Contents
This page explains how RootPacket B.V. approaches data protection under the General Data Protection Regulation (EU) 2016/679 ("GDPR" / AVG) and the Dutch GDPR Implementation Act. For how we handle personal data of website visitors and account holders, see our Privacy & Cookie Statement.
1. Controller vs processor
Our role under the GDPR depends on the data:
Our own business data
Account, billing, enquiry, and website data — we decide the purposes and means. Covered by the Privacy Statement.
Customer-hosted data
Personal data inside the servers and services you run on our infrastructure — you are the controller, we process it on your instructions.
As an infrastructure provider we generally do not access the content you store or transmit, except as needed to operate, secure, or support the Services, or where legally required.
2. Data Processing Agreement (DPA)
Where we act as processor, a Data Processing Agreement under Article 28 GDPR governs the processing. It sets out the subject matter, duration, nature and purpose, the types of data and categories of data subjects, and our obligations. A DPA is available to customers on request at contact@rootpacket.nl and, once signed, prevails over this page for that customer.
3. What we process as processor
| Element | Typical scope |
|---|---|
| Nature & purpose | Hosting, transmitting, and supporting the infrastructure on which the customer runs its own systems. |
| Types of data | Determined by the customer; may include any personal data the customer chooses to store or transmit. |
| Data subjects | Determined by the customer (e.g. the customer's own users or end customers). |
| Duration | For the term of the Services, plus deletion afterwards (see retention). |
4. Sub-processors
We use a limited set of sub-processors to deliver the Services, such as our datacenter operators (Equinix, Interxion/Digital Realty) and Tier 1 carriers. We impose data-protection obligations on sub-processors consistent with our own, and we will inform customers of intended changes to sub-processors so they can object, as required by Article 28(2) GDPR. A current sub-processor list is available on request.
5. International transfers
Our datacenters for launch are in the European Economic Area (Amsterdam and Frankfurt). Where a Service or sub-processor involves a transfer of personal data outside the EEA, we rely on an adequate transfer mechanism — an adequacy decision or the European Commission's Standard Contractual Clauses (SCCs) — together with supplementary measures where required.
6. Security measures (Article 32)
- Access controls and least-privilege access to systems.
- Encryption in transit; encryption at rest where offered for a Service.
- Network segmentation, firewalling, and monitoring.
- Physical security provided by Tier III+ certified datacenter operators (ISO 27001, SOC 2).
- Logging, and regular review of access and configuration.
The specific measures applicable to a Service are described in the DPA and any applicable SLA.
7. Personal data breach notification
If we become aware of a personal data breach affecting data we process on a customer's behalf, we will notify the affected customer without undue delay so they can meet their own obligation to notify the Autoriteit Persoonsgegevens within 72 hours where required. Our notification will include the information reasonably available to us to help the customer respond.
8. Data subject rights
For data where we are controller (account, billing, enquiries), you can exercise your rights of access, rectification, erasure, restriction, portability, and objection by emailing contact@rootpacket.nl; we respond within one month.
For data where we are processor (data inside customer systems), data subjects should contact the relevant customer (the controller). If a request reaches us directly, we will, where we can identify the controller, refer it to them and assist the customer in responding as required by Article 28.
9. Government & law-enforcement requests
We disclose data only in response to valid, legally binding requests from competent authorities, limited to what is legally required. Where permitted by law, we will inform the affected customer of a request relating to their data. See also the Acceptable Use Policy.
10. Retention & deletion
As processor, we retain customer-hosted personal data only for the term of the Services. On termination, we delete or return it in line with the DPA and after a reasonable wind-down period, except where retention is legally required. Our own controller-side retention is described in the Privacy Statement.
11. Supervisory authority
Our lead supervisory authority is the Dutch Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl). You have the right to lodge a complaint with them, though we ask that you contact us first so we can help.