Opening fee €0 until 13 OctoberOrder now
eWatt Smart Power

Annex 1: Data Processing Agreement (DPA)

Annex to the general terms of the Smart Power service · eWatt Smart Power Systems Oy, business ID 3321142-9.

1. Background and scope

1.1 This annex applies when eWatt Smart Power Systems Oy (the “Processor”) processes personal data on behalf of the Customer (the “Controller”) in providing the Smart Power service (the “Service”). Such processing consists above all of processing the property’s measurement data to the extent that a natural person can be identified from it, and of processing the contact details of the alert and report recipients designated by the Customer, according to the Customer’s instructions.

1.2 Processing for which eWatt is itself the controller (including user accounts, customer relationship management, invoicing and marketing) is described in eWatt’s privacy policy and is not covered by this annex.

1.3 The parties comply with the EU General Data Protection Regulation (EU) 2016/679 (the “GDPR”) and applicable national legislation. Terms have the meaning given to them in the GDPR. In the event of a conflict, this annex prevails over the terms of service as regards the processing of personal data.

2. Description of the processing

ItemDescription
Subject matter and nature of the processingCollection of measurement data with the eWatt reader, and its transfer, storage, analysis and reporting in the Service; delivery of alerts and reports to recipients designated by the Customer.
Purpose of the processingProviding the Service to the Customer in accordance with the terms of service and the order confirmation.
DurationThe term of the agreement and the deletion or return period under section 9.
Categories of personal dataElectricity consumption measurement data to the extent that a natural person can be identified from it; the name, email address and phone number of alert and report recipients.
Categories of data subjectsUsers and residents of the Customer’s properties, where applicable; the Customer’s staff and recipients designated by the Customer (e.g. contact persons at the property maintenance company).

3. Obligations of the Controller and the Processor

3.1 The Controller is responsible for having the right to process personal data and to transfer it to the Processor for the provision of the Service, and for informing the data subjects for its part.

3.2 The Processor processes personal data only on the documented instructions of the Controller. Documented instructions are the terms of service, the order confirmation, this annex and the choices the Customer makes in the Service’s settings (e.g. alert recipients). If the Processor considers that an instruction infringes the GDPR or other data protection legislation, it will inform the Controller without delay.

3.3 The Processor ensures that persons processing personal data have committed themselves to confidentiality or are under a statutory obligation of confidentiality.

4. Security (Article 32 GDPR)

The Processor implements technical and organisational measures appropriate to the risk, including at least:

  • encryption of data in transit from the reader to the service platform and to the service’s user interfaces (TLS)
  • storage of data in data centres located in the EU/EEA
  • access control based on job duties, personal credentials and multi-factor authentication for administration
  • monitoring of environments, logging, regular backups and a recovery plan
  • data protection instructions for staff.

5. Subprocessors

5.1 The Controller gives general prior authorisation for the use of subprocessors in the processing. The subprocessors in use and their locations are listed at the end of this annex.

5.2 The Processor gives notice of any addition or replacement of subprocessors at least 30 days in advance. The Controller may object to the change on reasonable data protection grounds; if no solution is found, the Controller may terminate the agreement for the part of the Service affected by the change.

5.3 The Processor imposes on its subprocessors, by written agreement, data protection obligations at least equivalent to those in this annex and is liable for the work of its subprocessors as for its own.

6. International transfers

Personal data is processed in the EU/EEA. Data is not transferred outside the EU or EEA without the Controller’s prior written approval, and any transfer is made with safeguards in accordance with Chapter V of the GDPR (e.g. the European Commission’s standard contractual clauses).

7. Assistance

7.1 The Processor assists the Controller with appropriate technical and organisational measures in responding to requests concerning the rights of data subjects (Chapter III GDPR). If a data subject makes a request directly to the Processor, the Processor forwards it to the Controller without undue delay.

7.2 The Processor assists the Controller in fulfilling its obligations under Articles 32–36 GDPR (security, breach notifications, impact assessments and prior consultations), taking into account the nature of the processing and the information available to the Processor.

7.3 Assistance to a customary extent is included in the price of the Service; more extensive assistance may be charged at the hourly rate in the price list in force at the time.

8. Personal data breaches

The Processor notifies the Controller of a personal data breach affecting the personal data processed on its behalf without undue delay, and no later than 48 hours after becoming aware of it. The notification contains the information required by Article 33(3) GDPR to the extent available: a description of the breach, the categories and approximate numbers of data concerned, the likely consequences, and the measures taken and proposed to address it. The Processor documents breaches and cooperates with the Controller in investigating them.

9. Deletion and return of data

9.1 When the agreement ends, the Processor returns the personal data to the Controller in a machine-readable format at the Controller’s request and deletes it from its systems within 90 days of the end of the agreement, unless Union or national law requires it to be retained.

9.2 The Processor has the right to anonymise the measurement data so that neither the data subjects nor the Customer can be identified, and to use the anonymised data in accordance with the terms of service. Anonymised data is not personal data.

10. Demonstrating compliance and audits

10.1 At the Controller’s request, the Processor provides the information necessary to demonstrate compliance with the obligations of Article 28 GDPR (e.g. descriptions of security measures and subprocessors).

10.2 The Controller, or an independent auditor it appoints (who may not be a competitor of the Processor), may audit compliance with this annex at most once a year, giving at least 60 days’ notice. The audit is carried out without unnecessarily disrupting normal business, and each party bears its own costs. The Processor may charge reasonable costs for assisting with the audit.

11. Liability and term

11.1 The limitations of liability in the terms of service apply to the parties’ liability, unless mandatory legislation requires otherwise.

11.2 This annex remains in force for as long as the Processor processes personal data on behalf of the Controller.

List of subprocessors

SubprocessorPurpose of processingLocation
Googleservice platform and databasesEU/EEA
Google / 1NCEemail and SMS alertsEU/EEA
Rise Technologies Oyinvoicing and paymentsEU/EEA