Data Processing Agreement

This Data Processing Agreement (the "DPA") forms part of the agreement between the customer ("Controller") and Electryion ("Processor") under which the Controller uses the Electryion platform (the "Service"). It sets out the terms on which Electryion processes personal data on behalf of the Controller and is intended to comply with Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR").

By using the Service, the Controller accepts this DPA. For a counter-signed version of this DPA, contact [email protected].

1. Definitions

Terms not defined in this DPA have the meaning given in the GDPR. "Personal Data", "Data Subject", "Processing", "Controller" and "Processor" have the meanings set out in Article 4 GDPR. "Sub-Processor" means any third party engaged by Electryion to process Personal Data on behalf of the Controller.

2. Subject Matter and Duration

Electryion processes Personal Data on behalf of the Controller solely to deliver the Service. Processing lasts for the term of the Controller's subscription and ends no later than 30 days after account termination, except where retention is required by law (for example tax records).

3. Nature and Purpose of Processing

4. Categories of Personal Data

5. Categories of Data Subjects

6. Obligations of the Controller

The Controller warrants that it has a lawful basis under the GDPR for all Personal Data it submits to the Service, has provided required notices to Data Subjects, and will instruct Electryion only to perform processing that is itself lawful.

7. Obligations of Electryion (Processor)

Electryion will:

8. Sub-Processors

The Controller provides general authorisation for Electryion to engage the Sub-Processors listed at https://electryion.com/sub-processors. Electryion will:

9. International Transfers

Where Electryion or a Sub-Processor transfers Personal Data outside the European Economic Area, the transfer is governed by the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914), which are hereby incorporated by reference. The Controller is the data exporter and Electryion is the data importer.

10. Security Measures

Electryion implements and maintains the technical and organisational measures set out in Annex A. The Controller acknowledges that the Service evolves; Electryion may update its measures over time provided the updated measures offer an equivalent or higher level of protection.

11. Audit Rights

Electryion will make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA, including summaries of its technical and organisational measures, Sub-Processor list, and security incidents involving the Controller. In addition, on reasonable written request and not more than once every 12 months, Electryion will permit an audit carried out by the Controller or an independent auditor, subject to reasonable confidentiality and scheduling constraints. The Controller bears the costs of any such audit unless the audit reveals a material breach.

12. Data Subject Requests

If Electryion receives a Data Subject request relating to the Controller's data, Electryion will promptly forward the request to the Controller and will not respond substantively except on the Controller's documented instructions or as required by law.

13. Return or Deletion of Data

On termination of the Service, Electryion will delete or return all Personal Data processed on behalf of the Controller within 30 days, except where continued retention is required by law. Export tooling is available through the Controller's account settings and on request.

14. Liability

Each party's liability under this DPA is subject to the limitations of liability in the main agreement between the parties.

15. Precedence

In the event of a conflict between this DPA and the main agreement, this DPA prevails for matters concerning the processing of Personal Data.

16. Contact

All notices under this DPA, including breach notifications, should be sent to [email protected]. Security issues may also be reported to [email protected].

Annex A - Technical and Organisational Measures

A.1 Access Control

A.2 Encryption

A.3 Application Security

A.4 Monitoring and Audit

A.5 Personnel

A.6 Incident Response

A.7 Business Continuity

A.8 Data Minimisation