← Back to Admin | DPA Template — Saha Sales Inc. dba Saha Lighting Solutions

Data Processing Agreement

This Data Processing Agreement ("DPA") is entered into between Saha Sales Inc., a California corporation doing business as Saha Lighting Solutions (Processor), and the Client identified in the account, Order Form, or Master Service Agreement governing that Client's use of the Lighting Studio platform (Controller), and forms part of that Master Service Agreement or Terms of Service.

Version: June 18, 2026  ·  Effective as of the Controller's acceptance of the Agreement.

0. Incorporation and Effect

This DPA is incorporated by reference into, and forms part of, the Master Subscription Agreement or Terms of Service between the parties (the "Agreement"). Where Applicable Data Protection Law requires a controller-processor contract (including GDPR Article 28, UK GDPR, and CCPA/CPRA), this DPA is binding on the parties and effective as of the Controller's acceptance of the Agreement, without the need for a separate signature. Where the parties do not execute a counter-signed copy, the Controller is the Client identified in the Agreement, and the Controller-identification details below are deemed completed by the Client's account registration and any applicable Order Form. The signature block below is provided solely for Clients who require a counter-signed copy and is not a condition of this DPA's effectiveness.

Parties

Processor (Service Provider) — Data Importer

Saha Sales Inc. dba Saha Lighting Solutions
a California corporation
1823 N Solano Ave
Ontario, CA 91764
Email: support@sahalighting.com

Controller (Client) — Data Exporter

The Controller and data exporter is the Client named in the account, Order Form, or Master Service Agreement governing that Client's use of the Services, together with the company name, address, data protection contact, and contact email recorded for that Client in its account registration and any applicable Order Form. These details are incorporated by reference and do not require completion here for this DPA to be effective.

1. Definitions

For the purposes of this DPA, the following terms have the meanings set out below:

2. Scope and Purpose of Processing

2.1 Role of the Parties. The Controller is the data controller in respect of Personal Data processed through the Services. The Processor processes Personal Data only on behalf of and under the documented instructions of the Controller, as set out in this DPA and the Principal Agreement.

2.2 Purpose. The Processor shall process Personal Data only for the purposes of providing the Services, including: hosting and operating the lighting layout platform; authenticating administrative users; delivering transactional emails; processing subscription payments; and providing usage analytics to the Controller. Any processing beyond these purposes requires the prior written consent of the Controller or a separate legal basis under Applicable Data Protection Law.

2.3 Instructions. The Controller's instructions are set out in this DPA and the Principal Agreement. The Controller may issue additional written instructions at any time. If the Processor believes an instruction violates Applicable Data Protection Law, it shall promptly notify the Controller.

3. Categories of Personal Data and Data Subjects

The Processor processes the following categories of Personal Data on behalf of the Controller:

CategoryData ElementsData Subjects
Account Data Email address, hashed password, role, account creation date Client's designated administrator users
Usage Analytics Data Fixture selections, tool type used, session ID (random, non-persistent), page URL, referrer URL, job name (if entered by end user), timestamp End users of the Client's public-facing lighting tools (only if tracking is enabled by the Controller)
Billing Contact Data Billing email address, Stripe customer identifier, subscription status Client's billing contact or administrator
Technical / Log Data IP addresses, browser type, request timestamps, error logs All visitors and admin users

The Processor does not knowingly process special categories of Personal Data (as defined under GDPR Article 9) on behalf of the Controller. The Controller warrants that it will not upload or cause to be processed through the Services any special category data without prior written agreement from the Processor.

4. Data Subject Rights

4.1 Assistance. Taking into account the nature of the processing, the Processor shall assist the Controller by appropriate technical and organisational measures in fulfilling the Controller's obligations to respond to Data Subject rights requests, including requests for access, rectification, erasure, restriction, portability, and objection, as required under Applicable Data Protection Law.

4.2 Forwarding Requests. If the Processor receives a Data Subject rights request directly, it shall promptly forward it to the Controller (and in any case within three (3) business days of receipt) and shall not respond to the Data Subject except to acknowledge receipt and confirm the Controller is the appropriate party to address the request, unless otherwise instructed by the Controller.

