This Privacy Policy explains how Duzett Roots LLC, a computer integrated systems design studio founded and led by developer Duzett Roots, collects, uses, stores and protects personal information. It applies to our website and to the professional, scientific and technical services we deliver to clients. We have written it to be read without a legal dictionary, and we encourage you to contact us with any question it does not answer.
Scope of This Policy
This policy covers personal information that Duzett Roots LLC handles when you visit our website, send us a message, call our studio, engage us for a project, or otherwise interact with our business. It also covers information we process on behalf of clients while delivering integrated systems design, data pipeline and monitoring services, to the extent that we act as a custodian of that information.
This policy does not apply to information that clients collect and control under their own privacy notices. When we work inside a client environment, the client remains the responsible party for the data it holds, and we handle that data strictly according to the written instructions in our agreement. If you are an end user of a client system, please direct your privacy request to that client first, and we will support them in responding.
Information We Collect
We collect information in three main ways: information you give us directly, information gathered automatically as you use our website, and information created as part of a project engagement.
Information you provide
- Your name, employer and role when you introduce yourself to the studio.
- Your email address, phone number and postal address when you request a survey.
- The content of messages you send through our contact form or by email.
- Project details, technical descriptions and documents you choose to share.
- Billing details when a contract requires invoicing and payment records.
Information collected automatically
- Server logs recording the pages requested and the time of each request.
- Approximate location derived from an internet protocol address.
- Browser type, device type and operating system.
- Referring pages and general interaction patterns on our site.
Information created during engagements
- System inventories, architecture notes and audit findings.
- Diagnostic traces and telemetry samples needed to engineer a fix.
- Correspondence records that document decisions and approvals.
How We Use Information
We use personal information only for purposes that a reasonable person would expect from a systems design studio. Each purpose is tied to a specific operational need and is reviewed when our practices change.
- To respond to enquiries, schedule conversations and prepare proposals.
- To deliver integrated systems design, audit, pipeline and monitoring work.
- To maintain the security and stability of our own website and infrastructure.
- To keep accurate records of contracts, deliverables and approvals.
- To meet accounting, tax and legal obligations that apply to our business.
- To improve our services by understanding which materials are useful to visitors.
- To protect the rights, property and safety of our studio, clients and staff.
We do not sell personal information, and we do not rent contact lists to any party. We do not use the content of client systems for training, resale or unrelated purposes.
Our Legal Basis for Processing
Where the law requires a legal basis for processing, we rely on the following grounds. We rely on your consent when you submit a form or subscribe to a newsletter. We rely on the performance of a contract when we deliver work you have engaged us to do. We rely on our legitimate interests when we secure our systems, prevent fraud and improve our services, provided those interests do not override your rights. We rely on legal obligation when we keep records for tax, accounting or regulatory reasons.
You may withdraw consent at any time where consent is the basis, and we will stop the related processing unless another lawful ground applies. Withdrawing consent does not affect processing that already took place while consent was valid.
Service Providers and Processors
When a third party processes personal information on our behalf, we require it to act only on our documented instructions and to apply protections that are at least as strong as those described here. We assess service providers for security posture, data location and subprocessor practices before we engage them, and we review the relationship periodically.
Our service providers fall into a few categories: infrastructure and hosting, email and communication, document storage, and accounting. Each provider is bound by a written agreement that covers confidentiality, security, deletion and cooperation with your privacy requests. If a provider cannot meet our standard, we do not use it, even when it would be cheaper.
Data Retention
We keep personal information only as long as we need it for the purpose it was collected, plus any period required by law. Enquiries that do not become projects are usually removed within twenty four months. Project records are retained for the duration of the engagement and for a reasonable period afterward so that we can support handover, audits and warranty questions. Financial records are retained for the period required by tax and accounting rules.
When a retention period ends, we delete or anonymise the information. Where deletion would also destroy records we are legally required to keep, we isolate those records and restrict access to them. If you ask us to delete information, we will do so unless a legal obligation or an active contract requires us to retain it, and we will explain the reason when that is the case.
How We Protect Information
We treat the security of personal information as part of our professional duty. We use encryption in transit for our website and email where the receiving service supports it. We restrict access to personal information to staff and contractors who need it to do their work, and we require confidentiality commitments from everyone who can reach it. We keep systems patched, we use strong authentication, and we avoid storing sensitive data when a reference is sufficient.
We also design our client work with privacy in mind. Data pipelines are built to move only the fields a task requires, monitoring dashboards display aggregates rather than raw personal records wherever possible, and diagnostic traces are purged after a root cause has been confirmed. No system is perfectly secure, and we do not claim otherwise, but we maintain the practices we would expect a serious studio to maintain.
