This Data Processing Agreement (“DPA”) is entered into as of July 17, 2026 between Polystorage LLC, a Michigan limited liability company (“Polystorage” or “Processor”), and the Customer identified in the applicable Master Service Agreement (“Customer” or “Controller”). This DPA is incorporated by reference into the Master Service Agreement between Polystorage and Customer (the “MSA”) and governs Polystorage’s processing of personal data on Customer’s behalf. Capitalized terms not defined here have the meanings given in the MSA.
Section 1 — Processing Details
1.1 Nature and Purpose. Polystorage processes Personal Data to provide the polystorage storage facility management platform, including tenant account management, lease administration, billing and payment processing, lien notice workflows, email communications, and related platform features as described in the MSA and Documentation.
1.2 Categories of Data Subjects. Current and former tenants of Customer’s storage facilities; Customer’s employees and administrators who use the platform.
1.3 Categories of Personal Data.
| Data Subject | Categories of Personal Data |
|---|---|
| Tenants | Name, email address, phone number, mailing address, gate PIN, payment method references (tokenized), lease and unit information, payment and invoice history, lien status, communication preferences, IP address (portal access logs), military status flag. |
| Operator Users | Name, email address, role, login credentials (managed by PropelAuth), session tokens, IP address (audit logs), activity logs. |
1.4 Duration. Polystorage processes Personal Data for the duration of the MSA. Upon termination, data handling is governed by Section 8 of this DPA and Section 9.3 of the MSA.
Section 2 — Controller Instructions and Responsibilities
2.1 Documented Instructions. Polystorage shall process Personal Data only on Customer’s documented instructions, as set out in this DPA and the MSA. If Polystorage is required by applicable law to process Personal Data beyond those instructions, Polystorage shall notify Customer before such processing unless prohibited by law.
2.2 Customer Responsibilities. Customer, as Controller, is responsible for: (a) ensuring it has a valid legal basis to collect and process the Personal Data it submits to the Service; (b) providing all required notices to data subjects and obtaining any required consents (including E-SIGN, TCPA, and Regulation E consents facilitated through the Tenant Portal); (c) ensuring Customer Data does not violate any third party’s rights; and (d) complying with applicable data protection law in its capacity as Controller.
Section 3 — Processor Obligations
3.1 Confidentiality of Processing. Polystorage shall ensure that all personnel authorized to process Personal Data are bound by appropriate confidentiality obligations and are informed of the relevant data protection requirements applicable to their role.
3.2 Security Measures. Polystorage shall implement and maintain the following technical and organizational measures to protect Personal Data:
- Encryption at rest — AES-256 encryption for all stored Personal Data;
- Encryption in transit — TLS 1.2 or higher for all data transmitted between users and the platform;
- Access controls — Role-based access control (RBAC) enforced at the application layer (Owner, Admin, and Member roles); PropelAuth is used for authentication only; principle of least privilege applied to internal personnel access;
- Authentication — Multi-factor authentication available for all operator accounts;
- Audit logging — Audit logs of access and actions affecting Personal Data, maintained with access controls that restrict modification to authorized system processes;
- Vulnerability management — Regular dependency updates and security patching; and
- Incident response — Documented incident response plan with the notification obligations set forth in Section 5 of this DPA.
3.3 Assistance with Data Subject Rights. Polystorage shall provide Customer with reasonable technical assistance to fulfill data subject rights requests (access, correction, deletion, portability, restriction) submitted to Customer under applicable data protection law, to the extent Polystorage has access to the relevant Personal Data and the requested action is technically feasible. Customer remains responsible for receiving, evaluating, and responding to data subject requests.
3.4 Assistance with Compliance. Polystorage shall, upon written request and to the extent reasonably possible, provide Customer with information necessary to demonstrate compliance with Polystorage’s obligations under this DPA, including information to assist Customer in conducting data protection impact assessments where required by applicable law.
Section 4 — Sub-processors
4.1 Authorization. Customer provides general written authorization for Polystorage to engage the sub-processors listed in Section 4.3. Polystorage shall use commercially reasonable efforts to contractually require data protection measures from each sub-processor that are consistent with those in this DPA, and will enter into a data processing or security agreement with each sub-processor where one is commercially available. Polystorage remains responsible for selecting sub-processors that provide sufficient guarantees to implement appropriate technical and organizational measures in accordance with this DPA.
4.2 Changes. Polystorage will provide Customer with at least thirty (30) days’ advance written notice (email to the billing contact on file) of any intended addition to or replacement of sub-processors. If Customer objects to a new sub-processor on reasonable data protection grounds within the notice period, the parties shall negotiate in good faith. If the parties cannot resolve the objection, Customer may terminate this DPA and the MSA with respect to the affected processing without penalty.
4.3 Current Sub-processors.
| Sub-processor | Location | Processing Purpose |
|---|---|---|
| Amazon Web Services (AWS) | United States | Cloud hosting, compute, and database storage for all platform data |
| Resend | United States | Transactional email delivery; receives recipient email address, message content, and delivery/bounce/complaint status |
| Stripe Inc. | United States | Payment processing and tokenization; connected-account onboarding and identity verification; payout services; receives billing name, address, tokenized payment method references, and (for operator payout accounts) identity-verification data submitted directly to Stripe |
| PropelAuth | United States | Operator user authentication, identity management, and session management |
Section 5 — Security Incidents
5.1 Notification. Polystorage shall notify Customer within five (5) business days of becoming aware of any event that Polystorage reasonably believes may involve unauthorized access to, disclosure of, or destruction of Customer’s Personal Data (“Security Incident”). Initial notification shall not be delayed pending full confirmation of the incident’s scope. Notification shall be made to the billing contact email on file and shall include, to the extent then known: (a) a description of the nature of the event; (b) the categories and approximate number of data subjects and records believed to be affected; (c) the likely consequences; and (d) the measures taken or proposed to address the incident and mitigate its effects. Polystorage shall provide a supplemental written report with confirmed findings within fifteen (15) days of initial notification.
