This Data Processing Agreement applies where Aalto processes personal data in connection with the Aalto Services Agreement. Cross-border transfer mechanisms are set out in the separate Data Transfers Addendum, which is incorporated into this DPA.
Overview
This Data Processing Agreement (“DPA”) is subject to and forms part of the Agreement and governs Aalto’s and its Affiliates’ Processing of Personal Data. Capitalized terms not defined in this DPA have the meanings given to them in the Agreement.
1. Structure.
User enters this DPA with Aalto Energy, Inc.. References in this DPA to “Aalto” mean Aalto Energy, Inc..
2. Aalto as Data Processor and Data Controller.
Data Processing Roles
| Aalto as a Data Processor | When Aalto Processes Personal Data as a Data Processor, it is acting as a Data Processor on behalf of User, the Data Controller. |
| Aalto as a Data Controller | When Aalto Processes Personal Data as a Data Controller, it has the sole and exclusive authority to determine the purposes and means of Processing Personal Data it receives from or through User. |
Data Processing Purposes
| Aalto as a Data Processor | The purposes of Aalto’s Processing of Personal Data in its capacity as a Data Processor are to service the Aalto platform, and to provide, and provide access to, Aalto’s products and services. |
| Aalto as a Data Controller | The purposes of Aalto’s Processing of Personal Data in its capacity as a Data Controller when providing Aalto’s products and services are to: - determine and utilize third parties (including Financial Providers and Charging Network Partners); - monitor, prevent and detect fraudulent transactions and other fraudulent activity on the Aalto platform; - monitor, prevent and mitigate financial loss, security risks, and other harm; - implement, maintain and perform internal processes that enable Aalto to provide its products and services, including relationship management, billing and invoicing; - comply with Law, including applicable anti-money laundering screening and know-your-customer obligations, and Financial Provider and Governmental Authority requirements and requests; and - analyze, improve and develop Aalto’s products and services. |
Categories of Data Subjects and Personal Data
| Data Subjects | Aalto may Process the Personal Data of Customers (including drivers and other end users), Representatives, fleet drivers and other individuals whose vehicles or devices are connected to the Services, and any natural person who accesses or uses the Aalto Account. |
| Personal Data | If applicable, Aalto may Process name, email address, phone number, billing address, payment method details (such as payment tokens and limited card metadata), bank account details, charging session details (including station identity and location, session date, time, duration, energy delivered, and amount), vehicle data (including location, state of charge, and charging activity), device ID, IP address/location, tax ID/status, unique customer identifier, support communications (including, where a call is recorded, the recording and any transcript of that call), and identity information including government-issued documents. |
| Sensitive Data | If applicable, Aalto may Process Sensitive Data (e.g., precise geolocation data from devices and connected vehicles). |
Duration of Processing
| Aalto as a Data Processor | For the Term and any period required to perform a party’s post-termination obligations. |
Data Security
| Aalto as a Data Processor and Data Controller | Aalto will implement and maintain a written information security program with the Data Security Measures stated in the Exhibit to this DPA. |
3. Aalto Obligations when Acting as a Data Processor.
3.1 Obligations.
When Aalto is acting as a Data Processor for User, Aalto will, to the extent required by DP Law:
(a) Process Personal Data on User’s behalf and according to User’s Instructions. Aalto will inform User if, in its opinion, Instructions violate or infringe DP Law;
(b) ensure that all persons Aalto authorizes to Process Personal Data are granted access to Personal Data on a need-to-know basis and are committed to respecting the confidentiality of that Personal Data;
(c) inform User of each request Aalto receives from Data Subjects (including “verifiable consumer requests” as defined under the CCPA) exercising their rights under DP Law to (i) access their Personal Data; (ii) have their Personal Data corrected or erased; (iii) restrict or object to Aalto’s Processing; or (iv) data portability (collectively, a “Data Subject Request”). Other than to request further information, identify the Data Subject, and, if applicable, direct the Data Subject to User as Data Controller, Aalto will not respond to these requests unless User instructs Aalto in writing to do so. Taking into account the nature of the Processing, Aalto will assist User by appropriate technical and organizational measures, insofar as this is possible, to enable User to meet its obligation to respond to a Data Subject Request;
(d) inform User of each law enforcement request Aalto receives from a Governmental Authority requiring Aalto to disclose Personal Data or participate in an investigation requiring Aalto to disclose Personal Data, unless prohibited by Law;
(e) provide User with reasonable assistance, following User’s written request, to help User comply with its obligations under DP Law and, taking into account the nature of the Processing and the information available to Aalto, provide reasonable information to help User conduct a data protection impact assessment or consult with a Supervisory Authority. If User requests assistance from Aalto that goes beyond Aalto’s obligations under DP Law or this Agreement, Aalto may charge User a reasonable fee;
