Data Processing Agreement

Version 1.2.0 (Effective: June 25, 2026)

Data Processing Agreement

Effective Date: June 25, 2026 Version: 1.2.0

This Data Processing Agreement ("DPA") is entered into by and between the customer identified in the applicable service agreement ("Customer" or "Controller") and GridBoost, Inc., a Delaware corporation ("Provider" or "Processor"), and is incorporated into and forms part of the GridWonk Terms of Service or other written agreement between the parties governing Customer's use of the Service (the "Agreement").

This DPA sets forth the parties' obligations with respect to the processing and security of Personal Data in connection with the Service. In the event of a conflict between this DPA and the Agreement, this DPA shall prevail with respect to the processing of Personal Data.


1. Definitions

For the purposes of this DPA, the following terms have the meanings set forth below. Capitalized terms not defined herein have the meanings set forth in the Agreement.

1.1 "Controller" means the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. For the purposes of this DPA, Customer is the Controller.

1.2 "Data Protection Laws" means all applicable laws, regulations, and legal requirements relating to (a) privacy, data protection, and data security, and (b) the Processing of Personal Data, including, where applicable, the California Consumer Privacy Act (CCPA), the California Privacy Rights Act (CPRA), the Virginia Consumer Data Protection Act (VCDPA), the Colorado Privacy Act (CPA), the Connecticut Data Privacy Act (CTDPA), the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK General Data Protection Regulation, and any implementing or successor legislation.

1.3 "Data Subject" means an identified or identifiable natural person to whom Personal Data relates.

1.4 "Personal Data" means any information relating to an identified or identifiable natural person that is Processed by Provider on behalf of Customer in connection with the Service. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.

1.5 "Processing" (and its cognates "Process" and "Processed") means any operation or set of operations performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.

1.6 "Sub-processor" means any third-party entity engaged by Provider to Process Personal Data on behalf of Customer in connection with the Service.

1.7 "Supervisory Authority" means an independent public authority established by a member state of the European Economic Area, the United Kingdom, or any other jurisdiction pursuant to applicable Data Protection Laws, which is responsible for monitoring the application of Data Protection Laws.

1.8 "Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data transmitted, stored, or otherwise Processed by Provider or its Sub-processors in connection with the Service.

1.9 "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to processors established in third countries, as approved by the European Commission or other competent authority under applicable Data Protection Laws.

1.10 "Operational Backup" means a short-term disaster-recovery copy of Personal Data maintained solely for service continuity, resiliency, restoration testing, and related security operations.

1.11 "Regulatory Archive" means Customer-elected long-term retention of designated records subject to regulatory, audit, contractual, or legal-hold requirements, governed by an Order, retention schedule, or archive addendum separate from Operational Backups.

1.12 "Legal Hold" means a directive to preserve records relevant to pending or reasonably anticipated litigation, audit, regulatory inquiry, governmental proceeding, or similar legal obligation.

1.13 "CEII-Designated Data" means customer-designated sensitive infrastructure data that Customer identifies as Critical Energy Infrastructure Information (CEII) or as requiring CEII-equivalent handling under the Agreement.


2. Scope and Roles

2.1 Roles of the Parties

Customer is the Controller of Personal Data, and Provider is the Processor of Personal Data. Provider shall Process Personal Data only as a Processor acting on behalf of Customer and in accordance with Customer's documented instructions as described in this DPA and the Agreement.

2.2 Scope of Processing

Provider Processes Personal Data solely to provide, maintain, and improve the Service as described in the Agreement. The details of the Processing are as follows:

  • Subject Matter and Purpose of Processing. The Processing is performed for the purpose of providing the GridWonk cloud platform, including grid interconnection document analysis, validation, compliance checking, AI-assisted workflow automation, and related energy sector services as described in the Agreement.
  • Duration of Processing. Processing shall continue for the duration of the Agreement, plus any post-termination period required for data return or deletion as specified in Section 11.
  • Nature of Processing. Collection, storage, retrieval, use, analysis, organization, structuring, adaptation, transmission, and erasure of Personal Data as necessary to provide the Service.
  • Categories of Data Subjects. Personal Data relates to the following categories of Data Subjects:
    • Customer's employees, contractors, and agents who access or use the Service;
    • Customer's end users, including third-party stakeholders, utility contacts, and consultants whose information is submitted to or processed through the Service.
  • Types of Personal Data. The following types of Personal Data are Processed:
    • Contact information (names, email addresses, phone numbers, job titles);
    • Company and organizational affiliation;
    • Account credentials and authentication data;
    • IP addresses and device identifiers;
    • Usage data, access logs, and session information;
    • Content data uploaded to or generated through the Service (to the extent such data contains Personal Data).

