RateGrid

Data Processing Addendum

Version 2026-08-29-r3 · reproduces sections 11.5 and 11.9 to 11.11 of the terms

You probably do not need to sign this. The terms in it are already binding on RateGrid through sections 11.5 and 11.9 to 11.11 of the Terms of Service, which every customer accepts at signup. This page exists because some compliance programs require a separate document with a signature block, and asking for one should not be a negotiation. It grants nothing further and imposes nothing further. If your counsel is satisfied by the Terms, you are already covered.

1. What this is

1.1 This Data Processing Addendum (the "Addendum") forms part of the Terms of Service between RateGrid LLC, a Wisconsin limited liability company ("RateGrid"), and the customer accepting them ("you"). Capitalized terms not defined here have the meaning given in the Terms.

1.2 This Addendum applies where Customer Inputs contain personal information relating to an identifiable individual — typically a utility customer of yours whose address, consumption or program enrollment you send to the Service.

1.3 Where this Addendum and the Terms address the same subject, they are intended to say the same thing. If they nonetheless conflict, this Addendum controls for the processing of personal information, and the Terms continue to govern everything else.

2. Roles

2.1 You are the business, controller or equivalent. RateGrid is your service provider, contractor or processor.

2.2 RateGrid processes personal information contained in Customer Inputs only on your documented instructions. The Terms, this Addendum, and your use of the API are those instructions. RateGrid will tell you if it believes an instruction infringes applicable data protection law.

3. The required terms

3.1 This section is the contract that the California Consumer Privacy Act and its regulations require between a business and its service provider, and that comparable state laws require between a controller and its processor. RateGrid:

(a) will not retain, use or disclose personal information contained in Customer Inputs for any purpose other than the business purposes specified in the Terms — providing the Service, computing and returning Output, and operating and securing the Service — or as the applicable statute otherwise permits;

(b) will not retain, use or disclose that information for any commercial purpose of its own, including any purpose unrelated to providing the Service to you;

(c) will not sell or share that information, as those terms are defined under the California Consumer Privacy Act, and will not retain, use or disclose it outside the direct business relationship between you and RateGrid;

(d) will not combine it with personal information received from any other source, except as the applicable statute permits a service provider to do;

(e) certifies that it understands the restrictions in (a) to (d) and will comply with them;

(f) will assist you, by reasonable and appropriate means and taking into account the nature of the processing, in responding to a verifiable consumer request to know, delete or correct, and in meeting your own security and assessment obligations;

(g) will notify you without undue delay if it determines it can no longer meet its obligations under the applicable statute, and grants you the right, on notice, to take reasonable and appropriate steps to stop and remediate unauthorized use of personal information; and

(h) engages the subprocessors identified in the privacy notice, each under written terms no less protective than these, and will give notice before adding another.

4. Nature and duration of the processing

4.1 Subject matter. The calculation of electricity bill estimates from tariff data and the inputs you supply.

4.2 Individuals. The utility customers to whom Customer Inputs relate.

4.3 Categories of personal information. Those the API accepts: addresses and coordinates, consumption and production profiles, system parameters, and income-qualified program flags. The Terms prohibit you from sending anything else, and section 11.6 of the Terms lists what must not be sent.

4.4 Duration. For the duration of the request. Inputs sent to the calculation endpoints are processed to compute the response and then discarded; they are not retained, and request and response bodies are not logged. Section 11.2 of the Terms governs retention and nothing in this Addendum extends it.

5. Security, breach and deletion

5.1 Security. RateGrid maintains the safeguards described in section 25.4 of the Terms and in the privacy notice: TLS in transit, API keys stored as a hash and a short prefix, no logging of request or response bodies, and production access restricted on a least-privilege basis.

5.2 Breach notification. Section 25.5 of the Terms applies: notice without undue delay and in any event within 72 hours of RateGrid determining that a security incident has resulted in unauthorized acquisition of personal information, by email to the address on your account.

5.3 Deletion and return. Because inputs are not retained, there is ordinarily nothing to delete or return at the end of the relationship. Account records are dealt with in the privacy notice, and you may request their deletion at support@rategrid.dev.

6. Audits and information

6.1 On reasonable written request, and not more than once in twelve months absent a documented incident, RateGrid will provide the information reasonably necessary for you to verify compliance with this Addendum. The response will be a written description and the published verification materials, not an on-site inspection or a completed enterprise questionnaire, unless separately agreed under section 1.3 of the Terms.

7. Execution

7.1 To execute this Addendum, send a copy signed on your behalf to support@rategrid.dev, identifying the account email it applies to. RateGrid will countersign and return it.

7.2 Signing changes no obligation on either side. Everything in this Addendum is already binding through the Terms.

← terms