DATA PROCESSING AGREEMENT (DPA)

Effective Date: Concluded dynamically and taking effect immediately upon the Controller’s electronic acceptance (via “Click-wrap” execution on the Processor’s platform) or upon the placement of the first Service order, whichever occurs earlier (the “Effective Date”).

This Data Processing Agreement (“DPA”) is entered into by and between:

  1. LionSolarSolutions OÜ, a company incorporated under the laws of Estonia, with its registered office and official correspondence address at Tartu maakond, Tartu linn, Tartu linn, Paju tn 2, 50603, Estonia, registered under registry code 16661502, holding VAT number EE102624805, and official notice email legal@lionsolarsolutions.com (hereinafter referred to as the “Processor” or “Lion Solar”); and
  2. The legal entity or individual utilizing the Services, registering an account, or placing an order on the Processor’s client portal (hereinafter referred to as the “Controller” or “Client”). The specific identity, registered address, registration number, VAT number, and contact details of the Controller are those provided by the Controller during the platform registration, onboarding process, or order placement (hereinafter referred to as the “Client Account Info”).

The Processor and the Controller are collectively referred to as the “Parties” and individually as a “Party.”

RECITALS

  • WHEREAS, the Controller operates as an Engineering, Procurement, and Construction (EPC) firm, solar aggregator, or renewable energy project developer, and wishes to engage the Processor to provide productized engineering services, including but not limited to solar project planning, PV*SOL simulations, 3D modeling, AutoCAD drawings, Single Line Diagrams (SLD), and substructure designs (the “Services”);
  • WHEREAS, in connection with the performance of the Services, the Processor may process certain Personal Data on behalf of the Controller, subject to the General Data Protection Regulation (EU) 2016/679 (“GDPR”); and
  • WHEREAS, the Parties wish to ensure that such processing is conducted in compliance with GDPR while structurally safeguarding the Processor’s cross-border operating model, strategic data assets, and long-term M&A viability.

NOW, THEREFORE, IT IS AGREED AS FOLLOWS:

1. DEFINITIONS

Capitalized terms used but not defined in this DPA shall have the meanings ascribed to them in the GDPR.

  • “Anonymized Technical Data” means structural, spatial, and geographic metadata—including but not limited to geographic coordinates, roof angles, azimuth, shading data, spatial indexing, and equipment preferences (e.g., module, inverter, and substructure brands used)—which has been irreversibly processed such that the data subject is no longer identifiable and cannot be re-identified, whether by the Processor or by any other person, by any means reasonably likely to be used, including by way of singling out, linkability, or inference, in accordance with Recital 26 GDPR and the prevailing guidance of the European Data Protection Board (EDPB). Where geolocation precision would, alone or in combination with other available data, permit identification of a household or End-Consumer, such data shall not be treated as Anonymized Technical Data until it has been effectively aggregated, generalized, or coarsened to defeat re-identification.
  • “Client Data” means any data, including Personal Data, provided by the Controller to the Processor for the purpose of executing the Services.
  • “Data Subject,” “Personal Data,” “Processing,” “Supervisory Authority,” and “Personal Data Breach” shall have the meanings given to them in Article 4 GDPR.
  • “End-Consumer” means the individual data subject (e.g., homeowner or commercial property owner) whose property is the subject of the solar project design.
  • “PII” means Personally Identifiable Information, specifically the End-Consumer’s name, telephone number, email address, and physical billing/installation address.
  • “Standard Contractual Clauses” or “SCCs” means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission pursuant to Article 46(2)(c) GDPR (Commission Implementing Decision (EU) 2021/914), as may be amended or replaced.
  • “Sub-processor” means any third-party or affiliated entity engaged by the Processor to process Client Data on behalf of the Controller.

2. SCOPE AND PURPOSE OF PROCESSING

2.1 Instructions

The Processor shall process Personal Data exclusively on behalf of and in accordance with the documented instructions of the Controller, including with respect to transfers of Personal Data to a third country, unless required to do so by European Union or Member State law to which the Processor is subject; in such a case, the Processor shall inform the Controller of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest. The Agreement, this DPA, and the parameters configured by the Client in the portal constitute the Controller’s complete initial instructions to the Processor.

