Legal & Trust
Legal

Data Processing Addendum

Review StorageFlo.io data processing terms, including controller and processor roles, security measures, SCCs, UK IDTA terms, and subprocessors.

EffectiveApril 25, 2026·v1.0·Last updatedApril 25, 2026
EUUKUSCAAU

1. Definitions

The following defined terms apply throughout this Data Processing Addendum ("DPA"). Where a term is defined in the General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR"), the definition in Article 4 of the GDPR applies and is reproduced or paraphrased below for ease of reference.

  • "Personal Data" means any information relating to an identified or identifiable natural person ("Data Subject"), identifiable directly or indirectly by reference to an identifier such as a name, identification number, location data, or online identifier, or to factors specific to that person's physical, physiological, genetic, mental, economic, cultural, or social identity. (GDPR Art. 4(1).)
  • "Process" / "Processing" means any operation or set of operations performed on Personal Data, whether or not by automated means, including collection, storage, use, disclosure, combination, restriction, erasure, or destruction. (GDPR Art. 4(2).)
  • "Controller" means the person or body that determines the purposes and means of Processing Personal Data. (GDPR Art. 4(7).)
  • "Processor" means a person or body that Processes Personal Data on behalf of the Controller. (GDPR Art. 4(8).)
  • "Sub-processor" means any third-party Processor engaged by StorageFlo to Process Customer Data in connection with the Service.
  • "Data Subject" has the meaning given in the definition of Personal Data above.
  • "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data. (GDPR Art. 4(12).)
  • "Customer Data" means all Personal Data submitted to the Platform by or on behalf of the Customer, including tenant names, contact details, lease records, and payment metadata.
  • "Standard Contractual Clauses (SCCs)" means the standard contractual clauses adopted by the European Commission under Implementing Decision (EU) 2021/914, as updated from time to time.
  • "UK IDTA" means the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner's Office under s.119A of the Data Protection Act 2018, as updated from time to time.
  • "Member State" means a member state of the European Union or, where applicable, the European Economic Area.
  • "Service" and "Terms" have the meanings given in the Terms of Service.
  • "Supervisory Authority" means the independent public authority established pursuant to GDPR Article 51, or the equivalent regulatory body in any applicable jurisdiction.

2. Roles of the parties

Customer as Controller. In the most common configuration, the Customer is a self-storage operator who acts as the Controller of Personal Data relating to its tenants. StorageFlo Processes that data on the Customer's behalf and at the Customer's direction, and is therefore the Processor under GDPR Articles 4(8) and 28.

Customer as Processor. Where the Customer is itself a Processor acting for an upstream controller (for example, a management company processing data on behalf of facility owners), the Customer warrants it has authority to engage StorageFlo as a Sub-processor. SCCs Module 3 applies accordingly (see Section 16). The Customer remains solely responsible for ensuring its own processing agreement permits this sub-processing arrangement.

Storage-operator chain. Self-storage operators routinely collect tenant Personal Data (identity, payment, and access records) as part of their business. That data flows through the Platform as an operational necessity, and this DPA governs StorageFlo's role in that chain.

This DPA supplements and is incorporated into the Terms. Where it conflicts with the Terms regarding Processing of Personal Data, this DPA governs.

3. Subject matter and duration of processing

Subject matter. StorageFlo Processes Customer Data as necessary to provide the Service, including operating the booking widget, synchronizing data with Integrated Systems, facilitating payment transactions, and providing administrative dashboards.

Duration. StorageFlo will Process Customer Data for the duration of the Customer's active Subscription and for any post-termination period required by Sections 14 and 15 of this DPA.

Instruction-based Processing. All Processing under this DPA is carried out on the documented instructions of the Customer, unless applicable law requires otherwise. Where law requires Processing outside those instructions, StorageFlo will notify the Customer before doing so, unless prohibited. If StorageFlo reasonably concludes that an instruction infringes applicable data protection law, it will promptly inform the Customer.

