Legal centre Data privacy

Privacy Policy

A plain-language account of the personal data Root Digit handles and the choices available to you.

This Policy covers Root Digit’s own processing. A customer’s use of personal data within a system we build or host may be governed by that customer’s privacy notice, with Root Digit acting as its processor or service provider.

01

Scope, entities and privacy roles

This Privacy Policy explains how Root Digit handles personal data when you visit rootdigit.com, submit an enquiry, apply for a role, use a Root Digit account or product, communicate with us, or represent a customer, supplier or partner.

Root Digit LLC is the controller of website, commercial, recruitment and account-administration data unless another incorporated Root Digit entity is expressly identified at collection. Root Digit Private Limited is proposed and does not presently control data or contract. When we process personal data only on a customer’s documented instructions, that customer is controller and our Data Processing Agreement applies.

02

Personal data we collect

CategoryExamplesTypical source
Identity and contactName, work email, telephone number, country, correspondence address where required.You, your organisation or an authorised representative.
Professional and organisationEmployer, role, department, business need, procurement context and professional profiles.You, your organisation and public professional sources.
Enquiry and relationshipMessages, meeting preferences, proposals, contracts, support records, feedback and customer history.Your interactions with Root Digit.
Account and securityAccount identifier, permissions, authentication events, IP address, device/browser data and audit logs.Our systems, security providers and your device.
TransactionsPlan, order, invoice, tax jurisdiction, payment status and payment-provider reference. We do not intentionally store full card details.You, the contracting organisation and payment providers.
RecruitmentApplication answers, CV, GitHub contribution evidence, work history, eligibility, interview notes and consent records.Candidates, referees and public professional sources.
Website usePages requested, timestamps, referring page, approximate location derived from IP and performance/error events.Browsers, servers and infrastructure providers.

We ask you not to send passwords, private keys, access tokens, government identifiers, financial credentials, health data or other sensitive information unless we specifically request it through an approved secure process.

03

Purposes and lawful bases

PurposeData usedBasis where required
Respond and contractIdentity, contact, organisation, enquiry and transaction data.Steps at your request, contract performance and legitimate business interests.
Deliver and support ServicesAccount, relationship, transaction, Customer Data and support records.Contract performance and documented customer instructions.
Secure systems and prevent misuseAccount, device, IP, audit, fraud and usage signals.Legitimate interests, legal obligations and protection of rights.
Operate the businessContracts, invoices, supplier, governance, audit and correspondence records.Contract, legal obligations and legitimate interests.
RecruitApplication, professional, assessment, communication and eligibility data.Steps before a contract, consent where required, and legitimate interests.
Communicate relevant updatesContact, role, relationship and communication preferences.Consent where required or legitimate interests for proportionate business communication.
Meet legal obligationsRecords reasonably required for tax, accounting, sanctions, litigation or regulator requests.Legal obligation, public interest or establishment and defence of claims.

Where consent is the legal basis, you may withdraw it prospectively. Withdrawal does not invalidate earlier processing. We do not use consent where the processing is genuinely required to perform a contract or meet law.

04

Who receives personal data

We disclose personal data only for a defined purpose and subject to appropriate access, confidentiality and contractual controls.

  • Service providers: cloud hosting, security, communications, collaboration, customer support, payment, analytics and professional-service providers.
  • Customer or organisation: where you interact with us on its behalf, relevant records may be available to its authorised administrators.
  • Professional advisers: lawyers, auditors, insurers, accountants and due-diligence advisers under confidentiality obligations.
  • Authorities and affected parties: where reasonably necessary to comply with law, protect safety or rights, investigate misuse, or establish and defend legal claims.
  • Corporate transactions: a genuine prospective or completed merger, financing, reorganisation or sale, subject to confidentiality and lawful-use restrictions.

No data brokerage

Root Digit does not sell personal data for money and does not currently share personal data for cross-context behavioural advertising. If that practice changes, we will update this notice and provide legally required choices before the change applies.

05

International transfers

Root Digit operates and uses service providers across borders. Personal data may therefore be processed outside your country, including in the United States and locations used by contracted infrastructure providers.

Where transfer restrictions apply, we use a legally recognised mechanism or another lawful basis, assess relevant risks, apply contractual and technical safeguards, and limit access to what is necessary. UAE, Indian and U.S. regional rights remain available to the extent applicable.

06

Retention

RecordTypical retention approach
Unsuccessful general enquiriesUp to 24 months after the last meaningful interaction, unless an earlier deletion request applies.
Customer and contract recordsFor the relationship and generally up to 7 years afterward for tax, accounting, warranty and claims records.
Security and access logsUsually 90 days to 24 months depending on system risk, investigation needs and contractual requirements.
Recruitment applicationsUp to 24 months after the process closes, unless law, consent or an active dispute requires a different period.
Marketing preferencesUntil opt-out, plus a limited suppression record so the preference can be honoured.
Customer DataAs stated in the agreement; deleted or returned after termination subject to backups and legal holds.

