Data Processing Agreement

Last updated: May 1, 2023

1. Introduction

This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("Data Controller") and Solar AI ("Data Processor") regarding the processing of personal data in accordance with applicable data protection laws, including the General Data Protection Regulation (GDPR).

2. Definitions

Terms such as "Personal Data", "Data Subject", "Processing", "Controller", "Processor", and "Supervisory Authority" shall have the meanings given to them in the applicable data protection laws.

3. Processing of Personal Data

3.1 The Data Processor shall only process Personal Data on documented instructions from the Data Controller, including with regard to transfers of Personal Data to a third country or an international organization, unless required to do so by Union or Member State law to which the Data Processor is subject.

3.2 The Data Processor shall immediately inform the Data Controller if, in its opinion, an instruction infringes applicable data protection laws.

4. Purpose and Nature of Processing

4.1 The purpose of the processing is to provide the services described in the Terms of Service.

4.2 The types of Personal Data processed may include:

  • Contact information (name, email address, phone number)
  • Professional information (company name, job title)
  • Customer information included in proposals
  • Location data for solar system performance calculations

4.3 The categories of Data Subjects whose Personal Data may be processed include:

  • The Data Controller's employees and representatives
  • The Data Controller's customers or prospective customers

5. Confidentiality

5.1 The Data Processor shall ensure that persons authorized to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

6. Security of Processing

6.1 The Data Processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of personal data
  • The ability to ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems and services
  • The ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident
  • A process for regularly testing, assessing, and evaluating the effectiveness of technical and organizational measures for ensuring the security of the processing

7. Sub-processors

7.1 The Data Processor shall not engage another processor without prior specific or general written authorization of the Data Controller.

7.2 Where the Data Processor engages another processor for carrying out specific processing activities on behalf of the Data Controller, the same data protection obligations as set out in this DPA shall be imposed on that other processor.

8. Data Subject Rights

8.1 The Data Processor shall assist the Data Controller in responding to requests from Data Subjects exercising their rights under applicable data protection laws.

9. Data Breach Notification

9.1 The Data Processor shall notify the Data Controller without undue delay after becoming aware of a personal data breach.

9.2 The Data Processor shall assist the Data Controller in ensuring compliance with the obligations pursuant to Articles 32 to 36 of the GDPR.

10. Deletion or Return of Personal Data

10.1 At the choice of the Data Controller, the Data Processor shall delete or return all the Personal Data to the Data Controller after the end of the provision of services relating to processing, and delete existing copies unless Union or Member State law requires storage of the Personal Data.

11. Audit Rights

11.1 The Data Processor shall make available to the Data Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 of the GDPR and allow for and contribute to audits, including inspections, conducted by the Data Controller or another auditor mandated by the Data Controller.

12. International Transfers

12.1 The Data Processor shall not transfer Personal Data outside the European Economic Area (EEA) without the prior written consent of the Data Controller, and only in compliance with applicable data protection laws.

13. Governing Law

13.1 This DPA shall be governed by the laws of Australia, without regard to its conflict of law provisions.

14. Contact Information

If you have any questions about this Data Processing Agreement, please contact us at:

Email: privacy@solarai.com
Address: 123 Solar Street, Sydney, NSW 2000, Australia