Basalt Storage

Data Processing Addendum

Forms part of the Terms of Service where the customer is a controller under Regulation (EU) 2016/679.

Roles

The customer acts as controller. Basalt Systems OÜ acts as processor and processes personal data only on documented instructions, which the API requests themselves constitute.

Processing details

Subject matterStorage and retrieval of customer objects
DurationTerm of the agreement plus 14 days
Categories of dataDetermined by the customer; opaque to the processor
Data subjectsDetermined by the customer
LocationsRegions selected by the customer, all within the EEA

Security measures

Encryption in transit (TLS 1.2+) and at rest (AES-256), erasure coding across three failure domains, least-privilege internal access with hardware-token authentication, quarterly restore tests, and annual third-party penetration testing.

Sub-processing and audits

Sub-processors are engaged under equivalent terms; customers are notified 30 days before additions and may object. Audit reports are provided annually; on-site audits may be requested once per year with 30 days' notice.

Breach notification

Confirmed personal data breaches are reported to the customer without undue delay and in any event within 48 hours of confirmation, with the facts known at that time and the remediation in progress.

← basalt storage