Zerod as Data Processor
Version 1.0Effective from 1 August 2026
In one sentence
When you use the Zerod platform, the personal data you enter remains yours. You decide what is processed and why. We process it only to provide you with the service, following your instructions, under a signed processor agreement, and with an obligation to return it or delete it when the relationship ends.
1. Why this page exists
Article 28 GDPR requires that the relationship between a controller and its processor be documented in a contract with a mandatory minimum content.
If you are a Zerod customer, you are the controller of the personal data you manage on the platform and we are your processor. This page summarises the terms of that agreement, in plain language, so you can assess them before procurement and legal join the conversation.
The full contractual document prevails over this summary.
2. Subject matter and duration
| Subject matter | Processing of personal data by Zerod on behalf of the customer, to the extent necessary to provide the contracted services |
| Duration | The term of the service agreement, plus the agreed return or deletion period |
| Nature of the processing | Hosting, structuring, consultation, analysis, generation of documentation and making available through the platform |
3. What data we process on your behalf
When you use the Zerod platform, the personal data you enter or connect remains your responsibility. We process it solely to provide you with the service. Below we describe, at a high level, what data in fact enters the platform on your behalf.
3.1 Categories of data subjects
Depending on the modules you use, the platform may process personal data relating to:
- Your platform users — the people in your organisation who access and operate the account.
- Your employees and contractors who receive security training, sign policies or are assigned tasks, even if they are not platform users.
- Contact persons at your suppliers, in vendor assessment and security questionnaires.
- Data subjects exercising rights against you through your privacy portal (name, email and the content of their request).
- People affected by a breach you record, to the extent of the data you document about it.
- Whistleblowers and people named in a report, in the internal whistleblowing channel.
- Auditors, signatories and third parties involved in your compliance and document-signing processes.
- Asset and incident owners and authority contacts you record.
- Trust Center visitors who request access or sign a non-disclosure agreement.
3.2 Categories of data
- Professional identification and contact details.
- Role, permissions and membership of your organisation.
- Training records: assignment, progress and completion.
- Electronic signatures and signature images.
- Free-text content you or your data subjects enter: rights requests, incidents, whistleblowing reports and documentary evidence.
- Information contained in your records of processing activities and impact assessments.
- Technical findings from the analysis tools: domains, IP addresses and, where applicable, your employees' email addresses detected in public breaches.
- Activity and access logs.
3.3 Sensitive data: what happens in practice
We prefer to be direct about this, because a generic denial would not hold up.
The platform is not designed for you to record special categories of data (Art. 9 GDPR) as structured data, and the records-of-processing module lets you declare that you process special categories without storing that data in the platform itself.
However, two parts of the service may receive sensitive data by their very nature:
- The whistleblowing channel receives, by design, free text and attachments that may contain data relating to offences (Art. 10 GDPR) and, frequently, special categories (Art. 9). This is the purpose of the channel, not a side effect.
- The evidence and documents you upload are files the platform treats as opaque content: we do not inspect their contents, and they could contain personal data of any category.
For these cases we apply reinforced measures: the body of whistleblowing reports and their attachments are stored encrypted, and access is restricted to the strictly authorised roles within your organisation. Even so, you, as the controller, decide what data you enter and must assess whether a given category should be processed in the platform or by another means.
4. Our commitments
As a processor, Zerod undertakes to:
- Process the data solely on your documented instructions, including as regards international transfers, unless a legal obligation requires otherwise, in which case we will inform you beforehand where the law permits.
- Ensure the confidentiality of all authorised personnel, through an express commitment or a statutory duty.
- Apply the security measures required by Article 32 GDPR, described in section 6.
- Assist you in responding to data subject rights requests, through the platform's own features.
- Assist you in meeting your obligations regarding security, breach notification and impact assessments.
- Notify you without undue delay of any security breach affecting your data, with the information you need to meet your notification obligations within the Article 33 deadline.
- Return or delete the data at the end of the engagement, at your choice, and delete existing copies save where a legal retention obligation applies.
- Make available the information necessary to demonstrate compliance with these obligations and allow audits in accordance with section 7.
- Not process your data for our own purposes. In particular, we do not use it to train artificial intelligence models or for marketing purposes.
5. Sub-processors
The subprocessors involved in providing the service fall into the following categories:
- Cloud infrastructure and database (hosting and running the service, within the European Union).
- Transactional email (delivery of service notifications).
- Form abuse prevention (anti-abuse control).
- Artificial intelligence model provider (AI-assisted document generation features, under a prohibition on training with your data).
- Intelligence sources for attack-surface analysis (services that process your organisation's domains and IP addresses, and which, in breach analysis, may process your employees' publicly exposed email addresses).
Our commitments:
- Every sub-processor is contractually bound by the same data protection obligations we owe to you.
- We will notify you in advance of any addition or replacement of a sub-processor, and you may object on reasonable data protection grounds.
- Zerod remains liable to you for its sub-processors' compliance.
The named, up-to-date list of sub-processors is provided to customers and prospective customers under a confidentiality agreement. Request it at privacy@zerod.io.
6. Security
We apply, among others, the following technical and organisational measures:
- Encryption in transit and at rest.
- Logical segregation of each customer's data.
- Role-based access control, least privilege, and multi-factor authentication for staff.
- Activity logging and traceability of actions on the data.
- Vulnerability management, regular security testing and code review.
- Backups and recovery procedures.
- A documented incident management and breach notification procedure.
- Mandatory security and data protection training for staff.
Current details, together with our certifications, are available in the Zerod Trust Center.
7. Audit
We will make available the information necessary to demonstrate compliance with our obligations as a processor, including current audit reports and certifications.
Where that documentation is not sufficient, you may carry out or mandate an audit on reasonable notice, during business hours, without interfering with operations and subject to confidentiality, on the terms set out in the contract.
8. International transfers
Our primary infrastructure is hosted in the European Union. Where delivery of the service involves a transfer outside the European Economic Area, it relies on an adequacy decision or on Standard Contractual Clauses with any supplementary measures required, following a transfer impact assessment.
9. How to obtain the full agreement
The data processing agreement forms part of Zerod's contractual documentation. You can request it before contracting:
- By writing to privacy@zerod.io
- Through the contact form
If your organisation needs to use its own agreement template, please say so in your request.
10. Language
This document is published in Spanish and English. In the event of any discrepancy between the two versions, the Spanish version shall prevail. The signed contract prevails over this summary.
Version history
| Version | Date | Changes |
|---|---|---|
| 1.0 | 2026-08-01 | First publication. No such document existed before this date. |