Skip to main content

LEGAL & POLICIES

Data Processing Agreement

The terms, privacy and data-processing documents that govern your use of StoreBay.

Version 1 · Last updated 2026-07-04 · Effective 2026-07-04

[DRAFT — pending legal sign-off]

This Data Processing Agreement is drafted to satisfy Article 28(3) of the UK GDPR and the Data Protection Act 2018 (as amended by the Data (Use and Access) Act 2025). It is incorporated into the Operator Agreement by reference and takes precedence over it on data-protection matters.

Parties

Controller: the Operator, at its registered address. Processor: StoreBay, at its registered address (legal-entity details to be confirmed before execution).

2. Roles and scope

The Operator is the controller and StoreBay is the processor of Operator Personal Data — principally the personal data of the Operator’s occupiers/licensees and prospects. The subject-matter, duration, nature and purpose of processing are set out in Annex I.

3. Processing only on documented instructions

StoreBay processes Operator Personal Data only on the Operator’s documented instructions, unless required otherwise by law. The Article 6/9 lawful basis for Operator Personal Data is the Operator’s responsibility, not StoreBay’s.

4. Confidentiality of personnel

StoreBay ensures that persons authorised to process Operator Personal Data are bound by an appropriate confidentiality obligation and process on a strict need-to-know basis.

5. Security of processing

StoreBay implements appropriate technical and organisational measures, including fail-closed row-level-security tenant isolation, encryption in transit and at rest, tokenised card handling with no card number or CVV stored on StoreBay systems, and an append-only audit log.

6. Sub-processors

The Operator gives general written authorisation for StoreBay to engage sub-processors. StoreBay maintains a current register (Annex III) and gives at least 30 days’ advance notice before adding or replacing a sub-processor, during which the Operator may object on reasonable data-protection grounds.

7–8. Assistance with data-subject rights and Articles 32–36

StoreBay assists the Operator, by appropriate technical and organisational measures, to fulfil its obligations to respond to data-subject requests, and with security, breach notification, data protection impact assessments and prior consultation with the ICO.

9. Personal data breach — notification SLA

On becoming aware of a personal data breach affecting Operator Personal Data, StoreBay notifies the Operator without undue delay and in any event within 48 hours. The Operator, as controller, owns the Article 33 72-hour clock for notifying the ICO.

10. Deletion or return of data on termination

On termination, StoreBay, at the Operator’s choice, deletes or returns all Operator Personal Data, subject to residual copies in immutable backups being deleted on the normal backup-rotation cycle and to any active legal hold.

11. Audits and inspections

StoreBay makes available all information necessary to demonstrate Article 28 compliance and allows for audits, which may be satisfied by security documentation and a reasonable security questionnaire, with on-site inspection on reasonable prior notice.

12. International transfers

StoreBay does not transfer Operator Personal Data outside the UK except to sub-processors under an appropriate Article 46 safeguard, as recorded in our data-residency documentation and the sub-processor register.

Annex I — details of processing

FieldDetail
Subject-matterProvision of the StoreBay self-storage management platform to the Operator.
DurationThe term of the Operator Agreement, plus any retention/hold period.
NatureCollection, storage, structuring, use, transmission and erasure by automated means to run the Operator's storage business.
PurposeAgreement management, billing & payments, collections, communications, access-control credentialing, optional identity verification, accounting sync, e-signature, and analytics.
Categories of data subjectsThe Operator's occupiers/licensees, prospects, and the Operator's own authorised staff users.

Annex III — approved sub-processors

Sub-processorPurposeRegion
DigitalOceanHosting, infrastructure & object storageLON1 (UK)
StripeCard payments & Connect payoutsUS / IE / UK
GoCardlessBacs Direct Debit collectionUK
ResendTransactional email deliveryUS
Bird (MessageBird)SMS deliveryEEA
Xero / QuickBooksAccounting syncNZ / US
Stripe IdentityOptional identity verificationUS

Access-control hardware vendors (Nokē, BearBox, PTI Security Systems, OpenTech Alliance, Paxton) are engaged per operator/per site depending on the hardware installed. The full, current register — including each sub-processor's exact legal entity and transfer mechanism — is maintained separately and available on request.

No obligation · UK-based support · migrations handled for you

Ready to fill more units and run every site from one place?