Reference copy — nothing to sign here. These are the master terms (Subscription Agreement + Data Processing Addendum) incorporated by reference into your Solar Nest™ Order Form. You accept them by signing the Order Form, which is sent to you separately for electronic signature.
Version 1.0 · Effective June 30, 2026 · Permanent link to this exact version:
mysolarnest.com/agreement-2026-06-30. Revisions are posted here with a new effective date; each prior version stays available at its own dated link.
SOLAR NEST™
Software-as-a-Service Subscription Agreement
Provided by Process Falcon, LLC · Governing law: State of Texas
This Software-as-a-Service Subscription Agreement (the "Agreement") governs each Order Form that incorporates it. It is entered into between Process Falcon, LLC, a Texas limited liability company ("Provider"), and the customer identified in the applicable Order Form ("Customer"). Solar Nest™ is Provider's enterprise workflow and operations platform designed for residential and commercial solar contractors. The Agreement takes effect as to a given Customer on the date of the last signature on the first Order Form referencing it (the "Effective Date"). Provider and Customer are each a "Party" and together the "Parties."
1. Definitions
- Services — the Solar Nest™ hosted software platform (the "Platform") and related services Provider makes available to Customer under an Order Form, including updates, integrations, and Support.
- Order Form — an ordering document or online order specifying the subscription, fees, term, and any optional modules or addenda, which incorporates this Agreement by reference.
- Authorized Users — Customer's employees and contractors permitted to use the Services. The subscription includes unlimited Authorized Users unless an Order Form states otherwise.
- Customer Data — electronic data and content submitted to the Services by or for Customer, excluding Usage Data and Reference Data.
- Personal Data — Customer Data that identifies or relates to an identifiable natural person, such as homeowner names, addresses, and contact details. Processing of Personal Data is governed by the Data Processing Addendum ("DPA") attached as Exhibit A.
- Sensitive Personal Data — dates of birth, Social Security numbers, driver's-license or other government-issued identifiers, financial-account numbers, and any other category of personal information subject to heightened legal protection. See §4.
- Usage Data — data that is aggregated and/or de-identified such that it does not identify Customer or any natural person, including data derived from Customer Data and from use of the Services. Addressed in Section 6.
- Reference Data — factual jurisdictional, utility, equipment, and financing-program information that is not proprietary to any one customer, including: (i) authority-having-jurisdiction (AHJ) requirements, permit fees, submission and inspection criteria, and processing timelines; (ii) utility and interconnection requirements, processes, timelines, document requirements, program/tariff information, and public contact information; (iii) equipment specifications and compatibility information; and (iv) financing-partner program requirements, categories, and processing information — regardless of the source from which such information was obtained. Reference Data excludes any customer's account credentials, login information, or portal access, and any customer's confidential commercial terms (see Section 7), and is expressly not Customer Data or Confidential Information. Addressed in Section 7.
- Completed Installation — a solar project recorded in the Services as having reached final installation. Used to determine Customer's pricing tier under Section 8.4.
- Confidential Information — non-public information disclosed by one Party to the other that is marked or reasonably understood to be confidential, excluding Usage Data and Reference Data.
2. The Services; License; Support
- Subject to this Agreement and payment of fees, Provider grants Customer a non-exclusive, non-transferable right during the Subscription Term to access and use the Services for Customer's internal business operations.
- Acceptable use. Customer will not (i) resell or provide the Services to third parties except as intended functionality; (ii) reverse engineer the Services; (iii) upload unlawful content or malware; (iv) use the Services in violation of law; (v) use the Services or any output to train or develop a competing artificial-intelligence model; (vi) attempt to extract prompts, system prompts, or model behavior from the Services; (vii) scrape or benchmark the Services without Provider's prior written consent; or (viii) use automated means to interfere with the operation or integrity of the Platform.
- No reliance on future functionality. Customer's purchase is not contingent on the delivery of any future functionality or feature, or on any oral or written public comment by Provider regarding future functionality.
- Provider may update the Services from time to time provided it does not materially degrade core functionality during the then-current term, and will use commercially reasonable efforts to give advance notice of materially adverse changes.
- Support. Provider will provide Support by email and in-app messaging during Provider's published support hours (business days, 9:00 a.m. to 5:00 p.m. Central, excluding U.S. federal holidays), with a target initial response within one (1) business day. Support levels may be expanded in an Order Form.
