Data Processing Addendum
Version 1.1 · Published September 28, 2026
This DPA forms part of the Hook Security Terms of Service. A PDF copy and our current subprocessor list are available from the Hook Security Trust Center. For a countersigned copy, email support@hooksecurity.co.
DPA at a glance
The questions reviewers ask most, answered in plain English. This summary is for convenience only, is not part of the DPA and is not legally binding. If anything here differs from the DPA below, the DPA controls.
Who is responsible for the data?
Your organization is the controller. Hook Security is the processor and only processes your people's data to deliver the service, following your instructions. (Section 2, Annex 1)
What data does Hook process?
Work contact details (name, work email, title, department, manager), simulation and training activity, and basic technical data such as IP address and browser. No sensitive data, such as health or government ID numbers, should be uploaded. (Section 5(c), Annex 1)
Do you sell data or train AI on it?
No. We do not sell or share personal data, and we do not use it, or let our subprocessors use it, to train or improve AI models without your written approval. (Section 10, Annex 3)
Are passwords captured in simulations?
No. Hook does not collect or store passwords that employees enter on simulated phishing pages. (Annex 1)
How fast will you tell us about a breach?
Without undue delay and, where feasible, within 72 hours of becoming aware of a security incident affecting your data, with updates as we learn more. (Section 4(c))
Who are your subprocessors?
Six vendors: AWS, Supabase, Vercel, Cloudflare, Mailgun and PhishingBox. We give 30 days' notice before adding one, and you can object. (Section 7, Annex 5)
Where is the data stored?
In the United States, with EU hosting for EU-hosted customers. Transfers out of the EU, UK and Switzerland are covered by the EU Standard Contractual Clauses, the UK Addendum and Swiss terms. (Annex 2)
How do you prove your security?
We maintain an annual SOC 2 Type 2 report, available through our Trust Center under NDA. It generally stands in for on-site audits, which are limited to once a year. (Section 8, Annex 4)
What happens when we leave?
You can ask for a copy of your data within 30 days. We delete it within 60 days of the end of service, and backups roll off in the normal cycle. (Section 9)
Which laws does it cover?
GDPR, UK GDPR, the Swiss FADP, the CCPA and other U.S. state privacy laws, where they apply. (Section 1, Annexes 2 and 3)
We already signed a DPA with you. Which applies?
The one you signed. A separately executed DPA governs in place of this one. (Preamble)
Do we need to sign anything?
No. This DPA is part of our Terms of Service automatically. If your team needs a countersigned copy, email us and we will send one. (Preamble)
This Data Processing Addendum ("DPA") forms part of the Hook Security Terms of Service at hooksecurity.co/terms, or any other written agreement under which Hook Security Inc., a Delaware corporation ("Hook"), provides the Services to the customer that is party to it ("Customer") (the "Agreement"). It applies automatically, without signature, from the later of the Agreement's effective date and this DPA's publication date. Customer may request a countersigned copy at support@hooksecurity.co. If Customer and Hook have signed a separate data processing agreement for the Services, that agreement applies instead of this DPA.
1. Definitions
Capitalized terms not defined here have the meanings given in the Agreement.
Applicable Data Protection Laws means all privacy and data protection laws that apply to Hook's Processing of Personal Data under the Agreement, including, where applicable, GDPR, the FADP and State Privacy Laws.
Controller, Processor, Data Subject, Personal Data and Processing have the meanings given in Applicable Data Protection Laws. "Controller" includes a "business" and "Processor" includes a "service provider" or "contractor" under State Privacy Laws.
Customer Personal Data means Personal Data that Hook Processes on Customer's behalf to provide the Services. It excludes Customer personnel's business contact details that Hook uses to manage the customer relationship, and data Hook collects independently of the Services.
FADP means the Swiss Federal Act on Data Protection.
GDPR means the EU General Data Protection Regulation (2016/679) ("EU GDPR") and the EU GDPR as retained in UK law, together with the UK Data Protection Act 2018 ("UK GDPR"), as applicable.
Security Incident means a breach of Hook's security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data. It does not include unsuccessful attempts that do not compromise Customer Personal Data, such as failed log-ins, pings, port scans or blocked denial-of-service attacks.
SCCs means the standard contractual clauses approved by European Commission Decision (EU) 2021/914.
