Skip to content

Privacy Policy

Version 2.0Effective from 1 August 2026

Summary

We work in compliance and data protection. It would be inconsistent of us to write a policy nobody can understand. This summary does not replace the full text, but it does anticipate it:

Who we areCybersec Hub, S.L. ("Zerod"), Barcelona, Spain
What this policy coversThe data we process as a controller: website visitors, contact and demo requests, platform users and suppliers
What it does NOT coverData we process on behalf of our customers, as a processor. That is governed by contract and summarised in Zerod as Data Processor
Do we sell your dataNo. Never. Nor do we share it for advertising purposes
Do we train AI on your dataWe do not train artificial intelligence models on personal data belonging to customers or visitors
Where your data is heldHosted on Google Cloud Platform, within the European Union
How to exercise your rightsThrough our own privacy portal: ciso.zerod.io/privacy/zerod, or by writing to privacy@zerod.io
CookiesNo banner, because we use no cookies that would require one. Details in the Cookie Policy

1. Data controller

ControllerCybersec Hub, S.L. ("Zerod")
Tax ID (NIF)B-09681867
Registered officeCalle Josep Irla i Bosch, 1 — 08034 Barcelona (Spain)
General enquiriescontact@zerod.io
Privacy mattersprivacy@zerod.io

Zerod is not required to appoint a Data Protection Officer and has not appointed one voluntarily. Privacy matters are handled through privacy@zerod.io.

2. Scope: Zerod's two roles

This is the most important section of this document. Zerod processes personal data in two distinct capacities, with distinct obligations.

2.1 Zerod as data controller

We determine the purposes and means. This applies to:

  • Data relating to visitors to zerod.io.
  • Data relating to those who write to us, request a demonstration or contact us commercially.
  • Data relating to people who administer or use a Zerod platform account.
  • Data relating to our suppliers and partners.

Everything that follows in this policy refers to these processing activities.

2.2 Zerod as data processor

When a customer uses the Zerod platform, they enter or connect information that may contain personal data relating to their employees, customers, suppliers or data subjects: records of processing activities, rights requests, compliance evidence, security awareness training records or technical findings.

In relation to that data, the customer is the controller and Zerod acts solely as a processor, following their documented instructions in accordance with Article 28 GDPR.

If you have received a communication from a company that uses Zerod, or you wish to exercise your rights against that company, your counterpart is that company, not Zerod. We will pass your request on to our customer without undue delay, but we cannot resolve it on their behalf.

The conditions of that processing are described in Zerod as Data Processor and formalised in the agreement signed with each customer.

3. What data we process, why, and on what legal basis

3.1 Website visitors

CategoriesIP address, technical session identifier, browser and device type, language, pages visited, server logs
PurposesServing the website, maintaining its security and availability, detecting and preventing abuse
Legal basisLegitimate interest (Art. 6(1)(f) GDPR) in operating and protecting our infrastructure. Balancing test carried out: minimal data is processed, no profiling is performed and no cross-referencing with other sources takes place
RetentionServer logs: Per our infrastructure provider's default retention periods, which we do not modify. They are not used for any purpose other than security and technical diagnostics.

We do not use third-party analytics tools that set cookies, nor advertising or cross-site tracking technologies. See the Cookie Policy.

3.2 Contact and demonstration requests

CategoriesFirst name, surname, business email address, company, job title, telephone number if you provide it, and the content of your message. The IP address is processed transiently for submission rate-limiting, as detailed below the table
PurposesHandling your request, contacting you, preparing and delivering the demonstration you requested
Legal basisPre-contractual measures taken at the data subject's request (Art. 6(1)(b) GDPR). For abuse control, legitimate interest (Art. 6(1)(f))
Retention12 months from the last meaningful contact, unless a contractual relationship is entered into or you request erasure.

Your IP address is used solely to apply rate limits at the moment of submission. It is neither stored nor transmitted alongside the rest of your request.

3.3 Marketing communications

CategoriesProfessional identification and contact details, engagement with our communications
PurposesInforming you about Zerod products, features, content and events
Legal basisConsent (Art. 6(1)(a) GDPR) where you have given it. Legitimate interest (Art. 6(1)(f)) for communications about similar products addressed to existing customers, in accordance with Art. 21(2) LSSI
RetentionUntil you withdraw consent or object

You may unsubscribe at any time via the link included in every communication or by writing to the privacy address. It is immediate and requires no justification.

