ZD-AYM-21Version 1.0Version date: 2026-09-06Effective date: «effective date»

Zero Door Platform Privacy Notice

1. Who we are and how to reach us

Zerone Siber Güvenlik Limited Şirketi (“Zerone”, “we”, “us”) develops and operates Zero Door, a file integrity monitoring and compliance platform sold to organisations. This notice explains how we process personal data and what rights you have in relation to it.

ControllerZerone Siber Güvenlik Limited Şirketi
Registered officeYenibaraj Mahallesi, Nursultan Nazarbayev Bulvarı No: 1, İç Kapı No: 3, Seyhan / Adana, Türkiye
Central registration (MERSİS) number0998199408600001
Trade registryAdana Chamber of Commerce, registry number 98809
Tax identification number9981994086 (Ziyapaşa Tax Office)
Telephone+90 507 806 21 37
Data protection contactprivacy@zeronesecurity.com
Security contactsecurity@zeronesecurity.com
General contactcontact@zeronesecurity.com
Representative in the European Union (GDPR Article 27)«EU representative: name and address»

We have not designated a data protection officer under Article 37 GDPR, and we do not hold ourselves out as having one. All matters arising under this notice, including the exercise of the rights described in section 14, are handled by our data protection contact, Hüseyin Volkan Akyüz, Director, who is reachable at privacy@zeronesecurity.com and at the postal address above. A request addressed to that contact is treated exactly as a request addressed to the controller.

If you are in the European Economic Area, you may address any matter under this notice either to our representative or directly to the contacts above.

2. What this notice covers, and what it does not

This notice covers personal data that Zerone processes as controller, that is, where Zerone decides why and how the data is processed. In practice this means:

  • personal data of individuals who use the Zero Door SaaS console at zerodoor.zeronesecurity.com;
  • personal data of individuals who apply for an account, are invited to one, or contact us about the product;
  • personal data of the individual representatives of our corporate customers and prospective customers, for contracting, billing and support.

This notice does not cover:

  • Server telemetry collected by a customer’s agents. For that data the customer organisation is the controller and Zerone is a processor. Section 3 explains the split and tells you where to direct a request.
  • On-premises installations. Where a customer installs Zero Door on infrastructure it controls, the customer operates the console and is the controller of its own users’ account data. Zerone has no access to that installation unless the customer grants it.
  • Our marketing website. Its processing is described in the separate website privacy and cookie notice.
  • Third-party destinations a customer chooses to connect. See section 9.

3. Our two capacities, and where to send a request

DataWho is the controllerWhere to send a request
Console account and profile data, authentication and session records, sign-up and invitation records, audit trail of console actions, support correspondence, billing and invoicing recordsZeroneprivacy@zeronesecurity.com
File integrity events, file access events, file paths, operating system usernames, process names and command line arguments, process ancestry, hostnames and server IP addresses collected by the agent from the customer’s serversThe customer organisation that deployed the agents. Zerone is its processorYour employer or the organisation that operates the monitored systems. If you send such a request to us, we will not act on it ourselves. We will tell you so, and we will pass it to the customer without undue delay so that the customer can respond

We do not use customer telemetry for our own purposes. We do not use it to develop or improve our products, to train models, to benchmark, to measure or to build profiles, and we do not sell, rent or disclose it for advertising. That restriction is a contractual undertaking in our Data Processing Agreement, and it is the reason no product improvement purpose appears in section 5.

One category sits outside that description, and we state it here rather than leave it implied. Clause B.2.8 of our Data Processing Agreement defines a separate category called Threat Intelligence Data: the file hash, the file size, package and vulnerability identifiers, and the first and last time a file was seen, derived from files observed across all deployments. That category is not the customer’s personal data, and clause B.4.4 permits us to use it to produce, maintain and improve a threat and software intelligence function that operates for the benefit of all of our customers, provided the use identifies no customer, no data subject and no deployment. It is held in a shared legitimacy record that every installation reads, so that a file already known to be legitimate or malicious is recognised everywhere. That record carries no tenant identifier, no hostname and no username. It does, in the implementation running today, store the full file path next to the hash, and a file path can carry an operating system account name, for example a path beneath a user home directory such as /home/ or C:\Users\ followed by that account name. This is the one respect in which something observed on a customer’s systems feeds a function that serves all of our customers, and it is described in the same terms in clause B.4.6 and Annex I of the Data Processing Agreement. If we stop sending the path, or begin masking it, we will update that Annex and our published sub-processor list accordingly.

