1. Purpose
This policy defines Bitkaya B.V.’s approach to backing up data stored in Odoo SaaS, ensuring proportional, secure, and compliant data protection aligned with operational risk and regulatory expectations.
2. Scope
This policy applies to:
- Odoo SaaS database and filestore
- Client (KYC/KYB) data
- Transaction and financial records
- Operational and administrative data
3. Backup Responsibility Model
3.1 Odoo SaaS Responsibility
Odoo SaaS provides:
- Automatic daily backups
- Internal redundancy and infrastructure protection
- Short-term recovery capability
These backups:
- Are managed by Odoo
- Are not directly controlled by Bitkaya
- Are not intended as a standalone compliance backup solution
3.2 Bitkaya Responsibility
Bitkaya remains responsible for:
- Independent backup control
- Long-term retention
- Regulatory compliance
- Data recovery capability
4. Backup Strategy (Proportionality Principle)
Bitkaya applies a risk-based and proportional approach to backups:
- The volume and frequency of backups reflect:
- business size
- transaction volume
- risk exposure
- Odoo’s daily backups mitigate short-term operational risk
- Bitkaya’s external backups mitigate:
- vendor dependency risk
- data loss scenarios
- audit and regulatory requirements
This approach balances:
- operational efficiency
- cost
- compliance obligations
5. Backup Types and Frequency
5.1 Odoo Internal Backups
- Frequency: Daily (automated by Odoo)
- Purpose: Operational recovery
- Control: Odoo-managed
5.2 Bitkaya External Backups
Monthly Backup (Primary Control)
- Frequency: Monthly
- Method: Manual download from Odoo
- Scope: Full database + filestore
Optional Additional Backups
Additional backups may be performed during:
- high transaction periods
- system changes
- prior to major releases
6. Offsite Storage (Microsoft SharePoint)
6.1 Primary Offsite Location
Bitkaya uses Microsoft 365 SharePoint as the primary offsite storage solution.
6.2 Rationale
- Existing enterprise infrastructure
- Strong access control and audit logging
- Integration with internal workflows
- Geographic redundancy
6.3 Storage Structure
Backups are stored in:
Bitkaya Compliance / offsite Backups (Bitkaya) / Odoo (Bitkaya)
7. Security Requirements
Backups are stored within the Microsoft 365 SharePoint environment, which provides:
- Access control via role-based permissions
- Audit logging and monitoring
- Secure transmission (HTTPS)
Given these controls, additional encryption of backup files is not required under this policy. Access to backup files remains restricted to authorized personnel.
8. Retention Policy
- Monthly backups retained for a minimum of 12 months
- Extended retention may apply based on regulatory requirements
- Older backups may be archived or securely deleted
9. Verification and Integrity
For each backup:
- File integrity must be verified after upload
- File size and completeness must be checked
- Periodic restore testing must be performed
10. Logging and Audit Trail
Bitkaya maintains a backup log including:
- Date of backup
- File name
- Responsible person
- Verification status
This ensures:
- auditability
- accountability
- compliance evidence
11. Incident Handling
In case of data loss or system failure:
- Attempt recovery via Odoo internal backups
- If unavailable, use latest Bitkaya external backup
- Document incident and recovery process
- Escalate to compliance if required
12. Limitations and Risk Acknowledgement
- Monthly backups may result in potential data gaps of up to one month
- This risk is accepted under the proportionality principle
- Additional backups may be triggered if risk profile increases
13. Review and Updates
This policy is reviewed:
- Annually
- Upon system changes
- Upon regulatory updates
15. Standard Operating Procedure (SOP) – Monthly Odoo Backup
This SOP defines the step-by-step process for performing Bitkaya’s monthly Odoo SaaS backup in line with this policy.
15.1 Preparation
- Ensure access to Odoo database manager
- Ensure access to SharePoint backup folder
15.2 Backup Execution Steps
Step 1 – Access Odoo Backup Manager
- Navigate to:
https://www.bitkaya.io/odoo/settings/my-subscription?debug=1
Step 2 – Download Backup
- Click “Backups”
- Download file
Step 3 – Rename File
- Use format:
YYYYMMDD Bitakaya Database Backup Odoo.zip
Step 4 – File Handling
- Ensure file is stored securely
- Do not distribute file outside approved storage locations
- Maintain access restrictions
Step 5 – Upload to SharePoint
- Upload encrypted file to:
Bitkaya Compliance / Offsite Backups / Odoo
Step 6 – Verification
- Confirm upload completed successfully
- Verify file size is consistent
- Optionally download file to confirm accessibility
15.3 Logging
- Record backup in backup log including:
- Date
- File name
- Responsible person
- Verification status
15.4 Exception Handling
If backup fails:
- Retry download once
- If failure persists:
- Notify responsible IT/Admin
- Log incident
If upload fails:
- Retry upload
- Escalate if unresolved
15.5 Security Requirements
- Store backups only within approved SharePoint location
- Do not distribute backup files outside controlled environment
- Ensure access is restricted to authorized personnel
- Follow internal access control policies for Microsoft 365
15.6 Responsibility
- Assigned staff member executes procedure
- Compliance officer oversees adherence
15.7 Frequency
- Perform once per month (first business day preferred)
- Additional backups may be triggered if required
Roles
- The Managing Director is the proposed approval authority pending confirmation.
