Privacy Policy
Version 2.0Effective from 1 August 2026
Summary
We work in compliance and data protection. It would be inconsistent of us to write a policy nobody can understand. This summary does not replace the full text, but it does anticipate it:
| Who we are | Cybersec Hub, S.L. ("Zerod"), Barcelona, Spain |
| What this policy covers | The data we process as a controller: website visitors, contact and demo requests, platform users and suppliers |
| What it does NOT cover | Data we process on behalf of our customers, as a processor. That is governed by contract and summarised in Zerod as Data Processor |
| Do we sell your data | No. Never. Nor do we share it for advertising purposes |
| Do we train AI on your data | We do not train artificial intelligence models on personal data belonging to customers or visitors |
| Where your data is held | Hosted on Google Cloud Platform, within the European Union |
| How to exercise your rights | Through our own privacy portal: ciso.zerod.io/privacy/zerod, or by writing to privacy@zerod.io |
| Cookies | No banner, because we use no cookies that would require one. Details in the Cookie Policy |
1. Data controller
| Controller | Cybersec Hub, S.L. ("Zerod") |
| Tax ID (NIF) | B-09681867 |
| Registered office | Calle Josep Irla i Bosch, 1 — 08034 Barcelona (Spain) |
| General enquiries | contact@zerod.io |
| Privacy matters | privacy@zerod.io |
Zerod is not required to appoint a Data Protection Officer and has not appointed one voluntarily. Privacy matters are handled through privacy@zerod.io.
2. Scope: Zerod's two roles
This is the most important section of this document. Zerod processes personal data in two distinct capacities, with distinct obligations.
2.1 Zerod as data controller
We determine the purposes and means. This applies to:
- Data relating to visitors to
zerod.io. - Data relating to those who write to us, request a demonstration or contact us commercially.
- Data relating to people who administer or use a Zerod platform account.
- Data relating to our suppliers and partners.
Everything that follows in this policy refers to these processing activities.
2.2 Zerod as data processor
When a customer uses the Zerod platform, they enter or connect information that may contain personal data relating to their employees, customers, suppliers or data subjects: records of processing activities, rights requests, compliance evidence, security awareness training records or technical findings.
In relation to that data, the customer is the controller and Zerod acts solely as a processor, following their documented instructions in accordance with Article 28 GDPR.
If you have received a communication from a company that uses Zerod, or you wish to exercise your rights against that company, your counterpart is that company, not Zerod. We will pass your request on to our customer without undue delay, but we cannot resolve it on their behalf.
The conditions of that processing are described in Zerod as Data Processor and formalised in the agreement signed with each customer.
3. What data we process, why, and on what legal basis
3.1 Website visitors
| Categories | IP address, technical session identifier, browser and device type, language, pages visited, server logs |
| Purposes | Serving the website, maintaining its security and availability, detecting and preventing abuse |
| Legal basis | Legitimate interest (Art. 6(1)(f) GDPR) in operating and protecting our infrastructure. Balancing test carried out: minimal data is processed, no profiling is performed and no cross-referencing with other sources takes place |
| Retention | Server logs: Per our infrastructure provider's default retention periods, which we do not modify. They are not used for any purpose other than security and technical diagnostics. |
We do not use third-party analytics tools that set cookies, nor advertising or cross-site tracking technologies. See the Cookie Policy.
3.2 Contact and demonstration requests
| Categories | First name, surname, business email address, company, job title, telephone number if you provide it, and the content of your message. The IP address is processed transiently for submission rate-limiting, as detailed below the table |
| Purposes | Handling your request, contacting you, preparing and delivering the demonstration you requested |
| Legal basis | Pre-contractual measures taken at the data subject's request (Art. 6(1)(b) GDPR). For abuse control, legitimate interest (Art. 6(1)(f)) |
| Retention | 12 months from the last meaningful contact, unless a contractual relationship is entered into or you request erasure. |
Your IP address is used solely to apply rate limits at the moment of submission. It is neither stored nor transmitted alongside the rest of your request.
3.3 Marketing communications
| Categories | Professional identification and contact details, engagement with our communications |
| Purposes | Informing you about Zerod products, features, content and events |
| Legal basis | Consent (Art. 6(1)(a) GDPR) where you have given it. Legitimate interest (Art. 6(1)(f)) for communications about similar products addressed to existing customers, in accordance with Art. 21(2) LSSI |
| Retention | Until you withdraw consent or object |
You may unsubscribe at any time via the link included in every communication or by writing to the privacy address. It is immediate and requires no justification.