4. Categories of personal data we process as controller

CategoryFields
Identity and profileFirst name, last name, corporate email address, role and permission assignment, optional profile image, preferred language and display time zone
AuthenticationPassword hash, password history hashes, multi-factor authentication secret and recovery code hashes, passkey credential identifier and public key, API key hash and prefix, identity provider identifiers and the email address asserted by a customer’s SAML, OIDC or LDAP directory
Sign-in and sessionIP address, user agent string and the browser, operating system and device type derived from it, sign-in and last activity timestamps, failed sign-in counters and lockout expiry, session token hashes
Sign-up and invitationEmail address, name, organisation name and requested workspace name, password hash, verification token hash, registrable domain, and the IP address and user agent recorded at the moment the terms and this notice were acknowledged
Acceptance recordsWhich version of which legal document was accepted, when, from which IP address and user agent, and by which route
Audit trailActor identifier and email address, action, affected resource, description, IP address, user agent, and the previous and new values of a changed setting
BillingLegal name, tax identification number (which, for a sole trader in Türkiye, may be a national identity number), tax office, billing address, invoice email address, registered electronic mail address, invoices and payment events
Support and feedbackEmail address, message body, page and application version, conversation and escalation metadata. Message bodies are free text and may contain whatever the sender chooses to write
Requests you make to usData subject request records including the requester’s email address, name, the verification method used, the description of the request and our response notes

We do not deliberately collect any special category data within the meaning of Article 9 GDPR, and we ask you not to include such data in free text fields. We do not process criminal offence data within the meaning of Article 10.

The legal basis differs by purpose. Where more than one basis is stated, each applies to the part of the processing it is stated against.

#PurposeData usedLegal basis
P1Creating, authenticating and administering console accounts for the individuals a customer authorises, including sessions, roles, multi-factor authentication and API keysIdentity and profile, authentication, sign-in and session, invitationArticle 6(1)(f), legitimate interests. See below
P2Processing a sign-up application submitted by an individual personally, up to the point the account is createdSign-upArticle 6(1)(b), steps at the request of the data subject prior to entering into a contract
P3Securing the platform: preventing and detecting unauthorised access, abuse, credential stuffing and account takeover, rate limiting, lockout, bot verification and incident responseSign-in and session, authentication countersArticle 6(1)(f), legitimate interests, read with Recital 49
P4Maintaining a tamper evident audit trail of administrative and security relevant actions in the consoleAudit trailArticle 6(1)(f), legitimate interests. Where a customer is itself subject to an audit or record keeping obligation under Union or Member State law, the same processing also supports that customer’s compliance
P5Keeping evidence of which version of our terms and of this notice an individual acceptedAcceptance recordsArticle 6(1)(f), legitimate interests
P6Operating the subscription: invoicing, collection, refunds, tax documentation and accountingBilling, identityArticle 6(1)(c) where the obligation arises under Union or Member State law. Where the obligation arises under Turkish commercial and tax law, which is not Union or Member State law and therefore cannot ground Article 6(1)(c), we rely on Article 6(1)(f), our legitimate interest in complying with the law of the country in which we are established
P7Providing support, answering questions and handling feedbackSupport and feedback, identityArticle 6(1)(f), legitimate interests
P8Sending service and lifecycle messages that are not marketing: verification, password reset, security alerts, licence expiry and account statusIdentity, sign-upArticle 6(1)(f), legitimate interests
P9Sending commercial electronic messages about our productsIdentityArticle 6(1)(a), consent. You may withdraw it at any time, with no effect on processing carried out before withdrawal
P10Establishing, exercising or defending legal claims, and responding to lawful requests from competent authoritiesAny of the above, as relevantArticle 6(1)(f), legitimate interests, and Article 6(1)(c) where a Union or Member State legal obligation applies
P11Handling requests made under this notice and recording how we handled themRequests you make to usArticle 6(1)(c), compliance with Articles 12 to 22 GDPR

