# Privacy Notice

URL: https://rootcr.com/privacy/
Updated: 2026-08-23

# Privacy Notice

> **In short:** rootcr.com collects personal data in exactly one place: the quote request form. I use what you provide there solely to answer your enquiry, on the basis of your consent, for 24 months. There is no cookie-based tracking, no advertising pixel and no analytics service on the site. The server log records technical data for security purposes. The data controller is a US-registered company, but the data sits on **a server in the European Union**, and access to it also happens from the EU.

## The data controller

| Item | Detail |
|---|---|
| Controller | RootCore, LLC (Delaware, United States) |
| Registered address | 1111B S Governors Ave STE 59361, Dover, DE 19904, United States |
| Place of operation and data processing | Hungary (European Union) |
| Email | info@rootcr.com |

I am not required to appoint a data protection officer, and I have not appointed one.

### Where is your data?

The controller is a company registered in the United States, but the actual work and the data processing take place from the European Union (Hungary), and the server is located within the European Union. **The place of registration is a legal fact, the location of the data is a technical one** — the two are not the same, and from your point of view the second one matters: the data from your quote request is not transferred to a third country. If that ever changes, I will state it in this notice in advance.

## What I process, for what purpose, and for how long

### 1. Quote request form

| Aspect | Content |
|---|---|
| Data processed | Name, company name, email address, phone number, project type, the text of the message |
| Purpose | Answering the enquiry, preparing a quote, keeping in touch |
| Legal basis | Consent of the data subject — GDPR Article 6(1)(a) |
| Duration | 24 months from receipt, or until consent is withdrawn |
| Consequence | Without this data I cannot answer the enquiry |

Technical data is recorded along with the submission: the time of submission, the sender's IP address and the browser identifier (user agent). These are needed to recognise abuse (automated mass submission) and to enforce the per-submission rate limit.

### 2. Server log

| Aspect | Content |
|---|---|
| Data processed | IP address, timestamp, requested page address, HTTP status, browser identifier |
| Purpose | Operating the service, troubleshooting, protection against abuse |
| Legal basis | Legitimate interest — GDPR Article 6(1)(f): secure operation of the server |
| Duration | At most 30 days |

### 3. Direct correspondence

If you write by email, I keep the content of the correspondence for the duration of our contact and for 24 months afterwards, on the basis of legitimate interest (documenting the collaboration).

## What I do NOT do

- No cookie-based visitor tracking, no advertising pixel, no social media embeds.
- No profiling and no automated decision-making.
- I do not sell the data, and I do not use it for newsletters without your consent.
- The site's fonts load from my own server, not from an external font service — so your browser does not connect to a third party for that purpose.

## Processors

I use the following services to operate. These providers process the data only to the extent necessary to deliver their service:

| Processor | What it does | What data it can access |
|---|---|---|
| Hosting provider located in the European Union | Hosting and server | All data stored on the server |
| Content delivery and attack protection provider (USA) | Content delivery, attack protection, human verification on the form | IP address, request data |
| Email service provider (USA) | Delivering the notification from the form and the confirmation email | The data contained in the email |

The law requires the *category* of recipient to be stated; I provide the names of the specific providers on request, in writing, for security reasons.

As the table shows, two processors are US-based. Transfers outside the European Union with them take place under the standard contractual clauses adopted by the European Commission. The **hosting** — that is, where your quote request is actually stored — is in the European Union regardless.

## Your rights

You may request at any time:

- **information** about the data processed about you, and a copy of it,
- **rectification** of inaccurate data,
- **erasure** of your data,
- **restriction** of processing,
- your data **in a portable format**,
- you may object to processing based on legitimate interest,
- you may **withdraw your consent** — this does not affect the lawfulness of processing before the withdrawal.

Send your request to info@rootcr.com. You will receive a reply within one month at the latest.

If you live outside the European Union, you have the same rights on request: I do not run a separate, weaker regime by region.

## Remedies

If you believe the processing infringes your rights, you may lodge a complaint with the supervisory authority of your own EU member state, or with the authority of the place of processing — the Hungarian National Authority for Data Protection and Freedom of Information (NAIH, 1055 Budapest, Falk Miksa utca 9-11., ugyfelszolgalat@naih.hu) — or you may go to court.

## Data security

I receive the data over an encrypted connection (HTTPS), store it on the server in a directory with restricted access, and the receiving service runs as a separate process with limited privileges. Regular, encrypted backups are made of the data. After the retention period expires, the data is deleted automatically.
