicable Service Order (as defined in the Services Agreement) effective upon the date Provider begins use of such new Third Party Subprocessor solely with respect to the Service(s) that will use the proposed new Subprocessor and pay Provider for all amounts due and owing under the Agreement as of the date of such termination.
7. Data Protection Assessment; Reviews and Audits of Compliance
- Data Protection Assessment. Provider will (taking into account the nature of the Processing and the information available to Provider) reasonably assist Company in complying with its obligations under Applicable Data Protection Laws to carry out a data protection assessment, by (a) making available documentation describing relevant aspects of Provider’s data protection program, information security program and the security measures applied in connection therewith and (b) providing the other information agreed upon by the parties.
- Audit. Where required by Applicable Data Protection Laws, Provider will provide information reasonably necessary to demonstrate its compliance with this DPA upon Company’s reasonable request. Company may audit Provider’s compliance with its obligations under this DPA up to once per year and on such other occasions as may be required by Applicable Data Protection Laws, including where mandated by Company’s supervisory authority. Provider will contribute to such audits by providing Company or Company’s supervisory authority with the information and assistance reasonably necessary to conduct the audit. If a third party is to conduct the audit, Provider may object to the auditor if the auditor is, in Provider’s reasonable opinion, not independent, a competitor of Provider, or otherwise manifestly unsuitable. Such objection by Provider will require Company to appoint another auditor or conduct the audit itself. To request an audit, Company must submit a proposed audit plan to Provider at least four weeks in advance of the proposed audit date and any third-party auditor must sign a customary non-disclosure agreement mutually acceptable to the parties (such acceptance not to be unreasonably withheld) providing for the confidential treatment of all information exchanged in connection with the audit and any reports regarding the results or findings thereof. The proposed audit plan must describe the proposed scope, duration, and start date of the audit. Provider will review the proposed audit plan and provide Company with any concerns or questions (for example, any request for information that could compromise Provider security, privacy, employment or other relevant policies). Provider will work cooperatively with Company to agree on a final audit plan. Nothing in this Section 7 shall require Provider to breach any duties of confidentiality, waive any privilege, or disclose Provider’s commercially sensitive, confidential, or proprietary information or the personal data or confidential information of any other customer of Provider. If the controls or measures to be assessed in the requested audit are addressed in an SOC 2 Type 2, ISO, NIST or similar audit report performed by a qualified third party auditor within twelve (12) months of Company’s audit request and Provider has confirmed there have been no known material changes in the controls audited since the date of such report, Company agrees to accept such report in lieu of requesting an audit of such controls or measures. The audit must be conducted during regular business hours, subject to the agreed final audit plan and Provider’s safety, security or other relevant policies, and may not unreasonably interfere with Provider business activities. Company will promptly notify Provider of any non-compliance discovered during the course of an audit (and, for critical findings, will notify Provider as soon as practicable, even before the termination of the audit). Company will provide Provider any audit reports generated in connection with any audit under this Section 7, unless prohibited by Applicable Data Protection Laws or otherwise instructed by a supervisory authority, even in the case of audits without any findings of non-compliance. Company may use the audit reports only for the purposes of meeting Company’s regulatory audit requirements and/or confirming compliance with the requirements of this DPA. Any audits are at Company’s sole expense. Company shall reimburse Provider for any time expended by Provider and any third parties in connection with any audits or inspections under this Section 7 at Provider’s then-current professional services rates, which shall be made available to Company upon request. Company will be responsible for any fees charged by any auditor appointed by Company to execute any such audit.
8. Company Responsibilities
- Company Compliance. Company shall comply with its obligations under Applicable Data Protection Laws. Company shall ensure (and is solely responsible for ensuring) that its instructions in Section 3 comply with Applicable Data Protection Laws, and that Company has given all notices to, and has obtained and will obtain and continue to have, during the term, all necessary rights, lawful bases, authorizations, consents, and licenses from, individuals to whom Personal Data pertains and all other parties as required by applicable laws or regulations for Company to Process Personal Data and to authorize Provider to Process Personal Data as contemplated by the Agreement and this DPA. Company represents and warrants that Provider’s Processing of Company Personal Data in accordance with the Agreement will not violate Applicable Data Protection Laws or cause a breach of any agreement or obligations between Company and any third party.
