Privacy Policy
Effective Date: 8 September 2026 · Last Updated: 8 September 2026
Subnet Calc Limited (company number 17177789), registered at Unit 34, 53 Mowbray Street, Sheffield, S3 8EN (“Subnet Calc”, “we”, “us”, “our”) is the data controller for personal data processed through the Subnet Calc service at www.subnetcalc.com (the “Service”).
This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, and your rights regarding your data.
1. Data We Collect
1.1 Account and Identity Data
When you create an Account by signing in with a third-party identity provider (Microsoft, Google, or Apple), we receive and store:
- Email address — used as your primary identifier
- First name and last name — used for display within the Service
- OAuth provider identifier — used to link your identity provider account to your Subnet Calc Account
We do not store passwords. Authentication is handled entirely by your chosen identity provider.
If you sign in with different providers that share the same email address, we link them to a single Subnet Calc Account.
1.2 Project and Design Data
When you use the Service with a paid Subscription, we store:
- Subnet design projects (IPv4 and IPv6 configurations, network hierarchy, address allocations)
- Project metadata (name, creation date, last modified date, assigned region)
- Collaboration data (team membership, role assignments, design locks)
1.3 Payment Data
Payment processing is handled entirely by Stripe. We do not store credit card numbers, bank account details, or other payment instruments on our systems.
We do store:
- Stripe Customer ID and Subscription ID (to link your Account to your Stripe subscription)
- Subscription status, tier, and billing period dates
- Cancellation reason (if you provide one voluntarily when cancelling)
For details on how Stripe processes your payment data, see Stripe's Privacy Policy.
1.4 Session Data
When you sign in, we create a server-side session that includes:
- A session identifier
- Your authentication token (short-lived JWT, 15-minute expiry)
- A refresh token (24-hour or 90-day expiry if you select “remember me”)
Session data is stored securely on our infrastructure and is not shared with third parties.
1.5 Communication Data
We store records of transactional emails sent to you (type, timestamp, delivery status) for operational and troubleshooting purposes.
1.6 Technical Data
We may collect:
- IP address (via Azure Front Door request logs)
- Browser type and version (via standard HTTP headers)
- Request timestamps and response codes
This data is used for security monitoring, abuse prevention, and service reliability.
1.7 Advertising Referral and Conversion Data
When you arrive through a supported advertising link, we may receive a referral identifier such as a Google gclid, campaign parameters such as UTM source, medium, campaign, and term, and the landing path. We use this information to record whether the referral leads to an account signup or paid purchase.
The customer application initially holds this information in memory. If you sign up or sign in, we may link the referral record to your Account for up to 90 days. When a purchase is completed, we may retain derived campaign and conversion fields with the related financial record for reporting, audit, fraud prevention, dispute handling, or legal obligations. Raw click identifiers are deleted or irreversibly suppressed from the account-linked record after 90 days unless a documented exception applies. We do not use this information to make decisions about your access to the Service, and we do not store it in a marketing cookie or localStorage.
See our Legitimate Interests Assessment for the balancing assessment supporting this processing.
2. How We Use Your Data
| Purpose | Legal Basis (GDPR) | Data Used |
|---|---|---|
| Provide and operate the Service | Performance of contract (Art. 6(1)(b)) | Account, project, session data |
| Process payments and manage Subscriptions | Performance of contract (Art. 6(1)(b)) | Account, payment data (via Stripe) |
| Send transactional emails (welcome, subscription events, team invites) | Performance of contract (Art. 6(1)(b)) | Email address, name |
| Replicate data across regions for availability | Performance of contract (Art. 6(1)(b)) | Account, project data |
| Security monitoring and abuse prevention | Legitimate interest (Art. 6(1)(f)) | Technical data, session data |
| Respond to support enquiries | Legitimate interest (Art. 6(1)(f)) | Account data, email address |
| Measure advertising referrals and attribute signups and purchases | Legitimate interest (Art. 6(1)(f)) | Advertising click identifier, campaign parameters, Account and purchase identifiers, transaction value and currency |
| Send marketing communications (if introduced) | Consent (Art. 6(1)(a)) | Email address |
| Comply with legal obligations | Legal obligation (Art. 6(1)(c)) | As required by law |
3. Data Sharing
We share your personal data only with the following categories of recipients, and only to the extent necessary:
3.1 Service Providers (Sub-processors)
| Provider | Purpose | Data Shared | Location |
|---|---|---|---|
| Inflecto Systems Ltd | Development, maintenance, and technical support of the Service | Account data, project data, session data, technical data (as needed for support and system administration) | United Kingdom |
| Microsoft Azure | Cloud infrastructure (compute, storage, networking) | All service data (encrypted at rest and in transit) | North Europe, East US, Australia East |
| Stripe | Payment processing | Email, name, Stripe Customer ID, payment instruments | United States |
| Google Ads (Google LLC) | Offline conversion measurement and advertising campaign optimisation | Advertising click identifier, purchase identifier, purchase timestamp, transaction value and currency; no email address or payment-card data. Google's role is determined under the applicable Google Ads service terms. | United States / Global |
| SendGrid (Twilio) | Transactional email delivery | Email address, name, email content | European Union |
| CookieBot (Usercentrics) | Cookie consent management | Cookie consent preferences, anonymised IP | European Union |
| Microsoft / Google / Apple | OAuth authentication | OAuth tokens (during authentication flow only) | Global |
A complete list is maintained at /legal/sub-processors.