4.3 Data Export. The Services include an account data export feature that allows the Controller to download its data in a portable format (ZIP archive). This export functionality satisfies the Processor's technical assistance obligation for portability requests relating to Controller account data.

5. Security Measures

The Processor shall implement and maintain appropriate technical and organisational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. These measures include, at a minimum:

The Processor will review and update these measures periodically to account for evolving threats and changes in the Services.

6. Sub-Processors

6.1 Authorization. The Controller provides general authorisation for the Processor to engage the Sub-Processors listed below. The Processor shall inform the Controller of any intended changes concerning the addition or replacement of Sub-Processors, giving the Controller at least thirty (30) days to object before the change takes effect. This DPA and its list of Approved Sub-Processors are identified by the Template version date shown above; the Processor will reference that version date when notifying the Controller of any addition to or replacement of a Sub-Processor.

6.2 Sub-Processor Obligations. The Processor shall ensure that each Sub-Processor is bound by data protection obligations no less protective than those set out in this DPA, by way of a written contract.

6.3 Approved Sub-Processors:

Sub-ProcessorLocationPurposePrivacy Policy
Stripe, Inc. United States Payment processing, subscription billing, and billing portal stripe.com/privacy
Resend, Inc. United States Transactional email delivery resend.com/privacy
Railway Corp. United States Cloud application hosting and managed infrastructure railway.app/legal/privacy
Cloudflare, Inc. / Amazon Web Services, Inc. United States (global CDN/storage) Object storage for uploaded files and backup archives cloudflare.com/privacypolicy / aws.amazon.com/privacy
Functional Software, Inc. (Sentry) United States Application error monitoring and diagnostics sentry.io/privacy

7. International Data Transfers

7.1 Transfers Outside the EEA/UK. Where Personal Data originating in the European Economic Area (EEA) or the United Kingdom is transferred to Sub-Processors or infrastructure located outside the EEA or UK (including the United States), the Processor shall ensure that an appropriate safeguard is in place as required by GDPR Chapter V or the UK GDPR, as applicable.

7.2 Standard Contractual Clauses. For transfers from the EEA to third countries that have not received an adequacy decision, the parties hereby incorporate the Standard Contractual Clauses adopted by the European Commission under Decision 2021/914/EU (Module Two: Controller to Processor), which are incorporated by reference into this DPA and available at eur-lex.europa.eu. In the event of any conflict between the SCCs and this DPA, the SCCs shall prevail in respect of the transfer. For the purposes of the SCCs incorporated above, the Parties agree the following operative selections: (i) only Module Two (Controller-to-Processor) applies; (ii) the optional docking clause in Clause 7 applies; (iii) under Clause 9, Option 2 (general written authorisation) applies, and the Processor shall notify the Controller of any intended addition or replacement of Sub-Processors in accordance with Section 6.1 of this DPA, giving the Controller at least thirty (30) days to object before the change takes effect; (iv) under Clause 11, the optional independent-dispute-resolution language does NOT apply; (v) under Clause 17, the SCCs are governed by the law of Ireland (this completes the reference in Section 13 of this DPA to "the EU Member State specified therein"); (vi) under Clause 18(b), disputes between the Parties under the SCCs shall be resolved before the courts of Ireland; and (vii) the Appendix/Annexes to the SCCs are populated as follows — Annex I.A (List of Parties) by the Parties section of this DPA; Annex I.B (Description of Transfer) by Sections 2 and 3; Annex I.C (Competent Supervisory Authority) is determined under Clause 13 of the SCCs from the applicable exporter, representative, and data-subject facts: it is the supervisory authority of the EEA Member State in which the Controller (as data exporter), or its EU/EEA representative where one is appointed, is established or, where the Controller is not established in the EEA but the SCCs apply by virtue of GDPR Article 3(2), the supervisory authority of the EEA Member State in which the relevant Data Subjects are located, namely the Irish Data Protection Commission where that Member State is Ireland; Annex II (Technical and Organisational Measures) by Section 5; and Annex III (List of Sub-Processors) by the table in Section 6.3.

7.3 UK Addendum. For transfers of Personal Data subject to the UK GDPR, the parties shall execute the UK International Data Transfer Addendum (IDTA) issued by the UK Information Commissioner's Office, as applicable.