- Prohibited Data. Company represents and warrants to Provider that Company Data does not and will not, without Provider’s prior written consent, contain any social security numbers or other government-issued identification numbers, protected health information subject to the Health Insurance Portability and Accountability Act (HIPAA) or other information regarding an individual’s medical history, mental or physical condition, or medical treatment or diagnosis by a health care professional; information about a non-United States person which originates in the European Economic Area, Switzerland, and/or the United Kingdom which could reasonably be considered “foreign intelligence information” as defined by 50 U.S.C. § 1801(e); health insurance information; biometric information; passwords for online accounts; credentials to any financial accounts; tax return data; credit reports or consumer reports; any payment card information subject to the Payment Card Industry Data Security Standard; information subject to the Gramm-Leach-Bliley Act, Fair Credit Reporting Act or the regulations promulgated under either such law; information subject to restrictions under Applicable Data Protection Laws governing Personal Data of children, including, without limitation, all information about children under 16 years of age; or any information that falls within any sensitive personal information as defined under the CCPA, sensitive data as defined under any other Applicable Data Protection Law, or special categories of data as defined in GDPR.
- Company Indemnity. Company will indemnify and defend Provider and its Affiliates against, and hold them harmless from, any third-party claim, and any resulting losses, liabilities, damages, costs, and expenses (including reasonable attorneys’ fees) finally awarded or agreed in settlement, to the extent arising from (i) Company’s failure to obtain or maintain the rights, lawful bases, notices, consents, or authority required for Provider to Process Personal Data as contemplated by the Agreement and this DPA; (ii) Company’s Processing instructions, where Provider’s compliance with them caused Provider to violate Applicable Data Protection Laws; or (iii) Company’s breach of Section 8(b) (Prohibited Data). This indemnity does not apply to the extent the claim arises from Provider’s breach of this DPA or its negligence or willful misconduct, and is subject to the limitations of liability in the Agreement.
9. Account Data
Provider acts as a controller with respect to information pertaining to Company’s or its End Users’ access to and use of the Services, (“Account Data”) and processes Account Data in accordance with its Privacy Policy available at: https://www.aurorasolar.com/privacy-policy/, not this DPA. Account Data is not Company Data and, for clarity, the Provider Privacy Policy does not apply to Company Data. This Section 9 shall survive termination of the Agreement.
10. Miscellaneous
- Service Optimization. Where permitted by Applicable Data Protection Laws, Provider may Process Personal Data: (i) for its internal uses to build, develop, or improve the quality of its services; (ii) to detect Information Security Incidents; and (iii) to protect against fraudulent or illegal activity.
- Aggregation and De-Identification. Provider may: (i) compile aggregated, anonymized and/or de-identified information in connection with providing the Services provided that such information cannot reasonably be used to identify Company or any data subject to whom Personal Data relates (“Aggregated and/or De-Identified Data”); and (ii) retain and use Aggregated and/or De-Identified Data for its lawful business purposes during and after the term of the Agreement.
- Limitation of Liability. For the avoidance of doubt and to the extent permitted by Applicable Data Protection Laws, each party’s liability and remedies under this DPA are subject to the aggregate liability limitations and damages exclusions set forth in the Agreement.
- Except as expressly modified by this DPA, the terms of the Agreement remain in full force and effect. In the event of any conflict or inconsistency between this DPA and the other terms of the Agreement, this DPA will govern. Notwithstanding anything in the Agreement or any order form entered in connection therewith to the contrary, the parties acknowledge and agree that Provider’s access to Personal Data does not constitute part of the consideration exchanged by the parties in respect of the Agreement. Notwithstanding anything to the contrary in the Agreement, any notices required or permitted to be given by Provider to Company under this DPA may be given (a) in accordance with any notice clause of the Service Agreement or this DPA; (b) to Provider’s primary points of contact with Company; or (c) to any email provided by Company for the purpose of providing it with Services-related communications or alerts. Company is solely responsible for ensuring that such email addresses are valid.
