Legal

Privacy Policy

Last updated: 4 August 2026 · Version 3.3

On this page

  1. Who we are
  2. What we collect
  3. How & why we use it
  4. Lawful basis
  5. Sharing & processors
  6. International transfers
  7. Retention
  8. Your rights
  9. Cookies
  10. Security
  11. Contact
  12. Complaints

01Who we are

Root Delta Ltd ("Root Delta", "we", "us") is a software studio based in Cambridge, United Kingdom.

Root Delta is the controller for personal data it uses for its own purposes, including website and email enquiries, business contacts, project administration, invoicing and legal compliance.

Where Root Delta processes personal data solely on a client’s documented instructions to deliver contracted services, the client is normally the controller and Root Delta is its processor. The client is responsible for providing privacy information about that processing. This notice still applies to information Root Delta uses for its own administrative, security or legal purposes.

Root Delta Ltd · Company No. 17304199 · Registered in England & Wales.
Registered office: St John’s Innovation Centre, Cowley Road, Cambridge, CB4 0WS.
ICO registration: ZC183600.
Contact: hello@rootdelta.net · 01223 625603

02What we collect

We collect only what we need to respond to you and to run our business:

If we obtained your details from another source and contact you, we will identify that source and provide or link to this notice no later than our first communication, unless a legal exception applies.

All visible website-form fields are required so we can understand your enquiry, respond and arrange the requested call. The phone number is not used for unrelated marketing. If a contract or law later requires other information, we will explain this when we ask for it.

We do not knowingly collect special category data, and we do not buy or sell personal data.

03How & why we use it

PurposeData used
Responding to your enquiry, arranging the requested call and preparing any reply, scope or proposalName, email, phone number, description of the work you need help with and any service label you provide
Filtering out automated spam so real enquiries reach usForm submission content and technical details of the submission
Delivering and managing projectsContact details, project data
Invoicing & legal/accounting obligationsContact & billing details
Keeping the website secure & workingServer logs

04Lawful basis

Under UK GDPR we rely on:

05Sharing & processors

We disclose personal data only where needed for the purposes described in this notice. The main recipients are:

We may also disclose personal data where genuinely needed to our accountant, insurer, broker, insurer-appointed legal, forensic or claims specialists, or another professional adviser, and to a regulator, court or law-enforcement body where we are legally required to. We do not share your data for advertising, and we do not sell it.

06International transfers

Some providers may process personal data outside the United Kingdom. Where this is a restricted transfer, we use an applicable UK adequacy regulation or approved contractual safeguards and assess the protection provided as UK law requires.

Cloudflare’s and Netlify’s current data-processing terms contain UK transfer mechanisms. Akismet is used through Netlify’s processing chain. Google and Intuit operate internationally. For a project-delivery provider, the applicable recipient and transfer safeguard are recorded in the signed project terms before personal data is processed.

You may ask us for information about the safeguard applying to a particular provider and how to obtain a copy.

07Retention

We keep enquiry emails and form submissions for as long as needed to deal with your request and for a reasonable follow-up period, with a target review no later than 12 months after our last contact with you. At that review we delete or anonymise records that are no longer needed, subject to any legal or contractual retention duty. The review covers the Netlify dashboard, email and any exported copies.

Cloudflare and Netlify retain technical and security information for periods set by their service terms, security schedules and the relevant service configuration. Those periods vary by log type and service. Root Delta does not create a separate archive of the providers’ raw logs.

Financial and statutory records are generally retained for six years where required for accounting, tax or legal purposes. Project contact and administration records are retained only for the relevant contractual, legal and dispute period. Where Root Delta processes personal data for a client, return and deletion follow the instructions in the applicable project contract.

08Your rights

Depending on the circumstances and the lawful basis for the processing, you may have rights to access, correct, delete or restrict the use of your personal data, to object to processing, and to receive or transfer certain data in a portable format. Where we rely on consent, you have the right to withdraw that consent at any time, without affecting processing already carried out. You also have the right to complain to the Information Commissioner’s Office (see Complaints).

To exercise any of these, email hello@rootdelta.net and we will respond within one month. We may need to verify your identity first, and for complex or numerous requests we may extend this by up to two further months, telling you if we do.

Root Delta does not use solely automated decision-making that produces legal or similarly significant effects.

09Cookies

Our own pages set no cookies and use no browser storage, and we run no analytics script, advertising or cross-site tracking. Cloudflare may set limited challenge or security cookies when it checks a request. We do not seek consent only where a cookie’s purpose and use meet an applicable exception in Schedule A1 to PECR; the site is not configured to use anything that requires consent, so there is no cookie banner. See our Cookie Policy for the detail.

10Security

We use HTTPS, multi-factor authentication on company accounts, BitLocker on company devices, least-privilege access and security updates. No online service is completely secure.

11Contact

Questions or concerns? Email hello@rootdelta.net or call 01223 625603. You can also write to us at Root Delta Ltd, St John’s Innovation Centre, Cowley Road, Cambridge, CB4 0WS. If you are unhappy with how we have handled your data, see Complaints below.

12Complaints

If you think Root Delta has not handled your personal data lawfully, you have a legal right to complain to us, under section 164A of the Data Protection Act 2018. Email hello@rootdelta.net, call 01223 625603 or write to our registered office. Tell us what happened and what you would like us to do; you do not need to use a special form, and you can complain in whichever of those ways suits you. We will acknowledge your complaint within 30 days of receiving it, then, without undue delay, make appropriate enquiries, keep you informed of progress and tell you the outcome.

You can also complain to the Information Commissioner’s Office at ico.org.uk (opens in a new tab). You do not have to complain to us first, and complaining to us does not affect that right.