GlacierGrid Data Processing Addendum
This Data Processing Addendum ("DPA") supplements the GlacierGrid Master Service Agreement between GlacierGrid, Inc. ("GlacierGrid") and the Client identified in the applicable Statement of Engagement ("Client") (the "Agreement"). Capitalized terms not defined here have the meanings given in the Agreement.
Unless otherwise stated herein, this DPA is in addition to and does not supersede the Agreement. In the event of a conflict between this DPA and the Terms and Conditions or any other addendum, this DPA will prevail solely with respect to the Processing of Personal Data.
1. Definitions
- "Applicable Data Protection Laws" means all privacy and data protection laws applicable to the Processing of Personal Data under the Agreement, including the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA") and other U.S. state privacy laws.
- "Personal Data" means Client Data that identifies or relates to an identified or identifiable individual and is Processed by GlacierGrid on Client's behalf under the Agreement.
- "Process/Processing" means any operation performed on Personal Data.
- "Controller," "Processor," "Business," "Service Provider," and "Sub-processor" have the meanings given under Applicable Data Protection Laws.
- "Client Personal Data" means Personal Data within Client Data (as defined in the Agreement).
- "Security Incident" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Client Personal Data.
2. Roles of the parties
For Client Personal Data, Client is the Controller / Business and GlacierGrid is the Processor / Service Provider, Processing Client Personal Data only on Client's behalf and for the purposes of providing the Services described in the Agreement and the applicable Statement of Engagement.
3. GlacierGrid obligations
GlacierGrid will:
- Process Client Personal Data only on Client's documented instructions, including the Agreement, this DPA, and each Statement of Engagement, unless required by law (in which case it will inform Client unless legally prohibited).
- Ensure persons authorized to Process Client Personal Data are bound by confidentiality obligations consistent with Section 4 of the Agreement.
- Maintain appropriate technical and organizational measures designed to protect Client Personal Data, including encryption in transit and at rest, role-based access controls, network security, and hosting with Amazon Web Services in the United States. GlacierGrid's current security measures are available on request and may be updated from time to time provided the level of protection is not materially reduced.
- Assist Client, taking into account the nature of Processing, in responding to data-subject requests and in meeting Client's security, breach-notification, and data-protection-assessment obligations.
- Notify Client of a Security Incident without undue delay and in any event within 72 hours after becoming aware of it.
- On termination or expiry of the Agreement, at Client's choice delete or return Client Personal Data within 30 days, and delete residual copies from backups within 90 days in the ordinary course, except where retention is required by law.
4. Sub-processors
- Client provides general written authorization for GlacierGrid to engage Sub-processors to Process Client Personal Data. The current list of Sub-processors is maintained at glaciergrid.com/subprocessors.
- GlacierGrid will impose data-protection obligations on each Sub-processor substantially the same as those in this DPA, and remains liable for its Sub-processors' performance.
- GlacierGrid will add or replace a Sub-processor by notifying Client at least 30 days in advance — by updating the Sub-processor list and notifying Client's designated contact by email. No amendment, order form, or Client signature is required to add or replace a Sub-processor.
- Client may object to a new Sub-processor on reasonable data-protection grounds within 15 days of the notice. The parties will work in good faith to resolve the objection; if they cannot, Client's sole remedy is to terminate the affected Services without penalty. Absent a timely objection, the new Sub-processor is deemed authorized.
5. Data-subject rights
GlacierGrid will, to the extent legally permitted, promptly notify Client of any request it receives from a data subject and will assist Client in fulfilling Client's obligations to respond, taking into account the nature of the Processing.
6. Data location and transfers
GlacierGrid Processes Client Personal Data in the United States and does not transfer it outside the United States. If GlacierGrid later introduces Processing outside the United States, it will implement an appropriate cross-border transfer mechanism before doing so.
7. CCPA-specific terms
GlacierGrid acts as a Service Provider under the CCPA. GlacierGrid will not: (a) sell or share Client Personal Data; (b) retain, use, or disclose Client Personal Data for any purpose other than performing the Services or as otherwise permitted by the CCPA; or (c) combine Client Personal Data with data from other sources except as the CCPA permits. GlacierGrid certifies it understands and will comply with these restrictions.
8. General
This DPA is governed by the laws of the State of California, without regard to conflicts-of-law provisions, consistent with the Agreement. GlacierGrid's liability under this DPA is subject to the limitations of liability in the Agreement. This DPA takes effect on the effective date of the Agreement and remains in effect for as long as GlacierGrid Processes Client Personal Data.
Exhibit A — Sub-processors
The current list of GlacierGrid's sub-processors is maintained at glaciergrid.com/subprocessors.
Exhibit B — Details of Processing
- Subject matter: GlacierGrid's provision of the Services under the Agreement.
- Duration: the term of the Agreement plus any legally required retention.
- Nature and purpose: monitoring and optimization of Client's facilities, and, where enabled, answering Client's natural-language questions about its own data through the GlacierGrid Connector for Claude.
- Categories of data subjects: Client's Authorized Users and facility personnel.
- Categories of Personal Data: Authorized User names and business contact details, and user or account identifiers within facility records. Most Client Data (utility, temperature, energy, and sensor telemetry) is not personal data.
- Sensitive data: None.