SubTru LLC Data Processing Addendum

Version: 1.0

Effective date: July 31, 2026

This Data Processing Addendum ("DPA") forms part of the agreement governing a customer's use of SubTru (the "Agreement") between SubTru LLC ("SubTru") and the customer accepting the Agreement ("Customer"). It applies where SubTru processes Customer Personal Data on Customer's behalf.

If there is a conflict concerning Customer Personal Data, the following order of precedence applies: applicable international-transfer terms, this DPA, and then the Agreement.

This DPA becomes binding when Customer accepts the Agreement.

1. Definitions

  • Applicable Data Protection Law means laws applicable to the processing of Customer Personal Data under the Agreement, including, where applicable, the EU GDPR, UK GDPR, Swiss Federal Act on Data Protection, and applicable United States state privacy laws.
  • Customer Personal Data means personal data, personal information, or equivalent regulated information contained in Customer Data that SubTru processes on Customer's behalf.
  • EU GDPR means Regulation (EU) 2016/679.
  • Process, Controller, Processor, Data Subject, Personal Data, and Supervisory Authority have the meanings given by Applicable Data Protection Law.
  • Security Incident means a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data processed by SubTru. It excludes unsuccessful attempts that do not compromise Customer Personal Data.
  • Subprocessor means a third party appointed by SubTru to process Customer Personal Data.
  • UK GDPR has the meaning given in the United Kingdom Data Protection Act 2018.

2. Roles and processing details

Customer is a Controller or Processor of Customer Personal Data. SubTru is the corresponding Processor or Subprocessor. Each party will comply with its obligations under Applicable Data Protection Law.

Schedule 1 describes the processing. Customer is responsible for its instructions, notices, legal bases, and permissions, and for determining whether the Service is appropriate for Customer's processing.

Customer will not instruct SubTru to process protected health information, payment-card numbers, government identification numbers, special-category personal data, or similarly sensitive personal information. Customer should use opaque subscriber identifiers and not encode names, email addresses, or other direct identifiers in those values.

3. Customer instructions

SubTru will process Customer Personal Data only:

  • to provide, secure, support, and maintain the Service;
  • according to Customer's use and configuration of the Service;
  • as documented in the Agreement and this DPA;
  • on other documented instructions that SubTru agrees to follow; or
  • as required by applicable law.

If law requires processing beyond Customer's instructions, SubTru will notify Customer before processing unless legally prohibited.

SubTru will inform Customer if, in SubTru's reasonable opinion, an instruction infringes Applicable Data Protection Law. SubTru may suspend the affected processing until the parties resolve the issue.

4. Confidentiality and security

SubTru will ensure that people authorized to process Customer Personal Data are bound by confidentiality obligations, receive access only as necessary for their responsibilities, and receive appropriate privacy and security instruction.

SubTru will maintain appropriate technical and organizational measures designed to protect Customer Personal Data, taking into account the state of the art, implementation costs, and the nature, scope, context, purposes, and risks of processing. Current measures are described in Schedule 2. SubTru may update them, provided the overall level of protection does not materially decrease during the Service term.

Customer is responsible for securely configuring and using the Service, protecting its credentials, and securing systems outside SubTru's control.

5. Security Incidents

SubTru will notify Customer without undue delay after becoming aware of a Security Incident affecting Customer Personal Data.

Where known, the notice will describe the nature of the incident; the affected data and data subjects; likely consequences; measures taken or proposed; and a contact for further information. SubTru may provide information in phases as it becomes available.

SubTru will take reasonable steps to contain, investigate, and mitigate a Security Incident and will reasonably assist Customer with legally required notifications. Customer is responsible for deciding whether to notify authorities or data subjects unless law assigns that responsibility to SubTru.

6. Subprocessors

Customer generally authorizes SubTru to use the Subprocessors listed at https://subtru.com/subprocessors.

SubTru will:

  • enter a written agreement requiring each Subprocessor to protect Customer Personal Data consistently with this DPA;
  • remain responsible for the Subprocessor's performance to the extent required by law; and
  • provide reasonable advance notice to Customer's account email or through the Service before a new Subprocessor begins processing Customer Personal Data.

Customer may object to a new Subprocessor on reasonable data-protection grounds by contacting [email protected] during the notice period. The parties will work in good faith on a reasonable solution. If none is available, Customer may terminate the affected Service and receive a prorated refund for prepaid, unused time.

