1. Purpose

This policy defines Bitkaya B.V.’s approach to backing up data stored in Odoo SaaS, ensuring proportional, secure, and compliant data protection aligned with operational risk and regulatory expectations.

2. Scope

This policy applies to:

  • Odoo SaaS database and filestore
  • Client (KYC/KYB) data
  • Transaction and financial records
  • Operational and administrative data

3. Backup Responsibility Model

3.1 Odoo SaaS Responsibility

Odoo SaaS provides:

  • Automatic daily backups
  • Internal redundancy and infrastructure protection
  • Short-term recovery capability

These backups:

  • Are managed by Odoo
  • Are not directly controlled by Bitkaya
  • Are not intended as a standalone compliance backup solution

3.2 Bitkaya Responsibility

Bitkaya remains responsible for:

  • Independent backup control
  • Long-term retention
  • Regulatory compliance
  • Data recovery capability

4. Backup Strategy (Proportionality Principle)

Bitkaya applies a risk-based and proportional approach to backups:

  • The volume and frequency of backups reflect:
    • business size
    • transaction volume
    • risk exposure
  • Odoo’s daily backups mitigate short-term operational risk
  • Bitkaya’s external backups mitigate:
    • vendor dependency risk
    • data loss scenarios
    • audit and regulatory requirements

This approach balances:

  • operational efficiency
  • cost
  • compliance obligations

5. Backup Types and Frequency

5.1 Odoo Internal Backups

  • Frequency: Daily (automated by Odoo)
  • Purpose: Operational recovery
  • Control: Odoo-managed

5.2 Bitkaya External Backups

Monthly Backup (Primary Control)

  • Frequency: Monthly
  • Method: Manual download from Odoo
  • Scope: Full database + filestore

Optional Additional Backups

Additional backups may be performed during:

  • high transaction periods
  • system changes
  • prior to major releases

6. Offsite Storage (Microsoft SharePoint)

6.1 Primary Offsite Location

Bitkaya uses Microsoft 365 SharePoint as the primary offsite storage solution.

6.2 Rationale

  • Existing enterprise infrastructure
  • Strong access control and audit logging
  • Integration with internal workflows
  • Geographic redundancy

6.3 Storage Structure

Backups are stored in:

Bitkaya Compliance / offsite Backups (Bitkaya) / Odoo (Bitkaya)

7. Security Requirements

Backups are stored within the Microsoft 365 SharePoint environment, which provides:

  • Access control via role-based permissions
  • Audit logging and monitoring
  • Secure transmission (HTTPS)

Given these controls, additional encryption of backup files is not required under this policy. Access to backup files remains restricted to authorized personnel.

8. Retention Policy

  • Monthly backups retained for a minimum of 12 months
  • Extended retention may apply based on regulatory requirements
  • Older backups may be archived or securely deleted

9. Verification and Integrity

For each backup:

  • File integrity must be verified after upload
  • File size and completeness must be checked
  • Periodic restore testing must be performed

10. Logging and Audit Trail

Bitkaya maintains a backup log including:

  • Date of backup
  • File name
  • Responsible person
  • Verification status

This ensures:

  • auditability
  • accountability
  • compliance evidence

11. Incident Handling

In case of data loss or system failure:

  1. Attempt recovery via Odoo internal backups
  2. If unavailable, use latest Bitkaya external backup
  3. Document incident and recovery process
  4. Escalate to compliance if required

12. Limitations and Risk Acknowledgement

  • Monthly backups may result in potential data gaps of up to one month
  • This risk is accepted under the proportionality principle
  • Additional backups may be triggered if risk profile increases

13. Review and Updates

This policy is reviewed:

  • Annually
  • Upon system changes
  • Upon regulatory updates

15. Standard Operating Procedure (SOP) – Monthly Odoo Backup

This SOP defines the step-by-step process for performing Bitkaya’s monthly Odoo SaaS backup in line with this policy.

