This Privacy Policy explains how RootSystems ("we," "us," or "our") collects, uses, and protects information when you use our products, including Offboarding Proof, TPRA, the HIPAA Compliance Tool, and AI Compliance Readiness (collectively, the "Services").
1. Information We Collect
Account information: When you sign up, we collect your name, email address, organization name, and password (stored as a secure hash, never in plain text).
Usage information: We collect information about how you use the Services, including questionnaire responses, assessment results, and activity logs (such as login times and actions taken within the product).
Integration data: For Services that connect to third-party systems (such as Offboarding Proof's checks against Google Workspace, Slack, or GitHub), we access only the specific data needed to perform the requested verification, such as user access status, and do not use this access for any purpose beyond delivering the Service.
Payment information: Payment details are handled directly by our third-party payment processor. We do not store your full credit card or payment information on our own servers.
2. How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the Services
- Generate the assessments, scores, and reports you request
- Communicate with you about your account, including security notices and support
- Improve and secure our Services
- Comply with legal obligations
3. How We Protect Your Information
We use industry-standard security practices to protect your data, including encrypted storage of sensitive credentials, access controls, and cryptographic tamper-evidence measures on generated reports. No system is perfectly secure, and we continually work to improve our security practices.
4. Data Sharing
We do not sell your personal data or organizational data to third parties. We may share data with:
- Service providers who help us operate the Services (such as hosting providers and our payment processor), under agreements that require them to protect your data
- Legal authorities, if required to comply with a valid legal process
- A successor entity, in the event of a merger, acquisition, or sale of assets, with notice to you where required by law
5. Data Retention
We retain your data for as long as your account is active, or as needed to provide the Services. If you close your account, we will delete or anonymize your data within a reasonable period, except where we are required to retain it for legal, tax, or audit-trail purposes (for example, tamper-evident historical reports that support an audit trail may be retained per their original design intent).
6. Your Rights
Depending on your location, you may have rights to access, correct, delete, or export your personal data. To exercise these rights, contact us at therootsystems.ops@gmail.com. We will respond within a reasonable timeframe and in accordance with applicable law.
7. International Data Transfers
Our Services may involve transferring data across borders, including to and from the United States and India, depending on where our infrastructure and our customers are located. We take reasonable steps to ensure data is protected consistent with this Policy regardless of where it is processed.
8. Cookies and Tracking
We use essential cookies to keep you logged in and to remember basic preferences. We do not use third-party advertising trackers.
9. Children's Privacy
Our Services are intended for business use and are not directed at individuals under 18. We do not knowingly collect personal information from children.
10. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will provide reasonable notice before the changes take effect.
11. Contact Us
If you have questions about this Privacy Policy or how we handle your data, contact us at therootsystems.ops@gmail.com.