Data Processing Addendum

Effective date: 2026-06-02 · Version 1.0

This Data Processing Addendum ("DPA") forms part of, and is incorporated into, the Terms of Service between EmberHound Ltd ("EmberHound", "Processor") and the Customer entity that accepts those terms ("Controller"). It governs the processing of Personal Data that EmberHound carries out on behalf of the Controller in connection with the EmberHound service. In the event of conflict between this DPA and the Terms of Service, this DPA prevails with respect to data protection matters.

1. Definitions

In this DPA the following terms have the meanings set out below. Capitalised terms not defined here have the meanings given in the Terms of Service.

  • "Data Protection Laws" means all applicable laws and regulations relating to the processing of Personal Data, including (where applicable) the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR as retained in domestic law by the Data Protection Act 2018 ("UK GDPR"), the Swiss Federal Act on Data Protection ("FADP"), and any subordinate legislation or guidance made under any of the foregoing.
  • "Personal Data", "Processing", "Data Subject", "Controller", "Processor", "Sub-processor", "Supervisory Authority", and "Personal Data Breach" each have the meanings given in the applicable Data Protection Laws.
  • "Findings Metadata" means the pseudonymised, hash-only artefacts that the EmberHound agent transmits to the service: cryptographic hashes of sensitive-data patterns, masked preview fragments containing only the minimum amount of information necessary to identify the relevant record, file-path tokens, and statistical counts. The agent does not transmit raw plaintext personal data.
  • "Standard Contractual Clauses" or "SCCs" means the European Commission's standard contractual clauses for the transfer of personal data to third countries pursuant to Decision 2021/914, Module 2 (Controller to Processor).
  • "UK IDTA" means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner's Office, Version B1.0 (March 2022).

2. Scope and Roles

EmberHound processes Personal Data as a Processor acting on behalf of the Controller solely to provide and improve the EmberHound service as described in this DPA and the Terms of Service. The Controller determines the purposes and means of that processing; EmberHound has no independent purpose for the Personal Data it processes under this DPA.

For avoidance of doubt, EmberHound acts as an independent Controller with respect to (a) its own employees' and contractors' data, (b) account and billing data for its direct relationship with the Customer, and (c) aggregated, de-identified service telemetry used to operate and improve the platform. This DPA does not apply to those categories.

3. Processing Details (Schedule 1)

The following describes the Personal Data processed by EmberHound on the Controller's behalf.

3.1 Nature and Purpose of Processing

EmberHound scans devices, file shares, databases, and cloud storage authorised by the Controller to discover and classify sensitive personal data for GDPR, PCI-DSS, and related compliance programmes. Processing activities include: receiving Findings Metadata transmitted by the EmberHound agent; storing, indexing, and deduplicating that metadata; matching metadata against Data Subject Access Request (DSAR) identifiers supplied by the Controller; generating compliance reports and dashboards; and retaining audit logs.

3.2 Types of Personal Data

  • Findings Metadata - cryptographic hashes of sensitive data patterns (email addresses, phone numbers, national identifiers, payment card numbers, names, etc.) detected on the Controller's systems; masked text previews (≤ 20 characters); file-path tokens; confidence scores.
  • DSAR subject identifiers - hashed and peppered versions of identifiers (name, email, phone) submitted by the Controller when creating a Data Subject Access Request. Raw identifiers are pseudonymised client-side before storage.
  • Account and device telemetry - hostnames, IP addresses, operating system types, agent version numbers, scan timestamps, and similar operational data relating to devices enrolled by the Controller.

3.3 Categories of Data Subject

Data subjects whose Personal Data may be referenced in Findings Metadata include: the Controller's employees, contractors, and customers whose personal data is stored on systems scanned by the agent; data subjects who submit DSARs to the Controller; and device operators and IT administrators whose operational data is captured as account/device telemetry.

3.4 Duration

EmberHound processes Personal Data for the duration of the subscription term. On termination EmberHound will delete or return Personal Data in accordance with Section 4.7. Findings Metadata and DSAR data are retained in accordance with the retention periods set out in the Privacy Policy.

4. Processor Obligations

EmberHound shall, in its capacity as Processor:

4.1 Instructions

Process Personal Data only on documented instructions from the Controller, including as set out in this DPA and the Terms of Service. If EmberHound is required by applicable law to process Personal Data for any other purpose, it will inform the Controller of that requirement before processing (unless prohibited by law on grounds of public interest).

4.2 Confidentiality

Ensure that persons authorised to process Personal Data under this DPA are subject to appropriate confidentiality obligations and have received adequate data protection training.

