Roots·Energy
SystemPropertiesAboutR&D
DEEN
Request analysis
DEEN
SystemPropertiesAboutResearch & Development
Request analysis
Privacy

Privacy Policy

Information on the processing of personal data at Roots·Energy in accordance with the GDPR.

Version of 1 April 2026

Chapter 01

Fundamentals

The legally binding version of this privacy policy is the German original. This English text is a convenience translation; in case of discrepancy, the German version prevails.

1.1 Controller

1.1.1 We, Roots Energy GmbH, Linzer Straße 76, 1140 Wien, +43 1 4350730, service@roots.energy, FN 555670 m (Commercial Court of Vienna), GISA number 35818281, VAT ID ATU76906369 (hereinafter referred to as “ROOTS”), are the controller within the meaning of data protection law. ROOTS is the company that decides on the purposes and means of processing personal data within the scope of our range of services and is responsible for security and compliance with the applicable laws. As the controller, ROOTS is subject to numerous information obligations, which are fulfilled by means of this privacy policy.

1.2 Scope

1.2.1 This privacy policy applies to all services provided by ROOTS and the associated use of products and services that ROOTS supplies or makes available. Unless otherwise provided for in this privacy policy, the same definitions apply as in the General Terms and Conditions (GTC). For the purposes of this privacy policy, the clients of ROOTS are also referred to as “users”.

1.3 Level of Data Protection

1.3.1 ROOTS regards Austrian and European data protection laws (in particular the EU General Data Protection Regulation, “GDPR”) as the minimum standard for handling the data of its clients. These laws are intended to ensure the highest level of data protection worldwide.

1.3.2 Nevertheless, no one is immune to unlawful access and illegal attacks. To that extent, ROOTS cannot guarantee absolute security of user data and excludes any responsibility and liability in this regard.

1.4 Definitions

1.4.1 Data protection applies to what is known as “personal data”. In short, this means all information relating to an identified person, thereby making that person identifiable.

1.4.2 The central element of data protection is what is known as the “processing” of personal data. This means any operation involving data, however simple, for example the collection, recording and storage, use, as well as the linking and transmission of personal data, as explained in more detail in the following chapters.

Back to top
Chapter 02

Data Collection

2.1 Principle

2.1.1 ROOTS generally collects the data that our clients provide via our website, by email or by telephone in the course of initiating business and the subsequent performance of the contractual relationship. The user thus decides for themselves about the disclosure of their data, although certain minimum details are necessary in order for ROOTS to be able to provide the desired services and products.

2.2 Data Collected

2.2.1 The data entries necessary for the performance of the contract are mandatory and essentially correspond to the master data and contact information of the clients, as well as the data of the property that is the subject of the contract, including the buildings erected on it. These are minimum details that ROOTS requires in order to prepare offers and to ensure the handling of specific orders. In addition, each user may optionally provide further property-related data.

2.2.2 In the course of initiating business, ROOTS will collect in particular the following data and information:

  • First and last name, company name, role/profession, email address, telephone number, address.
  • IP address, device identifier, operating system, browser type and version, activity events, email and support requests.
  • Login data, invoices, payment status, means of payment (credit card, bank account, etc.).
  • Property-related data, which is generally not subject to data protection, such as address and land register data.

2.2.3 Otherwise, data generated during the use of our website may also be collected, for example access logs or data from third-party providers, such as when the user accesses our services via social networks.

2.3 Method of Data Collection

2.3.1 The manner in which ROOTS collects data arises from the ordering process and the handling of the ORDER:

  • Booking an appointment on our website requires information for initiating business, in particular about the property concerned and contact information.
  • Communication with ROOTS, in particular via electronic messaging services (e.g. email, messenger, telephone), is used in the course of contract handling. It is primarily the user’s decision which information and data are disclosed in active communication with us.
  • Performance and billing of the specific order requires contact information, as well as bank data and other payment information.
  • Websites, cookies and similar technologies may collect data, but the user can regulate data collection in the consent management (cookie banner on the website) or in the respective browser settings.

2.4 Personal Settings and Updates

2.4.1 Apart from voluntary data entries, there is the option to independently activate or deactivate the collection of certain data in the settings of one’s own software.

