1. Introduction & Business Identity
Unbound Root ("we," "us," or "our") is a home-based technology business operated by Nicolas Figueroa Hidalgo , located in Port Orchard, Washington, USA. We provide cybersecurity and computer literacy consulting, awareness and education services to clients and visitors worldwide through our website at https://unboundroot.com.
This Privacy Policy describes what personal information we collect, why we collect it, how we use and protect it, how long we retain it, and what rights you have regarding your information. This policy applies to all users of our website and services, regardless of your country of residence.
Last Updated: July 22, 2026. We will post any updates to this policy on this page with a revised effective date.
By using our website, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with any part of this policy, please do not use our website.
2. Information We Collect
2.1 Information You Provide to Us
We collect personal information that you voluntarily provide when you submit our website contact form. This includes:
- Full name — so we can address you appropriately in our response;
- Email address — so we can reply to your inquiry;
- Message content — the details of your inquiry, question, or request.
We do not require you to create an account, and we do not collect payment information directly through our website.
2.2 Information Collected Automatically
When you visit our website, we and our service providers may automatically collect certain technical information, including:
- IP address — your Internet Protocol address, which may indicate your general geographic region;
- Browser type and version — e.g., Chrome, Firefox, Safari;
- Device type and operating system;
- Pages visited and time spent — which pages you viewed and how long you spent on them;
- Referring URLs — the website that directed you to ours;
- Date and time of your visit;
- Cookie identifiers and similar tracking data (see Section 5).
2.3 What We Do Not Collect
We do not knowingly collect any sensitive categories of personal data, including but not limited to: racial or ethnic origin, political opinions, religious beliefs, health information, biometric data, financial account information, Social Security numbers, or precise geolocation data. If you inadvertently include such information in a contact form message, please be aware that it will be handled with care and deleted as soon as it is identified as unnecessary.
3. How We Use Your Information
We use the personal information we collect only for the following purposes:
| Purpose | Data Used | Details |
|---|---|---|
| Responding to inquiries | Name, email, message | To read, evaluate, and reply to your contact form submission in a timely and professional manner. |
| Improving website performance | Analytics/usage data, cookies | To understand how visitors use our site, identify errors, and improve content and navigation. |
| Legal compliance | All data as necessary | To meet legal obligations, respond to lawful requests from authorities, and enforce our rights. |
| Security & fraud prevention | IP address, usage data | To detect and prevent unauthorized access, abuse, or harmful activity on our website. |
Our Commitment: We Do Not Sell Your Data.
We do not sell, rent, trade, or otherwise transfer your personal information to any third party for commercial or marketing purposes — ever.
Your data is used only to serve you and operate our business.
4. Legal Basis for Processing (GDPR / UK GDPR)
For visitors located in the European Union (EU), European Economic Area (EEA), or the United Kingdom (UK), we are required under the General Data Protection Regulation (GDPR) and UK GDPR to identify a lawful basis for processing your personal data. Our legal bases are as follows:
| Legal Basis | When We Rely on It |
|---|---|
| Legitimate Interests (Art. 6(1)(f) GDPR) | Processing website analytics data and usage logs to improve our services and maintain security. Our legitimate interests do not override your fundamental rights. |
| Performance of a Contract / Pre-contractual Steps (Art. 6(1)(b) GDPR) | Processing contact form data in order to respond to your inquiry about engaging our services. |
| Legal Obligation (Art. 6(1)(c) GDPR) | Retaining or disclosing data where required by applicable law or regulation. |
| Consent (Art. 6(1)(a) GDPR) | Where we deploy non-essential cookies or analytics tools, we rely on your consent obtained via our cookie consent banner. |
4.1 Data Controller Identification
For purposes of the GDPR and UK GDPR, the data controller is:
- Business Name: Unbound Root
- Owners / Responsible Persons: Nicolas Figueroa Hidalgo
- Address: Port Orchard, Washington, USA
- Contact Email: nitem18@hotmail.com
As a small business based in the United States, we do not have a mandatory EU/UK establishment. However, we are committed to honoring the rights of EU/UK data subjects as described in Section 8 of this policy. If required by applicable law based on the volume or nature of EU/UK data we process, we will appoint an EU or UK Representative and update this section accordingly.