2.3 Customer Obligations

Customer shall comply with its obligations under applicable Data Protection Laws with respect to its Processing of Personal Data and its instructions to Provider. Customer is responsible for ensuring that it has obtained all necessary consents, authorizations, and legal bases required under applicable Data Protection Laws for Provider to Process Personal Data as contemplated by this DPA and the Agreement.


3. Processing Instructions

3.1 Documented Instructions

Provider shall Process Personal Data only on the basis of Customer's documented instructions, unless Processing is required by applicable law to which Provider is subject. Customer's documented instructions for the Processing of Personal Data are set forth in:

  • The Agreement, including this DPA and any applicable order forms or statements of work;
  • Customer's configuration and use of the Service's features and functionality; and
  • Any additional written instructions provided by Customer and acknowledged by Provider.

3.2 Compliance with Instructions

Provider shall promptly inform Customer if, in Provider's reasonable opinion, an instruction from Customer infringes or would cause Provider to infringe applicable Data Protection Laws. Provider shall not be required to carry out any instruction that it reasonably believes would violate applicable law, and Provider may suspend performance of the relevant Processing activity until Customer modifies the instruction or confirms its lawfulness.

3.3 Additional Instructions

To the extent Customer requires Processing activities beyond the scope of the instructions set forth in Section 3.1, such additional instructions must be agreed upon in writing by both parties and may be subject to additional fees.


4. Confidentiality

4.1 Personnel Obligations

Provider shall ensure that all personnel authorized to Process Personal Data on its behalf are bound by appropriate confidentiality obligations, whether by contract or statutory duty. Such obligations shall survive the termination of the individual's engagement with Provider.

4.2 Access Limitation

Provider shall limit access to Personal Data to those personnel who require access to perform Provider's obligations under the Agreement and this DPA. Provider shall ensure that such personnel Process Personal Data only in accordance with Customer's documented instructions, except where otherwise required by applicable law.


5. Security Measures

5.1 Technical and Organizational Measures

Provider shall implement and maintain appropriate technical and organizational measures designed to protect Personal Data against unauthorized or unlawful Processing and against accidental loss, destruction, damage, theft, or alteration. These measures shall be appropriate to the risk and shall include, at a minimum, the measures described in Annex A (Technical and Organizational Measures) attached to this DPA.

5.2 Security Standards

Provider's security measures include, but are not limited to:

  • Encryption. Encryption of Personal Data at rest using AES-256 or equivalent encryption standards, and encryption of Personal Data in transit using TLS 1.2 or higher.
  • Access Controls. Role-based access control (RBAC), multi-factor authentication for administrative accounts, and enforcement of the principle of least privilege.
  • Row-Level Security. Database-level row-level security (RLS) policies ensuring organizational data isolation in the multi-tenant environment.
  • Audit Logging. Comprehensive audit logging of access to and operations on Personal Data, with tamper-resistant log storage.
  • Incident Response. A documented incident response plan with defined roles, escalation procedures, and notification protocols.
  • Regular Testing. Periodic security assessments, vulnerability scanning, and penetration testing of the Service.

5.3 Non-Degradation

Provider shall not materially decrease the overall level of security provided for Personal Data during the term of this DPA. Provider may update or modify specific security measures from time to time, provided that such updates do not result in a material reduction of the overall security posture.


6. Sub-processors

6.1 Authorization

Customer provides general written authorization for Provider to engage Sub-processors to Process Personal Data in connection with the Service, subject to the requirements of this Section 6.

6.2 Current Sub-processors

As of the Effective Date, Provider engages the following Sub-processors:

| Sub-processor | Purpose | Location | |---|---|---| | Anthropic | AI model processing and inference | United States | | Google Cloud / Gemini | AI model processing and document digitization | United States | | Google Cloud Platform | Backup storage and operational infrastructure | United States | | Supabase | Database hosting, authentication, and storage | United States | | Vercel | Application hosting and edge network | United States | | PostHog | Product analytics and usage telemetry | United States |

An up-to-date list of Sub-processors is maintained at Provider's website and may be updated from time to time in accordance with this Section 6.

6.3 Notification of New Sub-processors

Provider shall notify Customer at least thirty (30) days before engaging any new Sub-processor or materially changing the scope of an existing Sub-processor's Processing activities. Notification shall be provided via email to the address associated with Customer's account and/or through a notification mechanism within the Service.

