Effective Date: Concluded dynamically and taking effect immediately upon the Controller’s electronic acceptance (via “Click-wrap” execution on the Processor’s platform) or upon the placement of the first Service order, whichever occurs earlier (the “Effective Date”).
This Data Processing Agreement (“DPA”) is entered into by and between:
The Processor and the Controller are collectively referred to as the “Parties” and individually as a “Party.”
NOW, THEREFORE, IT IS AGREED AS FOLLOWS:
Capitalized terms used but not defined in this DPA shall have the meanings ascribed to them in the GDPR.
The Processor shall process Personal Data exclusively on behalf of and in accordance with the documented instructions of the Controller, including with respect to transfers of Personal Data to a third country, unless required to do so by European Union or Member State law to which the Processor is subject; in such a case, the Processor shall inform the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest. The Agreement, this DPA, and the parameters configured by the Client in the portal constitute the Controller’s complete initial instructions to the Processor.
The Processor shall immediately inform the Controller if, in its opinion, an instruction infringes the GDPR or other applicable Union or Member State data protection provisions. In such event, the Processor shall be entitled to suspend execution of the affected instruction until it is confirmed, amended, or withdrawn by the Controller, without such suspension constituting a breach of this DPA or the Agreement.
The details of the processing operations (categories of data, data subjects, and nature of processing) are specified in Annex I of this DPA, which forms an integral part hereof.
The Controller represents, warrants, and covenants that it has obtained full, explicit, valid, and GDPR-compliant consent (or possesses an unassailable alternative legal basis under Article 6 of the GDPR) from the End-Consumers to collect, process, and transfer their geographic, structural, and technical data to third-party engineering partners, specifically including the Processor.
The Controller maintains sole responsibility for the accuracy, quality, and legality of the Personal Data provided to the Processor. The Controller shall, upon reasonable request, demonstrate to the Processor that it has obtained the necessary consents or legal bases.
The Controller shall defend, indemnify, and hold harmless Lion Solar, its affiliates, successors, and directors against any and all direct or indirect losses, regulatory fines (including those issued by supervisory authorities), damages, liabilities, claims, and legal costs arising out of or resulting from:
Notwithstanding Sections 3.1 to 3.3, the Parties acknowledge that, under Article 82 GDPR, each Party bears direct statutory liability towards Data Subjects and Supervisory Authorities for damage caused by processing that infringes the GDPR. Accordingly, and to the extent required for this DPA to remain valid and enforceable:
The Processor shall retain PII (End-Consumer Name, physical address, Phone, and Email) only for the duration necessary to deliver the specific project and perform quality assurance. Within thirty (30) days following the final delivery of the respective project to the Client, the Processor shall permanently delete, mask, or scrub all PII from its production systems.
End-of-Services Return or Deletion (GDPR Article 28(3)(g)). Without prejudice to the foregoing, upon termination or expiry of the Agreement, or at any time upon the Controller’s written request, the Processor shall, at the choice of the Controller, delete or return all Personal Data to the Controller and delete all existing copies, unless Union or Member State law to which the Processor is subject requires storage of the Personal Data. This obligation does not apply to Anonymized Technical Data that has been effectively anonymized in accordance with Section 1 and Section 4.2, which by definition no longer constitutes Personal Data.
The Parties explicitly acknowledge and agree that Anonymized Technical Data does not constitute Personal Data under the GDPR once, and only to the extent that, the anonymization process meets the irreversibility standard set out in Section 1 (Recital 26 GDPR). Until that standard is met, the data shall be treated as Personal Data and shall remain fully subject to this DPA. The Processor bears the burden of demonstrating that the anonymization process is effective and resistant to re-identification, and shall not commercialize, license, or transfer such data to any third party until effective anonymization has been achieved.