Annex 1 to DPA: EEA, Switzerland, and UK Annex
1. Processing of Data
- Subject Matter and Details of Processing. The parties acknowledge and agree that (i) the subject matter of the Processing under the Agreement is Provider’s provision of the Services; (ii) the duration of the Processing is from Provider’s receipt of Personal Data until deletion of all Personal Data by Provider in accordance with the Agreement; (iii) the nature and purpose of the Processing is to provide the Services; (iv) the data subjects to whom the Personal Data pertains are (1) residents of homes; (2) employees, contractors, and representatives of commercial businesses where Company or its partners plans to install a solar energy system; (3) employees, contractors, and representatives of Company and its Affiliates; and (4) other End Users and individuals interacting with the Services; and (v) the categories of personal data are name, contact details (including email, phone, and postal address), authorization credentials, address and geolocation, LIDAR data, map data, site survey data, design files, photos, plan sets, project documentation, product usage information, and other relevant household information or professional details of the data subjects.
- Roles and Regulatory Compliance; Authorization. The parties acknowledge and agree that (i) Provider is a processor of that Personal Data under European Data Protection Laws; (ii) Company is a controller (or a processor acting on the instructions of a controller) of that Personal Data under European Data Protection Laws; and (iii) each party will comply with the obligations applicable to it in such role under the European Data Protection Laws with respect to the Processing of that Personal Data. If Company is a processor, Company represents and warrants to Provider that Company’s instructions and actions with respect to Personal Data, including its appointment of Provider as another processor, have been authorized by the relevant controller.
- Provider’s Compliance with Instructions. Provider will Process Personal Data only in accordance with Company’s instructions stated in this DPA unless applicable European Data Protection Laws require otherwise, in which case Provider will notify Company (unless that law prohibits Provider from doing so on important grounds of public interest).
2. Impact Assessments and Consultations
Provider will (taking into account the nature of the Processing and the information available to Provider) reasonably assist Company in complying with its obligations under Articles 35 and 36 of the GDPR or UK GDPR, by (a) making available documentation describing relevant aspects of Provider’s information security program and the security measures applied in connection therewith and (b) providing the other information contained in the Agreement, including this DPA.
3. Data Transfers
- Data Processing Facilities. Provider may, subject to Section 3(b) (Transfers out of the EEA, Switzerland, and/or the UK), transfer, store, and Process Personal Data in the United States or anywhere Provider or its Subprocessors maintains facilities.
-
Transfers out of the EEA, Switzerland, and/or the UK. If Personal Data originating in the European Economic Area, Switzerland, and/or the United Kingdom is transferred by Company to Provider in a country that has not been found to provide an adequate level of protection under European Data Protection Laws, the parties agree that the transfer shall be governed by the Standard Contractual Clauses as supplemented by Annex 1-A attached hereto, the terms of which are incorporated herein by reference. Where the Standard Contractual Clauses are applicable and Company acts as a controller of Personal Data with Provider acting as a processor of Personal Data, each party shall comply with its obligations under Module Two of the Standard Contractual Clauses. Where the Standard Contractual Clauses are applicable and Company acts as a processor of Personal Data with Provider acting as a (sub)processor of Personal Data, each party shall comply with its obligations under Module Three of the Standard Contractual Clauses. By entering into the Services Agreement (including by accepting it electronically or continuing to use the Services), each party is deemed to have signed and agreed to the Standard Contractual Clauses to the extent that the Standard Contractual Clauses apply hereunder.
