Data Processing Agreement (the "DPA")

This Annex contains the Data Processing Agreement on the processing of personal data (the "Data Processing Agreement"), the purpose of which is to determine, in a transparent and mutually agreed manner, the respective data protection obligations and responsibilities of the Parties, by virtue of this Agreement, under which NEOVEE SOLUTIONS SL ("TREE-NATION"), hereinafter the "Data Processor" or "Processor" will provide certain services involving access to personal data under the responsibility of the CUSTOMER, hereinafter the "Data Controller" or "Controller".

Therefore, in compliance with the obligations imposed by Regulation (EU) 2016/679 of the Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (hereinafter referred to as the GDPR), the Parties agree to enter into and sign this Data Processing Agreement, which shall be governed as set forth in Article 28 of the GDPR, and by the following:

CLAUSES

1. Purpose

In order to perform the services under the Agreement and to effectively provide the Services, the Processor may have access to personal data under the responsibility of the Controller.

The characteristics of the data processing to be carried out by the Processor on behalf of the Controller are specified in Appendix A.

2. Duration

This Agreement shall enter into force on the date it is signed. This Agreement is ancillary to the main Service Agreement and its duration is therefore linked to the duration of the main Service Agreement.

3. Obligations of the Data Controller

In addition to fulfilling of the obligations assigned to it in this Agreement, the Data Controller is responsible for carrying out the following tasks:

  • Provide or make available to the Processor the data referred to in Clause 1 of this document, as well as the necessary instructions to carry out the processing of the data in accordance with the terms established by the Data Controller.
  • Respond to the rights of data subjects affected by the processing, such as the rights of access, rectification, erasure and objection, restriction of processing, data portability and the right not to be subject to automated individual decisions, in cooperation with the Processor.
  • Carry out, where appropriate, an assessment of the impact on the protection of personal data of the processing operations to be carried out by the Processor.
  • Ensuring, prior to and during the processing, that the Data Processor complies with the applicable data protection provisions.
  • Supervise the processing, including carrying out inspections and audits.
  • Informing the Data Controller of any changes to the personal data provided, so that it can be updated.

In addition, the Data Controller guarantees that the data subject to processing as a result of the provision of the Services have been collected and processed by the Data Controller in accordance with the obligations established by the GDPR, taking into account in particular the need for a legal basis to legitimise the processing, as indicated in Article 6 of the GDPR.

4. Obligations of the Data Processor

The Processor represents and warrants to the Controller the following:

  • That it undertakes, in relation to the Services, to comply with the requirements of the GDPR and other applicable personal data protection legislation.
  • That it will maintain the confidentiality and secrecy of the personal data to which it has access.
  • That it will process and use the personal data to which it has access only as instated by the Data Controller, and in accordance with the purposes set out in the Agreement. Under no circumstances will it use this data for its own purposes.

Instructions in relation to the processing of the data are deemed to be included in this Data Processing Agreement and its Appendix A and any further instructions in the course of the provision of the Service shall be communicated to the Processor in writing.

If the Processor considers that complying with a particular instruction from the Controller may result in a breach of data protection regulations, the Processor shall immediately notify the Controller thereof. The Processor in this communication shall request the Controller to amend, withdraw or confirm the instruction given and may suspend compliance pending a decision by the Controller.

  • That it will not communicate to third parties, not even for conservation purposes, the data to which it has access through the Services. Neither will it carry out any elaborations, evaluations, or similar processes on this data, nor will it copy or reproduce, in whole or in part, any of the information, results or relations relating to such data, with the exception of the assumptions required by law.
  • That it shall appoint a Data Protection Officer ("DPO") or, if his or her appointment is not mandatory, a Privacy Contact Person. The contact details shall be as set out in Clause 8.
  • To ensure that the persons authorised to process personal data have undertaken, expressly and in writing, to comply with the established security measures and to respect the confidentiality of the data. Compliance with this obligation must be documented by the Data Processor and made available to the Data Controller.
  • That it will cooperate in the fulfilment of the Controller's obligations, and will offer support to the Controller, where appropriate and as requested by the Controller, in carrying out (i) impact assessments relating to the personal data to which it has access; (ii) prior consultations with the supervisory authority.
  • That it will keep a written record of the categories of processing activities carried out on behalf of the Controller with the content set out in art. 30 GDPR.

5. Security Breaches

The Processor shall notify the Controller, without undue delay, and in any event no later than within 24 hours, at the Controller’s address indicated in Clause 8, of any suspected or confirmed data protection incident within its area of responsibility. Among other things, it shall notify the Controller of any processing that may be considered unlawful or unauthorised, any loss, destruction or damage to data and any incident considered to be a breach of data security. The notification shall be accompanied by all relevant information for the documentation and communication of the incident to relevant authorities or affected data subjects.

