DATA PROCESSING AGREEMENT
Between Fifty Seven Digital Limited and the Customer
Last updated: 25 June 2026
Fifty Seven Digital Limited trading as Hacka | Registered in England and Wales | Companies House: 10964537 | support@hacka.co.uk
This Data Processing Agreement (“DPA”) forms part of the agreement between Fifty Seven Digital Limited, registered in England and Wales, trading as Hacka (“Processor”) and the customer entity that subscribes to the Services (“Controller”) under the Terms of Service (the “Agreement”). It applies where, and to the extent that, the Processor processes Personal Data on behalf of the Controller in the course of providing the Services. Capitalised terms not defined here have the meaning given in the Agreement or in applicable Data Protection Law.
By accepting the Agreement, the Controller accepts this DPA. Where a separately negotiated and countersigned data processing agreement exists between the parties, that agreement governs in the event of conflict.
1. Definitions
“Data Protection Law” means all applicable data protection and privacy legislation binding on the Processor, including the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Privacy and Electronic Communications Regulations 2003 (PECR), as amended or replaced.
“Personal Data”, “Controller”, “Processor”, “Data Subject”, “Processing”, “Personal Data Breach”, and “Supervisory Authority” have the meanings given in the UK GDPR.
“Customer Personal Data” means any Personal Data submitted to the Services by or on behalf of the Controller, or otherwise processed by the Processor on behalf of the Controller under the Agreement.
“Sub-processor” means any third party engaged by the Processor to process Customer Personal Data on behalf of the Controller.
“IDTA” means the International Data Transfer Agreement issued by the ICO under section 119A(1) of the Data Protection Act 2018, as amended or replaced from time to time.
2. Roles and Subject-Matter
In respect of Customer Personal Data, the Controller is the data controller and the Processor is the data processor. The Processor processes Customer Personal Data only on the documented instructions of the Controller: (a) to provide, secure, and support the Services as described in the Agreement; and (b) any further written instructions compatible with the Services.
The Processor shall inform the Controller if, in its opinion, an instruction infringes Data Protection Law, without being obliged to actively monitor the Controller’s compliance.
3. Duration, Nature, and Purpose of Processing
The duration of processing is the term of the Agreement plus any post-termination period required to complete deletion of Customer Personal Data as set out in Section 9. The nature of processing is the operation of an automated security scanning service. The purpose is to deliver the functionalities of the Services that the Controller configures and uses.
3.1 Categories of Data Subjects
Categories of data subjects may include: the Controller’s personnel and authorised users of the platform; individuals whose personal data is incidentally contained within code or repositories submitted for scanning.
3.2 Categories of Personal Data
Categories of Personal Data processed may include:
• Identifiers: full name, email address, account ID;
• Authentication data: scrypt-hashed passwords (direct registrations); OAuth access tokens from GitHub or GitLab (third-party sign-in); profile image URL (third-party sign-in);
• Organisation data: company name, company size, industry;
• Technical and connection data: IP address, browser and device information, application logs (deleted after 24 hours), LLM error logs (deleted when associated scan is deleted);
• Payment identifiers: billing name, last four digits of payment card, transaction IDs – full card data is processed exclusively by Stripe and never held by the Processor;
• Scan metadata: submission timestamps, scan status, finding counts – source code is never written to persistent storage and is deleted on container termination;
• Support correspondence: content of any communications with the Processor.
The Services are not intended to process special categories of personal data under Article 9 UK GDPR. The Controller agrees not to use the Services to deliberately submit such data without prior written agreement and additional safeguards.
4. Processor Obligations
4.1 Instructions
The Processor shall process Customer Personal Data only on the Controller’s documented instructions, except where required by law. The Processor shall inform the Controller before processing pursuant to a legal requirement unless prohibited from doing so.
4.2 Confidentiality
The Processor shall ensure that persons authorised to process Customer Personal Data are bound by confidentiality obligations and process such data only on the Controller’s instructions or as required by law.
4.3 Security
The Processor shall implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk. A full description of these measures is set out in Schedule 2 of this DPA.
4.4 Sub-processors
The Controller grants the Processor general authorisation to engage Sub-processors to process Customer Personal Data. The Processor shall:
• Maintain an up-to-date list of Sub-processors (available on request) and in Schedule 1 of this DPA;
• Provide the Controller with at least 30 days’ prior written notice of any intended addition or replacement of a Sub-processor;
• Impose data protection obligations on each Sub-processor materially consistent with this DPA;
• Remain liable to the Controller for the acts and omissions of its Sub-processors to the same extent as if it had performed the processing itself.