The legitimate interests we rely on, stated. For P1: delivering the contracted service only to the individuals the customer organisation has authorised, on an authenticated and individually attributable basis, so that access can be granted, restricted and withdrawn. For P3: keeping a security product and the data inside it resistant to compromise, which Recital 49 recognises as a legitimate interest of providers of security technologies and services. For P4: being able to reconstruct, after the fact, who changed what in a system that customers rely on for their own compliance evidence. For P5: being able to prove what was agreed and when. For P6: meeting the commercial and tax law obligations that apply to us where we are established. For P7: answering the person who wrote to us. For P8: telling account holders about things that affect their account and its security. For P10: being able to bring or defend a claim.

Why Article 6(1)(f) and not Article 6(1)(b) for account data. The subscription or licence agreement is concluded between Zerone and the customer organisation, which is a legal person. If you hold a Zero Door account because your employer or another organisation gave you one, you are not a party to that agreement. Article 6(1)(b) requires a contract “to which the data subject is party”, and the European Data Protection Board has confirmed that the necessity test in that provision has an independent meaning in Union law and is not satisfied merely because processing is written into a contract (Guidelines 2/2019 on the processing of personal data under Article 6(1)(b) in the context of the provision of online services to data subjects, version 2.0, adopted 8 October 2019). We therefore rely on Article 6(1)(f) for account data and have carried out and documented the balancing test that provision requires. A summary of our Legitimate Interests Assessment is available on request from privacy@zeronesecurity.com. The position is different for P2: an individual who personally submits a sign-up application is taking steps at their own request prior to entering into a contract, and Article 6(1)(b) applies to that step.

Public authorities. The second subparagraph of Article 6(1) GDPR excludes public authorities from relying on Article 6(1)(f) for processing carried out in the performance of their tasks. A public sector customer must therefore identify its own basis, ordinarily Article 6(1)(c) or 6(1)(e), for the processing it carries out as controller. That does not affect the basis on which Zerone processes account data as controller.

6. Where the data comes from (Article 14 GDPR)

Some of the personal data we hold about you does not come from you. It reaches us as follows.

SourceWhat we receive
An administrator at your organisationYour name, corporate email address and role, when an account or an invitation is created for you
Your organisation’s SAML, OIDC or LDAP directory, where single sign on is configuredYour external identifier, the email address asserted by the directory, your name and, where the customer maps them, group and role attributes
Another user of the consoleYour email address, where they invite you or reference you in support correspondence
The customer’s monitored servers, through the agentOperating system usernames, file paths, process command lines and similar operational identifiers. Zerone is a processor for this data; see section 3
Our payment providersConfirmation of payment status, invoice and buyer details returned to us after a transaction
An IP reputation service, where the customer has enabled itA reputation score and country code associated with the IP address from which a sign-in was made. See section 9
Publicly available sourcesThe corporate registration details of a prospective customer, and business contact details published by that organisation

Where we obtain personal data from a source other than you, we provide this notice within a reasonable period and at the latest within one month of obtaining the data, or at the time of our first communication with you if that is earlier, in accordance with Article 14(3) GDPR. Where the data was obtained from your organisation for the purpose of creating your account, that notice is given to you at first sign-in.

7. Recipients

We do not sell personal data, and we do not disclose it for anyone else’s marketing.