Notwithstanding the foregoing, the Standard Contractual Clauses (or obligations the same as those under the Standard Contractual Clauses) will not apply to the extent an alternative recognized compliance standard for the transfer of Personal Data outside the EEA, Switzerland, and/or the United Kingdom in accordance with European Data Protection Laws applies to the transfer. In the event of any conflict or inconsistency between (a) this Annex 1 and any other provision of this DPA, this Annex 1 will govern or (b) the Standard Contractual Clauses and any other provision of this Agreement, the Standard Contractual Clauses will govern.
Annex 1-A to DPA: Additional Terms for the Standard Contractual Clauses
This Annex 1-A forms part of the DPA and supplements the Standard Contractual Clauses. Capitalized terms not defined in this Annex 1-A have the meaning set forth in the DPA or the Agreement.
The parties agree that the following terms shall supplement the Standard Contractual Clauses:
1. Supplemental Terms
The parties agree that: (i) a new Clause 1(e) is added the Standard Contractual Clauses which shall read: “To the extent applicable hereunder, these Clauses also apply mutatis mutandis to the Parties’ processing of personal data that is subject to the Swiss Federal Act on Data Protection. Where applicable, references to EEA Member State law or EEA supervisory authorities shall be modified to include the appropriate reference under Swiss law as it relates to transfers of personal data that are subject to the Swiss Federal Act on Data Protection.”; (ii) a new Clause 1(f) is added to the Standard Contractual Clauses which shall read: “To the extent applicable hereunder, these Clauses, as supplemented by Annex III, also apply mutatis mutandis to the Parties’ processing of personal data that is subject to UK Data Protection Laws (as defined in Annex III).”; (iii) the optional text in Clause 7 is deleted; (iv) Option 1 in Clause 9 is struck and Option 2 is kept, and data importer must notify data exporter of any new Subprocessor in accordance with Section 6(c) of the DPA; (v) the optional text in Clause 11 is deleted; and (vi) in Clauses 17 and 18, the governing law and the competent courts are those of Ireland (for EEA transfers), Switzerland (for Swiss transfers), or England and Wales (for UK transfers).
2. Annex I
Annex I to the Standard Contractual Clauses shall read as follows:
A. List of Parties
Data Exporter: Company.
Address: As set forth in the Notices section of the Agreement or, if not set forth there, in Company’s account record with Provider.
Contact person’s name, position, and contact details: As set forth in the Notices section of the Agreement.
Activities relevant to the data transferred under these Clauses: The Services.
Role: Controller (Module Two), Processor (Module Three).
Data Importer: Provider.
Address: As set forth in the Notices section of the Agreement.
Contact person’s name, position, and contact details: As set forth in the Notices section of the Agreement.
Activities relevant to the data transferred under these Clauses: The Services.
Role: Processor.
B. Description of the Transfer
Categories of data subjects whose personal data is transferred: As set forth in Section 1(a) of Annex 1.
Categories of personal data transferred: As set forth in Section 1(a) of Annex 1.
Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialized training), keeping a record of access to the data, restrictions for onward transfers or additional security measures: To the parties’ knowledge, no sensitive data is transferred. Company is prohibited from submitting sensitive data without Provider’s prior written consent (see DPA Section 8(b) (Prohibited Data)).
The frequency of the transfer (e.g., whether the data is transferred on a one-off or continuous basis): Personal data is transferred in accordance with the standard functionality of the Services, or as otherwise agreed upon by the parties.
Nature of the processing: The Services, together with the additional Processing purposes set forth in the DPA.
Purpose(s) of the data transfer and further processing: The Services, together with the additional Processing purposes set forth in the DPA.
The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period: Data importer will retain personal data in accordance with the DPA.
For transfers to (sub-) processors, also specify subject matter, nature and duration of the processing: As set forth at the following URL: http://assets.aurorasolar.com/aurora-subprocessors.pdf.
C. Competent Supervisory Authority
The supervisory authority mandated by Clause 13. If no supervisory authority is mandated by Clause 13, then the Irish Data Protection Commission (DPC), and if this is not possible, then as otherwise agreed by the parties consistent with the conditions set forth in Clause 13.
