Subnet Calc logo
PlaygroundPricingFont Awesome Free 7.2.0 by @fontawesome - https://fontawesome.com License - https://fontawesome.com/license/free Copyright 2026 Fonticons, Inc.Login
OverviewTerms of ServicePrivacy PolicyCookie PolicyRefund & CancellationSubscription TermsData Processing AgreementSub-processorsLegitimate InterestsSecurity OverviewService Level AgreementData ResidencySustainabilityResponsible Disclosure
OverviewTerms of ServicePrivacy PolicyCookie PolicyRefund & CancellationSubscription TermsData Processing AgreementSub-processorsLegitimate InterestsSecurity OverviewService Level AgreementData ResidencySustainabilityResponsible Disclosure

Privacy Policy

Effective Date: 8 September 2026 · Last Updated: 8 September 2026

Subnet Calc Limited (company number 17177789), registered at Unit 34, 53 Mowbray Street, Sheffield, S3 8EN (“Subnet Calc”, “we”, “us”, “our”) is the data controller for personal data processed through the Subnet Calc service at www.subnetcalc.com (the “Service”).

This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, and your rights regarding your data.


1. Data We Collect

1.1 Account and Identity Data

When you create an Account by signing in with a third-party identity provider (Microsoft, Google, or Apple), we receive and store:

  • Email address — used as your primary identifier
  • First name and last name — used for display within the Service
  • OAuth provider identifier — used to link your identity provider account to your Subnet Calc Account

We do not store passwords. Authentication is handled entirely by your chosen identity provider.

If you sign in with different providers that share the same email address, we link them to a single Subnet Calc Account.

1.2 Project and Design Data

When you use the Service with a paid Subscription, we store:

  • Subnet design projects (IPv4 and IPv6 configurations, network hierarchy, address allocations)
  • Project metadata (name, creation date, last modified date, assigned region)
  • Collaboration data (team membership, role assignments, design locks)

1.3 Payment Data

Payment processing is handled entirely by Stripe. We do not store credit card numbers, bank account details, or other payment instruments on our systems.

We do store:

  • Stripe Customer ID and Subscription ID (to link your Account to your Stripe subscription)
  • Subscription status, tier, and billing period dates
  • Cancellation reason (if you provide one voluntarily when cancelling)

For details on how Stripe processes your payment data, see Stripe's Privacy Policy.

1.4 Session Data

When you sign in, we create a server-side session that includes:

  • A session identifier
  • Your authentication token (short-lived JWT, 15-minute expiry)
  • A refresh token (24-hour or 90-day expiry if you select “remember me”)

Session data is stored securely on our infrastructure and is not shared with third parties.

1.5 Communication Data

We store records of transactional emails sent to you (type, timestamp, delivery status) for operational and troubleshooting purposes.

1.6 Technical Data

We may collect:

  • IP address (via Azure Front Door request logs)
  • Browser type and version (via standard HTTP headers)
  • Request timestamps and response codes

This data is used for security monitoring, abuse prevention, and service reliability.

1.7 Advertising Referral and Conversion Data

When you arrive through a supported advertising link, we may receive a referral identifier such as a Google gclid, campaign parameters such as UTM source, medium, campaign, and term, and the landing path. We use this information to record whether the referral leads to an account signup or paid purchase.

The customer application initially holds this information in memory. If you sign up or sign in, we may link the referral record to your Account for up to 90 days. When a purchase is completed, we may retain derived campaign and conversion fields with the related financial record for reporting, audit, fraud prevention, dispute handling, or legal obligations. Raw click identifiers are deleted or irreversibly suppressed from the account-linked record after 90 days unless a documented exception applies. We do not use this information to make decisions about your access to the Service, and we do not store it in a marketing cookie or localStorage.

See our Legitimate Interests Assessment for the balancing assessment supporting this processing.


2. How We Use Your Data

PurposeLegal Basis (GDPR)Data Used
Provide and operate the ServicePerformance of contract (Art. 6(1)(b))Account, project, session data
Process payments and manage SubscriptionsPerformance of contract (Art. 6(1)(b))Account, payment data (via Stripe)
Send transactional emails (welcome, subscription events, team invites)Performance of contract (Art. 6(1)(b))Email address, name
Replicate data across regions for availabilityPerformance of contract (Art. 6(1)(b))Account, project data
Security monitoring and abuse preventionLegitimate interest (Art. 6(1)(f))Technical data, session data
Respond to support enquiriesLegitimate interest (Art. 6(1)(f))Account data, email address
Measure advertising referrals and attribute signups and purchasesLegitimate interest (Art. 6(1)(f))Advertising click identifier, campaign parameters, Account and purchase identifiers, transaction value and currency
Send marketing communications (if introduced)Consent (Art. 6(1)(a))Email address
Comply with legal obligationsLegal obligation (Art. 6(1)(c))As required by law

3. Data Sharing

We share your personal data only with the following categories of recipients, and only to the extent necessary:

3.1 Service Providers (Sub-processors)

ProviderPurposeData SharedLocation
Inflecto Systems LtdDevelopment, maintenance, and technical support of the ServiceAccount data, project data, session data, technical data (as needed for support and system administration)United Kingdom
Microsoft AzureCloud infrastructure (compute, storage, networking)All service data (encrypted at rest and in transit)North Europe, East US, Australia East
StripePayment processingEmail, name, Stripe Customer ID, payment instrumentsUnited States
Google Ads (Google LLC)Offline conversion measurement and advertising campaign optimisationAdvertising click identifier, purchase identifier, purchase timestamp, transaction value and currency; no email address or payment-card data. Google's role is determined under the applicable Google Ads service terms.United States / Global
SendGrid (Twilio)Transactional email deliveryEmail address, name, email contentEuropean Union
CookieBot (Usercentrics)Cookie consent managementCookie consent preferences, anonymised IPEuropean Union
Microsoft / Google / AppleOAuth authenticationOAuth tokens (during authentication flow only)Global

A complete list is maintained at /legal/sub-processors.