4. Nature and purpose of processing

StorageFlo Processes Customer Data for the following purposes:

  • Providing the self-storage booking and management platform, including unit availability lookup, online reservations, lease generation, and move-in processing.
  • Synchronizing Customer Data with Integrated Systems (such as storage management software) at the Customer's direction.
  • Facilitating payment collection and transmitting payment metadata to the Customer's connected payment processor (Stripe, Inc. or Square, Inc.).
  • Sending transactional communications (booking confirmations, payment receipts, access notifications) on the Customer's behalf.
  • Providing reporting, analytics, and administrative dashboards to the Customer's authorized users.
  • Maintaining audit logs and security event records as described in Section 9.
  • Responding to verified Data Subject requests at the Customer's direction, as described in Section 11.

StorageFlo does not use Customer Data for its own marketing purposes, does not sell Customer Data, and does not disclose Customer Data to third parties except as permitted by this DPA and the Terms.

5. Categories of data subjects

Customer Data Processed under this DPA may relate to the following categories of Data Subjects:

  • Tenants. Natural persons who rent or seek to rent storage units from the Customer, including prospective tenants who submit a booking inquiry or reservation.
  • Authorized Users. Employees, contractors, and agents of the Customer who are granted access to the Platform by the Customer.
  • Guarantors and emergency contacts. Natural persons whose contact or identity details are provided by a tenant or the Customer in connection with a lease.
  • Visitors and online users. Natural persons who interact with the Customer's booking widget deployed on the Customer's website.

6. Categories of personal data

The following categories of Personal Data may be Processed under this DPA, depending on the data the Customer submits and the features the Customer enables:

  • Identity data. Full name, date of birth, government-issued identification number, and physical description where provided.
  • Contact data. Email address, postal address, and telephone number.
  • Lease and account data. Unit number, lease start and end dates, access codes, and lease status.
  • Payment metadata. Transaction identifiers, payment amounts, timestamps, and payment method type (card, ACH, etc.). Full payment card numbers are not Processed by StorageFlo and are transmitted directly to the payment processor.
  • Communications. Messages exchanged between tenants and the Customer's staff routed through the Platform.
  • Access and security data. Gate access logs, lock activity records, and surveillance metadata to the extent integrated with the Platform.
  • Technical data. IP addresses, browser identifiers, and session tokens associated with interactions on the Customer's booking widget.

The Customer must not submit special categories of Personal Data (as defined in GDPR Article 9, including health, biometric, or racial data) to the Platform without first executing a written addendum with StorageFlo that addresses the additional safeguards required.

7. Customer's instructions

The Customer's primary instructions are set out in this DPA and in the Terms. Additional documented instructions may be issued through the Platform's configuration settings, administrative controls, support channels, or written communications.

The Customer is responsible for ensuring its instructions comply with applicable data protection law and for identifying a valid lawful basis for each category of Personal Data submitted to the Platform.

StorageFlo may Process Customer Data outside the Customer's instructions only where required by applicable law, or to prevent or investigate suspected fraud or security incidents. In either case, StorageFlo will notify the Customer as soon as practicable, unless prohibited by law.

8. Confidentiality of personnel

StorageFlo ensures that all personnel authorized to Process Customer Data are bound by legally binding confidentiality obligations that survive their engagement. Access to Customer Data is limited to personnel who need it for their duties, is reviewed at least annually, and is revoked promptly on departure or role change. Personnel who Process Customer Data receive data protection training on onboarding and at least annually thereafter.

9. Security measures

StorageFlo implements and maintains the technical and organizational measures ("TOMs") described in this Section to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access. Current security posture details are published at /security.

9.1. Encryption

All Customer Data is encrypted at rest using encryption managed by Google Cloud Platform and Firebase, employing AES-256 or equivalent standards. All data transmitted between the Customer's systems or browsers and StorageFlo's infrastructure is encrypted in transit using TLS 1.2 or higher. Connections that do not meet the minimum protocol version are rejected.

