SUBSURE · LEGAL & TRUST

Data Processing Agreement

Last updated: 11 October 2026 · Version 1.0

SUBSURE

DATA PROCESSING

AGREEMENT

UK GDPR Article 28 processor terms for the SUBSURE subscription compliance and monitoring service

ELECTRONIC ACCEPTANCE
This DPA is entered into when an authorised Customer representative accepts it through SUBSURE’s account flow. SUBSURE records the accepted version, date and time, account, user and acceptance action, and makes an acceptance copy available in the Customer’s Control Room.

Customer data protection terms for the SUBSURE service

ProcessorController
Valico Services Ltd trading as SUBSURE
Company number 14313622
167–169 Great Portland Street, 5th Floor
London, W1W 5PF, United Kingdom
The merchant legal entity or sole trader named in the Customer’s SUBSURE account and acceptance record (“Customer”).

Version 1.0 | 11 October 2026 | Effective for each Customer on electronic acceptance

1. Parties, status and precedence

1.1 This Data Processing Agreement (“DPA”) is between Valico Services Ltd trading as SUBSURE, company number 14313622, of 167–169 Great Portland Street, 5th Floor, London, W1W 5PF, United Kingdom (“Processor” or “SUBSURE”), and the merchant legal entity or sole trader identified in the Customer’s SUBSURE account and acceptance record (“Controller” or “Customer”). Each is a “Party” and together the “Parties”.

1.2 This DPA applies whenever SUBSURE processes Customer Personal Data on the Customer’s behalf in providing the SUBSURE service. The Customer is the Controller and SUBSURE is the Processor for that processing. “Customer Personal Data” means personal data processed by SUBSURE on the Customer’s behalf under this DPA. “Personal Data Breach” has the meaning given in the UK GDPR. “Data Protection Laws” means the UK GDPR, the Data Protection Act 2018 and other applicable UK laws relating to processing of personal data, as amended or replaced.

1.3 This DPA supplements SUBSURE’s Terms of Service accepted by the Customer. If this DPA conflicts with the Terms of Service on processing of Customer Personal Data, this DPA prevails to the extent of the conflict. The Terms of Service continue to govern other matters, including fees and service availability.

2. Processing particulars and roles

2.1 The processing details in Schedule 1 form part of this DPA. The Customer determines the purposes and essential means of processing and is responsible for its instructions, lawful basis, transparency, accuracy of supplied data and use of the service.

2.2 SUBSURE may process account, billing, support, security and website-visitor data as an independent controller where it determines purposes for its own service administration, security, legal compliance or business operations. That independent-controller processing is governed by SUBSURE’s privacy notice and is outside this DPA.

2.3 Stripe and GoCardless are billing providers selected and connected by the Customer. They provide their own services under their own terms and privacy information. This DPA does not make Stripe or GoCardless SUBSURE subprocessors for data they process independently as payment or billing providers. SUBSURE’s handling of provider data returned to it for the monitoring service is covered by this DPA where it is on the Customer’s behalf.

3. Customer instructions and permitted use

3.1 The Customer instructs SUBSURE to process Customer Personal Data only to provide, secure, support and improve the configured SUBSURE service, and in accordance with this DPA, the service terms, the Customer’s configuration choices and other documented instructions from the Customer. The agreement and those settings are the Customer’s initial documented instructions.

3.2 SUBSURE will inform the Customer if, in SUBSURE’s reasonable opinion, an instruction infringes Data Protection Laws. SUBSURE is not required to follow an instruction that it reasonably believes is unlawful, unless the Customer confirms or changes it after being informed.

3.3 SUBSURE will not sell Customer Personal Data, use it for targeted advertising, or use it for a purpose unrelated to the services as Processor. The Customer must not submit special category data, criminal offence data, payment card authentication data, or data about children unless the service is expressly configured for it and the Parties have agreed appropriate additional safeguards in writing.

