GDPR and UK GDPR compliant notice

Privacy Policy

Last updated: September 6, 2026

Effective date: September 6, 2026

1. Data Controller

The data controller for the ZeroHook service is Ronyecz Regő Botond e.v., a sole proprietor (egyéni vállalkozó) established in Hungary and trading as ZeroHook. For privacy matters, contact [email protected].

  • Registered seat: 6066 Tiszaalpár, Bethlen Gábor utca 30., Hungary
  • Tax number (adószám): 92352168-1-23
  • Registration number (nyilvántartási szám): 62776646

The full set of service-provider details is published in our Legal Notice.

2. Processing Activities and Lawful Basis (Art. 13)

ActivityPersonal dataPurposeLawful basis
Account creation and loginEmail, name, optional company, auth/session metadata, optional 2FA statusProvide access to the platformArt. 6(1)(b) contract
Billing and invoicingBilling identifiers, subscription and trial statusManage paid plans, trials, and accountingArt. 6(1)(b), Art. 6(1)(c)
Domain monitoring and scan historyDomain data, audit logs, evidence logsDeliver security/compliance monitoringArt. 6(1)(b)
Organization / team collaborationMember emails, roles, invite metadataProvide shared workspace accessArt. 6(1)(b)
API accessAPI key metadata and usage signalsProvide programmatic access and abuse controlsArt. 6(1)(b), Art. 6(1)(f)
Security, abuse preventionIP, device/browser signals, reCAPTCHA scoresProtect platform integrityArt. 6(1)(f) legitimate interests
Error monitoringTechnical error events and scrubbed request metadataDetect and fix application failuresArt. 6(1)(f) legitimate interests
Marketing communications and analytics cookiesEmail preferences, analytics identifiers, consent preferencesProduct updates and service improvementArt. 6(1)(a) consent
Statistical analysis and product improvementAggregated cookieless pageview totals (path, country code, referrer host, cookie-choice bucket), plus anonymized scan results and security trends. IP addresses are not stored.Measure site traffic including visitors who reject analytics cookies, identify common security patterns, and improve the serviceArt. 6(1)(f) legitimate interests

3. Third-Party Service Providers

We maintain Data Processing Agreements with all processors listed below where required.

ProcessorPurposeData sharedCountryTransfer mechanism
StripePayments and subscription billingBilling identifiers, invoicesUSSCCs / DPF where applicable
ResendTransactional emailEmail address, message metadataUSSCCs / DPF where applicable
Coolify (self-hosted VPS)HostingApplication and DB-hosted dataEUDPA / SCCs as applicable
CloudflareCDN/WAFIP, request metadataGlobalSCCs / DPF where applicable
Google (OAuth)SSO loginOAuth profile identifiersUSSCCs / DPF where applicable
Google (reCAPTCHA)Abuse preventionIP/device/browser signalsUSSCCs / DPF where applicable
PostHogProduct analytics (cookieless when analytics cookies are declined)Pseudonymous usage events; without consent a server-side daily-rotating hash instead of an identifierEUEU region config (eu.i.posthog.com)
SentryApplication error monitoringError events, scrubbed URLs/metadataUS/EU per project configSCCs / DPF where applicable

4. Data Retention

Retention periods currently applied in product logic:

  • Account profile: active account lifecycle; post-closure retention where legally required.
  • Monitoring/audit history (plan defaults): Free 7 days; Domain Monitor 30 days; Agency/MSP 90 days; Compliance Evidence Pack 365 days; Enterprise unlimited. Retention add-ons may extend these periods (including multi-year or unlimited options where purchased). Aggregated and anonymized data derived from these records may be retained indefinitely for statistical purposes and product development.
  • Billing/invoice records: retained for accounting/legal obligations.
  • Support records: retained for support operations and legal defense purposes.
  • Marketing preferences and cookie consent: retained until withdrawal/unsubscribe or consent cookie expiry (currently one year for the consent cookie).
  • Cookieless site traffic aggregates (pageviews by path, country, referrer host, and cookie choice): retained for up to 13 months, then deleted.

5. Your Rights

You may exercise rights of access, rectification, erasure, restriction, objection, and data portability by contacting [email protected] or, where available in the product, by using in-app account deletion and data export features.

Account deletion is processed through the platform's account deletion flow and removes or anonymizes account-linked data subject to legal retention needs (for example billing records). Data export requests are fulfilled as a downloadable export sent by email when the export job completes.

You also have the right to lodge a complaint with your supervisory authority. EU reference list: EDPB authority directory. For Hungary, the supervisory authority is the Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH).

6. Data Controller vs. Processor (MSP / White-label)

Where an MSP, agency, or managed service customer uses ZeroHook to process domain and monitoring data for its own end clients, the MSP/agency is the Data Controller and ZeroHook acts as Data Processor.

MSP/agency customers must execute and maintain a Data Processing Agreement (DPA) with ZeroHook before processing end-client personal data. Contact [email protected] to request a DPA.

7. Security Measures

We apply appropriate technical and organizational measures for a SaaS monitoring product, including encrypted transport (HTTPS), access controls, authentication cookies with secure attributes, CSRF protections on sensitive actions, rate limiting, and abuse prevention. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.