Data Processing Addendum
Last updated July 9, 2026
This summary describes how Rooots processes personal data on your behalf and the protections we apply. For most households, Rooots is the data controller; this addendum is provided for transparency and for users who require processor terms under the GDPR.
Roles & scope
Rooots processes the personal data you put into your household to provide the service described in our Terms, and only for that purpose and on your instructions.
Security measures
- Row-level security isolating each household’s data to its own account.
- Encryption in transit (HTTPS); access limited to a small number of trained personnel and only as needed.
- Capability tokens (fridge/calendar links) that are unguessable and revocable.
Sub-processors
We use vetted sub-processors under contract to deliver the service and give at least 30 days’ notice before adding a new one. See the Sub-processors page for the current list.
Data-subject requests & deletion
We assist with access, correction, deletion, and portability requests as described in the Privacy Policy. On account deletion, data is removed on the retention schedule set out there.
International transfers
Data is processed in the United States; for EEA/UK/Swiss transfers we rely on Standard Contractual Clauses.
Contact
For a countersigned DPA or processor terms, email support@rooots.net.