Last updated: 24 August 2026
Your data is controlled by RootCore, LLC and is used to deliver what you ordered: forming a US company, applying for an EIN and opening a bank account all require your name, address and identity document, because the authorities and the partner bank demand them. We never see or store card details — Stripe handles payment. Analytics and advertising cookies are only set after you agree. You can ask us to delete your data at any time at [email protected].
Controller: RootCore, LLC (registered address 1111B S Governors Ave STE 59361, Dover, DE 19904, United States), contact [email protected]. Day-to-day operations and data handling take place in Hungary (European Union); the server is in the European Union.
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Name, email address, phone number | contact, quotes, order confirmation | performance of a contract (GDPR Art. 6(1)(b)) | 5 years after the engagement closes |
| Billing name and address, company details | invoicing, delivering the service | legal obligation (Art. 6(1)(c)) | 8 years (accounting rules) |
| Passport or identity document details, home address | company registration, EIN application, bank account opening — required by the authority and the bank | performance of a contract (Art. 6(1)(b)) | 5 years after the engagement closes |
| Account data (email, password hash) | sign-in, order tracking | performance of a contract (Art. 6(1)(b)) | until the account is deleted |
| Analytics and advertising cookies | measuring site usage and campaign results | consent (Art. 6(1)(a)) | up to 24 months, until withdrawn |
| Server logs (IP address, timestamp, requested page) | operations, detecting abuse and attacks | legitimate interest (Art. 6(1)(f)) | 30 days |
Only those without whom the service cannot be delivered:
We do not sell your data and do not pass it to third parties for advertising.
The website and email servers are in the European Union. By the nature of the service, however, the data needed to form a US company does travel to the United States: to the state company registry, to the IRS and to the partner bank. That transfer is necessary to perform the contract (GDPR Art. 49(1)(b)). For Stripe, Google and Meta the transfer relies on the European Commission's adequacy decision (EU–US Data Privacy Framework) or on standard contractual clauses.
Payments are processed by Stripe, Inc. We never see and never store your card details; Stripe's own privacy policy governs that data.
Storage strictly needed for the site to work — your language choice, your sign-in session and your cookie decision — is used without consent, because the site would be unusable otherwise.
Beyond that we use Google Analytics and the Meta Pixel. These are off by default: they start in a denied state when the page loads and only begin collecting data if you accept on the bar at the bottom. If you decline, neither runs. Your choice is stored in your browser and you can change it at any time by clearing the site's stored data.
All traffic is encrypted with TLS. Documents are stored with access restricted to the people working on your engagement.
Write to [email protected]; we reply within 30 days.
If you believe the processing is unlawful, you may complain to your national data protection authority. In Hungary this is the National Authority for Data Protection and Freedom of Information (1055 Budapest, Falk Miksa utca 9-11., naih.hu).