9.2. Access control

StorageFlo applies a least-privilege model to all internal access to production systems containing Customer Data. Access is granted on a role-based basis ("RBAC") and requires formal justification and managerial approval. Multi-factor authentication ("MFA") is mandatory for all StorageFlo staff who access production infrastructure or administrative tooling. Privileged access is reviewed quarterly. Staff departures trigger immediate revocation of all access credentials.

9.3. Logging and audit

Security event logs covering authentication, administrative actions, data access, and configuration changes are retained for a minimum of 90 days, protected against tampering, and reviewed as part of regular security monitoring and incident response.

9.4. Segregation of customer data

Customer Data is logically isolated at the tenant level. The Platform's multi-tenancy architecture prevents any Customer from accessing, querying, or modifying another Customer's data, enforced at both the application layer and the database query layer.

9.5. Vulnerability management

StorageFlo conducts regular vulnerability scans of its infrastructure and application stack. Vulnerabilities are triaged by severity and remediated within industry-standard timeframes, with critical and high-severity issues prioritized. Dependency patches are applied on a scheduled basis and out-of-band where severity warrants. Penetration testing is conducted at least annually.

9.6. Personnel

Personnel with access to production systems are subject to the confidentiality obligations in Section 8, complete data protection training on onboarding and at least annually, and undergo background screening consistent with applicable law.

9.7. Resilience

StorageFlo leverages Google Cloud Platform regional infrastructure for high availability and data durability. Customer Data is backed up on a regular schedule with periodic integrity testing. A disaster recovery plan is maintained and tested at least annually. Recovery objectives are published at /security.

10. Subprocessors

General authorization. The Customer grants StorageFlo general written authorization under GDPR Article 28(2) to engage Sub-processors to help deliver the Service. The current Sub-processor list is maintained at /legal/subprocessors and includes Google Cloud Platform and Firebase (hosting, database, storage, authentication), Stripe, Inc. and Square, Inc. (payment processing), Sentry (error monitoring), and transactional email and SMS providers.

Notification of changes. StorageFlo will give the Customer at least 30 days advance written notice of any intended addition or replacement of a Sub-processor, by updating /legal/subprocessors and, where opted in, by direct email.

Customer objection rights. The Customer may object to a new or replacement Sub-processor on documented data-protection grounds by writing to [email protected] within 30 days of the notification. The parties will work in good faith to resolve the objection. If unresolved after 30 days, the Customer may terminate the affected portion of the Service without penalty, subject to a pro-rata refund of prepaid fees for that portion.

StorageFlo's responsibility. StorageFlo remains liable for each Sub-processor's acts and omissions with respect to Customer Data to the same extent as if performed directly by StorageFlo, and will enter into binding data processing agreements with each Sub-processor on terms at least as protective as this DPA.

11. Data subject rights

The Customer, as Controller, is responsible for responding to Data Subject requests under applicable data protection law (GDPR Articles 15 to 22 and equivalents). StorageFlo will, to the extent technically feasible:

  • Promptly forward to the Customer any Data Subject request received that relates to Customer Data.
  • Refrain from responding on the Customer's behalf without written authorization, except to acknowledge receipt.
  • Provide reasonable assistance, including access to the Platform's export, correction, restriction, and deletion tools, to help the Customer meet applicable statutory deadlines.

The Customer is responsible for maintaining records of lawful bases for Processing and any required consents or legitimate-interest assessments.

12. Personal data breach notification

Notification content. The initial notification will, to the extent information is available at the time, include:

  • A description of the nature of the Personal Data Breach, including the categories and approximate number of Data Subjects affected and the categories and approximate number of Personal Data records concerned.
  • The likely consequences of the Personal Data Breach.
  • A description of the measures taken or proposed by StorageFlo to address the Personal Data Breach, including measures to mitigate its possible adverse effects.