- AI features. Customer acknowledges that certain AI-powered features may transmit Customer prompts and related Customer Data to third-party AI providers solely for the purpose of generating requested outputs. Provider's current AI subprocessors are listed in the DPA.
3. Customer Data — Ownership & License to Provider
- Ownership. As between the Parties, Customer owns all right, title, and interest in and to Customer Data, subject to the licenses granted in this Agreement.
- License to Provider. Customer grants Provider a worldwide, non-exclusive, royalty-free right to host, access, use, process, transmit, and display Customer Data (i) to provide, maintain, secure, and improve the Services; (ii) to comply with applicable law; and (iii) to prevent or address security, support, and technical issues, and as further permitted in Sections 6 and 7.
- Customer responsibility. Customer is solely responsible for the accuracy, quality, and legality of Customer Data and for having all rights, consents, and notices necessary to upload it and to authorize Provider's processing — including for any Personal Data of homeowners or other third parties.
- Customer backups. Customer is responsible for maintaining its own backup copies of Customer Data. Provider's export functionality is provided as a convenience and is not intended to replace Customer's own backup procedures.
- Customer configurations. Customer-specific workflows, templates, automations, dashboards, and configurations created by Customer remain Customer Data. Nothing in this Agreement prevents Provider from using generalized ideas, concepts, techniques, know-how, or experience acquired while providing the Services, provided Provider does not disclose Customer Confidential Information.
4. Sensitive Personal Data — Data Minimization
- Default exclusion. The Services are not intended to collect or store Sensitive Personal Data. Customer will not submit, and will configure its use of the Services so as not to submit, Sensitive Personal Data unless such collection is expressly enabled for Customer in an Order Form or written addendum.
- If enabled. Where an Order Form or addendum expressly enables Sensitive Personal Data (for example, to satisfy a financing partner's underwriting requirements), the additional security and processing terms in that addendum and the DPA apply, and the elevated liability cap in §13.1(b) applies to that category.
- Customer responsibility. If Customer submits Sensitive Personal Data without it being enabled under §4.1, Customer does so at its own risk and is responsible for the consequences, irrespective of any act or omission of Provider.
5. Confidentiality
- Each Party will protect the other's Confidential Information using at least reasonable care, use it only to perform under this Agreement, and not disclose it except to personnel and advisors with a need to know who are bound by confidentiality.
- Exclusions: information that is or becomes public without breach, was known without obligation, is independently developed, or is rightfully received from a third party. For clarity, Usage Data and Reference Data are not Confidential Information.
- Either Party may seek injunctive relief for a breach or threatened breach of this Section, in addition to other remedies (see §15.2).
6. Usage Data (Aggregated / De-identified Data)
- Right and ownership. Provider may create Usage Data from Customer Data and from use of the Services. Provider owns all right, title, and interest in and to Usage Data, and may use it during and after the Subscription Term to operate, analyze, support, develop, and improve the Services and Provider's other products, and to produce industry benchmarks, statistics, research, and marketing materials. Usage Data may include, by way of example, operational timing and cycle-time metrics and the incidence of project scope items and adders (for instance, how often a given scope item occurs by jurisdiction or utility), in each case in aggregated and/or de-identified form and excluding any pricing, cost, or margin figures.
- Safeguards. Provider will: (i) use Usage Data only in aggregated and/or de-identified form that does not identify Customer or any natural person; (ii) implement reasonable technical and organizational measures to prevent re-identification or re-association with any individual; (iii) publicly commit to maintain such data in de-identified form and not attempt to re-identify it; and (iv) require any third party to whom it discloses Usage Data to comply with equivalent restrictions.
- This Section survives termination or expiration of this Agreement.
7. Reference Data (AHJ / Utility / Equipment / Financing Libraries)
- The Parties acknowledge that Reference Data consists of factual jurisdictional, utility-interconnection, equipment, and financing-program information that is not proprietary to Customer. Reference Data is excluded from Customer Data and Confidential Information.
- Customer grants Provider a perpetual, irrevocable, worldwide, royalty-free, sublicensable right to retain, use, reproduce, and share Reference Data, including to build and maintain cross-customer permitting, utility-interconnection, equipment, and financing-program libraries and to provide the Services to other customers. This right survives termination.
- For clarity, this Section does not grant Provider rights to: (i) Customer's account credentials, login information, or portal access for any AHJ, utility, financing partner, or other third-party system; or (ii) Customer's genuinely confidential business information (such as Customer's pricing, redlines, margins, adder costs, customer lists, or project financials). Such items remain Customer Data and/or Confidential Information.