Services means the SaaS Products and related services Hook provides under the Agreement.
State Privacy Laws means the comprehensive U.S. state privacy laws, including the California Consumer Privacy Act ("CCPA"), that apply to Hook's Processing of Customer Personal Data.
Subprocessor means any third party or Hook affiliate that Hook engages to Process Customer Personal Data.
2. Roles and Scope
(a) Customer is the Controller, or a Processor acting for its own clients (for example, a managed service provider). Hook is Customer's Processor, or Subprocessor where Customer acts as a Processor. Annex 1 describes the Processing.
(b) Annex 2 applies to Processing subject to GDPR or the FADP. Annex 3 applies to Processing subject to State Privacy Laws.
(c) This DPA remains in effect for as long as Hook Processes Customer Personal Data, including after the Agreement ends.
3. Processing Instructions
(a) Hook will Process Customer Personal Data only to provide the Services and on Customer's documented instructions, which are set out in the Agreement, this DPA and Customer's configuration and use of the Services. Hook will tell Customer if it believes an instruction violates Applicable Data Protection Laws. Instructions outside the scope of the Services require a written agreement between the parties.
(b) Hook may create de-identified or aggregated data from its operation of the Services, as permitted by the Agreement. Hook will keep that data in de-identified form, will not attempt to re-identify it, and will require any recipient to do the same. De-identified and aggregated data is not Customer Personal Data.
4. Security and Security Incidents
(a) Hook will maintain the technical and organizational measures described in Annex 4. Hook may update those measures but will not materially reduce the overall protection of Customer Personal Data.
(b) Hook will ensure that personnel with access to Customer Personal Data are bound by confidentiality obligations.
(c) Hook will notify Customer of a Security Incident without undue delay and, where feasible, within 72 hours of becoming aware of it. The notice will describe what is known, the steps Hook has taken and the steps Hook recommends Customer take. Hook will update Customer as it learns more and will reasonably cooperate with Customer's investigation. Notice is not an admission of fault or liability.
(d) Customer is responsible for any notices it must give to regulators, Data Subjects or others. Where such a notice identifies Hook, Customer will, where legally permitted, consult Hook in advance.
5. Customer Responsibilities
(a) Customer is responsible for having a lawful basis for the Processing, giving any required notices to and obtaining any required consents from Data Subjects, and the accuracy of the Customer Personal Data it provides.
(b) Customer is responsible for its own use of the Services, including securing its accounts and credentials and configuring the Services appropriately.
(c) Customer will not submit to the Services any government identification numbers, financial account or payment card data, health or medical information, biometric data, passwords for accounts other than the Services, personal data of children under 16, or any other special category of personal data under Applicable Data Protection Laws ("Restricted Data"), unless the parties agree otherwise in writing.
6. Data Subject Requests and Assistance
(a) If Hook receives a request from a Data Subject about Customer Personal Data, Hook will promptly forward it to Customer, unless legally prohibited, and will not respond except to direct the Data Subject to Customer.
(b) Taking into account the nature of the Processing, Hook will provide reasonable assistance to help Customer respond to Data Subject requests and to complete any data protection impact assessments or regulator consultations that relate to the Services. Hook may charge its standard professional services rates for assistance beyond the normal functionality of the Services, and will provide an estimate first.
7. Subprocessors
(a) Customer authorizes Hook to use the Subprocessors listed in Annex 5 and on Hook's Trust Center at trust.hooksecurity.co (the "Subprocessor List").
(b) Hook will bind each Subprocessor to written data protection terms at least as protective as this DPA, to the extent relevant to its services, and remains liable for each Subprocessor's performance.
(c) Hook will notify Customer at least 30 days before a new Subprocessor begins Processing Customer Personal Data, by updating the Subprocessor List and emailing Customer's designated contact. Customer may object on reasonable data protection grounds within 15 days of the notice. The parties will work in good faith to resolve the objection. If they cannot, Customer may terminate the affected Services on written notice as its sole remedy, and will pay any amounts accrued through the termination date.
8. Audits
(a) Hook maintains an annual SOC 2 Type 2 report from an independent auditor and will provide the most recent report to Customer on request, subject to confidentiality. Where that report, issued within the prior 12 months, covers the controls in question and Hook confirms no material changes since, Customer will accept it in place of an audit.
