Privacy Policy – RankX

At RankX, we value your privacy and are committed to safeguarding your personal information. This Privacy Policy explains what information we collect, how we use it, and the steps we take to protect it when you access our website or use our services.
Last Updated on 7th July 2026

1. Introduction

RankX (“RankX”, “RankXAI”, “we”, “us”, “our”) is an AI-powered SEO and analytics Software‑as‑a‑Service (SaaS) platform operated by ALIM Ltd, a company registered in England and Wales (Company Number 14528810). Our Services help businesses and agencies analyse search performance, aggregate SEO data, generate content using large language models, and connect with third‑party platforms such as WordPress and other websites.

This Privacy Policy explains how we collect, use, disclose, and protect your personal information when you access or use our website, platform, APIs, WordPress plugins, and related services (collectively, the “Services”). By using our Services, you acknowledge that you have read and understood this Privacy Policy and agree to the collection and use of your information as described here, to the extent permitted by applicable law.

We are committed to complying with applicable data‑protection laws, including the UK General Data Protection Regulation (“UK GDPR”), the Data Protection Act 2018, the EU GDPR where it applies, the UK Data (Use and Access) Act 2025, and the California Consumer Privacy Act (“CCPA”) as amended.

2. Data Controller and Contact Details

For most processing activities described in this Privacy Policy, the data controller is:

ALIM Ltd T/A RankX
Company Number: 14528810
Registered in England and Wales
Website: https://rankxai.com
Email (general contact): [email protected]

If you have any questions, concerns, or requests about this Privacy Policy or our data practices, please contact us at [email protected] and include “Privacy Request” in the subject line so we can route your message appropriately

Depending on how you use RankX, you may also act as a data controller in respect of personal information you upload or manage in your own account (for example, customer or leads data used in SEO projects). In those cases, we act as a data processor and process such data only on your documented instructions, as set out in our Terms of Service and any applicable Data Processing Agreement (“DPA”).

3. Scope of this Privacy Policy

This Privacy Policy applies to personal information we process in connection with:

– Visitors to our website (rankxai.com and associated subdomains).
– Registered users of the RankX platform, APIs, and WordPress plugins.
– Contacts who interact with us via email, support channels, or marketing communications.

This Privacy Policy does not apply to third‑party websites, platforms, or services you may connect to RankX (for example, WordPress hosting providers, search engines, or analytics tools). Their own privacy policies govern their use of your data; we encourage you to review those policies separately

4. Information We Collect

4.1 Information You Provide Directly
We collect information you voluntarily provide when you create an account, configure your workspace, or communicate with us. This typically includes:

– Account and Profile Information: Full name, business or organisation name, job title, email address, login credentials, and optional profile information.
– Business and Billing Information: Company name, billing address, VAT or tax ID (where applicable), subscription plan details, and billing history. Payment card data is processed by our payment processor (such as Stripe) and is not stored in full on RankX servers.
– Workspace and Project Information: SEO projects you create (domains, URLs, keywords, competitor lists), configuration settings, saved dashboards, and notes.
– Support and Communications: Messages you send to us via email, support tickets, or feedback forms; survey responses and product feedback

Authentication credentials and role‑based access control (RBAC) data may be stored in managed databases (for example, Supabase or PostgreSQL instances hosted in EU/UK regions) with encryption at rest and in transit
4.2 SEO and Analytics Data
As an SEO analytics and AI content platform, we process specific types of data on your behalf:

– Search and Performance Metrics: Keywords, rankings, impressions, clicks, positions, and other SEO metrics pulled from integrated data sources (for example, search APIs, Google Search Console, or DataForSEO).
– Site and Content Metadata: Page URLs, titles, meta descriptions, internal linking data, schema markup, and technical SEO signals.
– Generated Content: Drafts, outlines, and articles generated via large language models based on prompts, brand guidelines, and content you provide.