8. Fees & Payment
- Fees. Customer will pay the fees stated in the applicable Order Form ("Fees"). Unless an Order Form states otherwise, the subscription Fee is billed monthly in advance, prorated for the first partial month, commencing when Customer receives login access. Fees are exclusive of taxes and, except as expressly provided, are non-refundable.
- Authorization to charge. Customer will provide valid payment information and authorizes Provider (or its payment processor) to charge Customer's payment method — by ACH and/or card — on a recurring basis for the Fees for the duration of the Term. A processing fee may apply and will be disclosed at the time of the transaction.
- Annual fee adjustment. On each annual anniversary of the Effective Date, Provider may increase the subscription Fee by up to the greater of seven percent (7%) or the percentage change in the U.S. Consumer Price Index over the prior 12 months, on at least sixty (60) days' written notice.
- Volume-based pricing tier. Provider reviews Customer's Completed Installations over the trailing twelve (12) months on a quarterly basis. If that volume moves Customer into a different standard pricing tier under the then-current tier schedule (illustratively: under 300 / 300–750 / 750–1,500 Completed Installations per year), Provider will adjust the subscription Fee to the corresponding tier on at least thirty (30) days' written notice; any founding or promotional discount continues to apply at each tier. To avoid frequent changes for Customers whose volume fluctuates near a threshold, Provider may defer a tier adjustment unless Customer remains within the new tier for two consecutive quarterly reviews, and may apply reasonable administrative thresholds before adjusting. Downward adjustments take effect prospectively only and do not entitle Customer to credits or refunds of amounts already paid.
- Late and overdue amounts. Amounts unpaid for fifteen (15) days, or for which Customer withdraws ACH authorization without providing an alternative method within fifteen (15) days, are "Overdue." Overdue amounts accrue interest at the lesser of 1.5%/month or the maximum permitted by law, and Customer will reimburse Provider's reasonable costs of collection, including attorneys' fees. Provider's remedies for Overdue amounts include suspension under §9.3.
- Chargebacks. Before disputing a charge with its card issuer, Customer will first contact Provider to resolve the issue. Unauthorized chargebacks may result in suspension or termination.
- Taxes. Fees are exclusive of taxes; Customer is responsible for all taxes other than Provider's income or franchise taxes.
- Third-party and pass-through costs. Customer is responsible for the costs of any third-party tools or integrations it elects to use through the Services (for example, monitoring, design, or financing integrations), as identified in the applicable Order Form.
9. Term; Termination; Suspension
- Term. Unless the Order Form specifies a month-to-month term, the initial Subscription Term is twelve (12) months from the Effective Date and renews for successive twelve (12)-month terms unless either Party gives written non-renewal notice at least thirty (30) days before the end of the then-current term. The Order Form may instead specify a month-to-month term renewing monthly on the same notice.
- Termination for cause. Either Party may terminate for the other's material breach not cured within thirty (30) days of written notice. Either Party may terminate immediately if the other becomes the subject of a bankruptcy or insolvency proceeding not dismissed within sixty (60) days.
- Suspension. Provider may suspend the Services on ten (10) days' prior written notice if Fees are Overdue, and until paid; Fees continue to accrue during any such suspension and are not tolled. Provider may also immediately suspend access if Customer's use threatens the security, integrity, or availability of the Services or the services provided to other customers (for example, malware, denial-of-service activity, credential abuse, excessive automation, or attempts to compromise the system). Provider will not be liable for any consequence of a suspension made in accordance with this Section.
- Early termination for convenience. If Customer terminates a committed-term subscription for convenience (i.e., other than for Provider's uncured material breach), the subscription Fees for the remainder of the then-current Subscription Term become due as an early-termination charge. This Section does not apply to month-to-month subscriptions.
- Effect; export. On termination, Customer's access ends. For thirty (30) days after termination, Provider will, on request, make Customer Data available for export in a commercially reasonable, machine-readable format (such as CSV or JSON), as determined by Provider; thereafter Provider may delete it, subject to the DPA and Sections 6 and 7 (which survive).
- Transition assistance. Migration or transition assistance beyond the standard export described in §9.5 (for example, database extracts, custom migration work, or import into another platform's format) is not included and, upon Customer's request, may be provided at Provider's then-current professional-services rates.
10. Security & Data Protection
- Provider will maintain reasonable administrative, technical, and physical safeguards designed to protect Customer Data appropriate to its sensitivity.