(b) Customer may otherwise audit Hook's compliance with this DPA once per year, or more often where a regulator requires it, on at least two weeks' written notice with a proposed scope. Audits will take place during business hours, under a mutually agreed plan and confidentiality terms, and without unreasonable disruption. Hook may reject an auditor who is not independent or is a Hook competitor. Customer bears the cost of any audit, including Hook's reasonable costs at its standard rates, and will share the audit results with Hook.
9. Return and Deletion
(a) When the Services end, Hook will stop Processing Customer Personal Data except as needed to return or delete it.
(b) If Customer asks in writing within 30 days after the Services end, Hook will return a copy of Customer Personal Data by secure means, or delete it, as Customer chooses. Otherwise, Hook will delete or anonymize Customer Personal Data within 60 days after the Services end.
(c) Customer Personal Data in encrypted backups will be deleted in Hook's normal backup rotation and will remain protected, and not actively Processed, until then. Hook may retain data where the law requires, and will protect it under this DPA for as long as it is retained. Hook will certify deletion on Customer's written request.
10. Artificial Intelligence
(a) Hook will not use Customer Personal Data to train, fine-tune or improve any artificial intelligence or machine learning model, and will prohibit its Subprocessors from doing so, unless Customer authorizes it in writing.
(b) The Services do not make decisions that produce legal or similarly significant effects on Data Subjects.
11. General
(a) If this DPA conflicts with the Agreement, this DPA controls. If the SCCs conflict with this DPA or the Agreement, the SCCs control for the transfers they cover.
(b) Each party's liability under this DPA and the SCCs is subject to the limitations and exclusions of liability in the Agreement, except that nothing limits a Data Subject's rights as a third-party beneficiary under the SCCs.
(c) Hook may update this DPA on written notice where needed to comply with Applicable Data Protection Laws, including to adopt a replacement transfer mechanism, provided the update does not materially reduce the protection of Customer Personal Data or materially increase Customer's obligations.
(d) Hook may send notices under this DPA using the notice terms of the Agreement or to Customer's designated account contact. Customer's access to the Services, not access to Personal Data, is the consideration Hook receives under the Agreement.
Annex 1 — Description of Processing
Data importer / Processor: Hook Security Inc., 502 East Main Street, Lakeland, Florida 33801, U.S.A. Contact: support@hooksecurity.co.
Data exporter / Controller: Customer, at the address and contact in the Agreement or Customer's account.
Services: A security awareness training platform, including simulated phishing and social engineering exercises, training content, suspicious-email reporting tools and reporting. Hook sells directly and through managed service providers.
Data Subjects: Customer's employees and contractors enrolled in the Services; Customer's administrators; and, where Customer is a managed service provider, the employees of its client organizations.
Categories of Personal Data:
- Contact and profile data: name, work email, job title, department, manager, office location and group, provided by upload or identity-provider sync.
- Account data: administrator usernames and single sign-on identifiers. Hook does not collect or store passwords that employees enter on simulated phishing pages.
- Activity data: simulation interactions (delivery, open, click, attachment and data-entry events), suspicious-email reports, and training enrollment, progress, completion and assessment results.
- Technical data: IP address, browser and device information, identifiers and timestamps.
- Reported messages: where Customer uses reporting tools in the Services, the headers and content of messages employees report.
Sensitive data: None. Restricted Data is prohibited under Section 5(c).
Frequency and nature: Continuous, as needed to provide the Services: collection, storage, sending simulated and training communications, recording interactions and producing reports.
Purpose: To provide the Services under the Agreement.
Duration and retention: The term of the Agreement, then as set out in Section 9.
Subprocessors: As listed in Annex 5 and the Subprocessor List.
Annex 2 — European Transfer Terms
1. EU transfers. For transfers of Customer Personal Data subject to the EU GDPR to a country without an EU adequacy decision, the parties enter into the SCCs, which are incorporated by reference and completed as follows:
- Module Two applies where Customer is a Controller, and Module Three where Customer is a Processor. Customer is the data exporter and Hook is the data importer. Each party is deemed to have signed the SCCs.
- Clause 7 (docking clause) does not apply.
- Clause 9: Option 2 (general written authorization) applies, with the notice period in Section 7(c) of this DPA.