3.2 Legal Requirements
We may disclose personal data if required by law, regulation, legal process, or governmental request.
3.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, personal data may be transferred to the successor entity. We will notify you of any such transfer.
We do not sell your personal data to third parties.
4. International Data Transfers
Your data may be processed in the following regions:
- North Europe (Azure, primary region)
- East US (Azure)
- Australia East (Azure)
- United States (Stripe)
- European Union (SendGrid, CookieBot)
- United Kingdom (Inflecto Systems Ltd)
For transfers outside the European Economic Area (EEA), we rely on:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions where applicable (e.g., UK)
- The data recipient's certification under relevant frameworks
For details on regional data storage, see our Data Residency Statement.
5. Data Retention
| Data Type | Retention Period |
|---|---|
| Account data | Duration of Account + 12 months after last Subscription cancellation |
| Project data | Duration of active Subscription + 12 months read-only retention after cancellation |
| Session data | Until session expiry (24 hours or 90 days for remember-me) |
| Payment metadata | Duration of Account + as required by tax/accounting obligations (typically 7 years) |
| Account-linked advertising attribution | Up to 90 days from capture, unless deleted or suppressed following a valid request |
| Purchase conversion attribution | Derived campaign and conversion fields may be retained with the related payment and accounting record as required for reporting, audit, fraud prevention, dispute handling, and legal obligations. Raw click identifiers are deleted or irreversibly suppressed after 90 days unless a documented exception applies. |
| Transactional email records | 12 months |
| Technical/security logs | 90 days |
After the applicable retention period, data is permanently deleted.
6. Your Rights
Under the GDPR and other applicable data protection laws, you have the following rights:
6.1 Right of Access
You may request a copy of the personal data we hold about you.
6.2 Right to Rectification
You may request correction of inaccurate personal data. Note: your name and email are sourced from your identity provider — to update them, change them with your provider and re-authenticate.
6.3 Right to Erasure (“Right to be Forgotten”)
You may request deletion of your Account and all associated personal data. We will comply unless we have a legal obligation to retain certain data (e.g., tax records).
6.4 Right to Data Portability
You may request your project data in a structured, commonly used, machine-readable format (JSON).
6.5 Right to Restrict Processing
You may request that we restrict processing of your personal data in certain circumstances (e.g., while we verify accuracy of data you have contested).
6.6 Right to Object
You may object to processing based on legitimate interests. We will cease processing unless we have compelling legitimate grounds.
6.7 Right to Withdraw Consent
Where processing is based on consent (e.g., marketing emails), you may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.
6.8 Right to Lodge a Complaint
You have the right to lodge a complaint with your local data protection supervisory authority. In the UK, this is the Information Commissioner's Office (ICO) at ico.org.uk.
How to Exercise Your Rights
Submit a request via our support page. We will respond within 30 days (or the timeframe required by applicable law). We may need to verify your identity before processing your request.
7. Data Security
We implement appropriate technical and organisational measures to protect your personal data, including:
- Encryption in transit — all connections use TLS
- Encryption at rest — all stored data is encrypted using industry-standard AES-256 encryption
- No password storage — OAuth-only authentication
- Session security — HttpOnly, Secure, SameSite cookies; short-lived JWTs with server-side refresh token validation
- Access controls — role-based team permissions; principle of least privilege for infrastructure access
- Multi-region redundancy — data replicated across regions for availability and disaster recovery
For more information, see our Security Overview.
8. Children's Privacy
The Service is not directed at individuals under 18 years of age. We do not knowingly collect personal data from children. If you believe we have collected data from a child, contact us via our support page and we will delete it promptly.
9. Australian Privacy Principles
If you are located in Australia, you have additional rights under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). This includes:
- The right to access your personal information (APP 12)
- The right to request correction of inaccurate information (APP 13)
- The right to make a complaint about our handling of your information (APP 1)
We will respond to complaints within 30 days. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
In the event of an eligible data breach, we will notify affected individuals and the OAIC as required under the Notifiable Data Breaches scheme.
10. US State Privacy Rights
If you are a resident of California or another US state with applicable privacy legislation:
- You have the right to know what personal data we collect and how we use it
- You have the right to request deletion of your personal data
- You have the right to opt out of the sale of personal data — we do not sell personal data
- We will not discriminate against you for exercising your privacy rights
11. Cookies
We use a limited number of cookies, primarily for authentication. Our full cookie disclosure is available in our Cookie Policy. Cookie consent is managed by CookieBot.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or through the Service at least 30 days before they take effect. The “Last Updated” date at the top of this page indicates when the policy was last revised.
13. Contact
For privacy-related enquiries:
Data Controller:
Subnet Calc Limited
Unit 34, 53 Mowbray Street, Sheffield, S3 8EN
Submit a request via our support page.
Technical Support & System Maintenance:
Inflecto Systems Ltd (acting as data processor on behalf of Subnet Calc Limited)