πŸ”’ Privacy Policy

Last updated: January 2025

πŸ“‹ Quick Summary

We collect only what we need to provide our service. We never sell your data. You own your data and can export or delete it anytime. We're GDPR compliant and take security seriously.

1. Introduction & Who We Are

RootCascade Ltd. ("RootCascade", "we", "us", or "our") is committed to protecting your privacy and handling your personal data responsibly. This Privacy Policy explains how we collect, use, store, and protect your information when you use our incident management platform and related services.

🏒 Data Controller Information

Company: RootCascade Ltd.
Registration: England and Wales, Company No. 14523891
Address: 282A Lee High Rd, London SE13 5PJ, United Kingdom
Email: privacy@rootcascade.com
ICO Registration: ZB123456

This policy applies to all users of RootCascade, including visitors to our website, free trial users, and paying customers. By using our Service, you acknowledge that you have read and understood this Privacy Policy.

2. What Data We Collect

2.1 Information You Provide Directly

When you create an account, use our service, or contact us, you may provide:

Data TypeExamplesPurpose
Account InformationName, email, company name, job title, passwordCreate and manage your account
Billing InformationPayment card details, billing address, VAT numberProcess payments (via Stripe)
Incident DataIncident descriptions, timelines, postmortems, comments, severity levelsProvide core service functionality
Team InformationTeam member names, emails, roles, on-call schedulesEnable team collaboration
Integration CredentialsAPI tokens, OAuth tokens for connected servicesConnect third-party tools (stored encrypted)
Support CommunicationsSupport tickets, emails, chat messages, feedbackProvide customer support
User PreferencesTimezone, notification settings, UI preferencesPersonalise your experience

2.2 Information Collected Automatically

When you use our Service, we automatically collect:

Data TypeDetailsRetention
Usage AnalyticsPages visited, features used, actions taken, time spent90 days (aggregated indefinitely)
Device InformationBrowser type, OS, device type, screen resolution90 days
Log DataIP addresses (anonymised), access times, referring URLs, error logs90 days
Performance DataPage load times, API response times, error rates30 days

2.3 Information from Third-Party Integrations

When you connect third-party services to RootCascade, we may receive:

We only access data necessary for our service to function. You can disconnect integrations at any time, which stops further data collection from that service.

2.4 Information We Don't Collect

We do not collect:

3. How We Use Your Data

PurposeData UsedLegal Basis (GDPR)
Provide and maintain the ServiceAccount info, incident data, integrationsContract performance (Art. 6(1)(b))
Process payments and billingBilling informationContract performance (Art. 6(1)(b))
Send service communicationsEmail addressContract performance (Art. 6(1)(b))
Provide customer supportAccount info, support communicationsContract / Legitimate interests
Improve and develop the ServiceUsage analytics, feedbackLegitimate interests (Art. 6(1)(f))
Ensure security and prevent fraudLog data, device infoLegitimate interests (Art. 6(1)(f))
Send marketing communicationsEmail address, preferencesConsent (Art. 6(1)(a))
Comply with legal obligationsAs requiredLegal obligation (Art. 6(1)(c))
Generate AI-powered insightsIncident data (within your account)Contract performance (Art. 6(1)(b))

πŸ€– AI and Machine Learning

Our cascade tracing and postmortem generation features use machine learning. Your incident data is processed to provide these features within your account only. We do not use your data to train models that benefit other customers. You can disable AI features in your account settings.

4. Who We Share Data With

We never sell your personal data. We may share data with:

4.1 Service Providers (Sub-processors)

ProviderPurposeLocationData Shared
Amazon Web ServicesInfrastructure hostingEU (London)All service data
StripePayment processingUSA (EU SCCs)Billing information
IntercomCustomer supportUSA (EU SCCs)Support communications, account info
PostHogProduct analyticsEU (self-hosted)Usage analytics (anonymised)
SentryError trackingUSA (EU SCCs)Error logs, device info
ResendTransactional emailUSA (EU SCCs)Email addresses, email content

4.2 Third-Party Integrations

When you connect integrations, data flows between RootCascade and those services according to your configuration. Each integration has specific data flows documented in our Integrations documentation.

4.3 Legal and Safety Disclosures

We may disclose data if required by law, court order, or governmental request, or if we believe disclosure is necessary to protect the rights, property, or safety of RootCascade, our users, or the public.

4.4 Business Transfers

In the event of a merger, acquisition, or sale of assets, your data may be transferred. We will provide 30 days' notice before any such transfer and give you the opportunity to delete your data.

5. How Long We Keep Data

Data TypeRetention PeriodNotes
Account dataWhile account is active + 30 daysDeleted within 30 days of account closure
Incident dataPer your plan (7-365 days, or custom)You can configure retention in settings
PostmortemsPer your plan settingsExportable before deletion
Billing records7 yearsRequired for tax/legal compliance
Support communications3 years after resolutionTo improve support quality
Usage analytics90 days (raw), indefinite (aggregated)Aggregated data is anonymised
Log data90 daysFor security and debugging
Backups30 daysEncrypted, automatically purged

6. Your Rights (GDPR)

If you are in the European Economic Area (EEA), United Kingdom, or a jurisdiction with similar laws, you have the following rights:

πŸ“„ Right of Access Request a copy of all personal data we hold about you
✏️ Right to Rectification Request correction of inaccurate or incomplete data
πŸ—‘οΈ Right to Erasure Request deletion of your data ("right to be forgotten")
⏸️ Right to Restriction Request that we limit how we process your data
πŸ“¦ Right to Portability Receive your data in a machine-readable format (JSON/CSV)
🚫 Right to Object Object to processing based on legitimate interests
↩️ Right to Withdraw Consent Withdraw consent at any time (for consent-based processing)
πŸ€– Rights Related to Automated Decisions Request human review of automated decisions

To exercise your rights: Email privacy@rootcascade.com with your request. We will respond within 30 days. You may also use the self-service options in Settings β†’ Privacy.

Complaints: You have the right to lodge a complaint with a supervisory authority. In the UK, this is the Information Commissioner's Office (ICO).

7. How We Protect Your Data

We implement comprehensive security measures to protect your data:

See our Security page for more details.

8. International Data Transfers

Your data is primarily stored in AWS EU-West-2 (London). When we transfer data outside the EEA/UK, we ensure adequate protection through:

You can request a copy of our Data Processing Agreement (DPA) and SCCs by emailing legal@rootcascade.com.

9. Cookies & Tracking

We use cookies and similar technologies as described in our Cookie Policy. In summary:

10. Children's Privacy

Our Service is designed for business use and is not intended for individuals under 18 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately at privacy@rootcascade.com and we will delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes:

12. Contact Us

For privacy-related questions, to exercise your rights, or to raise concerns:

πŸ“¬ Privacy Contact

Email: privacy@rootcascade.com
Post: Data Protection Officer, RootCascade Ltd., 282A Lee High Rd, London SE13 5PJ, United Kingdom
Response time: We aim to respond within 5 business days, and will resolve requests within 30 days.