3.4 Platform account users and administrators
| Categories | Name, business email address, job title, organisation, role and permissions, authentication credentials, access and activity logs |
| Purposes | Creating and managing the account, authenticating access, providing support, maintaining traceability and security of the service, invoicing |
| Legal basis | Performance of the contract with the organisation you belong to (Art. 6(1)(b) GDPR). Legal obligation (Art. 6(1)(c)) for invoicing and its retention. Legitimate interest (Art. 6(1)(f)) for security logs |
| Retention | For as long as the account is active. Where a service agreement exists, for its term. After closure we retain your documentation so you can continue to access the reports and audits generated, unless you request erasure, in which case we act without undue delay. Tax and accounting records, 6 years (Art. 30 of the Spanish Commercial Code). |
These are account data. Content that your organisation enters into the platform is governed by section 2.2 and by the contract.
3.5 Suppliers, partners and business contacts
| Categories | Professional identification and contact details, and information necessary for the relationship |
| Purposes | Managing the commercial relationship, meeting contractual and legal obligations, assessing supply chain security |
| Legal basis | Performance of the contract (Art. 6(1)(b)) and legitimate interest (Art. 6(1)(f)) where the contact person is not the contracting party |
| Retention | The duration of the relationship plus the applicable statutory limitation periods |
3.6 Rights requests and privacy enquiries
| Categories | Identification data, content of the request, supporting documentation where strictly necessary |
| Purposes | Handling and responding to your request and evidencing that it was addressed |
| Legal basis | Legal obligation (Art. 6(1)(c) GDPR, Arts. 12 to 22) |
| Retention | 3 years from resolution, as evidence of compliance |
4. Source of the data
Data comes from you, except for:
- Professional contact details obtained from public or publicly accessible professional sources in the course of B2B prospecting, processed on the basis of legitimate interest and with an immediate right to object.
- Platform user data provided by the organisation that creates the account.
We do not purchase contact databases from brokers and we do not enrich profiles with third-party data.
5. Recipients
We do not sell personal data. We do not share it for advertising purposes. We do not disclose it to third parties except in the following cases.
5.1 Data processors
Providers who process data on our behalf, under a contract compliant with Article 28 GDPR, with obligations of confidentiality, security and deletion at the end of the engagement:
| Category | Purpose |
|---|---|
| Cloud infrastructure and hosting | Delivery of the service and storage |
| Form abuse prevention | Protection against automated submissions |
| Email and communications | Transactional and marketing email delivery |
| CRM and sales management | Tracking requests and customer relationships |
| Support and ticketing | Handling incidents |
| Legal, tax and audit advisers | Compliance with legal and contractual obligations |
We do not publish the named list of processors on this website. It is provided to customers and prospective customers on request, subject to a confidentiality agreement, through the Data Processing Agreement.
5.2 Other recipients
- Public authorities, judges and courts, where a legal obligation exists.
- Financial institutions, for the management of payments and collections.
- Third parties in corporate transactions, in the event of a merger, acquisition or transfer of a business line, with prior notice to data subjects.
6. International transfers
Our primary infrastructure is hosted on Google Cloud Platform, in a European region within the European Union. Backups are likewise kept within the European Union.
Some of our providers may process data outside the European Economic Area or belong to groups whose parent company is established outside the EEA, which may entail access from third countries.
In those cases we ensure that the transfer relies on one of the mechanisms provided for in Chapter V GDPR:
- An adequacy decision of the European Commission, including the EU-US Data Privacy Framework where the provider is certified.
- Standard Contractual Clauses approved by the European Commission, accompanied by a transfer impact assessment and supplementary measures where necessary.
You may request information on the safeguards applied to a specific processing activity by writing to the privacy address.
7. Retention periods
Specific periods are set out alongside each purpose in section 3. As a general rule:
- We retain data for as long as the purpose that justified its collection remains valid.
- When it ceases to be valid, we block the data: it remains available solely to judges, courts, the Public Prosecutor and competent authorities for the limitation period of any potential liabilities, with no operational access on our part.
- Once that period has elapsed, the data is securely and irreversibly deleted.
8. Automated decision-making and artificial intelligence
We do not take automated decisions producing legal effects or similarly significant effects concerning data subjects.
