PRIVACY POLICY

How Hacka collects, uses, and protects your personal data

Last updated: 25 June 2026
Fifty Seven Digital Limited trading as Hacka | Registered in England and Wales | Companies House: 10964537 | support@hacka.co.uk

This Privacy Policy explains how Fifty Seven Digital Limited, registered in England and Wales, trading as Hacka (“we”, “us”, “our”) collects, uses, stores, and shares personal data when you use the Hacka platform and associated services at www.hacka.co.uk (the “Services”). It applies to all users, whether visiting the marketing site or using the platform as a registered subscriber.
We are committed to protecting your personal data and complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

1. Who We Are and How to Contact Us

Fifty Seven Digital Limited (trading as Hacka) is the data controller in respect of personal data collected through the Services.
Email: support@hacka.co.uk
Website: www.hacka.co.uk
Companies House: 10964537

ICO Registration Number: ZA291846

If you have questions about this policy or wish to exercise your data subject rights, please contact us at support@hacka.co.uk. You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at ico.org.uk or by calling 0303 123 1113.

2. Personal Data We Collect

2.1 Account and Registration Data
When you create an account directly, we may collect and store:
• Full name;
• Email address;
• Password – stored as a one-way hash using scrypt. We never store your password in plain text or in a reversible format;
• Company name;
• Company size;
• Industry.
If you register or sign in using a third-party provider (GitHub or GitLab), we do not store a password. Instead we store:
• An access token provided by the third-party provider, used to authenticate your session;
• Your profile image URL, as provided by the third-party provider;
• Your name and email address, as provided by the third-party provider.

OAuth sign-in: We currently support sign-in via GitHub and GitLab. We request only the minimum scopes necessary to authenticate you and identify your account – specifically your basic profile and email address. We do not request access to your repositories, code, or any other data.

2.2 Billing and Payment Data

When you subscribe or purchase credits, payment is processed by Stripe. We do not collect or store full payment card details. We receive from Stripe:
• Your billing name and email address;
• The last four digits of your payment card and card expiry date;
• Billing address (where provided);
• Transaction identifiers and subscription status.

Stripe’s privacy policy is available at stripe.com/privacy.

2.3 Usage and Technical Data

When you use the Services, we automatically collect:
• IP address and approximate geographic location;
• Browser type, version, and operating system;
• Pages visited, features used, and navigation patterns;
• Scan submission timestamps, scan status, and scan result metadata — we do not store your source code;
• Application logs and LLM error logs (see Section 6 for retention periods).

2.4 Submitted Code

When you submit a repository or codebase for scanning, that code is processed exclusively within an ephemeral, hardware-isolated compute environment. Your source code is never copied to persistent storage at any point during processing. It exists only within the scan container’s own filesystem and is permanently deleted when the container terminates on scan completion.

Scan outputs – reports, vulnerability findings, and analysis artefacts derived from your code – are retained until you delete them or until you delete your account, whichever comes first.

2.5 Communications Data

If you contact us by email or through a support channel, we collect the content of your communications and your contact details.

2.6 Cookie and Tracking Data
We use cookies and similar technologies as described in our Cookie Policy (www.hacka.co.uk/cookies).

3. How We Use Your Personal Data

We use your personal data only where we have a lawful basis to do so under UK GDPR. The table below sets out our purposes and the lawful basis for each.

Purpose Lawful basis Retention
Providing the Services – processing scans, delivering reports, managing your account Performance of contract (Art. 6(1)(b) UK GDPR) Duration of account. Deleted immediately on account deletion.
Processing payments and managing subscriptions Performance of contract (Art. 6(1)(b)) 7 years – HMRC record-keeping requirements.
Sending transactional communications – scan completion, billing notices, security alerts Performance of contract (Art. 6(1)(b)) Duration of account.
Application logging – platform operation and error tracking Legitimate interests (Art. 6(1)(f)) – platform stability and security 24 hours, except LLM error logs which are retained until the associated scan is deleted.
Improving the Services – analysing usage patterns in aggregated, anonymised form Legitimate interests (Art. 6(1)(f)) – improving the platform Aggregated and anonymised – no personal data retained.
Marketing communications – product updates and new features Legitimate interests (Art. 6(1)(f)) or consent where required by PECR Until you unsubscribe.
Complying with legal obligations – responding to lawful requests from authorities Legal obligation (Art. 6(1)(c)) As required by applicable law.
Preventing fraud, abuse, and misuse of the Services Legitimate interests (Art. 6(1)(f)) – platform security 24 hours for routine logs; LLM error logs until associated scan is deleted.