D. Additional Data Transfer Impact Assessment Questions
Will data importer process any personal data that is transferred to the United States under the Clauses about a non-United States person that is “foreign intelligence information” as defined by 50 U.S.C. § 1801(e)?
Data exporter is prohibited from providing data importer with “foreign intelligence information.”
Is data importer subject to any laws in a country outside of the European Economic Area, Switzerland, and/or the United Kingdom where personal data is stored or accessed from that would interfere with data importer fulfilling its obligations under the Clauses? For example, FISA Section 702. If yes, please list these laws:
As of the effective date of the DPA, no court has found data importer to be eligible to receive process issued under the laws contemplated by this question, including FISA Section 702, and no such court action is pending.
Has data importer ever received a request from public authorities for information pursuant to the laws contemplated by the question above? If yes, please explain:
No.
Has data importer ever received a request from public authorities for personal data of individuals located in European Economic Area, Switzerland, and/or the United Kingdom? If yes, please explain:
No.
E. Data Transfer Impact Assessment Outcome
Taking into account the information and obligations set forth in the DPA and, as may be the case for a party, such party’s independent research, to the parties’ knowledge, the personal data originating in the European Economic Area, Switzerland, and/or the United Kingdom that is transferred pursuant to the Clauses to a country that has not been found to provide an adequate level of protection under applicable data protection laws is afforded a level of protection that is essentially equivalent to that guaranteed by applicable data protection laws.
F. Clarifying Terms
The parties agree that: (i) the certification of deletion required by Clause 8.5 and Clause 16(d) of the Standard Contractual Clauses will be provided upon data exporter’s written request and shall not apply to aggregated, anonymized, or deidentified data; (ii) the measures data importer is required to take under Clause 8.6(c) of the Standard Contractual Clauses will only cover data importer’s impacted systems; (iii) the audit described in Clause 8.9 of the Clauses shall be carried out in accordance with Section 7(b) of the DPA; (iv) under Module Three, data importer will communicate the information required under Clause 9(a) of the Standard Contractual Clauses to data exporter and data exporter will be responsible for communicating such information to the controller; (v) the termination right contemplated by Clause 14(f) and Clause 16(c) of the Standard Contractual Clauses will be limited to the termination of the Clauses; (vi) unless otherwise stated by data importer, data exporter will be responsible for communicating with data subjects pursuant to Clause 15.1(a) of the Standard Contractual Clauses; (vii) the information required under Clause 15.1(c) of the Standard Contractual Clauses will be provided upon data exporter’s written request; and (viii) notwithstanding anything to the contrary, data exporter will reimburse data importer for all costs and expenses incurred by data importer in connection with the performance of data importer’s obligations under Clause 15.1(b) and Clause 15.2 of the Standard Contractual Clauses without regard for any limitation of liability set forth in the Agreement.
3. Annex II
Annex II of the Standard Contractual Clauses shall read as follows:
Data importer shall implement and maintain technical and organizational measures designed to protect personal data in accordance with the DPA.
Pursuant to Clause 10(b), data importer will provide data exporter assistance with data subject requests in accordance with the DPA.
4. New Annex — UK Addendum
A new Annex shall be added to the Standard Contractual Clauses and shall read as follows:
The UK Information Commissioner’s Office International Data Transfer Addendum to the EU Commission Standard Contractual Clauses available at the following URL: https://ico.org.uk/media/for-organisations/documents/4019539/international-data-transfer-addendum.pdf (“UK Addendum”) is incorporated herein by reference.
Table 1: The start date in Table 1 is the effective date of the DPA. All other information required by Table 1 is set forth in Annex I, Section A of the Standard Contractual Clauses.
Table 2: The UK Addendum forms part of the version of the Approved EU SCCs which this UK Addendum is appended to including the Appendix Information, effective as of the effective date of the DPA.
Table 3: The information required by Table 3 is set forth in Annex I and II to the Standard Contractual Clauses.
Table 4: The parties agree that Importer may end the UK Addendum as set out in Section 19.
