There's a somewhat more secure way to go about it.
A backup script on the host in question runs periodically as root and makes a local copy of the files owned by the backup user. The central host then makes a backup of the not-root-owned files on the host in question. It adds two extra steps but you don't have to set up SSH access for the root account.