ROOTGUARDSECURITY LIMITED
Free tools Talk to us
Products ▼
All documentation packsSix editable packs, every one with a free sample Security Program PackNIST CSF 2.0, ISO 27001, CIS Controls Incident Response PackPlaybooks, evidence procedures, briefing templates Data Privacy PackNotices, inventories, subject request workflows SOC 2 Readiness PackMapped to the Trust Services Criteria CMMC Level 1 and Level 2FCI and CUI, for the US defense supply chain
Services ▼
All three servicesCompare scope, fee basis and what each ends with Security Program DeploymentAssess, document, implement, train, verify Incident Readiness DeploymentPlan, playbooks, tabletop exercise, verification Program SupportMonthly independent verification of closures
Why RootGuard ▼
IndependenceWe report to you, not to your IT provider Evidence, not assertionFull populations where the scale allows You own everythingEditable files, no platform, no lock-in Who does the workCISM, CISSP, CDPSE, CCSP, CHFI
Resources ▼
All fourteen free resourcesAssessments, policies, checklists and an exercise pack Free guidesPlain-language explainers on the questions buyers ask Framework referenceWhich standard applies to you, and why
Blog
About us

Privacy notice

Last updated [date]

RootGuard Security Limited, a company registered in Jamaica (company number [number]), is the data controller for personal data collected through rootguardsecurity.com and in the course of our engagements. This notice explains what we collect, why, and what you can ask us to do about it.

This website is a set of static pages. It has no accounts, no login, no forms, no payment processing, no advertising and no analytics. We do not set cookies and we do not track you across other sites.

The one third-party request

The typeface used on this site is served by Google Fonts. When a page loads, your browser requests the font from Google, which receives your IP address and the page you are viewing. Google states that it does not set cookies for this service. No other third party receives anything about your visit.

We regard this as a gap between what this site does and what we recommend to clients, and we are moving to a self-hosted typeface so that no external request is made at all.

What we collect through this website

Almost nothing. Because the site is static, the only data generated by your visit is the connection information our hosting provider records to deliver the page and protect the service.

DataWhyHeld by
IP address, browser type, page requested, time of request Delivering the page, and detecting and blocking abuse Cloudflare, as our hosting and security provider

We do not use this information to identify individuals and we do not combine it with anything else.

If you contact us

If you email us, we hold your message, your email address and any contact details you include, so that we can reply and keep a record of the correspondence. If you send us a completed readiness assessment, we hold what you send so we can review it with you.

We use that information only to respond to you and to provide what you asked for. We do not add you to a marketing list without your agreement, and we do not sell or share your details with anyone for their own purposes.

If we carry out an engagement for you

During an assessment we collect evidence about your systems and controls. That evidence often contains personal data, for example the names and roles of staff who hold accounts, who left the organization, or who operate a control.

  • We process it only to carry out the engagement described in your engagement letter.
  • We hold it for the retention period stated in that engagement letter, and then destroy it.
  • You can ask us to return or destroy it sooner.
  • Where we act as a processor on your behalf, our data processing terms apply and form part of the engagement.

We do not use client evidence for any other purpose. We do not use it to train anything, we do not reuse it as an example, and we do not name clients in our materials without written permission.

Who else handles data for us

ProviderPurpose
CloudflareWebsite hosting, DNS and security
CloudflareEmail routing for the contact address

Each provider processes data under its own terms and applicable data processing agreements. We do not sell personal data to anyone, and we do not permit any provider to use it for their own purposes.

Where your data is held

Our providers operate internationally, so data may be processed outside Jamaica. Where that happens we rely on the provider's own transfer safeguards. If you need specifics for an engagement, ask and we will tell you which providers are involved and where.

Your rights

You can ask us to tell you what personal data we hold about you, correct it if it is wrong, delete it where we have no continuing need or legal obligation to keep it, or restrict what we do with it.

Where we hold data as a processor on behalf of a client, direct your request to that client and we will support them in answering it.

Requests are free and we will respond within the period required by applicable law. If you are not satisfied with our response you can complain to the Office of the Information Commissioner in Jamaica, or to the supervisory authority in your own country.

How we protect it

Evidence and working papers are encrypted at rest and in transit, access is limited to the principals working on the engagement, and credentials are held in a managed credential store with multi-factor authentication. We apply to ourselves the controls we assess in others, and we are willing to evidence that on request.

Changes

If we change this notice we will update the date at the top. Where the change is material and we hold your contact details, we will tell you directly.

Contact

Questions about this notice, or to make a request: contact@rootguardsecurity.com
RootGuard Security Limited, [registered address]

© 2026 RootGuard Security Limited. Registered in Jamaica.
Services Who we are Privacy Terms