3.2 Legal Requirements

We may disclose personal data if required by law, regulation, legal process, or governmental request.

3.3 Business Transfers

In the event of a merger, acquisition, or sale of assets, personal data may be transferred to the successor entity. We will notify you of any such transfer.

We do not sell your personal data to third parties.


4. International Data Transfers

Your data may be processed in the following regions:

  • North Europe (Azure, primary region)
  • East US (Azure)
  • Australia East (Azure)
  • United States (Stripe)
  • European Union (SendGrid, CookieBot)
  • United Kingdom (Inflecto Systems Ltd)

For transfers outside the European Economic Area (EEA), we rely on:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Adequacy decisions where applicable (e.g., UK)
  • The data recipient's certification under relevant frameworks

For details on regional data storage, see our Data Residency Statement.


5. Data Retention

Data TypeRetention Period
Account dataDuration of Account + 12 months after last Subscription cancellation
Project dataDuration of active Subscription + 12 months read-only retention after cancellation
Session dataUntil session expiry (24 hours or 90 days for remember-me)
Payment metadataDuration of Account + as required by tax/accounting obligations (typically 7 years)
Account-linked advertising attributionUp to 90 days from capture, unless deleted or suppressed following a valid request
Purchase conversion attributionDerived campaign and conversion fields may be retained with the related payment and accounting record as required for reporting, audit, fraud prevention, dispute handling, and legal obligations. Raw click identifiers are deleted or irreversibly suppressed after 90 days unless a documented exception applies.
Transactional email records12 months
Technical/security logs90 days

After the applicable retention period, data is permanently deleted.


6. Your Rights

Under the GDPR and other applicable data protection laws, you have the following rights:

6.1 Right of Access

You may request a copy of the personal data we hold about you.

6.2 Right to Rectification

You may request correction of inaccurate personal data. Note: your name and email are sourced from your identity provider — to update them, change them with your provider and re-authenticate.

6.3 Right to Erasure (“Right to be Forgotten”)

You may request deletion of your Account and all associated personal data. We will comply unless we have a legal obligation to retain certain data (e.g., tax records).

6.4 Right to Data Portability

You may request your project data in a structured, commonly used, machine-readable format (JSON).

6.5 Right to Restrict Processing

You may request that we restrict processing of your personal data in certain circumstances (e.g., while we verify accuracy of data you have contested).

6.6 Right to Object

You may object to processing based on legitimate interests. We will cease processing unless we have compelling legitimate grounds.

6.7 Right to Withdraw Consent

Where processing is based on consent (e.g., marketing emails), you may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing before withdrawal.

6.8 Right to Lodge a Complaint

You have the right to lodge a complaint with your local data protection supervisory authority. In the UK, this is the Information Commissioner's Office (ICO) at ico.org.uk.

How to Exercise Your Rights

Submit a request via our support page. We will respond within 30 days (or the timeframe required by applicable law). We may need to verify your identity before processing your request.


7. Data Security

We implement appropriate technical and organisational measures to protect your personal data, including:

  • Encryption in transit — all connections use TLS
  • Encryption at rest — all stored data is encrypted using industry-standard AES-256 encryption
  • No password storage — OAuth-only authentication
  • Session security — HttpOnly, Secure, SameSite cookies; short-lived JWTs with server-side refresh token validation
  • Access controls — role-based team permissions; principle of least privilege for infrastructure access
  • Multi-region redundancy — data replicated across regions for availability and disaster recovery

For more information, see our Security Overview.


8. Children's Privacy

The Service is not directed at individuals under 18 years of age. We do not knowingly collect personal data from children. If you believe we have collected data from a child, contact us via our support page and we will delete it promptly.


9. Australian Privacy Principles

If you are located in Australia, you have additional rights under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). This includes:

  • The right to access your personal information (APP 12)
  • The right to request correction of inaccurate information (APP 13)
  • The right to make a complaint about our handling of your information (APP 1)

We will respond to complaints within 30 days. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

In the event of an eligible data breach, we will notify affected individuals and the OAIC as required under the Notifiable Data Breaches scheme.


10. US State Privacy Rights

If you are a resident of California or another US state with applicable privacy legislation:

  • You have the right to know what personal data we collect and how we use it
  • You have the right to request deletion of your personal data
  • You have the right to opt out of the sale of personal data — we do not sell personal data
  • We will not discriminate against you for exercising your privacy rights

11. Cookies

We use a limited number of cookies, primarily for authentication. Our full cookie disclosure is available in our Cookie Policy. Cookie consent is managed by CookieBot.


12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or through the Service at least 30 days before they take effect. The “Last Updated” date at the top of this page indicates when the policy was last revised.


13. Contact

For privacy-related enquiries:

Data Controller:
Subnet Calc Limited
Unit 34, 53 Mowbray Street, Sheffield, S3 8EN

Submit a request via our support page.

Technical Support & System Maintenance:
Inflecto Systems Ltd (acting as data processor on behalf of Subnet Calc Limited)

© 2026 Subnet Calc Limited. All rights reserved.

TermsPrivacyCookiesLegalUser GuideAppearance