Last updated August 2026
This Data Processing Addendum (“DPA”) forms part of the agreement between the customer (“Customer”) and SubincLabs, Inc. (“subinc”) and governs subinc’s processing of personal data on Customer’s behalf when Customer uses the Service. Where the customer is itself a processor for its end customers, subinc acts as a sub-processor. Capitalized terms not defined here have the meaning given in the applicable data protection laws (including the GDPR).
As between the parties, Customer is the controller (or a processor acting for its own controllers) and subinc is the processor of the personal data Customer submits to the Service. subinc processes that personal data only on Customer’s documented instructions, including as set out in the agreement and this DPA, unless required otherwise by law (in which case subinc will inform Customer unless legally prohibited).
Subject matter: provision of the Service. Duration: the term of the agreement plus any deletion period. Nature and purpose: hosting, processing, and transmitting billing and payment data to operate subscription billing, metering, invoicing, payments, and ledgering. Data subjects: Customer’s end customers and users. Categories of data: identifiers and contact details, account and transaction metadata, and billing records. Card numbers are tokenized by the payment gateway and are not stored by subinc.
Customer authorizes subinc to engage subprocessors to provide the Service, including hosting, email delivery, analytics, and payment gateways. subinc imposes data-protection obligations on each subprocessor no less protective than this DPA and remains responsible for their performance. The current list is published at /subprocessors, and subinc gives Customer prior notice of additions with a reasonable opportunity to object on legitimate grounds. Payment gateways and payout providers that Customer connects using its own credentials are engaged by Customer under Customer's own agreement with them; they are Customer's processors rather than subinc's subprocessors, and adding or removing one is not a change to that list.
subinc may generate aggregated and de-identified statistics from the operation of the Service — request volumes, error rates, latency, feature usage, and similar operational measures — and use them to secure, support, and improve the Service, to size capacity, and to inform its roadmap. Those statistics are produced so that they do not identify Customer, any data subject, or any individual transaction, and are not disclosed in a form that identifies Customer. subinc does not use the content of Customer's personal data to train machine-learning models or to build profiles of data subjects, and does not sell personal data.
The Service performs automated processing on Customer's instructions, including dunning retries, spend limits, automatic wallet top-ups, fraud and risk rules, sanctions screening, and reserve or payout holds. Customer configures those rules and remains the controller of the decisions they produce, including any obligation to provide human review, an explanation, or a route of appeal to a data subject. subinc makes available the record of what each automated rule did and the reason recorded for it, so that Customer can meet those obligations.
Where processing involves transferring personal data across borders, subinc relies on a lawful transfer mechanism, such as the European Commission’s Standard Contractual Clauses, and applies supplementary measures where required.
subinc maintains technical and organizational measures appropriate to the risk, including: tenant isolation enforced at the database (row-level security); encryption of data in transit; role-based access control and least-privilege access; idempotency on state-changing operations; a hash-chained, tamper-evident audit log; a hard test/live boundary that batch jobs respect; and PCI scope minimization (card data tokenized by the gateway, never stored by subinc).
subinc ensures that personnel authorized to process personal data are bound by appropriate confidentiality obligations and are trained on their responsibilities.
Taking into account the nature of the processing, subinc will provide reasonable assistance, including appropriate technical and organizational measures, to help Customer respond to requests from data subjects to exercise their rights within statutory timelines.
subinc will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer’s data, and will provide information reasonably available to help Customer meet its own notification and record-keeping obligations.
On termination or expiry of the agreement, subinc will, at Customer’s choice, delete or return the personal data it processes on Customer’s behalf, and delete existing copies, unless retention is required by law.
subinc will make available information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, subject to reasonable confidentiality, scheduling, and scope conditions, including reliance on third-party reports where available.
Each party’s liability under this DPA is subject to the limitations and exclusions of liability set out in the agreement.
DPA questions and signed copies: support@subinclabs.com, or SubincLabs, Inc., 1111b South Governors Ave, STE 33435, Dover, DE 19904, USA.
Questions about this document: support@subinclabs.com