These are default periods, not promises to keep every record for the maximum. We may retain less where the purpose ends, or longer where law, litigation hold, fraud prevention or a signed agreement requires it. Backups are isolated and age out under controlled schedules.

07

Security and incident response

We use risk-appropriate administrative, technical and organisational measures, which may include least-privilege access, authentication controls, encryption in transit, protected secrets, logging, backups, dependency management, vulnerability remediation, supplier review and incident procedures. No system is absolutely secure.

If a confirmed personal-data incident triggers a legal or contractual notice obligation, Root Digit will notify the appropriate customer, regulator or affected individual within the applicable period and provide information reasonably available at that time.

08

Your privacy rights

Depending on your location, our role and applicable statutory thresholds, you may request access or confirmation, correction, deletion, restriction, portability, withdrawal of consent, objection to certain processing, an explanation of certain decisions, nomination of another person, or an appeal of a request decision. You may also complain to the competent regulator.

RegionRights recognised where applicable
IndiaRights available under the Digital Personal Data Protection Act, 2023 and provisions brought into force, including access to prescribed information, correction, erasure, grievance redressal and nomination.
United Arab EmiratesAccess and information, correction, erasure, restriction or cessation, portability and objection to certain automated processing, subject to statutory exceptions.
United StatesRights under applicable state law, potentially including know/access, delete, correct, portability, opt out of sale, sharing, targeted advertising or certain profiling, and non-discrimination.

Submit a request through the privacy and legal enquiry route. We may verify identity and authority, narrow an overbroad request, or deny a request where law permits. We will explain a denial and available appeal route. Authorised agents must provide evidence of authority.

09

Additional U.S., India and UAE notices

United States

During the preceding twelve months, Root Digit has collected the categories described in this Policy for the stated business purposes and disclosed relevant categories to service providers and other recipients described above. We have not sold personal information or shared it for cross-context behavioural advertising. We do not offer a financial incentive for personal data. Where a legally recognised opt-out signal such as Global Privacy Control applies to our processing, we will treat it as a request for the relevant browser or device.

India

Where Indian data-protection law applies, Root Digit will provide required notice, process digital personal data for lawful purposes, maintain reasonable safeguards, enable grievance handling and honour rights within applicable statutory timelines. References to the DPDP framework apply according to its phased commencement. The Grievance Officer role can be reached through the legal enquiry route.

United Arab Emirates

Where the UAE Personal Data Protection Law applies, Root Digit will rely on consent or another lawful ground, maintain appropriate security, support data-subject rights and apply lawful cross-border transfer safeguards. Sector-specific or free-zone rules may apply instead for particular processing; the customer agreement will identify that context.

10

Children and automated decisions

Root Digit’s commercial website and Services are not directed to children, and we do not knowingly collect personal data from children through this website. If you believe a child has submitted data, use the legal enquiry route so we can investigate and take appropriate action. A product designed for education or minors requires a separate approved scope, notices, permissions and safeguards.

We may use automation to route enquiries, detect misuse or support evaluation, but we do not use website data to make a solely automated decision that produces legal or similarly significant effects about an individual. Human review remains available where required.

11

Third-party sites and social platforms

Links to client portals, social networks, translation services or other third-party sites take you to services operated under their own notices. We receive only information those platforms lawfully provide to us, such as messages, public profile details or aggregate page statistics. This website does not currently deploy social-media advertising pixels.

12

Contact, complaints and changes

Submit privacy requests, complaints or appeals through the structured legal enquiry form. Select “Privacy, legal or rights request” and describe the relationship, right and relevant account or interaction without sending secrets.

We may update this Policy when our processing, Services or law changes. The effective date and version will change, and material changes will be communicated through an appropriate channel. Previous versions may be requested where reasonably required for a transaction or claim.

Questions, notices or rights requests

Use Root Digit’s structured enquiry form and select “Privacy, legal or rights request”. Do not include passwords, access keys, or confidential credentials.

Submit a legal enquiry

Entity status

Know which company you are dealing with.

The entity named in an executed order form or statement of work is the contracting entity. A regional reference does not create a local establishment.

Root Digit LLC

Current operating and contracting company. Registered office: 1309 Coffeen Avenue STE 1200, Sheridan, Wyoming 82801, United States.

Root Digit Private Limited

Proposed Indian affiliate; incorporation pending. It is not presently a contracting party. After incorporation, it will be bound only where it is expressly named in the applicable agreement.

United Arab Emirates

UAE customers may be served cross-border by the contracting entity identified in their agreement. These pages do not represent that Root Digit presently maintains a UAE-incorporated entity, licensed branch, or DIFC establishment.

Privacy choices

We use necessary browser storage and security technology to operate this website. You may also allow optional functional and aggregate measurement technology. We do not currently use advertising cookies. Learn more