The Zerod platform includes artificial-intelligence-assisted features: it uses third-party language models to generate draft policies and documentation from the information in your compliance programme. These features produce suggestions that require human review and decision; they do not replace the user's judgement and produce no automatic legal effects.
Zerod does not train models of its own. Your data is not used to train any model, in its original form or aggregated or anonymised.
9. Security measures
We apply appropriate technical and organisational measures in accordance with Article 32 GDPR, taking into account the state of the art and the risk of the processing. These include:
- Encryption of data in transit and at rest.
- Access control on a least-privilege basis and multi-factor authentication.
- Logging and monitoring of system activity.
- Regular security testing of our own systems, including penetration testing and code review.
- Vulnerability management and an incident response procedure.
- Security and data protection training for staff, who are bound by confidentiality obligations.
- Security assessment of our suppliers.
Up-to-date details of our security posture and certifications are available in our Trust Center and on our Security page.
10. Your rights
You may exercise the following rights at any time:
| Right | What it allows you to do | Article |
|---|---|---|
| Access | Find out whether we process your data and obtain a copy | 15 |
| Rectification | Correct inaccurate data or complete incomplete data | 16 |
| Erasure | Request deletion where the data is no longer necessary | 17 |
| Restriction | Restrict processing in certain circumstances | 18 |
| Portability | Receive your data in a structured, commonly used format, or have us transmit it to another controller | 20 |
| Objection | Object to processing based on legitimate interest on grounds relating to your particular situation | 21 |
| Objection to direct marketing | Object at any time, without needing to give reasons | 21(2) |
| Not to be subject to automated decisions | Where they produce legal or similarly significant effects | 22 |
| Withdraw consent | At any time, without affecting the lawfulness of prior processing | 7(3) |
How to exercise them
Preferred channel — our privacy portal: ciso.zerod.io/privacy/zerod
It is the same portal the Zerod platform generates for our customers. We use it ourselves. Each right has its own form, the request is logged, and you can track its status.
Alternative channel: privacy@zerod.io, or by post to Calle Josep Irla i Bosch, 1 — 08034 Barcelona (Spain), stating the right you are exercising.
On identity verification
As a general rule we will not ask you for documentation to handle your request. We will only do so if there is a reasonable doubt as to your identity, in accordance with Article 12(6) GDPR — for example, if the request comes from a channel we cannot associate with you.
In that case, we will ask you by email, it will be the minimum documentation strictly necessary, and we will not keep a copy beyond what is strictly required to evidence that we handled your request. The privacy portal does not ask you for identity documents in order to submit a request.
Response time
One month from receipt, extendable by a further two months for complex requests or where a high volume of requests is received, informing you of the extension and its reasons within the first month.
Complaints to the supervisory authority
If you consider that we have not handled your request properly, you may lodge a complaint with the Spanish Data Protection Agency (AEPD): www.aepd.es — C/ Jorge Juan, 6, 28001 Madrid.
We would appreciate it if you contacted us first. It is usually quicker for you and allows us to correct whatever went wrong.
11. Minors
Our services are aimed exclusively at professionals and organisations. They are not intended for anyone under 18 and we do not knowingly collect their data. If we become aware that we have processed a minor's data without an appropriate legal basis, we will delete it.
12. Changes to this policy
We may update this policy to reflect changes in our services, in the law or in our practices. The current version and its effective date always appear in the header, and the full history at the foot of the page.
If a change is substantial and affects you as a registered user or subscriber, we will notify you with reasonable advance notice by email or by prominent notice within the service.
13. Language
This document is published in Spanish and English. In the event of any discrepancy between the two versions, the Spanish version shall prevail.
Version history
| Version | Date | Changes |
|---|---|---|
| 2.0 | 2026-08-01 | Complete rewrite. Introduces the distinction between the controller and processor roles. Adds sections on international transfers, automated decision-making and artificial intelligence, and the source of the data. Replaces indefinite retention with purpose-specific periods. Removes the blanket requirement to provide a copy of an identity document in order to exercise rights. Removes the service availability commitment, which belongs in the contract. Removes the processing purposes of the intermediation model between customers and professionals. Consolidates the privacy contact channel. Corrects the reference to the supervisory authority. Routes the exercise of rights to Zerod's privacy portal. |
| 1.0 | 25/03/2023 | Initial version, corresponding to the offensive security services intermediation model. |