GDPR Compliance Policy

How OneRoot ProTech meets its obligations under the EU and UK General Data Protection Regulation.

Last updated: August 15, 2026

This policy supplements our Privacy Policy and explains how OneRoot ProTech complies with the General Data Protection Regulation (EU) 2016/679 and the UK GDPR when processing personal data of individuals in the European Economic Area and the United Kingdom.

1. Our role: controller and processor

We act as a data controller for the B2B contact databases we build and maintain, for our website, and for our own marketing. We act as a data processor when we process personal data on behalf of a client under their instructions — for example, calling or emailing a contact list the client provides. When acting as a processor, we operate under data processing agreements that meet the requirements of Article 28 GDPR.

2. What we process and why

We process business contact data only: name, job title, employer, business email, business phone, and company firmographics. We use this data to connect business professionals with relevant technology content, events, and solutions, and to provide verification, enrichment, and demand generation services to our clients. We do not process special category data, and we do not carry out automated decision-making that produces legal or similarly significant effects.

3. Lawful bases

Our processing relies on: legitimate interests (Article 6(1)(f)) for B2B contact data processed in the context of a person's professional role, supported by documented balancing assessments; consent (Article 6(1)(a)) where we ask for it, such as newsletter subscriptions or non-essential cookies; contract (Article 6(1)(b)) for services requested from us; and legal obligation (Article 6(1)(c)) where retention or disclosure is required by law. Direct marketing under legitimate interests always carries an unconditional right to object.

4. Data subject rights

If you are in the EEA or UK, you may exercise the following rights at any time, free of charge:

  • Access (Art. 15) — obtain confirmation of processing and a copy of your data;
  • Rectification (Art. 16) — correct inaccurate or incomplete data;
  • Erasure (Art. 17) — have your data deleted where no overriding ground for retention exists;
  • Restriction (Art. 18) — limit processing while a dispute or verification is resolved;
  • Portability (Art. 20) — receive your data in a structured, machine-readable format;
  • Objection (Art. 21) — object to processing based on legitimate interests, including direct marketing. Objections to direct marketing are always honored without exception.

Submit any request to info@onerootprotech.com with the subject "GDPR Request". We respond within one month; complex requests may take up to three months, in which case we will tell you why. We may ask for information to verify your identity before acting.

5. Where your data comes from

Where we have not collected your data from you directly, it originates from publicly available professional sources, licensed data providers, or client-supplied lists, as described in our Privacy Policy. In line with Article 14, we identify ourselves and the source of the data in our first communication with you, and always include the means to object or opt out.

6. International transfers

Where personal data originating in the EEA or UK is transferred outside those territories — including to our delivery and service teams — we rely on European Commission adequacy decisions where available, and otherwise on Standard Contractual Clauses (and the UK International Data Transfer Addendum), together with technical and organizational safeguards.

7. Retention

Business contact records are retained while they remain accurate and relevant to the professional context in which they were collected, and are re-verified on a periodic cycle. Records are suppressed or erased when they become inaccurate, on objection, or when retention can no longer be justified. Opt-out and suppression records are retained indefinitely to ensure your preference is respected.

8. Security and breach notification

We implement technical and organizational measures appropriate to the risk, including encrypted transmission, access controls, and staff confidentiality obligations. In the event of a personal data breach likely to result in a risk to individuals, we will notify the competent supervisory authority within 72 hours and affected individuals without undue delay, in accordance with Articles 33 and 34.

9. Complaints

We would welcome the chance to resolve any concern directly — contact us first at info@onerootprotech.com. You also have the right to lodge a complaint with your local supervisory authority, or with the UK Information Commissioner's Office (ico.org.uk) if you are in the UK.

Ready to build a stronger pipeline?

Tell us your revenue goals — we'll show you the fastest route to them.

Talk to Our Team