7. Data-subject requests and compliance assistance

Taking into account the nature of processing, SubTru will provide reasonable assistance through available Service functionality or other reasonable means so Customer can respond to requests concerning Customer Personal Data.

If SubTru receives a request directly concerning Customer Personal Data, SubTru will notify Customer and direct the requester to Customer unless legally prohibited. SubTru will not independently respond except on Customer's documented instructions or as required by law.

Taking into account the nature of processing and information available to SubTru, SubTru will reasonably assist Customer with security-of-processing obligations, Security Incident notifications, data-protection impact assessments, and prior consultation with a Supervisory Authority.

8. Deletion and return

During the Service term, Customer may access or delete Customer Personal Data through available Service functionality or by contacting [email protected].

At Customer's choice, SubTru will return an available copy of Customer Personal Data or delete it within 90 days after termination, unless applicable law requires retention. Customer must request return before that period expires. Data in backups will be isolated from further processing and deleted according to the ordinary backup cycle described in Schedule 2.

9. Information and audits

SubTru will make available information reasonably necessary to demonstrate compliance with this DPA and will allow and contribute to audits required by Applicable Data Protection Law.

The parties will first use current reports, documentation, and questionnaires where reasonably sufficient. Unless required by a Supervisory Authority or reasonably necessary following a Security Incident, Customer may conduct no more than one further audit in any 12-month period. Any further audit must be conducted on reasonable notice, during normal business hours, subject to confidentiality and security requirements, and without unreasonably disrupting SubTru. Customer bears audit costs unless the audit identifies SubTru's material breach of this DPA.

10. International transfers

SubTru may process Customer Personal Data in the countries listed in Schedule 3. SubTru will use a lawful transfer mechanism for restricted transfers.

10.1 European Economic Area

Where required, the European Commission's 2021 Standard Contractual Clauses for international transfers ("EU SCCs") are incorporated by reference:

  • Module 2 applies when Customer is a Controller and SubTru is a Processor.
  • Module 3 applies when Customer is a Processor and SubTru is a Subprocessor.
  • The optional docking clause in Clause 7 applies.
  • Clause 9 uses Option 2 general authorization with the advance-notice period in Section 6.
  • The optional language in Clause 11 does not apply.
  • For Clause 17, Irish law governs. For Clause 18, the parties submit to the courts of Ireland.
  • Schedules 1–3 populate the corresponding EU SCC annexes.

10.2 United Kingdom

For restricted transfers governed by UK data-protection law, the UK International Data Transfer Addendum to the EU SCCs is incorporated and completed by Schedule 4.

10.3 Switzerland

Where Swiss data-protection law applies, references in the EU SCCs to the EU GDPR, Member State, and competent Supervisory Authority include the corresponding Swiss law, territory, and authority as legally required. Data subjects in Switzerland may enforce applicable rights under the EU SCCs.

10.4 Government requests

SubTru will evaluate government demands for Customer Personal Data and, where legally permitted, notify Customer and challenge demands SubTru reasonably believes are unlawful or disproportionate.

11. United States state privacy terms

Where SubTru processes Customer Personal Data subject to an applicable US state privacy law, SubTru will:

  • process it only for the limited purposes in the Agreement and Customer's documented instructions;
  • not sell or share it, or retain, use, or disclose it outside the parties' direct business relationship, except as permitted by law;
  • not combine it with personal information received from another person or collected through SubTru's own interactions with a consumer, except as permitted by law;
  • provide the level of protection required of a processor or service provider;
  • notify Customer if SubTru can no longer meet an applicable obligation; and
  • allow Customer to take reasonable steps to help ensure compliant processing.

SubTru certifies that it understands and will comply with these restrictions.

12. Liability and general terms

Each party's liability under this DPA is subject to the Agreement's exclusions and limitations, except where prohibited by Applicable Data Protection Law or the applicable transfer terms.

The Agreement's governing-law and dispute provisions apply except where Applicable Data Protection Law or transfer terms require otherwise. If part of this DPA is unenforceable, the remainder remains effective.

