Trust Centre
Data Protection & Confidentiality
Privacy is not simply a legal obligation at Roots by Vera — it is one of our core values. This page describes the practical care taken with everything you entrust to us.
Last reviewed: [Date of last review]
Our commitments
- Every project remains private. Client names and family histories are never used as examples without written permission.
- Every document remains confidential and is stored apart from anything publicly accessible.
- Only authorised processing is permitted. Access is limited to those working on your project.
- Information is processed only for the agreed research, never for unrelated purposes.
- Research findings belong to the client, and are delivered for your family's use.
How documents are handled
- Your documents are used exclusively for your own family legacy project.
- They are processed securely and accessed only by authorised personnel.
- They are never shared with third parties without your permission unless required by law.
- Documents are retained only for as long as necessary to complete the agreed commission or comply with legal obligations.
Technical measures in place
- All traffic to this site is encrypted in transit over HTTPS.
- Enquiries are written to a private database with no public read access.
- The administrative dashboard is passphrase protected and excluded from search engine indexing.
- The enquiry form is rate limited and screened for automated submissions.
- Client information is never displayed publicly anywhere on this site.
Working with archives and third parties
Some research requires contacting an archive, registry or local record agent. In those cases only the minimum information needed to locate a record is shared, and never the wider family story. Standing arrangements with recurring collaborators: [to be documented].
Living relatives
Research frequently touches people who are still living. Information about living individuals is handled with particular restraint and is included in a report only where it is necessary and appropriate: [internal policy to be confirmed with counsel].
If something goes wrong
In the unlikely event of a personal data breach, affected clients and the competent supervisory authority — [Competent data protection supervisory authority] — are notified as required by the GDPR. Concerns may be raised at any time at hello@rootsbyvera.eu.
Legal review note: This page describes practices currently in place and makes no certification claim. Have the wording reviewed before adding any further security or compliance statements.