At Root, we’re committed to protecting the privacy of your personal data.
This privacy policy (Privacy Policy) is meant to help you understand what data we collect, why we collect it and how you can update, manage, export and delete your data.
Personal data is information that relates to you and may identify you as an individual. This includes your name, contact information, age and gender and certain special categories of data like race, ethnic origin, health information or criminal record.
If you are in South Africa, personal data also applies to information that may be used to identify a juristic person, like a registered company.
We process personal data in line with all applicable laws, including:
To help you navigate this Privacy Policy:
We update this Privacy Policy occasionally. When we make major updates, we will place a prominent notice visible to site visitors and notify you where possible, however you should always check back here periodically to see if the Privacy Policy has been updated. We will always show the date of the last update at the top of the page for you to know when it was last changed.
We regularly review our compliance with this Privacy Policy. If you have any questions, please contact us by email at privacy@rootplatform.com.
This Privacy Policy applies to Root Platform Inc., a Delaware, USA corporation and its subsidiaries and affiliates (collectively, Root or we, us, our). We operate in various countries around the world, including the United Kingdom and South Africa.
We believe that the future of insurance is digital, personalised and embedded. Our mission is to grow insurance businesses into this future by providing the infrastructure that makes this possible.
We do this by providing our clients with access to an end-to-end digital insurance platform that enables them to launch, sell and administer insurance products and digital engagement channels fast (the Root Insurance Platform).
We also provide a range of other services, including:
For more information about our services, see here.
Sections of this Privacy Policy may apply differently to you based on the way you interact with Root.
You are either a Site Visitor or a Client, User or End User:
Site Visitor: You are a Site Visitor when you visit and interact with our web sites, web pages, interactive features, blogs and their respective contents at rootplatform.com (or any derivation like root.co.za) (Our Sites).
Client: You are a Client when you enter into an agreement relating to you, your Users or your End Users using our services.
User: You are a User when you set up a Root Account and gain access to the Root Insurance Platform at app.rootplatform.com (or any other derivation), because your employer or organisation is a Client. Support and operational staff or other agents of our Clients who gain access to the Root Insurance Platform are Users.
End User: You are an End User if you use any applications or add-ons built by or on behalf of a Client on the Root Insurance Platform. If you are a policyholder of a Client, you will be an End User.
For each user type we’ve explained what personal data we collect, why and how we process it:
If you have provided your consent to the collection, processing and/or transfer of your personal data, you have the right to fully or partially withdraw your consent. This includes where you want to opt out of some or all marketing communications. Once you have notified us that you have withdrawn your consent, we will no longer process your information for the purpose(s) to which you originally consented unless there is another valid legal ground for processing.
To stop receiving emails from us, click on the “unsubscribe” or “manage email preferences” link in the email you received from us to unsubscribe from some or all of the emails you receive. Alternatively, reach out to us at privacy@rootplatform.com.
Some of our services and features require that we share data with third parties, with our subsidiaries or affiliates, at our Clients’ request or for legal reasons.
These include the third parties or categories of third parties listed below. Where a third party is identified, please see their linked privacy policy / notices for information regarding their collection and use of personal data:
We will only share your personal data with these third party service providers to the extent necessary for them to perform their services for us. We only use service providers we trust, and who have agreed to keep your data secure and confidential and to only use it for the purpose for which we shared it with them. Some of our service providers may be located in other countries. We provide for appropriate safeguards through contracts between our foreign and local service providers and us, including through standard contractual clauses or other approved transfer mechanisms. Third party service providers are not owned or controlled by Root and third parties that have been granted access to information may have their own policies and practices for its collection, use and sharing.
We share data with our subsidiaries and affiliates to help us provide our services or conduct data processing on our behalf.
This includes sharing data with:
We may share your personal data if we believe we are legally required to do so (e.g. to comply with law enforcement investigations or other legal proceedings), to enforce our contracts and policies or to respond to an emergency that we believe in good faith requires that we disclose personal data.
If there is a change in our company structure or ownership, we may share your data as part of the assets transferred or the due diligence for the transaction. We’ll use reasonable endeavours to anonymise your data where possible, and will comply with any applicable confidentiality obligations.
We only retain your data for as long as necessary for the purposes described above. This varies depending on the type of data, the category of user you are, the purposes that we collected the data for and whether the data must be retained after an account deletion request for purposes described below.
You have the right to access all of your data stored on our platform. As a Client, you can export a copy of all of your data from the Root Insurance Platform if you want to back it up or use it with a service outside of Root. For more information on how to export your data, see our Documentation here.
If your agreement with us is terminated or you request that we delete your Root Account and/or data by contacting us, we will delete all of your data, data of your policyholders, Users and End users from the Root Insurance Platform and our servers within 60 days of termination or your request. We retain your other data for business reasons and to comply with legal and audit obligations. We will not keep it for longer than is necessary.
We understand how sensitive policyholder and user information is for your business. That’s why we emphasise privacy and security throughout all system design processes and implement security measures based on the sensitivity of the data we hold. These measures are in place to protect the data from being disclosed, from loss, misuse and unauthorised access and from being altered or destroyed. They include:
You can find more information about these and our other measures on our Security page.
We proactively monitor our systems for bugs, possible vulnerabilities and attacks and our team is on call 24/7 to address and report incidents. Still, no system is perfect and we could never guarantee that we will never experience a breach of any of our physical, technical or administrative safeguards.
You also have a role to play in keeping personal data safe. For example, you should never share your login credentials for your Root Account with anyone, and should make sure your employees or agents follow the same rule.
If you suspect that we (or you) have had a security breach, please let us know immediately by sending an email to privacy@rootplatform.com and contacting your Root account manager.
We will let you know of any incidents that affect your personal data and we will inform you about how you can help minimise the impact.
Cookies are small data files stored on your device by websites that you visit. They allow websites to track and remember information about your device and how you use the website.
When you visit Our Sites, we collect information from you automatically through cookies.
Our Sites use the following types of cookies:
You can block any of these cookies by activating a setting on your browser allowing you to refuse cookies, or by selecting your cookie preferences in the pop-up on our website. You can also delete cookies through your browser settings. If you turn off cookies, you can continue to use Our Sites, but certain services may not work effectively or at all.
We would like to make sure you are fully aware of all of your data protection rights. You have:
You can exercise your rights by contacting us at the addresses below.
We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.
We try to respond to requests within 30 days. Occasionally it may take us longer than 30 days if your request is particularly complex or you have made a number of requests.
We may also charge a reasonable fee if your request is manifestly unfounded, excessive or repetitive or as we’re otherwise legally allowed to do, alternatively, we may refuse to comply with your request in these circumstances to the extent we’re legally allowed to. We will let you know if this is the case.
If you are a User or End User, we may be required to redirect your request to the relevant Client who is your data controller or responsible party for them to respond directly.
We regularly review our compliance with this Privacy Policy. If you have any questions, please contact us by email at privacy@rootplatform.com, alternatively contact our individual responsible for data protection, Jared Lesar (Head of Legal) at jared@root.co.za.
If you do need to send physical mail, this should be sent to the following addresses:
You have the right to lodge a complaint with the following authorities: