Privacy Policy
Last updated:
This notice explains how we process personal data when you visit eroots.tech, contact us, request information or access to our products, or apply for a role. It covers this corporate website; product accounts and customer projects may have additional privacy information and contractual terms.
1. Data controller and contact
EROOTS ANALYTICS S.L. ("eRoots", "we", "our" or "us"), tax identification number B09796038, is the controller of the personal data described in this notice.
Registered address: Av. de Josep Tarradellas, 34-36, 1r esquerra, Eixample, 08029 Barcelona, Spain.
Privacy enquiries and rights requests: info@eroots.tech. You can also write to our registered address, marked "Data protection".
We process personal data under the General Data Protection Regulation (EU) 2016/679 (GDPR) and applicable Spanish data protection law.
2. Personal data we collect
- Contact and professional details: first and last name, email address, telephone number if supplied, company or institution, country or region where requested, product interest, and the content of your message and subsequent correspondence.
- Recruitment details: the role applied for, contact details, CV and other files you choose to provide, LinkedIn profile URL, salary expectations, visa sponsorship requirements, and your application message. Please avoid including sensitive personal data or information about other people that is unnecessary for your application.
- Technical and usage data: IP address, browser and device information, requested pages, access times, referrer, and website interactions. Our hosting and website service providers receive technical information when your browser connects to their services.
- Optional analytics and marketing data: cookie or similar identifiers, browsing and interaction information, campaign parameters (UTM source, medium, campaign, content and term), referring website, landing page and lead-source classification, when you permit the relevant optional category.
- Preference and communication data: your cookie choices, the date of that choice, and information you provide in a support conversation when you enable the optional chat service.
We receive data directly from you through forms, email, uploaded files and conversations, and automatically from your browser as described above. Fields marked with an asterisk are needed to handle the relevant request. Other fields are optional. If you do not provide required information, we may be unable to respond to your request or assess your application. Submitting a form does not subscribe you to unrelated marketing.
3. Purposes and legal bases
- Product enquiries, demonstrations and access requests: to respond and take steps you request before entering a contract, under Article 6(1)(b) GDPR. Where you act for a company rather than for yourself, we rely on our legitimate interest in handling business enquiries and maintaining professional relationships, under Article 6(1)(f).
- General enquiries and correspondence: to answer questions and manage communications, based on our legitimate interest in responding to people who contact us, under Article 6(1)(f).
- Recruitment: to review your application and contact you about the role, as steps at your request before a possible employment contract, under Article 6(1)(b). Keeping an application for unrelated future roles requires a separate basis and, where based on consent, a separate optional choice.
- Website operation and security: to deliver pages, maintain the site, diagnose faults and prevent misuse, based on our legitimate interest in operating a reliable and secure website, under Article 6(1)(f). Necessary browser storage remembers your privacy choice and a dismissed website banner.
- Optional analytics: to measure site and form performance, based on your consent under Article 6(1)(a).
- Optional marketing: to measure campaigns, associate a permitted visit with a submitted enquiry, and support advertising and visitor insights, based on your consent under Article 6(1)(a).
- Optional chat: to enable the third-party chat and its visitor features, based on your consent under Article 6(1)(a); handling the enquiry itself follows the enquiry bases above. You can contact us by email or form without enabling chat.
- Legal obligations and claims: to meet applicable legal duties, under Article 6(1)(c), and to establish, exercise or defend legal claims, based on our legitimate interest in protecting our rights, under Article 6(1)(f).
You can object to processing based on legitimate interests and withdraw consent as explained below. Optional analytics and marketing tools may group visitors by activity or campaign for reporting and advertising. We do not make decisions with legal or similarly significant effects on you solely by automated processing through this website.
4. Retention periods
The following retention limits apply to this website. We delete or anonymise data sooner when it is no longer needed; the legal retention exceptions below apply where necessary:
- Enquiries and product requests: while the enquiry is active and for up to 12 months after it is closed or the last substantive contact, whichever is later. If this leads to a customer relationship, relevant records are retained for that relationship and the applicable legal obligations and claims periods.
- Recruitment: during the selection process and for up to 6 months after it ends. Relevant records may then be restricted for applicable claims periods; an application is not retained for a future talent pool under this notice alone.
- Technical and security records: routine technical and security logs for up to 90 days. Records relating to a specific incident may be retained until the investigation and related legal claims are resolved.
- Browser preferences: the cookie choice expires after 180 days, or earlier if you change it or clear browser storage. A dismissed product banner is honoured for 24 hours; its local timestamp is replaced when you dismiss it again or removed when you clear storage.
- Marketing attribution in browser storage: up to 90 days from capture, subject to a valid marketing choice; it is removed when you withdraw that choice. Attribution sent with a form follows the retention criteria for that enquiry.