Annex 2 to DPA: California Annex
- For purposes of this Annex 2, the terms “business,” “commercial purpose,” “sell,” “service provider,” and “share” shall have the respective meanings given thereto in the CCPA, and “personal information” shall mean Personal Data that constitutes personal information governed by the CCPA.
- It is the parties’ intent that with respect to any personal information, Provider is a service provider.
- Company discloses or otherwise makes available Personal Data to Provider for the limited and specific purpose of Provider providing the Services to Company in accordance with the Agreement and this DPA. Provider shall: (i) comply with its applicable obligations under the CCPA; (ii) provide the same level of protection as required under the CCPA; (iii) notify Company if it can no longer meet its obligations under the CCPA; (iv) not “sell” or “share” Personal Data; (v) not retain, use, or disclose Company Personal Data for any purpose (including any commercial purpose) other than to provide the Services under the Agreement or as otherwise permitted under the CCPA; (vi) not retain, use, or disclose Personal Data outside of the direct business relationship between Company and Provider; and (vii) unless otherwise permitted by the CCPA, not combine Personal Data with personal information that Provider (a) receives from, or on behalf of, another person, or (b) collects from its own, independent consumer interaction. Provider will permit Company, upon reasonable request, to take reasonable and appropriate steps to ensure that Provider Processes Personal Data that is subject to this section in a manner consistent with a business’ obligations under the CCPA by requesting that Provider attest to its compliance with this CCPA section. Following any such request, Provider will promptly provide that attestation or notice about why it cannot provide it. If Company reasonably believes that Provider is engaged in unauthorized Processing of Personal Data that is subject to this section, Company will immediately notify Provider of such belief via email, and the parties will work together in good faith to remediate the allegedly violative Processing activities, if necessary.
- The parties acknowledge that Provider’s retention, use and disclosure of personal information authorized by Company’s instructions documented in the DPA are integral to Provider’s provision of the Services and the business relationship between the parties.
Annex 3 to DPA: Security Measures
- Organizational management responsible for the development, implementation and maintenance of Provider’s information security program.
- Data security controls which include, at a minimum, logical segregation of Personal Data, restricted (e.g., role-based) access and monitoring, and utilization of commercially available industry standard encryption technologies for Personal Data that is transmitted by Provider over public networks (i.e. the Internet) or when transmitted by Provider wirelessly or at rest in Provider’s environment or stored on portable or removable media (i.e., laptop computers, CD/DVD, USB drives, back-up tapes) by Provider.
- Logical access controls designed to manage electronic access to Personal Data and system functionality based on authority levels and job functions, (e.g., granting access on a need-to-know and least privilege basis, use of unique IDs and passwords for all users, periodic review and revoking/changing access promptly when employment terminates or changes in job functions occur).
- Password controls designed to manage and control password strength, expiration and usage including prohibiting users from sharing passwords and requiring that Provider’s passwords that are assigned to its employees.
- Physical and environmental security of data centers, server room facilities and other areas containing Personal Data which Provider operates or controls designed to: (i) protect Personal Data from unauthorized physical access, (ii) manage, monitor and log movement of persons into and out of Provider’s facilities, and (iii) guard against environmental hazards such as heat, fire and water damage.
- Operational procedures and controls to provide for configuration, monitoring and maintenance of technology and information systems which Process Personal Data, including secure disposal of systems and media to render all Personal Data contained therein as undecipherable or unrecoverable prior to final disposal or release from Provider’s possession.
- Change management procedures and tracking mechanisms designed to test, approve and monitor material changes to Provider’s technology and information assets which Process Personal Data.
- Incident management procedures designed to allow Provider to investigate, respond to, mitigate and notify of events related to Provider’s technology and information assets which Process Personal Data.
- Vulnerability assessment, patch management and threat protection technologies, and scheduled monitoring procedures designed to identify, assess, mitigate and protect against identified security threats, viruses and other malicious code.
- Business resiliency/continuity and disaster recovery procedures designed to maintain service and/or recovery from foreseeable emergencies or disasters.