Skip to main content

Rootsly Trust · v1.0.0

Privacy and data rights

The verified route for access, correction, restriction and anonymisation review, with separate responsible-organisation work and immutable action evidence.

Not yet effective for a genuine public pilot

This current staging record is visible for review. It does not turn unresolved legal, privacy, retention, provider or consumer wording into an approval.

01

Make a verified request

The privacy-request form verifies control of an email mailbox with a six-digit code. A homeowner account and clickable sign-in link are not required.

The requester can ask for access, correction, restriction or anonymisation review and later check the request using the verified route.

02

Responsible routing without overclaiming

Rootsly uses existing evidence to prepare separate protected work for Rootsly, the originating client or a receiver that actually received a consented transfer. Each organisation sees only its own work item.

Operational routing does not make a final legal controller determination. The responsible organisation reviews identity, scope, applicable rights, exemptions and its response obligations.

03

What the workflow can prepare

Access work can prepare a bounded private export. Correction appends the requested statement and can reference a later reassessment or corrected record without rewriting historical evidence.

Restriction can block new commercial lead or referral operations for the verified scope while privacy communication and report delivery remain available. Anonymisation creates a legal-hold and retention-checked plan; irreversible identity erasure remains disabled until the retention schedule is approved.

  • Temporary access exports expire automatically.
  • Actions, decisions and status changes retain audited evidence.
  • Historical assessment, result, report, consent and transfer facts are not silently edited.

04

Timing and communication

The operational workflow uses a one-calendar-month response target while allowing the responsible organisation to apply the law, verify identity and explain any extension, exemption or different outcome that applies.

Privacy requests are separate from product complaints, general support and security reports so their evidence and access boundaries remain clear.

05

Client offboarding

The proposed offboarding boundary provides a permitted export, disables staff access and the client journey, keeps a restricted 30-day recovery period, then applies the approved agreement and retention schedule.

Final deletion, anonymisation, justified minimal records and controller communication remain dependent on the professionally approved schedule and client terms.

Current and replaced versions are retained as separate records. A replacement never silently rewrites the version previously shown or accepted.

See all Trust versions