1. Introduction
ZT INFOSEC (“Company,” “we,” “our,” or “us”) is committed to protecting your privacy and ensuring transparency in how we collect, use, process, and safeguard your personal information. This Privacy Policy applies to all ZT INFOSEC services, including:
- Complimentary Security Assessment Tool (free reconnaissance service)
- Risk Assessment SaaS Platform (subscription-based)
- Professional Security Consulting Services (engagement-based)
- The ZT INFOSEC website (https://ztinfosec.com)
Please read this Privacy Policy carefully. If you do not agree with our practices, please do not use our services.
We comply with the General Data Protection Regulation (GDPR) for EU residents, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) for California residents, and other applicable data protection regulations, including PIPEDA, LGPD, and POPIA.
2. What Personal Data We Collect
2.1 Information you provide directly
Depending on which ZT INFOSEC service you use, you may provide:
| Data field | Services | Required? | Type |
|---|---|---|---|
| First name | All services | Yes | Personal data (PII) |
| Last name | All services | Yes | Personal data (PII) |
| Work email address | All services | Yes | Personal data (PII) |
| Company name | Assessment Tool, Consulting | Optional | Business information |
| Company domain | Assessment Tool, SaaS Platform | Yes (if applicable) | Technical data |
| Job title / role | SaaS Platform, Consulting | Optional | Professional information |
| Phone number | Consulting services | Optional | Contact information |
| Company address | Consulting, SaaS contracts | Optional | Business information |
| Bank account information | SaaS Platform (wire/deposit payment) | Yes (if applicable) | Financial data |
| Cryptocurrency wallet address | SaaS Platform (Bitcoin payment) | Yes (if applicable) | Financial data |
| Invoice / payment details | SaaS Platform (subscription) | Yes (if applicable) | Transaction data |
| Document uploads | SaaS Platform, Consulting | Optional | Compliance / system data |
| Security configuration data | SaaS Platform | As submitted | Technical data |
What we do NOT collect:
- Credit card or payment card holder data (PCI/CHD)
- Passwords or authentication credentials from assessed domains
- Sensitive personal information (SSN, driver’s license, health data)
- Behavioral tracking or cookies on the customer portal
- Raw personal IP addresses of form submitters
- Data from unauthorized reconnaissance or intrusion
2.2 Data generated during service delivery
Complimentary Assessment Tool: submission and completion timestamps; reconnaissance findings from public sources (DNS records, SSL/TLS certificate details, HTTP headers and server banners, discovered subdomains, resolved IP addresses, open ports and running services, web technology detection, WHOIS registration data); AI-generated analysis; risk rating (Critical, High, Medium, Low, Informational); and the generated PDF report.
Risk Assessment SaaS Platform: account creation and login timestamps; assessment submissions and completion dates; system configurations you upload or describe; security scan results and historical data; compliance evaluation findings; custom reports and executive dashboards; and user activity logs within your account.
Professional Consulting Services: engagement scope and timeline; assessment reports and findings; recommendations and remediation guidance; communication records and meeting notes; and deliverables specific to your engagement.
Website interaction: pages visited and time spent (if analytics is enabled), form submissions, email subscriptions, support inquiries, and download history.
2.3 Information from third parties
We may collect information about you from public sources (Certificate Transparency logs, WHOIS databases, DNS records, public security databases), publicly available reconnaissance platforms such as Censys.io, and your organization (for example, if someone on your team shares domain registration data).
3. Legal Basis for Processing (GDPR Article 6)
| Data category | Basis | Justification |
|---|---|---|
| Contact information (name, email) | Consent | You provide it via form or registration |
| Service delivery data | Contractual necessity | Required to provide the service you requested |
| Assessment findings | Consent + contractual | You requested the assessment |
| System configurations (SaaS) | Contractual necessity | Required for SaaS platform functionality |
| Payment information | Contractual necessity | Required for billing (SaaS subscriptions) |
| Device / browser information | Legitimate interest | Security, fraud prevention, service optimization |
| Engagement communications | Contractual necessity | Required for consulting delivery |
We have legitimate interests in preventing fraud and abuse of our services, maintaining service security, improving functionality and user experience, defending against legal claims, and complying with legal obligations. These interests are balanced against your privacy rights.
