GDPR and UK GDPR compliant notice
Privacy Policy
Last updated: September 6, 2026
Effective date: September 6, 2026
1. Data Controller
The data controller for the ZeroHook service is Ronyecz Regő Botond e.v., a sole proprietor (egyéni vállalkozó) established in Hungary and trading as ZeroHook. For privacy matters, contact [email protected].
- Registered seat: 6066 Tiszaalpár, Bethlen Gábor utca 30., Hungary
- Tax number (adószám): 92352168-1-23
- Registration number (nyilvántartási szám): 62776646
The full set of service-provider details is published in our Legal Notice.
2. Processing Activities and Lawful Basis (Art. 13)
| Activity | Personal data | Purpose | Lawful basis |
|---|---|---|---|
| Account creation and login | Email, name, optional company, auth/session metadata, optional 2FA status | Provide access to the platform | Art. 6(1)(b) contract |
| Billing and invoicing | Billing identifiers, subscription and trial status | Manage paid plans, trials, and accounting | Art. 6(1)(b), Art. 6(1)(c) |
| Domain monitoring and scan history | Domain data, audit logs, evidence logs | Deliver security/compliance monitoring | Art. 6(1)(b) |
| Organization / team collaboration | Member emails, roles, invite metadata | Provide shared workspace access | Art. 6(1)(b) |
| API access | API key metadata and usage signals | Provide programmatic access and abuse controls | Art. 6(1)(b), Art. 6(1)(f) |
| Security, abuse prevention | IP, device/browser signals, reCAPTCHA scores | Protect platform integrity | Art. 6(1)(f) legitimate interests |
| Error monitoring | Technical error events and scrubbed request metadata | Detect and fix application failures | Art. 6(1)(f) legitimate interests |
| Marketing communications and analytics cookies | Email preferences, analytics identifiers, consent preferences | Product updates and service improvement | Art. 6(1)(a) consent |
| Statistical analysis and product improvement | Aggregated cookieless pageview totals (path, country code, referrer host, cookie-choice bucket), plus anonymized scan results and security trends. IP addresses are not stored. | Measure site traffic including visitors who reject analytics cookies, identify common security patterns, and improve the service | Art. 6(1)(f) legitimate interests |
3. Third-Party Service Providers
We maintain Data Processing Agreements with all processors listed below where required.
| Processor | Purpose | Data shared | Country | Transfer mechanism |
|---|---|---|---|---|
| Stripe | Payments and subscription billing | Billing identifiers, invoices | US | SCCs / DPF where applicable |
| Resend | Transactional email | Email address, message metadata | US | SCCs / DPF where applicable |
| Coolify (self-hosted VPS) | Hosting | Application and DB-hosted data | EU | DPA / SCCs as applicable |
| Cloudflare | CDN/WAF | IP, request metadata | Global | SCCs / DPF where applicable |
| Google (OAuth) | SSO login | OAuth profile identifiers | US | SCCs / DPF where applicable |
| Google (reCAPTCHA) | Abuse prevention | IP/device/browser signals | US | SCCs / DPF where applicable |
| PostHog | Product analytics (cookieless when analytics cookies are declined) | Pseudonymous usage events; without consent a server-side daily-rotating hash instead of an identifier | EU | EU region config (eu.i.posthog.com) |
| Sentry | Application error monitoring | Error events, scrubbed URLs/metadata | US/EU per project config | SCCs / DPF where applicable |
4. Data Retention
Retention periods currently applied in product logic:
- Account profile: active account lifecycle; post-closure retention where legally required.
- Monitoring/audit history (plan defaults): Free 7 days; Domain Monitor 30 days; Agency/MSP 90 days; Compliance Evidence Pack 365 days; Enterprise unlimited. Retention add-ons may extend these periods (including multi-year or unlimited options where purchased). Aggregated and anonymized data derived from these records may be retained indefinitely for statistical purposes and product development.
- Billing/invoice records: retained for accounting/legal obligations.
- Support records: retained for support operations and legal defense purposes.
- Marketing preferences and cookie consent: retained until withdrawal/unsubscribe or consent cookie expiry (currently one year for the consent cookie).
- Cookieless site traffic aggregates (pageviews by path, country, referrer host, and cookie choice): retained for up to 13 months, then deleted.
5. Your Rights
You may exercise rights of access, rectification, erasure, restriction, objection, and data portability by contacting [email protected] or, where available in the product, by using in-app account deletion and data export features.
Account deletion is processed through the platform's account deletion flow and removes or anonymizes account-linked data subject to legal retention needs (for example billing records). Data export requests are fulfilled as a downloadable export sent by email when the export job completes.
You also have the right to lodge a complaint with your supervisory authority. EU reference list: EDPB authority directory. For Hungary, the supervisory authority is the Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH).
6. Data Controller vs. Processor (MSP / White-label)
Where an MSP, agency, or managed service customer uses ZeroHook to process domain and monitoring data for its own end clients, the MSP/agency is the Data Controller and ZeroHook acts as Data Processor.
MSP/agency customers must execute and maintain a Data Processing Agreement (DPA) with ZeroHook before processing end-client personal data. Contact [email protected] to request a DPA.
7. Security Measures
We apply appropriate technical and organizational measures for a SaaS monitoring product, including encrypted transport (HTTPS), access controls, authentication cookies with secure attributes, CSRF protections on sensitive actions, rate limiting, and abuse prevention. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.