Skip to main content
PRIVACY POLICY

This privacy policy explains which personal data Zero Trust processes through zero-trust.be.

This website is a static site operated by Zero Trust in Belgium. We only process personal data needed to receive your message, keep the site secure, and show a limited awareness demo on the /scan page.

Data controller

Company name
Zero Trust BV
Legal form
BV (besloten vennootschap / société à responsabilité limitée)
Registered office
Available through the official KBO/CBE record for enterprise number 1036.141.726.
BCE/KBO number
1036.141.726
VAT number
BE1036.141.726
Email
info@zero-trust.be
Domain
zero-trust.be

Through the /contact page, we process the data you choose to enter into the contact form: name, email address, subject, and free-text message content. When you submit the form, the message is sent over HTTPS POST to a small Node/Fastify backend. That backend then forwards the message through the Microsoft Graph API to info@zero-trust.be, a Microsoft 365 mailbox hosted by Microsoft Ireland.

In addition to the form content, the backend records a limited server-side log entry at the time of submission containing the IP address and the browser User-Agent. These logs are kept for about 30 days in container logs and are used only for abuse prevention, security, and technical debugging.

The web server for this site, Caddy, also keeps access logs. Those logs contain the IP address, request path, User-Agent, and timestamp. These logs are also retained for about 30 days and are used only for security, abuse detection, and operational follow-up.

Zero Trust runs limited first-party server-side analytics from Caddy access logs. Before storage, IP addresses are reduced to a rotating salted hash; approximate GeoIP information is resolved locally; and User-Agent metadata is parsed for aggregate device, browser, and operating-system reporting. We do not use client-side analytics scripts, marketing automation, CRM tracking, advertising pixels, or third-party trackers. There is therefore no advertising profiling and no automated marketing segmentation based on your behaviour on this site.

When the site loads, your browser may send a request to rsms.me to load the CSS for the Inter font. That third party may therefore receive technical connection data such as your IP address, browser information, and the time of the request.

When the site checks whether to suggest a country/language, your browser sends a fresh same-origin request to /api/scan/context. That endpoint captures the public IP address and selected HTTP request metadata visible to the server, and may look up that exact IP server-side through IP metadata providers such as ipwho.is, ipapi.co, ip-api.com, and ipinfo.io to return country, timezone, ASN, and organisation data. The browser may store the request-derived IP and its geolocation lookup result in local storage for up to 7 days, but each fresh request is compared with the stored IP first. If the public IP has changed, the stored IP context is replaced and the country/language prompt can appear again for the new network location.

On the /scan page, the current request IP is first looked up through the same-origin /api/scan/context endpoint. If that same-origin context is unavailable or incomplete, the browser may recover by contacting ipwho.is, ipapi.co, or ipinfo.io directly for the same public IP. The page may also probe api.ipify.org and api6.ipify.org to show which public IPv4 and IPv6 addresses are reachable from this browser. The page may also request browser GPS/geolocation permission to show the difference between network-derived location and precise browser-provided location. After that, your browser requests map tiles from the same-origin /api/scan/osm/* path. The edge proxy fetches OpenStreetMap tiles from tile.openstreetmap.org with sanitized forwarding headers, so your browser does not contact the tile provider directly. This awareness demo shows how much context can be visible from request, network, and browser data.

For the data you voluntarily enter and submit through the contact form, we rely on your consent within the meaning of Article 6(1)(a) GDPR. You choose whether to fill in and send the form.

For server and security logs, we rely on legitimate interests within the meaning of Article 6(1)(f) GDPR. Those interests are securing the website and backend, preventing abuse, investigating incidents, and resolving technical issues.

For first-party server-side analytics, we also rely on legitimate interests within the meaning of Article 6(1)(f) GDPR. Those interests are understanding aggregate use of the public website, improving content and availability, and detecting unusual traffic patterns without using marketing trackers.

Messages you send through the contact form are received in the mailbox info@zero-trust.be. We keep those messages for as long as needed to answer the request, maintain the business or legal record, and meet legal obligations. Messages that are no longer needed are deleted or archived according to the mailbox retention policy.

Backend logs containing the IP address and User-Agent at form submission are kept for about 30 days.

Caddy access logs containing IP address, request path, User-Agent, and timestamp are kept for about 30 days.

First-party analytics records derived from Caddy access logs are stored in the analytics database with hashed visitor identifiers and are pruned according to the deployment's configured analytics retention period.

For the processing connected to this website, we use the following processors or recipients:
- Microsoft Ireland Operations Ltd, Ireland, for Microsoft 365 and Microsoft Graph API, so that contact form messages can be received in our mailbox;
- Zero Trust BV itself, via self-hosting in a Datacenter United colocation facility in Oostkamp, Belgium — the website and backend run on hardware owned and operated by Zero Trust BV, so there is no separate third-party hosting provider;
- Let's Encrypt, public certificate authority, for the issuance and management of TLS certificates.

We are established in Belgium and aim for processing within the EU/EEA. Microsoft 365 for our mailbox is provided through Microsoft Ireland. Even so, Microsoft may, as part of support, security, infrastructure administration, or network routing, allow data to transit through systems outside the EEA, including the United States. Where such transfers occur, they take place under the contractual and organisational mechanisms Microsoft provides for that purpose. The current detail of those safeguards depends on Microsoft's own documentation.

Under the GDPR, you have the right of access, rectification, erasure, restriction of processing, data portability, and, in some cases, the right to object to processing. Where processing is based on consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing that took place before the withdrawal.

You can exercise these rights by emailing info@zero-trust.be. Please state as clearly as possible which processing your request relates to. We may ask for reasonable additional information to verify your identity before acting on your request.

If you believe that we process your personal data incorrectly, you can contact us at info@zero-trust.be. You also have the right to lodge a complaint with the Belgian Data Protection Authority via autoriteprotectiondonnees.be.

We may update this privacy policy if the operation of the site, the service providers we use, or the applicable rules change. The latest version is always available on zero-trust.be.

Last updated: 2 July 2026.