Legal centre Enterprise privacy

Data Processing Agreement

The processor framework for customer-controlled personal data handled through Root Digit Services.

This public DPA is not automatically a signed agreement. It becomes binding only when an executed order form or statement of work incorporates it, or the parties execute it separately.

01

Status and scope of this DPA

This Data Processing Agreement (“DPA”) forms part of a written agreement only where an order form or statement of work expressly incorporates it, or both parties sign it. It applies when Root Digit processes Personal Data on Customer’s behalf to provide the Services.

Customer is the Controller or Data Fiduciary and Root Digit is the Processor or Data Processor, except where applicable law assigns a different role for a specific activity. Capitalised terms not defined here have the meaning in the main agreement.

02

Applicable law and definitions

“Applicable Data Protection Law” means privacy and data-protection law that applies to the relevant processing, including applicable provisions of the India Digital Personal Data Protection Act, 2023 and rules in force, the UAE Federal Decree-Law No. 45 of 2021, U.S. state privacy law, and any contractually agreed regime.

“Personal Data”, “Process”, “Controller”, “Processor”, “Data Principal”, “Data Subject”, “Personal Data Breach” and “Sub-processor” carry the meanings given by applicable law. “Customer Data” is data submitted to or generated for Customer through the Services.

03

Documented instructions and responsibilities

Root Digit will process Personal Data only to provide and secure the Services, comply with Customer’s documented lawful instructions, and meet law. The agreement, configuration choices, support requests and written instructions together form Customer’s instructions.

  • Customer determines the purpose, lawful basis, data scope, notices, permissions and retention instructions.
  • Root Digit will inform Customer if an instruction appears to violate Applicable Data Protection Law and may pause the affected processing while the parties resolve it.
  • Personnel authorised to process Personal Data are bound by confidentiality and receive access appropriate to their role.

04

Security measures

Root Digit will maintain measures appropriate to the nature, scope, context and risk of the processing. The exact controls may evolve as threats and Services change, without materially reducing overall protection during a committed term.

Control areaIllustrative measures
Identity and accessRole-based access, least privilege, authentication controls, access review and timely revocation.
Data protectionEncryption in transit, protected secrets, tenant or environment separation and controlled backup access.
Secure engineeringCode review, dependency management, change control, vulnerability handling and environment separation.
OperationsLogging, monitoring, incident procedures, recovery planning and controlled administrative access.
People and suppliersConfidentiality commitments, security awareness, need-to-know access and risk-based supplier review.

No certification claim

These measures describe contractual safeguards. They do not state that Root Digit holds a particular certification unless a current certificate is separately provided.

05

Sub-processors

Customer grants general authorisation for Root Digit to use Sub-processors needed to provide the Services. Root Digit will maintain a current list for the relevant Service and make it available on request or through the client portal where supported.

Root Digit will impose data-protection obligations appropriate to the processing and remains responsible for a Sub-processor’s performance to the extent required by the agreement and law. Where required, Root Digit will give advance notice of a material new Sub-processor and allow Customer to object on reasonable data-protection grounds. The parties will work in good faith on an alternative; if none is reasonably available, either party may terminate only the affected Service.

06

Cross-border transfers

Root Digit will not transfer Personal Data across borders contrary to Applicable Data Protection Law. Where a transfer mechanism is required, the parties will use an approved contractual mechanism, consent or other lawful basis and implement supplementary safeguards appropriate to identified risk.

For UAE and Indian data, Root Digit will follow applicable transfer restrictions and government notifications in force. Customer will identify localisation or sector-specific restrictions before processing begins.

07

Personal Data Breach

After confirming a Personal Data Breach affecting Customer Data, Root Digit will notify Customer without undue delay and provide available information reasonably needed for Customer’s assessment and notices: nature of the breach, affected data and people, likely consequences, containment, remediation and a contact point.

Notice is not an admission of fault. Root Digit will take reasonable steps to contain, investigate and remediate the breach and will not notify affected individuals or regulators on Customer’s behalf unless required by law or authorised in writing.

08

Rights, assessments and regulator assistance

Taking account of the nature of processing and information available, Root Digit will reasonably assist Customer with verified requests from Data Subjects or Data Principals, security obligations, breach notifications, data-protection impact assessments and regulator consultations required by applicable law.

Root Digit will not respond directly to a request concerning Customer-controlled data unless Customer authorises it or law requires it. Customer is responsible for deciding the request and providing instructions.

09

Return, deletion and retention

During the term, Customer may export data using available functionality or agreed assistance. On termination and written request, Root Digit will return or delete Customer Personal Data within the contractually stated period, unless law requires retention. Data in protected backups will remain isolated from ordinary use and be deleted through the normal backup lifecycle.

10

Information and audits

Root Digit will provide information reasonably necessary to demonstrate compliance, such as security descriptions, relevant reports or written responses. If that material is insufficient and law requires an audit right, Customer may conduct one audit per year on reasonable notice through an independent qualified auditor bound by confidentiality.

Audits must avoid access to other customers’ data and unreasonable operational disruption. Customer bears its audit costs unless the audit identifies material non-compliance by Root Digit, in which case Root Digit will remediate and bear reasonable directly related re-audit costs.

11

Annex I — Processing details

ElementDescription
Subject matterPersonal Data processed to provide, secure, support and maintain the Services purchased by Customer.
DurationThe agreement term plus deletion, backup, legal-hold and transition periods stated in the agreement.
Data subjectsCustomer personnel, users, clients, suppliers, applicants, end users or other people whose data Customer submits.
Data typesIdentity, contact, account, professional, transaction, communication, device, usage and Customer-configured data.
Sensitive dataNot intended unless expressly documented, necessary, lawful and protected by agreed additional safeguards.
FrequencyContinuous, periodic or one-time according to the Service and Customer’s use.
PurposeHosting, storage, transmission, retrieval, support, security, development or other operations documented in the order.

12

Conflict, liability and contact

This DPA prevails over the main agreement only for conflicting data-protection terms. Liability under this DPA is subject to the agreement’s liability framework unless Applicable Data Protection Law prohibits that limitation.

DPA notices and requests should use the legal enquiry route. The request should identify the customer, agreement and relevant Service. Execution copies and Service-specific annexes may be requested through the same route.

Questions, notices or rights requests

Use Root Digit’s structured enquiry form and select “Privacy, legal or rights request”. Do not include passwords, access keys, or confidential credentials.

Submit a legal enquiry

Entity status

Know which company you are dealing with.

The entity named in an executed order form or statement of work is the contracting entity. A regional reference does not create a local establishment.

Root Digit LLC

Current operating and contracting company. Registered office: 1309 Coffeen Avenue STE 1200, Sheridan, Wyoming 82801, United States.

Root Digit Private Limited

Proposed Indian affiliate; incorporation pending. It is not presently a contracting party. After incorporation, it will be bound only where it is expressly named in the applicable agreement.

United Arab Emirates

UAE customers may be served cross-border by the contracting entity identified in their agreement. These pages do not represent that Root Digit presently maintains a UAE-incorporated entity, licensed branch, or DIFC establishment.

Privacy choices

We use necessary browser storage and security technology to operate this website. You may also allow optional functional and aggregate measurement technology. We do not currently use advertising cookies. Learn more