We typically process this information as a data processor on your behalf, meaning you determine what data is collected and how it is used, while we provide the platform and infrastructure
4.3 Integration and Connector Data
When you connect third‑party services to RankX (for example, WordPress via our plugin, other CMSs, search or analytics tools), we collect the minimal credentials, tokens, and configuration data necessary to provide and maintain the integration. This may include:

– OAuth tokens or API keys issued by the third‑party.
– Site identifiers (e.g., domain names, site IDs, property IDs).
– Publish settings and content mapping information (e.g., which posts, pages, or blogs you choose to manage through RankX).

We do not collect, store, or process more data from connected platforms than is required to deliver the integration you configure. For example, our WordPress connector is designed to work primarily with site and content data, not your end‑customers’ payment information or other sensitive personal data that you may process on your own website.
4.4 Automatically Collected Information
When you visit our website or use the platform, we automatically collect certain information to operate and secure the Services

– Usage and Activity Data: Pages visited, features used, actions taken, time spent, error events, and performance metrics.
– Device and Technical Information: IP address, browser type, operating system, device identifiers, referral URLs, and approximate location based on IP.
– Cookies and Similar Technologies: Session cookies to keep you signed in, preference cookies, and analytics cookies to understand how the Services are used.
For more details, see our separate Cookie Policy (or cookie banner) which describes the cookies we use and your choices.
4.5 Information from Third Parties
We may receive limited information from third‑party providers, where allowed by law, such as:

– Authentication providers (e.g., Google) providing your name, email address, and profile picture when you sign in using their services.
– SEO data providers (e.g., DataForSEO or search engines) providing performance metrics and search data about your properties.
– Payment processors (e.g., Stripe) providing billing confirmations, partial card information (last four digits, card type), and payment status.

5. How We Use Your Information

We use the information we collect for the following purposes, in line with UK GDPR requirements to be transparent about the purposes of processing and legal bases.

– Providing and Maintaining the Services: To create and manage your account, host dashboards, process SEO data, generate content, and deliver integrations you configure.
– Improving and Developing Features: To analyse usage patterns, troubleshoot issues, optimise performance, and develop new functionality.
– Billing and Account Management: To process subscriptions, manage invoices, apply usage‑based pricing where applicable, and handle account changes.
– Publishing Content and Managing Integrations: To push content, metadata, or configuration changes to your connected platforms (for example, publishing SEO content to your WordPress site) when you instruct us to do so.
– AI‑Powered Analysis and Content Generation: To send your inputs (keywords, URLs, prompts, brand guidelines) to large language models and AI providers in order to generate recommendations and content on your behalf.
– Security, Fraud Prevention, and Abuse Detection: To monitor usage for suspicious activity, protect accounts, enforce our Terms of Service, and prevent misuse of RankX.
– Communications and Support: To respond to your inquiries, send service‑related notices (such as security alerts or changes to the platform), and provide customer support.
– Marketing (Where Permitted): To send you newsletters, product updates, and promotions related to RankX; you can opt out at any time using the unsubscribe link in those emails.
– Compliance and Legal Obligations: To comply with tax, accounting, and other legal requirements; to cooperate with law‑enforcement requests where legally required; and to manage disputes.

We do not sell your personal information or User Content, including for targeted advertising, and we do not use your content to train third‑party foundation models beyond what is allowed under our agreements with those providers.

6. Legal Bases for Processing (UK, EEA, Switzerland)

Where UK GDPR, EU GDPR, or similar laws apply, we rely on the following legal bases:

– Contract: Processing necessary to perform our contract with you (for example, to provide the platform, maintain your account, and deliver integrations you configure).
– Legitimate Interests: Processing for our legitimate interests in operating, securing, and improving the Services, preventing fraud, and communicating with you about RankX, provided such interests are not overridden by your rights and interests.
– Consent: Processing for optional cookies, certain marketing communications, and any processing where consent is required under applicable law. You may withdraw consent at any time without affecting the lawfulness of prior processing.
– Legal Obligations: Processing necessary to comply with laws, regulations, court orders, or government requests, including tax and accounting obligations

