Version 1.0 · Effective 1 September 2026
This agreement is incorporated into our Terms & Conditions and applies automatically to every customer account. A signable copy is available as a PDF; countersigned copies can be requested at [email protected]. The current subprocessor list is maintained at darkstrata.io/en/subprocessors/.
This Data Processing Agreement (“DPA”) forms part of the agreement between DarkStrata Ltd (“DarkStrata”, “we”) and the customer identified in the applicable order or account registration (“Customer”, “you”) for the DarkStrata credential and dark-web monitoring services (the “Services”) (together, the “Agreement”).
It applies where DarkStrata processes Personal Data on the Customer’s behalf in the course of providing the Services and sets out the terms required by Article 28 of the UK GDPR and, where applicable, the EU GDPR.
In the event of conflict between this DPA and the rest of the Agreement, this DPA prevails in respect of the processing of Personal Data.
For Customer Data, the Customer is the Controller and DarkStrata is the Processor. Where the Customer acts on behalf of its own clients (for example as a managed service provider or reseller), the Customer warrants that it is authorised to appoint DarkStrata as a Processor or Sub-processor on those clients’ behalf.
For the Data Corpus, DarkStrata is an independent Controller. Matching the Customer’s monitored assets against the Data Corpus is a processing activity DarkStrata performs as Processor; the Data Corpus itself, and DarkStrata’s collection and retention of it, are outside the scope of this DPA and are governed by DarkStrata’s Privacy Policy.
DarkStrata processes Customer Data only on the Customer’s documented instructions, which are: the Agreement, this DPA, and the Customer’s configuration and use of the Services (including monitored assets, alert rules and integrations). DarkStrata will inform the Customer if, in its opinion, an instruction infringes Data Protection Law.
DarkStrata will not process Customer Data for any other purpose, including for model training, benchmarking or resale, and will not add Customer Data to the Data Corpus.
DarkStrata ensures that personnel authorised to process Customer Data are bound by written confidentiality obligations and receive appropriate data protection training. Access is restricted to personnel who need it to provide, support or secure the Services.
DarkStrata implements and maintains the technical and organisational measures described in Annex 2, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, so as to ensure a level of security appropriate to the risk.
DarkStrata may update those measures from time to time provided the overall level of security is not reduced.
The Customer gives DarkStrata general written authorisation to engage the Subprocessors listed in Annex 3, which is maintained at darkstrata.io/en/subprocessors/. DarkStrata imposes data protection obligations on each Subprocessor that are no less protective than those in this DPA and remains liable for the Subprocessor’s performance.
DarkStrata will give the Customer at least 30 days’ notice by email before a new Subprocessor processes Customer Data. The Customer may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection in good faith, the Customer may terminate the affected Services and receive a pro-rata refund of any prepaid fees.
Customer Data is stored and processed in the United Kingdom. DarkStrata’s hosting infrastructure is located in London and is listed in Annex 3.
Customers established in the EEA: the United Kingdom benefits from an adequacy decision of the European Commission under Article 45 of the EU GDPR. Transfers of Customer Data to DarkStrata therefore require no additional transfer mechanism.
Where a Subprocessor processes Customer Data outside the United Kingdom or EEA, DarkStrata ensures the transfer is covered by an adequacy regulation, the UK International Data Transfer Agreement or Addendum, or another mechanism valid under Data Protection Law, as recorded in Annex 3.
Taking into account the nature of the processing, DarkStrata will assist the Customer by appropriate technical and organisational measures in responding to Data Subject requests (access, rectification, erasure, restriction, portability and objection). Where a Data Subject contacts DarkStrata directly about Customer Data, DarkStrata will refer the request to the Customer without undue delay and will not respond except on the Customer’s instruction or as required by law.
DarkStrata will assist the Customer in meeting its obligations regarding security, Personal Data Breach notification, data protection impact assessments and prior consultation with a supervisory authority, taking into account the information available to DarkStrata.
DarkStrata will notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Customer Data. The notification will describe the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, the measures taken or proposed, and a point of contact. Information may be provided in phases as it becomes available.
On termination or expiry of the Agreement, or on the Customer’s written request, DarkStrata will delete Customer Data within 90 days, save to the extent retention is required by law. Before deletion the Customer may export its Customer Data through the Services or the API. Backups are overwritten in the ordinary course within the same period.
DarkStrata will make available to the Customer all information reasonably necessary to demonstrate compliance with this DPA, including security documentation and certifications. DarkStrata will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer, no more than once in any 12-month period unless required by a supervisory authority or following a Personal Data Breach, on at least 30 days’ written notice, during business hours, and subject to reasonable confidentiality and scope limitations.
Each party’s liability under this DPA is subject to the limitations and exclusions of liability in the Agreement. This DPA remains in force for as long as DarkStrata processes Customer Data. It is governed by the laws of England and Wales, save that where the Customer is established in the EEA, the mandatory provisions of the EU GDPR apply to the processing.
| Item | Description |
|---|---|
| Subject matter | Provision of credential, infostealer and dark-web exposure monitoring for the Customer’s domains, identities and assets. |
| Duration | The term of the Agreement plus the deletion period in section 11. |
| Nature and purpose | Storing the Customer’s monitored assets; matching them against the Data Corpus; generating, storing and delivering alerts, reports and summaries; delivering data to Customer-configured integrations; account administration, billing and support. |
| Categories of Data Subjects | The Customer’s employees, contractors and administrators; individuals whose identifiers the Customer monitors (for example staff or executives); the Customer’s own clients where the Customer resells the Services. |
| Categories of Personal Data | Names, business email addresses and roles of account users; monitored domains, email addresses and other identifiers; exposure findings relating to those identifiers (including breached or leaked credentials, device and malware details); alert history; audit logs; billing contact details. |
| Special category data | None intentionally processed. Exposure findings may incidentally reveal information about a Data Subject’s accounts or devices. |
The current list of Subprocessors, their location and the transfer safeguard relied on is published at darkstrata.io/en/subprocessors/ and is incorporated into this DPA. The list as at 1 September 2026 is:
| Subprocessor | Purpose | Location |
|---|---|---|
| DigitalOcean, LLC | Application and database hosting | United Kingdom (London) |
| Amazon Web Services EMEA SARL | Data storage and processing | United Kingdom (London) |
| Cloudflare, Inc. | Network delivery, security and backup | Global edge network; backups stored in Western Europe |
| Resend, Inc. | Email delivery | European Union (Ireland) |
| Stripe Payments Europe, Ltd. | Payments and invoicing | European Union and United States |
| Functional Software, Inc. (Sentry) | Error monitoring | European Union (Germany) |
| Anthropic, PBC | AI summaries of exposure findings | United States |
| GitHub, Inc. | Software delivery | United States |
| Tailscale Inc. | Private networking | Canada and United States |
Email: [email protected]
DarkStrata Ltd
Registered in England and Wales
Company No: 16521338
VAT Registration No: GB495674335