[Client Data Upload] ➔ [Service Execution] ➔ [Project Delivery]
│
┌──────────┴──────────┐
(Within 30 Days) (Perpetual License)
▼ ▼
[PII Purged] [Anonymized Data]
(Name, Email,Phone) (Coordinates, Roof Angles, Hardware)
The Controller explicitly acknowledges and approves the Processor’s operational architecture:
The Controller provides its general written authorization for the engagement of Sub-processors. The Processor shall maintain a current list of Sub-processors (accessible upon request or via the Client Portal) and shall inform the Controller of any intended addition or replacement of a Sub-processor, giving the Controller a reasonable period (no less than fourteen (14) days) to object on reasonable, data-protection-related grounds before the new Sub-processor begins processing. If the Controller raises a reasonable objection that the Parties cannot resolve, the Controller may suspend or terminate the affected Services without penalty.
Where the Processor engages a Sub-processor, it shall do so by way of a written contract imposing on the Sub-processor the same data protection obligations as set out in this DPA, in particular providing sufficient guarantees to implement appropriate technical and organizational measures meeting the requirements of the GDPR. Where a Sub-processor fails to fulfil its data protection obligations, the Processor shall remain fully liable to the Controller for the performance of that Sub-processor’s obligations.
The Controller hereby authorizes the transfer of Client Data to Turkey for the purpose of executing the productized engineering services. The Parties acknowledge that, as at the Effective Date, Turkey is not the subject of an adequacy decision under Article 45 GDPR. Accordingly, the Processor guarantees that such transfers are governed by appropriate safeguards under Article 46 GDPR, specifically the European Commission’s Standard Contractual Clauses (SCCs) (Module Two and/or Module Three as applicable), which the Processor undertakes to have duly executed and in force between the relevant exporting and importing entities prior to any transfer. The SCCs are incorporated into this DPA by reference and, in the event of any conflict between the SCCs and this DPA, the SCCs shall prevail in respect of the relevant transfer.
The Processor shall, where required, conduct and document a transfer impact assessment and implement any necessary supplementary technical, contractual, and organizational measures to ensure that the transferred Personal Data enjoys a level of protection essentially equivalent to that guaranteed within the EEA, consistent with EDPB Recommendations 01/2020. The reference to “equivalent legal mechanisms” shall mean only other transfer tools expressly recognized under Chapter V GDPR (such as binding corporate rules or an approved certification or code of conduct), and shall not be construed to permit transfers absent a valid Article 46 safeguard.
The Controller acknowledges that the engineering team is situated entirely outside the European Union (Turkey). This DPA and the provision of Services create no employment relationship, European labor law liabilities, or severance exposures for the Controller, the Processor, or any future acquirer of the Processor.
The Processor shall implement and maintain appropriate technical and organizational measures to protect Client Data against unauthorized or unlawful processing and against accidental loss, destruction, damage, alteration, or disclosure, as detailed in Annex II.
The Processor shall ensure that all personnel authorized to process Client Data have committed themselves to strict confidentiality obligations or are under an appropriate statutory obligation of confidentiality.
The Processor shall notify the Controller without undue delay, and in any event immediately after becoming aware of any accidental, unauthorized, or unlawful acquisition, destruction, loss, alteration, or disclosure of Personal Data (a “Personal Data Breach”). The Processor shall provide the Controller with reasonable assistance and necessary information to allow the Controller to comply with its regulatory breach notification obligations under the GDPR.
Taking into account the nature of the processing, the Processor shall assist the Controller by appropriate technical and organizational measures, insofar as this is possible, for the fulfilment of the Controller’s obligation to respond to requests from Data Subjects exercising their rights under Chapter III GDPR (including access, rectification, erasure, restriction, data portability, and objection). If a Data Subject submits such a request directly to the Processor, the Processor shall, without undue delay, forward the request to the Controller and shall not respond to it itself except on the Controller’s documented instructions.
Taking into account the nature of processing and the information available to it, the Processor shall assist the Controller in ensuring compliance with its obligations pursuant to Articles 32 to 36 GDPR, including security of processing, notification of Personal Data Breaches to the Supervisory Authority and to Data Subjects, the conduct of data protection impact assessments (DPIAs), and prior consultation with the Supervisory Authority where required.