The Controller may object in writing, on reasonable data protection grounds, to a new Sub-processor within 14 days of notice. If the parties cannot resolve the objection, the Controller may terminate the affected portion of the Services on reasonable written notice.
4.5 Data Subject Rights
The Processor shall assist the Controller by appropriate technical and organisational measures in fulfilling its obligations to respond to Data Subject requests under Chapter III UK GDPR. Where the Processor receives a Data Subject request directly relating to the Controller’s data, it shall promptly notify the Controller and not respond except on the Controller’s documented instructions or as required by law.
4.6 Personal Data Breach Notification
The Processor shall notify the Controller without undue delay – and in any event within 72 hours where feasible – after becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification shall include the information reasonably available to allow the Controller to meet its obligations under Articles 33 and 34 UK GDPR.
4.7 DPIA Assistance
Where required under Article 35 or 36 UK GDPR, the Processor shall provide reasonable assistance to the Controller in carrying out Data Protection Impact Assessments and prior consultations with the ICO.
4.8 Audit Rights
The Processor shall make available to the Controller, on reasonable written request and no more than once per calendar year (unless a Personal Data Breach involving the Controller’s data has occurred, or where required by the ICO), information reasonably necessary to demonstrate compliance with this DPA. The Processor may satisfy such requests by providing summary security reports or relevant documentation. Any on-site audit shall be agreed in advance, conducted by an independent auditor bound by confidentiality, shall not unreasonably disrupt operations, and shall be at the Controller’s cost unless material non-compliance is found.
5. International Data Transfers
The Processor’s cloud infrastructure runs exclusively in AWS eu-west-1 (Ireland). Ireland is a member of the European Economic Area and benefits from UK adequacy – no additional transfer mechanism is required for that processing.
Where Customer Personal Data is transferred to US-based Sub-processors – specifically Groq – such transfers are made under the IDTA incorporated into the relevant Sub-processor agreement. Copies of applicable transfer mechanisms are available on request at support@hacka.co.uk.
The parties agree that, to the extent any transfer of Customer Personal Data from the Controller to the Processor constitutes a Restricted Transfer, the IDTA (Module 2: Controller to Processor) is incorporated into this DPA by reference and completed with the information in Schedule 1.
6. Liability
Each party’s liability under this DPA is subject to the limitations and exclusions set out in the Agreement. Nothing in this DPA increases or expands the Processor’s liability beyond what is provided in the Agreement. In the event of conflict between this DPA and the Agreement on data protection matters, this DPA controls.
7. Governing Law
This DPA is governed by the laws of England and Wales, except where mandatory Data Protection Law requires otherwise. The parties submit to the non-exclusive jurisdiction of the courts of England and Wales. The ICO is the lead Supervisory Authority for the Processor’s processing activities under this DPA.
8. Updates to This DPA
The Processor may modify this DPA as required by changes in Data Protection Law, changes to the Services, or changes in Sub-processors. The Processor will provide at least 30 days’ prior notice of material changes. Continued use of the Services after the effective date constitutes acceptance. Where a change materially reduces the level of data protection provided, the Controller may terminate the Agreement on reasonable written notice.
9. Deletion and Return
On termination or expiry of the Agreement, the Processor shall within 30 days delete all Customer Personal Data and confirm deletion to the Controller in writing, except to the extent that retention is required by applicable law.
On account deletion by the Controller or any authorised user, all associated personal data is deleted immediately and permanently. Source code submitted for scanning is deleted on scan completion and is never written to persistent storage.
Payment records are retained for 7 years following the last transaction to comply with HMRC record-keeping requirements. This retention applies even following account deletion and cannot be waived.
Database backups are taken nightly and stored in AWS S3 (eu-west-1, Ireland). Backups are retained for 14 days and then automatically overwritten. Backup data is subject to the same encryption and access controls as live data and does not constitute a separate or extended retention of Customer Personal Data beyond the periods stated above.
Schedule 1 – Data Processing Details and Sub-processors
A. Parties
Controller: the customer entity that subscribes to the Services as identified in the account registration.
Processor: Fifty Seven Digital Limited, trading as Hacka, registered in England and Wales (Companies House: 10964537).
B. Description of Processing
Nature: automated security scanning of submitted source code repositories, conducted in ephemeral isolated compute environments. Source code is never written to persistent storage.
Purpose: delivery of security scanning services as described in the Agreement.
Duration: the term of the Agreement plus the post-termination deletion period in Section 9.
Frequency: continuous, triggered on each scan submission by the Controller.