- Where Provider processes Personal Data on Customer's behalf, the DPA (Exhibit A) applies. Customer is the controller/business and Provider is the processor/service provider with respect to such Personal Data.
- Consistent with §4, Customer will not submit Customer Data requiring safeguards beyond those described in the Documentation or DPA unless the Parties have agreed to such measures in writing.
- No guarantee of absolute security. No software, cloud service, or Internet transmission can be guaranteed to be completely secure. Provider implements reasonable administrative, technical, and organizational safeguards but cannot guarantee absolute security.
11. Intellectual Property; Feedback
- Provider owns all right, title, and interest in and to the Services, the Solar Nest™ Platform, and all software, content, and improvements, including all intellectual property rights therein, and including Usage Data and Reference Data. No rights are granted except as expressly stated.
- Feedback. If Customer provides suggestions or feedback, Provider may use it without restriction or obligation, and Provider owns any improvements it develops, whether or not inspired by such feedback.
12. Warranties; Disclaimer
- Provider warrants the Services will perform materially in accordance with their documentation during the Subscription Term. Customer's exclusive remedy for breach of this warranty is Provider's commercially reasonable effort to correct the non-conformity, and if it cannot, termination and a pro-rata refund of prepaid, unused fees.
- No service-level commitment. The Services may be temporarily unavailable for scheduled maintenance, unscheduled emergency maintenance, or causes beyond Provider's reasonable control. Provider does not commit to any uptime percentage or service-level credit except under a separate Service Level Agreement, if any, executed by the Parties. Provider will use reasonable efforts to give advance notice of scheduled downtime.
- EXCEPT AS EXPRESSLY STATED, THE SERVICES ARE PROVIDED "AS IS" AND "AS AVAILABLE," AND PROVIDER DISCLAIMS ALL IMPLIED WARRANTIES, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, NON-INFRINGEMENT, TIMELINESS, AND ACCURACY OF DATA. PROVIDER DOES NOT WARRANT THAT THE SERVICES WILL BE UNINTERRUPTED OR ERROR-FREE OR WILL MEET CUSTOMER'S REQUIREMENTS.
13. Limitation of Liability
- (A) GENERAL CAP. EXCEPT AS PROVIDED IN (B) AND (D), EACH PARTY'S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATED TO THIS AGREEMENT WILL NOT EXCEED THE FEES PAID OR PAYABLE BY CUSTOMER IN THE SIX (6) MONTHS BEFORE THE EVENT GIVING RISE TO LIABILITY.
- (B) DATA-PROTECTION SUPER-CAP. FOR LIABILITY ARISING FROM A BREACH OF A PARTY'S DATA-PROTECTION OBLIGATIONS UNDER SECTION 10 OR THE DPA, THE CAP IS THE FEES PAID OR PAYABLE BY CUSTOMER IN THE TWELVE (12) MONTHS BEFORE THE EVENT GIVING RISE TO LIABILITY.
- (C) EXCLUSION OF INDIRECT DAMAGES. NEITHER PARTY IS LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, OR LOST PROFITS OR DATA, EVEN IF ADVISED OF THE POSSIBILITY. THE EXISTENCE OF MULTIPLE CLAIMS WILL NOT INCREASE THE CAPS ABOVE.
- (D) CARVE-OUTS. THE CAPS AND EXCLUSIONS DO NOT APPLY TO: (i) CUSTOMER'S PAYMENT OBLIGATIONS; (ii) A PARTY'S INDEMNIFICATION OBLIGATIONS; (iii) BREACH OF CONFIDENTIALITY; OR (iv) A PARTY'S FRAUD, WILLFUL MISCONDUCT, OR GROSS NEGLIGENCE.
14. Indemnification
- By Provider. Provider will defend Customer against third-party claims that the Services, as provided, infringe a U.S. intellectual-property right, and pay resulting damages finally awarded or settled, excluding claims arising from Customer Data, Customer's misuse, or combination with non-Provider items. Provider may procure the right to continue use, modify or replace the Services, or terminate and refund prepaid unused Fees.
- By Customer. Customer will defend Provider against third-party claims arising from Customer Data or Customer's failure to have the rights, consents, or notices required to upload it (including any homeowner Personal Data or, where enabled, Sensitive Personal Data), and pay resulting damages finally awarded or settled.
- The indemnified Party must give prompt notice, reasonable cooperation, and control of defense to the indemnifying Party; no settlement imposing obligations on the indemnified Party without its consent (not to be unreasonably withheld).
