Key Points:
- We collect only what you submit through our forms, plus basic server logs and bot-protection data — no advertising or behavioural tracking.
- We use your information to respond to you and deliver the services you request, and we never sell it.
- We share it only with the providers that run our website, email, and secure portal — never with advertisers.
- You can access, correct, delete, export, restrict, or object to the use of your data, and complain to a regulator.
1. Information We Collect
1.1 Information You Provide
We collect the information you choose to submit through our forms:
- Contact and inquiries: your name, email address, and message.
- Free security assessment: your name, work email, phone, company details, and your answers about your security posture.
- Service, partner, and penetration-test requests: your name, work email, company, and the details needed to scope the work.
- Security-testing authorizations: signer name and title, company legal name, the domains or application in scope, and a record of your acceptance (the exact accepted text, a timestamp, your IP address, and your electronic signature) kept as legal evidence that the testing was authorized.
1.2 Information Collected Automatically
Our website is a static site with no advertising or analytics trackers, so automatic collection is limited to:
- Server logs: your IP address, browser type, and the time of your request, recorded by our hosting provider to operate and secure the site.
- Bot protection: when you submit a form, Cloudflare Turnstile runs a security check that may process your IP address and set a strictly necessary cookie to tell humans from automated bots.
- We do not use analytics or advertising cookies, and we do not build behavioural profiles of you.
2. Why We Use Your Information, and Our Legal Basis
We use your information for the purposes below. Where the DIFC Data Protection Law (DIFC Law No. 5 of 2020), the EU or UK GDPR, or a similar law applies, our legal basis is shown in brackets:
- To respond to your inquiries and requests [your consent; our legitimate interest in answering you].
- To scope and deliver the services you request, including assessments, scans, and penetration tests [performance of a contract; your consent].
- To keep a record of the security-testing authorizations you give us [legal obligation; our legitimate interest in evidencing authorized testing].
- To secure our website and prevent fraud and abuse [our legitimate interest in security].
- To meet our legal, regulatory, and tax obligations [legal obligation].
We do not send marketing emails unless you ask us to, and we do not make automated decisions that produce legal effects about you.
5. International Data Transfers
Zeroday Technology, LLC is based in the United States, and some of our providers process data in the United States and other countries. Where we transfer personal data out of the DIFC, the EEA, or the United Kingdom, we rely on appropriate safeguards — such as the European Commission’s Standard Contractual Clauses or an equivalent mechanism — a copy of which you can request at privacy@zeroday.group.
6. Data Retention
We keep personal data only as long as necessary, then delete or anonymise it:
- Inquiries and form submissions: up to 24 months after our last contact with you.
- Security-testing authorization records: up to 12 months after the engagement, as legal evidence.
- Server logs: up to 90 days.
7. Your Rights
Depending on where you live, you have some or all of these rights over your personal data:
- Access — a copy of the data we hold about you.
- Rectification — correction of inaccurate data.
- Erasure — deletion of your data.
- Restriction — limiting how we process it.
- Portability — a copy in a portable, machine-readable format.
- Objection — to processing based on our legitimate interests.
- Withdraw consent — at any time, without affecting processing already carried out.
To exercise any of these, email privacy@zeroday.group; we respond within the time the applicable law requires. You also have the right to complain to a data-protection authority — for DIFC matters, the DIFC Commissioner of Data Protection; in the EEA or UK, your local supervisory authority.
8. Data Security
We apply appropriate technical and organizational measures to protect your personal data, including encryption in transit and at rest, access controls, and least-privilege handling. No method of transmission or storage is completely secure, but we work to protect your data and to notify you and the relevant authority of a breach where the law requires.
9. Children’s Privacy
Our website and services are intended for businesses and adults. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us data, contact privacy@zeroday.group and we will delete it.
10. Changes to This Policy
We may update this Policy from time to time. We will update the “Last Updated” date above, and we will post material changes on this page.
11. Contact Us
For any privacy question, or to exercise your rights, contact the controller — Zeroday Technology, LLC — at privacy@zeroday.group.