2.4.2 In the course of the further development of the range of services offered by ROOTS, the usage options and the associated data collection may be expanded. We will update this privacy policy accordingly.

Back to top
Chapter 03

Data Storage

3.1 Place of Storage

3.1.1 The data provided by users and collected by ROOTS may be stored on the end devices used. In addition, this data is kept on servers owned or leased by ROOTS. Only cloud systems that comply with the requirements of the GDPR are used.

3.2 Duration of Storage

3.2.1 ROOTS stores personal data at least for the duration of the contractual relationship, that is, for as long and to the extent that the client makes use of services provided by ROOTS and the ORDER has not yet been performed or terminated.

3.2.2 In addition, storage may be necessary in order to fulfil post-contractual obligations or statutory retention or disclosure obligations, or to assert, exercise or defend potential legal claims. Such longer data storage is governed by the statutory time limits that ROOTS is required to observe and takes place exclusively to the extent required by the respective law (e.g. limitation periods).

Back to top
Chapter 04

Legal Basis

4.1 Principle

4.1.1 ROOTS uses personal data exclusively for the purposes set out in this privacy policy and on a permissible legal basis in accordance with the GDPR. These may be performance of a contract, legitimate interests of ROOTS, the user’s consent, or statutory requirements.

4.2 Performance of a Contract

4.2.1 The main purpose of data processing is the initiation of business, the preparation of offers through to the performance of the specific order, as well as the use of all associated products and services. In this context, ROOTS provides the following services that are inherent to the usage and typical of the contract:

  • Collection, verification and management of customer profiles.
  • Preparation and transmission of offers.
  • Organisation, administration, handling and billing of orders.
  • Disclosure of data to suppliers, subcontractors and other cooperation partners.
  • Operation and administration of registration processes and online services.
  • Provision and administration of messages, notifications and other direct communication, insofar as this forms an integral part of the contractual services.

4.2.2 Within the scope of the aforementioned purposes, data processing is necessary for the performance of the contract concluded with ROOTS (Art. 6(1)(b) GDPR). If required data (in particular mandatory details) is not provided, business cannot be initiated and a contract with ROOTS cannot be concluded. Data is also collected to process any comments and enquiries that the user may have via various communication channels with ROOTS in connection with the performance of the contract.

4.2.3 No profiling within the meaning of Art. 4(4) GDPR takes place (Art. 22(1) GDPR).

4.3 Legitimate Interests

4.3.1 The processing of user or client data may also take place around the necessary performance of the contract. In such cases, the data processing is in the overriding interest of ROOTS in order to maintain the functionality and security of our services and to keep operations economically viable. This includes in particular:

  • Processing and answering of non-contractual enquiries via email, website contact form, telephone, etc.
  • Development, testing and optimisation of required software and business processes.
  • Development of technologies and concepts for improving IT security and data protection.
  • Prevention of fraud, misuse of services or money laundering, arrangements for reporting suspected misconduct (whistleblowing).
  • Carrying out existing-customer advertising, direct advertising and other forms of marketing and advertising.
  • Processing for research purposes, including market research, for historical, scientific or statistical purposes.

4.3.2 The legal basis for data processing in the context of customer support, business development, as well as security and market research is Art. 6(1)(f) GDPR, whereby the legitimate interests of ROOTS lie in the aforementioned purposes and are generally of a security-related, as well as competitive and economic nature.

4.4 Legal Obligations

4.4.1 On the basis of mandatory statutory provisions, judicial or official decisions and orders, or for the purposes of criminal prosecution or on grounds of public or vital interests, ROOTS may be required to disclose or process personal data without the user’s consent. In such a case, the user concerned will be informed in good time (insofar as legally permissible).

4.4.2 This also includes requirements under company law, tax law or commercial law, as well as audit and reporting obligations to which ROOTS as a company is subject. In order to be able to fulfil these, personal data is processed in accordance with Art. 6(1)(c) GDPR to the extent required by the respective law.

4.5 Legal Claims and Fraud Prevention

4.5.1 Finally, the use of personal data may be necessary to prevent fraud or other criminal activity by users, or for our assertion, exercise or defence of legal claims. These are legitimate interests of ROOTS, and therefore in such cases the retention and processing of user data without consent is legally permissible.