Schedule 1 — Processing details

Parties

Customer / data exporter

  • Name: the customer identified in the Agreement
  • Address: the address associated with Customer's account or order
  • Contact: the account owner or privacy contact designated by Customer
  • Role: Controller or Processor, as applicable
  • Acceptance: Customer's acceptance of the Agreement and this DPA

SubTru / data importer

  • Legal name: SubTru LLC
  • Address: 9018 Weldon Dr, Richmond, VA 23229-5648, USA
  • Contact: Privacy Contact, [email protected]
  • Role: Processor or Subprocessor, as applicable
  • Acceptance: SubTru's publication and incorporation of this DPA into the Agreement

Description of processing

  • Subject matter: Providing SubTru's hosted subscription backend.
  • Duration: The Service term plus the deletion and backup periods in this DPA.
  • Nature and purpose: Receiving, verifying, deduplicating, ordering, and normalizing supported payment and app-store subscription events; maintaining subscription state; returning access-check results; displaying operational event history; and supporting customer-directed provider integrations.
  • Data subjects: Customer's subscribers and end users, and Customer personnel whose information appears in Customer Data.
  • Personal data: Customer-defined subscriber identifiers; provider subscription, event, product, and price identifiers; subscription status, billing dates, and event timestamps; processing results and error information; and provider-integration information that constitutes personal data.
  • Sensitive data: Not permitted under the Agreement.
  • Processing operations: Collection, receipt, verification, organization, storage, retrieval, consultation, transmission to customer-directed providers, deletion, and other processing needed to provide the Service.
  • Frequency: Continuous when Customer sends events, performs access checks, uses the dashboard, or requests provider operations.
  • Retention: The Service term and up to 90 days afterward, subject to Customer's deletion or return instructions and the ordinary backup cycle.
  • Processor-to-processor transfers: The subject matter, nature, and duration are determined by Customer's agreement with the relevant Controller.

Competent Supervisory Authority

The Supervisory Authority determined under Clause 13 of the EU SCCs.

Schedule 2 — Technical and organizational measures

SubTru maintains the following measures:

  • Access control: Organization- and project-scoped role-based access, least-privilege production access, and periodic access review.
  • Authentication: Managed authentication for dashboard users and project-scoped API keys for service access.
  • Encryption: TLS for data in transit; database and infrastructure encryption at rest; and AES-256-GCM encryption for stored webhook secrets and provider credentials.
  • Secrets management: Production secrets are stored outside source control and are not written to product logs.
  • Tenant separation: Organization, project, environment, and credential scoping are enforced in application authorization and database queries.
  • Logging and monitoring: Structured logs, metrics, traces, health checks, and alerts, with restrictions against logging raw credentials and secrets.
  • Secure development: Source code is maintained in version control, and changes are subject to testing and deployment controls appropriate to the change.
  • Availability, backup, and recovery: Managed hosting and database recovery capabilities appropriate to the Service configuration, together with health checks and operational recovery procedures.
  • Incident response: Monitoring and operational procedures designed to investigate, contain, mitigate, recover from, and provide notice of confirmed Security Incidents as described in Section 5.
  • Personnel: Confidentiality obligations and access limited to personnel with a business need.
  • Vendor management: Data-protection terms and security review appropriate to each Subprocessor's role.
  • Deletion: Project and organization scoping supports deletion; backups, if any, expire according to the applicable provider's ordinary lifecycle.
  • Rights assistance: Account and project records can be retrieved, corrected, exported, or deleted through Service functionality or support.

Schedule 3 — Subprocessors and processing locations

The current Subprocessor list at https://subtru.com/subprocessors identifies each Subprocessor's service, data categories, processing locations, and transfer mechanism.

Schedule 4 — UK transfer terms

The parties incorporate the official UK International Data Transfer Addendum (the "UK Addendum"). Acceptance of this DPA has the same effect as signing the UK Addendum. It is completed as follows:

  • Table 1 — Parties: The parties, contacts, roles, and acceptance details are those in Schedule 1.
  • Table 2 — Selected SCCs, modules, and clauses: The Addendum EU SCCs are the EU SCCs incorporated through Section 10.1, including its selected modules and optional clauses.
  • Table 3 — Appendix information: Annex I is completed by Schedules 1 and 3, Annex II by Schedule 2, and Annex III by the Subprocessor list referenced in Schedule 3.
  • Table 4 — Ending the Addendum: Neither party may end the UK Addendum under Section 19 solely because the UK Information Commissioner issues a revised approved addendum.

Part 2 of the UK Addendum applies as published, except Section 16 does not apply.

Official EU SCC reference

The applicable official EU SCC modules are incorporated without conflicting modification.