Legal
Effective October 2026
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between Sparrow Technology Ltd, company number 15676284 (“Decloak”, “we”), and the customer using the service (“Customer”). It applies to the extent Decloak processes personal data on the Customer's behalf and UK GDPR or EU GDPR applies. It applies automatically while you use the service; if you need a signed copy, email support@decloak.dev.
For personal data contained in the material the Customer submits or generates through the service (target URLs and the findings, evidence, reports, team data and integration settings produced from them), the Customer is the controller and Decloak is the processor. For account, billing, usage and security data about the Customer's users, Decloak is an independent controller, as described in our Privacy Policy.
Decloak will:
The Customer gives general authorisation for Decloak to use the subprocessors listed at decloak.dev/subprocessors. We will update that page before a new subprocessor starts processing Customer personal data. The Customer may object on reasonable data protection grounds within 30 days by emailing support@decloak.dev; if we cannot resolve the objection, the Customer may cancel the affected service. We impose data protection obligations on each subprocessor that are no less protective than this DPA, and remain responsible for them.
We will notify the Customer without undue delay, and where feasible within 72 hours, after becoming aware of a personal data breach affecting Customer personal data, with the information we then have to help the Customer meet its own notification duties, and will keep it updated.
Some subprocessors process data outside the UK and EEA, principally in the United States. Where UK or EU GDPR restricts such a transfer, we rely on an adequacy decision or the data privacy framework where available, or otherwise on the UK International Data Transfer Addendum and the EU Standard Contractual Clauses (module 3, processor to processor) with the subprocessor. Where the Customer is itself the exporter, the EU SCCs (module 2) and UK Addendum are incorporated by reference with Decloak as importer, completed by this DPA and the details in section 2.
The Customer can delete scans and its account at any time, which removes the data from active storage; backups roll over within a short period afterwards. On request we will return or delete Customer personal data when the service ends, except where law requires us to keep it (for example billing records).
On reasonable notice, and no more than once a year unless a breach has occurred, we will provide information reasonably needed to show compliance with this DPA, and allow for audits by the Customer or its auditor. We may satisfy this first with written answers and documentation.
This DPA is subject to the liability terms and governing law of the Terms of Service. If it conflicts with the Terms on the processing of personal data, this DPA prevails. We may update it to reflect changes in law or the service; material changes will be reflected in the effective date above.