7. Data Sharing and Sub‑processors

We share personal data only when necessary to operate RankX or where required by law. In particular, we may share data with the following categories of recipients:

Sub‑processors and Service Providers:
Trusted third parties that process data on our behalf under written data‑processing agreements, including:
– Cloud hosting and infrastructure providers (e.g., Google Cloud) for compute, storage, and logging.
– Database and authentication providers (e.g., Supabase, managed PostgreSQL) for secure data storage and user authentication.
– Payment processors and billing platforms (e.g., Stripe, subscription management tools) for payments and invoicing.
– Analytics and observability tools for product and performance monitoring.
– AI and LLM providers (e.g., large‑language‑model APIs) for content generation and SEO analysis.

Legal and Regulatory Authorities:
Where we are required to disclose information by law, subpoena, court order, or other legal process, or where disclosure is necessary to protect our rights, safety, or property or that of our users or the public.

Business Transfers:
If RankX or ALIM Ltd is involved in a merger, acquisition, financing, or sale of assets, personal data may be transferred as part of that transaction, subject to appropriate safeguards and notice.

We maintain an internal record of our sub‑processors and review them regularly. You may contact us at [email protected] if you need more information about specific sub‑processors or a copy of our DPA

8. AI and Automated Decision‑Making

RankX uses large language models and AI technologies to provide SEO recommendations, generate content, and perform certain analyses.

Inputs you provide (such as keywords, URLs, prompts, and brand voice examples) may be sent to our AI providers for inference and returned to you as generated outputs; we instruct these providers not to use your inputs or outputs to train their foundation models except to the extent strictly necessary to provide and maintain the service, as permitted by our contracts.

RankX does not make solely automated decisions that produce legal or similarly significant effects about individuals under UK GDPR Article 22 (for example, credit decisions or employment screening), and our AI outputs are designed to support your human decision‑making rather than replace it

9. Cookies and Tracking Technologies

We use cookies and similar technologies to:

– Keep you signed in and maintain session state.
– Remember your preferences (such as language or UI settings).
– Analyse how the Services are used so we can improve performance and usability.

You can control cookies through your browser settings and our cookie banner, but disabling certain cookies may affect your ability to use parts of the Services. For detailed information, including categories of cookies and retention periods, please refer to our Cookie Policy available via our website or cookie banner.

10. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes described in this Privacy Policy, unless a longer period is required or permitted by law. In general:

– Account and Profile Data: Retained for the life of your account. If you close your account, we will delete or anonymise personal data within a reasonable period (typically 30–60 days), except where retention is required for legal, tax, accounting, or fraud‑prevention purposes.
– Project and SEO Data: Retained for the life of your account or until you delete it via the dashboard. Deleted data may persist in encrypted backups for a limited period before being overwritten in the normal backup cycle.
– Integration Tokens and Credentials: Retained while the integration remains active and deleted promptly when you disconnect the integration or uninstall a connector/plugin.
– Logs and Analytics: Usage logs and diagnostic data may be retained in identifiable form for a short period (for example, up to 90 days) and thereafter in aggregated or anonymised form.
– Billing and Transaction Records: Retained for the period required by applicable tax and accounting laws (often up to 7 years)

11. International Data Transfers

RankX operates globally and may transfer personal data to countries outside the UK and the European Economic Area (“EEA”), including to cloud infrastructure, sub‑processors, and AI providers located in other jurisdictions.

Where such transfers constitute “restricted transfers” under UK GDPR, we implement appropriate safeguards, which may include:

– Relying on UK adequacy regulations for countries recognised as providing an adequate level of protection.
– Using the UK International Data Transfer Agreement (“IDTA”) or the UK Addendum to the EU Standard Contractual Clauses for international transfers, as published and approved by the ICO
– Conducting transfer risk assessments and, where necessary, implementing additional technical and organisational measures such as encryption and access controls.

