Roon access to personally identifiable core data without user consent

It would also be crucial to know if the pulling implies access through the user’s firewall.

So three questions:

  1. is personal data as defined by the GDPR continually pullable by Roon, and without the customer knowing?
  2. is this in conflict with GDPR requirements?
  3. does the pulling mechanism imply a reduction of the user’s network safety, for instance by bypassing a firewall?

If the answer to either one of these is «yes» I would like to also ask: why do you think this particular solution is worth it?