← All documents

Open Storage Platform (OSP) Data Processing Addendum (DPA)

Version: 0.7.1 Beta Draft Effective: [EFFECTIVE DATE] Between: btec LLC ("Processor") and OSP Customer ("Controller") Contact: b@btec.me


Plain-Language Summary

What this means for you:

  • This is the formal document that governs how b-tec handles your data when we provide the hosted OSP service.
  • You are the controller. You decide what data goes into OSP and why. We follow your instructions.
  • We are the processor. In the hosted model, We run the infrastructure and keep it working. We don't use your data for anything else.
  • We use subprocessors (Vercel, Neon, Stripe, Resend, Inngest). You agree to their use by using the service.
  • Stripe is your account, not ours. That changes the processing relationship — b-tec doesn't handle your payment data directly.
  • We'll tell you if we add new subprocessors. You can object if you have a legitimate reason. You always have options.
  • This is beta. We haven't done full GDPR Article 28 compliance yet. Plan accordingly.

1. Scope & Role Definitions

This Data Processing Addendum ("DPA") supplements the Hosted Service Terms and Privacy Policy. It applies when b-tec processes Customer Data on your behalf as part of the OSP hosted service. Roles under data protection law:

PartyRoleMeaning
Customer (You)Data ControllerYou determine the purposes and means of processing Customer Data
b-tec LLCData ProcessorWe process Customer Data on your behalf and per your instructions

For Account Data (your email, name, billing contact), b-tec acts as an independent Controller. That data is governed by the Privacy Policy, not this DPA.

2. Customer Data Description

2.1 Categories of Data

The Customer Data processed through OSP may include:

CategoryExamplesSensitivity
Tenant PIINames, addresses, phone numbers, email addresses, identification documentsHigh
Lease & Rental RecordsAgreement terms, unit assignments, move-in/move-out dates, rental ratesMedium
Financial DataPayment records, transaction histories, outstanding balances, ledgersHigh
Facility Operational DataUnit configurations, maintenance records, access logs, inspection reportsLow-Medium
Audit LogsUser action records, timestamps, IP addresses, change historyMedium

2.2 Data Subjects

Data subjects whose information may be processed include:

  • Tenants and lessees of the Customer's facilities
  • Customer's employees and contractors
  • Facility visitors and vendors (if recorded in the system)
  • Prospective tenants (if tracked)

2.3 Processing Frequency

Data is processed on a continuous basis as you and your Authorized Users interact with OSP.

3. Nature & Purpose of Processing

b-tec processes Customer Data solely to provide the OSP hosted service:

  • Storing and retrieving Customer Data in the PostgreSQL database
  • Serving the OSP web application and API to Authorized Users
  • Executing background jobs (notifications, scheduled tasks, data processing)
  • Sending transactional emails (via Resend)
  • Maintaining audit logs as part of normal platform operation
  • Providing technical support (with Customer consent to access data)

b-tec does not process Customer Data for:

  • Advertising or marketing
  • Training digital learning models
  • Sale to third parties
  • Any purpose not directed by the Customer through normal use of OSP

4. Duration of Processing

PhaseProcessing
Active serviceContinuous, as directed by Customer
TerminationData exported to Customer within 10 business days, then deleted from b-tec systems within 90 days
Legal holdsb-tec may retain data longer if required by law, with notice to Customer unless prohibited

5. Subprocessors

5.1 Current Subprocessors

By using the OSP hosted service, you authorize b-tec to engage the following subprocessors:

SubprocessorService ProvidedData ProcessedLocationSecurity
Vercel Inc.Application hosting, edge functionsApplication data in transit, server logsUSASOC 2 Type II, ISO 27001
Neon, Inc.PostgreSQL database hostingAll Customer Data at restUSASOC 2, encryption at rest & in transit
Stripe, Inc.Payment processingPayment transaction dataUSAPCI DSS Level 1
Resend, Inc.Transactional email deliveryEmail content, recipient addressesUSASOC 2
Inngest Inc.Background job processingJob payloads (may contain business data)USASOC 2

Important note on Stripe: The OSP connected Stripe account used for payment processing is owned and controlled by the Customer, not by b-tec. b-tec does not have direct access to the Customer's Stripe dashboard, funds, or full transaction data. b-tec's processing relationship with Stripe is limited to what Stripe's Connect platform exposes for hosted management.

5.2 Subprocessor Changes

b-tec will notify Customers of new subprocessors at least 10 days before they begin processing Customer Data. Customers may object to a new subprocessor based on reasonable data protection concerns. If b-tec cannot accommodate the objection, the Customer may terminate without penalty within 30 days of the objection.

5.3 Subprocessor Obligations

b-tec enters into written agreements with subprocessors that impose data protection obligations at least as protective as this DPA.

6. Technical & Organizational Measures

The technical and organizational measures b-tec implements are detailed in the Security Overview. Key measures restated:

  • Row-Level Security at the database level
  • Bcrypt password hashing
  • HTTPS/TLS for all data in transit
  • Append-only audit logging
  • Database role separation (owner/app/auth)
  • Idempotency keys on financial operations
  • Access controls and session management

7. Data Subject Requests

The Customer is responsible for responding to data subject access requests (DSARs) from individuals whose data resides in OSP. If b-tec receives a DSAR directly, we will:

  • Forward it to the Customer promptly
  • Not respond independently unless legally required
  • Provide reasonable assistance to the Customer in fulfilling the request

8. Breach Notification

b-tec will notify the Customer without undue delay, and no later than 72 hours, after becoming aware of a personal data breach affecting Customer Data. The notification will include:

  • The nature of the breach
  • Categories and approximate number of records affected
  • Measures taken or proposed
  • Point of contact for further information

9. Audit Rights

9.1 Documentation

This DPA and the Security Overview serve as documentation of b-tec's processing activities and security measures.

9.2 Customer Audits

The Customer may, no more than once per year and with 30 days notice:

  • Request written confirmation of b-tec's compliance with this DPA
  • Request a summary of any third-party security assessments b-tec has completed

The Customer bears the cost of any audit, and audits must be conducted during normal business hours without disrupting operations.

10. International Data Transfers

b-tec is US-based and all subprocessors process in the US.

11. Limitation of Liability

Liability under this DPA is subject to the limitations in the Hosted Service Terms.

12. Beta Acknowledgment

This DPA is provided for the OSP beta service. Formal GDPR Article 28 compliance documentation, Data Protection Impact Assessments, and Transfer Impact Assessments have not been completed. The Customer acknowledges this when using the beta service.

13. Contact

Data protection inquiries: b@btec.me btec LLC Bourbonnais, Illinois

Questions? b@btec.me