4. How We Use Your Data
4.1 Service delivery
- Generate assessments and reports based on the data you provide or request
- Deliver reports and findings via email or secure portal
- Provide support and consulting services related to your engagement
- Maintain your account and service access
- Customize recommendations to your specific infrastructure and needs
4.2 Communication
- Send assessment results and reports
- Notify you of service updates, changes, or security issues
- Respond to support requests and inquiries
- Schedule consultations or meetings (consulting services)
- Send billing and account information (subscription services)
4.3 Service improvement
- Analyze aggregated, anonymized findings to improve assessment accuracy
- Identify trends in security posture across industries
- Enhance our tools and methodologies based on findings
- Develop new features and services based on customer needs
- Conduct security research (with anonymized data only)
4.4 Security and compliance
- Prevent unauthorized scanning and misuse of assessment tools
- Detect and prevent fraud and abuse
- Maintain audit logs for compliance and incident response
- Verify authorization to request assessments of submitted domains
- Comply with legal requests from law enforcement
4.5 Marketing and business development
- Notify you of new services or special offers (with your consent)
- Reference your company as a customer (with your permission)
- Develop case studies (with your explicit written approval)
- Conduct industry research (anonymized data)
4.6 What we do NOT do with your data
- We do NOT sell or rent personal data to third parties
- We do NOT share findings with assessed domains without your authorization
- We do NOT publish assessment results publicly
- We do NOT use data for automated profiling or scoring
- We do NOT share data with competitors or business partners without consent
- We do NOT use data for purposes unrelated to your service
5. Data Storage and Retention
5.1 Where your data is stored
| Data type | Storage location | Encryption |
|---|---|---|
| Personal data (name, email, domain) | ZT INFOSEC local data center | AES-256 at rest |
| Assessment findings | ZT INFOSEC local data center | AES-256 at rest |
| Payment information (bank details, crypto address) | ZT INFOSEC local data center | AES-256 at rest |
| Documents / uploads | ZT INFOSEC local data center | AES-256 at rest |
| Support communications | Email system + backup | TLS in transit |
| Application logs | ZT INFOSEC local data center | Hashed PII (SHA-256) |
ZT INFOSEC does not process or store credit card data. We accept payments via wire transfer, bank deposit, and Bitcoin; bank account and cryptocurrency wallet information is encrypted and stored securely in our local data center. All data in transit is encrypted using TLS 1.2 or higher (HTTPS).
5.2 Retention periods by service
| Service / data | Retention |
|---|---|
| Assessment Tool — personal data and findings | 90 days, then soft-deleted (30-day recovery period) |
| Assessment Tool — PDF report | 30 days, then permanently deleted |
| Assessment Tool — application logs (hashed) | 30 days, then permanently deleted |
| SaaS Platform — account data, results, documents | Duration of subscription, deleted 30 days after cancellation |
| SaaS Platform — audit logs | 2 years (for compliance) |
| Consulting — engagement documents, communications, billing | 7 years (professional and legal standards) |
| Website — contact form submissions | 1 year |
| Website — email subscriptions | Until unsubscribed + 30 days |
| Website — analytics data (if enabled) | Per analytics provider (typically 26 months) |
5.3 Data deletion and the “right to be forgotten”
You may request deletion of your personal data at any time by emailing privacy@ztinfosec.com. Include your full name, the email address you used, the service(s) you accessed, and the specific data you wish to delete.
We respond within 30 days (GDPR requirement). Personal data is soft-deleted and becomes non-recoverable after the recovery period; associated files and reports are permanently deleted; backup copies are deleted within 60 days. Data required by law (for example, accounting records retained for 7 years) is excluded.
6. Data Sharing and Third Parties
6.1 Sub-processors
We share data with the following processors only as necessary to provide the service:
| Service | Purpose | Data shared |
|---|---|---|
| Private Email (privateemail.com) | Email delivery of reports and notifications (DPA in place) | Name, work email, PDF reports |
| ZT INFOSEC local data center | Secure storage on our own infrastructure (no third party) | Reports, uploads, findings |
| Google reCAPTCHA v3 | Bot and spam prevention on forms (score not persisted) | IP address (scoring only) |
| Censys.io and public sources | Reconnaissance data for assessments | Domain names only (no personal data) |
| Analytics provider (only if enabled) | Understand engagement and improve the website | Anonymized behavior data |
Payments: we accept wire transfer, bank deposit, and Bitcoin, with no third-party payment processor. Bank account and wallet information is encrypted and stored in our local data center. ZT INFOSEC does not accept credit cards and does not process, store, or transmit credit card holder data.
6.2 What we do NOT share
- We do NOT sell or rent personal data to data brokers
- We do NOT share with marketing or advertising companies
- We do NOT share assessment findings with third parties without consent
- We do NOT share with competitors or industry rivals
- We do NOT share with government agencies except as required by law
- We do NOT process or share credit card holder data (we don’t accept credit cards)
- We do NOT share bank account information with payment processors
6.3 Disclosure for legal reasons
We may disclose your data only if required by law — under a subpoena or court order, a valid law-enforcement request, to protect rights, privacy, safety, or property, or to detect and address fraud or security issues. In such cases we will notify you in advance whenever legally permissible, provide only the minimum necessary information, and object to overly broad requests.
