Legal
Data Processing Addendum
Last updated: August 5, 2026
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between RankControl, LLC, a Delaware limited liability company (“RankControl”, “we”, “us”, the “processor”), and the customer (“Customer”, “you”, the “controller”). It applies where we process personal data on your behalf, principally the personal data of your website's visitors collected through our analytics embeds. By using those features, you accept this DPA. If you require a countersigned copy, use our contact form.
1. Definitions
“Applicable Data Protection Law” means all privacy and data-protection laws applicable to the processing, including the EU General Data Protection Regulation 2016/679 and the UK GDPR (together, “GDPR”), India's Digital Personal Data Protection Act, 2023 (“DPDP Act”), and the California Consumer Privacy Act as amended (“CCPA”). The terms “controller”, “processor”, “data subject”, “personal data”, “processing”, and “personal data breach” have the meanings given in the GDPR; where the DPDP Act applies, “Data Fiduciary”, “Data Processor”, and “Data Principal” are read as controller, processor, and data subject respectively. “Customer Personal Data” means personal data we process on your behalf under the Terms, as described in Annex I.
2. Roles and Scope
For Customer Personal Data, you are the controller and we are the processor. You determine the purposes and means of processing; we process only to provide the service. Where you are yourself a processor acting for a third party, you appoint us as a sub-processor and represent that you have the authority to do so. A description of the processing is set out in Annex I.
3. Our Obligations as Processor
We will:
- process Customer Personal Data only on your documented instructions, including as set out in the Terms and through your configuration and use of the service, unless required by law, in which case we will inform you where legally permitted;
- ensure that persons authorized to process Customer Personal Data are bound by confidentiality;
- implement appropriate technical and organizational measures as described in Annex II and on our Security page;
- engage sub-processors only in accordance with Section 6;
- taking into account the nature of the processing, assist you with appropriate measures to respond to requests from data subjects or Data Principals, as described in Section 5;
- assist you in ensuring compliance with your security, breach-notification, and data-protection impact-assessment obligations, taking into account the information available to us;
- at your choice, delete or return Customer Personal Data at the end of the service, as described in Section 9; and
- make available information necessary to demonstrate compliance with this DPA and allow for audits as described in Section 9.
4. Your Obligations as Controller
You represent and warrant that: (a) you have a lawful basis and any required consents to collect and provide Customer Personal Data and to have us process it; (b) you provide all required notices to your visitors, including your own privacy policy and, where required, a cookie or consent banner covering our embeds; (c) your processing instructions are lawful; and (d) you will not provide us with special-category or sensitive data, or data you are not permitted to process, except as expressly agreed. You are responsible for the accuracy and legality of Customer Personal Data and for your relationship with data subjects as the controller.
5. Data Subject and Data Principal Requests
Where a data subject or Data Principal contacts us directly about Customer Personal Data, we will, unless legally prohibited, promptly forward the request to you and will not respond except on your instructions. Taking into account the nature of the processing, we will provide reasonable assistance (including appropriate technical and organizational measures, insofar as this is possible) to help you fulfill your obligation to respond to requests to exercise rights of access, correction, deletion, portability, objection, restriction, and similar rights.
6. Sub-processors
You provide a general authorization for us to engage sub-processors to process Customer Personal Data. Our current sub-processors are listed at rctrl.com/subprocessors. We impose data-protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain responsible for their performance. We will update the sub-processor list before authorizing a new or replacement sub-processor and, where required by Applicable Data Protection Law, give you a reasonable opportunity to object on reasonable data-protection grounds; if we cannot resolve your objection, you may terminate the affected part of the service.
7. Personal Data Breach
We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide information reasonably available to us to help you meet your own breach-notification obligations. Our notice of, or response to, a breach is not an acknowledgement of fault or liability.
8. International Transfers
You authorize us and our sub-processors to transfer Customer Personal Data internationally, including to and from the United States and India, as necessary to provide the service. Where such transfers are subject to the GDPR, they are made under the European Commission's Standard Contractual Clauses (“SCCs”), which are incorporated into this DPA by reference and completed by Annexes I–III, together with the UK Addendum where applicable, or under another lawful transfer mechanism (including the EU-U.S. Data Privacy Framework and its UK and Swiss extensions, if and when we certify to it). Where the DPDP Act or other Applicable Data Protection Law restricts transfers to particular countries, we will comply with those restrictions.
9. Deletion, Return, and Audit
Deletion and return. On termination of the service, or on your written request, we will delete or return Customer Personal Data and delete existing copies within a reasonable period, unless retention is required by law. Data in routine backups is deleted on our standard backup cycle.
Audit. We will make available information necessary to demonstrate compliance with Article 28 of the GDPR and this DPA, and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate, no more than once per year and on reasonable prior notice, subject to confidentiality. In the first instance, we may satisfy audit requests by providing our security documentation and responding to reasonable questionnaires.
10. India DPDP Act
Where the DPDP Act applies, we act as your Data Processor and process Customer Personal Data only under this contract and your instructions. We will assist you, as Data Fiduciary, in meeting your obligations to Data Principals and in responding to personal data breaches, and we will delete Customer Personal Data on your instruction or when the purpose for which it was processed is no longer being served, unless retention is required by law. Where incident-reporting directions issued under India's Information Technology Act, 2000 (including the CERT-In directions) apply to an incident affecting Customer Personal Data, we will make the required reports within the prescribed timelines and, where legally permitted, keep you informed.
11. California Consumer Privacy Act
To the extent Customer Personal Data includes personal information subject to the CCPA, we act as your “service provider.” We will not: (a) sell or share Customer Personal Data; (b) retain, use, or disclose it for any purpose other than providing the service under the Terms and this DPA, including outside the direct business relationship between you and us; or (c) combine it with personal information we receive from other sources, except as permitted by the CCPA. We certify that we understand and will comply with these restrictions, and we will notify you if we determine we can no longer meet our obligations under the CCPA. You may take reasonable and appropriate steps to ensure we use Customer Personal Data consistently with your obligations, and to stop and remediate unauthorized use.
12. Liability and Order of Precedence
Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms. In the event of a conflict, this DPA prevails over the Terms with respect to the processing of Customer Personal Data, and the SCCs prevail over this DPA where they apply. All other provisions of the Terms remain in full effect.
13. Contact
Questions about this DPA, or requests for a countersigned copy, may be sent through our contact form.
Annex I — Description of the Processing
- Parties: Controller — the Customer; Processor — RankControl, LLC.
- Subject matter: provision of the RankControl content, publishing, and analytics service.
- Duration: the term of the Terms and until deletion or return of Customer Personal Data under Section 9.
- Nature and purpose: collecting and processing visitor data on the Customer's published content in order to measure and attribute traffic and make the results available through the dashboard.
- Types of personal data: contact and identity details submitted in forms (such as name, email, and company); online identifiers (such as IP address and cookie or device identifiers); referral source and query data; and engagement or behavioral metrics (such as pages viewed, time on page, and actions taken).
- Categories of data subjects: visitors to the Customer's websites, and the Customer's own users of the dashboard.
- Frequency: continuous, for the duration of the service.
Annex II — Technical and Organizational Measures
We maintain the measures described on our Security page, including: encryption in transit (TLS) and at rest; role-based access control and least-privilege access; organization-level data isolation; audit logging of administrative actions; secret management via environment variables; automated backups; bot filtering on analytics; and monitoring with documented incident response and breach notification. These measures are reviewed and updated as the service evolves.
Annex III — Sub-processors
The current list of authorized sub-processors is maintained at rctrl.com/subprocessors and forms part of this DPA.