Legal
Privacy Policy
Last updated: 4 August 2026 · Version 3.3
On this page
01Who we are
Root Delta Ltd ("Root Delta", "we", "us") is a software studio based in Cambridge, United Kingdom.
Root Delta is the controller for personal data it uses for its own purposes, including website and email enquiries, business contacts, project administration, invoicing and legal compliance.
Where Root Delta processes personal data solely on a client’s documented instructions to deliver contracted services, the client is normally the controller and Root Delta is its processor. The client is responsible for providing privacy information about that processing. This notice still applies to information Root Delta uses for its own administrative, security or legal purposes.
Root Delta Ltd · Company No. 17304199 · Registered in England & Wales.
Registered office: St John’s Innovation Centre, Cowley Road, Cambridge, CB4 0WS.
ICO registration: ZC183600.
Contact: hello@rootdelta.net · 01223 625603
02What we collect
We collect only what we need to respond to you and to run our business:
- Contact enquiries: your name, email address, phone number and description of the work you need help with, which are required when you use our website form. A service link may add a hidden service label. The form also contains technical fields used for routing and spam detection. If you contact us another way, we collect the information you choose to provide and what we need to respond.
- Business contact data: your name, role, organisation, professional contact details and relevant business context. We may receive this from you, your organisation, a referrer or a publicly available professional source, such as an organisation’s website or professional profile.
- Project & client data: information you share with us in the course of a project, which may include business documents, workflow descriptions and related materials. Please do not submit passwords or access credentials through the contact form or ordinary email. Access to systems should be granted through client-owned account invitations or another agreed secure method.
- Technical data: the standard operational and security logs our network and hosting providers create at their end when they serve you a page, which is normal for any website. Those logs include your IP address and the page you asked for. From them our network provider produces an aggregated traffic summary we can see: request and visitor counts, which pages were asked for, roughly which country requests came from, and what its security layer blocked. We run no analytics script on this site, so nothing is placed on your device to measure or profile your visit, and we do not attempt to identify individual visitors from that summary.
If we obtained your details from another source and contact you, we will identify that source and provide or link to this notice no later than our first communication, unless a legal exception applies.
All visible website-form fields are required so we can understand your enquiry, respond and arrange the requested call. The phone number is not used for unrelated marketing. If a contract or law later requires other information, we will explain this when we ask for it.
We do not knowingly collect special category data, and we do not buy or sell personal data.
03How & why we use it
| Purpose | Data used |
|---|---|
| Responding to your enquiry, arranging the requested call and preparing any reply, scope or proposal | Name, email, phone number, description of the work you need help with and any service label you provide |
| Filtering out automated spam so real enquiries reach us | Form submission content and technical details of the submission |
| Delivering and managing projects | Contact details, project data |
| Invoicing & legal/accounting obligations | Contact & billing details |
| Keeping the website secure & working | Server logs |
04Lawful basis
Under UK GDPR we rely on:
- Legitimate interests: to respond to and manage enquiries, maintain professional relationships, keep appropriate business records, protect the website and our systems from spam and abuse, prepare quotes and proposals efficiently, and send proportionate business communications relevant to your role or organisation. The interests we are pursuing are running and growing a small software business, answering the people who contact us properly and promptly, and keeping our records and systems reliable, useful and secure. Before relying on this basis we weigh those interests against your rights and use only what the purpose needs; we do not rely on it where the effect on you would outweigh it, and the chosen channel must also be permitted under PECR. You can object to any processing we base on legitimate interests, and you can object to direct marketing at any time. If you object to marketing we stop and retain only the minimum suppression record needed to respect your choice.
- Contract: where you are personally party to a contract with us, or ask us to take necessary steps before entering one, to deliver that work. Where you act for a company or other organisation that is the contracting party, we normally rely on legitimate interests for proportionate project administration and communication with you.
- Legal obligation: to meet tax, accounting and other statutory duties.
- Consent: where PECR requires consent for electronic marketing, or where we ask for consent to another specific optional use. You may withdraw consent at any time without affecting earlier lawful processing.
05Sharing & processors
We disclose personal data only where needed for the purposes described in this notice. The main recipients are:
- Cloudflare (Cloudflare, Inc., United States): domain-name service, content delivery and security for rootdelta.net. It processes request information, customer logs and contact-form content passing through its network under its data-processing terms. For limited information Cloudflare processes for its own security or legal purposes, its own privacy notice applies. It may set limited challenge or security cookies, as explained in our Cookie Policy.
- Netlify (Netlify, Inc., United States): website hosting and contact-form handling. It stores submissions and makes them available to us as our processor. We do not use Netlify Analytics.
- Akismet (Automattic Inc., United States): Netlify uses Akismet as part of its form service to check submissions for spam. Akismet receives the submission content and related technical details through Netlify’s processing chain.