Sensitive data: none intended. The Controller agrees not to deliberately submit special category data as defined under Article 9 UK GDPR without prior written agreement and additional safeguards.
C. Competent Supervisory Authority
The Information Commissioner’s Office (ICO), United Kingdom. ico.org.uk
D. Sub-processors – Personal Data Processed
These are the only third-party services that receive or process personal data on Hacka’s behalf. Each is appointed under a written contract imposing data protection obligations consistent with this DPA.
| Sub-processor | Purpose | Location | Transfer mechanism |
| Amazon Web Services | Cloud compute – ephemeral scan containers and artefact storage. All infrastructure runs exclusively in eu-west-1. | Ireland | No transfer mechanism required – Ireland is within the EEA and benefits from UK adequacy. |
| Groq | AI inference – LLM processing of scan content during analysis phases. | USA | IDTA (Controller to Processor) incorporated into sub-processor agreement. |
| Stripe Payments Europe Limited | Payment processing and subscription management for UK and EEA customers. | Ireland | No transfer mechanism required — Ireland benefits from UK adequacy. Stripe’s US entity is not used for UK customer data. |
E. Public Data Sources – No Personal Data Transferred
The following external services are queried during the supply chain analysis phase of scanning. They are public APIs used to look up vulnerability and package data. No personal data belonging to the Controller or any data subject is transmitted to these services — queries contain only package names, version numbers, and CVE identifiers.
These services are not sub-processors and are not subject to the sub-processor provisions of this DPA.
| Service | Purpose | Location |
| NVD / NIST National Vulnerability Database | Public CVE and vulnerability data lookup | USA (public API) |
| Sonatype OSS Index | Open source package vulnerability data lookup | USA (public API) |
Schedule 2 – Technical and Organisational Measures
The following measures are maintained by Fifty Seven Digital Limited in accordance with Article 32 UK GDPR. These may be updated provided such updates do not result in a material reduction of protection for Customer Personal Data.
Compute and Scan Isolation
• All scan processing runs in ephemeral AWS ECS Fargate tasks using Firecracker microVM isolation – each task has a separate kernel, memory, and network namespace and is destroyed on completion.
• Source code submitted for scanning is never written to S3 or any persistent storage. It exists only within the scan container’s filesystem and is permanently deleted when the container terminates.
• No scan shares compute, filesystem, or network state with any other scan.
• All scan tasks run in private VPC subnets in eu-west-1 with no internet gateway by default.
• Container images are built from minimal base images with no package managers. Images are scanned for vulnerabilities on every push. Image digests are pinned in task definitions.
• All secrets are fetched from AWS Secrets Manager at task runtime. No credentials are baked into container images or environment variables.
• Read-only root filesystems on all scan task containers.
Data Encryption
• All data in transit is encrypted using TLS 1.2 or higher.
• Scan artefacts stored in S3 are encrypted at rest using AES-256 (SSE-S3).
• Passwords are hashed using scrypt – never stored in plain text or reversible format.
• OAuth access tokens are stored encrypted at rest.
• Payment card data is processed exclusively by Stripe and never stored on our infrastructure.
Access Controls
• Least-privilege IAM roles applied to all scan pipeline components. Each scan phase has its own task role limited to specific S3 paths and actions required for that phase only.
• No wildcard IAM permissions on any task role.
• Multi-factor authentication required for all administrative access to production infrastructure.
• Access to production systems restricted to authorised personnel with a documented business need.
Logging and Data Minimisation
• Application and platform logs are deleted every 24 hours as a matter of routine operational policy.
• LLM error logs are retained only until the associated scan is deleted by the user.
• Account data is deleted immediately and permanently on account deletion.
• CloudTrail enabled on all AWS API calls. S3 access logging enabled on all storage buckets.
Infrastructure Location
• All AWS infrastructure runs exclusively in eu-west-1 (Ireland) – no data is processed or stored in any other AWS region.
• Self-hosted infrastructure for account data and scan metadata is located in the United Kingdom and is under the direct control of Fifty Seven Digital Limited.
Database backups are taken nightly to AWS S3 (eu-west-1, Ireland), retained for 14 days, and then automatically overwritten. Backups are encrypted at rest using AES-256 (SSE-S3) and access is restricted to authorised personnel only.
Contact
Requests and queries under this DPA should be sent to support@hacka.co.uk with the subject line “DPA Request”.
Fifty Seven Digital Limited (trading as Hacka)
Email: support@hacka.co.uk
Website: www.hacka.co.uk
Registered in England and Wales | Companies House: 10964537