Data processing agreement
Sunnix Pro · version of 30 September 2026
This is the agreement that Art. 28 GDPR requires between a company using Sunnix Pro, which is the controller of its customers' data, and SoLink, which processes that data on its behalf. The company's owner accepts it from their account, before the trial or the subscription.
The parties
This agreement (the "Agreement") is made between the company using Sunnix Pro, identified by its account details (the "Controller"), and SoLink S.r.l., registered office at Via Bergamo 44, 23807 Merate (LC), Italy, VAT IT03727580130, which runs the Sunnix platform (the "Processor").
The Agreement supplements the Sunnix Terms and Conditions, in particular Article 4 on Sunnix Pro. The Controller accepts it from their account, and it applies for as long as the Processor processes data on the Controller's behalf. If the Agreement and the Terms conflict, the Agreement prevails on data protection.
1. Definitions
"Personal data", "processing", "controller", "processor", "data subject", "personal data breach" and "sub-processor" have the meaning given in Article 4 of Regulation (EU) 2016/679 (GDPR). "Customers" means the people who use the Controller's links and pages, or receive the quotes and proposals the Controller prepares with Sunnix Pro.
2. Subject matter and roles
2.1. The Processor processes, on the Controller's behalf, the Customers' personal data described in Annex A, solely to provide Sunnix Pro.
2.2. The following fall outside the Agreement, because the Processor handles them as an independent controller under its own privacy policy:
- the account data of the Controller and its people: login email, alert inbox, company details, subscription and payments;
- estimates made on the public site sunnix.it outside the Controller's links, including the choice, by whoever makes them, of a nearby company to contact;
- monitoring of a plant with an account in the Customer's name: if the Customer agrees to share figures or alerts with the Controller, the Processor passes them on based on that consent;
- site visit statistics, collected only with the visitor's consent and never on proposals, estimates, projects or widgets embedded in other people's sites;
- reports of content that anyone makes on company pages (Regulation (EU) 2022/2065);
- aggregated and anonymous data on use of the platform, which is not personal data.
3. The Controller's instructions
3.1. The Processor processes the data only on the Controller's documented instructions. Instructions include the Terms, the Agreement and the choices the Controller makes on the platform: the links it creates, the fields it asks for, the quotes and proposals it prepares and sends, the data and files it uploads or removes.
3.2. If an instruction appears to infringe the GDPR or another data protection rule, the Processor tells the Controller at once, and may suspend it until it is confirmed or changed.
3.3. If EU or Italian law requires the Processor to process data differently, the Processor informs the Controller first, unless the law forbids it.
4. Confidentiality and staff access
4.1. The Processor authorises to process the data only the people who need to in order to provide the service or the support the Controller asked for. All of them are bound to confidentiality by contract or by law.
4.2. The Processor's staff enter the Controller's account only at the Controller's request and for the time the Controller grants, or to set up the company before handing it over. Every change made this way appears in the account history the Controller reads, and the Controller can remove the access at any time.
5. Security
5.1. The Processor applies the technical and organisational measures in Annex B, appropriate to the risk under Article 32 GDPR.
5.2. It may update them over time, provided the level of protection does not decrease.
6. Sub-processors
6.1. The Controller gives general authorisation to use the sub-processors in Annex C.
6.2. The Processor notifies the Controller by email at least 30 days before adding or replacing a sub-processor. Within that period the Controller may object on reasonable data protection grounds; if no solution is found, the Controller may terminate the subscription without penalty, with a refund of the part of the period already paid and not used.
6.3. The Processor imposes on each sub-processor data protection obligations no less strict than those of the Agreement, and is liable to the Controller for them.
7. Transfers outside the European Union
Data is stored and processed on servers in the European Union: the database and files (Supabase), the functions of the site and the API (Vercel) and the temporary cache (Upstash) run in European regions. The sub-processors in Annex C are, however, companies based in, or owned by groups based in, the United States, and access from outside the European Union remains possible, for support or because the law of their country requires it; for Twilio (SendGrid) and Google, processing may also take place there. For this reason every sub-processor also has a transfer safeguard: participation in the EU-U.S. Data Privacy Framework, or the standard contractual clauses approved by the European Commission (Decision (EU) 2021/914), as set out in Annex C.
