Skip to content
RankX AI

Legal and compliance

Data Processing Agreement

How RankX AI processes personal data on your behalf under Article 28 of the UK and EU GDPR. It applies to every customer automatically, with no signature needed.

Last updated
Applies to
All RankX AI services

How this agreement applies, and why you do not need to sign it

This Data Processing Agreement (the DPA) is incorporated into the Terms of Service between you (the Customer) and ALIM LTD, trading as RankX AI (we, us, the Processor). It takes effect on the date you accept the Terms and continues for as long as we process personal data on your behalf.

No signature required

This DPA is in force for every customer automatically. You do not need to request it, sign it or return it. It is published so that your own compliance records can point at a stable URL, and so that an agency can show it to a client without waiting for us.

If your organisation requires a signed counterpart or a negotiated variation, email [email protected]. Until a variation is agreed in writing, these terms apply.

It applies only to processing where you are the controller. Where we process personal data as controller for our own purposes, such as your account and billing records and our security logging, this DPA does not apply and the Privacy Policy governs instead. Section 2 of that policy explains the boundary.

Order of precedence. On any question about personal data processed on your behalf, this DPA prevails over the Terms of Service and over any conflicting term in an order form, except where an order form expressly amends this DPA and is signed by both parties.

Definitions

Data Protection Law
The UK GDPR and the Data Protection Act 2018; Regulation (EU) 2016/679 (the EU GDPR) and the national laws implementing it; the Privacy and Electronic Communications Regulations 2003; and any other data protection or privacy law applicable to a party in respect of the processing, each as amended or replaced.
Controller, processor, sub-processor, data subject, personal data, personal data breach, processing, supervisory authority
Have the meanings given in the UK GDPR, and their equivalents under other applicable Data Protection Law.
Customer Personal Data
Personal data contained in Customer Data that we process on your behalf in providing the platform, as described in Annex A.
EU SCCs
The standard contractual clauses annexed to European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
UK Addendum
The International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the Information Commissioner under section 119A of the Data Protection Act 2018, as in force from time to time.
UK IDTA
The International Data Transfer Agreement issued by the Information Commissioner under the same section, as in force from time to time.
Restricted Transfer
A transfer of Customer Personal Data to a country or organisation outside the UK or the EEA that requires an appropriate safeguard under Chapter V of the UK GDPR or the EU GDPR.

Terms defined in the Terms of Service and used but not defined here have the meaning given there.

The roles of the parties

For Customer Personal Data, you are the controller and we are your processor. Where you are yourself acting as a processor for another controller, for example an agency processing on behalf of a client, we are a sub-processor and you confirm that you have that controller’s authority to appoint us and to agree these terms on its behalf. Every reference in this DPA to your obligations as controller applies to you in that capacity too.

Each party will comply with the obligations that apply to it under Data Protection Law in respect of the processing. Neither party is a joint controller with the other in respect of Customer Personal Data.

Processing only on your instructions

We will process Customer Personal Data only on your documented instructions, including in relation to transfers, unless we are required to process it by law that applies to us. Where a law requires it, we will tell you before processing unless that law forbids us from telling you on important grounds of public interest.

Your documented instructions consist of:

  • this DPA and the Terms of Service;
  • your use of the platform’s features and settings, which is itself an instruction to process as those features are documented;
  • instructions you give through the platform, the API or the Model Context Protocol server;
  • any further written instruction we agree to in writing.

We will tell you if, in our opinion, an instruction infringes Data Protection Law, and may suspend processing under that instruction until it is withdrawn or amended. We may charge for work needed to comply with an instruction that goes beyond ordinary use of the platform, having told you the cost first.

We do not use Customer Personal Data to train generalised artificial intelligence or machine learning models, we do not sell it, and we do not use it for our own purposes. We may produce aggregated and anonymised statistics from platform usage that cannot identify you, your clients or any individual, and use them to operate, secure and improve the service. Once anonymised that information is no longer personal data.

