Legal

Privacy Policy

How GoalPath B.V. collects, uses and protects personal data — on this website and in the ZeroRisk platform. Last updated 16 September 2026.

1. Who we are

GoalPath B.V. ("ZeroRisk", "we") is a company registered in The Hague, the Netherlands (KvK 65820061). We operate zerorisk.com and the ZeroRisk compliance platform at app.zerorisk.com. For the data described in this policy we are the controller, with one exception: the content organizations upload into the platform (section 4), which we process on their instructions.

Questions or requests about this policy: service@zerorisk.com.

2. Data we collect on this website

Forms

When you request a gap report, book a demo, ask about a custom plan or contact us, the form collects your name, work email, company and what you tell us. Forms are processed by HubSpot (EU data center) and the details go into our CRM so we can respond.

Analytics and advertising

We use Google Analytics to understand how the site is used and Google Ads conversion tracking to measure our advertising, and HubSpot records page visits linked to the contact record after you submit a form. These tools set cookies. You can browse the site without submitting anything, and you can block these cookies in your browser without losing access to any content.

Hosting logs

The site is served by Cloudflare, which processes IP addresses and request metadata to deliver pages and protect against abuse. We see aggregated statistics, not a browsing profile.

3. Data we collect when you become a customer

Account data

Name, work email, role and sign-in metadata for each person your organization gives platform access. Authentication is handled by our identity provider under a data processing agreement.

Billing

Subscriptions are managed by Chargebee. Your card details go directly to Chargebee and its payment processors — we never see or store them. We keep invoices and subscription records.

4. Content you upload into the platform

Running a compliance program means the platform holds business content: vendor lists, staff directories and HR exports, equipment records, access grants, policies and evidence documents. Some of this is personal data about your employees and contacts.

For this content, your organization is the controller and ZeroRisk is the processor. We process it only to provide the service, under our data processing agreement, and your administrators control what is uploaded, who sees it, and when it is deleted. If you are an employee of a ZeroRisk customer and want to know how your data is handled, your employer’s privacy policy governs — and we support them in answering it.

5. Why we process data, and on what legal basis

PurposeDataLegal basis
Answering your request (gap report, demo, contact)Form submissionsSteps at your request before a contract (art. 6(1)(b) GDPR)
Providing the platformAccount data, uploaded contentContract (art. 6(1)(b)); uploaded content per our DPA
Billing and accountingInvoices, subscription recordsLegal obligation (art. 6(1)(c))
Improving the site and measuring campaignsAnalytics and advertising cookiesConsent / legitimate interest (art. 6(1)(a), (f))
Relevant product updates to leads and customersEmail, companyLegitimate interest — every email has an unsubscribe link
Security and abuse preventionHosting logsLegitimate interest (art. 6(1)(f))

6. Who receives data

We share personal data only with the service providers that run the site and platform: HubSpot (forms and CRM, EU region), Google (analytics and advertising), Cloudflare (hosting and security), Chargebee (billing), and our authentication and email-delivery providers. Each acts under a data processing agreement. We do not sell personal data, and we do not share it with anyone else unless the law requires it.

7. Where data lives

EU residency by default: the platform and our CRM run in EU data centers. Some providers (Google, Cloudflare) operate globally; where data leaves the EEA, transfers rely on the EU–US Data Privacy Framework or Standard Contractual Clauses.

8. How long we keep it

DataRetention
Lead and contact records24 months after the last interaction, then deleted
Account data and uploaded contentLife of the subscription; export window after termination, then deleted within 90 days
Invoices and billing records7 years (Dutch tax law)
Hosting and security logsWeeks, not months — provider defaults

9. Your rights

Under the GDPR you can ask us for access to your data, correction, deletion, a portable copy, restriction of processing, or object to processing based on legitimate interest. Email service@zerorisk.com — we respond within one month. You can also complain to the Dutch supervisory authority, the Autoriteit Persoonsgegevens.

10. Security

Data is encrypted in transit and at rest. Access is role-based and limited to the people who need it, and we review that access — the same discipline the product itself enforces.

11. Changes

When this policy changes materially, we update the date at the top and, for customers, give notice in the platform or by email before the change takes effect.

12. Contact

GoalPath B.V., Prinses Margrietplantsoen 33, 2595 AM The Hague, The Netherlands · KvK 65820061 · service@zerorisk.com