ENERGY EXEMPLAR DATA PROCESSING AGREEMENT

Last Updated: July 2026

This Data Processing Agreement ("DPA") forms part of the Agreement between Energy Exemplar ("EE") and Customer where EE Processes Personal Data on behalf of Customer in connection with the Products.

Capitalized terms not defined in this DPA have the meanings given in the Agreement.

1. Scope

This DPA applies only to the extent EE Processes Personal Data on behalf of Customer as a Processor under applicable Data Protection Laws.

If EE Processes Personal Data as a Controller (such as account administration, billing contacts, website visitors, or marketing contacts), such Processing is governed by EE's Privacy Notice.

2. Roles of the Parties

Customer acts as Controller.

EE acts as Processor.

Customer instructs EE to Process Personal Data solely for the purposes described in the Agreement.

3. Processing of Personal Data

EE shall Process Personal Data only:

  • to provide the Products;
  • to provide Support;
  • to perform Professional Services;
  • to maintain security;
  • to comply with applicable law; and
  • pursuant to Customer's documented instructions.
  • maintain an up-to-date list of subprocessors;
  • impose written data protection obligations on subprocessors; and
  • remain responsible for its subprocessors' performance of their obligations.
  • Standard Contractual Clauses;
  • the UK International Data Transfer Addendum; or
  • another legally recognized transfer mechanism.
  • data subject requests;
  • security incidents;
  • impact assessments; and
  • regulatory inquiries.
  • return Customer Personal Data; or
  • securely delete Customer Personal Data,

EE shall not sell Customer Personal Data or Process Personal Data for unrelated commercial purposes.

4. Confidentiality

EE shall ensure that personnel authorized to Process Personal Data are subject to appropriate confidentiality obligations.

5. Security

EE shall maintain appropriate technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access.

Additional information regarding EE's security practices is available in EE's Security Policy.

6. Subprocessors

Customer authorizes EE to use Affiliates and third-party subprocessors to provide the Products.

EE shall:

7. International Transfers

Where Personal Data is transferred internationally, EE will implement an appropriate lawful transfer mechanism, including where applicable:

8. Assistance

Taking into account the nature of the Processing, EE will provide reasonable assistance to Customer to enable Customer to comply with applicable Data Protection Laws, including with respect to:

Customer shall reimburse EE for material additional costs incurred in providing assistance beyond the ordinary provision of the Products unless otherwise required by law.

9. Security Incidents

EE shall notify Customer without undue delay after becoming aware of a confirmed Security Incident affecting Customer Personal Data.

Such notification shall include available information reasonably necessary for Customer to comply with applicable law.

10. Return or Deletion

Upon termination of the Agreement, EE shall, at Customer's election:

except where retention is required by applicable law or permitted under the Agreement.

11. Audit Information

EE shall make available information reasonably necessary to demonstrate compliance with this DPA.

Where required by applicable law, Customer may conduct an audit no more than once annually upon reasonable advance notice and subject to reasonable confidentiality and security requirements.

Third-party certifications, audit reports, or similar independent assessments may satisfy this obligation.