Confidentiality of personnel

We ensure that every person we authorise to process Customer Personal Data is bound by a written duty of confidentiality or is under an appropriate statutory obligation of confidentiality, and that the duty survives the end of their engagement with us.

Access is granted on a least privilege basis: only to those who need it to perform the service, to support you or to keep the platform secure, and only for as long as they need it. Access to production data is logged and reviewed. We provide data protection and security awareness training to personnel with access.

Security of processing

We implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking account of the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as required by Article 32. The measures in force are set out in Annex B.

We may update those measures as technology and threats change, provided that we do not materially reduce the overall level of security. Annex B is maintained on this page, so the current measures are always the published ones.

Your side of it. Security is shared. You are responsible for configuring the platform appropriately, for controlling who you invite and what access they hold, for removing users promptly, for protecting API keys and integration credentials, and for deciding what personal data you put into the platform in the first place. The single most effective control available to you is not putting personal data into a free-text field that does not need it.

Sub-processors

You give us general written authorisation to engage sub-processors to process Customer Personal Data, subject to this section. The current list, with each sub-processor’s purpose and location, is published and maintained at rankxai.com/sub-processors and forms Annex C to this DPA.

Where we engage a sub-processor, we will:

  • carry out due diligence on its ability to provide the level of protection required;
  • impose on it, by written contract, data protection obligations that are no less protective than those in this DPA;
  • put appropriate transfer safeguards in place where its involvement causes a Restricted Transfer; and
  • remain fully liable to you for its acts and omissions as if they were our own.

Notice and objection

We will give at least 30 days’ notice before a new sub-processor starts processing Customer Personal Data, by email to your account address if you have subscribed to sub-processor notifications, and in every case by updating the sub-processor page and its change log.

You may object on reasonable data protection grounds within those 30 days by emailing [email protected]. We will work with you in good faith to find an alternative, such as making the affected feature avoidable. If no reasonable solution is available within a further 30 days, you may terminate the affected part of the service, or the whole subscription if the sub-processor is essential to it, and receive a pro rata refund of fees paid for the unused remainder of your term.

We may appoint a replacement sub-processor immediately and without the notice period where the change is urgent and necessary to keep the service running or secure, in which case we will tell you as soon as we can afterwards.

Assisting you with data subject requests

Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures, insofar as this is possible, in fulfilling your obligation to respond to requests to exercise data subject rights under Chapter III of the UK GDPR and the EU GDPR.

Most of that assistance is built into the platform: you can access, export, correct and delete data in your workspaces yourself, without asking us, which is faster than any support process. Where a request cannot be answered from the platform, we will provide reasonable assistance, and we may charge for assistance that goes materially beyond ordinary support, having told you the cost first.

If a data subject contacts us directly about data in your workspace, we will not respond to the substance of the request. We will tell them to contact you, and we will notify you promptly unless we are prohibited from doing so. That is the correct handling for a processor and it protects your position as controller.

Personal data breaches

We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and in any event within 48 hours of becoming aware of it, so that you have time to meet your own 72-hour obligation to your supervisory authority.

The notification will describe, to the extent known at the time and supplemented as we learn more:

  • the nature of the breach, including where possible the categories and approximate number of data subjects and records concerned;
  • a contact point for further information;
  • the likely consequences of the breach; and
  • the measures taken or proposed to address it and to mitigate its effects.

We will take reasonable steps to contain and remediate the breach, preserve evidence, and cooperate with you in investigating it. We will not make a public statement identifying you in connection with a breach without consulting you first, unless we are legally required to.

Notifying regulators and data subjects is your decision, not ours, because you are the controller. We will give you the information you need to make it. Report a suspected breach or a security issue to [email protected].

Impact assessments and prior consultation

Taking into account the nature of the processing and the information available to us, we will provide reasonable assistance with your obligations under Articles 32 to 36: security of processing, breach notification to the supervisory authority and to data subjects, data protection impact assessments, and prior consultation with a supervisory authority.