4.3 Security

Implement and maintain the technical and organisational measures described in Schedule 3 of this DPA, designed to provide a level of security appropriate to the risk presented by the Processing, having regard to the state of the art, the cost of implementation, and the nature, scope, context, and purposes of Processing (GDPR Art. 32).

4.4 Sub-processors

Not engage any Sub-processor to carry out specific processing activities on the Controller's Personal Data without the Controller's prior written authorisation, which is given generally by the Controller's acceptance of this DPA with respect to the Sub-processors listed in Schedule 2. EmberHound will give the Controller at least 30 days' written notice before adding or replacing any Sub-processor; the Controller may object on reasonable data-protection grounds within that period. If the Controller objects and EmberHound cannot accommodate the objection, the Controller may terminate the affected service with no penalty.

EmberHound will impose data-protection obligations on each Sub-processor no less protective than those in this DPA and will remain liable to the Controller for any failure of a Sub-processor to fulfil its data-protection obligations.

4.5 Data Subject Rights

Assist the Controller, by appropriate technical and organisational measures and to the extent reasonably possible, to fulfil its obligations to respond to Data Subject requests to exercise their rights under Data Protection Laws. Where a Data Subject contacts EmberHound directly, EmberHound will promptly redirect that request to the Controller.

4.6 DPIAs and Prior Consultation

Provide reasonable assistance to the Controller in carrying out Data Protection Impact Assessments (DPIAs) and, where required, prior consultations with a Supervisory Authority, in each case in relation to Processing under this DPA.

4.7 Deletion and Return

At the Controller's election, on termination of the subscription either delete or return all Personal Data to the Controller and delete existing copies, except to the extent that applicable law requires storage of the Personal Data. Upon written request, EmberHound will provide confirmation that deletion has been completed.

4.8 Audit and Inspection

Make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA, and allow for and contribute to audits and inspections conducted by the Controller or its designated auditor, subject to (a) reasonable advance notice of not less than 30 days, (b) a maximum of one audit per year absent reasonable cause to believe a breach has occurred, and (c) the auditor executing EmberHound's standard confidentiality undertaking. EmberHound may satisfy this obligation by providing up-to-date third-party audit reports (e.g. ISO 27001, SOC 2 Type II) in lieu of a bespoke audit.

5. Personal Data Breach Notification

EmberHound will notify the Controller without undue delay, and in any event within 72 hours of becoming aware of a Personal Data Breach affecting Personal Data processed under this DPA. The notification will include, to the extent then known:

  • A description of the nature of the breach, including categories and approximate number of Data Subjects and records affected;
  • The name and contact details of the Data Protection Officer or other relevant contact;
  • The likely consequences of the breach; and
  • The measures taken or proposed to address the breach, including mitigation steps.

Where not all information is available within 72 hours, EmberHound may provide it in phases without undue further delay. The Controller remains responsible for determining whether regulatory notification to a Supervisory Authority is required and for making any such notification.

6. International Data Transfers

Where Personal Data is transferred to or accessed from a country outside the EEA, the UK, or Switzerland that does not benefit from an adequacy decision, such transfer is governed by:

  • EU transfers: The Standard Contractual Clauses (Module 2 - Controller to Processor), incorporated by reference into this DPA. The Controller is the data exporter and EmberHound (or the relevant Sub-processor) is the data importer.
  • UK transfers: The SCCs as supplemented by the UK IDTA (Version B1.0). Table 1 (Parties) and Table 3 (Appendix) of the IDTA are populated by the information in this DPA and its Schedules.
  • Swiss transfers: The SCCs as amended in accordance with the guidance of the Swiss Federal Data Protection and Information Commissioner (FDPIC).

A copy of the applicable SCCs and UK IDTA is available on written request to privacy@emberhound.com.

Consistent with the EDPB's post-Schrems II guidance (Recommendations 01/2020), EmberHound maintains a Transfer Impact Assessment for each transfer covered by this Section, evaluating whether the destination country's laws and government access practices could undermine the protections in the applicable SCCs or UK IDTA, and documenting any supplementary technical, contractual, or organisational measures adopted as a result. A summary is available on written request to privacy@emberhound.com.

7. Liability

Each party's liability under this DPA is subject to the limitations and exclusions set out in the Terms of Service, except that nothing in this DPA or the Terms of Service limits a party's liability where such limitation is not permitted by applicable Data Protection Laws (for example, a party's liability to a Data Subject under GDPR Art. 82).

