Home

Careers

Log in

Book my demo

Contents

Data Processing Addendum

Version 1.1 · Takes effect · Last updated

This Data Processing Addendum (“DPA”) forms part of the agreement between Solesca Energy, Inc. (“Solesca,” “Processor,” “we,” “us,” or “our”) and the customer (“Customer” or “Controller”) using the Services.

This DPA applies when Solesca processes Personal Data on behalf of Customer in connection with the Services.

Version 1.1 replaces version 1.0 (June 2026); the only change is Section 7.


1. Definitions

Applicable Data Protection Law means all laws and regulations applicable to the processing of Personal Data, including where applicable the GDPR, UK GDPR, Swiss data protection laws, and applicable U.S. state privacy laws.

Personal Data, Processing, Controller, Processor, Data Subject, and Subprocessor have the meanings assigned under applicable law.

2. Roles of the Parties

Customer acts as Controller (or equivalent legal role). Solesca acts as Processor (or equivalent legal role) with respect to Personal Data processed through the Services.

3. Scope and Purpose of Processing

Solesca will process Personal Data only to provide, maintain, support, secure, and improve the Services; comply with Customer’s documented instructions; comply with applicable law; and otherwise perform its obligations under the Agreement.

Solesca will not sell Personal Data or share Personal Data for cross-context behavioral advertising.

4. Customer Responsibilities

Customer is responsible for ensuring it has all required rights, notices, consents, and legal bases for Personal Data submitted to the Services and for complying with Applicable Data Protection Law.

5. Processor Obligations

Solesca shall process Personal Data only on documented instructions from Customer unless otherwise required by law; ensure authorized personnel are bound by confidentiality obligations; maintain appropriate technical and organizational measures; assist Customer with data subject requests and compliance obligations taking into account the nature of the processing and information available to Solesca; and make available information reasonably necessary to demonstrate compliance with this DPA.

6. Security Measures

Solesca will maintain reasonable and appropriate administrative, technical, and organizational safeguards designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access.

7. Subprocessors

7.1 General authorization:

Customer provides a general authorization for Solesca to engage Subprocessors to process Personal Data in connection with the Services. Solesca maintains the current list of Subprocessors at solesca.com/legal/subprocessors.

7.2 Notice of changes:

Before a new Subprocessor processes Customer Personal Data, Solesca will update that list and give at least thirty (30) days’ notice by email to the Owners and Admins of Customer’s organization.

7.3 Objection:

Customer may object in writing within the notice period on reasonable data-protection grounds. Solesca will work with Customer in good faith to address the objection. If Solesca cannot reasonably accommodate it, Customer may terminate the affected Services by written notice before the change takes effect, and Solesca will refund any prepaid subscription fees for the unused remainder of the term on a pro-rata basis. SOL Credits are not refundable.

7.4 Emergency replacement:

Where a Subprocessor must be replaced without advance notice to keep the Services secure or available, Solesca may do so and will notify Customer as soon as practicable. The objection process above then applies from the date of that notice.

7.5 Responsibility:

Solesca shall impose data protection obligations on Subprocessors that are substantially similar to those in this DPA and remains responsible for the performance of its Subprocessors’ obligations to the extent required by law.

8. Security Incidents

Solesca will notify Customer without undue delay and, where feasible, within seventy-two (72) hours after becoming aware of a confirmed Security Incident affecting Personal Data processed under this DPA. Such notice will include available information regarding the nature of the incident and mitigation measures.

9. Data Subject Requests

Taking into account the nature of the processing and information available to Solesca, Solesca will provide reasonable assistance to Customer in responding to lawful requests from Data Subjects.

10. Audits

Upon reasonable written request no more than once annually, Customer may request documentation reasonably necessary to demonstrate Solesca’s compliance with this DPA. On-site audits may occur only where required by law or where documentation is insufficient to demonstrate compliance.

11. International Transfers

Where required, the parties agree that the applicable European Commission Standard Contractual Clauses, together with any required UK or Swiss addenda, are incorporated into this DPA by reference.

12. Return and Deletion of Data

Upon termination of the Services and Customer request, Solesca will delete or return Personal Data unless retention is required by law or for legitimate backup, security, legal, or recordkeeping purposes.

13. U.S. Privacy Laws

To the extent applicable, Solesca acts as a Service Provider or Processor and will comply with obligations applicable to service providers and processors under relevant U.S. privacy laws.

14. Liability

The liability of each party under this DPA is subject to the limitations of liability contained in the Agreement.

15. Order of Precedence

If there is a conflict between this DPA and the Agreement regarding Personal Data processing, this DPA controls.

16. Annex 1 – Description of Processing

Subject Matter
Provision of Solesca’s software and related services.
Duration
For the duration of the Agreement and any applicable retention period.
Categories of Data Subjects
Customer personnel, end users, contractors, business contacts, and other individuals whose Personal Data is submitted to the Services.
Categories of Personal Data
Names, email addresses, usernames, account identifiers, business contact information, customer-generated content, and other Personal Data submitted by Customer.
Nature and Purpose
Hosting, storage, analysis, support, maintenance, transmission, and other processing necessary to provide the Services.
Sensitive Data
Customer shall not provide special categories of personal data unless expressly authorized by Solesca in writing.

17. Annex 2 – Technical and Organizational Measures

  • Role-based access controls
  • Multi-factor authentication for administrative accounts
  • Encryption in transit using TLS
  • Encryption at rest where supported by infrastructure providers
  • Logging and monitoring of production systems
  • Vulnerability and patch management processes
  • Personnel confidentiality obligations
  • Backup and disaster recovery procedures
  • Security incident response procedures
  • Vendor and subprocessor review processes

LEGAL

Terms of Service

Legal

CONTACT

Email: contact@solesca.com

Phone: (312) 899 - 6750

Chicago, IL 60659

SOCIAL

Book a demo



Email: contact@solesca.com

Phone: (312) 899 - 6750

Chicago, IL 60659


© 2026 Solesca Energy, Inc.