- Optional service records: identifiable analytics records for up to 14 months; marketing records for up to 12 months after the last interaction or until consent is withdrawn; chat conversations for up to 12 months after closure and chat visitor records for up to 90 days. These limits apply to records under our control. Providers acting as independent controllers set their own retention, described in their linked notices.
After a purpose ends, data must be deleted or anonymised unless retention is required by law or for a legal claim. In that case, access and use must be restricted to that purpose until the applicable period ends. Withdrawing consent stops future processing based on it; it does not affect the lawfulness of earlier processing or retention required on another lawful basis.
5. Recipients of personal data
Personal data may be accessed by authorised eRoots personnel and service providers supporting website hosting, email, customer relationship management, recruitment handling, analytics, marketing and chat. Our forms send the information you submit to Zoho CRM at its European service endpoint.
The website integrations include the following providers, subject to your optional choices:
- Zoho: CRM form handling; optional form analytics and SalesIQ chat/visitor features.
- Google: optional Google Analytics.
- LinkedIn: optional Insight Tag advertising and conversion measurement.
- Apollo: optional website visitor insights for marketing.
- HubSpot: optional marketing tracking.
Loading fonts, icons and other resources from external content providers also sends the technical information needed to deliver those resources. Providers processing data on our behalf must be subject to appropriate data processing terms. Some optional providers may also process information for their own purposes, as described in their privacy notices. Data may also be disclosed to advisers or public authorities when required by law or necessary for legal claims.
6. International data transfers
Some providers and their subprocessors operate outside the European Economic Area (EEA), including in the United States. Their use can involve storing or accessing personal data outside the EEA. A European service endpoint alone does not establish that all processing stays in the EEA.
Transfers outside the EEA must be covered by an applicable European Commission adequacy decision or appropriate safeguards under the GDPR, such as the Commission's standard contractual clauses and supplementary measures where necessary. The EU-US Data Privacy Framework can be relied on only for an eligible recipient with an active certification covering the transfer. Your cookie choice does not replace the required transfer safeguards.
Contact info@eroots.tech to request information about the destinations and safeguards applicable to your data and a copy of the relevant safeguards, subject to necessary redactions.
7. Cookies and similar technologies
We use necessary browser storage to remember your choices. Optional services are blocked until you enable their category: analytics (Google Analytics and Zoho form analytics), marketing (LinkedIn, Apollo, HubSpot and campaign attribution), and chat (Zoho SalesIQ, including visitor features).
You can accept all, reject all optional services, or select categories. You can change or withdraw your choice at any time using , also available on every page. Refusing optional services does not prevent browsing or submitting a form.
When you withdraw an enabled category, the page reloads to stop its running scripts and the site removes accessible first-party tracking cookies and marketing attribution storage. Third-party cookies and records already held by providers cannot all be removed by this site; you can clear remaining cookies through your browser and exercise your rights with us or the provider. Browser settings can also block or delete cookies and local storage.
8. Your data protection rights
Subject to the conditions in the GDPR, you can request:
- Access to your personal data and information about its processing.
- Rectification of inaccurate data and completion of incomplete data.
- Erasure when there is no lawful reason to continue retaining it.
- Restriction of processing in the circumstances provided by law.
- Objection to processing based on legitimate interests, on grounds relating to your situation. You can object to direct marketing, including related profiling, at any time.
- Data portability for data you provided where processing is automated and based on consent or a contract.
- Withdrawal of consent at any time, without affecting earlier lawful processing.
- Protection from solely automated decisions with legal or similarly significant effects, where applicable.
Send your request to info@eroots.tech or our registered address. Describe your request and provide enough information to locate your data. We may request proportionate additional information if needed to verify your identity; please do not send identity documents unless requested.
We normally respond within one month of receiving a request. For complex or numerous requests, this can be extended by up to two further months; we will explain the extension within the first month. Requests are normally free of charge, subject to the exceptions permitted by the GDPR.
You can complain to the Spanish Data Protection Agency (AEPD) or the supervisory authority in your place of habitual residence, work or the alleged infringement. You do not have to contact us first.
9. Security measures
We are responsible for selecting technical and organisational safeguards appropriate to the nature of the data and the risks of processing. This website redirects connections to HTTPS, and its forms submit data to Zoho over HTTPS to protect information in transit.
Our security requirements include limiting access to authorised people who need the data, confidentiality obligations, appropriate authentication, maintaining systems, reviewing supplier safeguards, protecting stored data and backups, and procedures to detect, assess and respond to incidents. Measures must be reviewed as risks and services change. If a personal data breach triggers a notification duty, we must inform the relevant authority and affected individuals as required by the GDPR.
No website or transmission method can guarantee absolute security. Avoid sending passwords or unnecessary sensitive information through enquiry forms. To report a suspected issue affecting personal data, contact info@eroots.tech.
10. Changes to this notice
We will update this notice when our processing or legal requirements change. The date above identifies the current version. Material changes affecting consent-based processing require a new choice before the changed optional processing begins.