Category of recipientWhy
Our hosting provider, OVHcloud group. Contracting entity: OVH Hosting Limited, Enterprise House, O’Brien Road, Carlow R93Y0Y3, Ireland, company number 468585, VAT number 9520632RPhysical servers, data centre, network and hardware for the SaaS platform. Processor
PrismTrail, our own threat and software intelligence service, operated by Zerone in TürkiyeFile hash, file path, file size, package and vulnerability lookups, licence validation and provisioning. Not a separate legal entity
Our transactional email relay, «transactional email provider»Delivery of verification, security, lifecycle and report email. Processor
Object storage, where configuredStorage of generated reports and database backups. Processor. The product default is the local filesystem, in which case no third party is involved
Cloudflare, Inc., where bot verification is enabledVerification of the sign-in challenge. The request carries your IP address, browser information and the challenge token. The product default is off
Payment providers: Moka United Ödeme Hizmetleri ve Elektronik Para Kuruluşu A.Ş. for Turkish Lira collection, and Paddle for global collectionPayment processing. Both act as independent controllers in respect of the payment data they process under their own regulatory duties. Paddle acts as merchant of record and, as a matter of law, is the seller to the buyer
Professional advisers: lawyers, accountants and auditorsAdvice, audit and the defence of claims, under a duty of confidentiality
Competent authorities and courtsWhere we are legally required to disclose, and only to the extent required
A successor in a corporate transactionWhere all or part of our business is transferred, subject to the same protections

The current list of our sub-processors, with their names, countries of establishment, the services they provide and the transfer mechanism relied on for each, is published at https://zeronesecurity.com/legal/sub-processors and is also available on request. Customers may subscribe to advance notification of changes at subprocessors@zeronesecurity.com.

8. International transfers

We state this in both directions, because both apply.

8.1 Where the data is stored. The production infrastructure of the Zero Door cloud edition runs on servers rented from OVH Hosting Limited, established in Ireland, and is located within the European Union, and therefore inside the European Economic Area. In the target architecture the product runs in the Paris (France) region of OVH Public Cloud. Storage of your data does not take place outside the EEA. The hosting region is agreed in the Order Form and is not changed without the Customer’s prior consent. A separate region in Türkiye is on the roadmap; data residency in Türkiye is not offered today and the provider for that region has not yet been selected.

8.2 Access from Türkiye is a transfer, and we treat it as one. Zerone is established in Türkiye and its personnel administer, support and troubleshoot the platform remotely from Türkiye. Under the European Data Protection Board’s Guidelines 05/2021 on the interplay between the application of Article 3 and the provisions on international transfers (version 2.0, adopted 14 February 2023), remote access from a third country is a transfer even where the data remains stored in the EEA and is only displayed on a screen. Türkiye does not benefit from an adequacy decision of the European Commission. We therefore do not rely on Article 45 GDPR. The safeguard we rely on is the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914 of 4 June 2021, applying Module Two (controller to processor) or Module Three (processor to processor) according to the capacity in which we act for the transfer in question, supported by a documented transfer impact assessment and by the supplementary technical and organisational measures identified in it. You may obtain a copy of the clauses, with commercially confidential terms redacted, by writing to privacy@zeronesecurity.com.

8.3 Access by hosting provider group companies outside the EEA. Our hosting provider’s published sub-processor information records group companies established in Canada, the United Kingdom, India, Singapore, Australia and Morocco, any of which may access the infrastructure remotely in the course of support and maintenance, and its data processing agreement expressly reserves remote processing for security and maintenance purposes. We therefore do not state that data is processed only in a single country. What we state is this: the data is stored within the European Union, and may be accessed remotely for support and maintenance by group companies of the hosting provider established outside the European Union. Those transfers are covered by the standard contractual clauses annexed to the hosting provider’s own data processing agreement.

8.4 Transfers out of Türkiye under Turkish law. Because Zerone is established in Türkiye, our storage of platform data in the European Union is also a transfer abroad within the meaning of Article 9 of Turkish Law No. 6698 on the Protection of Personal Data. The Turkish Personal Data Protection Board has issued no adequacy decision for any country, including Ireland and France. That transfer accordingly rests on the standard contracts adopted by the Board, which are notified to the Turkish Personal Data Protection Authority within five business days of signature. This is stated for completeness; it does not reduce the protection described in paragraphs 8.1 to 8.3.