5. Cookies & Tracking Technologies
Our website uses cookies and similar technologies. A cookie is a small text file placed on your device when you visit a website. Cookies allow us to recognize your browser and remember certain information about your visit.
5.1 Types of Cookies We Use
| Cookie Type | Purpose | Can You Opt Out? |
|---|---|---|
| Essential / Strictly Necessary | Required for basic website functionality (e.g., form submission, security). These cannot be disabled without breaking the site. | No — required for core functions. |
| Analytics / Performance | Helps us understand how visitors interact with our site (e.g., pages visited, session duration) using tools such as Google Analytics or equivalent. | Yes — via cookie consent banner or browser settings. |
| Preference / Functional | Remembers choices you have made on our site (e.g., language, region) to improve your experience on return visits. | Yes — via cookie consent banner. |
5.2 Managing and Opting Out of Cookies
You have several options to manage cookies:
- Cookie Consent Banner: When you first visit our site, a cookie consent banner will appear allowing you to accept or decline non-essential cookies. You may update your preferences at any time.
- Browser Settings: Most browsers allow you to refuse or delete cookies. Refer to your browser's help documentation for instructions. Note that disabling all cookies may affect some website functionality.
- Opt-Out Tools: For analytics cookies, you may use tools such as the Google Analytics Opt-Out Browser Add-on.
We do not use advertising, retargeting, or cross-site tracking cookies.
6. Data Sharing & Third Parties
6.1 No Sale of Personal Data
We do not sell, rent, lease, or share your personal information with third parties for their own marketing or commercial purposes. Period.
6.2 Service Providers
We may share limited personal data with trusted third-party service providers who help us operate our website. These providers are contractually required to use your data solely to perform services on our behalf and are prohibited from using it for any other purpose.
| Service Provider Category | Purpose | Data Shared |
|---|---|---|
| Web Hosting Provider | To host and deliver our website. | IP address, usage logs. |
| Analytics Provider | To analyze website traffic and performance. | Anonymized/pseudonymized usage data, cookies. |
| Email / Communication Provider | To receive and respond to contact form submissions. | Name, email address, message content. |
6.3 Legal Disclosures
We may disclose your personal information if required to do so by law, court order, or governmental authority, or if we believe in good faith that such disclosure is necessary to protect the rights, property, or safety of our business, our users, or the public.
6.4 International Data Transfers
Our business is located in the United States. If you are accessing our website from the EU, EEA, UK, or other regions with laws governing data collection and use, your information may be transferred to and processed in the United States, where data protection laws may differ from those in your jurisdiction.
Where we transfer personal data of EU/UK individuals to third-party service providers located outside the EEA or UK, we ensure that appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) or other lawful transfer mechanisms. You may request information about the specific safeguards in place for any international transfer by contacting us at nitem18@hotmail.com.
7. Data Retention
We retain personal information only for as long as necessary to fulfill the purposes for which it was collected, or as required by law. Our specific retention practices are:
| Data Type | Retention Period | Disposal Method |
|---|---|---|
| Contact form submissions (name, email, message) | Retained for X months following the date of last contact or the conclusion of any related business engagement, whichever is later. | Permanently deleted from email systems and any associated records. |
| Website analytics data | Retained per the analytics platform's default policy (typically 14 months for Google Analytics) or until anonymized. | Anonymized or deleted in accordance with platform data lifecycle settings. |
| Server/access logs (IP address, usage) | Retained for up to 90 days for security purposes. | Automatically purged by hosting provider. |
| Cookie data | Session cookies expire when you close your browser; persistent cookies expire as defined in your cookie settings. | Automatically cleared or deletable via browser settings. |
At the end of each applicable retention period, data is securely deleted or anonymized so that it can no longer be linked to any individual.
