ElectraCalcIQ

Engineering-caliber calculations

Data Processing Addendum

Version 1.0 — effective 2026-08-19

This Data Processing Addendum (“DPA”) forms part of the ElectraCalcIQ Terms of Service (the “Agreement”) between the customer (“Customer” or “Controller”) and Peninsula Logic, LLC (“Peninsula Logic” or “Processor”), operator of the ElectraCalcIQ service. It applies to Peninsula Logic’s processing of Personal Data on Customer’s behalf and is designed to satisfy Article 28 of the EU General Data Protection Regulation (“GDPR”), the UK GDPR, and the California Consumer Privacy Act as amended (“CCPA”).

Enterprise Customers who need a countersigned copy on their own paper may email security@electracalciq.com. For most Customers, execution of the Agreement (including signup) is deemed acceptance of this DPA as written.

1. Definitions

Terms not defined here have the meaning given in the GDPR or the CCPA, as applicable.

2. Roles of the Parties

With respect to Personal Data submitted through the ElectraCalcIQ service, Customer is the Controller and Peninsula Logic is the Processor. Peninsula Logic Processes Personal Data only on Customer’s documented instructions, as set out in the Agreement, this DPA, and any additional instructions Customer provides in writing.

Where Peninsula Logic determines the means and purposes of Processing on its own behalf — for example, billing records, account provisioning, security logging, and product analytics on de-identified usage patterns — Peninsula Logic acts as an independent Controller. Those Processing activities are governed by the Privacy Policy, not this DPA.

3. Nature, Purpose, and Duration of Processing

4. Peninsula Logic’s Obligations

Peninsula Logic will:

5. Sub-processors

Customer provides a general written authorization for Peninsula Logic to engage the Sub-processors listed on the Security & Trust page. Peninsula Logic:

6. Security Measures

Peninsula Logic implements the technical and organizational measures described on the Security & Trust page, incorporated into this DPA by reference. Those measures include, at a minimum:

Peninsula Logic may update these measures over time, provided the overall level of security is not materially reduced.

7. Data Subject Rights Assistance

Taking into account the nature of the Processing, Peninsula Logic will assist Customer by appropriate technical and organizational measures, insofar as this is possible, in fulfilling Customer’s obligation to respond to requests from Data Subjects to exercise their rights of access, rectification, restriction, erasure, portability, and objection under Articles 15–22 GDPR and comparable CCPA rights.

Where a Data Subject contacts Peninsula Logic directly with a rights request relating to Customer’s account, Peninsula Logic will, without undue delay, forward the request to Customer and will not respond to the request itself except to acknowledge receipt and direct the Data Subject to Customer.

Standard in-app export and account-deletion functions available to Customer’s administrators, and the email-based full-account export and organization-deletion procedures described on the Security & Trust page, are provided at no additional charge. Extraordinary requests requiring bespoke engineering work may be billed at Peninsula Logic’s standard professional-services rate on prior written agreement.

8. Personal Data Breach Notification

Peninsula Logic will notify Customer without undue delay, and in any event within 72 hours of becoming aware of a confirmed Personal Data Breach affecting Customer’s Personal Data. The notification will include, to the extent then known:

Peninsula Logic will supplement this information as it becomes available and will cooperate reasonably with Customer’s own breach-response and regulator-notification activities. A notification will not be construed as an admission of fault or liability.

9. Data Protection Impact Assessments

On Customer’s reasonable written request, Peninsula Logic will provide Customer with information reasonably necessary for Customer to conduct data protection impact assessments and prior-consultation processes under GDPR Articles 35–36, to the extent such information is not already available on the Security & Trust page or in this DPA and is within Peninsula Logic’s reasonable ability to provide.

10. International Data Transfers

ElectraCalcIQ is hosted in the United States. Where Customer’s use of the service involves the transfer of Personal Data from the European Economic Area, the United Kingdom, or Switzerland to the United States or to another country not recognized as offering an adequate level of protection, the parties agree that:

11. Deletion or Return of Personal Data

On termination or expiration of the Agreement, and following any post-termination export window described on the Security & Trust page (currently 30 days), Peninsula Logic will delete all Personal Data from production systems within 7 days and purge Personal Data from backup media within 90 days on the standard backup-rotation schedule, unless applicable law requires continued retention.

Customer may request an accelerated deletion or a machine-readable export of Personal Data at any time during or after the export window by emailing support@electracalciq.com. Peninsula Logic will provide written confirmation of completed deletions.

12. Audit Rights

Peninsula Logic will make available to Customer all information reasonably necessary to demonstrate compliance with this DPA. That obligation is discharged, in the first instance, by Peninsula Logic:

Where Customer reasonably determines that the foregoing does not provide sufficient assurance and applicable law entitles Customer to further audit, Customer may, on 30 days’ prior written notice and no more than once per twelve-month period (except following a confirmed Personal Data Breach or a specific regulator directive), conduct an audit at Customer’s expense during Peninsula Logic’s business hours, scoped to minimize disruption. Peninsula Logic may require the auditor to sign a reasonable non-disclosure agreement and may redact information relating to other customers, security details whose disclosure would materially weaken Peninsula Logic’s security posture, or Sub-processor information Peninsula Logic is contractually barred from sharing.

13. CCPA-Specific Terms

To the extent Peninsula Logic Processes “personal information” (as defined in the CCPA) on Customer’s behalf, Peninsula Logic acts as a “service provider” under the CCPA. Peninsula Logic:

14. Liability and Order of Precedence

Each party’s and its affiliates’ liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Agreement. In the event of a conflict between this DPA and the Agreement, this DPA governs solely with respect to the subject matter of this DPA. In the event of a conflict between this DPA and the Standard Contractual Clauses, the Standard Contractual Clauses govern.

15. Term and Termination

This DPA takes effect on the earlier of Customer’s acceptance of the Agreement or Customer’s first Processing of Personal Data through the service, and continues in force for as long as Peninsula Logic Processes Personal Data on Customer’s behalf. Termination of the Agreement does not relieve either party of obligations that by their nature survive termination, including confidentiality, deletion, and post-termination breach notification.

16. Governing Law and Jurisdiction

This DPA is governed by the same law that governs the Agreement, without regard to conflict-of-laws principles, except where mandatory local data-protection law provides otherwise (for example, GDPR jurisdictional rules for Data Subject claims).

Contact

Peninsula Logic, LLC — operator of ElectraCalcIQ.