8.5 Integrations that a customer chooses to enable. See section 9.

9. Integrations configured by the customer organisation

Zero Door ships with every external integration switched off. A customer organisation may switch one on using its own account and its own access key. Where it does, the customer decides the purpose, selects the destination and contracts with it. The customer is therefore responsible for its own lawful basis and, where the destination is outside the EEA, for its own transfer mechanism. Zerone is the technical channel that carries out the customer’s instruction. We describe what each integration sends so that you can see it, whether or not you are the person who enabled it.

IntegrationCountry of the recipientWhat is sent when enabled
AbuseIPDB LLC (Pennsylvania, United States)United StatesThe public IP address of a user who has just signed in to the console successfully, on every such sign-in. Private, loopback and link local addresses are not queried. The provider publishes no data processing agreement, is not certified under the EU-US Data Privacy Framework and offers no standard contractual clauses. Where this integration is enabled, the outcome is recorded in our audit trail; it does not by itself block access
VirusTotal (Google Cloud EMEA Ltd; Google LLC at group level)Ireland and the United StatesA single cryptographic file hash, in the request path. No file path, hostname, username or IP address is sent
Have I Been Pwned, Pwned Passwords (Superlative Enterprises Pty Ltd, Queensland, Australia; served from a cloud region in the United States)Australia and the United StatesOnly the first five characters of the SHA-1 hash of a candidate password, under the k-anonymity model, with the padding header enabled. Neither the password, nor its full hash, nor any email address or username is sent, and matching is performed locally. A customer may point the check at an internal mirror instead
Slack, Microsoft Teams, PagerDuty, Jira Cloud, generic webhooksAs determined by the customer and the providerAlert fields: hostname, file path, severity, title, change type, alert and server identifiers
SIEM and log forwarding (Syslog, CEF, LEEF, JSON)The customer’s own collectorServer identifier and hostname, file path, file hash, change type, description, scan identifier
The customer’s own SMTP relay, object storage, timestamping service, LDAP directory and identity providerAs selected by the customerNotification and report content, report and backup files, hash values, directory queries and authentication flow fields

If you want to know whether a particular integration is enabled in the console you use, ask the organisation that operates it. A platform administrator can disable any of them installation wide.

10. Retention

We keep personal data no longer than is necessary for the purposes in section 5. The periods below are the product’s defaults. A customer organisation may shorten them for its own workspace; it cannot extend them beyond the ceiling attached to its licence tier.

DataRetention
Account and profile dataFor as long as the account exists. Deleting an account deletes the account record and the authentication data attached to it
Session records7 days
Sign-up applicationsUntil expiry if never completed; 30 days after the account is created
Invitation recordsUntil accepted or revoked, or until the workspace record is deleted
Acceptance records for legal documentsFor the life of the account or workspace. These records are append only by design, because their purpose is to be reliable evidence of what was accepted; they are removed when the account or workspace is deleted
Audit trail2555 days (7 years) by default. This period is set so that a single default serves customers whose own record keeping duties are long, and it may be shortened by the customer. The differing bases for the underlying classes are: records derived from commercial books and invoices, 10 years under Article 82 of the Turkish Commercial Code; tax records, 5 years under Article 253 of the Tax Procedure Law; security and access audit records, 2 years as our own operating default
File access telemetry (usernames, file paths, process command lines, process ancestry)30 days
File integrity events and security events30 days
Alerts90 days
Scans and scan differences180 days
Completed reports90 days. Failed report jobs, 14 days
Decommissioned server records180 days
Notification delivery records30 days once delivered; 90 days for undeliverable messages
Database backups30 days by default
Billing records and invoices10 years, under Article 82 of the Turkish Commercial Code
Support correspondence and feedbackFor the duration of the customer relationship and, thereafter, for the applicable limitation period for claims
Records of requests made under this notice10 years from closure of the request, as evidence that we handled it properly. The period follows the general limitation period in Article 146 of the Turkish Code of Obligations and the ten year retention of commercial correspondence in Article 82(5) of the Turkish Commercial Code

Deletion from our primary stores does not immediately remove a record from backups. Backups roll off on the schedule above, after which the data is gone from them too. A record that has been deleted from the primary store is not restored into it by a backup restore except where the whole system is being recovered, and in that event the deletion is reapplied.