8. Your Privacy Rights
Depending on your country or state of residence, you may have specific legal rights regarding your personal information. We honor these rights for all users to the fullest extent practicable.
8.1 European Union / EEA & United Kingdom (GDPR / UK GDPR)
If you are located in the EU, EEA, or UK, you have rights including access, rectification, erasure, restriction of processing, data portability, objection, withdrawal of consent, and the right to lodge a complaint with your local supervisory authority.
8.2 California Residents (CCPA / CPRA)
California residents have rights including the right to know, delete, correct, opt-out of sale or sharing (which we do not do), limit use of sensitive personal information (not applicable as we do not collect it), and the right to non-discrimination.
8.3 Washington State Residents (WA Privacy Act / My Health MY Data Act)
Washington residents have rights including access, deletion, correction, data portability, and opt-out of targeted advertising (not applicable). We do not collect consumer health data as defined under the My Health MY Data Act.
8.4 Brazil Residents (LGPD)
Brazilian residents have rights including access, deletion, correction, portability, information on sharing, revocation of consent, and the right to lodge a complaint with the ANPD.
8.5 Canadian Residents (PIPEDA / Quebec Law 25)
Canadian residents have rights including access, correction, withdrawal of consent (subject to legal and contractual restrictions), and the right to complain to the OPC or CAI.
8.6 Australian Residents (Australian Privacy Act / APPs)
Australian residents have rights including access, correction, and the right to complain to the OAIC.
8.7 All Other Residents
Regardless of your jurisdiction, we extend the following baseline rights to all website users: the right to request access to the personal information we hold about you, the right to request correction of inaccurate information, and the right to request deletion of your personal information where we have no overriding legal obligation to retain it.
9. How to Exercise Your Rights
To submit a privacy rights request, please contact us by email at nitem18@hotmail.com with the subject line: "Privacy Rights Request." Please include:
- Your full name and email address (so we can locate your information);
- Your country or state of residence;
- A clear description of the right you wish to exercise (e.g., access, deletion, correction);
- Any additional context needed to process your request efficiently.
9.1 Response Timeframes
| Request Type | Standard Response Time | Maximum Extension |
|---|---|---|
| General / GDPR requests | Within 30 days of receipt. | Up to 60 additional days for complex or high-volume requests (we will notify you of the extension). |
| CCPA/CPRA requests | Within 45 days of receipt. | Additional 45 days with prior notice. |
| LGPD (Brazil) requests | Within 15 days of receipt. | As permitted under LGPD. |
9.2 Identity Verification
To protect your privacy and prevent unauthorized access to your information, we may need to verify your identity before processing a request. We will use the information you provided in your request (e.g., email address) to match against our records. We will not request more information than is reasonably necessary to verify your identity.
We will not charge a fee for reasonable requests. If a request is manifestly unfounded or excessive, we reserve the right to charge a reasonable administrative fee or decline to act, in accordance with applicable law.
10. Children's Privacy
Our website and services are not directed at, designed for, or intended to be used by children. Specifically:
- We do not knowingly collect personal information from children under the age of 13 (as defined under the Children's Online Privacy Protection Act, COPPA, USA).
- We do not knowingly collect personal information from children under the age of 16 (as defined under the GDPR and UK GDPR, unless applicable Member State law specifies a lower age of digital consent).
If you believe that we have inadvertently collected personal information from a child without appropriate parental or guardian consent, please contact us immediately at nitem18@hotmail.com. We will take prompt steps to delete that information from our records.
11. Data Security
We take the security of your personal information seriously and implement reasonable and appropriate technical and organizational measures to protect it against unauthorized access, loss, alteration, disclosure, or destruction. These measures include:
- Transmission of data over encrypted connections (HTTPS/TLS);
- Restricted access to personal information on a need-to-know basis;
- Use of reputable, security-conscious hosting and email service providers;
- Regular review of our data collection, storage, and processing practices;
- Secure deletion of data when no longer needed.