The Processor shall immediately inform the Controller if, in its opinion, an instruction infringes the GDPR or other applicable Union or Member State data protection provisions. In such event, the Processor shall be entitled to suspend execution of the affected instruction until it is confirmed, amended, or withdrawn by the Controller, without such suspension constituting a breach of this DPA or the Agreement.

2.2 Details of Processing

The details of the processing operations (categories of data, data subjects, and nature of processing) are specified in Annex I of this DPA, which forms an integral part hereof.

3. CONTROLLER WARRANTIES & ABSOLUTE INDEMNIFICATION

3.1 Strict Liability Shift & Consent Warranty

The Controller represents, warrants, and covenants that it has obtained full, explicit, valid, and GDPR-compliant consent (or possesses an unassailable alternative legal basis under Article 6 of the GDPR) from the End-Consumers to collect, process, and transfer their geographic, structural, and technical data to third-party engineering partners, specifically including the Processor.

3.2 Verification

The Controller maintains sole responsibility for the accuracy, quality, and legality of the Personal Data provided to the Processor. The Controller shall, upon reasonable request, demonstrate to the Processor that it has obtained the necessary consents or legal bases.

3.3 Absolute Indemnification

The Controller shall defend, indemnify, and hold harmless Lion Solar, its affiliates, successors, and directors against any and all direct or indirect losses, regulatory fines (including those issued by supervisory authorities), damages, liabilities, claims, and legal costs arising out of or resulting from:

  • A breach of the Controller’s warranties under this Section 3; or
  • Any claims brought by End-Consumers alleging a violation of their data privacy rights under GDPR due to data processing executed within the scope of the Services.

3.4 Statutory Liability Preservation (GDPR Article 82)

Notwithstanding Sections 3.1 to 3.3, the Parties acknowledge that, under Article 82 GDPR, each Party bears direct statutory liability towards Data Subjects and Supervisory Authorities for damage caused by processing that infringes the GDPR. Accordingly, and to the extent required for this DPA to remain valid and enforceable:

  • Nothing in this Section 3 shall operate to exclude, limit, or transfer the Processor’s own liability for damage, regulatory fines, or sanctions to the extent they arise from the Processor’s failure to comply with obligations under the GDPR specifically directed to processors (Article 82(2)) or from the Processor’s failure to act on, or its action contrary to, the Controller’s lawful documented instructions.
  • The Controller’s indemnification obligations under Section 3.3 apply to losses and fines arising from the Controller’s own acts, omissions, or warranty breaches, and shall not require the Controller to indemnify the Processor against fines or liabilities attributable to the Processor’s own breach of its obligations under this DPA, Article 28, or Article 32 GDPR.
  • The allocation of liability between the Parties under this Section 3 is enforceable only as between the Parties and may not be invoked against any Data Subject or Supervisory Authority.

4. DATA ANONYMIZATION, OWNERSHIP & STRATEGIC RETENTION

4.1 PII Purge Timeline

The Processor shall retain PII (End-Consumer Name, physical address, Phone, and Email) only for the duration necessary to deliver the specific project and perform quality assurance. Within thirty (30) days following the final delivery of the respective project to the Client, the Processor shall permanently delete, mask, or scrub all PII from its production systems.

End-of-Services Return or Deletion (GDPR Article 28(3)(g)). Without prejudice to the foregoing, upon termination or expiry of the Agreement, or at any time upon the Controller’s written request, the Processor shall, at the choice of the Controller, delete or return all Personal Data to the Controller and delete all existing copies, unless Union or Member State law to which the Processor is subject requires storage of the Personal Data. This obligation does not apply to Anonymized Technical Data that has been effectively anonymized in accordance with Section 1 and Section 4.2, which by definition no longer constitutes Personal Data.

4.2 Retention and Ownership of Anonymized Technical Data

The Parties explicitly acknowledge and agree that Anonymized Technical Data does not constitute Personal Data under the GDPR once, and only to the extent that, the anonymization process meets the irreversibility standard set out in Section 1 (Recital 26 GDPR). Until that standard is met, the data shall be treated as Personal Data and shall remain fully subject to this DPA. The Processor bears the burden of demonstrating that the anonymization process is effective and resistant to re-identification, and shall not commercialize, license, or transfer such data to any third party until effective anonymization has been achieved.