11. Automated decision making and profiling

We do not take decisions about you based solely on automated processing that produce legal effects concerning you or similarly significantly affect you, within the meaning of Article 22(1) GDPR. We want to be precise rather than to claim that nothing is automated, because parts of the product are:

  • Alert severity classification. The platform classifies file integrity findings automatically and assigns a severity. It classifies events on systems, not people, and it produces no decision about any individual. Where a finding names a username, that name is an attribute of the event, not the object of an assessment.
  • Temporary account lockout. After a configured number of failed sign-in attempts an account is locked automatically for a limited period. The measure is technical, time limited and reversible, and an administrator at your organisation can lift it. We do not consider it to produce a legal effect concerning you or to affect you similarly significantly. In any event, if you are locked out and consider the outcome wrong, contact us at privacy@zeronesecurity.com and a person will review it.
  • IP reputation and bot verification. Where a customer has enabled the IP reputation integration, a score returned by the third party is recorded against a sign-in. Where bot verification is configured, a challenge is scored by the provider. Neither is used to make a decision about you beyond allowing or repeating a challenge, and neither results in a profile being built about you.

We do not carry out profiling for marketing, credit assessment, employee evaluation, or any comparable purpose.

12. Cookies and browser storage

The Zero Door console is an authenticated application. It sets no analytics, advertising, measurement or cross site tracking cookies, loads no third-party scripts, and serves its fonts from its own origin. Its content security policy restricts network connections initiated by the page to the application’s own origin, so the browser cannot reach an external host. The only cookies set are:

CookiePurposeLifetime
next-auth.session-token (__Secure- prefixed over HTTPS)Keeps you signed in7 days, cleared on sign out
next-auth.csrf-tokenCross site request forgery protectionSession
next-auth.callback-urlWhere to return you after sign inSession
NEXT_LOCALERecords the interface language you selected. It is written only when you actively choose a language, never merely because you loaded a page, and it carries no identifier1 year

The console also keeps a small number of interface preferences in your browser’s local storage, such as sidebar state, display time zone and dismissed hints, and, for platform operators only, the workspace currently being operated. These stay on your device.

All of the above are strictly necessary for a service you requested, or are set on your own explicit action. Full details, including how to clear them, are in the Cookie Policy at https://zeronesecurity.com/legal/cookies.

13. Is providing your data a requirement, and what happens if you do not

DataRequirementIf you do not provide it
Name, corporate email address and a credentialContractual requirement of the agreement between Zerone and your organisation. You are under no statutory obligation to provide itAn account cannot be created and you cannot use the console. Your organisation may be able to give you access by another route; that is a matter between you and your organisation
Multi-factor authentication enrolment, where your organisation requires itContractual, as configured by your organisationSign-in cannot be completed while the requirement is in force
Billing details, for the person who contracts with usStatutory requirement under Turkish tax and commercial law for the contracting partyWe cannot issue a compliant invoice and cannot supply the paid service
Consent to commercial electronic messagesNeither statutory nor contractualYou simply do not receive marketing. Nothing else changes, and no service is withheld
Information supporting a request under section 14Necessary for us to verify your identityWe may be unable to act on the request, because we will not disclose personal data to an unverified requester

14. Your rights

Subject to the conditions in the GDPR, you have the right to:

