Last updated: October 6, 2026
1. Introduction
This Privacy Policy describes how INFOSEC TECHNOLOGIES ESP LLC, the owner of the ZERYON brand, collects, uses and protects personal data relating to visitors of the website zeryon.io (the "Website") and to anyone who contacts us through it.
ZERYON provides professional cybersecurity and threat intelligence services to businesses and organizations. Protecting information is at the core of what we do, and we hold ourselves to the same standard with the personal data we handle: we collect only what we need, use it for clearly defined purposes and safeguard it appropriately.
This policy has been prepared in light of Regulation (EU) 2016/679, the General Data Protection Regulation ("GDPR"), Spanish Organic Law 3/2018 on the Protection of Personal Data and Guarantee of Digital Rights ("LOPDGDD"), Spanish Law 34/2002 on Information Society Services and Electronic Commerce ("LSSI-CE") and, to the extent applicable, the privacy laws of the United States of America.
2. Who is responsible for your data
- Data controller: INFOSEC TECHNOLOGIES ESP LLC, a limited liability company organized under the laws of the State of New Mexico, U.S.A., pursuant to Articles of Organization filed on November 8, 2022.
- Trade name: ZERYON.
- Employer Identification Number (EIN, IRS): 92-1630529.
- Principal place of business: 407 Lincoln Road, Suite 708, Miami Beach, Florida 33139, U.S.A.
- Registered agent in New Mexico: CSC (Corporation Service Company).
- Authorized representative: Josué López Martín, Member.
- Privacy contact: [email protected].
3. EU representative and data protection officer
INFOSEC TECHNOLOGIES ESP LLC is not established in the European Union. However, because it offers its services to businesses and professionals located in the European Union, the GDPR applies to it under Article 3(2).
In accordance with Article 27 GDPR, the controller is in the process of appointing a representative in the European Union, whose details will be published in this policy. In the meantime, data subjects and supervisory authorities may contact the controller directly at [email protected] on any matter relating to the processing of personal data.
The appointment of a representative is required unless the exemption in Article 27(2) GDPR applies (processing that is occasional, does not include large-scale processing of special categories of data or of data relating to criminal convictions and offences, and is unlikely to result in a risk to the rights and freedoms of individuals). The controller will periodically review whether that exemption applies.
Given the nature and scale of the processing described in this policy, the controller is not required to appoint a data protection officer (DPO) under Article 37 GDPR and Article 34 LOPDGDD, although it will do so should that requirement arise in the future. All privacy enquiries can be sent to [email protected].
4. Personal data we collect and where it comes from
4.1. Information you provide to us
The Website contains a contact form with the following fields: name, email address, company, type of enquiry and message. You must tick a box confirming that you have read this Privacy Policy.
Please note how this form works: the Website itself does not transmit or store the information you enter. When you click the submit button, the form opens the email program or service configured on your device, with a pre-filled message addressed to [email protected]. You can review and edit the message before sending it, and we will only receive it if you choose to send it. When you do, we will also receive the information that accompanies any email, such as your email address, the date and time it was sent, technical message headers and any signature or attachment you include.
Please do not include special categories of personal data (for example, health data) or confidential details about security incidents in your message until we have agreed on an appropriate, and where necessary encrypted, communication channel.
4.2. Information generated when you browse
As with any website, when you visit the Website your browser automatically sends certain technical information to the server hosting it, such as your IP address, the date and time of the request, the page requested, your browser type and version, your operating system and the referring page. This information is recorded in the server logs of our hosting provider and is used solely to deliver the Website, keep it secure and troubleshoot errors.
All Website resources (fonts, images and JavaScript libraries) are served from our own server; no third-party resources are loaded. The Website is delivered through the network of Cloudflare, Inc., which acts as a reverse proxy and content delivery network to improve speed and protect the Website against attacks. To do so, Cloudflare necessarily processes your IP address and the technical details of the request, and may set strictly necessary security cookies (for example, for bot detection). This processing is essential to provide the service securely.