Back to top
Chapter 05

Consent and Withdrawal

5.1 Processing Requiring Consent

5.1.1 Insofar as the legal bases set out above are not applicable, certain data processing operations require the active consent of users or clients. This includes in particular:

  • Ordering and dispatch of a newsletter.
  • Analysis and tracking of user behaviour on websites or in apps (cookie policy).
  • Transmission of user data to third parties, in certain countries outside the EU.

5.1.2 The legal basis for data processing within the scope of the aforementioned purposes is the user’s consent (Art. 6(1)(a) GDPR), which, where necessary, is obtained at an appropriate point (e.g. cookie banner on the website, registration process) or in writing in the course of contract handling.

5.2 Withdrawal of Consent

5.2.1 Consent once given may be deactivated or withdrawn at any time, either in the consent management or in the settings of the browser used, or simply by email message to service@roots.energy. The withdrawal of consent does not affect the lawfulness of the data processing carried out up to that point.

5.3 Recommendations and Marketing

5.3.1 Within the scope of the range of services offered by ROOTS, property-related suggestions and recommendations may be made in the future. These may also involve information about products and services from specialised third-party providers, as well as invitations to take part in surveys or other sales-promotion and marketing activities. Any consent required for this is obtained in advance, while at the same time instruction and information obligations are met to the extent required by law.

Back to top
Chapter 06

Data Transfer

6.1 Processors and Cooperation Partners

6.1.1 ROOTS relies on the organisational and technical support of reliable cooperation partners and external service providers (so-called processors) in order to offer comprehensive and optimal use and proper contract handling. The processors are bound by the contracts concluded with ROOTS as well as by the GDPR and process data only in accordance with the specifications and instructions of ROOTS.

6.1.2 User data is provided in particular in the course of the necessary performance of the contract:

  • Suppliers, subcontractors and other cooperation partners provide partial services for ROOTS, where applicable directly to our clients.
  • Hosting and cloud services and their tools serve the storage and management of the order data.
  • Accounting and payment service providers assist with the billing of the contracts.
  • Analytics service providers and their tools help to understand how users use our website, in order to provide tailored communication and product improvements in the future.
  • Marketing service providers assist with the creation, sorting, customisation and dispatch of newsletters, advertising and other notifications to users.

6.2 Data Transmission within the EU and the EEA

6.2.1 ROOTS primarily selects cooperation partners that have their registered office or servers within the European Union (EU) or the European Economic Area (EEA). A data transmission within the EU and the EEA is unproblematic, because the GDPR applies in all Member States.

6.3 Data Transmission to Third Countries

6.3.1 In exceptional cases, third-party providers with their registered office or servers outside the EU are engaged. In these cases, a high level of protection in accordance with the GDPR may be ensured with regard to personal data, namely by an adequacy decision of the EU, by which the level of data protection in certain third countries is deemed adequate (e.g. Switzerland, Canada, Japan), and by standard data protection clauses reviewed by the EU that underlie the contractual relationship with processors, or by comparable legal instruments or certifications permissible under the GDPR.

6.4 Data Transmission to the USA

6.4.1 The USA is currently not certified by the Court of Justice of the European Union as having an adequate level of data protection if it does not participate in the Data Privacy Framework Program. In particular, there is the risk that personal data may be subject to access by US authorities for control and surveillance purposes and that EU citizens have no effective legal remedies against this. It is further criticised that access by US authorities is not legally limited to the strictly necessary extent and that no judicial authorisations for this are enshrined in law.

6.4.2 Before user data is transmitted to US companies that are not subject to the Data Privacy Framework Program, explicit consent is requested at an appropriate point (Art. 6(1)(a) in conjunction with Art. 49(1)(a) GDPR), and the relevant data processing operations are explained (in particular the purposes, data categories and storage period), insofar as this does not already arise from this privacy policy.

Back to top
Chapter 07

Data Subject Rights

7.1 Withdrawal and Objection

7.1.1 Insofar as ROOTS processes data on the basis of consent, every user has the right to withdraw their given consent in whole or in part at any time. In the event of a withdrawal, ROOTS is obliged to erase or irreversibly anonymise the personal data without undue delay (subject to the retention obligations or rights mentioned). A withdrawal does not, however, affect the lawfulness of the data processing carried out on the basis of the consent up to that point.