In practice that means supplying the information you need about how the platform processes data, which is largely what this DPA, its annexes and the Privacy Policy already contain. Where you need more, ask at [email protected].

Information and audits

We will make available to you all information necessary to demonstrate compliance with the obligations in Article 28 and this DPA, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate.

To keep that workable for a business of our size without weakening your right:

  • we will first provide our published documentation, this DPA and its annexes, and answers to a reasonable security questionnaire;
  • if that does not satisfy your obligations, you may audit us on 30 days’ written notice, no more than once in any twelve months, except after a personal data breach affecting your data or where a supervisory authority requires it, when you may audit as often as is necessary;
  • audits take place during business hours, cause the minimum disruption reasonably possible, and are subject to confidentiality;
  • an auditor you mandate must not be a competitor of ours, and must sign a confidentiality undertaking;
  • you bear the cost of an audit unless it reveals a material breach of this DPA, in which case we bear our own costs and reasonably contribute to yours;
  • nothing in an audit gives access to another customer’s data, to our sub-processors’ premises, or to information whose disclosure would compromise the security of the platform.

Return and deletion at the end of the service

At the end of the provision of services, we will, at your choice, delete or return all Customer Personal Data and delete existing copies, unless UK or EU law requires us to keep it.

The mechanics, which match section 17 of the Terms:

  • You have 30 days from termination to export your data from the platform, which is the return option and is available to you directly.
  • After that window we delete within 90 days from live systems.
  • Encrypted backups are purged on their normal cycle, within 35 days of the live deletion. Until then the data remains only in those backups, is not accessible for any operational purpose, and stays protected by this DPA.
  • You can ask for immediate deletion at any time by emailing [email protected], and we will confirm in writing when it is done.
  • We retain records we are legally required to keep, principally invoices and financial records for seven years. Those are our own controller records and contain no Customer Personal Data beyond the billing contact.

International transfers

The platform is hosted in the European Union, with application servers in Belgium and primary databases in Ireland. Some sub-processors are established outside the UK and the EEA, principally in the United States, and their involvement causes a Restricted Transfer.

You instruct us to make those transfers. For each one we rely, in this order of preference, on:

  1. an adequacy regulation or adequacy decision covering the recipient, including the EU-US Data Privacy Framework and its UK extension where the recipient is certified under it;
  2. the EU SCCs, with the UK Addendum where UK GDPR applies, as set out in Annex D; or
  3. the UK IDTA, where it is the more appropriate instrument.

We carry out a transfer risk assessment for each Restricted Transfer and apply supplementary measures, principally encryption in transit and at rest, minimising the data transferred, and contractual commitments on government access requests. Copies of the safeguards relied on for a given sub-processor are available on request at [email protected].

If a safeguard we rely on is invalidated or ceases to provide an adequate level of protection, we will notify you and work in good faith to put an alternative in place without undue delay.

Your obligations and warranties as controller

You warrant and undertake that:

  • you have a lawful basis for every purpose for which Customer Personal Data is processed through the platform, and where consent is the basis, that you have obtained and recorded it properly;
  • you have given the individuals concerned the information required by Articles 13 and 14, including that a processor of our description is involved;
  • your instructions to us, including your use of the platform’s features, comply with Data Protection Law;
  • you are authorised to connect every website, Google property and WordPress installation you connect, and to submit every audit target you submit;
  • you will not put special category personal data or criminal offence data into the platform;
  • where you act as a processor for another controller, you have that controller’s authority to appoint us and to agree these terms.

You will indemnify us against losses arising from a breach of these warranties, subject to the limits in section 15 of the Terms of Service.

Annex A: details of the processing

This annex is the description required by Article 28(3) and, for a Restricted Transfer, corresponds to Annex I.B of the EU SCCs.