7.4 Transfer Impact Assessment. The Processor shall cooperate in good faith with the Controller to conduct any transfer impact assessment required by Applicable Data Protection Law before initiating a restricted transfer.

7.5 EU and UK Representative. As of the effective date of this DPA (June 18, 2026), the Processor has not appointed a representative in the European Union under GDPR Article 27 or a representative in the United Kingdom under the UK GDPR, on the basis that the Processor does not currently target or regularly monitor the behaviour of data subjects in the EEA or UK. The Processor keeps this position under review and will appoint such a representative, and update this DPA accordingly, if it begins actively targeting or regularly serving EEA or UK users in a manner that triggers an Article 27 (or UK GDPR equivalent) obligation.

8. Security Incident (Breach) Notification

8.1 Notification Obligation. In the event the Processor becomes aware of a Security Incident affecting Personal Data processed under this DPA, the Processor shall notify the Controller without undue delay and, in any event, within 72 hours of becoming aware of the Security Incident, to the extent practicable.

8.2 Content of Notification. The notification shall include, to the extent then known: (a) a description of the nature of the Security Incident; (b) the categories and approximate number of Data Subjects affected; (c) the categories and approximate volume of Personal Data records affected; (d) the likely consequences of the Security Incident; and (e) the measures taken or proposed to address the Security Incident, including measures to mitigate its possible adverse effects.

8.3 Controller Responsibility. The Controller is solely responsible for determining whether and when to notify supervisory authorities and affected Data Subjects, as required by Applicable Data Protection Law. The Processor's notification to the Controller does not constitute an admission of fault or liability.

8.4 Cooperation. The Processor shall reasonably cooperate with the Controller and provide further information about the Security Incident as it becomes available, to assist the Controller in meeting its own notification obligations.

9. Confidentiality of Processing

The Processor shall ensure that all personnel authorised to process Personal Data under this DPA are subject to appropriate confidentiality obligations (whether under contract or statutory duty) and are informed of the confidential nature of the Personal Data they process.

10. Data Protection Impact Assessments and Prior Consultation

Taking into account the nature of the processing and the information available to the Processor, the Processor shall provide reasonable assistance to the Controller in relation to any data protection impact assessments (DPIAs) and any prior consultation with supervisory authorities that the Controller is required to conduct under Applicable Data Protection Law.

11. Audit Rights

Upon the Controller's reasonable written request (no more than once per calendar year absent a Security Incident), the Processor shall make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA and shall permit and cooperate with audits or inspections by the Controller or its designated auditor. The Controller shall give the Processor at least thirty (30) days prior written notice of any audit, conduct audits during normal business hours, and bear all costs of such audits. Any audit is subject to the Processor's reasonable confidentiality requirements and may not unreasonably disrupt the Processor's business operations. The Processor may satisfy an audit request under this Section by providing then-current third-party audit reports, certifications, or security documentation (for example, SOC 2 Type II or an equivalent independent assessment), together with written responses to the Controller's reasonable security questionnaires. Where such documentation is reasonably insufficient to demonstrate compliance with this DPA, or following a confirmed Security Incident attributable to the Processor, the Controller (or its designated independent auditor bound by confidentiality) may request an on-site inspection. The once-per-calendar-year frequency limit and the cost allocation in this Section do not apply where an audit or inspection is required by a competent supervisory authority or is conducted following a confirmed Security Incident attributable to the Processor, in which case the Processor shall bear its own costs of cooperation. Nothing in this Section limits or derogates from any audit or inspection right the Controller has under the Standard Contractual Clauses or Applicable Data Protection Law, which prevail to the extent of any conflict.

12. Data Deletion on Termination

12.1 Deletion Obligation. Upon termination or expiry of the Principal Agreement (or upon the Controller's written request), the Processor shall, at the Controller's election, delete or return all Personal Data processed under this DPA, together with all existing copies, unless Applicable Data Protection Law requires continued storage.