7.1.2 Every user also has the right to object to data processing based on legitimate interests of ROOTS, if grounds for this arise from their particular situation. Where personal data is processed for the purposes of direct advertising (including profiling), the user may object to this.

7.2 Information, Rectification and Restriction

7.2.1 Every user has the right to request information about the processing of their personal data. The right of access includes information about the purposes of processing, the categories of data and recipients, the storage period, any origin of the data, as well as the rights under data protection law. All of this can in any case already be found in this privacy policy and can be made available on request in an electronic format.

7.2.2 Should it turn out that individual items of personal data are incorrect, the user may at any time request the rectification or completion of their data. For the duration of any examination of a request, there is also the right to restriction of data processing.

7.3 Erasure (“Right to be Forgotten”)

7.3.1 Every user has the right to request the erasure of their personal data. If the data is no longer necessary for the performance of the contract, a declaration of consent is withdrawn or an objection is made to data processing, then the data is erased without undue delay.

7.3.2 If delays arise due to identity verification or for technical or economic reasons, the data processing is restricted as far as possible until final erasure. Apart from this, it should be noted that further data processing may still be necessary, namely for the fulfilment of legal obligations (including post-contractual handling), on grounds of public interest, or for the assertion, exercise or defence of legal claims.

7.4 Data Portability

7.4.1 Every user has the right to request that an overview of their personal data be transmitted to another controller, insofar as this is technically feasible (right to data portability).

7.5 Right to Lodge a Complaint

7.5.1 Should a user be of the opinion that ROOTS does not adequately safeguard data protection rights, they may contact us at any time by message to service@roots.energy.

7.5.2 Otherwise, every user has the right to lodge a complaint with the competent Austrian Data Protection Authority (www.dsb.gv.at) at 1030 Wien, Barichgasse 40-42, if they consider that the processing of their personal data infringes data protection law. In addition, the right to lodge a complaint may also be exercised before a supervisory authority in the EU Member State of the place of residence, the place of work or the place of an alleged infringement.

Back to top

The
Sane
Choice
.

  • Research & Development
  • About
  • Contact
  • LinkedIn

© 2026 · Roots·Energy GmbH · Vienna · Made in Europe

  • Imprint
  • Privacy
  • Terms

Request analysis

We review your district or property in a no-obligation initial conversation and deliver a concrete first assessment, informed, clear, on equal footing.

Customer group
    Role in the project
    • Ing.
    • Dr.
    • Dr.in
    • DDr.
    • Dr.-Ing.
    • Mag.
    • Mag.a
    • Dipl.-Ing. (DI)
    • Prof.
    • Prof. Dr.
    • Univ.-Prof.
    • Univ.-Prof. Dr.
    • +43Austria
    • +49Germany
    • +41Switzerland
    • +423Liechtenstein
    • +355Albania
    • +376Andorra
    • +32Belgium
    • +387Bosnia and Herzegovina
    • +359Bulgaria
    • +45Denmark
    • +372Estonia
    • +358Finland
    • +33France
    • +30Greece
    • +353Ireland
    • +354Iceland
    • +39Italy
    • +383Kosovo
    • +385Croatia
    • +371Latvia
    • +370Lithuania
    • +352Luxembourg
    • +356Malta
    • +373Moldova
    • +377Monaco
    • +382Montenegro
    • +31Netherlands
    • +389North Macedonia
    • +47Norway
    • +48Poland
    • +351Portugal
    • +40Romania
    • +378San Marino
    • +46Sweden
    • +381Serbia
    • +421Slovakia
    • +386Slovenia
    • +34Spain
    • +420Czechia
    • +380Ukraine
    • +36Hungary
    • +379Vatican City
    • +44United Kingdom
    • +357Cyprus
    • Initial conversation
    • Commission an analysis
    • Request a quote
    • Press contact
    • Other

    Thank you for your enquiry.

    We will be in touch.

    Submission failed.

    Please try again, or write to us directly at mariella.neuwirther@roots.energy.