3.4 Platform account users and administrators

CategoriesName, business email address, job title, organisation, role and permissions, authentication credentials, access and activity logs
PurposesCreating and managing the account, authenticating access, providing support, maintaining traceability and security of the service, invoicing
Legal basisPerformance of the contract with the organisation you belong to (Art. 6(1)(b) GDPR). Legal obligation (Art. 6(1)(c)) for invoicing and its retention. Legitimate interest (Art. 6(1)(f)) for security logs
RetentionFor as long as the account is active. Where a service agreement exists, for its term. After closure we retain your documentation so you can continue to access the reports and audits generated, unless you request erasure, in which case we act without undue delay. Tax and accounting records, 6 years (Art. 30 of the Spanish Commercial Code).

These are account data. Content that your organisation enters into the platform is governed by section 2.2 and by the contract.

3.5 Suppliers, partners and business contacts

CategoriesProfessional identification and contact details, and information necessary for the relationship
PurposesManaging the commercial relationship, meeting contractual and legal obligations, assessing supply chain security
Legal basisPerformance of the contract (Art. 6(1)(b)) and legitimate interest (Art. 6(1)(f)) where the contact person is not the contracting party
RetentionThe duration of the relationship plus the applicable statutory limitation periods

3.6 Rights requests and privacy enquiries

CategoriesIdentification data, content of the request, supporting documentation where strictly necessary
PurposesHandling and responding to your request and evidencing that it was addressed
Legal basisLegal obligation (Art. 6(1)(c) GDPR, Arts. 12 to 22)
Retention3 years from resolution, as evidence of compliance

4. Source of the data

Data comes from you, except for:

  • Professional contact details obtained from public or publicly accessible professional sources in the course of B2B prospecting, processed on the basis of legitimate interest and with an immediate right to object.
  • Platform user data provided by the organisation that creates the account.

We do not purchase contact databases from brokers and we do not enrich profiles with third-party data.

5. Recipients

We do not sell personal data. We do not share it for advertising purposes. We do not disclose it to third parties except in the following cases.

5.1 Data processors

Providers who process data on our behalf, under a contract compliant with Article 28 GDPR, with obligations of confidentiality, security and deletion at the end of the engagement:

CategoryPurpose
Cloud infrastructure and hostingDelivery of the service and storage
Form abuse preventionProtection against automated submissions
Email and communicationsTransactional and marketing email delivery
CRM and sales managementTracking requests and customer relationships
Support and ticketingHandling incidents
Legal, tax and audit advisersCompliance with legal and contractual obligations

We do not publish the named list of processors on this website. It is provided to customers and prospective customers on request, subject to a confidentiality agreement, through the Data Processing Agreement.

5.2 Other recipients

  • Public authorities, judges and courts, where a legal obligation exists.
  • Financial institutions, for the management of payments and collections.
  • Third parties in corporate transactions, in the event of a merger, acquisition or transfer of a business line, with prior notice to data subjects.

6. International transfers

Our primary infrastructure is hosted on Google Cloud Platform, in a European region within the European Union. Backups are likewise kept within the European Union.

Some of our providers may process data outside the European Economic Area or belong to groups whose parent company is established outside the EEA, which may entail access from third countries.

In those cases we ensure that the transfer relies on one of the mechanisms provided for in Chapter V GDPR:

  • An adequacy decision of the European Commission, including the EU-US Data Privacy Framework where the provider is certified.
  • Standard Contractual Clauses approved by the European Commission, accompanied by a transfer impact assessment and supplementary measures where necessary.

You may request information on the safeguards applied to a specific processing activity by writing to the privacy address.

7. Retention periods

Specific periods are set out alongside each purpose in section 3. As a general rule:

  • We retain data for as long as the purpose that justified its collection remains valid.
  • When it ceases to be valid, we block the data: it remains available solely to judges, courts, the Public Prosecutor and competent authorities for the limitation period of any potential liabilities, with no operational access on our part.
  • Once that period has elapsed, the data is securely and irreversibly deleted.

8. Automated decision-making and artificial intelligence

We do not take automated decisions producing legal effects or similarly significant effects concerning data subjects.