12.2 Retention Period. Following termination of the subscription, the Processor will retain Client account data and uploaded content for a period of at least thirty (30) days to allow the Controller to request a data export. Thereafter, the Processor will delete such Personal Data from active production systems upon the Controller's instruction under Section 12.1 or as part of the Processor's routine data-lifecycle management; copies held in encrypted backups are purged on the Processor's then-current backup retention cycle (currently thirty (30) days). Billing and tax metadata may be retained for longer periods as required by applicable tax and financial regulation.

12.3 Certification. Upon request, the Processor shall provide written certification to the Controller confirming deletion of Personal Data following termination.

13. Governing Law and Jurisdiction

This DPA is governed by the laws of the State of California, United States, without regard to conflict-of-law principles, except that the Standard Contractual Clauses (where incorporated) are governed by the laws of the EU Member State specified therein. Disputes arising under this DPA shall be subject to the exclusive jurisdiction of the courts of San Bernardino County, California, subject to any mandatory jurisdiction provisions in the SCCs.

14. Order of Precedence

In the event of any conflict or inconsistency between this DPA and the Principal Agreement, the terms of this DPA shall prevail with respect to the subject matter of data protection. In the event of any conflict between this DPA and the Standard Contractual Clauses, the Standard Contractual Clauses shall prevail.

15. CCPA/CPRA Service Provider Terms

To the extent the Processor processes Personal Data that constitutes "personal information" of California "consumers" under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, the "CCPA/CPRA"), the Processor acts as the Controller's "Service Provider" (as defined in Cal. Civ. Code §1798.140). With respect to such personal information, the Processor shall: (a) not Sell or Share it (as "sell" and "share" are defined under the CCPA/CPRA); (b) not retain, use, or disclose it for any purpose other than the specific business purpose of providing the Services under the Master Subscription Agreement, Master Service Agreement, or Terms of Service governing the Controller's use of the Services (collectively, the "Agreement"), or as otherwise permitted by the CCPA/CPRA, including not retaining, using, or disclosing it for any commercial purpose other than providing the Services; (c) not retain, use, or disclose it outside the direct business relationship between the parties; (d) not combine it with personal information that the Processor receives from, or on behalf of, any other person, or that the Processor collects from its own interaction with the consumer, except as expressly permitted under Cal. Civ. Code §1798.140(ag)(1) and its implementing regulations; and (e) comply with all obligations applicable to a Service Provider under the CCPA/CPRA and provide at least the same level of privacy protection as is required of the Controller (as a "business") thereunder. The Processor hereby certifies that it understands the restrictions set out in this Section 15 and will comply with them. The Processor shall notify the Controller promptly (and in any event without undue delay) if it determines that it can no longer meet these obligations. The Controller may, upon notice, take reasonable and appropriate steps to stop and remediate any unauthorized use of personal information. This Section 15 applies notwithstanding anything to the contrary in this DPA or the Agreement; in the event of any conflict between this Section 15 and any other provision regarding the processing of personal information of California consumers, this Section 15 controls.

Exhibit A — Processing Details

Subject matter of processing: Provision of the Lighting Studio SaaS platform, including authentication, fixture library management, usage analytics, and subscription billing.

Duration of processing: For the term of the Principal Agreement, plus any post-termination retention period specified in Section 12.

Nature and purpose of processing: Storage, retrieval, and display of Client account data; delivery of transactional emails; processing of subscription payments; aggregation of usage analytics; error monitoring; and backup/recovery operations.

Types of Personal Data: See Section 3 of this DPA.

Categories of Data Subjects: The Client's designated administrator users and (if analytics is enabled by the Controller) end users of the Client's public-facing lighting tools.

Special category data: None intended. Controller must not upload special category data without prior written agreement.

Signatures

By signing below, each party agrees to be bound by the terms of this Data Processing Agreement.

Saha Sales Inc. dba Saha Lighting Solutions (Processor / Data Importer)

Signature

Printed Name

Title

Date

Client (Controller / Data Exporter)

Signature

Printed Name

Title

Date

Version: June 18, 2026. This DPA takes effect automatically on the Controller's acceptance of the Agreement and is incorporated by reference; the Controller details and the signature block above are completed only where a Client requires a counter-signed copy. Saha Sales Inc. dba Saha Lighting Solutions recommends having a licensed attorney review this agreement before execution. For questions or to request a counter-signed copy, contact support@sahalighting.com.