01
Scope, entities and privacy roles
This Privacy Policy explains how Root Digit handles personal data when you visit rootdigit.com, submit an enquiry, apply for a role, use a Root Digit account or product, communicate with us, or represent a customer, supplier or partner.
Root Digit LLC is the controller of website, commercial, recruitment and account-administration data unless another incorporated Root Digit entity is expressly identified at collection. Root Digit Private Limited is proposed and does not presently control data or contract. When we process personal data only on a customer’s documented instructions, that customer is controller and our Data Processing Agreement applies.
02
Personal data we collect
| Category | Examples | Typical source |
|---|---|---|
| Identity and contact | Name, work email, telephone number, country, correspondence address where required. | You, your organisation or an authorised representative. |
| Professional and organisation | Employer, role, department, business need, procurement context and professional profiles. | You, your organisation and public professional sources. |
| Enquiry and relationship | Messages, meeting preferences, proposals, contracts, support records, feedback and customer history. | Your interactions with Root Digit. |
| Account and security | Account identifier, permissions, authentication events, IP address, device/browser data and audit logs. | Our systems, security providers and your device. |
| Transactions | Plan, order, invoice, tax jurisdiction, payment status and payment-provider reference. We do not intentionally store full card details. | You, the contracting organisation and payment providers. |
| Recruitment | Application answers, CV, GitHub contribution evidence, work history, eligibility, interview notes and consent records. | Candidates, referees and public professional sources. |
| Website use | Pages requested, timestamps, referring page, approximate location derived from IP and performance/error events. | Browsers, servers and infrastructure providers. |
We ask you not to send passwords, private keys, access tokens, government identifiers, financial credentials, health data or other sensitive information unless we specifically request it through an approved secure process.
03
Purposes and lawful bases
| Purpose | Data used | Basis where required |
|---|---|---|
| Respond and contract | Identity, contact, organisation, enquiry and transaction data. | Steps at your request, contract performance and legitimate business interests. |
| Deliver and support Services | Account, relationship, transaction, Customer Data and support records. | Contract performance and documented customer instructions. |
| Secure systems and prevent misuse | Account, device, IP, audit, fraud and usage signals. | Legitimate interests, legal obligations and protection of rights. |
| Operate the business | Contracts, invoices, supplier, governance, audit and correspondence records. | Contract, legal obligations and legitimate interests. |
| Recruit | Application, professional, assessment, communication and eligibility data. | Steps before a contract, consent where required, and legitimate interests. |
| Communicate relevant updates | Contact, role, relationship and communication preferences. | Consent where required or legitimate interests for proportionate business communication. |
| Meet legal obligations | Records reasonably required for tax, accounting, sanctions, litigation or regulator requests. | Legal obligation, public interest or establishment and defence of claims. |
Where consent is the legal basis, you may withdraw it prospectively. Withdrawal does not invalidate earlier processing. We do not use consent where the processing is genuinely required to perform a contract or meet law.
04
Who receives personal data
We disclose personal data only for a defined purpose and subject to appropriate access, confidentiality and contractual controls.
- Service providers: cloud hosting, security, communications, collaboration, customer support, payment, analytics and professional-service providers.
- Customer or organisation: where you interact with us on its behalf, relevant records may be available to its authorised administrators.
- Professional advisers: lawyers, auditors, insurers, accountants and due-diligence advisers under confidentiality obligations.
- Authorities and affected parties: where reasonably necessary to comply with law, protect safety or rights, investigate misuse, or establish and defend legal claims.
- Corporate transactions: a genuine prospective or completed merger, financing, reorganisation or sale, subject to confidentiality and lawful-use restrictions.
No data brokerage
05
International transfers
Root Digit operates and uses service providers across borders. Personal data may therefore be processed outside your country, including in the United States and locations used by contracted infrastructure providers.
Where transfer restrictions apply, we use a legally recognised mechanism or another lawful basis, assess relevant risks, apply contractual and technical safeguards, and limit access to what is necessary. UAE, Indian and U.S. regional rights remain available to the extent applicable.
