ENERGY EXEMPLAR DATA PROCESSING AGREEMENT
Last Updated: July 2026
This Data Processing Agreement ("DPA") forms part of the Agreement between Energy Exemplar ("EE") and Customer where EE Processes Personal Data on behalf of Customer in connection with the Products.
Capitalized terms not defined in this DPA have the meanings given in the Agreement.
1. Scope
This DPA applies only to the extent EE Processes Personal Data on behalf of Customer as a Processor under applicable Data Protection Laws.
If EE Processes Personal Data as a Controller (such as account administration, billing contacts, website visitors, or marketing contacts), such Processing is governed by EE's Privacy Notice.
2. Roles of the Parties
Customer acts as Controller.
EE acts as Processor.
Customer instructs EE to Process Personal Data solely for the purposes described in the Agreement.
3. Processing of Personal Data
EE shall Process Personal Data only:
- to provide the Products;
- to provide Support;
- to perform Professional Services;
- to maintain security;
- to comply with applicable law; and
- pursuant to Customer's documented instructions.
- maintain an up-to-date list of subprocessors;
- impose written data protection obligations on subprocessors; and
- remain responsible for its subprocessors' performance of their obligations.
- Standard Contractual Clauses;
- the UK International Data Transfer Addendum; or
- another legally recognized transfer mechanism.
- data subject requests;
- security incidents;
- impact assessments; and
- regulatory inquiries.
- return Customer Personal Data; or
- securely delete Customer Personal Data,
EE shall not sell Customer Personal Data or Process Personal Data for unrelated commercial purposes.
4. Confidentiality
EE shall ensure that personnel authorized to Process Personal Data are subject to appropriate confidentiality obligations.
5. Security
EE shall maintain appropriate technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access.
Additional information regarding EE's security practices is available in EE's Security Policy.
6. Subprocessors
Customer authorizes EE to use Affiliates and third-party subprocessors to provide the Products.
EE shall:
7. International Transfers
Where Personal Data is transferred internationally, EE will implement an appropriate lawful transfer mechanism, including where applicable:
8. Assistance
Taking into account the nature of the Processing, EE will provide reasonable assistance to Customer to enable Customer to comply with applicable Data Protection Laws, including with respect to:
Customer shall reimburse EE for material additional costs incurred in providing assistance beyond the ordinary provision of the Products unless otherwise required by law.
9. Security Incidents
EE shall notify Customer without undue delay after becoming aware of a confirmed Security Incident affecting Customer Personal Data.
Such notification shall include available information reasonably necessary for Customer to comply with applicable law.
10. Return or Deletion
Upon termination of the Agreement, EE shall, at Customer's election:
except where retention is required by applicable law or permitted under the Agreement.
11. Audit Information
EE shall make available information reasonably necessary to demonstrate compliance with this DPA.
Where required by applicable law, Customer may conduct an audit no more than once annually upon reasonable advance notice and subject to reasonable confidentiality and security requirements.
Third-party certifications, audit reports, or similar independent assessments may satisfy this obligation.