The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR and shall allow for and contribute to audits, including inspections, conducted by the Controller or an independent third-party auditor mandated by the Controller. Such audits shall take place on reasonable prior written notice (no less than thirty (30) days, save where a Personal Data Breach or Supervisory Authority requirement justifies shorter notice), no more than once per calendar year absent reasonable cause, during normal business hours, and subject to appropriate confidentiality undertakings so as not to compromise the security or confidentiality of other clients’ data. The Processor may satisfy audit requests, where appropriate, by providing recognized third-party certifications or audit reports (e.g., ISO/IEC 27001 or SOC 2).
This DPA, along with the underlying terms of service, is fully, freely, and automatically assignable by Lion Solar to any future buyer, parent company, investor, or successor-in-interest in the event of an acquisition, merger, corporate reorganization, or sale of substantially all of its assets.
Notwithstanding any confidentiality provisions contained in this DPA or the main service agreement, Lion Solar is explicitly permitted to disclose anonymized or aggregated operational metrics, historical contract volumes, platform activity logs, and transaction history to potential institutional buyers, venture capital investors, private equity firms, or professional auditors during an M&A due diligence process.
This DPA is executed digitally via a “Click-wrap” mechanism. By checking the designated box (e.g., “I have read and agree to the Data Processing Agreement”) upon registering an account or placing an order on the Lion Solar client portal, the Controller legally binds itself to the entirety of this DPA. No physical signatures or manual completion of placeholders are required to make this DPA a legally binding and enforceable agreement.
The Parties agree that the electronic record of the Controller’s acceptance of this DPA, or the execution of a Master Services Agreement that references this DPA, constitutes valid execution under all applicable digital signature laws, including the EU eIDAS Regulation (Regulation (EU) No 910/2014).
The Processor shall maintain an immutable, automated electronic log recording the execution of this DPA. This log shall serve as definitive legal proof of execution and shall capture:
Except in cases of intentional misconduct, gross negligence, or willful fraud, the total aggregate liability of the Processor (Lion Solar) arising out of or in connection with this Data Processing Agreement, whether in contract, tort (including negligence), breach of statutory duty, or otherwise, shall be strictly limited to and shall not exceed the total fees paid by the Controller to the Processor in the twelve (12) months immediately preceding the event giving rise to the claim.
This limitation shall not apply to, and nothing in this DPA shall exclude or restrict, any liability that cannot be excluded or limited under applicable mandatory law, including the Processor’s direct statutory liability to Data Subjects and Supervisory Authorities under Article 82 GDPR. As between the Parties, the contractual cap above shall not relieve the Processor of liability for damage or administrative fines to the extent attributable to the Processor’s own breach of its obligations under Articles 28 and 32 GDPR.
This DPA and any contractual or non-contractual obligations arising out of or in connection with it shall be governed by, and construed in accordance with, the laws of Estonia.
Any dispute, controversy, or claim arising out of or relating to this DPA, including its formation, existence, validity, interpretation, performance, breach, or termination, shall be referred to and finally resolved by arbitration in accordance with the Rules of the Arbitration Court of the Estonian Chamber of Commerce and Industry (ECCI) current at the time of application.
| Processing Element | Description |
| Categories of Data Subjects | * End-Consumers (Homeowners, commercial property owners, or solar project leads).* Employees, administrators, or contractors of the Controller utilizing the Processor’s platform. |
| Categories of Personal Data | * Direct PII: Name, physical billing/installation address, telephone number, email address of the End-Consumer (retained for a maximum of 30 days post-project delivery).* Technical/Geographic Data: Solar project dimensions, exact geographic coordinates (lat/long), roof angles, azimuth, shading values, AutoCAD structural designs, equipment brand preferences, and single-line electrical layouts. |
| Nature & Purpose of Processing | Processing involves the execution of productized engineering and design tasks on behalf of the Controller, including PV*SOL simulations, 3D structural model generation, and electrical diagram planning, followed by the systematic anonymization of technical data parameters for analytical, modeling, and system optimization purposes. |
| Duration of Processing | For Personal Data (PII): active project lifecycle plus 30 days post-delivery.For Anonymized Technical Data: Perpetual (as it does not constitute Personal Data). |
The Processor shall maintain the following core security baseline:
This Annex records the revisions made to bring this DPA into compliance with Regulation (EU) 2016/679 (GDPR), in particular Article 28. No commercial protection, strategic data right, or M&A clause has been deleted or abbreviated; the revisions add the mandatory data-protection safeguards and balance the clauses that would otherwise have been unenforceable. (Bu Ek, sözleşmeyi GDPR’a — özellikle Madde 28’e — uyumlu hale getirmek için yapılan değişiklikleri kaydeder. Hiçbir ticari koruma, stratejik veri hakkı veya M&A maddesi silinmemiş ya da kısaltılmamıştır.)