8. Assistance to the Controller
8.1. Data subjects' rights. The platform lets the Controller find the Customers' data, download a copy of it (point 10.2) and remove it, as follows:
- estimates and uploaded files are deleted from the account, one by one, at any time. A document that a published link still shows must first be removed from that link, because its address may be printed on a QR code;
- links and proposals are withdrawn: from then on they no longer open, but the record stays for as long as the account exists. A proposal is also the act through which a Customer takes into their own account the plant they bought;
- plant folders are archived, bookings are cancelled and requests from the plant check are dismissed: together with job quotes, they stay in the plant's history for as long as the account exists;
- when a Customer asks for deletion rather than mere withdrawal, the Controller asks the Processor, which deletes the indicated proposal, job quote with its photos, booking, request or folder within 5 working days;
- everything is deleted when the account is closed, and at the end of the period in point 10.4.
If a Customer writes directly to the Processor to exercise a right over the Controller's data, the Processor forwards the request to the Controller within 5 working days and does not answer on the merits without the Controller's instruction.
8.2. Other obligations. The Processor assists the Controller, as far as it is concerned and with the information available to it, with the obligations of Articles 32-36 GDPR: security, breach notification, impact assessment and prior consultation.
9. Personal data breaches
9.1. The Processor informs the Controller without undue delay, and in any case within 48 hours of becoming aware of it, of a breach affecting the Controller's data. It writes to the account email and to the company's public email.
9.2. The notice describes, as far as already known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact. Missing information follows as soon as it is available.
9.3. Notifying the supervisory authority and informing the data subjects remain the Controller's responsibility. The Processor does not contact the data subjects without the Controller's instruction, unless required by law.
10. Duration, return and deletion
10.1. The Agreement lasts as long as the subscription, and in any case for as long as the Processor processes data on the Controller's behalf.
10.2. At any time, and before closing the account, the Controller can download from the account a copy of the data in JSON format ("Your data"): company, links and their events, estimates, proposals, plant folders and their history, bookings, requests from the plant check, job quotes with the list of their photos, and the log of what the Processor's staff did in the account.
10.3. When the account is closed, the Processor deletes the Controller's data: company, links and their events, estimates, proposals, folders, bookings, requests, job quotes, uploaded files and photos. Deletion from the database is immediate; from the database provider's backups the data disappears as they rotate, within 30 days, and until then it is not used.
10.4. Once a subscription has expired and not been renewed, the Controller's links stop working, and the data stays in the account for twelve months from the end of the last subscription. The Processor notifies the Controller by email 30 and 7 days beforehand; if the Controller does not renew in the meantime, it deletes the data as in point 10.3. The Controller can download a copy until that day. If a notice goes out late, the deletion moves accordingly: it never happens before the date written in the notice. The personal account and the monitoring of plants in the Controller's name remain.
10.5. Any obligation of the Processor to keep data required by law is unaffected.
11. Audits
11.1. The Processor makes available to the Controller the information needed to demonstrate compliance with Article 28 GDPR, answering its reasonable requests in writing.
11.2. The Controller may request an inspection, also through an auditor bound to confidentiality, with at least 30 days' notice, no more than once a year unless there is an established breach or a request from an authority, and at its own expense. Audits of sub-processors are based on their certifications and audit reports.
12. The Controller's obligations
The Controller:
- gives the Customers the information notice (Articles 13-14 GDPR) about the processing it carries out through Sunnix Pro;
- has a legal basis for the data it collects or uploads, in particular for job photos and for the Customer's name that it writes in quotes;
- does not write in free-text fields (notes, captions, titles) data the service does not ask for, such as phone numbers, health or criminal data, and does not upload special categories of data (Article 9 GDPR);
- keeps access to its account confidential and decides which of its people use it.
13. Liability
The parties' liability towards data subjects is governed by Article 82 GDPR. Between the parties, the limits of the Terms apply, except for wilful misconduct or gross negligence and except where the law does not allow a derogation.
14. Governing law and jurisdiction
The Agreement is governed by Italian law. Disputes between the parties fall under the jurisdiction of the Court of Lecco, where SoLink S.r.l. has its registered office.
