Legal
Data processing addendum
Last updated August 11, 2026
This addendum forms part of the agreement between Rankable and a customer where we process personal data on the customer's behalf. A countersigned copy is available on request at legal@rankable.ai.
1. Roles of the parties
The customer is the controller of personal data it submits or that is contained in the reports we produce for it. Rankable is the processor and processes that data only on the customer's documented instructions.
Where Rankable determines the purposes of processing — for example, its own account and billing records — it acts as controller under its privacy policy.
2. Subject matter and scope
Subject matter: provision of AI search visibility audits and related reporting.
Duration: for the term of the customer's subscription, plus the retention period described below.
Categories of data subjects: the customer's personnel who hold accounts, and recipients of report previews who supply an email address.
Types of personal data: names, business email addresses, account identifiers and usage logs. Audit content itself is drawn from publicly accessible sources.
No special categories of personal data are required by, or intended for, the service.
3. Processor obligations
We process personal data only on documented instructions, including for international transfers, unless required otherwise by law.
Personnel authorised to process personal data are bound by confidentiality obligations.
We implement appropriate technical and organisational measures, described on our security page, including encryption in transit and at rest, row-level tenant isolation and least-privilege access.
We assist the customer, taking into account the nature of processing, with data subject requests and with security, breach notification and impact assessment obligations.
4. Sub-processors
The customer grants general authorisation for Rankable to engage sub-processors for hosting and database services, email delivery, payment processing and AI model access.
Each sub-processor is bound by data protection obligations no less protective than those in this addendum. We will give notice of any intended addition or replacement and the customer may object on reasonable data protection grounds.
5. Personal data breach
We notify the customer without undue delay, and in any event within seventy-two hours of becoming aware of a personal data breach affecting the customer's data, with the information reasonably available to us at that time and updates as the investigation progresses.
6. International transfers
Where personal data originating in the EEA, UK or Switzerland is transferred to a country without an adequacy decision, the transfer is governed by the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum where applicable, and supplementary measures as appropriate.
7. Audits
On reasonable written request, and no more than once per year unless required by a supervisory authority, we make available the information necessary to demonstrate compliance with this addendum and cooperate with audits conducted by the customer or an independent auditor bound by confidentiality.
8. Return and deletion
On termination, and at the customer's choice, we delete or return personal data processed on the customer's behalf within thirty days, except where retention is required by law.
Backups containing residual copies are overwritten on their normal rotation schedule and remain protected by the measures in this addendum until then.
9. Contact
Data protection enquiries and signature requests: legal@rankable.ai.