Legal

Data Processing Addendum

Effective October 2026

This Data Processing Addendum (“DPA”) forms part of the Terms of Service between Sparrow Technology Ltd, company number 15676284 (“Decloak”, “we”), and the customer using the service (“Customer”). It applies to the extent Decloak processes personal data on the Customer's behalf and UK GDPR or EU GDPR applies. It applies automatically while you use the service; if you need a signed copy, email support@decloak.dev.

1. Roles

For personal data contained in the material the Customer submits or generates through the service (target URLs and the findings, evidence, reports, team data and integration settings produced from them), the Customer is the controller and Decloak is the processor. For account, billing, usage and security data about the Customer's users, Decloak is an independent controller, as described in our Privacy Policy.

2. Details of processing

  • Subject matter and purpose: providing the Decloak security scanning and reporting service.
  • Duration: the term of the Customer's account, plus the deletion period in section 8.
  • Data subjects: the Customer's users and team members, and any individuals whose data appears on pages the Customer scans.
  • Types of data: names and email addresses, scan target URLs, page content and evidence snippets captured during scans, and, for Enterprise authenticated scans, session cookies and storage supplied through the Session Capture extension.
  • Special category data: not intentionally processed. The Customer should avoid scanning pages that expose it.

3. Our obligations

Decloak will:

  • process the personal data only on the Customer's documented instructions (the Terms, this DPA, and the Customer's use of the service settings), unless the law requires otherwise, in which case we will tell the Customer first where permitted;
  • ensure that people authorised to process the data are bound by confidentiality;
  • implement the security measures in section 5;
  • assist the Customer, taking into account the nature of processing, with data subject requests and with its obligations on security, breach notification, and data protection impact assessments; and
  • tell the Customer if we believe an instruction infringes data protection law.

4. Subprocessors

The Customer gives general authorisation for Decloak to use the subprocessors listed at decloak.dev/subprocessors. We will update that page before a new subprocessor starts processing Customer personal data. The Customer may object on reasonable data protection grounds within 30 days by emailing support@decloak.dev; if we cannot resolve the objection, the Customer may cancel the affected service. We impose data protection obligations on each subprocessor that are no less protective than this DPA, and remain responsible for them.

5. Security measures

  • Encryption in transit (HTTPS/TLS) for all traffic to our API and between our services.
  • Database access controlled by authentication, team-based row-level security, and role-based permissions; service credentials held as server-side secrets.
  • Passwordless sign-in (magic link or passkey).
  • Captured authenticated sessions are single-use, expire after 15 minutes, are deleted after the scan that consumes them, and where retained for a scheduled scan are encrypted at rest.
  • Scanner network requests are restricted from reaching internal or private addresses, and AI Pentesting tools run in isolated, temporary sandboxes with outbound access scoped to the target.
  • Rate limiting and abuse controls on the public API.
  • Access to production systems limited to the people who need it.

6. Personal data breaches

We will notify the Customer without undue delay, and where feasible within 72 hours, after becoming aware of a personal data breach affecting Customer personal data, with the information we then have to help the Customer meet its own notification duties, and will keep it updated.

7. International transfers

Some subprocessors process data outside the UK and EEA, principally in the United States. Where UK or EU GDPR restricts such a transfer, we rely on an adequacy decision or the data privacy framework where available, or otherwise on the UK International Data Transfer Addendum and the EU Standard Contractual Clauses (module 3, processor to processor) with the subprocessor. Where the Customer is itself the exporter, the EU SCCs (module 2) and UK Addendum are incorporated by reference with Decloak as importer, completed by this DPA and the details in section 2.

8. Deletion and return

The Customer can delete scans and its account at any time, which removes the data from active storage; backups roll over within a short period afterwards. On request we will return or delete Customer personal data when the service ends, except where law requires us to keep it (for example billing records).

9. Audits

On reasonable notice, and no more than once a year unless a breach has occurred, we will provide information reasonably needed to show compliance with this DPA, and allow for audits by the Customer or its auditor. We may satisfy this first with written answers and documentation.

10. General

This DPA is subject to the liability terms and governing law of the Terms of Service. If it conflicts with the Terms on the processing of personal data, this DPA prevails. We may update it to reflect changes in law or the service; material changes will be reflected in the effective date above.