This privacy policy informs you in accordance with Art. 13 and Art. 14 GDPR about the processing of personal data when visiting our website and using our services.
1. Data Controller
ZERO Cybernetic Systems & Digital Solutions UG (haftungsbeschränkt)
(limited-liability entrepreneurial company under German law)
Fidicinstr. 23
10965 Berlin
Germany
Represented by: Azad Kader, Managing Director
Registration: HRB 258363 B (District Court Berlin-Charlottenburg)
Contact for privacy matters: privacy@zerotrust.is
We have not appointed an external Data Protection Officer as we do not meet the thresholds of § 38 BDSG (German Federal Data Protection Act).
2. Competent Supervisory Authority
Berlin Commissioner for Data Protection and Freedom of Information (BlnBDI)
Friedrichstr. 219, 10969 Berlin, Germany
https://www.datenschutz-berlin.de
You have the right to lodge a complaint about us with this authority at any time.
3. What Data We Process
We process only data that is technically necessary for providing our services. We do not track, we do not profile, we do not sell data.
3.1 Simply visiting the website
| Data category | Purpose | Retention |
|---|---|---|
| IP address (anonymised after 24h) | Anti-abuse (rate-limiting / attack protection) | 24 hours |
| Date and time of access | Error analysis | 7 days |
| Requested URL + HTTP status | Error analysis | 7 days |
| User agent (browser) | Browser compatibility | 7 days |
| Referrer URL | not logged | — |
Legal basis: Art. 6 (1) (f) GDPR (legitimate interest in security logging).
3.2 When ordering or contacting us
| Data category | Purpose | Retention |
|---|---|---|
| First and last name | Order processing, delivery | 10 years (§ 147 AO German Tax Code) |
| Delivery address | Shipping | 10 years (§ 147 AO) |
| Email address | Order confirmation, shipping tracking | 10 years (§ 147 AO) |
| Phone number (optional) | Queries | until deletion request |
| Order details, payment method | Billing | 10 years (§ 147 AO) |
| Workshop appointment slot | Drop-off/Pickup coordination | until order completion + 6 months |
Legal basis: Art. 6 (1) (b) GDPR (contract performance) and (c) (legal retention obligation for invoices).
The 10-year retention of order and invoice data is required by law (§ 147 AO, § 257 HGB) and not our own choice. Without this obligation we would keep this data for a much shorter time.
3.3 Cookies
We do not use tracking cookies, advertising cookies, Google Analytics, or Facebook Pixel.
The following technically necessary cookies are set:
| Cookie | Purpose | Lifetime |
|---|---|---|
wp_* (Session) |
WP login + cart | Session |
zero_lang |
Language preference (DE/EN) | 1 year |
TranslatePress (trp_language etc.) |
Language selection (translation) | Session / 1 year |
| WooCommerce session | Cart persistence | Session |
Legal basis: Art. 6 (1) (b) GDPR resp. § 25 (2) (2) TTDSG (technically necessary, no consent required).
4. Processors
We use as few external service providers as possible. Where processing under Art. 28 GDPR takes place, a data processing agreement (DPA) is in place or will be concluded.
4.1 Hosting
1984 ehf., Reykjavík, Iceland — operation of website and shop on a server in Iceland. (Iceland is an EEA member; the GDPR applies directly, there is no third-country transfer.)
– Privacy information: 1984.hosting (confirm final link before go-live)
4.2 Email delivery
Transactional emails (order confirmations, shipping notifications) are sent server-side from our shop server (1984, Iceland) — no external email delivery provider is involved.
Our contact mailboxes (contact@, orders@, privacy@ … @zerotrust.is) are hosted by Proton AG, Geneva, Switzerland (the EU Commission has issued an adequacy decision for Switzerland). No marketing emails, no active newsletter.
4.3 Payment processing
- Crypto (BTC/XMR): via a self-hosted BTCPay server on our own infrastructure — no external payment provider, no data sharing with third parties. (Note: BTCPay is being set up; until it goes live, no live crypto payment.)
- SEPA transfer: directly to our business bank — processing by your bank and our bank under applicable data protection law.
- Cash at the workshop appointment: no electronic data processing.
4.4 Appointment booking (workshop services)
Appointments are handled via self-hosted software on our own infrastructure — no external booking provider.
4.5 Backups
Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany — encrypted (GPG) off-site backups on a Storage Box in Germany (EU). Personal data in backups is client-side encrypted.
– DPA: Hetzner standard DPA.
– Privacy policy: https://www.hetzner.com/legal/privacy-policy
5. Data Sharing
Your data will be shared with third parties only:
- with legal authorities when legally required (e.g. tax authority for invoice retention)
- with shipping service providers (DHL, Hermes etc.) — delivery address only, no order content
- with our tax advisor as part of accounting (professional secrecy)
- for workshop appointments: NO data sharing (service performed on-site by our workshop)
No data sharing with advertising providers, analytics tools, tracking services, or similar third parties.
6. Your Rights as a Data Subject
- Right of access (Art. 15 GDPR) — what data we have stored about you
- Right to rectification (Art. 16 GDPR) — correction of incorrect data
- Right to erasure (Art. 17 GDPR) — provided no legal retention obligations stand in the way
- Right to restriction of processing (Art. 18 GDPR)
- Right to data portability (Art. 20 GDPR)
- Right to object (Art. 21 GDPR) to processing based on legitimate interests
- Right to lodge a complaint with a supervisory authority (Art. 77 GDPR) — see Section 2
To exercise your rights please contact privacy@zerotrust.is or by post to our address.
7. .onion Mirror (Tor)
Our website is also accessible via a Tor hidden service. When using Tor:
– NO IP address is logged (Tor architecture)
– Server logs show only incoming Tor connections without source IP
– Connection is end-to-end encrypted via the Tor network
The .onion address can be found in the footer and in the Onion-Location HTTP header.
8. Security
We implement appropriate technical and organisational measures pursuant to Art. 32 GDPR to protect your data against loss, misuse and unauthorised access — including:
– transport encryption (HTTPS/TLS) on all connections
– data minimisation: we collect only what the service requires
– access restrictions and regular updates of our systems
– encrypted backups kept in a separate location
For security reasons we do not disclose the details of our safeguards here; we demonstrate them to the supervisory authority on request.
9. Changes to this Policy
We reserve the right to adapt this privacy policy so that it always meets current legal requirements. For material changes, we will notify you by email (if you have an active order).