Details of the processing carried out by RankX AI on behalf of the customer
ItemDetail
Subject matterProvision of the RankX AI search and AI-answer visibility platform under the Terms of Service.
DurationThe term of the Terms of Service, plus the deletion periods in section 12 of this DPA.
Nature of the processingCollection, retrieval, storage, structuring, organisation, analysis, generation of derived content, display, transfer to sub-processors, erasure and destruction, all by automated means.
PurposeTracking brand visibility in AI assistant answers and search results; auditing websites; researching keywords and competitors; generating and publishing content; reporting to you and to your clients; and supporting you in your use of the platform.
Categories of data subjectYour personnel and other users you invite; your clients’ personnel where you operate an agency account; authors, staff and contacts named in website content we crawl or read through a connected system; users listed in a connected WordPress installation; customers appearing in WooCommerce order data where you grant the commerce scope; and any individual whose personal data you choose to enter into a project, prompt or brief.
Types of personal dataNames, business contact details, job titles, usernames and user identifiers, profile and biography text, authorship attributions, website and social profile URLs, content authored by an identifiable person, order and customer records from a connected commerce system, and IP addresses where they appear in data you supply. Google Analytics data reaches us aggregated by Google and contains no user-level identifiers.
Special category dataNone. The platform has no feature that requests it and you undertake not to submit it.
Frequency of transferContinuous, on a scheduled and on-demand basis for as long as the service is provided.
Competent supervisory authorityThe Information Commissioner’s Office of the United Kingdom, as we are established in England and Wales. Where the EU GDPR applies to your processing, your own lead supervisory authority remains competent in respect of you.

Annex B: technical and organisational measures

These are the measures in force, and they correspond to Annex II of the EU SCCs. Every one describes something the platform does today.

Encryption and key handling

  • TLS on every connection, internal and external.
  • Encryption at rest for every database, object store and backup.
  • Integration credentials (Google OAuth refresh tokens, WordPress application passwords, customer SMTP credentials) encrypted with AES-256-GCM under a separate key before they are written, never returned to a browser and never written to a log.
  • Secrets held in a managed secret store, never in source control and never passed as build arguments.

Access control and tenant isolation

  • Row level security enforced by the database, so one customer’s rows are unreachable from another customer’s session regardless of application code.
  • Credential storage isolated in tables reachable only by a privileged server role, with row level security enabled and no policies granting the ordinary application roles any path to them.
  • The marketing subscriber store separated from the content store by schema, database role and connection string, so a compromise of one cannot read the other.
  • Role-based access within a customer account, controlled by the customer, including separate client workspaces on the agency track.
  • Least privilege staff access, reviewed periodically, with administrative actions logged.

Authentication

  • Sign-in by one-time code sent to a verified email address. No passwords are stored, so there is no password database to breach and no credential stuffing surface.
  • Server-side OAuth for every integration, with tokens never exposed to the browser.
  • Session tokens scoped, expiring and refreshed.

Network and application security

  • A web application firewall, bot protection and rate limiting in front of every public endpoint.
  • A restricted origin, so the application cannot be reached except through the protected edge.
  • A content security policy restricting script origins to our own, our bot-protection provider and our tag manager.
  • Server-side request forgery protection on every feature that fetches a customer-supplied URL.
  • Input validation on every API boundary, and output escaping on every rendered surface.

Resilience and recovery

  • Managed, regionally redundant hosting with automated failover.
  • Automated encrypted backups with point-in-time recovery, retained for up to 35 days and restore-tested.
  • Infrastructure defined in code and deployed through a reviewed pipeline, so a recovery is a redeploy rather than a manual rebuild.

Governance and change control

  • Every production change goes through version control, automated type checking, linting, tests and an automated deployment pipeline.
  • Dependency and vulnerability monitoring, with security patches prioritised.
  • Structured application logging and audit trails for security-relevant events, including every write the platform makes to a connected system.
  • A documented incident response process, with the notification commitments in section 9.
  • Written confidentiality obligations for all personnel with access, and data protection training.
  • Data minimisation by design: aggregated Google Analytics rather than user-level data, hashed IP addresses for rate limiting rather than stored addresses, and no personal data in the free-tool cache.