The fonts used on the Website are hosted on our own server, so no connections are made to third-party font services such as Google Fonts.
4.3. Local storage in your browser
The Website stores only two technical values in your browser's local storage (localStorage): your language preference and a record that you have seen and accepted the cookie notice. These values remain on your device and are not sent to our servers. We do not use cookies or similar technologies for analytics, advertising or profiling. Please see our Cookie Policy for details.
5. Why we use your data and our legal bases
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Handling and responding to your enquiry, including preparing proposals or quotes you request. | Name, email address, company, type of enquiry, message and data contained in the email received. | Steps taken at your request prior to entering into a contract (Art. 6(1)(b)) where the enquiry concerns our services; our legitimate interest in responding to communications addressed to us (Art. 6(1)(f)) in all other cases. |
| Managing relationships with clients, suppliers and partners where an enquiry leads to a contract. | Business contact details and any data required to perform the contract. | Performance of a contract (Art. 6(1)(b)) and compliance with legal obligations, in particular tax and accounting obligations (Art. 6(1)(c)). |
| Sending you marketing communications about our services. | Name, email address and company. | Your consent (Art. 6(1)(a) and Article 21 LSSI-CE) or, if you are an existing client, our legitimate interest in informing you about services similar to those you have purchased, with the right to opt out at any time (Article 21(2) LSSI-CE). |
| Operating the Website, keeping it secure and preventing abuse or attacks. | IP address and technical browsing data. | Our legitimate interest in the secure operation of the Website (Art. 6(1)(f)). |
| Remembering your preferred language and your acceptance of the cookie notice. | Technical values in your browser's local storage. | Our legitimate interest in providing the service you request (Art. 6(1)(f)); storage exempt from consent under Article 22(2) LSSI-CE. |
| Handling vulnerability reports received through our responsible disclosure channel. | Reporter's contact details and the content of the report. | Our legitimate interest in protecting the security of our systems and our clients (Art. 6(1)(f)). |
| Responding to requests to exercise data protection rights and defending our interests in the event of claims. | The data required in each case. | Compliance with legal obligations (Art. 6(1)(c)) and our legitimate interest in establishing, exercising or defending legal claims (Art. 6(1)(f)). |
Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms and concluded that they are not overridden, since the processing involves business contact details you choose to share with us or minimal technical data. You may object to this processing as described in Section 10.
The form fields are needed for us to handle your enquiry properly; if you do not provide them, we may be unable to respond. We do not make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you.
6. How long we keep your data
- Enquiries that do not lead to a contract: kept for up to twelve (12) months after our last exchange, so that we can follow up on the conversation, and then deleted.
- Clients and contractual relationships: for the duration of the relationship and, after it ends, for the periods required by law. By way of reference, commercial and accounting records are kept for six (6) years, and tax-relevant records for the applicable limitation period, without prejudice to any retention periods required under U.S. law.
- Marketing communications: until you withdraw your consent or opt out. We will keep your email address on a suppression list to ensure you do not receive further messages.
- Server logs: for the period set by the configuration of our hosting provider which we aim to limit to a maximum of ninety (90) days, unless they are needed to investigate a security incident, in which case they will be kept for as long as the investigation and any resulting action require.
- Browser local storage: remains on your device until you delete it; see our Cookie Policy.
- Vulnerability reports: while the report is being handled and for up to three (3) years after it is closed, for follow-up and record-keeping purposes.
- Data protection rights requests: for three (3) years after they are resolved, to demonstrate compliance.
Once these periods expire, and where required by law, data will be kept blocked under Article 32 LOPDGDD, available only to courts, public prosecutors and competent authorities for the limitation period of any potential liability, and then securely deleted.
7. Who we share your data with
We do not sell, rent or disclose your personal data to third parties for their own marketing purposes. Your data will only be disclosed in the following circumstances:
- Service providers acting as processors on our behalf, with whom we have entered into, or will enter into, the agreements required by Article 28 GDPR: our web hosting provider and the email service provider that hosts the mailboxes [email protected] and [email protected].