4. SUBSURE obligations

4.1 SUBSURE will:

process Customer Personal Data only on documented instructions, including instructions concerning international transfers, unless applicable law requires otherwise; where legally permitted, inform the Customer of that legal requirement before processing;

ensure persons authorised to process Customer Personal Data are bound by confidentiality obligations;

implement and maintain the technical and organisational measures in Schedule 2, appropriate to the risks and nature of the processing;

provide reasonable assistance, taking into account the nature of processing and information available to SUBSURE, with data subject requests, security obligations, personal data breach obligations, DPIAs and prior consultation with the ICO;

notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and provide available information reasonably needed for the Customer’s response;

make available information reasonably necessary to demonstrate compliance with this DPA and permit audits as described in clause 8; and

at the Customer’s choice, return or delete Customer Personal Data at the end of the services, subject to clause 9 and applicable law.

4.2 The assistance described in clause 4.1(d) is provided at the Customer’s reasonable cost where the request is unusually burdensome or outside SUBSURE’s standard service, except to the extent the request is required because of SUBSURE’s breach of this DPA or applicable law.

5. Customer obligations

5.1 The Customer will:

ensure it has a lawful basis and has provided required privacy information to data subjects for the processing and disclosures involved;

ensure its instructions and configuration comply with Data Protection Laws and do not require SUBSURE to collect or use data beyond what is necessary for the service;

configure connected billing accounts and website monitoring accurately, ensure it is authorised to connect them, and avoid submitting data it is not entitled to provide;

promptly notify SUBSURE of data subject requests, regulator inquiries or suspected issues relevant to SUBSURE’s processing; and

use available account controls to manage authorised users, exports and deletion, and keep credentials secure.

6. Subprocessors and international transfers

6.1 The Customer gives SUBSURE general written authorisation to use the subprocessors listed in Schedule 3 and other subprocessors appointed in accordance with this clause. SUBSURE will impose written data protection obligations on each subprocessor that are materially protective of Customer Personal Data and will remain responsible for their performance to the extent required by Data Protection Laws.

6.2 SUBSURE will notify the Customer at least 30 days before a new or replacement subprocessor first processes Customer Personal Data, by email to the account contact or through the service. The Customer may object in writing within that period on reasonable data protection grounds. The Parties will work in good faith to resolve the objection. If they cannot, the Customer may stop using the affected feature or terminate the affected service before the change takes effect, without an early termination charge for the affected service, and SUBSURE will refund any prepaid unused fees for it.

6.3 SUBSURE will not make a restricted transfer of Customer Personal Data from the UK unless an applicable adequacy regulation applies or an appropriate safeguard is in force. Where required, SUBSURE will put in place the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses with the relevant recipient and complete the applicable UK data protection test (also referred to as a transfer risk assessment) and any supplementary measures before the transfer. A copy of the applicable transfer terms will be made available to the Customer on request, subject to lawful redactions.

7. Personal Data Breaches and data subject rights

7.1 SUBSURE will notify the Customer without undue delay and, where practicable, within 48 hours after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notice will describe the nature of the breach, likely consequences, measures taken or proposed, and a contact point for follow-up, as information becomes available. SUBSURE may provide information in phases if a complete notice is not immediately available. The Parties will cooperate reasonably in investigation, mitigation and required notifications. SUBSURE’s notice does not itself constitute an admission of fault.

7.2 SUBSURE will not respond directly to a data subject request about Customer Personal Data except on the Customer’s documented instructions or where required by law. SUBSURE will promptly refer such requests to the Customer where legally permitted and provide reasonable assistance to enable the Customer to respond.

8. Compliance information and audits

8.1 On reasonable request, SUBSURE will provide information reasonably necessary to demonstrate compliance with this DPA, including relevant policies, summaries of security measures and available third-party assurance materials. The Customer will first use information already supplied or publicly available.

8.2 If that information is insufficient, the Customer or an independent auditor bound by confidentiality may audit the processing relevant to this DPA, no more than once in any 12-month period, on at least 30 days’ written notice, during normal business hours and in a manner that minimises disruption. Shorter notice may be used where required by a regulator or following a suspected material breach. Audits must not expose another customer’s data or compromise security. Each Party bears its own costs unless the audit identifies a material breach by SUBSURE, in which case SUBSURE will bear reasonable audit costs.