Where the above information is not fully available within the initial 72-hour notification, StorageFlo will provide it in phases as it becomes available, without undue further delay.

Customer's obligations. The Customer is responsible for determining whether the breach must be notified to a Supervisory Authority or to affected Data Subjects under GDPR Articles 33 and 34 or equivalent law. StorageFlo will provide reasonable assistance with those obligations.

Notification channels. Breach notifications will be sent to the Customer's account email address and, where a security contact is designated, to that address. For operational matters the Customer may also contact [email protected] and for legal matters [email protected].

Exclusions. A notification under this Section is not an admission of fault or liability.

13. Data protection impact assessments

Where Processing is likely to result in a high risk to Data Subjects, the Customer, as Controller, may be required to conduct a Data Protection Impact Assessment ("DPIA") under GDPR Article 35 or equivalent law. StorageFlo will provide reasonable assistance, which may include describing the Processing and TOMs in Section 9, making the Sub-processor list at /legal/subprocessors available, and responding to reasonable written questionnaires. DPIA assistance is subject to the confidentiality obligations in the Terms. StorageFlo does not provide legal advice; the Customer should engage its own counsel to assess its DPIA obligations.

14. Return or deletion of personal data

Data export window. On expiry or termination of the Customer's Subscription, the Customer will have a period of 30 days (the "Export Window") during which the Customer may export Customer Data from the Platform using the standard export mechanisms available within the Service. StorageFlo will maintain the Customer Data in a retrievable state throughout the Export Window.

Deletion. Within 30 days after the end of the Export Window, StorageFlo will securely delete or irreversibly anonymize all Customer Data from its production systems and backups, except to the extent that:

  • StorageFlo is required to retain the data by applicable law (including tax, accounting, or regulatory requirements), in which case StorageFlo will retain only the minimum data required for the minimum period required and will isolate that data from further active Processing; or
  • The data is contained in encrypted backups that are subject to standard automated deletion cycles, in which case the data will be deleted no later than 90 days after the end of the Export Window.

Certification. On the Customer's reasonable written request submitted before or during the Export Window, StorageFlo will provide the Customer with written certification of the deletion of Customer Data within a reasonable time after deletion is complete.

Sub-processor data. StorageFlo will take commercially reasonable steps to ensure Sub-processors delete or return Customer Data on the same terms.

15. Audits and inspections

Customer's audit right. The Customer may, no more than once per calendar year and on at least 30 days advance written notice to [email protected], audit or inspect StorageFlo's compliance with this DPA. Audits must be conducted:

  • During StorageFlo's normal business hours.
  • In a manner that does not unreasonably disrupt StorageFlo's operations or the services provided to other customers.
  • Under the terms of a non-disclosure agreement acceptable to both parties.

Certification reports. The audit right may be satisfied, at StorageFlo's election, by making available the most recent SOC 2 Type II report, ISO 27001 certification, or equivalent independent assessment. The Customer may review those reports and submit written questions, which StorageFlo will address within a reasonable time.

Third-party auditors. The Customer may bring an independent, qualified third-party auditor at its own cost. The auditor must agree in advance to StorageFlo's reasonable confidentiality and security requirements. StorageFlo may refuse access to an auditor it reasonably determines poses a competitive conflict of interest.

Additional audits. Additional audits beyond the annual entitlement may be agreed in writing, with costs borne by the Customer unless the additional audit was triggered by a confirmed Personal Data Breach attributable to StorageFlo.

16. International data transfers

Customer Data may be transferred to, stored in, and Processed in countries outside the Customer's country of establishment, including the United States. The following mechanisms govern such transfers.

16.1. European Economic Area (EU SCCs)

Where Customer Data is transferred from the EEA to a country not recognized by the European Commission as providing an adequate level of protection, the parties agree that the EU SCCs apply as follows:

  • Module 2 (Controller-to-Processor). Where the Customer acts as Controller and StorageFlo acts as Processor, the SCCs Module 2 are incorporated by reference into this DPA and shall apply to the transfer.
  • Module 3 (Processor-to-Processor). Where the Customer acts as Processor and StorageFlo acts as Sub-processor, the SCCs Module 3 are incorporated by reference into this DPA and shall apply to the transfer.

