Contents
Version 1.1 · Takes effect · Last updated
This Data Processing Addendum (“DPA”) forms part of the agreement between Solesca Energy, Inc. (“Solesca,” “Processor,” “we,” “us,” or “our”) and the customer (“Customer” or “Controller”) using the Services.
This DPA applies when Solesca processes Personal Data on behalf of Customer in connection with the Services.
Version 1.1 replaces version 1.0 (June 2026); the only change is Section 7.
Applicable Data Protection Law means all laws and regulations applicable to the processing of Personal Data, including where applicable the GDPR, UK GDPR, Swiss data protection laws, and applicable U.S. state privacy laws.
Personal Data, Processing, Controller, Processor, Data Subject, and Subprocessor have the meanings assigned under applicable law.
Customer acts as Controller (or equivalent legal role). Solesca acts as Processor (or equivalent legal role) with respect to Personal Data processed through the Services.
Solesca will process Personal Data only to provide, maintain, support, secure, and improve the Services; comply with Customer’s documented instructions; comply with applicable law; and otherwise perform its obligations under the Agreement.
Solesca will not sell Personal Data or share Personal Data for cross-context behavioral advertising.
Customer is responsible for ensuring it has all required rights, notices, consents, and legal bases for Personal Data submitted to the Services and for complying with Applicable Data Protection Law.
Solesca shall process Personal Data only on documented instructions from Customer unless otherwise required by law; ensure authorized personnel are bound by confidentiality obligations; maintain appropriate technical and organizational measures; assist Customer with data subject requests and compliance obligations taking into account the nature of the processing and information available to Solesca; and make available information reasonably necessary to demonstrate compliance with this DPA.
Solesca will maintain reasonable and appropriate administrative, technical, and organizational safeguards designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access.
Customer provides a general authorization for Solesca to engage Subprocessors to process Personal Data in connection with the Services. Solesca maintains the current list of Subprocessors at solesca.com/legal/subprocessors.
Before a new Subprocessor processes Customer Personal Data, Solesca will update that list and give at least thirty (30) days’ notice by email to the Owners and Admins of Customer’s organization.
Customer may object in writing within the notice period on reasonable data-protection grounds. Solesca will work with Customer in good faith to address the objection. If Solesca cannot reasonably accommodate it, Customer may terminate the affected Services by written notice before the change takes effect, and Solesca will refund any prepaid subscription fees for the unused remainder of the term on a pro-rata basis. SOL Credits are not refundable.
Where a Subprocessor must be replaced without advance notice to keep the Services secure or available, Solesca may do so and will notify Customer as soon as practicable. The objection process above then applies from the date of that notice.
Solesca shall impose data protection obligations on Subprocessors that are substantially similar to those in this DPA and remains responsible for the performance of its Subprocessors’ obligations to the extent required by law.
Solesca will notify Customer without undue delay and, where feasible, within seventy-two (72) hours after becoming aware of a confirmed Security Incident affecting Personal Data processed under this DPA. Such notice will include available information regarding the nature of the incident and mitigation measures.
Taking into account the nature of the processing and information available to Solesca, Solesca will provide reasonable assistance to Customer in responding to lawful requests from Data Subjects.
Upon reasonable written request no more than once annually, Customer may request documentation reasonably necessary to demonstrate Solesca’s compliance with this DPA. On-site audits may occur only where required by law or where documentation is insufficient to demonstrate compliance.
Where required, the parties agree that the applicable European Commission Standard Contractual Clauses, together with any required UK or Swiss addenda, are incorporated into this DPA by reference.
Upon termination of the Services and Customer request, Solesca will delete or return Personal Data unless retention is required by law or for legitimate backup, security, legal, or recordkeeping purposes.
To the extent applicable, Solesca acts as a Service Provider or Processor and will comply with obligations applicable to service providers and processors under relevant U.S. privacy laws.
The liability of each party under this DPA is subject to the limitations of liability contained in the Agreement.
If there is a conflict between this DPA and the Agreement regarding Personal Data processing, this DPA controls.
Book a demo
Email: contact@solesca.com
Phone: (312) 899 - 6750
Chicago, IL 60659
Email: contact@solesca.com
Phone: (312) 899 - 6750
Chicago, IL 60659
© 2026 Solesca Energy, Inc.