roote.Back to site

ROOTE · ENGLISH TRANSLATION

ROOTE Privacy Policy

1. Purpose and scope

This policy describes the data protection framework of ROOTE services on roote.ai and its subdomains, as well as the roote.si showcase. The features actually used determine the concerned data. Specific information presented in a service, a form or at the time of authorization complements this policy. The GDPR and the French Data Protection Act constitute the applicable framework. External services, notably AI assistants to which a link directs the user, have their own policies.

2. Controller and contact

The services are offered by Roote SAS, a simplified joint-stock company identified by SIREN 841 005 663. Contact address provided for these documents: 128 rue La Boétie, 75008 Paris. Email address: contact@roote.ai. Roote SAS is responsible for processing it determines for its own services. For a service used on behalf of a professional client, the allocation of roles and applicable instructions must be set in the corresponding contractual agreement.

3. Data according to features used

Depending on the activated service, data may include account and contact information, access identifiers and parameters, order and billing references, API usage data, technical connection information, searches and content sent to an AI assistant. Proximity functions may process the position or address provided by the user. Terminal geolocation is requested via browser or device permissions; it may be refused or disabled. A required data and the consequences of its absence must be indicated at the collection point. The roote.si showcase itself does not request account, payment or geolocation.

4. Contact by email

If you write to contact@roote.ai, the processed data are your email address, the content of your message and any information or attachments you choose to send. They are used to process your request, ensure its follow-up and, if necessary, handle a complaint. Avoid sending sensitive data or identity documents if not necessary for your request.

5. Purposes and legal bases

Data necessary for an account, an order, a subscription, an API or an AI request are processed to provide the requested service and execute the contract or necessary pre-contractual measures. Billing and accounting obligations rely on applicable legal requirements. Maintenance, abuse prevention, security and request processing may rely on legitimate interest, considering the person’s rights. Operations requiring consent, notably certain trackers or optional uses, must be subject to prior and specific choice. A technical browser authorization does not exempt from providing information related to processing. No general consent results from mere navigation.

6. Cookies and local storage

The roote.si showcase contains no advertising tracker nor Google Analytics in its code; its language is determined by the page address. ROOTE applications may use technical storage for session, security or preferences, notably mobility modes. Non-essential trackers must be described and submitted to required choice before activation. The configuration specific to each application and its hosting determines the mechanisms present. Disabling certain necessary mechanisms may limit a functionality.

7. Artificial intelligence and external links

A request sent to a ROOTE AI service may contain text, a place, a search context and elements provided by the user. Data necessary for the response may be transmitted to providers involved in this service, according to its configuration and information provided at the point of use. Avoid communicating sensitive data or concerning a third party without necessity. Processing, conversation retention and any other uses must be specified in the concerned service; no advertising use or additional training is authorized by this policy alone. On the showcase, external assistant buttons transmit a pre-filled public question to the chosen provider after clicking the link. The copy button writes this question to the clipboard without sending it to an assistant. External providers apply their own policies.

8. Recipients and transfers

Authorized persons of Roote SAS and providers necessary for service operation may access data within the limits of their mission: hosting, email, payment and, when the feature requires, AI processing. The roote.si showcase is hosted by Vercel. The list and information specific to providers of other services must be made accessible in the concerned services. Authorities may receive information when a legal obligation requires it. Processing outside the European Economic Area requires applicable safeguards, notably an adequacy decision or appropriate contractual guarantees. Data are not sold or rented for a purpose unrelated to the service on the sole basis of this policy.

9. Retention

Data are retained for a duration proportionate to their purpose. Account and access data are processed during the relationship necessary for the service, subject to elements that must be legally retained or to establish a right. Accounting documents are retained for applicable legal durations. Contact messages are retained during processing and follow-up of the request, then only if an obligation or dispute justifies it. Durations specific to API requests, AI conversations, location data and technical logs must be specified in the information of the concerned service, according to its actual configuration. Geolocation must not be retained beyond the justified need without appropriate information and legal basis.

10. Security

Appropriate measures are taken to limit data access to authorized persons and protect exchanges and Site resources. However, no system can guarantee absolute security. If you notice an incident likely to concern your data, you may report it to contact@roote.ai.

11. Your rights

Under conditions provided by the GDPR, you may request access to your data, their rectification or deletion, restriction of processing, object to processing based on legitimate interest and request portability when applicable. When processing relies on your consent, you may withdraw it for the future. You may also define directives provided by French law regarding your data after your death. Address your request to contact@roote.ai specifying information allowing understanding it. Proof of identity may only be requested in case of reasonable doubt about your identity. You may file a complaint with the CNIL, notably at www.cnil.fr.

12. Update and language

This policy may evolve with services and actually implemented processing. An update does not alone constitute consent to new processing. The policy is available in French and English translation. In case of discrepancy, only the original French version shall prevail, subject to applicable mandatory provisions. Date of signature of the reference document: 01-08-2018.