Privacy policy
Last updated on 21 August 2026
This policy sets out what data Code Roots processes when delivering the service, why it does so, and what rights you have.
Data we process
For users we process name, email address, company name and the details needed for billing. For connected sites we process the URL, version numbers, the list of plugins and themes, uptime measurements and the results of security checks.
We do not store website content and we do not process visitor data from connected sites.
Why we process this data
The data is needed to deliver the service: showing status, running updates and backups, and putting together reports. The legal basis is performance of the contract.
Billing and bookkeeping data is kept under a statutory retention requirement.
Retention periods
Uptime measurements and log entries are kept for thirteen months so you can produce a yearly report. Account data is kept for thirty days after the subscription ends. Invoices are kept for seven years.
Processors and storage
Data is stored on servers within the European Union. We use processors for hosting, database, email delivery, payments and screenshot capture. A data processing agreement is in place with every processor. An up to date list of the processors we use is available on request via hello@rootswp.com.
If you use Sentro to manage sites for your own clients, you are the controller and we are the processor. Our data processing agreement is published on the Data processing agreement page and applies as soon as you use the service.
Security
Traffic between Sentro and connected sites runs over HTTPS and is signed with HMAC-SHA256. Connection keys are stored encrypted and are not visible to regular team members. Access to production systems is limited to those who need it.
Your rights
You can view, correct or request deletion of your data. Send a message to hello@rootswp.com. You can also lodge a complaint with your national data protection authority.