What we do not claim. We hold no ISO 27001 certification and no SOC 2 report at this time. Several of our sub-processors do, and their certifications are noted on the sub-processor page, but that is their assurance and not ours. We would rather say so than imply a certification we do not have.

Annex C: authorised sub-processors

The list of authorised sub-processors, with the purpose, location and transfer mechanism for each, is published and maintained at rankxai.com/sub-processors. That page is Annex C to this DPA and corresponds to Annex III of the EU SCCs.

It is published rather than reproduced here so that the list and this agreement cannot fall out of step. The notice period and your right to object are in section 7.

Annex D: transfer clauses and how they are completed

Where a Restricted Transfer is made and no adequacy decision covers it, the following applies and is incorporated into this DPA by reference.

EU Standard Contractual Clauses

The EU SCCs apply and are completed as follows, for transfers subject to the EU GDPR:

  • Module. Module Two (controller to processor) where you are a controller. Module Three (processor to sub-processor) where you are yourself a processor.
  • Clause 7 (docking clause). Applies.
  • Clause 9 (sub-processors). Option 2, general written authorisation, with the 30-day notice period in section 7.
  • Clause 11 (redress). The optional independent dispute resolution provision does not apply.
  • Clause 17 (governing law). The law of Ireland.
  • Clause 18 (forum). The courts of Ireland.
  • Annexes. Annex I.A is completed by the parties’ details in the Terms of Service and section 19 below; Annex I.B by Annex A; Annex I.C by the supervisory authority named in Annex A; Annex II by Annex B; and Annex III by Annex C.

The UK Addendum

For transfers subject to the UK GDPR, the UK Addendum applies to the EU SCCs above and is completed as follows:

  • Table 1, parties. The exporter is the Customer as identified in its account; the importer is ALIM LTD, trading as RankX AI, with the contact details in section 19.
  • Table 2, selected SCCs. The EU SCCs as completed directly above, including their appendix information.
  • Table 3, appendix information. Annex 1A the parties, Annex 1B Annex A, Annex II Annex B, Annex III Annex C.
  • Table 4, ending the Addendum. Neither party may end the Addendum when the Approved Addendum changes.

The UK IDTA may be used instead of the Addendum where that is the more appropriate instrument for a particular transfer, completed with the equivalent information.

The Information Commissioner updated its international transfer guidance on 15 January 2026 following the Data (Use and Access) Act 2025, and has indicated that the IDTA and the Addendum will themselves be revised during 2026. This annex incorporates the versions in force from time to time, so it does not fall out of date when they are reissued.

Precedence. If there is any conflict between this DPA and the EU SCCs or the UK Addendum, the transfer clauses prevail in respect of the Restricted Transfer they govern.

Liability, changes, and how to contact us about this DPA

Liability. Each party’s liability under this DPA is subject to the exclusions and limits in section 15 of the Terms of Service, except where Data Protection Law prevents that limit from applying, and nothing here limits either party’s liability directly to a data subject or to a supervisory authority.

Changes. We may update this DPA to reflect changes in law, in guidance from a supervisory authority, or in how the platform works. Material changes are notified as set out in section 18 of the Terms of Service. We will not make a change that materially reduces the protections in it without giving you the right to terminate.

Governing law. This DPA is governed by the law of England and Wales, except where the EU SCCs or the UK Addendum specify otherwise for the transfer they govern.

Data protection contact
[email protected]
Processor
ALIM LTD, trading as RankX AI, company number 14528810, registered in England and Wales
Registered office
[TODO: registered office address]

Back to contents

Start here

See where you show up in AI answers today.

Add your site and RankX AI suggests the prompts to track, monitors the keywords that matter and audits your pages, with your first results minutes after you finish setup.

Start Free Trial

7-day free trial. No credit card required. Cancel anytime.