SubAvengers

Privacy Policy

Effective date: 2 July 2026

This Privacy Policy explains how SubAvengers, operated by Cyberheroes VOF (company number BE 0735.783.008), Gross Geraulaan 18, 8700 Tielt, Belgium (“we”, “us”, “our”), processes personal data in connection with the SubAvengers application and related services (the “Service”). We process personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and applicable Belgian law.

1. Controller and processor roles

For account, billing and usage data, Cyberheroes VOF acts as the data controller. For the content you enter into your workspace (network inventory such as IP addresses, hostnames, MAC addresses, assigned users and discovered hosts), you are the controller and we act as your processor, processing that data only on your instructions. Our processor obligations are set out in our Data Processing Agreement (DPA).

2. Data we process

  • Account data: name, email address, authentication identifiers (passwords are hashed by Supabase — we never see them in clear text).
  • Billing data: full name, billing address, company name (optional), VAT number (optional), and Polar customer/subscription identifiers. Payment card data is handled by Polar and never reaches our servers.
  • Workspace data: subnets, IP addresses, VLANs, segments and labels you store. This may contain personal data (e.g. hostnames, assigned users, MAC addresses) — for this data you are the controller.
  • Discovery data: where you deploy an agent, technical inventory of hosts on your own network (IP/MAC addresses, hostnames, OS, open ports, and device vendor/model/category). When you configure credentials for authenticated scanning (SSH, WinRM/SMB or LDAP), the agent may also collect richer host inventory such as the currently logged-in username, installed software and patch levels, and hardware details (serial number, CPU/RAM/disk). Agents are read-only and run on your infrastructure under your control; scanning credentials are stored only in the agent’s local config file and are never sent to us.
  • Technical data: device/browser information, IP address, and server logs kept for security, abuse prevention and diagnostics.

3. Purpose & legal basis (Art. 6 GDPR)

  • Providing and maintaining the Service — performance of a contract (Art. 6(1)(b));
  • Security, fraud/abuse prevention and diagnostics — legitimate interests (Art. 6(1)(f));
  • Billing and subscription management — contract performance and legal obligation (Art. 6(1)(b) and (c));
  • Support and service communications — legitimate interests, or consent where required (Art. 6(1)(a)/(f)).

4. Processors & sharing

We use a limited number of trusted sub-processors that act on our documented instructions under a data processing agreement. The current list, including purpose and location, is kept up to date on our Subprocessors page:

  • Supabase — authentication & database hosting (EU region);
  • Netlify — application hosting & delivery;
  • Polar — subscription billing and payment processing (merchant of record);
  • Resend — transactional email delivery;
  • Upstash — rate-limiting (abuse protection).

We do not sell personal data and we do not use it for advertising.

5. International transfers

Your core account and workspace data is hosted in the European Economic Area (EEA) on Supabase’s EU region. Some sub-processors are established outside the EEA (e.g. in the United States). Where personal data is transferred outside the EEA, we rely on appropriate safeguards under Chapter V GDPR — primarily the European Commission’s Standard Contractual Clauses (SCCs) — together with supplementary technical measures such as encryption in transit and at rest.

6. Retention

  • Account and workspace data: kept while your account is active and deleted within 30 days after you delete your account, unless a longer period is legally required.
  • Invoices and accounting records: kept for 7 years as required by Belgian tax and accounting law.
  • Backups: rolling backups are retained for approximately 30 days and then overwritten.
  • Security and diagnostic logs: kept only briefly (server/function logs typically up to 7 days).

7. Your rights

Under the GDPR you have the right to:

  • access, rectify or erase your personal data;
  • restrict or object to processing;
  • data portability;
  • withdraw consent at any time, where processing is based on consent.

You can exercise access and portability yourself at any time via Settings → Download my data, which produces a machine-readable (JSON) export of your personal data. You can erase your account and associated data via Settings → Delete account. For any other request, contact privacy@subavengers.com; we respond within one month (Art. 12(3) GDPR).

You may also lodge a complaint with the Belgian Data Protection Authority — Gegevensbeschermingsautoriteit / Autorité de protection des données, Drukpersstraat 35, 1000 Brussels — contact@apd-gba.be.

8. Security

We apply appropriate technical and organisational measures (Art. 32 GDPR), including encryption in transit and at rest, row-level access controls, hashed credentials, rate limiting and monitoring. No method is 100% secure; you are also responsible for keeping your credentials confidential.

9. Data breaches

We maintain an internal data-breach response procedure. Where a personal data breach is likely to result in a risk to your rights and freedoms, we notify the Belgian Data Protection Authority without undue delay and, where feasible, within 72 hours of becoming aware of it (Art. 33 GDPR). Where the breach is likely to result in a high risk, we also inform the affected users without undue delay (Art. 34 GDPR).

10. Cookies & analytics

We use only functional cookies necessary to operate the Service and do not run analytics or tracking cookies by default. See our Cookie Policy for details.

11. Changes

We may update this Privacy Policy from time to time. Material changes will be communicated via the Service or by email where appropriate, and the effective date and version above will be updated.

12. Contact

For privacy-related questions, contact privacy@subavengers.com.
Data controller: Cyberheroes VOF, company number BE 0735.783.008, Gross Geraulaan 18, 8700 Tielt, Belgium. We have not appointed a Data Protection Officer, as this is not legally required for our processing activities; privacy requests are handled at the address above.

    SubAvengers – Free Visual IPAM, Subnet Planner & Automatic IP Discovery