- Operations owns execution, logging, exception handling and recovery coordination.
- Technology owns technical access, security, restore testing and change assessment.
- Compliance oversees adherence, retention, evidence and regulatory alignment.
- The outsourcing owner monitors Odoo and Microsoft 365 dependencies under the outsourcing framework.
- Assigned staff perform backups only through authorized systems and storage locations.
Policy Requirements
- Maintain documented backup responsibilities between Odoo and Bitkaya.
- Perform an independent full database and filestore backup monthly, preferably on the first business day.
- Perform additional backups after risk-based triggers such as material system change, major release or unusually high transaction activity.
- Store external backups only in the approved Microsoft 365 SharePoint location with restricted role-based access and audit logging.
- Retain monthly backups for at least 12 months and apply longer retention where legal or regulatory duties require.
- Verify upload completion, file size and apparent completeness and record each backup in a controlled log.
- Test restoration periodically and retain evidence that backup files are accessible and recoverable.
- Escalate failed downloads, uploads, integrity checks or restores and preserve incident and remediation records.
- Review backup frequency, accepted recovery-point exposure, provider dependency and proportionality annually and after material change or incident.
- Resolve the date, approval, storage-path and file-encryption conflicts recorded in ISS-ODOO-001 Resolve Odoo Backup Policy Approval and Control Conflicts before approval.
Recovery Position
The document accepts a potential external-backup data gap of up to one month. This is a proposed recovery-point risk acceptance, not an approved recovery objective, until the accountable authority confirms it against the Business Impact Analysis and regulatory retention needs.
Recovery should first use Odoo’s available internal backup capability and then the latest verified Bitkaya external backup where provider recovery is unavailable or insufficient.
Operating Layer
This policy is implemented through PRC-RSA-001 Resilience Systems and Assurance and the linked PROC-ODOO-* procedures and CTRL-ODOO-* controls.
It specializes the backup, continuity, outsourcing and data-protection requirements in the IT, BCM, OUT and PRIV frameworks.
Implementing Procedures and Controls
Procedures
- PROC-ODOO-001 Govern Odoo Backup Strategy Responsibilities and Recovery Objectives
- PROC-ODOO-002 Execute Monthly Odoo SaaS External Backup
- PROC-ODOO-003 Protect SharePoint Backup Storage Access Retention and Disposal
- PROC-ODOO-004 Verify Backup Integrity Logging and Evidence
- PROC-ODOO-005 Test Odoo Restore and Perform Data Recovery
- PROC-ODOO-006 Manage Backup Exceptions Vendor Dependency Changes and Review
Controls
- CTRL-ODOO-001 Ensure Odoo Backup Strategy Responsibilities and Objectives Are Approved
- CTRL-ODOO-002 Ensure Monthly Odoo External Backup Is Completed
- CTRL-ODOO-003 Ensure Odoo Backup Storage Access Retention and Disposal Are Controlled
- CTRL-ODOO-004 Ensure Odoo Backups Are Verified Logged and Evidenced
- CTRL-ODOO-005 Ensure Odoo Backups Are Restored and Recovery Is Tested
- CTRL-ODOO-006 Ensure Backup Exceptions Dependencies and Changes Are Reviewed
Source Document
- Document title: Odoo SaaS Backup Policy
- Version: 1.0 (Final)
- Visible document date: 2025-03-22
- PDF creation and modification date: 2026-03-22
- Approval evidence: not present in the document
- Permanent artifact: 20260322 Odoo SaaS Backup Policy v10 Final.pdf
- Note: the policy is an internal artifact and is not registered as a regulatory source.
Assurance
- Design status: documented; approval and conflicts pending
- Operating assurance: pending system-derived assessment
- Evidence status: backup log, files, access records, integrity checks and restore tests require verification
- Overall status: review-stage design; do not represent as approved implementation
History
- 2026-07-26: Aligned assurance wording with the system-derived Hermes/Odoo result model.
- 2026-07-26: Registered the final Odoo backup policy, derived its operating layer and recorded document conflicts for resolution.
- 2026-07-28: Enriched policy body to 100% PDF coverage — all 15 sections including the full SOP reproduced from the source document.