The Zerod platform includes artificial-intelligence-assisted features: it uses third-party language models to generate draft policies and documentation from the information in your compliance programme. These features produce suggestions that require human review and decision; they do not replace the user's judgement and produce no automatic legal effects.

Zerod does not train models of its own. Your data is not used to train any model, in its original form or aggregated or anonymised.

9. Security measures

We apply appropriate technical and organisational measures in accordance with Article 32 GDPR, taking into account the state of the art and the risk of the processing. These include:

  • Encryption of data in transit and at rest.
  • Access control on a least-privilege basis and multi-factor authentication.
  • Logging and monitoring of system activity.
  • Regular security testing of our own systems, including penetration testing and code review.
  • Vulnerability management and an incident response procedure.
  • Security and data protection training for staff, who are bound by confidentiality obligations.
  • Security assessment of our suppliers.

Up-to-date details of our security posture and certifications are available in our Trust Center and on our Security page.

10. Your rights

You may exercise the following rights at any time:

RightWhat it allows you to doArticle
AccessFind out whether we process your data and obtain a copy15
RectificationCorrect inaccurate data or complete incomplete data16
ErasureRequest deletion where the data is no longer necessary17
RestrictionRestrict processing in certain circumstances18
PortabilityReceive your data in a structured, commonly used format, or have us transmit it to another controller20
ObjectionObject to processing based on legitimate interest on grounds relating to your particular situation21
Objection to direct marketingObject at any time, without needing to give reasons21(2)
Not to be subject to automated decisionsWhere they produce legal or similarly significant effects22
Withdraw consentAt any time, without affecting the lawfulness of prior processing7(3)

How to exercise them

Preferred channel — our privacy portal: ciso.zerod.io/privacy/zerod

It is the same portal the Zerod platform generates for our customers. We use it ourselves. Each right has its own form, the request is logged, and you can track its status.

Alternative channel: privacy@zerod.io, or by post to Calle Josep Irla i Bosch, 1 — 08034 Barcelona (Spain), stating the right you are exercising.

On identity verification

As a general rule we will not ask you for documentation to handle your request. We will only do so if there is a reasonable doubt as to your identity, in accordance with Article 12(6) GDPR — for example, if the request comes from a channel we cannot associate with you.

In that case, we will ask you by email, it will be the minimum documentation strictly necessary, and we will not keep a copy beyond what is strictly required to evidence that we handled your request. The privacy portal does not ask you for identity documents in order to submit a request.

Response time

One month from receipt, extendable by a further two months for complex requests or where a high volume of requests is received, informing you of the extension and its reasons within the first month.

Complaints to the supervisory authority

If you consider that we have not handled your request properly, you may lodge a complaint with the Spanish Data Protection Agency (AEPD): www.aepd.es — C/ Jorge Juan, 6, 28001 Madrid.

We would appreciate it if you contacted us first. It is usually quicker for you and allows us to correct whatever went wrong.

11. Minors

Our services are aimed exclusively at professionals and organisations. They are not intended for anyone under 18 and we do not knowingly collect their data. If we become aware that we have processed a minor's data without an appropriate legal basis, we will delete it.

12. Changes to this policy

We may update this policy to reflect changes in our services, in the law or in our practices. The current version and its effective date always appear in the header, and the full history at the foot of the page.

If a change is substantial and affects you as a registered user or subscriber, we will notify you with reasonable advance notice by email or by prominent notice within the service.

13. Language

This document is published in Spanish and English. In the event of any discrepancy between the two versions, the Spanish version shall prevail.

Version history

VersionDateChanges
2.02026-08-01Complete rewrite. Introduces the distinction between the controller and processor roles. Adds sections on international transfers, automated decision-making and artificial intelligence, and the source of the data. Replaces indefinite retention with purpose-specific periods. Removes the blanket requirement to provide a copy of an identity document in order to exercise rights. Removes the service availability commitment, which belongs in the contract. Removes the processing purposes of the intermediation model between customers and professionals. Consolidates the privacy contact channel. Corrects the reference to the supervisory authority. Routes the exercise of rights to Zerod's privacy portal.
1.025/03/2023Initial version, corresponding to the offensive security services intermediation model.
Privacy Policy · Zerod