6.4 Customer Objection Rights

Customer may object to a new Sub-processor within fifteen (15) days of receiving notice pursuant to Section 6.3, provided that Customer's objection is based on reasonable grounds relating to the protection of Personal Data. Customer's objection must be submitted in writing and must specify the reasonable grounds for the objection.

Upon receiving a timely objection, Provider shall use commercially reasonable efforts to make available to Customer a change in the Service or recommend a commercially reasonable alternative Sub-processor. If Provider is unable to resolve Customer's objection within thirty (30) days of receiving it, Customer may terminate the portion of the Agreement relating to the Service that cannot be provided without the objected-to Sub-processor, without penalty, by providing written notice to Provider.

6.5 Sub-processor Obligations

Provider shall:

  • Enter into a written agreement with each Sub-processor that imposes data protection obligations no less protective than those set forth in this DPA;
  • Conduct appropriate due diligence on each Sub-processor's ability to meet its data protection obligations; and
  • Remain fully liable to Customer for the acts and omissions of its Sub-processors to the same extent Provider would be liable if performing the Processing directly.

7. Data Subject Rights

7.1 Assistance with Data Subject Requests

Provider shall assist Customer, by appropriate technical and organizational measures and to the extent reasonably possible, in fulfilling Customer's obligations to respond to requests from Data Subjects exercising their rights under applicable Data Protection Laws, including rights of access, rectification, erasure, restriction of Processing, data portability, and objection.

7.2 Data Subject Requests Received by Provider

If Provider receives a request directly from a Data Subject regarding Personal Data Processed on behalf of Customer, Provider shall promptly notify Customer and shall not respond to the request directly unless authorized by Customer or required by applicable law. Provider shall provide Customer with commercially reasonable cooperation and assistance in relation to the handling of such requests.

7.3 Technical Measures

Provider shall make available to Customer, through the Service's functionality or upon reasonable request, the technical capabilities necessary to assist Customer in responding to Data Subject requests, including the ability to access, export, correct, and delete Personal Data associated with individual Data Subjects.


8. Data Breach

8.1 Notification

In the event of a Security Incident, Provider shall notify Customer without undue delay and in any event within seventy-two (72) hours after becoming aware of the Security Incident. Notification shall be provided to the email address associated with Customer's account and, where available, through the Service's notification mechanisms.

8.2 Content of Notification

Provider's notification shall include, to the extent reasonably available at the time of notification:

  • A description of the nature of the Security Incident, including, where possible, the categories and approximate number of Data Subjects affected and the categories and approximate number of Personal Data records concerned;
  • The name and contact details of Provider's designated point of contact for further information;
  • A description of the likely consequences of the Security Incident; and
  • A description of the measures taken or proposed to be taken by Provider to address the Security Incident, including, where appropriate, measures to mitigate its possible adverse effects.

8.3 Supplementary Information

Where it is not possible to provide all of the information specified in Section 8.2 at the time of the initial notification, Provider shall provide the information in phases without further undue delay as it becomes available.

8.4 Cooperation

Provider shall cooperate with Customer and take commercially reasonable steps to assist Customer in investigating, mitigating, and remediating the Security Incident. Provider shall preserve and provide to Customer relevant evidence and logs relating to the Security Incident to the extent within Provider's possession or control.

8.5 No Assessment of Risk

Provider's notification of a Security Incident to Customer shall not be construed as an acknowledgment of fault or liability by Provider. Customer retains sole responsibility for determining whether a Security Incident triggers notification obligations to Data Subjects, Supervisory Authorities, or other parties under applicable Data Protection Laws.


9. Data Transfers

9.1 Processing Location

Personal Data is Processed primarily within the United States. Provider shall not transfer Personal Data to a country or territory outside the United States without Customer's prior knowledge, except as necessary to engage Sub-processors listed in Section 6.2 or otherwise approved by Customer.

9.2 Transfer Mechanisms

To the extent that the Processing of Personal Data involves a transfer of Personal Data from the European Economic Area, the United Kingdom, or Switzerland to a jurisdiction that has not been recognized as providing an adequate level of data protection:

  • The parties shall execute the applicable Standard Contractual Clauses as approved by the European Commission (or the UK Information Commissioner's Office, as applicable), which are hereby incorporated by reference into this DPA;
  • Provider shall implement supplementary measures as necessary to ensure that the transferred Personal Data is afforded a level of protection that is essentially equivalent to that guaranteed within the originating jurisdiction; and
  • Provider shall cooperate with Customer to implement any additional or alternative transfer mechanisms that may be required under applicable Data Protection Laws.