The Processor shall also assist the Controller in relation to the notification obligations under the GDPR (in particular, Articles 33 and 34 of the GDPR) and any other applicable current or future regulation modifying or supplementing such obligations.

6. Response to Rights of data subjects

The Processor shall provide the information and/or documentation requested by the Controller in order to respond to requests for the exercise of rights that the Controller may receive from data subjects whose data are processed. The Processor shall provide such information within reasonable period of time and, in any case, sufficiently in advance to enable the Controller to comply with the legally applicable time limits for responding to the exercise of such rights.

When the data subjects exercise their rights of access, rectification, erasure and objection, limitation of processing, data portability and the right not to be subjected to automated individual decisions, the Data Processor shall notify the Data Controller by email to the address of the Data Controller indicated in Clause 8. The communication must be made immediately in order to be dealt with within the established legal deadlines, and in no case later than the working day following receipt of the request, and must be submitted to the Controller together with any information that may be relevant to its resolution.

7. Information and Audit Rights

The Processor shall provide the Controller with all information necessary to demonstrate compliance with the obligations set out under this Data Processing Agreement.

The Processor shall provide such assistance as may be required by the Controller for audits or inspections, carried out by the Controller or any other auditor authorised by the Controller.

In this regard, the Controller has the right, upon reasonable notice, to conduct one (1) inspection of the Processor's establishment(s) and/or systems per year for the purpose of verifying compliance with this Data Processing Agreement and data protection regulations in the processing of the Controller's data. Any auditor commissioned to conduct such audits must have demonstrable experience in conducting such audits. The audits or inspections shall not extend beyond what is necessary for the purpose described in this paragraph and shall not include systems owned by third parties or sub-processors.

If the result of the audit establishes that the Processor, or the data processing carried out by the Processor, does not comply with the data protection regulations, the Parties shall analyse the result and the Processor shall immediately take the necessary corrective measures for compliance as established by the Controller. The Controller may terminate the Data Processing Agreement for non-compliance by the Controller if the Processor Party fails to correct the detected non-compliance.

Each Party shall also bear its own costs associated with the audits referred to in this clause.

8. Data Protection Officer or Privacy Contact Person

Each Party has appointed a Data Protection Officer or, where such appointment is not mandatory, an employee/person to act as a point of contact for all matters relating to the processing of personal data and this Data Processing Agreement. The contact details of these persons are as follows:

  • On behalf of the Data Controller: indicated in the Data Controller's Account.
  • On the part of the Data Processor: legal@tree-nation.com.

The change of the authorized representative does not constitute an amendment to the Data Processing Agreement but shall be notified to the other Party in the usual means of communication specified in the Master Agreement.

9. Recruitment of subcontractors

The Controller grants the Processor a general authorisation for subcontracting part of the Services to third parties or subcontractors (the "Sub-processor"). The Processor shall inform the Controller of the processing operations to be subcontracted and clearly and unambiguously identify the subcontracting company and its contact details. The subcontracting may be carried out if the Controller does not express its opposition within fifteen (15) days.

The Processor shall exercise due diligence to choose only those Sub-processors that provide sufficient guarantees to implement appropriate technical and organisational measures, so that the outsourced processing is in compliance with the requirements of the GDPR and the protection of the rights of the data subjects subject to the processing is ensured.

The Sub-processor, who shall also have the status of processor, shall also be obliged to comply with the obligations imposed on the Processor and the instructions issued by the Controller, as set out in this Data Processing Agreement. It is incumbent upon the Processor to regulate the new relationship in a contract signed by the Processor and the Sub-processor, so that the Sub-processor is subject to the same conditions (instructions, obligations, security measures...) and with the same formal requirements as the initial Processor, with regard to the proper processing of personal data and the guarantee of the rights of the data subjects. In the event of non-compliance by the Sub-processor, the Processor shall remain fully liable to the Controller for compliance with the obligations contained in this Agreement.

The list of sub-processors authorised by the Controller is attached as Appendix B to this Agreement.

10. International Transfers

The Processor shall not carry out international transfers of personal data to which it has access, and for which the Controller is responsible, unless it has prior authorisation from the Controller or unless they are duly regularised in accordance with the provisions of articles 45, 46 or 47 of the GDPR.

11. Security

With regards to technical and organisational security measures, the Data Controller shall implement mechanisms to:

  • Ensure the continued confidentiality, integrity, availability, and resilience of processing systems and services.
  • Restore availability and access to personal data quickly in the event of a physical or technical incident.
  • Regularly verify, evaluate, and assess the effectiveness of the technical and organisational measures implemented to ensure the security of the processing.
  • Where appropriate, pseudonymise and encrypt personal data.