Annex A — Description of the processing
Nature and purpose. Collection, recording, storage, calculation, consultation, transmission by email and deletion, solely to let the Controller make estimates and quotes, send proposals, receive requests and bookings and follow its Customers' plants with Sunnix Pro.
Data subjects. The Controller's customers and prospective customers who use its links or receive its quotes and proposals.
Data processed:
- address and coordinates of the property, in estimates, proposals, plant folders, bookings and requests from the plant check;
- plant data: power, roof planes, panels, estimated production; in a plant check, the production totals read from the inverter app and their summary;
- consumption and spending taken from the energy bill: the file is read in the Customer's browser and is not uploaded, only the figures are kept;
- name, phone, email and message of requests and bookings: only in transit to the Controller's email. They are not saved in the database, and stay for a limited time in the email service's logs;
- day, time, service and address of bookings, and a secret token to move or cancel them;
- the email of the Customer to whom the Controller sends a proposal, stored encrypted;
- the Customer's reply and comment on a proposal, the optional items they choose and, for a consumer, whether they ask to start before the 14-day withdrawal period ends; the opens of the proposal;
- job quotes: the job, the items, the prices, the texts and up to six photos with their captions, in a private store. Photos lose their GPS location before leaving the browser;
- "Your plant today": the production measured by monitoring, if the Customer shares it, or the inverter app figures the Controller types in;
- the town from which a link was opened, without name, email or IP address;
- the documents and images uploaded by the Controller;
- construction dates, stages and history of the plant, promised production.
The Customer's name does not reach the Processor: it stays in the Controller's browser, in the PDF and in the part of the link after the "#" sign, which the server does not receive.
Duration. That of the Agreement (point 10). Estimates made on the Controller's links do not expire by themselves: they stay until the Controller deletes them or closes the account.
Annex B — Security measures
- Encrypted connections (HTTPS/TLS) between browser, site, API and database.
- Passwordless account access, with a one-time link or code by email, and a limit on attempts.
- HttpOnly session cookie, which the page's scripts cannot read.
- Isolation between companies: every read and write goes through the API and is limited to the company of whoever is signed in; an automated test requires the company filter in every query.
- Database not exposed: Row Level Security on every table, no permissions for public roles and no function executable from outside. Only the Processor's servers access it.
- Application-level AES-256-GCM encryption of the emails of proposal recipients and of the credentials for inverter portals.
- Proposal and appointment links with unguessable secrets; actions started from emails, such as confirming an appointment, are signed.
- Job photos in a private store, shown through signed addresses that expire after 12 hours.
- Anti-abuse limits by IP address, stored only as a fingerprint.
- The email recipient never comes from the browser: the server derives it from the link or the appointment.
- Technical logs without emails or names: people appear under an internal identifier.
- Backups managed by the database provider, rotating within 30 days.
- Administrative access to the systems restricted to those who run the service for the Processor, with two-factor authentication.
- Access by the Processor's staff to an account only as described in point 4.2, and always logged.
Annex C — Authorised sub-processors
- Supabase Inc. (United States; servers in the European Union) — database, access, and storage of files and photos — all data in Annex A, except data only in transit — standard contractual clauses (Decision (EU) 2021/914), in its data processing agreement.
- Vercel Inc. (United States; site and API functions on servers in the European Union) — hosting of the site and the API — all data, in transit, and technical logs — EU-U.S. Data Privacy Framework.
- Twilio Inc., SendGrid service (United States) — sending emails — requests, bookings and proposals sent — EU-U.S. Data Privacy Framework.
- Upstash Inc. (United States; servers in the European Union) — anti-abuse limits and temporary weather cache — IP address fingerprints and coordinates rounded to about 100 metres — standard contractual clauses, in its data processing agreement.
- Google Ireland Ltd. and Google LLC — map, address search and roof data — addresses and coordinates — EU-U.S. Data Privacy Framework.
Stripe is not a sub-processor under this Agreement: it processes the Controller's payments, not its Customers' data. Open-Meteo and PVGIS (European Commission) receive only geographic coordinates. No artificial intelligence service receives Customers' data.