We will update our transfer mechanisms as required by changes in law, regulatory guidance, or our sub‑processor arrangements

12. Data Security

We implement appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access, disclosure, alteration, and destruction. Such measures may include:

– Encryption of data in transit (TLS) and at rest.
– Network and infrastructure security controls, including firewalls and private networking.
– Role‑based access controls (RBAC) and tenant‑level isolation within our databases.
– Audit logging of security‑relevant events and administrative actions.
– Regular reviews of our security practices and supplier security posture.

While we strive to protect your information, no method of transmission or storage is completely secure. If we become aware of a security incident affecting personal data, we will notify affected users and, where required, relevant authorities in accordance with applicable law.

13. Your Rights

Depending on where you live and the laws that apply to you, you may have some or all of the following rights in relation to your personal data:

– Right of Access: To request a copy of the personal data we hold about you.
– Right to Rectification: To request correction of inaccurate or incomplete data.
– Right to Erasure: To request deletion of your personal data, subject to legal retention obligations.
– Right to Restriction: To ask us to limit the processing of your data in certain circumstances.
– Right to Data Portability: To receive your data in a structured, commonly used, machine‑readable format and to transmit it to another controller.
– Right to Object: To object to processing based on our legitimate interests, including profiling and direct marketing.
– Right to Withdraw Consent: Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.ico+1
– Right to Lodge a Complaint: To lodge a complaint with your local supervisory authority (for UK residents, the Information Commissioner’s Office (ICO)).

You can exercise many of these rights directly via the RankX dashboard (for example, updating your profile, managing integrations, and deleting projects). For other requests, please contact us at [email protected]; we will respond within the timeframes required by applicable law, typically within one month

14. Additional Rights for California Residents

If you are a California resident, you may have additional rights under the CCPA and related legislation, including the right to know what categories of personal information we collect and the right to opt out of certain data sharing. RankX does not sell personal information as defined by the CCPA.

You can contact us using the details above if you wish to exercise your CCPA rights; we may need to verify your identity before acting on your request, in line with CCPA requirements.

15. Children’s Privacy

RankX is intended for use by professionals and businesses and is not directed to children under 16. We do not knowingly collect personal information from children. If you believe that a child has provided us with personal information, please contact us at [email protected] and we will take appropriate steps to delete such information

16. Customer Responsibilities (Controllers Using RankX)

When you use RankX to process personal data about your own customers, leads, or website visitors, you are responsible for:

– Providing appropriate privacy notices to your data subjects explaining how you use RankX and other tools.
– Ensuring that you have a lawful basis for processing their data and for any international transfers you undertake.
– Configuring RankX and any integrations in a secure manner, including user‑access controls and retention settings.
– Responding to data‑subject requests relating to your own customer data; we will assist you by providing exports or deleting data within the RankX platform upon your verified request.

We recommend that you maintain your own privacy policy and cookies notice for your website and channels, and reference RankX where appropriate.

17. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, Services, or applicable law. When we make material changes, we will notify you through appropriate channels, which may include:

– Email notices to registered account holders.
– In‑app notifications within the RankX dashboard.
– Updated “Last updated” date at the top of this page.

Your continued use of the Services after the effective date of a revised Privacy Policy constitutes acceptance of the updated policy. If you do not agree with any changes, you should discontinue use of the Services and may request closure of your account.

18. Governing Law and Jurisdiction

This Privacy Policy and any disputes arising from it are governed by and construed in accordance with the laws of England and Wales, without regard to conflict‑of‑law principles. Any disputes will be subject to the exclusive jurisdiction of the courts of England and Wales, although you may also have the right to bring proceedings in the courts of your country of residence where applicable law permits

Residents of the UK may lodge complaints with the Information Commissioner’s Office (ICO), and residents of the EEA may lodge complaints with their local data‑protection authority.
Stay Ahead of Search and AI
Get practical SEO, GEO and AI visibility insights, product updates and growth strategies delivered to your inbox.