RightArticleWhat it means here
Access15Obtain confirmation of whether we process your data, a copy of it, and the information in this notice as it applies to you
Rectification16Have inaccurate data corrected and incomplete data completed
Erasure17Have data deleted where one of the grounds in Article 17(1) applies. This right is limited where we must keep the data to comply with a legal obligation, or to establish, exercise or defend legal claims. What happens in practice, stated exactly: when your account is deleted, the account record and the authentication data attached to it are permanently deleted from our relational database and your sessions are ended. Your email address remains in the audit trail entries held in our analytical store until that record reaches the end of its own retention period in section 10. We rely on Article 17(3)(b), because we keep the audit trail to meet our own security obligation, and on Article 17(3)(e), because its evidential value depends on entries not being edited or selectively removed. Audit trail entries are removed as a whole only where the workspace itself is deleted, which the customer organisation may request and which we carry out where no legal hold applies. Our acceptance records are append only for the same reason and are removed when the account or workspace is deleted. Erasure reaches backups when the backup concerned rolls off the schedule in section 10
Restriction18Have processing restricted in the circumstances listed in Article 18(1)
Data portability20Receive the data you provided to us, in a structured, commonly used and machine readable format, for processing based on consent or on contract and carried out by automated means
Objection21Object at any time, on grounds relating to your particular situation, to processing we base on Article 6(1)(f). We will stop unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is for the establishment, exercise or defence of legal claims. Where we process for direct marketing, you may object at any time and we will stop unconditionally
Withdraw consent7(3)Withdraw consent at any time where processing is based on consent, including for commercial electronic messages. Withdrawal is as easy as giving consent and does not affect the lawfulness of processing carried out before it
Lodge a complaint77See below

How to exercise them. Write to privacy@zeronesecurity.com, or to the postal address in section 1. You may use the Data Subject Request Form published with this notice, but you are not obliged to. Tell us which right you are exercising and give us enough information to find your records. We will verify your identity before acting, and we will not use the information you give us for verification for any other purpose.

Our response. We respond without undue delay and in any event within one month of receipt. Where a request is complex, or where we have received a number of requests from you, we may extend that period by up to two further months, and we will tell you within the first month that we have done so and why. Our response is free of charge. Where a request is manifestly unfounded or excessive, in particular because it is repetitive, we may charge a reasonable fee based on our administrative costs or refuse to act; if we refuse, we will tell you why and how to challenge it.

Requests about server telemetry. If your request concerns file access or file integrity data collected from your employer’s systems, we are the processor and cannot answer it ourselves. We will tell you so promptly and forward the request to the customer organisation, which is the controller. Section 3 explains this.

Complaints. If you are in the European Economic Area, you may lodge a complaint with the supervisory authority of the Member State of your habitual residence, of your place of work, or of the place of the alleged infringement. The Commission publishes contact details for every national supervisory authority. If you are in the United Kingdom, the Information Commissioner’s Office is the competent authority. You may also complain to the Turkish Personal Data Protection Authority, Kişisel Verileri Koruma Kurumu, whose procedures are published at kvkk.gov.tr. We would prefer that you raise the matter with us first, at privacy@zeronesecurity.com, but you are not required to.

15. How we protect the data

The platform enforces tenant isolation at the database level, requires multi-factor authentication capability for console accounts, encrypts specific sensitive fields at the application layer using AES-256-GCM, writes an integrity chained audit trail, and restricts administrative access on a role basis with every privileged action logged. Our infrastructure provider’s dedicated server service falls within the scope of its ISO/IEC 27001 certification. Zerone itself does not hold an ISO/IEC 27001 certificate and makes no such claim. The full description of our technical and organisational measures is published separately and is available to customers on request.

Personal data may appear in free text fields, in file paths and in process command line arguments captured from monitored servers. We do not control what a customer’s systems put there. Access to that data inside the platform is restricted by role, and its retention is short by default, as section 10 shows.

16. Children

Zero Door is a business product sold to organisations. It is not directed at children and we do not knowingly process the personal data of anyone under 16. If you believe we hold such data, tell us at privacy@zeronesecurity.com and we will delete it.

17. Changes to this notice

We keep this notice under review and update it when our processing changes. The version and effective date appear at the top. Where a change is material, we notify account holders before it takes effect, through the console or by email, and, where the change requires it, we ask for a fresh acknowledgement at next sign in. Previous versions are retained and are available on request.

All legal texts