ZeroHookZeroHook

Privacy Policy

GDPR and UK GDPR compliant notice

Last updated: July 23, 2026

Effective date: July 23, 2026

1. Data Controller

The data controller for the ZeroHook service is a sole proprietor (egyéni vállalkozó) established in Hungary, trading as ZeroHook. For privacy matters, contact [email protected].

Legal name and registered business address: Available on request via [email protected].

2. Processing Activities and Lawful Basis (Art. 13)

ActivityPersonal dataPurposeLawful basis
Account creation and loginEmail, name, optional company, auth/session metadata, optional 2FA statusProvide access to the platformArt. 6(1)(b) contract
Billing and invoicingBilling identifiers, subscription and trial statusManage paid plans, trials, and accountingArt. 6(1)(b), Art. 6(1)(c)
Domain monitoring and scan historyDomain data, audit logs, evidence logsDeliver security/compliance monitoringArt. 6(1)(b)
Organization / team collaborationMember emails, roles, invite metadataProvide shared workspace accessArt. 6(1)(b)
API accessAPI key metadata and usage signalsProvide programmatic access and abuse controlsArt. 6(1)(b), Art. 6(1)(f)
Security, abuse preventionIP, device/browser signals, reCAPTCHA scoresProtect platform integrityArt. 6(1)(f) legitimate interests
Error monitoringTechnical error events and scrubbed request metadataDetect and fix application failuresArt. 6(1)(f) legitimate interests
Marketing communications and analytics cookiesEmail preferences, analytics identifiers, consent preferencesProduct updates and service improvementArt. 6(1)(a) consent
Statistical analysis and product improvementAggregated and anonymized usage data, scan results, and security trendsIdentify common security patterns, improve service quality, and publish general market insightsArt. 6(1)(f) legitimate interests

3. Third-Party Service Providers

We maintain Data Processing Agreements with all processors listed below where required.

ProcessorPurposeData sharedCountryTransfer mechanism
StripePayments and subscription billingBilling identifiers, invoicesUSSCCs / DPF where applicable
ResendTransactional emailEmail address, message metadataUSSCCs / DPF where applicable
RailwayHostingApplication and DB-hosted dataUSSCCs
CloudflareCDN/WAFIP, request metadataGlobalSCCs / DPF where applicable
Google (OAuth)SSO loginOAuth profile identifiersUSSCCs / DPF where applicable
Google (reCAPTCHA)Abuse preventionIP/device/browser signalsUSSCCs / DPF where applicable
PostHogProduct analyticsPseudonymous usage eventsEUEU region config (eu.i.posthog.com)
SentryApplication error monitoringError events, scrubbed URLs/metadataUS/EU per project configSCCs / DPF where applicable

4. Data Retention

Retention periods currently applied in product logic:

  • Account profile: active account lifecycle; post-closure retention where legally required.
  • Monitoring/audit history (plan defaults): Free 7 days; Deliverability 30 days; Agency/Business 90 days; Compliance Evidence 365 days; Enterprise unlimited. Retention add-ons may extend these periods (including multi-year or unlimited options where purchased). Aggregated and anonymized data derived from these records may be retained indefinitely for statistical purposes and product development.
  • Billing/invoice records: retained for accounting/legal obligations.
  • Support records: retained for support operations and legal defense purposes.
  • Marketing preferences and cookie consent: retained until withdrawal/unsubscribe or consent cookie expiry (currently one year for the consent cookie).

5. Your Rights

You may exercise rights of access, rectification, erasure, restriction, objection, and data portability by contacting [email protected] or, where available in the product, by using in-app account deletion and data export features.

Account deletion is processed through the platform's account deletion flow and removes or anonymizes account-linked data subject to legal retention needs (for example billing records). Data export requests are fulfilled as a downloadable export sent by email when the export job completes.

You also have the right to lodge a complaint with your supervisory authority. EU reference list: EDPB authority directory. For Hungary, the supervisory authority is the Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH).

6. Data Controller vs. Processor (MSP / White-label)

Where an MSP, agency, or managed service customer uses ZeroHook to process domain and monitoring data for its own end clients, the MSP/agency is the Data Controller and ZeroHook acts as Data Processor.

MSP/agency customers must execute and maintain a Data Processing Agreement (DPA) with ZeroHook before processing end-client personal data. Contact [email protected] to request a DPA.

7. Security Measures

We apply appropriate technical and organizational measures for a SaaS monitoring product, including encrypted transport (HTTPS), access controls, authentication cookies with secure attributes, CSRF protections on sensitive actions, rate limiting, and abuse prevention. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.