15.1 Preparation

  • Ensure access to Odoo database manager
  • Ensure access to SharePoint backup folder

15.2 Backup Execution Steps

Step 1 – Access Odoo Backup Manager

  • Navigate to: https://www.bitkaya.io/odoo/settings/my-subscription?debug=1

Step 2 – Download Backup

  • Click “Backups”
  • Download file

Step 3 – Rename File

  • Use format: YYYYMMDD Bitakaya Database Backup Odoo.zip

Step 4 – File Handling

  • Ensure file is stored securely
  • Do not distribute file outside approved storage locations
  • Maintain access restrictions

Step 5 – Upload to SharePoint

  • Upload encrypted file to: Bitkaya Compliance / Offsite Backups / Odoo

Step 6 – Verification

  • Confirm upload completed successfully
  • Verify file size is consistent
  • Optionally download file to confirm accessibility

15.3 Logging

  • Record backup in backup log including:
    • Date
    • File name
    • Responsible person
    • Verification status

15.4 Exception Handling

If backup fails:

  • Retry download once
  • If failure persists:
    • Notify responsible IT/Admin
    • Log incident

If upload fails:

  • Retry upload
  • Escalate if unresolved

15.5 Security Requirements

  • Store backups only within approved SharePoint location
  • Do not distribute backup files outside controlled environment
  • Ensure access is restricted to authorized personnel
  • Follow internal access control policies for Microsoft 365

15.6 Responsibility

  • Assigned staff member executes procedure
  • Compliance officer oversees adherence

15.7 Frequency

  • Perform once per month (first business day preferred)
  • Additional backups may be triggered if required

Roles

  • The Managing Director is the proposed approval authority pending confirmation.
  • Operations owns execution, logging, exception handling and recovery coordination.
  • Technology owns technical access, security, restore testing and change assessment.
  • Compliance oversees adherence, retention, evidence and regulatory alignment.
  • The outsourcing owner monitors Odoo and Microsoft 365 dependencies under the outsourcing framework.
  • Assigned staff perform backups only through authorized systems and storage locations.

Policy Requirements

  • Maintain documented backup responsibilities between Odoo and Bitkaya.
  • Perform an independent full database and filestore backup monthly, preferably on the first business day.
  • Perform additional backups after risk-based triggers such as material system change, major release or unusually high transaction activity.
  • Store external backups only in the approved Microsoft 365 SharePoint location with restricted role-based access and audit logging.
  • Retain monthly backups for at least 12 months and apply longer retention where legal or regulatory duties require.
  • Verify upload completion, file size and apparent completeness and record each backup in a controlled log.
  • Test restoration periodically and retain evidence that backup files are accessible and recoverable.
  • Escalate failed downloads, uploads, integrity checks or restores and preserve incident and remediation records.
  • Review backup frequency, accepted recovery-point exposure, provider dependency and proportionality annually and after material change or incident.
  • Resolve the date, approval, storage-path and file-encryption conflicts recorded in ISS-ODOO-001 Resolve Odoo Backup Policy Approval and Control Conflicts before approval.

Recovery Position

The document accepts a potential external-backup data gap of up to one month. This is a proposed recovery-point risk acceptance, not an approved recovery objective, until the accountable authority confirms it against the Business Impact Analysis and regulatory retention needs.

Recovery should first use Odoo’s available internal backup capability and then the latest verified Bitkaya external backup where provider recovery is unavailable or insufficient.

Operating Layer

This policy is implemented through PRC-RSA-001 Resilience Systems and Assurance and the linked PROC-ODOO-* procedures and CTRL-ODOO-* controls.

It specializes the backup, continuity, outsourcing and data-protection requirements in the IT, BCM, OUT and PRIV frameworks.

Implementing Procedures and Controls

Procedures

Controls

Source Document

  • Document title: Odoo SaaS Backup Policy
  • Version: 1.0 (Final)
  • Visible document date: 2025-03-22
  • PDF creation and modification date: 2026-03-22
  • Approval evidence: not present in the document
  • Permanent artifact: 20260322 Odoo SaaS Backup Policy v10 Final.pdf
  • Note: the policy is an internal artifact and is not registered as a regulatory source.

Assurance

  • Design status: documented; approval and conflicts pending
  • Operating assurance: pending system-derived assessment
  • Evidence status: backup log, files, access records, integrity checks and restore tests require verification
  • Overall status: review-stage design; do not represent as approved implementation

History

  • 2026-07-26: Aligned assurance wording with the system-derived Hermes/Odoo result model.
  • 2026-07-26: Registered the final Odoo backup policy, derived its operating layer and recorded document conflicts for resolution.
  • 2026-07-28: Enriched policy body to 100% PDF coverage — all 15 sections including the full SOP reproduced from the source document.