Data processing agreement

How SquidGrid processes personal data on your behalf when you use the service — and the limits on that processing that are built into the product, not merely promised here.

Last updated 31 August 2026

This agreement is written to sit alongside our Terms and Privacy policy, not to contradict them.

Where a business customer's procurement needs a formal data processing agreement, this is it. The commitments here are the same ones made in our terms of service and privacy policy: we do not read your traffic and we cannot, we do not measure your internal network, and we never task your probe with our own work. This document puts those commitments into the language a controller/processor arrangement uses.

1. Parties and scope

This data processing agreement ("DPA") forms part of the agreement between you (or the organisation you represent), the "Customer", and SquidGrid, operating from Texas, United States, the "Processor". It applies whenever SquidGrid processes personal data on the Customer's behalf in providing the service. It takes effect when the Customer accepts our terms of service and lasts as long as SquidGrid processes personal data for the Customer.

Where the terms differ, this DPA governs the processing of personal data; our terms of service govern everything else.

2. Roles

For the Customer's account data and the measurements produced by the probes the Customer configures, the Customer is the controller and SquidGrid is the processor. SquidGrid processes that data only to provide the service and only on the Customer's documented instructions, which are given by the Customer's use of the service and its settings, and by this DPA.

SquidGrid is a separate, independent controller for two things that are not covered by this DPA: the measurements made by SquidGrid's own probe fleet, which are our data and not the Customer's; and our website server logs, which are governed by our privacy policy.

If SquidGrid receives an instruction that it believes infringes data protection law, it will tell the Customer without undue delay.

3. Subject matter, duration and purpose

The subject matter is the provision of network path measurement and reporting. The duration is the term of the Customer's account. The purpose is limited to:

SquidGrid does not process the data for any other purpose, and does not sell it or share it for advertising.

4. Categories of data and data subjects

CategoryWhat it is
Account dataThe email address, organisation name, and the names of the people who belong to it. Sign-in is handled by a third-party authentication provider; SquidGrid never sees or stores a password.
Measurement metadataFor each destination the Customer chooses: round-trip time, packet loss, and the sequence of router addresses the Customer's packets crossed to reach it, together with which of the Customer's probes made the measurement, the version it runs, and the city the Customer told it that it lives in.

The data subjects are the Customer's authorised users. Router addresses along a measured path belong to third-party network infrastructure and may incidentally constitute personal data.

What the probe cannot process, said plainly.

The probe measures its own packets and the ICMP responses they provoke. It has no capability to capture, inspect or store the Customer's network traffic. SquidGrid does not read traffic payloads, and it cannot — this is a property of how the probe is built, verifiable in the public image at squidgrid/probe, not a policy we ask you to take on trust. No content of the Customer's communications is ever within the scope of this processing.

5. Processor obligations

SquidGrid will:

6. Customer measurement data stays the Customer's

Customer Measurement Data is processed solely to provide the Services to the Customer. SquidGrid does not publish Customer Measurement Data or incorporate it into shared, public, or cross-customer views or datasets; SquidGrid’s shared and public network-health information derives exclusively from measurement infrastructure SquidGrid owns and operates. Processing incidental to service delivery — ingestion, storage, backup, and integrity verification — remains within this purpose.

7. Security

SquidGrid maintains technical and organisational measures appropriate to the risk, including:

8. Sub-processors

The Customer authorises SquidGrid to use the sub-processors below. Each processes personal data only on SquidGrid's behalf and for no other purpose, and each is bound by data protection terms no less protective than this DPA.

CategoryWhat for
AuthenticationSign-in and session management
HostingRunning the service, its database, and our measurement probes
Network ingressReceiving probe data
EmailAccount and support email

A current list of our named sub-processors is available to the Customer on request, and SquidGrid notifies the Customer before adding or replacing one so the Customer may object.

Payments, where taken, are handled by Paddle, which acts as the merchant of record — it is the seller on the transaction and is an independent controller of the payment data it collects, not a sub-processor under this DPA. SquidGrid does not receive or store the Customer's card details.

SquidGrid will tell account holders before adding or replacing a sub-processor that handles personal data, giving the Customer the chance to object. If the Customer reasonably objects on data protection grounds and we cannot resolve it, the Customer may terminate the affected part of the service.

9. Assisting with data subject rights

Taking into account the nature of the processing, SquidGrid will assist the Customer by appropriate measures in responding to requests from data subjects to exercise their rights — access, correction, deletion, restriction, objection and portability. Because a Customer's authorised users are identified by account, much of this the Customer can do directly; where our help is needed, write to [email protected] and we will respond promptly.

10. Assisting with security, breaches and assessments

SquidGrid will assist the Customer in meeting its own obligations for security, breach notification, data protection impact assessments and prior consultation, taking into account the nature of the processing and the information available to us.

Breach notification. If SquidGrid becomes aware of a personal data breach affecting the Customer's data, it will notify the Customer without undue delay, and in any event within 72 hours of becoming aware, at the account's security contact. The notice will describe what we know: the nature of the breach, the categories and rough number of records involved, the likely consequences, and the measures taken or proposed. We will keep the Customer updated as we learn more.

11. Retention

SquidGrid retains personal data only as long as needed for the purposes above. The schedule is the same one published in our privacy policy:

DataRetained
Latency and loss samples30 days at full resolution
Hourly summaries400 days
Incident evidence180 days
Path and hop records180 days
Account and organisation recordsUntil the account is closed

Path and hop records are kept for 180 days, so a route today can be compared against the same route months back. The Customer may ask us to delete them sooner and we will.

12. Return and deletion on termination

On the end of the service, and at the Customer's choice, SquidGrid will delete or return the Customer's personal data, and delete existing copies unless law requires us to keep them. As stated in our terms, on account closure we delete the Customer's measurement data; tell us first if an export is wanted, and we will provide one in a commonly used format.

13. Audit

SquidGrid will make available to the Customer the information reasonably needed to demonstrate compliance with this DPA, and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates, on reasonable notice and no more than once a year unless a breach or a regulator requires otherwise. Much of what an audit would examine is already open: the probe image is public and rebuildable from source, so the central claim — that it cannot read your traffic — is one you can verify yourself rather than take from a report.

14. International transfers

SquidGrid's service and database run in the European Union; its own probes, and some sub-processors, operate in several countries. Measurement data therefore crosses borders by design — measuring international paths is the service. Where a transfer of personal data is subject to the GDPR or UK data protection law, it is made under an adequacy decision or the applicable Standard Contractual Clauses, which are incorporated into this DPA by reference and prevail over it to the extent of any conflict on transfers.

15. Liability

Each party's liability under this DPA is subject to the limitations and exclusions of liability in our terms of service.

16. Contact

For any question about this agreement, or to exercise a right under it, write to [email protected]. We answer privacy requests from that address and nowhere else.