SubAvengers

Data Processing Agreement (DPA)

Effective date: 2 July 2026

This Data Processing Agreement (“DPA”) is entered into pursuant to Article 28 of the General Data Protection Regulation (EU) 2016/679 (“GDPR”). It forms an integral part of, and is governed by, the General Terms & Conditions (the “Agreement”) between you (the “Controller”) and Cyberheroes VOF, company number BE 0735.783.008, Gross Geraulaan 18, 8700 Tielt, Belgium (the “Processor”). It is accepted when you accept the Agreement. Enterprise customers may request a countersigned copy via privacy@subavengers.com.

1. Roles and scope

This DPA applies only where the Processor processes personal data on behalf of the Controller in the course of providing the Service — namely the content the Controller stores in its workspace (network inventory such as IP addresses, hostnames, MAC addresses, assigned users and discovered hosts). For account, billing and usage data, the Processor acts as an independent controller under its Privacy Policy, and this DPA does not apply.

2. Subject matter, nature, purpose and duration

  • Subject matter & nature: storage, organisation, display and processing of the Controller’s network-inventory data as necessary to provide the Service.
  • Purpose: providing IP address management, subnet/VLAN visualisation and optional agent-based discovery to the Controller.
  • Duration: for the term of the Agreement, plus the deletion period set out in clause 9.
  • Categories of data subjects: individuals whose data the Controller chooses to store (e.g. employees, contractors or users identifiable via hostnames, assigned-user labels or device identifiers).
  • Types of personal data: as determined by the Controller — typically IP/MAC addresses, hostnames, device/OS details and free-text labels, and (where authenticated agent scanning is enabled) logged-in usernames and installed-software inventory. The Controller must not store special categories of data (Art. 9 GDPR) in the Service.

3. Processor obligations

  • Process personal data only on the Controller’s documented instructions (including as configured through the Service), unless required by EU or Member State law, in which case the Processor informs the Controller unless legally prohibited (Art. 28(3)(a)).
  • Ensure persons authorised to process the data are bound by confidentiality (Art. 28(3)(b)).
  • Implement appropriate technical and organisational security measures (clause 4; Art. 32).
  • Respect the conditions for engaging sub-processors (clause 5).
  • Assist the Controller, by appropriate technical and organisational measures, in responding to data-subject requests under Chapter III GDPR (clause 6).
  • Assist the Controller in ensuring compliance with Art. 32–36 (security, breach notification, DPIAs and prior consultation), taking into account the nature of processing and information available.
  • At the Controller’s choice, delete or return all personal data at the end of the provision of services (clause 9).
  • Make available all information necessary to demonstrate compliance and allow for and contribute to audits (clause 8).

4. Security (Art. 32)

The Processor implements appropriate technical and organisational measures, including: encryption of data in transit and at rest; row-level access controls and authentication; hashed credentials; rate limiting and monitoring; least-privilege access; and regular review of measures. Details are described in our Privacy Policy.

5. Sub-processors

The Controller provides a general authorisation for the Processor to engage the sub-processors listed on our Sub-processors page. The Processor imposes data-protection obligations on each sub-processor no less protective than those in this DPA and remains fully liable for their performance. The Processor will update that page before adding or replacing a sub-processor; the Controller may object on reasonable data-protection grounds within 30 days, in which case the parties will work in good faith to resolve the objection (which may include termination of the affected part of the Service).

6. Data-subject requests

Taking into account the nature of the processing, the Processor assists the Controller through appropriate technical and organisational measures — including self-service export and deletion in the Service (Settings → Download my data / Delete account) — to fulfil the Controller’s obligation to respond to data-subject requests. If the Processor receives a request directly from a data subject, it will, where lawful, refer the request to the Controller.

7. Personal data breaches

The Processor notifies the Controller without undue delay after becoming aware of a personal data breach affecting the Controller’s personal data, and provides reasonable information to help the Controller meet its own obligations under Art. 33–34 GDPR.

8. Audits

The Processor makes available information necessary to demonstrate compliance with Art. 28 and allows for and contributes to audits, including inspections, conducted by the Controller or an auditor it mandates. Audits take place on reasonable prior notice, no more than once per year (unless required by a supervisory authority or following a breach), during business hours, and subject to confidentiality. The Processor may satisfy audit requests by providing relevant documentation and sub-processor attestations.

9. Deletion and return

On termination of the Agreement, or on the Controller’s request, the Processor deletes the Controller’s personal data within 30 days, unless EU or Member State law requires storage. The Controller can export its data at any time via Settings → Download my data.

10. International transfers

Core data is hosted in the EEA. Where the Processor transfers personal data to a sub-processor outside the EEA, it relies on appropriate safeguards under Chapter V GDPR, primarily the European Commission’s Standard Contractual Clauses (SCCs), as described on the Sub-processors page.

11. Liability and governing law

Each party’s liability under this DPA is subject to the limitations and exclusions of liability set out in the Agreement. This DPA is governed by Belgian law, and the courts of Kortrijk (West Flanders) have exclusive jurisdiction. In case of conflict between this DPA and the Agreement on data-protection matters, this DPA prevails.

12. Contact

Data-protection contact: privacy@subavengers.com — Cyberheroes VOF, BE 0735.783.008, Gross Geraulaan 18, 8700 Tielt, Belgium.

    SubAvengers – Free Visual IPAM, Subnet Planner & Automatic IP Discovery