(f) if Aalto experiences a Data Incident, notify User without undue delay, which for Data Incidents affecting Personal Data subject to the GDPR or UK GDPR will be no later than 48 hours, in each case after becoming aware of the Data Incident. To the extent known to Aalto, Aalto’s notification to User will describe in reasonable detail (i) the type of Personal Data that was the subject of the Data Incident, (ii) the categories and potential number of individuals or records affected (including their countries), and (iii) the status of Aalto’s investigation and current or planned remediation. Following the notification, Aalto will provide relevant updates to assist User in complying with its obligations under DP Law;
(g) following User’s written request, contribute to audits or inspections by making available documentation regarding Aalto’s Processing of Personal Data. Following this request, and no more frequently than once annually, Aalto will promptly provide documentation or complete a written data security questionnaire of reasonable scope and duration regarding Aalto’s Processing of Personal Data. Audit and inspection rights under this DPA are satisfied through written responses, documentation, and remote review only; onsite or physical audits are not permitted, because the Services are operated on cloud infrastructure and Aalto does not store or Process Personal Data on physical premises that Aalto controls. All documentation provided, including any response to a security questionnaire, is Aalto’s Confidential Information; and
(h) at User’s choice, delete or return to User all Personal Data Processed in connection with the Services, and delete existing copies, following termination of the Agreement, except that Aalto will not be required to delete or return that Personal Data, or delete existing copies, to the extent that Aalto’s storage of that Personal Data or those copies is (i) required by Aalto to exercise its rights and perform its obligations under this Agreement; or (ii) required or authorized by DP Law for a longer period.
3.2 Sub-processors.
(a) Aalto engages Sub-processors as necessary to perform the Services. User consents to Aalto’s use of its existing Sub-processors, as set out on the Aalto Sub-Processors List, and grants Aalto a general written authorization to engage Sub-processors as necessary to perform the Services. Aalto will update the Aalto Sub-Processors List at least 30 days before a new Sub-processor begins Processing Personal Data. User may reasonably object to a change on legitimate grounds relating to data protection within 30 days after the update is posted. If User objects, the parties will discuss the objection in good faith, and Aalto may propose a commercially reasonable change to the Services or User’s configuration to avoid the objected-to Sub-processor’s Processing of User’s Personal Data. If the parties do not resolve the objection within 30 days after User raises it, User may, as its sole and exclusive remedy for the objection, terminate the Services that Aalto cannot provide without the objected-to Sub-processor by providing written notice to Aalto. User acknowledges that Aalto’s Sub-processors are essential to provide the Services and that, notwithstanding anything to the contrary in the Agreement (including this DPA), Aalto is not obligated to provide User the Services for which Aalto uses a Sub-processor to which User has objected.
(b) Aalto will enter into a written agreement with each Sub-processor that imposes on that Sub-processor obligations comparable to those imposed on Aalto under this DPA, including the obligation to implement appropriate Data Security Measures. If a Sub-processor fails to fulfill its data protection obligations under that agreement, Aalto will remain liable to User for the acts and omissions of its Sub-processor to the same extent Aalto would be liable if performing the relevant Services directly under this DPA.
3.3 CCPA.
To the extent the CCPA applies and Aalto is acting as a Data Processor, Aalto will not (except to provide Aalto’s services as permitted by Law): (a) sell or share (as defined under the CCPA) Personal Data; (b) retain, use or disclose Personal Data outside of its direct business relationship with User other than to provide Aalto’s products and services and as required to comply with Law; and (c) combine Personal Data received from or through User with Personal Data received from or on behalf of an individual or collected from Aalto’s own interactions with the individual. Aalto certifies that it understands and will comply with the requirements in this DPA relating to the CCPA and will provide the same level of privacy protection to Personal Data as required by the CCPA. Aalto will inform User if it determines that it can no longer meet its obligations under the CCPA and will take reasonable and appropriate steps to remediate any unauthorized Processing of Personal Data.
3.4 Disclaimer of Liability.
Notwithstanding anything to the contrary in the Agreement, including this DPA, Aalto and its Affiliates will not be liable for any claim made by a Data Subject arising from or related to Aalto’s or any of its Affiliates’ acts or omissions, to the extent that Aalto was acting in accordance with User’s Instructions.