- Delivery and security network (Cloudflare, Inc.), which processes the IP address and technical data of each request in order to deliver the Website and protect it against attacks, under its own terms and privacy policy.
- Professional advisers (legal, tax or accounting) bound by confidentiality obligations, where necessary.
- Public authorities, courts and tribunals, where we are legally required to do so.
8. International data transfers
INFOSEC TECHNOLOGIES ESP LLC is based in the United States of America. Accordingly, if you are located in the European Economic Area (EEA) and send us your data, it will be transferred to a country outside the EEA. Some of our service providers may also process data outside the EEA.
Such transfers are carried out on the basis of one of the following safeguards, as appropriate:
- The European Commission's adequacy decision for the EU-U.S. Data Privacy Framework, solely in respect of recipients that are certified under that framework. INFOSEC TECHNOLOGIES ESP LLC does not claim to be certified under the Data Privacy Framework; should it obtain certification in the future, this policy will expressly say so.
- The standard contractual clauses adopted by the European Commission (Article 46(2)(c) GDPR), in particular in contractual relationships with clients and with providers that do not offer another safeguard.
- Failing that, and on an occasional basis, the derogations in Article 49 GDPR, in particular where the transfer is necessary to respond to your pre-contractual request or to perform a contract concluded at your request or in your interest (Article 49(1)(b) and (c)).
You can request further information about the safeguards we rely on, or a copy of them, by writing to [email protected].
9. Information security
As a cybersecurity company, we implement technical and organizational measures appropriate to the risk, in line with Article 32 GDPR, to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access. These include:
- Encryption of all communications with the Website using TLS (HTTPS).
- A static website architecture, with no databases or server-side forms storing information, which reduces the attack surface.
- Access control based on the principle of least privilege and strong (multi-factor) authentication on accounts with access to personal data.
- Ongoing system maintenance and patching, and monitoring of security events.
- Confidentiality obligations for everyone with access to personal data.
- A security incident management procedure, including notification of personal data breaches to the supervisory authority and, where required, to affected individuals, under Articles 33 and 34 GDPR, and to individuals and authorities under applicable U.S. state breach notification laws.
No system is entirely immune to attack. If you discover a potential vulnerability on the Website, we would be grateful if you reported it through the responsible disclosure channel described in our Legal Notice ([email protected]).
10. Your rights
You may exercise the following rights at any time:
- Access: to find out whether we process your data and to obtain a copy of it.
- Rectification: to have inaccurate data corrected or incomplete data completed.
- Erasure: to have your data deleted where, among other grounds, it is no longer necessary for the purposes for which it was collected.
- Objection: to object, on grounds relating to your particular situation, to processing based on legitimate interests, and at any time to processing for direct marketing purposes.
- Restriction of processing: to ask us to retain your data without otherwise using it in the cases set out in Article 18 GDPR.
- Data portability: to receive the data you have provided to us in a structured, commonly used and machine-readable format, or to have it transmitted to another controller, where processing is based on consent or a contract and carried out by automated means.
- Withdrawal of consent: where processing is based on consent, to withdraw it at any time, without affecting the lawfulness of processing carried out before its withdrawal.
To exercise these rights, please email [email protected] stating which right you wish to exercise. If we have reasonable doubts about your identity, we may ask for additional information to verify it. We will respond within one month of receiving your request. That period may be extended by two further months where necessary, taking into account the complexity and number of requests, in which case we will let you know within the first month. Exercising your rights is free of charge, except for requests that are manifestly unfounded or excessive.
You can also unsubscribe from marketing communications using the link or instructions included in each message.
If you believe that we have not properly addressed your request or that our processing of your data breaches the law, you have the right to lodge a complaint with the Spanish Data Protection Agency (Agencia Española de Protección de Datos, www.aepd.es) or with the supervisory authority of the EU Member State where you habitually reside, work or where the alleged infringement took place. We would, however, appreciate the chance to address your concerns first, so please contact us beforehand if you can.