9.3 Compliance Certification

Provider certifies that it is not aware of any laws or practices in the jurisdictions where Personal Data is Processed that would prevent it from fulfilling its obligations under this DPA and any applicable Standard Contractual Clauses. Provider shall notify Customer promptly if it becomes aware of any change in applicable law that may materially affect its ability to comply with this DPA.


10. Audits

10.1 Audit Rights

Customer may audit Provider's compliance with this DPA up to one (1) time per twelve (12) month period. Customer shall provide Provider with at least thirty (30) days' prior written notice of any audit, including the proposed scope and duration.

10.2 Audit Procedures

Audits shall be conducted during Provider's normal business hours, in a manner that minimizes disruption to Provider's operations, and subject to reasonable confidentiality obligations. Customer may engage a qualified independent third-party auditor to conduct the audit on Customer's behalf, provided that such auditor enters into appropriate confidentiality agreements.

10.3 SOC 2 Report Alternative

Provider may satisfy Customer's audit request by providing Customer with a copy of Provider's most recent SOC 2 Type II report (or equivalent independent third-party audit report or certification) that covers the Service. If such report does not reasonably address Customer's audit concerns, Customer retains the right to conduct an on-site audit in accordance with Sections 10.1 and 10.2.

10.4 Audit Costs

Customer shall bear the costs associated with any audit initiated by Customer, including Customer's internal costs and the fees of any third-party auditor engaged by Customer. Provider shall bear its own costs in facilitating the audit, including making personnel and documentation reasonably available.

10.5 Remediation

If an audit reveals a material non-compliance with this DPA, Provider shall promptly develop and implement a remediation plan to address the identified issues. Provider shall inform Customer of the remediation plan and its progress within a reasonable timeframe.


11. Deletion and Return of Personal Data

11.1 Export Window

Upon termination or expiration of the Agreement, Provider shall make Customer's Personal Data available for export through the Service's standard export functionality for a period of sixty (60) days following the effective date of termination or expiration (the "Export Period").

11.2 Deletion

Unless the Agreement, a Regulatory Archive schedule, or applicable law states otherwise, Provider shall delete Personal Data from active systems within ninety (90) days after the Export Period ends and shall remove Personal Data from Operational Backups within an additional commercially reasonable period not to exceed ninety (90) days after active-system deletion. During that period, Provider will continue to protect Personal Data in accordance with this DPA and the Agreement.

11.3 Certification of Deletion

Upon Customer's written request following the completion of deletion, Provider shall provide Customer with written certification confirming that all Personal Data has been deleted in accordance with this Section 11.

11.4 Legal Retention

To the extent that applicable law, a Legal Hold, or a customer-elected Regulatory Archive requires Provider to retain copies of Personal Data beyond the periods specified in this Section 11, Provider shall (a) isolate and protect such Personal Data from further Processing except as required by the applicable obligation, (b) continue to apply the security measures specified in this DPA, and (c) delete such Personal Data promptly when the applicable legal requirement, Legal Hold, or Regulatory Archive schedule expires.


12. Term

12.1 Effective Period

This DPA shall become effective on the Effective Date and shall remain in effect for the duration of the Agreement.

12.2 Survival

The obligations of Provider under this DPA with respect to the Processing and security of Personal Data shall survive the termination or expiration of the Agreement and this DPA until all Personal Data has been deleted or returned in accordance with Section 11. Sections 1 (Definitions), 8 (Data Breach), 10 (Audits), 11 (Deletion and Return of Personal Data), 12 (Term), and 13 (Liability) shall survive termination or expiration of this DPA.


13. Liability

13.1 Limitation of Liability

Each party's liability under or in connection with this DPA shall be subject to the limitations and exclusions of liability set forth in the Agreement.

13.2 Apportionment

To the extent permitted by applicable Data Protection Laws, where a party is held liable for damage caused by Processing that infringes applicable Data Protection Laws, the parties shall be liable only to the extent of their respective responsibility for the Processing that caused the damage, subject to the terms of the Agreement.


Annex A: Technical and Organizational Measures

The following technical and organizational measures are implemented by Provider to protect Personal Data Processed in connection with the Service. These measures are subject to periodic review and update to reflect changes in technology, threats, and best practices.