In particular, the Parties have agreed on a list of measures to be implemented by the Processor, set out in Appendix C to this Agreement.

These measures, and any others, may be modified by the Controller to adapt them to regulatory changes or to variations in the type of personal data to which the Processor will have access. Notwithstanding the foregoing, if the Controller, subsequent to the execution of the Agreement, requires the Processor to adopt or maintain security measures other than those agreed in this Appendix C, or if they are required by any future regulation, and this significantly affects the costs of providing the Services, the Processor and the Controller shall agree on the appropriate contractual measures to address the effect that such modifications may have on the price of the Services.

12. Destination of data

Upon termination of the provision of the Services, the Processor shall return or delete the personal data to which it has had access and any existing copies, as instructed by the Controller.

The Processor shall be obliged to return or delete, as the case may be: a) data contained in files under the responsibility of the Controller, made available to the Processor as a consequence of the provision of the Services; b) data generated by the Processor during the processing of data under the responsibility of the Controller; c) media on which these data are stored.

The Data Processor may keep a copy of the data duly blocked, for as long as liabilities may arise from the performance of the Services.

13. Responsibilities

The Data Processor shall be considered responsible for the processing, and shall be personally liable for any breaches that may occur, in the event that he/she use the data for any purpose other than that established in this Data Processing Agreement, communicate it to third parties, or use it improperly in any other way in violation of the GDPR.

The Controller shall inform the Processor immediately of the sanctioning procedures initiated against the Controller by the AEPD or any other competent authority, for such breaches or defective compliance, so that the Processor may assume the legal defence at its own expense, acting, always, in coordination with the Controller and preserving its public image and reputation.

APPENDIX A – DESCRIPTION OF PROCESSING

Purpose of processing:

Provision of Tree-Nation's platform and related Services, including project management, reforestation tracking, tree-gift delivery, account management, and customer support.

Nature of processing:

Collection, consultation, storage, organization, and communication necessary to operate the platform, including maintenance and support.

Categories of personal data:

  • Identification data (name, surname)
  • Contact data (email address, company name, job title/role)
  • Tree-gift recipient data (name, email, optional message)
  • Platform-usage data (account activity, logs)

Categories of data subjects:

Employees, customers, partners, and other end-users of Tree-Nation's corporate clients.

Retention:

For the duration of the service provision and thereafter only as required by law.

APPENDIX B – AUTHORIZED SUB-PROCESSORS

Sub-processorService ProvidedLocationTransfer Mechanism
Amazon Web Services (AWS) Hosting infrastructure USA EU-US DPF
HubSpot Inc. CRM and support platform USA EU-US DPF
Apollo.io, Inc. Lead enrichment and CRM data integration USA EU-US DPF
Mailgun Technologies, Inc. Transactional and marketing email delivery USA EU-US DPF
Hotjar Ltd. User behavior analytics and session recording EU (Malta) N/A (intra-EEA)
Google Workspace (Google LLC) Productivity and internal communication USA EU-US DPF
Tableau Software, LLC (Salesforce) Business intelligence and analytics platform USA EU-US DPF
Stripe Payments Europe Ltd. (TBC) Payment processing EU / USA SCC / DPF

APPENDIX C – SECURITY MEASURES

The Processor applies, both at the time of determining the means of processing and at the time of the processing itself, appropriate technical and organisational measures, such as those included in this document and mentioned in the body of the Data Processing Agreement, designed to effectively implement data protection principles, such as data minimisation, and to integrate the necessary safeguards into the processing.

The person in charge ensures that the following measures are implemented:

  • Physical security – Controlled office access, key-card entry, alarm and CCTV systems, secure AWS data centers with industry-standard certifications.
  • Access control & authentication – Unique user credentials, strong password policies, Google SSO, role-based permissions, immediate de-provisioning upon termination.
  • Encryption – SSL/TLS encryption for data in transit; encryption of sensitive data at rest.
  • Endpoint security – Managed devices with antivirus, firewalls, and remote-wipe capability.
  • Data backup & recovery – Daily backups across multiple EU data centers; tested disaster-recovery plan.
  • Logging & monitoring – Activity logs and audit trails for key systems; change tracking.
  • Testing & evaluation – Annual security audits, vulnerability assessments, and staff awareness testing (including phishing simulations).
  • Incident response – Documented internal procedure for detection, escalation, notification, and mitigation of security incidents.

This DPA is incorporated by reference into Tree-Nation's Terms of Service and applies automatically to all business Customers. A signed copy is available upon request at legal@tree-nation.com.