15. Pilot & Beta Programs
- Pilots and founding-partner programs. Provider may offer trial, pilot, or founding design-partner arrangements at reduced or no cost for a stated period, as set forth in an Order Form. Eligibility is at Provider's discretion. Unless the Order Form states otherwise, at the end of the pilot period the subscription converts to the paid tier identified in the Order Form, and founding pricing (if any) is governed by that Order Form.
- Beta features. Features identified as beta, preview, or "early access" are provided "as is," may contain errors, may be modified or discontinued at any time, and may not preserve Customer Data. Customer should not rely upon beta features for production operations. Beta features are excluded from the warranty in §12.1.
16. Publicity & Marketing
- Provider may use Customer's name and logo in a factual manner on Provider's website and in communications with existing or prospective customers. Customer may opt out by written notice.
- Any press release, case study, or marketing use beyond name and logo requires Customer's prior written consent.
- For clarity, Provider's use of aggregated/de-identified benchmarks and statistics under Section 6 does not require consent because it does not identify Customer.
17. General
- Governing law. This Agreement is governed by the laws of the State of Texas, without regard to conflicts of law.
- Dispute resolution; arbitration. Except for claims for injunctive relief (which may be brought in court), any dispute arising out of or relating to this Agreement will be finally resolved by binding arbitration administered by the American Arbitration Association under its Commercial Arbitration Rules before a single arbitrator, seated in Leander, Texas. Judgment on the award may be entered in any court of competent jurisdiction. The Parties consent to the exclusive jurisdiction and venue of the state and federal courts located in Williamson County, Texas for any permitted court proceeding.
- JURY-TRIAL WAIVER. EACH PARTY KNOWINGLY AND VOLUNTARILY WAIVES ANY RIGHT TO A TRIAL BY JURY FOR ANY DISPUTE ARISING OUT OF OR RELATING TO THIS AGREEMENT.
- Attorneys' fees. In any proceeding to enforce this Agreement, the prevailing Party is entitled to recover its reasonable attorneys' fees and costs.
- DTPA waiver. Customer represents it is a business with the knowledge and opportunity to engage counsel, and, to the extent permitted, waives its rights under the Texas Deceptive Trade Practices–Consumer Protection Act (Tex. Bus. & Com. Code § 17.41 et seq.).
- Force majeure. Except for payment obligations, neither Party is liable for delay or failure to perform due to causes beyond its reasonable control, including acts of God, war, civil unrest, pandemic, governmental action, denial-of-service attacks, or failures of telecommunications or third-party services.
- Assignment. Neither Party may assign without the other's consent, except to a successor in a merger or sale of substantially all assets.
- Independent contractors. The Parties are independent contractors; nothing creates a partnership, agency, or joint venture.
- Order of precedence. The Order Form controls for conflicting commercial terms; this Agreement controls for conflicting legal terms. Pre-printed terms on any Customer purchasing document have no effect.
- Modifications. Provider may modify this Agreement by posting a revised version at its designated agreement URL (an unlinked, non-indexed page), effective on the first day of the month following posting; the then-current version applies to each Order Form. Provider will give email notice of any material change at least thirty (30) days in advance, and Customer's continued use after the effective date constitutes acceptance.
- Notices in writing; entire agreement; no waiver by inaction; severability; counterparts and electronic signatures permitted.
No separate signature required. This Agreement and its Data Processing Addendum are the master terms incorporated by reference into your Solar Nest™ Order Form. You accept them by signing that Order Form, which is delivered separately for electronic signature. Executing the Order Form binds both Parties to this Agreement and the DPA as of the Effective Date — there is nothing to sign on this page.
SOLAR NEST™
Data Processing Addendum
Provided by Process Falcon, LLC ("Provider / Service Provider") for the Solar Nest™ Platform · Customer — "Controller / Business"
This Data Processing Addendum ("DPA") forms part of and is incorporated into the SaaS Subscription Agreement between Process Falcon, LLC ("Provider") and the customer identified in the Agreement ("Customer"). In case of conflict regarding Personal Data, this DPA controls.
1. Roles & Definitions
- "Personal Data," "Process/Processing," "Business," "Service Provider," and "Consumer" have the meanings in the California Consumer Privacy Act, as amended by the CPRA, and analogous U.S. state privacy laws ("Applicable Privacy Laws").
- As to Personal Data processed under the Agreement, Customer is the Business/Controller and Provider is the Service Provider/Processor. Provider Processes Personal Data only on Customer's behalf.