  • Subject to and conditional upon effective anonymization, the Controller hereby grants to the Processor a perpetual, irrevocable, worldwide, royalty-free, fully paid-up, transferable, and sublicensable license to own, store, aggregate, analyze, manipulate, and commercialize Anonymized Technical Data for any business purpose.
  • This includes, but is not limited to, optimizing engineering workflows, training machine learning or AI models, compiling market intelligence, and generating proprietary industry benchmarks.
  • For the avoidance of doubt, this license attaches exclusively to non-personal, effectively anonymized data and confers no right to retain, process, or exploit PII or any data capable of singling out or re-identifying an End-Consumer.

[Client Data Upload] ➔ [Service Execution] ➔ [Project Delivery] 

                                                       │

                                             ┌──────────┴──────────┐

                                 (Within 30 Days)   (Perpetual License)

                                           ▼                 ▼

                                        [PII Purged]     [Anonymized Data]

                                (Name, Email,Phone)     (Coordinates, Roof Angles, Hardware)

                                                 

5. CROSS-BORDER SUB-PROCESSING & OPERATIONAL SETUP

5.1 Approved Sub-processors and Infrastructure

The Controller explicitly acknowledges and approves the Processor’s operational architecture:

  • Billing & Corporate Jurisdiction: Handled via the Estonian entity (LionSolarSolutions OÜ) utilizing automated, secure payment rails (such as Stripe).
  • Core Engineering & Operations Team: Located in Turkey (facilitated via Lion Solar’s regional operations branch, local subsidiaries, or dedicated operations centers).

The Controller provides its general written authorization for the engagement of Sub-processors. The Processor shall maintain a current list of Sub-processors (accessible upon request or via the Client Portal) and shall inform the Controller of any intended addition or replacement of a Sub-processor, giving the Controller a reasonable period (no less than fourteen (14) days) to object on reasonable, data-protection-related grounds before the new Sub-processor begins processing. If the Controller raises a reasonable objection that the Parties cannot resolve, the Controller may suspend or terminate the affected Services without penalty.

5.1A Sub-processor Flow-Down and Continuing Liability (GDPR Article 28(4))

Where the Processor engages a Sub-processor, it shall do so by way of a written contract imposing on the Sub-processor the same data protection obligations as set out in this DPA, in particular providing sufficient guarantees to implement appropriate technical and organizational measures meeting the requirements of the GDPR. Where a Sub-processor fails to fulfil its data protection obligations, the Processor shall remain fully liable to the Controller for the performance of that Sub-processor’s obligations.

5.2 International Data Transfers

The Controller hereby authorizes the transfer of Client Data to Turkey for the purpose of executing the productized engineering services. The Parties acknowledge that, as at the Effective Date, Turkey is not the subject of an adequacy decision under Article 45 GDPR. Accordingly, the Processor guarantees that such transfers are governed by appropriate safeguards under Article 46 GDPR, specifically the European Commission’s Standard Contractual Clauses (SCCs) (Module Two and/or Module Three as applicable), which the Processor undertakes to have duly executed and in force between the relevant exporting and importing entities prior to any transfer. The SCCs are incorporated into this DPA by reference and, in the event of any conflict between the SCCs and this DPA, the SCCs shall prevail in respect of the relevant transfer.

The Processor shall, where required, conduct and document a transfer impact assessment and implement any necessary supplementary technical, contractual, and organizational measures to ensure that the transferred Personal Data enjoys a level of protection essentially equivalent to that guaranteed within the EEA, consistent with EDPB Recommendations 01/2020. The reference to “equivalent legal mechanisms” shall mean only other transfer tools expressly recognized under Chapter V GDPR (such as binding corporate rules or an approved certification or code of conduct), and shall not be construed to permit transfers absent a valid Article 46 safeguard.

5.3 Labor Law Exclusion

The Controller acknowledges that the engineering team is situated entirely outside the European Union (Turkey). This DPA and the provision of Services create no employment relationship, European labor law liabilities, or severance exposures for the Controller, the Processor, or any future acquirer of the Processor.

