DATA PROCESSING ADDENDUM

Last updated August 27, 2026.

This Data Processing Addendum (the DPA) forms part of the Solarise Terms of Serviceor another agreement governing a Customer's use of the Services (the Agreement). It applies when Solarise Technologies d.o.o. processes personal data for Customer as a processor or service provider.

Capitalised terms not defined here have the meaning given in the Agreement. If this DPA conflicts with the Agreement about processing of Customer Personal Data, this DPA controls.

1. DEFINITIONS AND ROLES

Applicable Data Protection Law means laws applicable to the processing of Customer Personal Data, including, where applicable, the EU General Data Protection Regulation 2016/679 (GDPR), the UK GDPR and Data Protection Act 2018, the Serbian Law on Personal Data Protection, and applicable US state privacy laws.

Customer Personal Data means personal data contained in Customer Data that Solarise processes for Customer. The terms controller, processor, data subject, process, personal data and supervisory authority have the meanings given by Applicable Data Protection Law. Where those terms do not apply, controller includes business and processor includes service provider.

Customer is the controller of Customer Personal Data and Solarise is its processor. Customer determines the purposes and essential means of processing and is responsible for lawful instructions, notices, lawful bases, consents and data-subject requests. Customer's use and configuration of the Services are documented instructions to Solarise.

2. PROCESSING INSTRUCTIONS

Solarise will process Customer Personal Data only to provide, secure, support and improve the Services; perform the Agreement; comply with Customer's documented instructions; and comply with applicable law. Solarise will notify Customer if we believe an instruction infringes Applicable Data Protection Law and may pause the affected processing until the parties resolve the issue.

If law requires processing outside Customer's instructions, Solarise will notify Customer before processing unless the law prohibits notice. Solarise will not sell Customer Personal Data, share it for cross-context behavioural advertising, or retain, use or disclose it outside the direct business relationship except as permitted by Applicable Data Protection Law and the Agreement.

3. CONFIDENTIALITY

Solarise will ensure that personnel authorised to process Customer Personal Data are bound by confidentiality obligations and receive appropriate privacy and security guidance. Access is limited to personnel who need it to perform the Services.

4. SECURITY

Taking into account the state of the art, implementation costs, the nature, scope, context and purposes of processing, and the risks to individuals, Solarise will maintain appropriate technical and organisational measures. The current baseline measures are described in Annex 2. Customer is responsible for securely configuring its account, managing its users and determining whether the Services are appropriate for the data it submits.

5. PERSONAL DATA BREACHES

Solarise will notify Customer without undue delay after becoming aware of a confirmed personal data breach affecting Customer Personal Data. The notice will include available information reasonably needed for Customer to meet its legal obligations, such as the nature of the breach, affected data and individuals, likely consequences, mitigation and a contact point. Information may be provided in phases as it becomes available.

Solarise will take reasonable steps to contain, investigate and mitigate the breach. Notice is not an acknowledgement of fault or liability. Customer is responsible for notifications to individuals and authorities unless the parties agree otherwise.

6. SUBPROCESSORS

Customer gives Solarise general written authorisation to appoint subprocessors. Solarise will require each subprocessor to protect Customer Personal Data under obligations no less protective in substance than those applicable to Solarise under this DPA. Solarise remains responsible for its subprocessor's performance to the extent required by Applicable Data Protection Law.

Current subprocessors used for relevant features include Microsoft Azure and Azure OpenAI (AI and search), Twilio SendGrid (email), Twilio and Infobip (SMS and communications), Google, Apple, Azure Maps, Mapbox and Getmapping (mapping, geocoding and imagery), LlamaIndex/LlamaParse (document parsing), and LangSmith (AI diagnostics and observability). Only subprocessors needed for the features and region in use receive Customer Personal Data.

We will provide at least 30 days' notice before a new subprocessor begins processing Customer Personal Data, normally by email or in-product notice. Customer may make a reasonable, documented objection on data-protection grounds during that period. The parties will work in good faith on a reasonable solution. If none is available, Customer may stop using the affected feature or terminate it without penalty and receive a pro-rata refund of prepaid fees for the unused period.

