Privacy Policy
GDPR and UK GDPR compliant notice
Last updated: July 23, 2026
Effective date: July 23, 2026
1. Data Controller
The data controller for the ZeroHook service is a sole proprietor (egyéni vállalkozó) established in Hungary, trading as ZeroHook. For privacy matters, contact [email protected].
Legal name and registered business address: Available on request via [email protected].
2. Processing Activities and Lawful Basis (Art. 13)
| Activity | Personal data | Purpose | Lawful basis |
|---|---|---|---|
| Account creation and login | Email, name, optional company, auth/session metadata, optional 2FA status | Provide access to the platform | Art. 6(1)(b) contract |
| Billing and invoicing | Billing identifiers, subscription and trial status | Manage paid plans, trials, and accounting | Art. 6(1)(b), Art. 6(1)(c) |
| Domain monitoring and scan history | Domain data, audit logs, evidence logs | Deliver security/compliance monitoring | Art. 6(1)(b) |
| Organization / team collaboration | Member emails, roles, invite metadata | Provide shared workspace access | Art. 6(1)(b) |
| API access | API key metadata and usage signals | Provide programmatic access and abuse controls | Art. 6(1)(b), Art. 6(1)(f) |
| Security, abuse prevention | IP, device/browser signals, reCAPTCHA scores | Protect platform integrity | Art. 6(1)(f) legitimate interests |
| Error monitoring | Technical error events and scrubbed request metadata | Detect and fix application failures | Art. 6(1)(f) legitimate interests |
| Marketing communications and analytics cookies | Email preferences, analytics identifiers, consent preferences | Product updates and service improvement | Art. 6(1)(a) consent |
| Statistical analysis and product improvement | Aggregated and anonymized usage data, scan results, and security trends | Identify common security patterns, improve service quality, and publish general market insights | Art. 6(1)(f) legitimate interests |
3. Third-Party Service Providers
We maintain Data Processing Agreements with all processors listed below where required.
| Processor | Purpose | Data shared | Country | Transfer mechanism |
|---|---|---|---|---|
| Stripe | Payments and subscription billing | Billing identifiers, invoices | US | SCCs / DPF where applicable |
| Resend | Transactional email | Email address, message metadata | US | SCCs / DPF where applicable |
| Railway | Hosting | Application and DB-hosted data | US | SCCs |
| Cloudflare | CDN/WAF | IP, request metadata | Global | SCCs / DPF where applicable |
| Google (OAuth) | SSO login | OAuth profile identifiers | US | SCCs / DPF where applicable |
| Google (reCAPTCHA) | Abuse prevention | IP/device/browser signals | US | SCCs / DPF where applicable |
| PostHog | Product analytics | Pseudonymous usage events | EU | EU region config (eu.i.posthog.com) |
| Sentry | Application error monitoring | Error events, scrubbed URLs/metadata | US/EU per project config | SCCs / DPF where applicable |
4. Data Retention
Retention periods currently applied in product logic:
- Account profile: active account lifecycle; post-closure retention where legally required.
- Monitoring/audit history (plan defaults): Free 7 days; Deliverability 30 days; Agency/Business 90 days; Compliance Evidence 365 days; Enterprise unlimited. Retention add-ons may extend these periods (including multi-year or unlimited options where purchased). Aggregated and anonymized data derived from these records may be retained indefinitely for statistical purposes and product development.
- Billing/invoice records: retained for accounting/legal obligations.
- Support records: retained for support operations and legal defense purposes.
- Marketing preferences and cookie consent: retained until withdrawal/unsubscribe or consent cookie expiry (currently one year for the consent cookie).
5. Your Rights
You may exercise rights of access, rectification, erasure, restriction, objection, and data portability by contacting [email protected] or, where available in the product, by using in-app account deletion and data export features.
Account deletion is processed through the platform's account deletion flow and removes or anonymizes account-linked data subject to legal retention needs (for example billing records). Data export requests are fulfilled as a downloadable export sent by email when the export job completes.
You also have the right to lodge a complaint with your supervisory authority. EU reference list: EDPB authority directory. For Hungary, the supervisory authority is the Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH).
6. Data Controller vs. Processor (MSP / White-label)
Where an MSP, agency, or managed service customer uses ZeroHook to process domain and monitoring data for its own end clients, the MSP/agency is the Data Controller and ZeroHook acts as Data Processor.
MSP/agency customers must execute and maintain a Data Processing Agreement (DPA) with ZeroHook before processing end-client personal data. Contact [email protected] to request a DPA.
7. Security Measures
We apply appropriate technical and organizational measures for a SaaS monitoring product, including encrypted transport (HTTPS), access controls, authentication cookies with secure attributes, CSRF protections on sensitive actions, rate limiting, and abuse prevention. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.