6. TECHNICAL AND ORGANIZATIONAL MEASURES (TOMs)

6.1 Security Standard

The Processor shall implement and maintain appropriate technical and organizational measures to protect Client Data against unauthorized or unlawful processing and against accidental loss, destruction, damage, alteration, or disclosure, as detailed in Annex II.

6.2 Personnel Confidentiality

The Processor shall ensure that all personnel authorized to process Client Data have committed themselves to strict confidentiality obligations or are under an appropriate statutory obligation of confidentiality.

6.3 Data Breach Notification

The Processor shall notify the Controller without undue delay, and in any event immediately after becoming aware of any accidental, unauthorized, or unlawful acquisition, destruction, loss, alteration, or disclosure of Personal Data (a “Personal Data Breach”). The Processor shall provide the Controller with reasonable assistance and necessary information to allow the Controller to comply with its regulatory breach notification obligations under the GDPR.

6.4 Assistance with Data Subject Rights (GDPR Article 28(3)(e))

Taking into account the nature of the processing, the Processor shall assist the Controller by appropriate technical and organizational measures, insofar as this is possible, for the fulfilment of the Controller’s obligation to respond to requests from Data Subjects exercising their rights under Chapter III GDPR (including access, rectification, erasure, restriction, data portability, and objection). If a Data Subject submits such a request directly to the Processor, the Processor shall, without undue delay, forward the request to the Controller and shall not respond to it itself except on the Controller’s documented instructions.

6.5 Assistance with Compliance, DPIAs and Prior Consultation (GDPR Article 28(3)(f))

Taking into account the nature of processing and the information available to it, the Processor shall assist the Controller in ensuring compliance with its obligations pursuant to Articles 32 to 36 GDPR, including security of processing, notification of Personal Data Breaches to the Supervisory Authority and to Data Subjects, the conduct of data protection impact assessments (DPIAs), and prior consultation with the Supervisory Authority where required.

6.6 Records, Information and Audit Rights (GDPR Article 28(3)(h))

The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR and shall allow for and contribute to audits, including inspections, conducted by the Controller or an independent third-party auditor mandated by the Controller. Such audits shall take place on reasonable prior written notice (no less than thirty (30) days, save where a Personal Data Breach or Supervisory Authority requirement justifies shorter notice), no more than once per calendar year absent reasonable cause, during normal business hours, and subject to appropriate confidentiality undertakings so as not to compromise the security or confidentiality of other clients’ data. The Processor may satisfy audit requests, where appropriate, by providing recognized third-party certifications or audit reports (e.g., ISO/IEC 27001 or SOC 2).

7. M&A READY CLAUSES: ASSIGNMENT, SUCCESSORS & DUE DILIGENCE

7.1 Automatic Assignment to Successors

This DPA, along with the underlying terms of service, is fully, freely, and automatically assignable by Lion Solar to any future buyer, parent company, investor, or successor-in-interest in the event of an acquisition, merger, corporate reorganization, or sale of substantially all of its assets.

  • Such assignment shall take effect automatically without requiring the prior written consent or re-execution of terms by the Controller, subject to providing subsequent written or electronic notification to the Controller within a commercially reasonable period following the closing of the transaction.

7.2 M&A Due Diligence Exception to Confidentiality

Notwithstanding any confidentiality provisions contained in this DPA or the main service agreement, Lion Solar is explicitly permitted to disclose anonymized or aggregated operational metrics, historical contract volumes, platform activity logs, and transaction history to potential institutional buyers, venture capital investors, private equity firms, or professional auditors during an M&A due diligence process.

  • Any such disclosure shall remain subject to a standard, commercially reasonable mutual Non-Disclosure Agreement (NDA) executed between Lion Solar and the prospective transaction party.

8. MECHANICS, EXECUTION & LIABILITY LIMITS

8.1 Click-wrap Validity and Electronic Execution

This DPA is executed digitally via a “Click-wrap” mechanism. By checking the designated box (e.g., “I have read and agree to the Data Processing Agreement”) upon registering an account or placing an order on the Lion Solar client portal, the Controller legally binds itself to the entirety of this DPA. No physical signatures or manual completion of placeholders are required to make this DPA a legally binding and enforceable agreement.

