Compliance with GDPR
Details on how ZeroCloak supports GDPR compliance for our customers and their users in the EU, EEA, and UK.
Last updated: June 1, 2026
01Our GDPR role
For click-level personal data our customers submit to ZeroCloak for scoring (such as an end visitor's IP address), ZeroCloak acts as a data processor and the customer acts as the data controller. For account and billing data of our direct customers, ZeroCloak acts as the data controller.
02Legal basis for data processing
We process personal data on the basis of contractual necessity (to provide the fraud-scoring service you signed up for), legitimate interest (such as securing our platform and improving detection accuracy), and consent where required, such as for optional marketing communications.
03Rights of data subjects
Individuals in the EU/EEA and UK have the right to access, rectify, erase, restrict, or port their personal data, and to object to certain processing. Requests can be submitted to our privacy team and will be honored within one month as required by law.
- Right of access and data portability
- Right to rectification of inaccurate data
- Right to erasure ('right to be forgotten')
- Right to restrict or object to processing
04Our data processing agreement
Business customers can request a Data Processing Agreement (DPA) that incorporates the EU Standard Contractual Clauses. Our standard DPA is available for self-service signature from the billing settings page.
05Our sub-processors
We maintain an up-to-date list of sub-processors who may access personal data to help deliver ZeroCloak, including cloud hosting, email delivery, and webhook/alerting providers. We notify customers of material sub-processor changes at least 30 days in advance.
06Cross-border transfers and SCCs
Where personal data is transferred outside the EU/EEA or UK, we rely on the European Commission's Standard Contractual Clauses or an equivalent adequacy mechanism to safeguard the transfer.
07Notification of data breaches
In the event of a personal data breach affecting customer data, we will notify affected customers without undue delay and, in any event, within 72 hours of becoming aware of the breach, in accordance with Article 33 of the GDPR.
08Our data protection officer
Our Data Protection Officer can be reached directly for GDPR-related inquiries, data subject requests, or to review our current DPA and sub-processor list.
09How to exercise your rights
To exercise any of the rights described above, contact our privacy team using the email below. We may need to verify your identity before processing certain requests.
Have a question about this policy?
Contact our legal & compliance team directly.