4. Who We Share Your Data With

4.1 Sub-processors
We use the following third-party services to operate the platform. Each is bound by contractual data protection obligations consistent with UK GDPR Article 28:

Processor Purpose Location Privacy policy
Amazon Web Services (AWS) Cloud compute — ephemeral scan containers and artefact storage Ireland (eu-west-1) aws.amazon.com/privacy
Groq AI inference — LLM processing during scan phases USA groq.com/privacy
Stripe Payment processing and subscription management USA / Ireland stripe.com/privacy

4.2 Self-Hosted Infrastructure
Account data, scan metadata, and scan outputs are stored on self-hosted infrastructure operated by us and located in the United Kingdom. This infrastructure is under our direct control and is not a third-party sub-processor.

4.3 Legal Disclosures
We may disclose personal data to law enforcement, regulatory authorities, or courts where required by applicable law, or where we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others. Where legally permitted, we will notify you before complying.

5. International Data Transfers

Our cloud infrastructure runs exclusively in AWS eu-west-1 (Ireland). Ireland is a member of the European Economic Area and benefits from UK adequacy – no additional transfer mechanism is required for that processing.

Groq is US-based. Where we transfer personal data to Groq, we do so under UK Standard Contractual Clauses (the ICO’s International Data Transfer Agreement – IDTA) incorporated into our sub-processor agreement. Stripe processes UK customer payments through Stripe Payments Europe Limited in Ireland, which benefits from UK adequacy – no transfer mechanism is required for that processing. Where any data is transferred to Stripe’s US entity, we do so under the IDTA. You may request a copy of any applicable transfer mechanism by contacting us at support@hacka.co.uk.

6. Data Retention

We retain personal data only for as long as necessary to fulfil the purpose for which it was collected, or as required by law:
• Source code submitted for scanning: deleted immediately on scan completion. Never written to persistent storage.
• Scan outputs (reports, findings, artefacts): retained until you delete them or until you delete your account – whichever comes first.
• Account data (name, email, company details): deleted immediately and permanently when you delete your account.
• Application and platform logs: deleted every 24 hours.
• LLM error logs: retained until you delete the associated scan.
• Payment records: retained for 7 years to comply with HMRC record-keeping requirements. This applies even following account deletion.
• Database backups: backed up nightly to AWS S3 (eu-west-1, Ireland) and retained for 14 days, after which they are automatically overwritten.

When you delete your account, all personal data we hold about you is deleted immediately and permanently, with the sole exception of payment records which are retained for 7 years as a legal obligation.

7. Your Rights Under UK GDPR

You have the following rights in relation to your personal data:
• Right of access – you may request a copy of the personal data we hold about you.
• Right to rectification – you may ask us to correct inaccurate or incomplete data.
• Right to erasure – you may ask us to delete your personal data. Deleting your account deletes all your data immediately.
• Right to restriction – you may ask us to restrict processing in certain circumstances.
• Right to data portability – you may request your data in a structured, machine-readable format.
• Right to object – you may object to processing based on legitimate interests, including for direct marketing.
• Rights related to automated decision-making – you have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects.

To exercise any of these rights, contact us at support@hacka.co.uk. We will respond within one month. We may need to verify your identity first. If you are not satisfied with our response, you may complain to the ICO at ico.org.uk or by calling 0303 123 1113.

8. Security

We implement appropriate technical and organisational measures to protect your personal data, including:
• TLS encryption for all data in transit;
• Scrypt hashing for all stored passwords;
• Encrypted storage of OAuth access tokens;
• Ephemeral, hardware-isolated compute environments for scan processing — source code never touches persistent storage;
• All AWS infrastructure in a single controlled region (eu-west-1, Ireland);
• Least-privilege access controls on all infrastructure;
• Multi-factor authentication for administrative access;
• Routine deletion of logs every 24 hours.

No method of transmission over the internet is completely secure. In the event of a personal data breach affecting your data, we will notify you and the ICO in accordance with our legal obligations.

9. Children

The Services are not directed at anyone under the age of 18. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, contact us at support@hacka.co.uk and we will delete it promptly.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or by a prominent notice on the Site before they take effect. The “Last updated” date at the top of this page reflects the most recent revision.

11. Contact and Complaints

For questions, requests, or complaints relating to this Privacy Policy:
Fifty Seven Digital Limited (trading as Hacka)
Email: support@hacka.co.uk
Website: www.hacka.co.uk
Registered in England and Wales | Companies House: 10964537
To complain to the ICO: ico.org.uk | 0303 123 1113

“I scan every client project before delivery now. It takes five minutes and I bill it as due diligence. Twice it’s caught something I would have missed.”

Priya, freelance developer

“Hacka has become a key part of how we approach software quality at Code Galaxy. It gives our development team clear visibility of potential vulnerabilities within the systems we build, allowing us to address risks early and with confidence.

The real value is in how it prioritises what matters. Instead of generic alerts, we get a structured view of risk, which helps us focus on building robust, well-tested software for our clients without slowing down delivery.”

Nicky, Code Galaxy