- Google Workspace (provided by Google): our email, calendar and document storage. Your enquiry and any correspondence with us sit in this mailbox.
- OpenAI: we may use OpenAI’s commercial services to help us handle website enquiries. This may involve sending information included in your enquiry to OpenAI. We do not use this processing to make solely automated decisions about you with legal or similarly significant effects.
- Intuit (QuickBooks Online, UK edition): if you become a client or supplier, we may use QuickBooks for business contact details, invoice details, payment status, billing address, tax details and related correspondence. Website enquiries are not sent to QuickBooks. If we enter your information there, Intuit says it also acts as an independent controller for limited uses of that Business Connection Data, including product development and improvement, analytics, fraud prevention and security. Intuit’s Global Privacy Statement (opens in a new tab) explains that processing, and its QuickBooks UK terms (opens in a new tab) explain the role split.
- Project-delivery providers and specialists: on a live project, providers or specialists described in the signed project terms may process the minimum information needed to deliver the work. Where Root Delta acts as a processor, they are used only with the client’s authorisation and under written confidentiality and data-protection terms. Root Delta remains responsible for its own obligations.
We may also disclose personal data where genuinely needed to our accountant, insurer, broker, insurer-appointed legal, forensic or claims specialists, or another professional adviser, and to a regulator, court or law-enforcement body where we are legally required to. We do not share your data for advertising, and we do not sell it.
06International transfers
Some providers may process personal data outside the United Kingdom. Where this is a restricted transfer, we use an applicable UK adequacy regulation or approved contractual safeguards and assess the protection provided as UK law requires.
Cloudflare’s and Netlify’s current data-processing terms contain UK transfer mechanisms. Akismet is used through Netlify’s processing chain. Google and Intuit operate internationally. For a project-delivery provider, the applicable recipient and transfer safeguard are recorded in the signed project terms before personal data is processed.
You may ask us for information about the safeguard applying to a particular provider and how to obtain a copy.
07Retention
We keep enquiry emails and form submissions for as long as needed to deal with your request and for a reasonable follow-up period, with a target review no later than 12 months after our last contact with you. At that review we delete or anonymise records that are no longer needed, subject to any legal or contractual retention duty. The review covers the Netlify dashboard, email and any exported copies.
Cloudflare and Netlify retain technical and security information for periods set by their service terms, security schedules and the relevant service configuration. Those periods vary by log type and service. Root Delta does not create a separate archive of the providers’ raw logs.
Financial and statutory records are generally retained for six years where required for accounting, tax or legal purposes. Project contact and administration records are retained only for the relevant contractual, legal and dispute period. Where Root Delta processes personal data for a client, return and deletion follow the instructions in the applicable project contract.
08Your rights
Depending on the circumstances and the lawful basis for the processing, you may have rights to access, correct, delete or restrict the use of your personal data, to object to processing, and to receive or transfer certain data in a portable format. Where we rely on consent, you have the right to withdraw that consent at any time, without affecting processing already carried out. You also have the right to complain to the Information Commissioner’s Office (see Complaints).
To exercise any of these, email hello@rootdelta.net and we will respond within one month. We may need to verify your identity first, and for complex or numerous requests we may extend this by up to two further months, telling you if we do.
Root Delta does not use solely automated decision-making that produces legal or similarly significant effects.
09Cookies
Our own pages set no cookies and use no browser storage, and we run no analytics script, advertising or cross-site tracking. Cloudflare may set limited challenge or security cookies when it checks a request. We do not seek consent only where a cookie’s purpose and use meet an applicable exception in Schedule A1 to PECR; the site is not configured to use anything that requires consent, so there is no cookie banner. See our Cookie Policy for the detail.
10Security
We use HTTPS, multi-factor authentication on company accounts, BitLocker on company devices, least-privilege access and security updates. No online service is completely secure.
11Contact
Questions or concerns? Email hello@rootdelta.net or call 01223 625603. You can also write to us at Root Delta Ltd, St John’s Innovation Centre, Cowley Road, Cambridge, CB4 0WS. If you are unhappy with how we have handled your data, see Complaints below.
12Complaints
If you think Root Delta has not handled your personal data lawfully, you have a legal right to complain to us, under section 164A of the Data Protection Act 2018. Email hello@rootdelta.net, call 01223 625603 or write to our registered office. Tell us what happened and what you would like us to do; you do not need to use a special form, and you can complain in whichever of those ways suits you. We will acknowledge your complaint within 30 days of receiving it, then, without undue delay, make appropriate enquiries, keep you informed of progress and tell you the outcome.
You can also complain to the Information Commissioner’s Office at ico.org.uk (opens in a new tab). You do not have to complain to us first, and complaining to us does not affect that right.