7. INTERNATIONAL TRANSFERS

Solarise may process Customer Personal Data in Serbia and in countries where authorised subprocessors operate. For a restricted transfer from the EEA to a country without an adequacy decision, the European Commission's 2021 Standard Contractual Clauses are incorporated by reference, using Module Two (controller to processor), with Customer as data exporter and Solarise as data importer. The optional docking clause applies, option 2 for subprocessor authorisation applies with the notice period in section 6, the law of Ireland governs clause 17, and the courts of Ireland are selected under clause 18. Those choices apply only where the SCCs require an EU Member State's law and courts; the Agreement's Serbian dispute terms otherwise remain unchanged. Annexes 1 and 2 of this DPA complete the corresponding SCC annexes.

For restricted UK transfers, the UK International Data Transfer Addendum to the EU SCCs is incorporated by reference. The parties will cooperate in good faith to implement a replacement transfer mechanism or supplementary safeguards if required by law.

8. DATA-SUBJECT REQUESTS

Taking into account the nature of processing, Solarise will provide reasonable assistance through available product functionality and other proportionate measures so Customer can respond to requests to access, correct, delete, restrict, object to or port Customer Personal Data. If Solarise receives a request directly, we will refer it to Customer and will not respond substantively unless Customer instructs us or law requires it.

9. COMPLIANCE ASSISTANCE AND AUDITS

Taking into account the nature of processing and information available to us, Solarise will reasonably assist Customer with security, breach notifications, data-protection impact assessments and prior consultations required by Applicable Data Protection Law.

On reasonable written request, Solarise will provide information needed to demonstrate compliance with this DPA. No more than once per year, unless a breach or regulator requires more, Customer may request an audit by an independent auditor bound by confidentiality. Audits must use reasonable advance notice, avoid disruption and protect other customers' and Solarise's confidential information. Customer pays its audit costs; Solarise pays the cost of correcting a material non-compliance it caused.

10. RETURN AND DELETION

During the Agreement, Customer may export available Customer Personal Data using product tools or by requesting reasonable assistance. After termination, Solarise will make the data available for retrieval for at least 30 days, then delete or irreversibly de-identify it from active systems within a reasonable period, unless Customer requests earlier deletion or law requires retention. Residual backup copies remain protected, are not restored for ordinary use and are deleted as backups rotate.

11. GOVERNMENT REQUESTS

Unless prohibited by law, Solarise will notify Customer of a legally binding request for Customer Personal Data. We will review requests for validity, challenge unlawful or disproportionate requests where there are reasonable grounds, and disclose only data legally required.

12. LIABILITY AND TERMINATION

The liability limitations and dispute provisions in the Agreement apply to this DPA, except to the extent Applicable Data Protection Law prohibits a limitation. This DPA terminates when Solarise no longer processes Customer Personal Data, but confidentiality, deletion, audit and transfer obligations survive as necessary.

ANNEX 1 — PROCESSING DETAILS

Subject matter and duration: processing Customer Personal Data to provide the Services for the term of the Agreement and the limited post-termination period described above.

Nature and purpose: collecting, recording, organising, structuring, storing, adapting, retrieving, consulting, analysing, generating, transmitting, making available, securing, backing up, exporting, deleting and otherwise processing data to operate solar lead, calculator, proposal, CRM, communication, AI and support features.

Data subjects: Customer personnel, authorised users, leads, prospects, end users, property owners, customers, suppliers and other people whose data Customer submits.

Data categories: identity and contact details; account and authentication information; property address, coordinates, imagery and characteristics; energy use and bills; product, system, financing, quote and proposal information; communications, chat content, documents, notes and support data; device, usage and security data; and integration data. Special-category data is not intended for processing unless separately agreed in writing.

Processing frequency: continuous or as initiated by Customer and its users during use of the Services.

ANNEX 2 — TECHNICAL AND ORGANISATIONAL MEASURES

  • role-based and least-privilege access controls;
  • unique accounts, password hashing and session-security controls;
  • encryption in transit using current transport-security protocols;
  • production access restrictions, environment separation and secret management;
  • logging, monitoring, abuse prevention and incident-response processes;
  • backup, restoration and continuity measures appropriate to the Service;
  • secure development, code review, dependency management and vulnerability remediation processes;
  • subprocessor due diligence and contractual privacy safeguards;
  • personnel confidentiality and security awareness; and
  • data minimisation, retention controls and secure deletion or de-identification.

CONTACT

Privacy and DPA requests may be sent to [email protected].