This Data Processing Agreement is drafted to satisfy Article 28(3) of the UK GDPR and the Data Protection Act 2018 (as amended by the Data (Use and Access) Act 2025). It is incorporated into the Operator Agreement by reference and takes precedence over it on data-protection matters.
Parties
Controller: the Operator, at its registered address. Processor: StoreBay, at its registered address (legal-entity details to be confirmed before execution).
2. Roles and scope
The Operator is the controller and StoreBay is the processor of Operator Personal Data — principally the personal data of the Operator’s occupiers/licensees and prospects. The subject-matter, duration, nature and purpose of processing are set out in Annex I.
3. Processing only on documented instructions
StoreBay processes Operator Personal Data only on the Operator’s documented instructions, unless required otherwise by law. The Article 6/9 lawful basis for Operator Personal Data is the Operator’s responsibility, not StoreBay’s.
4. Confidentiality of personnel
StoreBay ensures that persons authorised to process Operator Personal Data are bound by an appropriate confidentiality obligation and process on a strict need-to-know basis.
5. Security of processing
StoreBay implements appropriate technical and organisational measures, including fail-closed row-level-security tenant isolation, encryption in transit and at rest, tokenised card handling with no card number or CVV stored on StoreBay systems, and an append-only audit log.
6. Sub-processors
The Operator gives general written authorisation for StoreBay to engage sub-processors. StoreBay maintains a current register (Annex III) and gives at least 30 days’ advance notice before adding or replacing a sub-processor, during which the Operator may object on reasonable data-protection grounds.
7–8. Assistance with data-subject rights and Articles 32–36
StoreBay assists the Operator, by appropriate technical and organisational measures, to fulfil its obligations to respond to data-subject requests, and with security, breach notification, data protection impact assessments and prior consultation with the ICO.
9. Personal data breach — notification SLA
On becoming aware of a personal data breach affecting Operator Personal Data, StoreBay notifies the Operator without undue delay and in any event within 48 hours. The Operator, as controller, owns the Article 33 72-hour clock for notifying the ICO.
10. Deletion or return of data on termination
On termination, StoreBay, at the Operator’s choice, deletes or returns all Operator Personal Data, subject to residual copies in immutable backups being deleted on the normal backup-rotation cycle and to any active legal hold.
11. Audits and inspections
StoreBay makes available all information necessary to demonstrate Article 28 compliance and allows for audits, which may be satisfied by security documentation and a reasonable security questionnaire, with on-site inspection on reasonable prior notice.
12. International transfers
StoreBay does not transfer Operator Personal Data outside the UK except to sub-processors under an appropriate Article 46 safeguard, as recorded in our data-residency documentation and the sub-processor register.
Annex I — details of processing
| Field | Detail |
|---|---|
| Subject-matter | Provision of the StoreBay self-storage management platform to the Operator. |
| Duration | The term of the Operator Agreement, plus any retention/hold period. |
| Nature | Collection, storage, structuring, use, transmission and erasure by automated means to run the Operator's storage business. |
| Purpose | Agreement management, billing & payments, collections, communications, access-control credentialing, optional identity verification, accounting sync, e-signature, and analytics. |
| Categories of data subjects | The Operator's occupiers/licensees, prospects, and the Operator's own authorised staff users. |
Annex III — approved sub-processors
| Sub-processor | Purpose | Region |
|---|---|---|
| DigitalOcean | Hosting, infrastructure & object storage | LON1 (UK) |
| Stripe | Card payments & Connect payouts | US / IE / UK |
| GoCardless | Bacs Direct Debit collection | UK |
| Resend | Transactional email delivery | US |
| Bird (MessageBird) | SMS delivery | EEA |
| Xero / QuickBooks | Accounting sync | NZ / US |
| Stripe Identity | Optional identity verification | US |
Access-control hardware vendors (Nokē, BearBox, PTI Security Systems, OpenTech Alliance, Paxton) are engaged per operator/per site depending on the hardware installed. The full, current register — including each sub-processor's exact legal entity and transfer mechanism — is maintained separately and available on request.