Data Processing Agreement

Effective August 16, 2026 · Last updated August 16, 2026

This Data Processing Agreement (“DPA”) forms part of, and is incorporated into, the Terms of Service between the customer and HukProof. It applies whenever HukProof processes personal data on the customer’s behalf — principally the workforce data a customer uploads to run simulations. In this DPA the customer is the “Controller” (data fiduciary) and HukProof is the “Processor”.

Plain summary. You decide whose data goes into HukProof and why; we only process it to run the service you asked for, keep it secure, use only the sub-processors we publish, help you answer data-subject requests and breaches, and delete or return it when you’re done. Enterprise customers can request a countersigned copy at privacy@hukproof.com.

1. Definitions

“Personal data”, “processing”, “controller”, “processor”, “data subject”, and “personal-data breach” have the meanings given in applicable data-protection law (including the GDPR and India’s DPDP Act, 2023). “Applicable Data Protection Law” means the privacy and data-protection laws that apply to a party’s processing under this DPA. “Sub-processor” means a third party engaged by HukProof to process personal data. Capitalized terms not defined here have the meaning in the Terms of Service.

2. Roles & scope of processing

The Controller determines the purposes and means of processing; HukProof processes only as a Processor on the Controller’s documented instructions. The particulars required by GDPR Article 28(3) are:

ItemDetail
Subject-matterProviding the HukProof security-awareness / phishing-simulation service.
DurationThe term of the Terms of Service, until deletion/return under Section 9.
Nature & purposeHosting, sending simulated messages (including QR-code / “quishing” simulations), tracking engagement, computing risk scores, and reporting — to deliver and secure the service.
Types of personal dataWorkforce records (names and email addresses — encrypted at rest; email domain; optional department, timezone) and simulation results (delivery, open, click, QR scan, derived risk). No passwords or credentials are captured. For a shared-QR simulation, an email address a recipient types on a mock sign-in page is matched in memory to the Controller’s own employee list to attribute the result and is not stored.
Categories of data subjectsThe Controller’s own employees, contractors, and comparable members.

3. Controller obligations

The Controller warrants it has a lawful basis and any required notices or consents to upload and process the workforce data, that all recipients are its own authorized workforce, and that its instructions comply with Applicable Data Protection Law. The Controller’s use is also governed by the Acceptable Use Policy.

4. Processor obligations

HukProof will, in line with GDPR Article 28(3):

  • Instructions. Process personal data only on the Controller’s documented instructions (including this DPA and use of the service), unless required by law — in which case we will inform the Controller where lawful.
  • Confidentiality. Ensure personnel authorized to process personal data are bound by confidentiality.
  • Security. Implement appropriate technical and organizational measures (Article 32) — see Section 6 and our Security page.
  • Sub-processors. Engage sub-processors only under Section 7.
  • Data-subject requests. Assist the Controller, by appropriate measures, to respond to data-subject requests (Section 8).
  • Assistance. Assist the Controller with security, breach notification, data-protection impact assessments, and prior consultation, taking into account the nature of processing and information available to us.
  • Deletion / return. Delete or return personal data at the end of the service (Section 9).
  • Records & audits. Make available information necessary to demonstrate compliance and allow for audits (Section 10).

5. Controller instructions

The service configuration and this DPA are the Controller’s complete and final instructions. Additional or different instructions must be agreed in writing and may be subject to fees if they require changes to the service.

6. Security measures

HukProof maintains measures including: encryption in transit (TLS) and at rest (AES-256-GCM with a per-organization key for the most sensitive fields); tenant isolation via database row-level security; access controls, optional MFA, and login lockout; least-privilege administration and audit logging; and the default recipient-domain restriction. Full detail is on our Sub-processors & Security page.

7. Sub-processors

The Controller provides a general authorization for HukProof to engage the sub-processors listed on our Sub-processors page, each under a contract imposing data-protection obligations no less protective than this DPA. We keep that list current and give advance notice of any new sub-processor before it begins processing personal data — by updating that page and, for customers who subscribe to notifications or are under a signed DPA, by email. Any Controller may object to a new sub-processor on reasonable data-protection grounds; if we cannot resolve the objection, the Controller may terminate the affected service.

8. Data-subject requests

Taking into account the nature of the processing, HukProof will assist the Controller with appropriate technical and organizational measures — insofar as possible — to fulfill the Controller’s obligation to respond to data-subject requests. If a data subject contacts HukProof directly about data we process for a Controller, we will refer them to that Controller.

9. International transfers

Where processing involves transferring personal data across borders, the parties will rely on an appropriate transfer mechanism, such as the EU Standard Contractual Clauses, which are incorporated by reference where they apply. India data-residency options can be discussed for enterprise engagements.

10. Personal-data breach

HukProof will notify the Controller without undue delay after becoming aware of a personal-data breach affecting the Controller’s data, and will provide information reasonably available to help the Controller meet its own notification obligations (e.g. GDPR Articles 33–34; DPDP breach rules).

11. Deletion & return

On expiry or termination of the service, HukProof will delete or, at the Controller’s choice, return the personal data, and delete existing copies, unless retention is required by law — subject to short backup-rotation windows after which backups are overwritten.

12. Audits

HukProof will make available information necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates — on reasonable prior notice, no more than once per year absent a regulator requirement or a breach, during business hours, subject to confidentiality, and in a manner that does not compromise other customers’ security. We may satisfy audit requests by providing then-current documentation.

13. Liability

Each party’s liability under this DPA is subject to the limitations and exclusions in the Terms of Service.

14. Conflict & execution

If there is a conflict between this DPA and the Terms of Service on the processing of personal data, this DPA controls. To request a countersigned copy for your records, email privacy@hukproof.com. This DPA is entered into by HukProof and the Controller.

Last updated August 16, 2026 · privacy@hukproof.com