1. Parties and scope
This Data Processing Addendum (“DPA”) is entered into between [LEGAL ENTITY NAME] (“Processor”, “we”) and the Customer identified in the account (“Controller”, “you”). It applies whenever we process Personal Data on your behalf in connection with the Service, and to the extent that Data Protection Laws apply to that processing.
Where you require a countersigned copy, email legal@westorably.com with your legal entity name and address.
2. Definitions
“Data Protection Laws” means all laws applicable to the processing, including the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK GDPR and Data Protection Act 2018, the Swiss FADP, the California Consumer Privacy Act as amended (“CCPA/CPRA”) and comparable US state laws. “Personal Data”, “processing”, “controller”, “processor”, “data subject” and “personal data breach” have the meanings given in the GDPR. “Customer Personal Data” means Personal Data contained in Customer Data. “SCCs” means the Standard Contractual Clauses adopted by the European Commission in Decision 2021/914. “UK Addendum” means the International Data Transfer Addendum issued by the UK Information Commissioner.
3. Roles of the parties
- You are the controller of Customer Personal Data, including data about your tenants, their leases and their payment history. You determine why and how it is processed.
- We are the processor and will process it only on your documented instructions, which consist of this DPA, the Terms of Service, your configuration of the Service, and any additional written instruction you give that we agree to.
- We are an independent controller for our own account, billing and support records, and for website analytics. That processing is governed by our Privacy Policy, not by this DPA.
- Under the CCPA/CPRA we act as a “service provider”. We do not sell or share Customer Personal Data, do not retain, use or disclose it outside the direct business relationship, and do not combine it with data from other sources except as permitted by law.
If we believe an instruction infringes Data Protection Laws, we will tell you without undue delay and may pause that processing.
4. Our obligations
- Process Customer Personal Data only on your documented instructions, unless required otherwise by law, in which case we will notify you first unless the law prohibits it.
- Ensure that personnel authorised to process Customer Personal Data are bound by confidentiality and are trained appropriately.
- Implement and maintain the technical and organisational measures described in Annex II.
- Assist you, taking into account the nature of the processing and the information available to us, with data subject requests, data protection impact assessments, prior consultations and breach notification.
- Make available the information necessary to demonstrate compliance with Article 28 GDPR.
- Not use Customer Personal Data to train generative artificial intelligence models, and contractually prohibit our sub-processors from doing so.
5. Your obligations
- Ensure you have a lawful basis for the processing you instruct, and that you have given your tenants any notice their law requires.
- Ensure your instructions comply with Data Protection Laws.
- Not upload special category data or data relating to criminal convictions into free-text fields.
- Configure the Service, including retention, access roles and automated actions, in a way that complies with the law where your facility operates.
- Respond to your tenants' rights requests as the controller, using the export, edit and delete tools in the Service.
6. Sub-processors
You grant general authorisation for us to engage sub-processors. The current list is published at westorably.com/subprocessors, which forms Annex III.
We will impose data protection obligations on each sub-processor no less protective than those in this DPA, and remain fully liable for their performance. We will give at least 30 days' notice, by email to your account address and by updating that page, before adding or replacing a sub-processor. You may object on reasonable data protection grounds within that period by emailing legal@westorably.com. We will work in good faith to offer an alternative; if none is reasonably available, you may terminate the affected subscription and receive a pro-rata refund of prepaid unused fees. Subscribe to sub-processor notices at legal@westorably.com.
7. International transfers
We may transfer Customer Personal Data outside the country of origin, including to the United States. Where we do so from the EEA, the UK or Switzerland, the following apply and are incorporated by reference:
- EEA: the SCCs, Module Two (controller to processor), with you as data exporter and us as data importer. Clause 7 (docking) applies; Clause 9 option 2 (general written authorisation, 30 days) applies; Clause 11 optional redress language does not apply; Clause 17 is governed by the law of Ireland; Clause 18(b) selects the courts of Ireland. Annex I, II and III of the SCCs are populated by Annexes I, II and III below.
- UK: the UK Addendum applies to the SCCs, with the relevant tables completed by reference to Annexes I to III, and the UK ICO as competent authority.
- Switzerland: the SCCs apply with references to the GDPR read as references to the FADP, and the Swiss FDPIC as supervisory authority.
We carry out transfer impact assessments, apply encryption in transit and at rest as supplementary measures, and will challenge any unlawful government request for data. We publish the number of such requests received in aggregate on request.
8. Security
We maintain the measures described in Annex II. We may update them provided the level of protection is not reduced. You are responsible for the security decisions within your control: strong unique passwords, multi-factor authentication where offered, and prompt removal of users who leave your business.
9. Personal data breach
We will notify you without undue delay and in any event within 72 hours of becoming aware of a personal data breach affecting Customer Personal Data. The notice will describe, to the extent known: the nature of the breach and the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed; and a contact point for more information. We will provide further detail as the investigation progresses and will reasonably assist you with your own notification obligations. Notification is not an acknowledgement of fault.
