Privacy Notice

This notice explains what information Svart Works Inc. (“Svart Works,” “we”) collects when you use the DecryptAds web application, REST API, and MCP endpoint (the “Service”), why we collect it, how we use and share it, and the choices and rights available to you.

Effective date: May 2, 2026 · Last updated: June 18, 2026.

1. Who we are

Svart Works Inc. operates DecryptAds, a programmatic supply chain transparency and ad fraud investigation tool. For most uses of the Service, Svart Works acts as a data “controller” for account and Service operations data, and as a data “processor” (or “service provider”) for content you submit on behalf of your organization. Where an enterprise agreement, Order Form, or Data Processing Addendum (“DPA”) applies, that document controls.

Controller of record: Svart Works Inc., a Delaware (USA) corporation, Wilmington, Delaware, United States. General privacy contact: privacy@decryptads.com.

2. What we collect

We collect or generate the following categories of data:

3. Why we use it

Lawful bases (UK / EU / Swiss residents). Operating the Service and providing accounts: performance of a contract with you (GDPR Art. 6(1)(b)). Securing the Service, preventing abuse, and improving the Service through aggregated / de-identified data: legitimate interests (Art. 6(1)(f)). Service announcements and security notices: legitimate interests or contract; marketing emails: consent (Art. 6(1)(a)) where required. Compliance with law and lawful requests: legal obligation (Art. 6(1)(c)). Analytics and risk indicators target hostnames and infrastructure, not natural persons; we do not use Submissions to build behavioral profiles of identifiable end-users, and we do not make solely automated decisions producing legal or similarly significant effects on individuals.

4. How Submissions are handled

Files and text you upload or paste — together with derivatives we compute from them — are processed to deliver the analyses you request. By submitting data on pages where this notice is referenced, you confirm that you have the right to share that data and that you have not included personal information, login credentials, payment data, or other sensitive content.

Inadvertent personal information. If a Submission contains personal information that should not have been included (for example, a contact email pasted into a comment field), contact privacy@decryptads.com. We will work with the submitting customer to delete or minimize that data, subject to legal hold and audit requirements.

5. Sharing

We share data only as needed:

A current sub-processor list and DPA terms are available to enterprise customers on request from privacy@decryptads.com.

6. Retention

We retain personal data only as long as needed for the purposes set out above, then delete or de-identify it. Indicative defaults (subject to legal holds, contractual commitments in your Order Form / DPA, and applicable law):

7. Security

We use technical and organizational measures including encryption in transit, role-based access, audit logging, and infrastructure hardening to protect data. No system is perfectly secure; you are responsible for protecting your account credentials and API keys, and for limiting Submissions to data you are authorized to share.

Breach notification. If we determine that a security incident has resulted in unauthorized access to or disclosure of personal data we control, we will notify affected customers and (where required) regulators without undue delay, consistent with applicable law and any DPA in place.

8. Your rights

Depending on your jurisdiction, you may have the right to:

To exercise these rights for personal data we control, contact privacy@decryptads.com. We will respond within the timeframes required by applicable law (generally within 30 to 45 days) and will not discriminate against you for exercising these rights.

For Submissions and other data we process on behalf of an enterprise customer, please direct requests to that customer’s administrator; we will support them in responding under our DPA.

9. Cookies

The public marketing pages are static HTML and do not set authentication cookies. When you sign in to the DecryptAds web application, we set a first-party signed session cookie so the browser can stay logged in. The cookie may appear in your browser under the name session. We do not currently use third-party analytics, advertising, or tracking cookies on the marketing site or in the app.

10. Children

The Service is intended for business and research use. It is not directed to children. We do not knowingly collect personal information from children under 13 (or under 16 in jurisdictions where that is the applicable threshold under the EU General Data Protection Regulation or other law). If you believe we may have collected personal information from a child, contact privacy@decryptads.com and we will delete it.

11. US privacy supplemental notice (CCPA / CPRA)

This section provides additional disclosures for California residents under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, “CCPA”), and applies to comparable rights under other US state privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas, and Oregon) where those laws apply.

We do not sell or share your personal information. We do not sell personal information for monetary or other valuable consideration, and we do not share it for cross-context behavioral advertising, as those terms are defined under the CCPA.

Your CCPA rights. California residents may request to know, access, correct, delete, or limit certain processing of their personal information, and may exercise these rights through an authorized agent (we may verify the agent’s authority and your identity). We will not discriminate against you for exercising these rights.

Submit a request to privacy@decryptads.com. For Submissions and other data we process on behalf of an enterprise customer, contact that customer’s administrator; we will support them in responding under our DPA.

12. EU / UK / Swiss supplemental notice

For individuals in the European Economic Area, the United Kingdom, and Switzerland, the lawful bases on which we process personal data are summarized in § 3. Categories of personal data, recipients, retention periods, and rights are described in §§ 2, 5, 6, and 8 of this notice.

Where this notice and any separate enterprise DPA conflict on a point relating to your organization’s data, the DPA controls.

13. Changes to this notice

We may update this notice as the Service or applicable law changes. Material changes will be communicated via the Service or by email to account holders. The “Last updated” date above reflects the most recent change.

14. Contact

Privacy questions or requests: privacy@decryptads.com. General contact options live on the Contact page; Terms of Service covers acceptable use.

Postal: Svart Works Inc., a Delaware (USA) corporation, Wilmington, Delaware, United States. Please include “Privacy Request” in the subject line so we can route the message to the right team.