DATA PROCESSING AGREEMENT (DPA)

Effective Date: 01-01-2025

This Data Processing Agreement (“DPA”) forms part of and supplements the applicable:

  • EOSVOLT Platform Terms & Conditions;
  • EOSVOLT Spark App Terms & Conditions;
  • commercial agreement; or
  • other services agreement

between EOSVOLT ApS (“EOSVOLT”) and the applicable customer, charging point operator (“CPO”), business customer, or other entity using the Services (“Customer”).

This DPA applies where EOSVOLT processes Personal Data on behalf of the Customer in connection with the Services.

 

1. PARTIES

1.1 Processor

EOSVOLT ApS
Arne Jacobsens Alle 15
2300 Copenhagen S
Denmark
CVR: 44305844

(“EOSVOLT” or “Processor”)

 

1.2 Controller

The Customer using the Services and acting as data controller under applicable data protection laws.

(“Customer” or “Controller”)

 

2. PURPOSE OF THIS DPA

This DPA governs EOSVOLT’s processing of Personal Data on behalf of the Customer in accordance with:

  • the General Data Protection Regulation (EU) 2016/679 (“GDPR”);
  • applicable EU Member State laws;
  • UK GDPR where applicable; and
  • other applicable privacy and data protection laws.

 

3. DEFINITIONS

Unless otherwise defined in this DPA, capitalised terms have the meaning given in the applicable Services agreement.

3.1 “Personal Data”

Has the meaning given under GDPR.

3.2 “Processing”

Has the meaning given under GDPR.

3.3 “Controller”

Has the meaning given under GDPR.

3.4 “Processor”

Has the meaning given under GDPR.

3.5 “Subprocessor”

Means a third party engaged by EOSVOLT to process Personal Data on behalf of the Customer.

3.6 “Data Subject”

Means an identified or identifiable natural person.

 

4. SCOPE OF PROCESSING

EOSVOLT may process Personal Data on behalf of the Customer in connection with:

  • EV charging operations;
  • charging-session management;
  • user management;
  • payment integrations;
  • charger diagnostics;
  • analytics;
  • support services;
  • APIs and integrations;
  • platform monitoring;
  • cybersecurity operations; and
  • related software services.

 

5. ROLE OF THE PARTIES

5.1 Controller

The Customer acts as Controller for Personal Data processed in connection with:

  • End User relationships;
  • charging operations;
  • pricing and billing;
  • charging-session management;
  • customer communications; and
  • applicable legal compliance.

5.2 Processor

EOSVOLT acts as Processor where EOSVOLT processes Personal Data solely on behalf of and under instructions from the Customer.

5.3 Independent Controller Activities

The Parties acknowledge that EOSVOLT may independently act as Controller for certain processing activities including:

  • platform security;
  • fraud prevention;
  • operational monitoring;
  • legal compliance;
  • service analytics;
  • internal business operations; and
  • cybersecurity activities.

 

6. CUSTOMER INSTRUCTIONS

EOSVOLT shall process Personal Data:

  • only on documented instructions from the Customer;
  • as necessary to provide the Services;
  • as required by applicable law; or
  • as otherwise permitted under this DPA.

The applicable Services agreement and Customer’s use of the Services constitute documented instructions for processing.

 

7. TYPES OF PERSONAL DATA

Depending on the Services used, EOSVOLT may process:

  • names;
  • email addresses;
  • phone numbers;
  • billing information;
  • account information;
  • charging-session data;
  • charging locations;
  • charger identifiers;
  • technical diagnostics;
  • IP addresses;
  • device identifiers;
  • usage data;
  • support communications;
  • payment metadata; and
  • operational telemetry.

EOSVOLT does not intentionally process special categories of personal data unless explicitly required and agreed.

 

8. CATEGORIES OF DATA SUBJECTS

Data Subjects may include:

  • End Users;
  • EV drivers;
  • Customer employees;
  • fleet users;
  • support contacts;
  • business representatives; and
  • platform administrators.

 

9. AI-ASSISTED PROCESSING AND ANALYTICS

EOSVOLT may use automated analytics systems, machine learning technologies, and AI-assisted tools to support:

  • charger diagnostics;
  • log analysis;
  • error detection;
  • cybersecurity monitoring;
  • fraud prevention;
  • operational analytics;
  • customer support assistance;
  • platform optimisation; and
  • service improvement.

Such systems are used to support operational processes and service quality.

EOSVOLT does not use solely automated decision-making producing legal or similarly significant effects within the meaning of Article 22 GDPR unless explicitly disclosed and permitted under applicable law.

Where reasonably possible, EOSVOLT applies:

  • data minimisation;
  • access controls;
  • pseudonymisation; and
  • security safeguards

to reduce unnecessary processing of Personal Data.

 

10. CONFIDENTIALITY

EOSVOLT shall ensure that persons authorised to process Personal Data:

  • are subject to confidentiality obligations; or
  • are under appropriate statutory duties of confidentiality.