Important Notice: No method of data transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee absolute security. By using our website, you acknowledge and accept this inherent risk.
11.1 Data Breach Notification
In the event of a data breach that is likely to result in a risk to your rights and freedoms, we are committed to:
- Notifying the relevant supervisory authority within 72 hours of becoming aware of the breach, where required by law (e.g., under GDPR Article 33);
- Notifying affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms (e.g., under GDPR Article 34);
- Complying with state breach notification laws, including the Washington State Data Breach Notification Law (RCW 19.255.010).
12. Links to Third-Party Websites
Our website may contain links to external websites, resources, or services operated by third parties. These links are provided for your convenience and informational purposes only.
We have no control over the content, privacy practices, or policies of any third-party websites. This Privacy Policy applies solely to our website and does not extend to any external site you may access via links on our pages. We encourage you to review the privacy policy of any third-party website you visit.
We are not responsible for the privacy practices, security, or content of any third-party sites and disclaim all liability arising from your use of such sites.
13. Washington State Specific Disclosures
13.1 Washington My Health MY Data Act
The Washington My Health MY Data Act imposes specific requirements on entities that collect, share, or sell "consumer health data." We do not collect, use, process, or share any consumer health data as defined under this Act. Our website contact form and analytics tools are not designed to, and do not, collect health-related information of any kind.
13.2 Washington Consumer Protection Act (CPA)
We conduct our business in compliance with the Washington Consumer Protection Act, which prohibits unfair or deceptive business practices. Our data practices are transparent, and we do not engage in any deceptive practices regarding the collection or use of personal information. If you believe we have violated any applicable consumer protection law, you have the right to contact the Washington State Attorney General's Office.
15. Changes to This Privacy Policy
We reserve the right to update or modify this Privacy Policy at any time to reflect changes in our practices, legal requirements, or the services we offer. Any changes we make will be effective immediately upon posting the revised policy to this page, unless otherwise stated.
The "Last Updated" date at the top of this document will always reflect the date of the most recent revision. We encourage you to review this policy periodically to stay informed about how we protect your information.
For material changes — particularly those that may affect your rights or how we use your personal information — we will make reasonable efforts to provide more prominent notice, such as a notice on our website homepage prior to the change taking effect.
Your continued use of our website following the posting of changes constitutes your acknowledgment of those changes. If you do not agree to any updated version of this policy, please discontinue use of our website.
16. Contact & Data Controller Information
If you have any questions, concerns, or requests regarding this Privacy Policy or the handling of your personal information, please contact us:
| Contact Detail | Information |
|---|---|
| Business Name | Unbound Root |
| Owners / Privacy Contacts | Nicolas Figueroa Hidalgo |
| Business Address | Port Orchard, Washington, USA |
| Email (Primary Privacy Contact) | nitem18@hotmail.com |
| Website | https://unboundroot.com |
| Subject Line for Privacy Requests | "Privacy Rights Request" or "CCPA Opt-Out Request" as applicable. |
16.1 EU / UK Representative
As a small business primarily operating in the United States, we currently do not have a designated EU or UK Representative as defined under Article 27 GDPR / UK GDPR Article 27. We make this determination based on the limited, incidental, and non-systematic nature of our processing of EU/UK personal data. However, EU/UK individuals may exercise their rights directly by contacting us at nitem18@hotmail.com, and we will respond in accordance with applicable law.
Should the nature or scale of our EU/UK data processing change to the extent that an EU/UK Representative becomes legally required, we will appoint one and update this policy accordingly.
16.2 Complaints and Escalation
We are committed to resolving any privacy complaints promptly and fairly. If you are not satisfied with our response to a privacy inquiry, you have the right to escalate your complaint to the relevant supervisory authority in your jurisdiction (see Section 8 for jurisdiction-specific authority information).