06
Retention
| Record | Typical retention approach |
|---|---|
| Unsuccessful general enquiries | Up to 24 months after the last meaningful interaction, unless an earlier deletion request applies. |
| Customer and contract records | For the relationship and generally up to 7 years afterward for tax, accounting, warranty and claims records. |
| Security and access logs | Usually 90 days to 24 months depending on system risk, investigation needs and contractual requirements. |
| Recruitment applications | Up to 24 months after the process closes, unless law, consent or an active dispute requires a different period. |
| Marketing preferences | Until opt-out, plus a limited suppression record so the preference can be honoured. |
| Customer Data | As stated in the agreement; deleted or returned after termination subject to backups and legal holds. |
These are default periods, not promises to keep every record for the maximum. We may retain less where the purpose ends, or longer where law, litigation hold, fraud prevention or a signed agreement requires it. Backups are isolated and age out under controlled schedules.
07
Security and incident response
We use risk-appropriate administrative, technical and organisational measures, which may include least-privilege access, authentication controls, encryption in transit, protected secrets, logging, backups, dependency management, vulnerability remediation, supplier review and incident procedures. No system is absolutely secure.
If a confirmed personal-data incident triggers a legal or contractual notice obligation, Root Digit will notify the appropriate customer, regulator or affected individual within the applicable period and provide information reasonably available at that time.
08
Your privacy rights
Depending on your location, our role and applicable statutory thresholds, you may request access or confirmation, correction, deletion, restriction, portability, withdrawal of consent, objection to certain processing, an explanation of certain decisions, nomination of another person, or an appeal of a request decision. You may also complain to the competent regulator.
| Region | Rights recognised where applicable |
|---|---|
| India | Rights available under the Digital Personal Data Protection Act, 2023 and provisions brought into force, including access to prescribed information, correction, erasure, grievance redressal and nomination. |
| United Arab Emirates | Access and information, correction, erasure, restriction or cessation, portability and objection to certain automated processing, subject to statutory exceptions. |
| United States | Rights under applicable state law, potentially including know/access, delete, correct, portability, opt out of sale, sharing, targeted advertising or certain profiling, and non-discrimination. |
Submit a request through the privacy and legal enquiry route. We may verify identity and authority, narrow an overbroad request, or deny a request where law permits. We will explain a denial and available appeal route. Authorised agents must provide evidence of authority.
09
Additional U.S., India and UAE notices
United States
During the preceding twelve months, Root Digit has collected the categories described in this Policy for the stated business purposes and disclosed relevant categories to service providers and other recipients described above. We have not sold personal information or shared it for cross-context behavioural advertising. We do not offer a financial incentive for personal data. Where a legally recognised opt-out signal such as Global Privacy Control applies to our processing, we will treat it as a request for the relevant browser or device.
India
Where Indian data-protection law applies, Root Digit will provide required notice, process digital personal data for lawful purposes, maintain reasonable safeguards, enable grievance handling and honour rights within applicable statutory timelines. References to the DPDP framework apply according to its phased commencement. The Grievance Officer role can be reached through the legal enquiry route.
United Arab Emirates
Where the UAE Personal Data Protection Law applies, Root Digit will rely on consent or another lawful ground, maintain appropriate security, support data-subject rights and apply lawful cross-border transfer safeguards. Sector-specific or free-zone rules may apply instead for particular processing; the customer agreement will identify that context.
10
Children and automated decisions
Root Digit’s commercial website and Services are not directed to children, and we do not knowingly collect personal data from children through this website. If you believe a child has submitted data, use the legal enquiry route so we can investigate and take appropriate action. A product designed for education or minors requires a separate approved scope, notices, permissions and safeguards.
We may use automation to route enquiries, detect misuse or support evaluation, but we do not use website data to make a solely automated decision that produces legal or similarly significant effects about an individual. Human review remains available where required.
11
Third-party sites and social platforms
Links to client portals, social networks, translation services or other third-party sites take you to services operated under their own notices. We receive only information those platforms lawfully provide to us, such as messages, public profile details or aggregate page statistics. This website does not currently deploy social-media advertising pixels.
12
Contact, complaints and changes
Submit privacy requests, complaints or appeals through the structured legal enquiry form. Select “Privacy, legal or rights request” and describe the relationship, right and relevant account or interaction without sending secrets.
We may update this Policy when our processing, Services or law changes. The effective date and version will change, and material changes will be communicated through an appropriate channel. Previous versions may be requested where reasonably required for a transaction or claim.
Questions, notices or rights requests
Use Root Digit’s structured enquiry form and select “Privacy, legal or rights request”. Do not include passwords, access keys, or confidential credentials.
Submit a legal enquiryRelated documents