- The categories of data subjects (e.g., Customer's homeowner end-customers and personnel) and Personal Data (e.g., name, address, and contact details) are described in Schedule 1. Sensitive Personal Data (such as date of birth, Social Security numbers, and government-issued identifiers) is out of scope and will not be Processed unless expressly enabled for Customer under Section 4 of the Agreement and a Sensitive Data Addendum.
2. Processing Instructions; Restrictions
- Provider will Process Personal Data only (i) to provide the Services, (ii) in accordance with Customer's documented instructions (including the Agreement), and (iii) as required by law (with notice to Customer where permitted).
- As a Service Provider, Provider will not: sell or share Personal Data; retain, use, or disclose it for any purpose other than the business purposes specified in the Agreement; or combine it with personal information from other sources, except as permitted by Applicable Privacy Laws. Provider certifies it understands and will comply with these restrictions.
- Permitted internal use of de-identified and aggregated data as set out in Section 6 (Usage Data) of the Agreement is consistent with this DPA, provided the de-identification safeguards there are maintained.
3. Customer Responsibilities
- Customer has sole responsibility for the accuracy, quality, and legality of Personal Data and the means by which it acquired it, and for providing all notices and obtaining all consents/authorizations required for Provider to Process it (including any homeowner Personal Data).
- Customer will not instruct Provider to Process Personal Data in violation of Applicable Privacy Laws.
4. Security
- Provider will implement and maintain reasonable and appropriate technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, appropriate to the nature of the data. A summary of current measures is in Schedule 2.
- Provider limits access to Personal Data to personnel who need it and are bound by confidentiality.
5. Sub-processors
- Customer authorizes Provider to engage sub-processors to support the Services. Provider will impose data-protection obligations on each sub-processor that are no less protective than those in this DPA and remains responsible for their performance.
- Provider's current sub-processors are listed in Schedule 3. Provider will give notice of a new sub-processor; Customer may object on reasonable data-protection grounds within thirty (30) days, and if the Parties cannot resolve the objection, Customer may terminate the affected Services and receive a pro-rata refund of prepaid, unused fees.
6. Personal Data Breach
Provider will notify Customer without undue delay after becoming aware of a Personal Data breach affecting Customer's Personal Data, and will provide information reasonably available to help Customer meet its notification obligations.
7. Assistance; Data-Subject Requests
Taking into account the nature of Processing, Provider will provide reasonable assistance to Customer in responding to verifiable consumer/data-subject requests (access, deletion, correction, opt-out) and, where applicable, in conducting risk assessments. If Provider receives a request directly, it will (unless legally prohibited) direct the individual to Customer.
8. Return & Deletion
On termination, Provider will, at Customer's election and within the export window in the Agreement, make Customer's Personal Data available for export and thereafter delete it, except (i) de-identified/aggregated Usage Data, (ii) Reference Data, and (iii) copies required by law or routine backup cycles, which Provider will protect and not actively use.
9. Audit
On reasonable written request (no more than annually, except after a breach), Provider will make available information reasonably necessary to demonstrate compliance with this DPA, which may be satisfied by a then-current third-party report or completed security questionnaire.
Schedule 1 — Nature of Processing
| Item | Description |
| Subject matter | Provision of the Solar Nest™ Platform to Customer. |
| Duration | The Subscription Term, plus the post-termination export/deletion window. |
| Categories of data subjects | Customer's homeowner end-customers; Customer's personnel and contractors. |
| Categories of Personal Data | Name, address, email, phone; project/service details. |
| Sensitive data | Out of scope by default. Date of birth, Social Security numbers, and government-issued identifiers (e.g., driver's license) are not Processed unless expressly enabled per Section 4 of the Agreement and a Sensitive Data Addendum. |
Schedule 2 — Security Measures (summary)
Encryption in transit (TLS); access controls and least-privilege; tenant isolation via row-level security; hosting on reputable cloud infrastructure; logging and monitoring; secrets stored in a managed vault; regular dependency/security updates.
Schedule 3 — Authorized Sub-processors
| Sub-processor | Purpose |
| Supabase | Application database, authentication, file storage |
| Vercel | Application hosting / delivery |
| OpenRouter (and underlying model providers) | AI/LLM features (e.g., Ferris assistant) |
| Resend | Transactional email |
| Twilio | SMS / messaging |
| Enphase | Solar production/monitoring integration (where enabled) |
© 2026 Process Falcon, LLC. All rights reserved. Solar Nest™ is a product of Process Falcon, LLC.