7. Data Security Measures
7.1 Technical security
- Encryption in transit: TLS 1.2+ (HTTPS) for all connections
- Encryption at rest: AES-256-GCM for sensitive data
- Database security: PostgreSQL with role-based access control (RBAC)
- Parameterized queries: all database access uses prepared statements
- Input validation and sanitization on all user inputs
- API security: JWT tokens with secure refresh mechanisms
- Secure session management with timeouts
- API rate limiting to prevent abuse and brute-force attacks
7.2 Administrative security
- Access limited to authorized staff on a need-to-know basis
- All administrative access to personal data is logged
- Staff undergo data protection training and background verification
- All staff sign confidentiality agreements
7.3 Data protection in logs
Personal identifiers (emails, domains) are SHA-256 hashed in application logs; API keys, credentials, and tokens are encrypted before logging; logs are accessible only to the security team and deleted after 30 days.
7.4 Infrastructure security
Enterprise-grade firewalls and DDoS protection, regular security scans and penetration testing, timely patch management, 24/7 security monitoring and alerting, and documented incident response procedures.
7.5 Limitations
While we implement strong security controls, no system is 100% secure. We cannot guarantee protection against advanced persistent threats, insider threats, zero-day exploits, supply chain attacks, or force majeure. If you believe your data has been compromised, contact privacy@ztinfosec.com immediately — we will investigate and notify affected parties within 72 hours (GDPR requirement).
8. International Data Transfers
Your personal data may be processed in Guatemala (ZT INFOSEC headquarters), the United States (if US-based services are used), the European Union (if EU-based cloud providers are used), or other countries as required for service delivery.
The United States is not considered “adequate” under GDPR. Where data is transferred to US-based processors, we rely on Standard Contractual Clauses (SCCs) and Data Processing Agreements with those processors, binding commitments to GDPR-compliant safeguards, and transfer impact assessments.
You have the right to ask where your data is processed, to object to transfers to non-adequate countries, and to request deletion if you do not consent to international transfer. Contact privacy@ztinfosec.com.
9. Your Privacy Rights
9.1 GDPR rights (EU residents)
- Access (Art. 15): request a copy of your personal data — response within 30 days in a structured, machine-readable format (CSV or JSON)
- Rectification (Art. 16): correct inaccurate or incomplete data
- Erasure (Art. 17): request deletion (“right to be forgotten”) — completed within 30 days except where retention is legally required
- Restriction (Art. 18): ask us to limit processing while a request is investigated
- Portability (Art. 20): receive your data in a portable format within 30 days
- Objection (Art. 21): object to processing based on legitimate interest
- Complaint (Art. 77): lodge a complaint with your national Data Protection Authority
9.2 CCPA rights (California residents)
- Right to know: what personal information we have collected — response within 45 days
- Right to delete: request deletion — response within 45 days (limited exceptions)
- Right to opt out: we do not sell or share personal information; if reCAPTCHA is considered a “share,” you may opt out by disabling JavaScript
- Right to correct: request correction of inaccurate information — response within 45 days
- Non-discrimination: you will not be denied service, charged differently, or given lower quality for exercising your rights
9.3 CPRA rights (California, 2023+)
You may request that we not use automated decision-making producing legal effects (we do not perform such processing) and request confirmation of data deletion or non-sale.
9.4 How to exercise your rights
Email privacy@ztinfosec.com with the subject line “[GDPR/CCPA/CPRA] Data Request — [type of request].” Include your full name, the email address used with our services, and the type of request (access, delete, correct, port, restrict, or object). We respond within 30 days for GDPR requests and 45 days for CCPA/CPRA requests; complex requests may take an additional 45 days with notice. We will verify your identity before processing, and business accounts require an authorized representative with documentation.
10. Cookies and Tracking Technologies
10.1 Cookies used
Customer portal (Assessment Tool, SaaS): we do not set persistent cookies; Google reCAPTCHA v3 may set a cookie for bot detection; no session or authentication cookies are retained after logout.
Website: no marketing or tracking cookies. Analytics cookies only if analytics is enabled, and functional cookies (such as a language preference) only if needed.
10.2 Browser storage
We do not use localStorage to persist personal data or sessionStorage for authentication tokens. Where tokens are used, they are stored in secure HTTP-only cookies.