For both modules:

  • Annex I (Parties and description of transfer). The parties and description of the transfer are as set out in this DPA: the Customer is the data exporter; South Star Holdings LLC, [REGISTERED ADDRESS PENDING INCORPORATION], is the data importer. The subject matter, duration, nature, purpose, categories of Data Subjects, and categories of Personal Data are as described in Sections 3 to 6 of this DPA.
  • Annex II (Technical and organisational security measures). The TOMs described in Section 9 of this DPA serve as Annex II to the SCCs.
  • Annex III (List of Sub-processors). The Sub-processor list maintained at /legal/subprocessors serves as Annex III to the SCCs.

Where an adequacy decision issued by the European Commission applies to a transfer, the parties may rely on that decision in lieu of the SCCs for its duration.

16.2. United Kingdom (UK IDTA)

For transfers of Customer Data from the United Kingdom to countries not recognized by the UK as providing adequate protection, the UK IDTA is incorporated by reference into this DPA and applies as an addendum to the EU SCCs described above.

Tables 1 to 4 of the UK IDTA are populated by reference to the information in Annexes I, II, and III described in the EU SCCs section above. The "Exporter" is the Customer; the "Importer" is South Star Holdings LLC. The approved EU SCCs to which the UK IDTA is appended are the EU SCCs referenced in Section 16 (European Economic Area).

Where the ICO issues a revised UK IDTA, this DPA will incorporate it from its effective date unless the Customer objects in writing within 30 days. The UK representative under UK GDPR Article 27 is [UK REPRESENTATIVE PENDING APPOINTMENT].

16.3. Switzerland

For transfers of Customer Data from Switzerland, the SCCs described above are adapted as follows to satisfy the requirements of the Swiss Federal Act on Data Protection (FADP):

  • References to "Member State" in the SCCs are read to include Switzerland, and Data Subjects located in Switzerland may exercise their rights under the SCCs in Switzerland.
  • The supervisory authority competent for Switzerland is the Federal Data Protection and Information Commissioner (FDPIC), and references to "the competent supervisory authority" in the SCCs include the FDPIC.
  • References to the GDPR are read to include the FADP and its implementing ordinances to the extent they apply.
  • The governing law for Swiss-origin transfers is the law of Switzerland, and the competent courts are the courts of Switzerland, unless the parties agree otherwise.

17. Liability

Cap. The aggregate liability of each party to the other under or in connection with this DPA, whether in contract, tort (including negligence), or otherwise, will not exceed an amount equal to the total Fees paid or payable by the Customer to StorageFlo in the twelve (12) months immediately preceding the event giving rise to the claim. This cap mirrors the limitation set out in the Terms of Service and applies on an aggregate basis across both the Terms and this DPA.

Exclusions. Neither party will be liable to the other for indirect, consequential, special, incidental, exemplary, or punitive damages arising out of or related to this DPA, including loss of profit, loss of revenue, loss of goodwill, or loss of data, even if the party has been advised of the possibility of such damages.

Statutory rights of Data Subjects. Nothing in this Section limits the statutory rights of Data Subjects under GDPR Article 82 or any equivalent provision of applicable data protection law. To the extent that any Data Subject has a direct right of action against StorageFlo as Processor under applicable law, StorageFlo does not limit or exclude that right.

Mandatory liability. Nothing in this DPA limits or excludes liability that cannot be limited or excluded by applicable law, including liability for death or personal injury caused by negligence, or liability arising from fraud or fraudulent misrepresentation.

Contribution. Where both parties contributed to a Data Subject's loss, liability is allocated proportionately to each party's responsibility.