9. Return, deletion and retention

9.1 During the service, the Customer may request access to or an export of Customer Personal Data by contacting support@subsure.io. On termination or expiry, SUBSURE will, at the Customer’s choice made within 30 days, return the Customer Personal Data in a commonly used electronic format or delete it within 30 days after receiving that choice. If the Customer does not make a choice, SUBSURE will delete it within 60 days after termination or expiry. This does not apply to personal data that applicable law requires SUBSURE to retain, which will be isolated and processed only for that legal purpose.

9.2 Customer Personal Data held in routine disaster-recovery backups will be protected under this DPA, will not be restored except for disaster recovery, and will be overwritten or deleted within 90 days. Data retained by law will be isolated and protected and processed only for that legal purpose.

10. Term, liability and general

10.1 This DPA takes effect for a Customer when an authorised representative accepts the DPA through the SUBSURE account flow, including by selecting the required acceptance control after being shown links to the DPA and Terms of Service. The representative confirms authority to bind the Customer. SUBSURE’s electronic record of the acceptance, including the accepted document versions, account, user identity, date and time, forms part of this DPA and is available to the Customer in its Control Room. This DPA continues while SUBSURE processes Customer Personal Data on the Customer’s behalf and thereafter only as needed to complete return or deletion under clause 9.

10.2 Each Party’s liability under this DPA is subject to the exclusions and limitations in the Terms of Service, except to the extent liability cannot lawfully be limited. Nothing in this DPA excludes or limits either Party’s direct obligations or liabilities under Data Protection Laws.

10.3 Notices under this DPA may be sent to the account email addresses or formal notice addresses specified in the service terms. Amendments must be in writing or recorded through a documented electronic process accepted by both Parties. If any provision is unenforceable, the remaining provisions continue in effect.

10.4 This DPA and any non-contractual obligations arising from it are governed by the laws of England and Wales. The courts of England and Wales have exclusive jurisdiction, subject to mandatory rights that cannot lawfully be restricted.

Schedule 1 — Processing particulars

ItemParticulars
Subject matterProcessing necessary to provide SUBSURE subscription compliance and monitoring services for the Customer.
DurationFrom the effective date of this DPA until the Customer’s SUBSURE service ends and Customer Personal Data is returned or deleted under clause 9.
Nature and purposeReceive and synchronise subscription and recurring billing data; monitor configured subscription terms and customer journeys; analyse uploaded contract documents; create compliance checks, findings, alerts, evidence records and reports; provide support and secure the service.
Data subjectsThe Customer’s subscribers and customers; the Customer’s staff and administrators; and authorised business contacts whose details are included in the service.
Personal data typesNames and contact details where present; merchant, customer, subscriber, subscription, product and price identifiers; subscription status, amount, currency, billing cadence, renewal and cancellation information; configured website URLs and journey check results; uploaded contract documents and extracted text; evidence, audit and system records associated with those data.
Special categories / criminal dataNot intended. The Customer must not submit such data unless the Parties agree in writing to the purpose, lawful condition, additional safeguards and any necessary service changes.
Processing operationsCollection, recording, organisation, storage, retrieval, consultation, analysis, use to generate findings/evidence, disclosure to authorised Customer users, export, restriction, deletion and backup.
Customer rights and instructionsThe Customer may configure connected providers, monitored URLs, authorised users and service features, and may request access, correction, restriction, export or deletion through available controls or support.

Schedule 2 — Technical and organisational measures

SUBSURE will maintain the following technical and organisational measures while processing Customer Personal Data. They are proportionate to the service’s nature, scope, context and purposes and the risks to individuals. SUBSURE will review them periodically and will not materially reduce the protection they provide during the term.