11. Notice for California residents
This section supplements the rest of this policy and applies to residents of the State of California. The California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA"), applies only to businesses that meet at least one of its thresholds: annual gross revenues above the amount set by the statute (currently USD 25 million, as adjusted for inflation), buying, selling or sharing the personal information of 100,000 or more California consumers or households per year, or deriving 50% or more of annual revenues from selling or sharing personal information. INFOSEC TECHNOLOGIES ESP LLC will comply with the CCPA where it meets those thresholds and, in any event, voluntarily follows the practices described below.
Personal information we collect
In the preceding twelve (12) months, we may have collected the following categories of personal information, from the sources and for the business purposes described in Sections 4 and 5:
- Identifiers: name, email address and IP address.
- Professional or employment-related information: the company you work for and, where you provide it, your job title.
- Commercial information: the services you enquire about or purchase.
- Internet or other electronic network activity information: technical data recorded in server logs when you visit the Website.
- Other information you choose to include in your message.
We do not intentionally collect sensitive personal information and do not use or disclose it for the purpose of inferring characteristics about you. Retention periods for each category are described in Section 6.
Disclosures, sale and sharing
We disclose the categories of personal information listed above to service providers for business purposes, as described in Section 7. We do not sell personal information and do not share it for cross-context behavioral advertising, as those terms are defined in the CCPA, and we have not done so in the preceding twelve (12) months. We do not knowingly sell or share the personal information of consumers under 16 years of age. Because we do not sell or share personal information, we do not offer a "Do Not Sell or Share My Personal Information" link; nevertheless, we treat Global Privacy Control (GPC) signals as a valid opt-out request.
Your rights
Subject to the conditions and exceptions set out in the CCPA, California residents have the right to:
- Know what personal information we have collected about them, including the categories of personal information, the categories of sources, the business or commercial purposes for collecting it, the categories of third parties to whom we disclose it, and the specific pieces of personal information we hold.
- Request deletion of their personal information.
- Request correction of inaccurate personal information.
- Opt out of the sale or sharing of their personal information (although we do not sell or share it).
- Limit the use and disclosure of sensitive personal information (although we do not use it for purposes that would trigger this right).
- Not be discriminated or retaliated against for exercising any of these rights.
To submit a request, email [email protected]. We will verify your request by matching the information you provide with the information we hold, and we will respond within 45 days, which may be extended by a further 45 days where reasonably necessary, in which case we will inform you. You may designate an authorized agent to submit a request on your behalf; we may require proof of the agent's authorization and may ask you to verify your identity directly with us.
Other U.S. state privacy laws
Residents of other U.S. states that have enacted comprehensive consumer privacy laws (such as Virginia, Colorado, Connecticut, Utah, Texas, Oregon and others) may have similar rights, including rights of access, correction, deletion, data portability and opting out of targeted advertising, sale or profiling. Those laws apply only where their respective thresholds are met, and many of them do not apply to data processed in a business-to-business context. Where they apply, you may exercise those rights by writing to [email protected], and you may appeal any decision we make on your request by replying to our response with the subject line "Appeal".
12. Children
The Website and ZERYON's services are intended exclusively for businesses, organizations and professionals. They are not directed at children under the age of sixteen (16), and we do not knowingly collect personal data from children. If you become aware that a child has provided us with personal data, please contact [email protected] and we will delete it.
13. Accuracy and third-party data
You confirm that the information you provide is accurate and up to date and agree to let us know of any changes. If you provide us with personal data about other people (for example, colleagues within your organization), you confirm that you have informed them of this policy and have a lawful basis for sharing their data with us.
14. Third-party websites
The Website may contain links to third-party websites, such as professional social network profiles. This policy does not apply to those websites, which have their own privacy policies. We recommend reviewing them before providing any personal data.
15. Changes to this policy
We may update this Privacy Policy to reflect changes in the law, in technology or in our business, for example if we introduce new tools or service providers. The current version will always be available on the Website, together with the date of its last update. Where changes are material and we hold your contact details, we will let you know. If we introduce cookies or similar technologies that require your consent in the future, we will ask for it before using them.