18. Jurisdiction-specific addenda

18.1. United Kingdom Addendum

This Addendum applies where Customer Data is subject to the UK GDPR (as retained in UK law by the European Union (Withdrawal) Act 2018) and the Data Protection Act 2018. References to "GDPR" in this DPA are read as "UK GDPR" where the UK GDPR applies, and the Information Commissioner's Office (ICO) is the relevant Supervisory Authority. The transfer mechanism for UK-origin transfers is the UK IDTA described in Section 16. The UK representative of South Star Holdings LLC is [UK REPRESENTATIVE PENDING APPOINTMENT].

18.2. Swiss Addendum

This Addendum applies where Customer Data is subject to the revised Swiss Federal Act on Data Protection (FADP, SR 235.1, effective 1 September 2023). References to "GDPR" include the FADP to the extent applicable; references to "Member State" include Switzerland; and the Federal Data Protection and Information Commissioner (FDPIC) is the relevant supervisory authority. Data Subject rights and DPIA obligations described in this DPA apply equally under the FADP.

18.3. California (CPRA service-provider terms)

This Addendum applies where the Customer is a "Business" and StorageFlo is a "Service Provider" under the CCPA as amended by the CPRA. StorageFlo agrees to:

  • Not sell Personal Information Processed under this DPA.
  • Not share Personal Information for cross-context behavioral advertising.
  • Not retain, use, or disclose Personal Information for any purpose other than the business purposes specified in this DPA and the Terms, or as otherwise permitted by the CCPA/CPRA.
  • Not retain, use, or disclose Personal Information outside of the direct business relationship with the Customer.
  • Not combine Personal Information from the Customer with Personal Information from other sources, except as permitted by the CCPA/CPRA.
  • Allow the Customer to audit compliance with these service-provider obligations consistent with Section 15.
  • Certify compliance on the Customer's reasonable written request.

The Customer, as Business, acknowledges that disclosing Personal Information to StorageFlo for the purpose of receiving the Service is not a "sale" or "sharing" under the CCPA/CPRA.

19. Order of precedence

This DPA is incorporated into and forms part of the Terms. Where it conflicts with the Terms regarding the Processing of Personal Data, this DPA governs; for all other matters, the Terms govern. Where there is a conflict between this DPA and the SCCs or the UK IDTA, the SCCs or UK IDTA prevail for transfers subject to those instruments. The jurisdiction-specific addenda in Section 18 supplement this DPA and prevail over the main body for processing subject to the relevant jurisdiction's law.

20. Effective date and amendments

Effective date. This DPA is effective on the latest of: (a) the date the Customer accepts the Terms or otherwise agrees to this DPA; or (b) the effective date stated in the frontmatter above.

Amendments. StorageFlo may amend this DPA from time to time. For material amendments that reduce protections for the Customer or Data Subjects, StorageFlo will provide at least 30 days advance written notice by email or in-product notification. Continued use of the Service after the effective date constitutes acceptance. The Customer may reject a material amendment by terminating the Subscription before that date in accordance with the Terms. Non-material amendments (typographical corrections, clarifications, or law-required updates that do not reduce protections) may take effect with shorter notice.

The current version of this DPA is always available at storageflo.io/legal/dpa.

For questions about this DPA, international data transfer mechanisms, or data protection matters, contact us:

  • Legal inquiries: [email protected]
  • Privacy and data requests: [email protected]
  • Security disclosures: [email protected]
  • Data Protection Officer: [DPO PENDING APPOINTMENT]
  • EU representative: [EU REPRESENTATIVE PENDING APPOINTMENT]
  • UK representative: [UK REPRESENTATIVE PENDING APPOINTMENT]

Mailing address:

South Star Holdings LLC [REGISTERED ADDRESS PENDING INCORPORATION]

Ready to evaluate?

Review the terms, then start the setup.

Once the operational, privacy, and payment boundaries make sense for your team, you can start shaping the booking path for your facility.

Clear policiesDefined boundariesOperator control