8. Term and Termination

This DPA commences on the effective date of the Terms of Service and continues until the expiry or termination of the Terms of Service. Termination of this DPA does not relieve either party of obligations with respect to Personal Data processed prior to termination. Sections 4.7 (Deletion and Return), 5 (Breach Notification), 7 (Liability), and 9 (Governing Law) survive termination.

9. Order of Precedence

In the event of conflict, the order of precedence is: (1) applicable Data Protection Laws; (2) the Standard Contractual Clauses / UK IDTA (where engaged); (3) this DPA; (4) the Terms of Service. This DPA does not limit or override any rights a Data Subject has under applicable law.

10. Governing Law

This DPA is governed by and construed in accordance with the laws of England and Wales, except to the extent that the Standard Contractual Clauses or UK International Data Transfer Addendum require the application of another law.

Schedule 2 - Authorised Sub-processors

The following Sub-processors are authorised as of the effective date of this DPA. EmberHound will give 30 days' prior written notice of changes (additions or replacements) in accordance with Section 4.4. List last updated: 24 June 2026.

Sub-processorRoleLocationTransfer mechanism
Supabase, Inc. (AWS)Database hosting, authentication, storage, and edge functionsEuropean Union (AWS eu-west-1, Ireland)SCCs Module 2 / UK IDTA
Vercel, Inc.Frontend hosting and edge deliveryGlobal edge network (HQ United States)SCCs Module 2 / UK IDTA
Stripe Payments Europe, Ltd.Payment processing and billing (billing data only)Ireland, with onward transfer to United States (Stripe, Inc.)SCCs Module 2 / UK IDTA
iwocaPay (Iwoca Ltd.)Buy-now-pay-later payment processingUnited KingdomUK GDPR (no transfer); SCCs as applicable for EEA customers
Resend, Inc.Transactional email delivery (notifications)European Union (AWS eu-west-1, Ireland)EU/UK (no transfer outside EEA; UK adequacy decision)
Sentry (Functional Software, Inc.)Error monitoring and diagnosticsEuropean Union (EU)EU/UK (no transfer outside EEA; UK adequacy decision)
Better Stack, a.s.Uptime monitoring and incident alerting for platform endpointsEuropean Union (Czech Republic)EU/UK (no transfer outside EEA; UK adequacy decision)
GitHub, Inc. (Microsoft)Status page hosting via Upptime (GitHub Actions workflow)United StatesSCCs Module 2 / UK IDTA

Stripe and iwocaPay process billing data only (name, email, payment method); they do not receive Findings Metadata or DSAR identifiers. DSAR pepper values are stored exclusively in Supabase Vault (pgsodium) and are never transmitted to any other Sub-processor.

Schedule 3 - Technical and Organisational Measures

EmberHound implements the following measures to protect Personal Data processed under this DPA (GDPR Art. 32):

Encryption

  • All data in transit encrypted with TLS 1.2+ (TLS 1.3 preferred).
  • All data at rest encrypted with AES-256 (managed by Supabase / AWS KMS).
  • DSAR identifier hashes derived using PBKDF2-SHA-256 (100,000 iterations) with a per-organisation cryptographic pepper stored in Supabase Vault (pgsodium).
  • Device secrets stored as PBKDF2-SHA-256 hashes; never in plaintext.

Access Controls

  • Role-based access control (RBAC) with least-privilege roles for Customer users and EmberHound platform staff.
  • Row-Level Security (RLS) enforced at the database layer - all queries are automatically scoped to the authenticated organisation.
  • Multi-factor authentication (MFA) required for platform administrator actions; step-up authentication for critical mutations.
  • API keys and service-role credentials stored as environment secrets, not in source code.

Data Minimisation and Pseudonymisation

  • The EmberHound agent transmits only Findings Metadata (hashes and ≤ 20-character masked previews); it does not transmit raw plaintext sensitive data.
  • DSAR subject identifiers are peppered and hashed before storage; the plaintext identifier is never persisted server-side.

Availability and Resilience

  • Infrastructure hosted on AWS via managed database and platform providers with automated failover.
  • Daily encrypted backups with a 7-day retention window.
  • Recovery Point Objective (RPO) target: ≤ 24 hours. Recovery Time Objective (RTO) target: ≤ 8 hours.
  • Automated health checks and alerting for all production services.

Organisational Measures

  • Comprehensive audit logging of all data access and mutations.
  • Incident response plan with defined breach notification procedure (Section 5).
  • Staff data-protection training and confidentiality obligations.
  • Formal data retention and deletion policy aligned to the Privacy Policy.
  • Vendor security reviews for all Sub-processors listed in Schedule 2.

We use cookies to improve your experience and analyse site usage. Privacy policy.