Prospect Privacy Notice
Article 14 notice for individuals researched via Rōmy
This notice is for individuals whose personal data has been processed by Rōmy at the request of a nonprofit organisation that uses our Service ("Prospects"). It is published in accordance with Article 14 of the EU/UK General Data Protection Regulation (GDPR) and equivalent transparency obligations.
If you are a customer of Rōmy, see our main Privacy Policy instead.
Plain-English summary
A nonprofit organisation uses Rōmy, a research tool, to help identify and understand potential donors. Rōmy researches publicly available information — news, regulatory filings, professional directories, public donation records — to give the nonprofit a profile of you that helps them decide whether to reach out about supporting their cause.
Rōmy itself is not contacting you. The nonprofit decided to research you. We process the data on their behalf as a "data processor."
You have rights over this data, including the right to access it and the right to ask for it to be deleted. See §6 below.
1. Who is responsible for the data
For data uploaded to Rōmy by a nonprofit (e.g., your name and address from their donor database), the nonprofit is the data controller and Rōmy is a processor. Your first point of contact is the nonprofit.
For data Rōmy retrieves from public sources to build a profile, Rōmy and the nonprofit are joint controllers to the extent of the retrieval and aggregation; the nonprofit is sole controller of any decisions to act on the profile.
Rōmy contact:
- Company: GetRomy LLC, a Texas limited liability company based in Kerrville, Texas
- General / privacy: howard@getromy.app (Howard, CEO)
- Technical / security: solomon@getromy.app (Solomon, VP of Product)
If you do not know which nonprofit holds your data in Rōmy, email us and we will help connect you to them.
2. What categories of data we process
Depending on what the nonprofit uploaded and what is publicly available about you, we may process:
- Identity: name, prefix, suffix
- Contact: postal address, email, phone (if uploaded by the nonprofit)
- Professional: employer, job title, professional affiliations
- Public profile: information from news articles, professional directories (e.g. LinkedIn-style public bios), industry publications, regulatory filings, official records
- Philanthropic indicators: publicly disclosed donations, board memberships, foundation roles, public giving history
- Wealth indicators (inferred): estimated giving capacity based on publicly available signals (e.g. publicly disclosed property records, where retrieved); always inferred, never financial-account data
- Custom notes: notes the nonprofit added about you
We do not intentionally process special-category personal data (Art. 9 GDPR) such as health, race, sexual orientation, religious belief, or political opinion. If such data appears incidentally in a public source, we treat it as personal data and apply the same safeguards. Contact us to have it removed.
3. Where we got the data
We process two kinds of data:
- Provided by the nonprofit: typically from their donor list, CRM export, event attendee list, or similar.
- Retrieved from public sources by us at the nonprofit's request — this includes news websites, professional directory pages, regulatory filings, official government records, and other openly available content reachable via standard web search.
We do not buy data from data brokers and do not scrape behind login walls.
4. Why we process it (lawful basis)
Our lawful basis under GDPR Art. 6(1)(f) is legitimate interests — specifically, the legitimate interests of the nonprofit in identifying potential donors to support its mission, and our legitimate interest in providing this Service.
We have completed a Legitimate Interest Assessment (LIA) balancing this interest against your rights. The assessment is on file and available to supervisory authorities on request. Key conclusions:
- The processing relates only to data already in the public domain or shared by you with the controller.
- The volume of data is the minimum necessary to assess donor potential.
- We retain it only for as long as needed (see §5).
- You have a clear, easy way to object (see §6) and we will honour the objection unless we have an overriding compelling justification — which is unlikely.
5. How long we keep it
- Prospect profiles in active customer accounts: kept until the nonprofit deletes the batch or their account.
- When a nonprofit deletes their account: all related Prospect data is erased immediately as part of the deletion operation.
- After you successfully request erasure: within 30 days, and across every customer account that holds your data. We retain a minimal "do-not-research" record (email or other identifier provided + erasure timestamp) so we don't re-research you accidentally; you can ask us to delete that too.
- Backups: copies of deleted Prospect data may persist briefly in routine database backups until they are rotated out, after which the data is irrecoverable.
6. Your rights
You have the following rights, regardless of where you live:
- Right to access — get a copy of the data we hold about you
- Right to erasure ("right to be forgotten") — have it deleted
- Right to rectification — correct inaccurate data
- Right to object — to processing based on legitimate interests (Art. 21). We honour objections by default.
- Right to restrict processing
- Right to data portability
- Right to lodge a complaint with your local supervisory authority (EU/UK) without contacting us first
To exercise any right: email howard@getromy.app or use the form at /privacy/request.
We respond within 30 days. We may need to verify your identity (e.g. confirm an email address) before acting on a request. There is no fee.
If your data is held by a specific nonprofit using our Service, we will also coordinate with that nonprofit to honour your request across their account.
7. Automated decision-making
Rōmy may produce inferred scores (e.g. estimated giving capacity, "RōmyScore"). These are decision-support outputs for the nonprofit, not automated decisions with legal or similarly significant effect on you under Art. 22 GDPR. The nonprofit decides whether and how to reach out; Rōmy never contacts you on its own initiative.
If you believe a Rōmy-generated profile or score has caused you harm, contact howard@getromy.app and we will investigate.
8. International transfers
Our processing happens in the United States. Where required, we rely on Standard Contractual Clauses with our sub-processors. See /subprocessors for the full list.
9. Security
We protect Prospect data with the same controls we apply to all personal data: encryption in transit and at rest, access controls, and audit logging. See our Security Overview for details.
10. Changes to this notice
We post material changes here with a new effective date.
11. Contact
- General / privacy / fastest route: howard@getromy.app (Howard, CEO)
- Technical / security: solomon@getromy.app (Solomon, VP of Product)
You can also contact your local data protection authority (in the EU/UK) or the US FTC.
This document is the canonical Article 14 notice published at intel.getromy.app/privacy/prospects.