Data Processing Agreement
Effective Date: 7 May 2026 · Last Updated: 7 May 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between Subnet Calc Limited (“Data Processor”, “we”, “us”) and the Customer (“Data Controller”, “you”, “your”) for the provision of the Subnet Calc service (the “Service”).
This DPA applies where you, as a Data Controller, use the Service and the processing of personal data of your team members, employees, or other data subjects is involved.
1. Definitions
Terms used in this DPA have the meanings given in the General Data Protection Regulation (EU) 2016/679 (“GDPR”), the UK GDPR, and the Terms of Service, unless otherwise defined.
- “Personal Data” means any information relating to an identified or identifiable natural person processed by the Data Processor on behalf of the Data Controller through the Service.
- “Processing” means any operation performed on Personal Data, including collection, storage, retrieval, use, disclosure, combination, erasure, or destruction.
- “Sub-processor” means a third party engaged by the Data Processor to process Personal Data on behalf of the Data Controller.
- “Data Subject” means an identified or identifiable natural person whose Personal Data is processed.
2. Scope and Purpose of Processing
2.1 Categories of Data Subjects
- Team members invited to your Team within the Service
- Account owners and administrators
2.2 Types of Personal Data Processed
- Email addresses
- First and last names
- OAuth provider identifiers
- Team membership and role assignments
- Subnet design project data (to the extent it contains or is linked to personal data)
- Session and authentication data
2.3 Purpose of Processing
Personal Data is processed solely for the purpose of providing the Service, including:
- Account management and authentication
- Team membership management
- Subnet design storage, collaboration, and replication
- Transactional email communications
- Payment processing (via Stripe)
- Technical support and system maintenance (via Inflecto Systems Ltd)
3. Obligations of the Data Processor
We shall:
3.1. Process Personal Data only on documented instructions from the Data Controller, unless required by applicable law (in which case we will inform the Data Controller before processing, unless prohibited by law).
3.2. Ensure that persons authorised to process Personal Data have committed to confidentiality or are under an appropriate statutory obligation of confidentiality.
3.3. Implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- Encryption of Personal Data in transit (TLS) and at rest (AES-256)
- OAuth-only authentication (no password storage)
- Role-based access controls
- Regular security monitoring and vulnerability management
- Multi-region data replication for availability and disaster recovery
3.4. Not engage another processor (Sub-processor) without prior specific or general written authorisation of the Data Controller. Where general authorisation is given, the Data Processor shall inform the Data Controller of any intended additions or replacements of Sub-processors, giving the Data Controller the opportunity to object.
3.5. Assist the Data Controller in responding to Data Subject requests (access, rectification, erasure, portability, restriction, objection) by appropriate technical and organisational measures.
3.6. Assist the Data Controller in ensuring compliance with obligations relating to security of processing, notification of personal data breaches, data protection impact assessments, and prior consultation with supervisory authorities.
3.7. At the choice of the Data Controller, delete or return all Personal Data after the end of the provision of the Service, and delete existing copies unless applicable law requires storage.
3.8. Make available to the Data Controller all information necessary to demonstrate compliance with these obligations and allow for and contribute to audits, including inspections, conducted by the Data Controller or a mandated auditor.
4. Sub-processors
4.1 Authorised Sub-processors
The Data Controller provides general authorisation for the use of the Sub-processors listed at /legal/sub-processors.
4.2 Obligations on Sub-processors
We impose the same data protection obligations as set out in this DPA on each Sub-processor by way of a contract. We remain fully liable for the performance of each Sub-processor's obligations.
4.3 Changes to Sub-processors
We will notify the Data Controller at least 30 days in advance of any intended addition or replacement of Sub-processors by updating the Sub-processor List and notifying you by email.
If the Data Controller objects to a new Sub-processor within 14 days of notification, the parties shall discuss the objection in good faith. If no resolution is reached, the Data Controller may terminate the affected Service with immediate effect.
5. International Data Transfers
Personal Data may be transferred to and processed in the jurisdictions listed in our Data Residency Statement.
For transfers outside the EEA/UK, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) as approved by the European Commission (and the UK Information Commissioner's Office as applicable)
- Adequacy decisions where applicable
- Supplementary measures where required by applicable law
6. Data Breach Notification
6.1. We will notify the Data Controller without undue delay (and in any event within 72 hours) after becoming aware of a personal data breach affecting the Data Controller's Personal Data.
6.2. The notification will include:
- A description of the nature of the breach, including categories and approximate numbers of data subjects and records affected
- The name and contact details of our data protection contact
- A description of the likely consequences of the breach
- A description of the measures taken or proposed to address the breach, including measures to mitigate its adverse effects
7. Data Protection Impact Assessments
We will provide reasonable assistance to the Data Controller in conducting data protection impact assessments and prior consultations with supervisory authorities, where required under Articles 35 and 36 of the GDPR.
8. Audit Rights
8.1. Upon written request, the Data Processor shall provide the Data Controller with documentation and evidence demonstrating compliance with the obligations set out in this DPA. This may include security certifications, compliance reports, or written responses to reasonable audit questionnaires.
8.2. If documentation alone is insufficient to demonstrate compliance, the Data Controller (or a mandated third-party auditor bound by confidentiality) may conduct a remote audit upon reasonable notice (at least 30 days) and no more than once per calendar year, unless a data breach or supervisory authority request necessitates an additional audit.
8.3. Audits shall be conducted during normal business hours and shall not unreasonably interfere with our operations.
8.4. The Data Controller shall bear the costs of any audit it initiates.
9. Term and Termination
9.1. This DPA shall remain in effect for the duration of the processing of Personal Data under the Service agreement.
9.2. Upon termination of the Service, we will:
- Continue to protect Personal Data during any post-cancellation read-only retention period (12 months)
- Delete all Personal Data after the retention period unless applicable law requires continued storage
10. Liability
The liability of each party under this DPA is subject to the limitations and exclusions set out in the Terms of Service.
11. Contact
Data Processor:
Subnet Calc Limited
Unit 34, 53 Mowbray Street, Sheffield, S3 8EN
Submit enquiries via our support page.
Technical Support (Sub-processor):
Inflecto Systems Ltd