 

11. SECURITY MEASURES

EOSVOLT shall implement commercially reasonable technical and organisational measures designed to protect Personal Data against:

  • unauthorised access;
  • unlawful processing;
  • accidental loss;
  • destruction; or
  • damage.

Security measures may include:

  • authentication controls;
  • encryption;
  • access restrictions;
  • infrastructure monitoring;
  • logging systems;
  • cybersecurity protections; and
  • operational safeguards.

EOSVOLT may update security measures from time to time provided the overall level of security is not materially reduced.

 

12. SUBPROCESSORS

12.1 Authorised Subprocessors

The Customer authorises EOSVOLT to engage Subprocessors in connection with the Services.

Subprocessors may include providers relating to:

  • cloud infrastructure;
  • analytics;
  • payment processing;
  • notifications;
  • customer support;
  • AI-assisted diagnostics;
  • cybersecurity;
  • communications; and
  • operational monitoring.

12.2 Subprocessor Obligations

EOSVOLT shall impose data protection obligations on Subprocessors that are materially consistent with this DPA where required by applicable law.

12.3 Changes to Subprocessors

EOSVOLT may update or replace Subprocessors from time to time.

EOSVOLT may maintain a current subprocessor list on its website or make such list available upon reasonable request.

 

13. INTERNATIONAL DATA TRANSFERS

Personal Data may be processed in countries outside the European Economic Area (“EEA”) where EOSVOLT or its Subprocessors operate.

Where required by applicable law, EOSVOLT shall implement appropriate safeguards for international transfers including:

  • Standard Contractual Clauses approved by the European Commission; or
  • equivalent legal transfer mechanisms.

 

14. DATA SUBJECT REQUESTS

Where EOSVOLT receives a request from a Data Subject relating to Personal Data processed on behalf of the Customer, EOSVOLT may:

  • notify the Customer;
  • redirect the request to the Customer; or
  • assist the Customer where reasonably necessary.

The Customer remains responsible for responding to Data Subject requests.

 

15. ASSISTANCE

Taking into account the nature of processing and information available to EOSVOLT, EOSVOLT shall provide reasonable assistance to the Customer regarding:

  • GDPR compliance obligations;
  • security obligations;
  • breach notifications;
  • Data Subject requests;
  • DPIAs; and
  • regulatory inquiries,

where required by applicable law.

EOSVOLT may charge reasonable fees for substantial or excessive assistance requests.

 

16. PERSONAL DATA BREACHES

EOSVOLT shall notify the Customer without undue delay after becoming aware of a confirmed Personal Data breach affecting Personal Data processed on behalf of the Customer where notification is required under applicable law.

EOSVOLT shall take commercially reasonable steps to:

  • investigate;
  • mitigate; and
  • remediate

the effects of confirmed Personal Data breaches.

 

17. DATA RETENTION AND DELETION

EOSVOLT retains Personal Data only for as long as reasonably necessary:

  • to provide the Services;
  • to comply with legal obligations;
  • to maintain security;
  • to prevent fraud;
  • to resolve disputes; or
  • to enforce agreements.

Upon termination of the applicable Services agreement and written request by the Customer, EOSVOLT shall:

  • delete; or
  • return

Personal Data processed on behalf of the Customer unless retention is required by applicable law or necessary for legitimate business, security, fraud prevention, backup, or compliance purposes.

Backup systems and archival copies may remain subject to standard retention cycles.

 

18. AUDITS

EOSVOLT may provide reasonable information regarding its privacy and security practices upon written request.

To the extent required by applicable law, EOSVOLT may permit reasonable audits or assessments relating to processing activities under this DPA, provided that:

  • reasonable prior notice is given;
  • audits do not unreasonably disrupt operations;
  • confidentiality obligations are maintained; and
  • the Customer bears its own costs.

EOSVOLT may satisfy audit obligations through:

  • security documentation;
  • certifications;
  • summaries;
  • questionnaires; or
  • third-party audit reports,

where appropriate.

 

19. LIABILITY

The liability limitations and exclusions contained in the applicable Services agreement shall apply to this DPA unless prohibited by applicable law.

 

20. TERM

This DPA remains in effect for as long as EOSVOLT processes Personal Data on behalf of the Customer.

 

21. GOVERNING LAW

This DPA shall be governed by and construed in accordance with the laws of Denmark unless otherwise required by applicable data protection law.

Any dispute arising from this DPA shall be subject to the exclusive jurisdiction of the courts of Copenhagen, Denmark.

 

22. LANGUAGE

This DPA is provided in English and may be made available in other languages.

In the event of any inconsistency or conflict between the English-language version and any translated version, the English-language version shall prevail.

 

23. CONTACT INFORMATION

Questions regarding this DPA may be directed to:

EOSVOLT ApS
Arne Jacobsens Alle 15
2300 Copenhagen S
Denmark

Email: contact@eosvolt.com