The Parties agree that the electronic record of the Controller’s acceptance of this DPA, or the execution of a Master Services Agreement that references this DPA, constitutes valid execution under all applicable digital signature laws, including the EU eIDAS Regulation (Regulation (EU) No 910/2014).

8.2 Version Control and Automated Logging

The Processor shall maintain an immutable, automated electronic log recording the execution of this DPA. This log shall serve as definitive legal proof of execution and shall capture:

  • User ID and Account Profile metrics corresponding to the Client Account Info.
  • Timestamp (Coordinated Universal Time – UTC) of acceptance.
  • IP Address of the executing user.
  • DPA Version Control Number active at the time of execution.

8.3 Limitation of Liability

Except in cases of intentional misconduct, gross negligence, or willful fraud, the total aggregate liability of the Processor (Lion Solar) arising out of or in connection with this Data Processing Agreement, whether in contract, tort (including negligence), breach of statutory duty, or otherwise, shall be strictly limited to and shall not exceed the total fees paid by the Controller to the Processor in the twelve (12) months immediately preceding the event giving rise to the claim.

This limitation shall not apply to, and nothing in this DPA shall exclude or restrict, any liability that cannot be excluded or limited under applicable mandatory law, including the Processor’s direct statutory liability to Data Subjects and Supervisory Authorities under Article 82 GDPR. As between the Parties, the contractual cap above shall not relieve the Processor of liability for damage or administrative fines to the extent attributable to the Processor’s own breach of its obligations under Articles 28 and 32 GDPR.

9. GOVERNING LAW AND ARBITRATION

9.1 Applicable Law

This DPA and any contractual or non-contractual obligations arising out of or in connection with it shall be governed by, and construed in accordance with, the laws of Estonia.

9.2 Dispute Resolution via Institutional Arbitration

Any dispute, controversy, or claim arising out of or relating to this DPA, including its formation, existence, validity, interpretation, performance, breach, or termination, shall be referred to and finally resolved by arbitration in accordance with the Rules of the Arbitration Court of the Estonian Chamber of Commerce and Industry (ECCI) current at the time of application.

  • The seat of the arbitration shall be Tallinn, Estonia.
  • The language of the arbitration shall be English.
  • The arbitral tribunal shall consist of a sole arbitrator appointed in accordance with the said Rules. The decision of the arbitrator shall be final, binding upon both Parties, and enforceable in any court of competent jurisdiction.

ANNEX I: DETAILS OF PROCESSING

Processing ElementDescription
Categories of Data Subjects* End-Consumers (Homeowners, commercial property owners, or solar project leads).* Employees, administrators, or contractors of the Controller utilizing the Processor’s platform.
Categories of Personal Data* Direct PII: Name, physical billing/installation address, telephone number, email address of the End-Consumer (retained for a maximum of 30 days post-project delivery).* Technical/Geographic Data: Solar project dimensions, exact geographic coordinates (lat/long), roof angles, azimuth, shading values, AutoCAD structural designs, equipment brand preferences, and single-line electrical layouts.
Nature & Purpose of ProcessingProcessing involves the execution of productized engineering and design tasks on behalf of the Controller, including PV*SOL simulations, 3D structural model generation, and electrical diagram planning, followed by the systematic anonymization of technical data parameters for analytical, modeling, and system optimization purposes.
Duration of ProcessingFor Personal Data (PII): active project lifecycle plus 30 days post-delivery.For Anonymized Technical Data: Perpetual (as it does not constitute Personal Data).

ANNEX II: TECHNICAL AND ORGANIZATIONAL MEASURES (TOMs)

The Processor shall maintain the following core security baseline:

  • Data Encryption: Transmission of data via TLS 1.3 (or latest industry-standard secure version) encryption mechanisms, with secure, encrypted at-rest storage utilized via GDPR-compliant secure cloud infrastructure.
  • Access Control: Strict Role-Based Access Controls (RBAC) ensuring that only engineering and operations personnel assigned to a specific client project have access to the incoming technical files and Personal Data.
  • Isolation Framework: Logical separation of client project files, assets, and data within secured cloud-hosted directories to prevent cross-client data contamination.
  • Automated Anonymization & Purging: Standardized automated scripts running on production databases to identify and purge direct PII parameters within 30 days following project completion, migrating structural, spatial, and brand metadata into an isolated analytical database.