International Data Transfers
Duzett Roots LLC is based in the United States, and the information we handle is primarily stored and processed in the United States. Some of our service providers operate infrastructure in other countries, so personal information may be transferred across borders to reach their systems. When we make such a transfer, we rely on appropriate safeguards, including contractual protections and provider commitments that preserve the protections described in this policy.
If you are located outside the United States and choose to contact us, you understand that your information will be handled under United States law and under this policy. Where local law grants you additional rights, we honor those rights to the extent they apply to our processing.
Your Privacy Rights
Subject to the law where you live, you may have the right to access the personal information we hold about you, to correct information that is inaccurate, to request deletion of information we no longer need, to restrict or object to certain processing, to receive a portable copy of information you provided, and to withdraw consent where consent is the basis for processing.
To exercise a right, contact us using the details at the end of this policy. We will verify your identity before acting, and we will respond within the time the applicable law allows. We will not discriminate against you for making a request. If we cannot fulfill a request in full, we will tell you why and explain what you can do next, including how to escalate to a supervisory authority where one applies.
Marketing and Communications
We may send occasional studio updates to people who have asked to receive them, such as notes about our autumn intake window or new service lines. Every marketing message includes a simple way to unsubscribe, and we honor unsubscribe requests promptly. We do not add people to a marketing list simply because they sent a project enquiry.
Transactional messages, such as a reply to your form submission, a project update or an invoice, are not marketing and are sent as required to deliver the service you requested. If you prefer not to receive even transactional email, tell us and we will note your preference on your record.
Client and Project Data
During an engagement, we may encounter confidential and personal information inside a client environment. We treat this data as confidential, use it only to deliver the agreed work, and separate it from our own business records. We document what we access, keep the footprint minimal, and remove project copies at the end of the engagement unless the contract says otherwise.
When we build a data pipeline or monitoring platform, we design it so that personal information is minimised and access is controlled. Where a client asks us to process personal data as a service provider, our agreement names the subject matter, the duration, the nature and purpose of processing, the categories of data and the obligations of both parties. We cooperate with client audits and with requests from individuals routed through the client.
Privacy for Children
Our website and services are intended for businesses and professionals, and they are not directed at children. We do not knowingly collect personal information from anyone under the age of thirteen. If we learn that we have collected such information without appropriate consent, we will delete it promptly. If you believe a child has provided information to us, please contact us so that we can act.
Because our client work focuses on systems design for professional and scientific organisations, we do not expect to process children personal data. If a project would involve such data, we require the client to confirm that it has the necessary consents and safeguards in place before we begin.
Third Party Websites
Our website may link to third party sites, such as a provider documentation page or a standards body. We do not control those sites and we are not responsible for their privacy practices. When you follow a link away from our site, we encourage you to read the privacy notice of the destination before you provide personal information.
Links are provided for convenience and reference only, and a link does not imply that we endorse the content, products or practices of the destination. If you believe a link on our site points to something harmful or misleading, please tell us and we will review it.
Data Breach Notification
We maintain a simple incident process so that we can respond quickly if personal information is ever compromised. When we become aware of a breach, we investigate, contain the issue, and assess the risk to affected individuals. Where the law requires notification, we notify affected individuals and relevant authorities without undue delay.
Our response includes a written record of what happened, what data was involved, what we did to contain it and what we will change to prevent a repeat. We would rather be judged on how honestly we handle an incident than on a claim that it could never happen.
Do Not Track Signals
Some browsers can send a Do Not Track signal to the websites they visit. There is still no common industry standard for how such a signal should be interpreted, so our site does not change its behavior in response to it. We keep our analytics minimal and aggregated, which reduces the value of tracking regardless of the signal setting.
You can limit tracking through browser settings, privacy extensions and cookie controls. We support those choices, and the site remains fully usable when tracking is restricted. If a future standard for Do Not Track gains broad adoption, we will review our approach and update this policy.
Changes to This Policy
We review this policy when our practices, our tools or the law change. When we make a material change, we update the effective date at the top and, where appropriate, provide a notice on our homepage or by email to people who have an active relationship with the studio. The current version is always the one posted on this page.
We keep prior versions of this policy in our records so that we can explain how our practices have evolved. If you have questions about a change, contact us and we will walk through what changed and why. Continued use of our website after a change means you accept the updated policy.
How to Contact Us
Duzett Roots LLC welcomes questions about this Privacy Policy and about how we handle personal information. Reach the studio by email at contact@duzettroots.lol, by phone at +14844636877, or by post at 1425 W 8780 S, West Jordan - 84088-9110, United States (US).
When you write, please include enough detail for us to understand your request, such as the email address you used and the nature of your concern. We will acknowledge your message, explain what we can do, and keep you informed until the matter is resolved. Your trust in a systems design studio depends on clear handling of exactly this kind of information, and we take that responsibility seriously.