10.3 Third-party cookies (reCAPTCHA)
Google reCAPTCHA v3 may set cookies to detect bots and remember trust signals. You can review Google’s privacy policy, opt out by disabling JavaScript, or use privacy-focused browsers.
10.4 Email tracking
We do not use pixel tracking in emails and do not track opens or clicks. Email delivery is logged, but not opened status.
11. Service-Specific Privacy Practices
11.1 Complimentary Assessment Tool
Collects your name, work email, and company domain, plus public reconnaissance data (DNS, SSL, HTTP headers, IPs, subdomains). Personal data and findings are retained 90 days (soft-delete); the PDF report is deleted after 30 days. You must confirm you own or control the domain and are authorized to request the assessment. Data is shared only with our email delivery provider and Google reCAPTCHA.
11.2 Risk Assessment SaaS Platform
Collects account registration details, the system configurations and security data you submit, assessment results, and account activity. Account data and results are retained for the subscription period plus 30 days; audit logs for 2 years. You must be an authorized representative of your organization. Data is shared only with our email provider and secure storage.
11.3 Professional Consulting Services
Collects engagement scope, authorized system details, communication records, findings, and deliverables. Engagement documents, communications, and billing records are retained for 7 years per professional and legal standards. Non-disclosure agreements may apply. Data is shared with subcontractors only as necessary for your engagement and only with your explicit approval.
12. Children’s Privacy
Our services are intended for business professionals and are not directed to anyone under 16 years of age (or 13 under COPPA in the US). If we discover we have collected information from a child, we will immediately delete the data, notify a parent or guardian where possible, and close any associated account. Contact privacy@ztinfosec.com if you believe a child’s data has been collected.
13. Data Breach Notification
If we discover a confirmed breach of personal data, we will notify affected individuals within 72 hours (GDPR requirement) and without unreasonable delay (CCPA requirement). Notification will include the date and time of the breach, the types of data affected, the steps we took to secure the data, recommended actions for you, and our contact information.
Where applicable, we will also notify the relevant Data Protection Authority, affected regulators, and credit bureaus.
14. Changes to This Privacy Policy
We may update this policy to reflect changes in our practices, comply with new legal requirements, improve clarity, or cover new services. For material changes we will update the “Last Updated” date, email you at your registered address if available, and require consent for major changes. Continued use of our services after changes means you accept the updated policy.
15. Data Protection Impact Assessment (DPIA)
For services involving large-scale or sensitive processing, we conduct Data Protection Impact Assessments to identify privacy risks, implement appropriate safeguards, and ensure GDPR compliance. A DPIA summary is available upon request at privacy@ztinfosec.com.
16. Contact Us
Privacy and data protection: privacy@ztinfosec.com · ZT INFOSEC, Guatemala City, Guatemala · response within 30 days (GDPR requirement).
General inquiries: info@ztinfosec.com · response within 5 business days.
Regulatory complaints: EU residents may file a complaint with their national Data Protection Authority (see the EDPB member list); California residents may contact the California Attorney General.
17. Key Privacy Principles
- Privacy by design — minimal collection, limited use, secure storage
- Transparency — clear explanations in plain language
- Data minimization — collect only what is necessary
- Purpose limitation — use data only for stated purposes
- Storage limitation — delete data when no longer needed
- Integrity and confidentiality — encrypt and access-control all data
- Accountability — audit logs and staff training
- User empowerment — easy access, correction, and deletion rights
18. Summary
| Question | Answer |
|---|---|
| What do you collect? | Personal data (name, email, domain); technical data (DNS, SSL, IPs); assessment findings |
| Why do you collect it? | Service delivery, communication, improvement, security |
| Who sees my data? | Only ZT INFOSEC staff and authorized sub-processors |
| Do you sell my data? | No, never |
| How long do you keep it? | Assessment Tool: 90 days · SaaS: subscription duration · Consulting: 7 years |
| Can I delete my data? | Yes, anytime — email privacy@ztinfosec.com |
| Is my data secure? | Encrypted in transit (TLS 1.2+) and at rest (AES-256), access-controlled |
| What if there’s a breach? | We notify you within 72 hours |
| Do you track me? | No cookies or analytics on the customer portal |
| Do you accept credit cards? | No — wire transfer, bank deposit, and Bitcoin only |
| Where is my data stored? | ZT INFOSEC local data center, encrypted |
19. Acknowledgment
By using ZT INFOSEC services, you acknowledge that you have read this Privacy Policy, understand what personal data we collect and how we use it, consent to the processing of your personal data as described, and understand your privacy rights and how to exercise them.
Version 1.0 · Last updated June 2026 · Questions? Read our Terms of Service or contact our privacy team.