- Clause 11: the optional language does not apply.
- Clauses 17 and 18: the SCCs are governed by the law of Ireland, and disputes are resolved by the courts of Ireland.
- Annex I is completed with Annex 1 of this DPA. The competent supervisory authority is the one for the EU Member State where Customer is established, or, if Customer is not established in the EU, where its EU representative is located, or otherwise where the relevant Data Subjects are located.
- Annex II is completed with Annex 4 of this DPA.
2. UK transfers. For transfers subject to the UK GDPR, the SCCs apply as amended by the UK International Data Transfer Addendum issued by the Information Commissioner's Office (version B1.0). Tables 1 to 3 are completed with the information in this DPA and Annex 2, and in Table 4 Hook, as data importer, may end the Addendum under its Section 19.
3. Swiss transfers. For transfers subject to the FADP, the SCCs apply with these changes: references to the GDPR mean the FADP; references to the EU, Union and Member States include Switzerland; the supervisory authority is the Swiss Federal Data Protection and Information Commissioner; and Data Subjects in Switzerland may bring claims in the Swiss courts.
4. Clarifications. Audits under Clauses 8.9(c) and (d) follow Section 8 of this DPA. Certification of deletion under Clauses 8.5 and 16(d) will be provided on Customer's written request. Subprocessor approvals under Section 7 are Customer's instructions for onward transfers under Clause 8.8. Customer is responsible for notifying Data Subjects and any third-party Controllers where the SCCs require it. Hook will provide a signed copy of the completed SCCs on Customer's reasonable request.
Annex 3 — U.S. State Privacy Terms
For Customer Personal Data subject to State Privacy Laws, Hook acts as a service provider, contractor or processor, and:
- will not sell or share Customer Personal Data, as those terms are defined in State Privacy Laws;
- will not retain, use or disclose Customer Personal Data for any purpose other than providing the Services, or outside its direct business relationship with Customer;
- will not combine Customer Personal Data with personal data from other sources, except as State Privacy Laws permit;
- will provide the level of privacy protection State Privacy Laws require, and will notify Customer if it can no longer meet its obligations; and
- agrees that Customer may take reasonable steps, including audits under Section 8, to confirm compliance and to stop and remediate unauthorized use.
Notice under Section 7 satisfies any requirement to notify Customer of Subprocessors. Hook certifies that it understands and will comply with these restrictions.
Annex 4 — Security Measures
- Governance: a written information security program based on NIST and ISO/IEC 27001, reviewed at least annually, with named owners and an annual SOC 2 Type 2 examination by an independent auditor.
- Encryption: Customer Personal Data encrypted at rest using AES-256 or an equivalent provider-managed standard, and in transit using TLS 1.2 or higher.
- Access control: least-privilege, role-based access; unique accounts; multi-factor authentication and single sign-on for Hook personnel; prompt removal of access when roles change.
- Logical separation: Customer data is logically separated from other customers' data.
- Monitoring: logging and monitoring of system access and activity.
- Network and application security: firewalls, network segmentation, vulnerability scanning and timely patching.
- Change management: testing and approval of changes to production systems.
- Incident response: a documented incident response plan, a retained third-party incident response team, and an annual tabletop exercise.
- Resilience: daily encrypted backups; a recovery time objective of 4 hours and recovery point objective of 15 minutes; quarterly backup restoration checks and an annual recovery test.
- Physical security: production systems hosted with cloud providers that maintain independently audited physical and environmental controls.
- Vendor management: security review of each Subprocessor before engagement.
- Secure disposal: media and data disposed of so they cannot be recovered.
Annex 5 — Subprocessors
The current list is also maintained at trust.hooksecurity.co.
| Subprocessor | Location | Purpose |
|---|---|---|
| Amazon Web Services, Inc. | United States; EU (Germany, Ireland) for EU-hosted customers | Cloud hosting |
| Supabase, Inc. | United States | Application database |
| Vercel Inc. | United States | Application hosting |
| Cloudflare, Inc. | United States; global edge network | Content delivery, DNS and network security |
| Mailgun Technologies, Inc. | United States; EU for EU-hosted customers | Platform notification email |
| PhishingBox, LLC | United States; EU (Germany) for EU-hosted customers | Delivery of simulated phishing and training content; suspicious-email reporting |