ANNEX III: SCHEDULE OF GDPR COMPLIANCE REVISIONS

This Annex records the revisions made to bring this DPA into compliance with Regulation (EU) 2016/679 (GDPR), in particular Article 28. No commercial protection, strategic data right, or M&A clause has been deleted or abbreviated; the revisions add the mandatory data-protection safeguards and balance the clauses that would otherwise have been unenforceable. (Bu Ek, sözleşmeyi GDPR’a — özellikle Madde 28’e — uyumlu hale getirmek için yapılan değişiklikleri kaydeder. Hiçbir ticari koruma, stratejik veri hakkı veya M&A maddesi silinmemiş ya da kısaltılmamıştır.)

#LocationIssue Identified (GDPR)Revision Made
1Section 1 — “Anonymized Technical Data”Removing only name/phone/email does not anonymize data; precise geo-coordinates + roof data can re-identify a household (Recital 26 singling-out test). Treating it as non-personal was legally fragile.Redefined anonymization to the irreversibility / no-singling-out standard of Recital 26 GDPR and EDPB guidance; required aggregation/coarsening of precise geolocation before it qualifies as anonymous. Added defined terms (Data Subject, Supervisory Authority, SCCs, etc.) and added physical address to PII.
2Section 2.1 — InstructionsMissing the mandatory processor duty to flag unlawful instructions and to pre-notify legal compulsion.Added the Article 28(3) final paragraph duty to immediately inform the Controller if an instruction infringes GDPR (with a right to suspend), and the duty to notify before processing under legal compulsion.
3Section 3 — Indemnification (new 3.4)“Absolute” shifting of all regulatory fines to the Controller — including fines for the Processor’s own breaches — is void under Article 82 GDPR.Added Section 3.4 preserving each Party’s direct statutory liability; the Controller is not required to indemnify fines attributable to the Processor’s own Article 28/32 breaches; inter-party allocation cannot be invoked against Data Subjects/authorities.
4Section 4.1 — RetentionMissing the mandatory end-of-services data fate option.Added the Article 28(3)(g) obligation to delete or return all Personal Data at the Controller’s choice on termination/request, and delete copies.
5Section 4.2 — Anonymized Data LicenseDeclaring data non-personal “once anonymization is complete” without a legal standard; risk of licensing still-personal data.Made the perpetual license conditional on effective anonymization (Recital 26); placed the burden of proof on the Processor; prohibited commercialization/transfer until effective anonymization. Commercial license preserved in full.
6Section 5.1 / new 5.1AMissing sub-processor change notice + right to object, flow-down of obligations, and continuing liability.Added Article 28(2) notice-and-objection right for new Sub-processors and Article 28(4) flow-down of equivalent obligations plus Processor’s continuing full liability for Sub-processors.
7Section 5.2 — International Transfers“SCCs or equivalent mechanisms” was vague; Turkey lacks an adequacy decision; no transfer impact assessment.Confirmed no adequacy decision; required duly executed Article 46 SCCs incorporated by reference; required a transfer impact assessment and supplementary measures (Schrems II / EDPB Rec. 01/2020); narrowed “equivalent mechanisms” to Chapter V tools only.
8Section 6 — new 6.4, 6.5, 6.6Missing three mandatory Article 28(3) obligations.Added 6.4 assistance with Data Subject rights (28(3)(e)); 6.5 assistance with DPIAs and Articles 32–36 (28(3)(f)); 6.6 information and audit/inspection rights for the Controller (28(3)(h)).
9Section 8.3 — Limitation of LiabilityA blanket cap cannot exclude unwaivable statutory liability to Data Subjects/authorities.Added a carve-out: the cap does not limit liability that cannot be limited under mandatory law, including Article 82 GDPR liability. Commercial 12-month cap otherwise preserved.