A.1 Access Control

  • Role-Based Access Control (RBAC). All access to systems containing Personal Data is governed by role-based access control policies. Users are assigned roles with the minimum permissions necessary to perform their functions.
  • Multi-Factor Authentication (MFA). Multi-factor authentication is required for all administrative accounts and for access to production systems and databases.
  • Principle of Least Privilege. Access to Personal Data is restricted to authorized personnel who require access to perform their job responsibilities. Access rights are reviewed periodically and revoked promptly upon change of role or termination.
  • Unique Credentials. Each authorized user is assigned unique credentials. Shared or generic accounts are prohibited for access to systems containing Personal Data.

A.2 Encryption

  • Encryption at Rest. Personal Data stored in databases, file systems, and backup storage is encrypted using AES-256 or equivalent encryption standards.
  • Encryption in Transit. All data transmitted between Customer and the Service, and between the Service and its Sub-processors, is encrypted using TLS 1.2 or higher.
  • Key Management. Encryption keys are managed using industry-standard key management practices, including key rotation, access controls, and separation of duties.

A.3 Network Security

  • Firewall Protection. Network firewalls are deployed to control inbound and outbound traffic to systems containing Personal Data, with rules configured according to the principle of least privilege.
  • DDoS Protection. Distributed denial-of-service mitigation is provided at the network and application layers through infrastructure providers.
  • Web Application Firewall (WAF). A web application firewall is deployed to detect and block common web-based attacks, including SQL injection, cross-site scripting, and other OWASP Top 10 threats.

A.4 Data Isolation

  • Multi-Tenant Architecture with Row-Level Security. The Service employs a multi-tenant architecture with database-level row-level security (RLS) policies that enforce strict data isolation between Customer organizations.
  • Organizational Boundaries. Each Customer organization's data is logically separated and accessible only to authorized users within that organization, as enforced by RLS policies and application-level access controls.
  • Environment Separation. Production, staging, and development environments are logically separated, with Personal Data restricted to production environments.

A.5 Monitoring and Logging

  • Real-Time Security Monitoring. Automated security monitoring systems continuously analyze system events, access patterns, and network traffic for indicators of compromise or unauthorized activity.
  • Audit Logging. Comprehensive audit logs are maintained for access to and operations on Personal Data, including user identity, timestamp, action performed, and affected data. Logs are stored in tamper-resistant storage.
  • Anomaly Detection. Automated anomaly detection systems identify and alert on unusual patterns of access, data movement, or system behavior that may indicate a security threat.
  • Log Retention. Audit logs are retained for a minimum period consistent with applicable Data Protection Laws and security best practices.

A.6 Incident Response

  • Incident Response Plan. Provider maintains a documented incident response plan that defines roles and responsibilities, classification criteria, escalation procedures, containment strategies, and communication protocols.
  • 72-Hour Notification SLA. Provider commits to notifying Customer of a Security Incident within seventy-two (72) hours of becoming aware of the incident, as specified in Section 8.
  • Post-Incident Review. Following resolution of a Security Incident, Provider conducts a post-incident review to identify root causes, lessons learned, and preventive measures.

A.7 Business Continuity

  • Automated Backups. Personal Data is backed up on a regular automated schedule, with backups encrypted and stored in geographically separated locations.
  • Disaster Recovery. Provider maintains a disaster recovery plan that includes recovery time objectives (RTO) and recovery point objectives (RPO) appropriate to the Service.
  • Redundancy. Critical Service components are deployed with redundancy to minimize single points of failure.

A.8 Personnel Security

  • Background Checks. Provider conducts background checks on personnel with access to systems containing Personal Data, to the extent permitted by applicable law.
  • Security Training. All personnel receive security awareness training upon hire and on a recurring basis. Personnel with access to Personal Data receive additional training on data protection requirements.
  • Confidentiality Agreements. All personnel with access to Personal Data are bound by written confidentiality agreements or equivalent statutory obligations, as described in Section 4.

A.9 Secure Development

  • Secure Software Development Lifecycle (SDLC). Provider follows a secure development lifecycle that incorporates security considerations at each stage of development, including design review, threat modeling, secure coding practices, and security testing.
  • Code Review. All code changes affecting systems that Process Personal Data are subject to peer review before deployment to production.
  • Dependency Scanning. Automated dependency scanning tools are used to identify known vulnerabilities in third-party libraries and components. Identified vulnerabilities are remediated according to severity-based timelines.
  • Vulnerability Management. Provider maintains a vulnerability management program that includes regular scanning, risk assessment, and timely remediation of identified vulnerabilities.

Contact

For questions about this Data Processing Agreement, please contact:

GridBoost, Inc. Email: contact@gridwonk.com