4. User’s Obligations when Acting as a Data Controller.
4.1 Instructions.
User must only provide Instructions to Aalto that are lawful.
4.2 Compliance with DP Law.
User must comply with and perform User’s obligations under DP Law, including with regard to Data Subject rights, data security and confidentiality, and ensure User has an appropriate legal basis for the Processing of Personal Data as described in the Agreement, including this DPA.
4.3 Disclosures.
User must provide all necessary notices (including by making available a Privacy Policy) to, and obtain all necessary rights, permissions and consents from, Data Subjects (including Customers and, where applicable, drivers of vehicles User connects to the Services), to enable Aalto to lawfully Process any Personal Data provided by User as described in the Agreement, including this DPA. User is solely responsible for the content of notices it provides to its Customers.
5. Aalto’s Obligations when Acting as a Data Controller.
Aalto must comply with and perform its obligations under DP Law when Processing Personal Data, including making available a Privacy Policy that explains how and for what purposes Aalto collects, uses, retains, discloses and safeguards Personal Data.
6. Data Transfers.
6.1 Cross-border Data Transfers by User.
User acknowledges that in order for Aalto to provide the Services, User transfers Personal Data to Aalto Energy, Inc. in the United States. If the transfer comprises Personal Data that requires a Data Transfer Mechanism, the Data Transfers Addendum, which is incorporated into this DPA, will apply.
6.2 Cross-border Data Transfers by Aalto.
Aalto and its Affiliates may transfer Personal Data on a global basis as necessary to provide the Services. In particular, Personal Data may be transferred to Aalto Energy, Inc. in the United States and to Aalto’s Sub-processors in other jurisdictions.
7. Conflict.
To the extent of any conflict between the provisions of this DPA and any provision of the:
(a) Agreement regarding Personal Data Processing, the provisions of this DPA will prevail; and
(b) Data Transfers Addendum, the provisions of the Data Transfers Addendum will prevail.
8. Definitions.
Capitalized terms not defined in this DPA have the meanings given to them in the Agreement.
“Agreement” means the Aalto Services Agreement between User and Aalto, or as otherwise agreed by the parties.
“CCPA” means the California Consumer Privacy Act of 2018, Cal. Civ. Code Sections 1798.100-1798.199, and its implementing regulations.
“Data Controller” means the entity which, alone or jointly with others, determines the purposes and means of Processing Personal Data, which may include, as applicable, a “Business” as defined under the CCPA.
“Data Incident” has the meaning given to it in the General Terms.
“Data Privacy Framework” means, as applicable, the EU-US, Swiss-US or UK-US Data Privacy Framework self-certification program operated by the US Department of Commerce.
“Data Processor” means the entity that Processes Personal Data on behalf of the Data Controller, which may include, as applicable, a “Service Provider” as defined under the CCPA.
“Data Security Measures” means technical and organizational measures that are intended to secure Personal Data to a level of security appropriate for the risk of the Processing.
“Data Subject” means an identified or identifiable natural person to which Personal Data relates.
“Data Transfer Mechanism” means a transfer mechanism that enables the lawful cross-border transfer of Personal Data under DP Law, which includes transfer mechanisms that are required under DP Law in the EEA, Switzerland and the UK, such as the Data Privacy Framework, the EEA SCCs, the UK International Data Transfer Addendum and any data transfer mechanism available under DP Law that is incorporated into this DPA.
“Data Transfers Addendum” means the data transfers addendum located at aalto.energy/legal/dta, as updated from time to time.
“DP Law” means Law that applies to Personal Data Processing under the Agreement and this DPA, including international, federal, state, provincial and local Law relating in any way to privacy, data protection or data security.
“EEA” means the European Economic Area.
“EEA SCCs” means Module 1 (Transfer: Controller to Controller) and Module 2 (Transfer: Controller to Processor) of the standard contractual clauses set out in the European Commission Implementing Decision (EU) 2021/914 on standard contractual clauses for the transfer of personal data to third countries according to the GDPR.
“GDPR” means General Data Protection Regulation (EU) 2016/679.
“Instructions” means any communication or documentation, including that which may be provided through an Aalto API or Aalto Dashboard, or written agreements between User and Aalto, through which the Data Controller instructs a Data Processor to perform specific Processing of Personal Data for that Data Controller.
