ROOTCR HU

Privacy Notice

In short: rootcr.com collects personal data in exactly one place: the quote request form. I use what you provide there solely to answer your enquiry, on the basis of your consent, for 24 months. There is no cookie-based tracking, no advertising pixel and no analytics service on the site. The server log records technical data for security purposes. The data controller is a US-registered company, but the data sits on a server in the European Union, and access to it also happens from the EU.

The data controller

ItemDetail
ControllerRootCore, LLC (Delaware, United States)
Registered address1111B S Governors Ave STE 59361, Dover, DE 19904, United States
Place of operation and data processingHungary (European Union)
Emailinfo@rootcr.com

I am not required to appoint a data protection officer, and I have not appointed one.

Where is your data?

The controller is a company registered in the United States, but the actual work and the data processing take place from the European Union (Hungary), and the server is located within the European Union. The place of registration is a legal fact, the location of the data is a technical one — the two are not the same, and from your point of view the second one matters: the data from your quote request is not transferred to a third country. If that ever changes, I will state it in this notice in advance.

What I process, for what purpose, and for how long

1. Quote request form

AspectContent
Data processedName, company name, email address, phone number, project type, the text of the message
PurposeAnswering the enquiry, preparing a quote, keeping in touch
Legal basisConsent of the data subject — GDPR Article 6(1)(a)
Duration24 months from receipt, or until consent is withdrawn
ConsequenceWithout this data I cannot answer the enquiry

Technical data is recorded along with the submission: the time of submission, the sender's IP address and the browser identifier (user agent). These are needed to recognise abuse (automated mass submission) and to enforce the per-submission rate limit.

2. Server log

AspectContent
Data processedIP address, timestamp, requested page address, HTTP status, browser identifier
PurposeOperating the service, troubleshooting, protection against abuse
Legal basisLegitimate interest — GDPR Article 6(1)(f): secure operation of the server
DurationAt most 30 days

3. Direct correspondence

If you write by email, I keep the content of the correspondence for the duration of our contact and for 24 months afterwards, on the basis of legitimate interest (documenting the collaboration).

4. Published client testimonials

AspectContent
Data processedThe client's name, professional title, the address of their own website, the text of the testimonial and its date
PurposeReference: presenting verifiable feedback on work delivered
Legal basisThe explicit, written consent of the data subject — GDPR Article 6(1)(a)
DurationUntil consent is withdrawn
ConsequenceGiving consent is entirely voluntary; it is not a condition of any engagement

A testimonial is published only with prior written consent, and only in the form of the name that consent covers. Consent may be withdrawn at any time, without giving reasons, in a single email to info@rootcr.com; after withdrawal the testimonial is removed at the next publication, and in any case within 5 working days — from both the Hungarian and the English version of the site. Withdrawal does not affect the lawfulness of publication before it.

5. Chat on the site

The "Message me" tab at the edge of the page opens a chat window: you write there, and you get the reply in the same place.

AspectDetails
Data processedThe text of your messages, the conversation identifier, the address of the page you wrote from, the times, your IP address, your browser identifier and the country the request came from; if you provide it: your email address or phone number
PurposeAnswering your question in the chat window or — if you leave a contact — through that contact
Legal basisSteps taken at your request before entering into a contract — GDPR Art. 6(1)(b); when you leave a contact, your consent — GDPR Art. 6(1)(a)
Duration24 months from the last message
ConsequenceChatting is voluntary; I only ask for a contact if I could not reply within 10 minutes, and even then it is optional

Every message — yours and my replies — is logged with the time it was sent, the IP address, the browser identifier and the page address, and so are rejected attempts (messages stopped by the bot filter, the message limit or the size limit), to protect against abuse — legitimate interest, GDPR Art. 6(1)(f). The retention period is the same: 24 months.

The conversation identifier is kept in your browser's local storage (localStorage) — not a cookie — so that you still see the earlier messages after changing page or reloading. The browser discards it after 24 hours of inactivity; I do not use it for tracking.

I receive your messages on my phone through a messaging service and reply from there. That service operates outside the European Union, and no Commission adequacy decision covers the transfer; the transfer takes place at your request, to answer your question — GDPR Art. 49(1)(b). So please do not write health data or other special category data, passwords or card numbers in the chat. For sensitive matters, write an email: info@rootcr.com.

What I do NOT do

  • No cookie-based visitor tracking, no advertising pixel, no social media embeds.
  • No profiling and no automated decision-making.
  • I do not sell the data, and I do not use it for newsletters without your consent.
  • The site's fonts load from my own server, not from an external font service — so your browser does not connect to a third party for that purpose.

Processors

I use the following services to operate. These providers process the data only to the extent necessary to deliver their service:

ProcessorWhat it doesWhat data it can access
Hosting provider located in the European UnionHosting and serverAll data stored on the server
Content delivery and attack protection provider (USA)Content delivery, attack protection, human verification on the formIP address, request data
Email service provider (USA)Delivering the notification from the form and the confirmation emailThe data contained in the email
Messaging service provider (outside the EU)Forwarding chat messages to my phone and returning my replyThe text of the messages, the page address, the country, and your contact if you provide it

The law requires the category of recipient to be stated; I provide the names of the specific providers on request, in writing, for security reasons.

As the table shows, two processors are US-based. Transfers outside the European Union with them take place under the standard contractual clauses adopted by the European Commission. There is no such contract with the messaging service provider: chat messages are forwarded at your request, see point 5. The hosting — that is, where your quote request is actually stored — is in the European Union regardless.

Your rights

You may request at any time:

  • information about the data processed about you, and a copy of it,
  • rectification of inaccurate data,
  • erasure of your data,
  • restriction of processing,
  • your data in a portable format,
  • you may object to processing based on legitimate interest,
  • you may withdraw your consent — this does not affect the lawfulness of processing before the withdrawal.

Send your request to info@rootcr.com. You will receive a reply within one month at the latest.

If you live outside the European Union, you have the same rights on request: I do not run a separate, weaker regime by region.

Remedies

If you believe the processing infringes your rights, you may lodge a complaint with the supervisory authority of your own EU member state, or with the authority of the place of processing — the Hungarian National Authority for Data Protection and Freedom of Information (NAIH, 1055 Budapest, Falk Miksa utca 9-11., ugyfelszolgalat@naih.hu) — or you may go to court.

Data security

I receive the data over an encrypted connection (HTTPS), store it on the server in a directory with restricted access, and the receiving service runs as a separate process with limited privileges. Regular, encrypted backups are made of the data. After the retention period expires, the data is deleted automatically.

Updated: September 24, 2026

Message me

Message me now

Write any time — evenings and weekends too. As soon as I see it, I reply right here, in this window.

Hi! Tell me how I can help. No form to fill in, just write.

Your message is processed to answer your enquiry. Privacy

Prefer Telegram? Telegram