Data Processing Addendum

Last updated: July 2026

This Data Processing Addendum (“DPA”) forms part of the agreement between you (“Controller”) and HackTheKnowledge (“Processor” or “HTK”) and governs the processing of personal data in accordance with Art. 28 of Regulation (EU) 2016/679 (GDPR).

HTK is the trading name of Francisco Ramos Cascales, Spanish tax ID (NIF) —, address for notices Zürcherstrasse, 8952, Schlieren, Suiza. Contact: privacy@hacktheknowledge.com.

Note: where you use the platform as an individual student, HTK acts as controller and the Privacy Policy applies. This DPA applies to corporate customers who entrust HTK with the processing of data relating to their own employees or learners.

1. Definitions

  • Controller: the entity that determines the purposes and means of processing (corporate customers using the platform to train their staff).
  • Processor: HackTheKnowledge, processing personal data on behalf of the Controller.
  • Personal data / data subject: as defined in Art. 4 GDPR.
  • Sub-processor: a third party engaged by HTK to carry out specific processing activities on behalf of the Controller.

2. Subject matter and duration

HTK processes personal data to provide access to online cybersecurity training courses and virtual machine labs. Processing lasts for the term of the service agreement and ends when that agreement terminates or the data subject's account is deleted, subject to statutory retention obligations.

3. Nature and purpose of processing

  • Account creation, authentication and access management.
  • Course enrolment, progress tracking and certificate issuance.
  • Lab session provisioning (only pseudonymous identifiers are transmitted to Azure: CUID, courseId, labId).
  • Billing and payment processing via Stripe.
  • Transactional email (purchase confirmation, password reset) via Resend.
  • Learning analytics and platform improvement.
  • Security, fraud and abuse prevention.

4. Categories of data subjects and personal data

  • Students: name, email address, password hash, learning progress, lab activity.
  • Billing contacts: name, email address, billing country, transaction history.

No special categories of personal data under Art. 9 GDPR are processed. The Controller undertakes not to introduce data of those categories into the platform.

5. Sub-processors

The Controller authorises HTK to engage the following sub-processors. HTK will notify the Controller of any intended change (addition or replacement) with 30 days' notice, giving the Controller the opportunity to object.

Sub-processorPurposeLocationTransfer safeguard
Neon Inc.PostgreSQL database hostingEuropean Union (AWS eu-central-1, Frankfurt)EU processing; Standard Contractual Clauses for support access
Vercel Inc.Application hosting, edge delivery and Speed Insights (anonymous page-timing metrics: no cookies, no IP storage, no cross-page identification)United StatesStandard Contractual Clauses and EU-US Data Privacy Framework
Stripe Inc. / Stripe Payments Europe Ltd.Payment and refund processingUnited States / IrelandStandard Contractual Clauses and EU-US Data Privacy Framework
Microsoft AzureLab virtual machine provisioning. Pseudonymous identifiers only (CUID, courseId, labId); no directly identifying dataEuropean Union regionsEU processing; Microsoft DPA
BunnyWay d.o.o. (Bunny Stream)Course video hosting and deliveryEuropean Union (Slovenia), with a global delivery networkProvider DPA and Standard Contractual Clauses
Cloudflare, Inc.Object storage (R2) for uploaded files: assignment submissions and support-ticket screenshotsEU data residencyStandard Contractual Clauses
Resend Inc.Transactional email (verification, receipts, support)United StatesStandard Contractual Clauses
Upstash Inc.Rate limiting and debounce store. Ephemeral dataEuropean Union, where so configuredStandard Contractual Clauses
Google LLC / Google Ireland Ltd.Google Analytics 4 via Google Tag Manager, and Search Console. Loaded only after the user consents to analytics cookiesUnited StatesEU-US Data Privacy Framework and Standard Contractual Clauses
Discord Inc.Community access, only if the user links their Discord accountUnited StatesEU-US Data Privacy Framework

6. Controller instructions

HTK processes personal data only on documented instructions from the Controller, including with regard to transfers to third countries. HTK will inform the Controller if it believes an instruction infringes the GDPR or other applicable data protection law.

7. Confidentiality

HTK ensures that persons authorised to process personal data have committed themselves to confidentiality. Access to personal data is role-based and limited to those who need it to perform their duties.

8. Security measures (Art. 32 GDPR)

  • Encryption in transit (HTTPS/TLS 1.2 or higher, with HSTS preload).
  • Encryption at rest for the database.
  • bcrypt password hashing (cost factor ≥ 12).
  • HMAC-SHA256 signed calls between internal services.
  • Pseudonymisation of the identifiers sent to the lab infrastructure.
  • Role-based access control, database-verified for administrative functions.
  • Rate limiting on authentication and other sensitive endpoints.
  • Automatic session invalidation after a password change.
  • Technical log retention capped at 90 days.
  • Per-student isolated lab virtual machines with a maximum time-to-live and idle shutdown.
  • Regular dependency audits.

9. Assistance with data subject rights

HTK will assist the Controller in meeting its obligation to respond to data subject rights requests (access, rectification, erasure, restriction, portability and objection) within the timescales required by the GDPR. Contact: privacy@hacktheknowledge.com.

10. Personal data breach notification

In the event of a personal data breach, HTK will notify the Controller without undue delay and in any case no later than 72 hours after becoming aware of it, to the extent technically possible and subject to legal exceptions. The notification will include the nature of the breach, the categories and approximate number of data subjects affected, and the measures taken or proposed.

11. Deletion and return of data

On termination of the service, HTK will, at the Controller's choice, delete or return all personal data and delete existing copies, unless Union or Member State law requires storage. Deletion will be completed within 90 days of termination, unless a legal obligation requires longer retention.

12. Audits

HTK will make available to the Controller all information necessary to demonstrate compliance with the obligations in Art. 28 GDPR and will allow for and contribute to audits and inspections conducted by the Controller or a mandated auditor, subject to reasonable notice and confidentiality obligations.

13. International transfers

Where personal data is transferred to sub-processors located outside the European Economic Area without an adequacy decision, HTK relies on the Standard Contractual Clauses adopted by the European Commission in Implementing Decision (EU) 2021/914, supplemented where necessary by additional measures following a transfer impact assessment.

14. Governing law

This DPA is governed by Spanish law, consistent with the Terms of Service, without prejudice to mandatory provisions of the GDPR applicable in the data subject's country of residence. The competent supervisory authority is the Spanish Data Protection Agency (C/ Jorge Juan, 6 — 28001 Madrid, www.aepd.es).

15. Contact

DPA enquiries: privacy@hacktheknowledge.com.