10. Data subject requests
The Service lets you access, correct, export and delete tenant records yourself. If a data subject contacts us directly about data we process for you, we will not respond substantively; we will forward the request to you without undue delay where we can identify you. Where you need additional assistance we will provide it, and may charge a reasonable fee for disproportionate effort after first agreeing it with you.
11. Audit
On request, no more than once in any twelve months and subject to confidentiality, we will provide: our current security documentation; responses to a reasonable security questionnaire; and any third-party audit report or certification we hold. Where that is genuinely insufficient to demonstrate compliance, and where Data Protection Laws require it, you may conduct an on-site audit on 30 days' written notice, during business hours, without unreasonably disrupting our operations, at your cost, using an independent auditor who is not our competitor and who signs a confidentiality agreement.
12. Deletion and return
You may export Customer Personal Data at any time during the subscription and for 30 days after termination. After that period we will delete it from live systems within 60 days, and it rotates out of backups within 35 days of deletion. We will certify deletion in writing on request. We may retain data where required by law, in which case we will continue to protect it and process it only for that purpose.
13. Liability, precedence and term
Each party's liability under this DPA is subject to the limitations in section 18 of the Terms of Service, except where Data Protection Laws prohibit that limitation. Where this DPA conflicts with the Terms of Service, this DPA prevails on data protection matters. Where the SCCs conflict with this DPA, the SCCs prevail. This DPA takes effect when you first use the Service and continues until we no longer process Customer Personal Data.
Annex I: Details of processing
| Data exporter | The Customer, as identified in the account. Contact: the account owner's email address. Role: controller. |
|---|---|
| Data importer | [LEGAL ENTITY NAME], [REGISTERED ADDRESS]. Contact: privacy@westorably.com. Role: processor. |
| Categories of data subjects | The Customer's tenants and prospective tenants; the Customer's employees and authorised users; emergency and alternate contacts provided by tenants. |
| Categories of personal data | Name; postal address; email address; telephone number; unit assignment; lease dates and terms; rental rate; payment, arrears and dispute history; last four digits and brand of payment method; notes entered by the Customer; identity documents where the Customer uploads them; gate and lock access events where smart lock integration is enabled; IP address and authentication logs for user accounts. |
| Special category data | None instructed. The Customer is contractually required not to upload special category data. If present, it is processed only as incidental content within free-text fields, with the same measures as other data. |
| Frequency of transfer | Continuous, for the duration of the subscription. |
| Nature and purpose | Hosting, storage, retrieval, display, transmission, backup, automated billing instruction, notification delivery, reporting, support and deletion, solely to provide the Service. |
| Duration | The term of the subscription, plus the retention periods in section 12. |
| Competent supervisory authority | The authority of the EEA member state in which the exporter is established, or its Article 27 representative; for UK transfers, the Information Commissioner's Office. |
Annex II: Technical and organisational measures
| Area | Measures |
|---|---|
| Encryption | TLS 1.2 or above for all data in transit, including internal service-to-service traffic. AES-256 encryption at rest for databases, file storage and backups. |
| Pseudonymisation | Passwords stored only as salted hashes. Analytics and diagnostics use aggregated or de-identified data wherever sufficient. |
| Access control | Role-based access inside the product. Least-privilege internal access on a documented need-to-know basis, reviewed periodically. Multi-factor authentication required for all administrative and infrastructure systems. Access revoked within one business day of a role change or departure. |
| Tenancy isolation | Logical separation of each Customer's data, enforced at the application and query layer, with automated tests covering cross-tenant access. |
| Payment data | Card data captured directly by Stripe (PCI DSS Level 1) in isolated fields. Westorably systems never receive or store full card numbers. |
| Resilience | Automated daily backups with point-in-time recovery, stored separately from production. Backup restoration tested periodically. |
| Logging and monitoring | Authentication and privileged-action logging, error and performance monitoring, and alerting on anomalous access patterns. |
| Secure development | Version control with peer review, dependency vulnerability scanning, separation of development and production environments, and no use of production personal data in development. |
| Vendor management | Security and data protection review before engaging a sub-processor, with written data protection terms in every case. |
| Incident response | Documented response procedure with defined roles, containment steps, notification timelines and post-incident review. |
| Personnel | Confidentiality obligations for all personnel and contractors; security awareness training; background checks where lawful and proportionate. |
| Deletion | Documented retention schedule with automated deletion routines and certified deletion on request. |
Annex III: Authorised sub-processors
The current list, with each sub-processor's purpose and processing location, is maintained at westorably.com/subprocessors and is incorporated into this DPA by reference.
Related: Terms of Service · Privacy Policy · Sub-processors · Acceptable Use Policy