Ergova

Data Processing Addendum

Effective date: January 1, 2025Last updated: March 1, 2025

Summary

This Data Processing Addendum ("DPA") sets out the terms under which Ergova processes personal data on behalf of customers who act as controllers. It is intended for B2B customers who need a DPA for compliance (e.g., GDPR, CCPA). This DPA template is provided for review and may require company-specific legal approval before execution.

Important notice

Legal review required

This DPA template is provided for review and may require company-specific legal approval before execution. It is not legal advice. Customers should have their legal counsel review this DPA and the underlying Terms of Service and Privacy Policy before relying on it.

Subject matter and duration

This DPA applies to the processing of personal data by Ergova Technologies, Inc. ("Processor") on behalf of the customer ("Controller") in connection with the services provided under the Terms of Service. The duration of processing is the term of the agreement between the parties, plus any post-termination period required for deletion or return of data.

Nature and purpose of processing

Processing is carried out for the purpose of providing the Ergova platform and related services (e.g., scheduling, dispatch, invoicing, analytics, support) as described in the agreement and in accordance with the Controller's documented instructions.

Categories of personal data

Personal data processed may include: account and contact information; billing information; usage and device data; content and communications submitted by users; and other categories necessary to provide the services as specified in the order or configuration. The Controller is responsible for ensuring it has a lawful basis for providing such data to the Processor.

Categories of data subjects

Data subjects may include the Controller's employees, contractors, customers, and other individuals about whom data is submitted to the services through the Controller's use of Ergova.

Controller and processor roles

The Controller determines the purposes and means of processing. The Processor processes personal data only on documented instructions from the Controller, including with regard to transfers, unless required by law. The Processor will inform the Controller if it believes an instruction infringes applicable data protection law.

Confidentiality

The Processor will ensure that persons authorized to process personal data are bound by appropriate confidentiality obligations (contractual or statutory).

Security measures

The Processor will implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including as described in our Privacy Policy and security documentation. Measures include encryption (in transit and at rest where applicable), access controls, and regular review of our security practices.

Subprocessors

The Controller generally authorizes the Processor to engage subprocessors. A list of subprocessors is maintained at /subprocessors. The Processor will inform the Controller of any intended changes (e.g., new subprocessors or material changes) and give the Controller an opportunity to object where required by law.

International transfers

Placeholder

Where personal data is transferred to a country that has not been recognized as providing an adequate level of protection, the Processor will implement appropriate safeguards (e.g., standard contractual clauses, binding corporate rules) as required by applicable law. (TODO: Founder/legal to confirm transfer mechanisms and add annexes if needed.)

Assistance with data subject requests

The Processor will assist the Controller in responding to data subject requests (e.g., access, rectification, erasure, restriction, portability) and in ensuring compliance with the Controller's obligations regarding security, breach notification, and data protection impact assessments, to the extent required by applicable law and within the scope of the Processor's capabilities.

Deletion and return of data

Upon termination or at the Controller's request, the Processor will delete or return all personal data in accordance with the agreement and applicable law, unless the Processor is required to retain data by law. The Controller may request a certification of deletion where feasible.

Audits

Placeholder

The Controller may audit the Processor's compliance with this DPA, subject to reasonable notice and confidentiality obligations. The Processor may provide certifications or audit reports (e.g., SOC 2) in lieu of or in support of an audit where acceptable to the Controller. (TODO: Founder/legal to add audit terms and any limitations.)

For questions about this DPA, contact [DPA CONTACT] or see our Legal Center.