“Personal Data” means any information relating to an identifiable natural person that is Processed in connection with the Services, and includes “personal data” as defined under the GDPR and “personal information” as defined under the CCPA.
“Privacy Policy” means any or all of a publicly posted privacy policy, privacy notice, data policy, cookies policy, cookies notice or other similar public policy or public notice that addresses a party’s Personal Data practices and commitments.
“Process” means to perform any operation or set of operations on Personal Data or sets of Personal Data, such as collecting, recording, organizing, structuring, storing, adapting or altering, retrieving, consulting, using, disclosing by transmission, disseminating or otherwise making available, aligning or combining, restricting, erasing or destroying, as described under DP Law. “Processed” and “Processing” have corresponding meanings.
“Aalto Sub-Processors List” means the list of Aalto’s Sub-processors located at aalto.energy/legal/subprocessors, as updated from time to time.
“Sensitive Data” means, to the extent this data is treated distinctly as a special category of Personal Data under DP Law: (a) Personal Data that is genetic data, biometric data, data concerning health, a natural person’s sex life or sexual orientation; (b) data about racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership; (c) geolocation data; or (d) sensitive personal information as defined under the CCPA.
“Sub-processor” means an entity a Data Processor engages to Process Personal Data on that Data Processor’s behalf in connection with the Services.
“Supervisory Authority” means an independent public authority which is (i) established by a European Union member state pursuant to Article 51 of the GDPR; or (ii) the public authority governing data protection that has supervisory authority and jurisdiction over User.
“UK GDPR” means the GDPR, as transposed into United Kingdom national law by operation of section 3 of the European Union (Withdrawal) Act 2018 and as amended by the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019.
“UK International Data Transfer Addendum” means the international data transfer addendum to the EEA SCCs issued by the United Kingdom’s Information Commissioner’s Office.
Exhibit: Aalto Data Security
| Security Program and Policies | Aalto maintains and enforces a security program that addresses how Aalto manages security, including documented policies that are reviewed periodically, clear assignment of responsibility for security activities, and policies covering acceptable use, access control, cryptographic controls, and remote access. Aalto also maintains a privacy program and related policies that address how Personal Data is collected, used, and shared. |
| Personnel Controls | Aalto personnel who may access Personal Data are granted access on a need-to-know basis, are bound by confidentiality obligations, and complete security and privacy awareness training. Upon termination or role change, Aalto promptly removes or updates personnel access rights. Personnel authenticate using strong credentials, including multi-factor authentication for access to production systems. |
| Access Controls | Aalto implements measures to prevent data processing systems from being used by unauthorized persons, and to ensure that persons entitled to use a data processing system gain access only to the Personal Data allowed for their access rights, including user identification and authentication procedures, role-based and least-privilege access rights, access logging, and access removal procedures. |
| Encryption | Aalto encrypts Personal Data in transit between users and the Services and between production systems using TLS, and encrypts production data at rest using industry-standard encryption provided by its cloud infrastructure providers. Payment card credentials are not stored by Aalto: they are collected, tokenized, and stored by Aalto’s PCI-DSS Level 1 certified payment processors, and Aalto retains only payment tokens and limited card metadata. |
| Physical Access Controls | Aalto uses reputable third-party cloud service providers to host its production infrastructure and relies on those providers to manage physical access controls to their data center facilities, including access control systems, monitoring, and security staff. Aalto reviews its providers’ published certifications and audit reports to verify that they maintain appropriate physical access controls. |
| Network and Operations Management | Aalto implements policies and procedures for network and operations management, including change control with code review and approvals before release to production, separation of development and production environments, malware protection, audit logging, and infrastructure managed through automated deployment processes. |
| Vulnerability Management | Aalto monitors its systems and dependencies for vulnerabilities and remediates identified vulnerabilities according to risk. |
| Availability and Resilience | Aalto implements measures to restore the availability of and access to Personal Data in a timely manner in the event of a physical or technical incident, including database replication and backup procedures. |
| Logging and Monitoring | Aalto logs access to and activity within production systems and monitors logs and alerts to detect unauthorized access and anomalous activity. |
| Data Retention and Deletion | Aalto implements and maintains data retention policies and procedures related to Personal Data and reviews these policies and procedures as appropriate. |
| Reviews and Security Questionnaires | Upon written request, and no more frequently than annually, Aalto will complete a written data security questionnaire of reasonable scope and duration regarding Aalto’s business practices and data technology environment in relation to the Processing of Personal Data. Aalto’s responses are Aalto’s Confidential Information. |