Privacy Policy
How OneRoot ProTech collects, uses, shares, and protects personal information — and the rights you have over your data.
Last updated: August 15, 2026
Related policies: GDPR Compliance · CCPA — Do Not Sell or Share My Personal Information · Anti-Spam & Email Compliance
OneRoot ProTech ("OneRoot ProTech", "we", "us", or "our") provides B2B marketing, lead generation, and data services. We are committed to processing personal information lawfully, fairly, and transparently. This Privacy Policy applies to our website, our marketing activities, and the B2B databases we maintain to deliver services to our clients.
This policy is designed to meet the requirements of the EU/UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended by the CPRA (CCPA), Canada's Anti-Spam Legislation (CASL) and PIPEDA, and the U.S. CAN-SPAM Act.
1. Information we collect
Information you provide to us. When you use our contact form, register for an event or webinar, download content, or correspond with us, we collect the information you submit: name, business email address, company, job title, phone number, and the content of your message.
Information collected automatically. When you visit our website we collect technical data such as IP address, browser type, device information, referring pages, and pages visited. This is used for security, troubleshooting, and understanding how our site is used.
Business contact information in our B2B databases. As a B2B data and demand generation company, we maintain databases of business contact records — typically name, job title, business email, business phone, employer, industry, and company firmographics. This information is collected from:
- Publicly available professional sources, such as company websites, press releases, and professional networking profiles;
- Licensed third-party data providers who warrant lawful collection;
- Direct interactions, including content downloads, event registrations, webinar attendance, and telephone conversations;
- Our clients and partners, where they engage us to process data on their behalf.
We process business contact information only — we do not intentionally collect consumer, financial, health, or other sensitive personal data, and we do not knowingly collect any information from anyone under 18 years of age.
2. How we use personal information
- To respond to enquiries and provide the services our clients request;
- To connect business professionals with relevant B2B content, events, and technology solutions on behalf of our clients;
- To verify, correct, and enrich business contact records so the data we process is accurate;
- To send business communications relevant to a recipient's professional role, with a clear way to opt out in every message;
- To operate, secure, and improve our website and services;
- To comply with legal obligations and enforce our agreements.
3. Legal bases for processing (GDPR)
Where the GDPR applies, we rely on the following legal bases: consent, where you have opted in (for example, subscribing to communications or accepting non-essential cookies); legitimate interests, for processing business contact information in the context of the data subject's professional role — including B2B marketing communications — where those interests are not overridden by individual rights and freedoms; contract, where processing is necessary to provide services you have requested; and legal obligation, where we must retain or disclose information by law. Where we rely on legitimate interests, we conduct balancing assessments and honor every objection and opt-out.
4. How we share information
- With our clients, when you engage with a campaign we run on their behalf — for example, downloading a client's whitepaper or registering for their event. The client's own privacy policy also applies in those cases.
- With service providers who support our operations (hosting, email delivery, CRM, analytics), bound by contractual confidentiality and data protection obligations.
- For legal reasons, where disclosure is required by law, court order, or to protect our rights, security, or property.
- In a business transfer, if we are involved in a merger, acquisition, or asset sale, in which case this policy will continue to apply to previously collected data.
We do not sell personal information to data brokers for consumer marketing, and we never share personal information for cross-context behavioral advertising.
5. Your rights
Depending on your jurisdiction, you have the right to:
- Access — request a copy of the personal information we hold about you;
- Rectification — have inaccurate or incomplete information corrected;
- Erasure — request deletion of your personal information ("right to be forgotten");
- Restriction and objection — limit or object to our processing, including direct marketing;
- Portability — receive your data in a structured, machine-readable format;
- Opt out — stop receiving marketing communications at any time via the unsubscribe link in any email or by contacting us;
- Non-discrimination — exercise any of these rights without receiving discriminatory treatment.
To exercise any right, email info@onerootprotech.com with the subject line "Data Rights Request". We respond within 30 days (GDPR) or 45 days (CCPA). We may need to verify your identity before acting on a request. If you are in the EU/UK, you also have the right to lodge a complaint with your local supervisory authority.
6. California residents (CCPA/CPRA)
California residents have the right to know what personal information we collect, use, and disclose; the right to delete; the right to correct; and the right to opt out of the sale or sharing of personal information. The categories of personal information we collect are described in Section 1 and are limited to professional and identification categories (name, business contact details, professional information, and internet activity on our website). We do not sell personal information as most people understand that term; to the extent any disclosure to clients qualifies as a "sale" or "sharing" under the CCPA's broad definitions, you may opt out by emailing info@onerootprotech.com with the subject line "Do Not Sell or Share My Personal Information".
7. Email compliance (CAN-SPAM & CASL)
Every marketing email we send identifies the sender, includes a valid physical or reply address, uses truthful subject lines, and contains a functioning unsubscribe mechanism. Opt-out requests are honored promptly and suppressed permanently across our systems. For Canadian recipients, we send commercial electronic messages only where we have express or implied consent under CASL, and we maintain records of that consent.
8. Data retention
We keep personal information only as long as needed for the purposes described above. Website enquiry records are retained while we handle your request and for a reasonable period afterwards. Business contact records in our databases are periodically re-verified and are suppressed or deleted when they become inaccurate, when the individual objects, or when retention is no longer justified. Suppression lists (opt-outs) are retained indefinitely so your preference is never lost.
9. International data transfers
We operate globally and may transfer personal information across borders, including to service providers in other countries. Where data originating in the EU/UK is transferred internationally, we use appropriate safeguards such as Standard Contractual Clauses and require equivalent protection from our processors.
10. Security
We apply administrative, technical, and physical safeguards appropriate to the data we process: encrypted connections (TLS), access controls on databases and systems, staff confidentiality obligations, and periodic review of our security practices. No method of transmission or storage is completely secure; if a breach affecting your personal information occurs, we will notify you and the relevant authorities as required by law.
11. Cookies
Our website uses strictly necessary cookies required for security and site function (such as CSRF protection). We do not use advertising or cross-site tracking cookies. If we introduce analytics or other non-essential cookies in the future, we will request your consent where required.
12. Third-party links
Our website and communications may contain links to third-party sites, including our clients' content. We are not responsible for the privacy practices of those sites and encourage you to review their policies.
13. Changes to this policy
We may update this policy from time to time. The "Last updated" date at the top reflects the latest revision, and material changes will be highlighted on this page. Continued use of our website after changes constitutes acceptance of the updated policy.
14. Contact us
For any privacy question, request, or complaint, contact our privacy team at info@onerootprotech.com with "Privacy" in the subject line. We aim to acknowledge every privacy enquiry within two business days.