| # | Location | Issue Identified (GDPR) | Revision Made |
| 1 | Section 1 — “Anonymized Technical Data” | Removing only name/phone/email does not anonymize data; precise geo-coordinates + roof data can re-identify a household (Recital 26 singling-out test). Treating it as non-personal was legally fragile. | Redefined anonymization to the irreversibility / no-singling-out standard of Recital 26 GDPR and EDPB guidance; required aggregation/coarsening of precise geolocation before it qualifies as anonymous. Added defined terms (Data Subject, Supervisory Authority, SCCs, etc.) and added physical address to PII. |
| 2 | Section 2.1 — Instructions | Missing the mandatory processor duty to flag unlawful instructions and to pre-notify legal compulsion. | Added the Article 28(3) final paragraph duty to immediately inform the Controller if an instruction infringes GDPR (with a right to suspend), and the duty to notify before processing under legal compulsion. |
| 3 | Section 3 — Indemnification (new 3.4) | “Absolute” shifting of all regulatory fines to the Controller — including fines for the Processor’s own breaches — is void under Article 82 GDPR. | Added Section 3.4 preserving each Party’s direct statutory liability; the Controller is not required to indemnify fines attributable to the Processor’s own Article 28/32 breaches; inter-party allocation cannot be invoked against Data Subjects/authorities. |
| 4 | Section 4.1 — Retention | Missing the mandatory end-of-services data fate option. | Added the Article 28(3)(g) obligation to delete or return all Personal Data at the Controller’s choice on termination/request, and delete copies. |
| 5 | Section 4.2 — Anonymized Data License | Declaring data non-personal “once anonymization is complete” without a legal standard; risk of licensing still-personal data. | Made the perpetual license conditional on effective anonymization (Recital 26); placed the burden of proof on the Processor; prohibited commercialization/transfer until effective anonymization. Commercial license preserved in full. |
| 6 | Section 5.1 / new 5.1A | Missing sub-processor change notice + right to object, flow-down of obligations, and continuing liability. | Added Article 28(2) notice-and-objection right for new Sub-processors and Article 28(4) flow-down of equivalent obligations plus Processor’s continuing full liability for Sub-processors. |
| 7 | Section 5.2 — International Transfers | “SCCs or equivalent mechanisms” was vague; Turkey lacks an adequacy decision; no transfer impact assessment. | Confirmed no adequacy decision; required duly executed Article 46 SCCs incorporated by reference; required a transfer impact assessment and supplementary measures (Schrems II / EDPB Rec. 01/2020); narrowed “equivalent mechanisms” to Chapter V tools only. |
| 8 | Section 6 — new 6.4, 6.5, 6.6 | Missing three mandatory Article 28(3) obligations. | Added 6.4 assistance with Data Subject rights (28(3)(e)); 6.5 assistance with DPIAs and Articles 32–36 (28(3)(f)); 6.6 information and audit/inspection rights for the Controller (28(3)(h)). |
| 9 | Section 8.3 — Limitation of Liability | A blanket cap cannot exclude unwaivable statutory liability to Data Subjects/authorities. | Added a carve-out: the cap does not limit liability that cannot be limited under mandatory law, including Article 82 GDPR liability. Commercial 12-month cap otherwise preserved. |