Data Processing Addendum
The terms on which we process your website visitors' personal data on your behalf.
Last updated: 2 August 2026 · Version 1.0
1. Parties, and which way round we are
This addendum forms part of the Terms of Service between you (the customer) and Ranksify Ltd — currently being incorporated, and until then its founder trading as Ranksify — of 71-75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ.
For personal data about your own website visitors, collected through the Ranksify beacon or through log lines you send us, you are the controller and we are the processor.
For your account data — your name, email, billing status and the brands you set up — we are the controller in our own right, and our privacy policy governs it. This addendum does not apply to that.
Where this addendum and the Terms of Service conflict on the processing of your visitors' personal data, this addendum wins.
2. Subject matter, duration, nature and purpose
Subject matter and purpose: measuring which of your website's visits arrive from AI assistants, and reporting that back to you.
Nature of the processing: collection, storage, aggregation and display within your workspace. We do not enrich, sell, share or profile the data, and we do not combine it with any other customer's.
Duration: for as long as your account exists, plus the backup window in §7.
Data subjects: visitors to the websites you add to Ranksify.
3. Categories of personal data
Deliberately narrow. For each AI-referred visit we store:
- the page path and query string (not the host);
- the referrer;
- the browser user agent;
- a two-letter country code resolved at the network edge;
- a session identifier — either a random value the beacon generates in the visitor's
localStorage, or, for log-line ingest, a truncated SHA-1 of IP address, user agent and date that changes daily. Both are pseudonyms; we do not describe them as anonymised.
A visitor's IP address is never stored in a traffic record. It is used transiently for rate limiting and discarded. The beacon sets no cookie on your visitors and sends nothing at all when Global Privacy Control or Do Not Track is set.
No special category data is processed. Do not send us any — the ingest endpoint is not designed for it.
4. Our instructions, and confidentiality
We process your visitors' personal data only on your documented instructions, which are: this addendum, the Terms of Service, and what you do in the product. If we ever believed an instruction breached data protection law we would tell you rather than carry it out. If the law compelled us to process it some other way, we would tell you first unless the law forbade that.
Everyone with access is bound by confidentiality, and access is limited to those who need it to run and support the service.
5. Security measures
The technical and organisational measures we apply are described in full, and honestly, on our security page — encryption in transit and at rest, server-side access control, application hardening, visitor-data minimisation, nightly integrity-checked backups with a tested restore, and the certifications we do not hold. That page is part of this addendum by reference.
If a personal data breach affects your data, we will tell you without undue delay and give you what you need to meet your own notification obligations.
6. Sub-processors
You authorise the sub-processors below. We will give you at least 14 days' notice by email before adding or replacing one, so you have a chance to object; if you object on reasonable data-protection grounds and we cannot resolve it, you may terminate the affected part of the service and we will refund the unused period.
| Sub-processor | Location | Role | Data it receives |
|---|---|---|---|
| Hetzner Online GmbH | Germany (EU) | Hosting — the servers and database Ranksify runs on | All service data, at rest |
| Cloudflare, Inc. | United States / global | DNS and edge for the application domain | Request metadata in transit, including IP address |
| Stripe, Inc. | United States | Payments and subscription billing | Email address at customer creation; card data goes to Stripe directly and never to us |
| Resend, Inc. | United States | Transactional and lifecycle email delivery | Recipient address, subject and body |
| Anthropic, OpenAI, Google (Gemini), Perplexity | United States | AI answer engines — the systems Ranksify measures | Only the prompt text a customer configures. No end-user personal data |
| DataForSEO | United States | Search-results and domain-authority lookups | Domains and keywords only |
| Functional Software, Inc. (Sentry) | United States | Error reporting — planned, currently disabled | Nothing yet — it is disabled. If we enable it, it is configured to send no personal data: headers, cookies, request bodies and user context are all scrubbed, and this row will say so |
Every sub-processor is bound by terms no less protective than these. We remain responsible to you for what they do.
7. Deletion and return
You can export your data from the product while your account exists. On termination, or on request at any time by emailing [email protected], we delete the personal data we process for you. Backups are retained for 14 days and are not edited in place, so deleted data ages out of backups within 14 days of the deletion rather than disappearing from them instantly.
8. Helping you with data subject requests
If one of your visitors contacts us directly, we will not respond to them on your behalf — we will point them at you and tell you. If you need help answering an access, erasure or objection request, tell us what you need and we will help, at no charge for the volume a normal customer generates.
9. Audits
On request, no more than once a year, we will give you a written summary of our security measures and answer reasonable questions in writing. We do not hold a SOC 2 report or an ISO 27001 certificate and will not pretend otherwise. On-site audits are available only where a supervisory authority requires one, at your cost.
10. International transfers
Your data is at rest in the European Union, on servers in Falkenstein, Germany. Where a sub-processor is in the United States, we rely on its certification under the UK Extension to the EU-US Data Privacy Framework where it holds one, and otherwise on the UK International Data Transfer Agreement or the EU Standard Contractual Clauses with the UK Addendum.
11. Governing law and contact
This addendum is governed by the law of England and Wales. Questions to [email protected].