5.2 Cooperation. Polystorage shall cooperate with Customer and take reasonable steps to assist in the investigation, mitigation, and remediation of any Security Incident. Polystorage’s notification of or response to a Security Incident does not constitute an admission of fault or liability.
5.3 Customer Obligations. Customer is solely responsible for determining whether a Security Incident requires notification to data subjects, regulators, or other third parties under applicable law, and for providing any such notifications. Polystorage shall provide reasonable assistance upon written request.
Section 6 — Audit Rights
6.1 Documentation. Polystorage shall make available to Customer, upon reasonable written request, documentation sufficient to demonstrate Polystorage’s compliance with its obligations under this DPA, including this DPA and responses to Customer’s reasonable written information security questionnaires.
6.2 Information Security Questionnaires. Polystorage will cooperate with Customer’s reasonable written information security questionnaires submitted in connection with Customer’s vendor management or compliance obligations. Polystorage will use commercially reasonable efforts to respond within forty-five (45) days of receipt. Where Polystorage has obtained a current third-party security audit or certification, Polystorage may provide that report in lieu of responding to specific questionnaire items covered by its scope, subject to a written non-disclosure agreement.
6.3 On-Site Audits. Where Customer has a documented, good-faith basis to believe a material compliance failure has occurred that cannot be addressed through the process in Section 6.2, Customer may request a more targeted audit no more than once per twelve-month period (except following a confirmed Security Incident) on at least thirty (30) days’ written notice specifying the audit scope. Auditors must be independent, not a competitor of Polystorage, and bound by a written confidentiality agreement with Polystorage before receiving any access. If the audit reveals no material non-compliance, Customer bears the cost; if material non-compliance is found, Polystorage bears the reasonable third-party audit cost. For purposes of this Section, “material non-compliance” means Polystorage’s documented failure to implement or maintain one or more of the specific security measures enumerated in Section 3.2, or Polystorage’s failure to fulfill its notification obligations under Section 5.1. Differences in implementation approach, matters of degree, or areas where Polystorage has deployed equivalent alternative controls do not constitute material non-compliance.
Section 7 — International Data Transfers
7.1 U.S.-Based Processing. Polystorage’s primary processing infrastructure is located in the United States. The platform is designed to serve storage facility operators within the United States. If Customer anticipates processing Personal Data of individuals located in the European Economic Area, United Kingdom, or Switzerland, Customer must notify Polystorage in writing before onboarding such data subjects, and the parties will cooperate to implement appropriate transfer safeguards (including Standard Contractual Clauses where required) before any such transfer occurs. Processing EU/EEA Personal Data through the platform without completing this process constitutes a material breach by Customer.
Section 8 — Retention and Deletion
8.1 During the Term. Polystorage retains Personal Data for as long as necessary to provide the Service, subject to the following baseline retention periods. For purposes of this DPA, “anonymized” means that personal identifiers (name, email address, phone number, mailing address, and gate PIN) have been replaced with non-identifying placeholder values such that the individual cannot reasonably be identified from the remaining data without reference to external information not in Polystorage’s possession.
- Tenant PII (name, email, phone, address, gate PIN, payment method references) — anonymized ninety (90) days after all associated leases are closed and balances settled;
- Financial records (invoices, transaction amounts, dates, fees assessed) — retained for seven (7) years to satisfy applicable accounting and tax record requirements;
- Security and access logs — retained for ninety (90) days, after which identifying information (IP addresses, user IDs) is anonymized; and
- Legal action logs (lien status changes, auction approvals, SCRA holds) — retained for seven (7) years from the date of the relevant action.
8.2 Post-Termination. Following termination or expiration of the MSA, Polystorage will make Customer Data available for export for ninety (90) days as provided in the MSA. After that export window, Polystorage will delete or anonymize all remaining Customer Personal Data, except to the extent retention is required by applicable law or the retention periods in Section 8.1.
8.3 Deletion Requests. Customer may submit requests to delete specific Tenant Personal Data through the platform’s data deletion workflow. Polystorage will process confirmed deletion requests within thirty (30) days, including issuing deletion instructions to sub-processors (PropelAuth and Stripe) as part of the automated deletion workflow. Polystorage shall confirm completion of deletion from its own systems and from sub-processors in writing within forty-five (45) days of the confirmed request. Notwithstanding the foregoing, Stripe independently retains transaction records (charge history, invoice amounts, and dates) and connected-account verification data (KYC/identity records) for fraud prevention and regulatory compliance purposes pursuant to Stripe’s own legal obligations; such retention by Stripe is not a violation of this DPA.
Section 9 — General
9.1 Relationship to MSA. This DPA is incorporated into and forms part of the MSA. In the event of a conflict between this DPA and the MSA on matters relating to the processing of Personal Data, this DPA controls. In all other matters, the MSA controls. The liability provisions of the MSA (including the aggregate cap and exclusion of consequential damages) apply to this DPA.
9.2 Governing Law. This DPA is governed by the laws of the State of Michigan, consistent with the MSA.
9.3 Updates. Polystorage may update this DPA from time to time to reflect changes in applicable data protection law or Polystorage’s processing activities. Polystorage will provide Customer with at least thirty (30) days’ written notice of any material changes. Customer’s continued use of the Service after the effective date of an update constitutes acceptance.