Privacy Policy
Last updated: 21 August 2026
1. Who we are
The controller for personal data collected through zeroone01.com is Dimitris Gkoutzamanis, trading as Zero One Cybersecurity, established in Cyprus.
A limited company, Zero One Technologies Ltd, is in formation. When it is incorporated it will become the controller and this notice will be updated to name it. Until that happens, the controller is the named individual above.
Contact, for anything in this notice or to exercise any of the rights in section 7: info@zeroone01.com. A postal address is available on request.
2. What we collect
2.1 When you contact us
Through the contact form or by email:
- Your name
- Your email address
- Your company name (optional)
- The contents of your message
The notification email we send ourselves also records the IP address the message was sent from, as a spam and abuse control.
2.2 When you use the readiness assessment
The readiness assessment collects information in two stages, and the first stage is anonymous.
- While you answer — your responses to the questionnaire, your sector, approximate headcount and what is prompting the work, plus the framework and depth you chose. We also record the country your request came from, how you reached the site, and your browser's user-agent string. We do not store your IP address.
- If you request the report — your work email address, name, company and role, together with a record of the consent you gave and the exact wording you consented to.
Your session is kept together by a cookie holding a random identifier, so you can leave and come back to a part-finished assessment. It contains nothing about you and is described in section 8.
2.3 How the report is produced
Reports are not generated and sent automatically. Your responses are read by our lead consultant, who reviews the findings, writes the summary and releases the report — normally within one business day. This means a person sees what you submitted. That is the point of the service, and we would rather say so plainly than bury it.
The report itself is published at a private, unguessable web address. Anyone holding that address can open it, so treat the link as confidential. We record when it is first opened and how many times it is viewed.
2.4 Analytics
If you accept analytics, Google Analytics records the pages you visit on the main website, in aggregate. It is not loaded unless you accept, and the assessment pages, the report and the review console never load it at all. Section 8 covers this in full.
3. Why we process it, and on what basis
- To respond to your enquiry — legitimate interests (Article 6(1)(f) GDPR) and, where applicable, steps prior to entering a contract (Article 6(1)(b)).
- To prepare and send your readiness report — your consent (Article 6(1)(a)), given when you request it. You can withdraw that consent at any time; doing so does not affect processing carried out before you withdrew it.
- To follow up on a report we sent you — legitimate interests in offering the service the report relates to. You can object at any time and we will stop.
- To send you occasional guidance by email — your consent, given separately from the report request and never pre-ticked. Every message carries an unsubscribe link.
- To improve the assessment — legitimate interests in understanding, in aggregate, where people abandon the questionnaire.
- To operate and secure the website — legitimate interests in maintaining a functional, secure service.
Nothing in the assessment involves automated decision-making that produces legal or similarly significant effects. The score is calculated automatically, but it is a description of the answers you gave, and a person reviews the report before it reaches you.
4. Who we share it with
We do not sell personal data. We share it with the following processors, each under a data-processing agreement:
- Cloudflare, Inc. — website and application hosting, the database holding assessment responses and report requests, and bot protection on our forms (Turnstile).
- Resend (Plus Five Five, Inc.) — sending the report notification and our replies to enquiries.
- Google LLC — website analytics on the main site (only if you accept analytics cookies), web fonts, and the calendar booking link used to arrange calls. Where you accept analytics, Google also acts for its own purposes in estimating demographics and recognising visitors across devices — see section 8.2.
We may also disclose personal data where we are legally required to do so.
5. International transfers
Cloudflare, Resend and Google are established in the United States. Transfers to them are carried out under appropriate safeguards as defined in Chapter V of the GDPR — Standard Contractual Clauses, and where applicable the EU–US Data Privacy Framework. You can ask us for details of the safeguards that apply.
6. How long we keep it
- Enquiries — for as long as needed to handle your enquiry and a reasonable period afterwards, typically up to 24 months.
- Assessments you started but did not finish — deleted after 90 days.
- Assessments you finished but did not request a report for — deleted after 180 days.
- Report requests, and the responses behind them — up to 24 months from when you requested the report.
- Submissions we judge to be junk — deleted after 30 days.
These deletions run automatically on a daily schedule. Where a working relationship begins, the relevant records move into our client files and are kept under that relationship instead, for as long as our professional and legal obligations require.
7. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you
- Have it corrected if it is inaccurate
- Have it erased
- Restrict or object to processing
- Receive it in a portable format
- Withdraw consent at any time, where processing is based on consent
- Lodge a complaint with a supervisory authority
To exercise any of these, use the data request form or email info@zeroone01.com. We respond within one month. We may ask you to confirm your identity first — that is what stops someone else erasing or requesting your data.
Our supervisory authority is the Office of the Commissioner for Personal Data Protection in Cyprus (dataprotection.gov.cy). If you are in another EU or EEA country you may also complain to your local authority.
8. Cookies
We use as few as we can, and the only optional ones are gated behind your consent.
8.1 Strictly necessary — no consent needed
- Assessment session — holds a random identifier so a part-finished assessment can be resumed. It expires after 90 days and contains no personal data itself.
- Cloudflare Turnstile — set when a form is submitted, to distinguish people from bots.
- Your cookie choice — stored in your browser so we do not ask again. It never leaves your device.
8.2 Analytics — only if you accept
We would like to use Google Analytics on the main website pages to understand how the site is used. It is not loaded at all unless you accept it: declining, ignoring the banner or simply scrolling past all mean it never runs, and no analytics cookie is set.
Google Signals is enabled on our analytics property. Where you accept, and where you have turned on Ads Personalisation in your own Google account, this means Google may estimate your age, gender and interests and recognise you across the devices you use. We see only aggregated reports and never individual profiles, but Google processes that data for its own purposes as well as ours, and you should weigh that when deciding.
You can change your mind at any time using the Cookie settings link at the foot of any page. Declining later stops any further analytics, though it cannot delete cookies a previous acceptance already placed — your browser settings can do that.
The assessment pages, the report and the review console carry no analytics at all, regardless of your choice.
9. Changes
We may update this notice from time to time. The version published on this page is always the current one, it carries the date it was last changed, and it replaces any earlier version.