Control areaCurrent measure / commitment
Access controlAccess to Customer data is restricted to authenticated users and scoped to the Customer account or organisation. Privileged access is limited to authorised personnel and reviewed periodically.
AuthenticationThe application uses Supabase authentication. Edge Function requests validate Supabase JWTs, including ES256 sessions where applicable. Secrets and service credentials are kept server-side.
Encryption in transitApplication and service communications use HTTPS/TLS in transit.
Credential protectionConnected provider OAuth credentials are encrypted using AES-GCM before storage. Stripe permissions are read-only for Customer Portal, Prices, Products and Subscriptions. GoCardless uses its configured authorisation scopes.
StorageUploaded contract files are held in a private storage bucket. Access is subject to authenticated account and organisation checks and storage access policies. Uploads are restricted by file type and size.
Logging and evidenceThe service records monitoring activity and evidence results for the Customer to review. Operational logs are limited to information needed to operate, secure and troubleshoot the service; payment card credentials are not collected by SUBSURE.
ResilienceSUBSURE uses the backup and recovery capabilities of its hosting and database providers and maintains procedures to restore service following an infrastructure incident. Backup retention and deletion are governed by clause 9.
Incident responseSUBSURE will maintain a process to assess, contain, investigate and document suspected personal data breaches and to notify affected Customers without undue delay.
Data minimisationThe service is intended to ingest only billing and journey information needed for compliance monitoring. Payment card numbers and authentication secrets are not required for the service.
AssuranceSUBSURE does not claim an independent security certification.

Schedule 3 — Authorised subprocessors and service providers

The Customer authorises the providers below as subprocessors for the stated purposes. Their current subprocessor disclosures and data transfer terms are incorporated by reference for the locations and onward processing they describe. SUBSURE will provide a copy or link on request and will give change notices under clause 6.2. The Customer’s connected billing providers are not appointed by SUBSURE as subprocessors for their independent merchant services.

ProviderRole for SUBSURE serviceProcessing and transfer information
Supabase, Inc. and its affiliatesDatabase, authentication, private file storage and Edge Functions.Primary project region: London, United Kingdom. Supabase may use affiliates and subprocessors in other locations, including the United States and Singapore, and may permit support or operational access from outside the UK. Current list and DPA: supabase.com/legal/customer-resources/subprocessor-list and supabase.com/legal/customer-resources/data-processing-addendum.
Vercel, Inc. and its affiliatesWebsite hosting, deployment and application runtime.The application runtime is configured for London; Vercel and its subprocessors may process service data in the United States and other locations. Current DPA and subprocessor disclosures: vercel.com/legal/dpa and security.vercel.com.
Plus Five Five, Inc. (Resend)Delivery of account and service email to merchant users when enabled. Customer Notices to merchants’ end customers remain disabled.Resend’s published subprocessor list currently identifies providers in the United States. Current DPA and list: resend.com/legal/dpa and resend.com/legal/subprocessors.
Microsoft 365 / MicrosoftSUBSURE support mailbox and business correspondence.Mailbox data location and support access depend on SUBSURE’s Microsoft 365 tenant and Microsoft’s service configuration. Microsoft’s Data Protection Addendum and current subprocessor disclosures apply.
jsDelivr / Prospect One, s.r.o.Public browser library delivery.The CDN receives technical connection data such as IP address, browser and request details. No merchant billing or subscriber data is intentionally sent in CDN requests. Published DPA: jsdelivr.com/documents/data-processing-agreement.pdf.
Stripe and GoCardlessBilling services selected and connected by the Customer; not appointed by SUBSURE as subprocessors for their independent merchant services.The Customer’s agreements with these providers govern their own processing. SUBSURE processes billing data returned to it for monitoring under this DPA.

Electronic acceptance record

The Customer’s authorised representative accepts this DPA and the SUBSURE Terms of Service through the acceptance control presented in the account flow. The acceptance control is not pre-ticked. The representative is shown the documents and can open or download them before accepting. The acceptance record retained by SUBSURE identifies the Customer, account, accepting user, the accepted version and content hash of each document, and the date and time of acceptance. SUBSURE makes the record and accepted documents available from Control Room → Agreements. The acceptance record is evidence of the Customer’s electronic signature and agreement.

For questions or data protection requests, contact support@subsure.io or write to Valico Services Ltd t/a SUBSURE, 167–169 Great Portland Street, 5th Floor, London, W1W 5PF, United Kingdom.