Details on how we process data on your behalf.
Last updated: June 20, 2026
This Data Processing Agreement ("DPA") forms part of the agreement between RankGrip and the customer using the Service ("Customer", "you", or "Controller"). It applies when RankGrip processes Customer Personal Data on behalf of Customer as a processor under applicable data protection laws, including the GDPR.
The Service is provided by:
Piyush Chandwani
Operating under the brand name RankGrip
Country of establishment: India
Email: [email protected]
By using the Service for business, organization, website, client, or workspace data, you agree to this DPA. This DPA supplements our Terms of Service and Privacy Policy. If there is a conflict between this DPA and the Terms of Service regarding the processing of Customer Personal Data, this DPA controls.
Capitalized terms not defined in this DPA have the meanings given in the Terms of Service or applicable data protection law.
For Customer Personal Data, Customer is the Controller and RankGrip is the Processor.
This DPA applies only to Customer Personal Data processed by RankGrip on behalf of Customer. It does not apply to personal data for which RankGrip acts as an independent controller, such as account registration data, billing records, direct support communications, marketing preferences, product analytics, security logs, and legal compliance records. Those processing activities are described in the Privacy Policy.
Customer is responsible for determining whether it acts as a controller, joint controller, processor, or other role for any data it submits to the Service. Customer is also responsible for its own customer, employee, contractor, end-user, and client relationships.
The subject matter, duration, nature, purpose, categories of data, and categories of data subjects are described in Annex I.
RankGrip will process Customer Personal Data only to provide, secure, maintain, support, and improve the Service, and only as instructed by Customer through:
RankGrip will inform Customer if, in RankGrip's reasonable opinion, an instruction violates Applicable Data Protection Laws, unless prohibited from doing so by law.
Customer represents and warrants that:
Customer is responsible for reviewing AI outputs, SEO recommendations, generated tasks, exports, and reports before using or sharing them.
RankGrip will:
RankGrip will implement appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.
Current measures are described in Annex II and include, as applicable:
Customer acknowledges that security measures may evolve over time, provided that RankGrip does not materially reduce the overall protection of Customer Personal Data.
Customer grants RankGrip general authorization to engage Subprocessors to provide the Service.
Current Subprocessors and Subprocessor categories are listed in Annex III. RankGrip will impose data protection obligations on each Subprocessor that are no less protective, in substance, than those in this DPA, to the extent applicable to the Subprocessor's services.
RankGrip remains responsible for Subprocessors' processing of Customer Personal Data to the extent required by Applicable Data Protection Laws.
RankGrip may add or replace Subprocessors from time to time. RankGrip will provide notice by updating this DPA, the Privacy Policy, a subprocessors page if available, or by other reasonable means such as email or in-app notice for material changes.
Customer may object to a new Subprocessor on reasonable data protection grounds by contacting [email protected] within 15 days of notice. If RankGrip cannot reasonably address the objection, Customer may stop using the affected feature or terminate the affected Service according to the Terms of Service.
Customer is responsible for responding to Data Subject requests relating to Customer Personal Data.
To the extent Customer cannot fulfill a request using the Service, RankGrip will provide reasonable assistance, taking into account the nature of processing and information available to RankGrip. Requests for assistance should be sent to [email protected].
If RankGrip receives a request directly from a Data Subject relating to Customer Personal Data, RankGrip may direct the Data Subject to Customer unless prohibited by law. RankGrip will not independently respond to the request except as required by law or authorized by Customer.
RankGrip will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.
Where reasonably possible, the notice will include:
RankGrip may provide information in phases as it becomes available. RankGrip's notification of a Personal Data Breach is not an admission of fault or liability.
Customer is responsible for determining whether it must notify regulators, Data Subjects, customers, or other parties, unless Applicable Data Protection Laws require RankGrip to make a notification directly.
During the term of the Service, Customer may access, export, delete, or modify certain Customer Personal Data through the Service where features allow.
Upon termination of the Service or upon Customer's written request, RankGrip will delete or return Customer Personal Data within a reasonable period, unless retention is required or permitted by law, necessary for legal claims, security, fraud prevention, financial records, backups, or otherwise described in the Privacy Policy.
Backups containing Customer Personal Data are deleted or overwritten according to standard backup rotation, typically within 90 days.
RankGrip is not required to delete Customer Personal Data retained in anonymized, aggregated, or de-identified form that no longer identifies Customer or Data Subjects.
RankGrip will make available information reasonably necessary to demonstrate compliance with this DPA, subject to confidentiality, security, and legal restrictions.
Where required by Applicable Data Protection Laws, Customer may request an audit no more than once per 12 months, unless a Personal Data Breach or regulator request justifies an additional audit. Audits must:
RankGrip may satisfy audit requests by providing security documentation, policies, summaries, third-party reports, questionnaires, or written responses. On-site audits are permitted only where legally required and where remote documentation is insufficient.
Customer is responsible for its own audit costs and will reimburse RankGrip for reasonable costs of support for audits that are unusually broad, frequent, or time-consuming, unless prohibited by law.
RankGrip is established in India, but the Service may involve transfers of Customer Personal Data to countries outside the European Economic Area, United Kingdom, or Switzerland, including the United States.
Where RankGrip transfers Customer Personal Data internationally, RankGrip will use appropriate transfer mechanisms as required by Applicable Data Protection Laws, such as:
If SCCs are required for a transfer from Customer to RankGrip, the parties incorporate the SCCs as follows:
For UK transfers, the SCCs are modified by the UK International Data Transfer Addendum. For Swiss transfers, references to the GDPR include the Swiss Federal Act on Data Protection where applicable, and the Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority where required.
If Customer connects Google Search Console, RankGrip processes Google API data only as necessary to provide requested Search Console, URL inspection, SEO analysis, chat, task, and reporting features.
RankGrip's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including Limited Use requirements.
RankGrip will not:
Customer is responsible for ensuring it has authority to connect each Google account and Search Console property and for honoring any obligations it has to its own users, clients, or Data Subjects.
RankGrip uses AI features to provide SEO analysis, chat responses, recommendations, summaries, and tasks.
When Customer uses AI features, RankGrip may send relevant prompts, messages, website data, Search Console excerpts, tool results, and context to AI Subprocessors. RankGrip uses those Subprocessors only to provide the requested feature and related Service functionality.
RankGrip does not use Customer Personal Data or Google user data to train generalized AI models. Customer acknowledges that AI outputs may contain Customer Personal Data if Customer includes such data in prompts, connected sources, or context.
Customer is responsible for deciding what Customer Personal Data to submit to AI features and for reviewing generated outputs before using or sharing them.
Where US state privacy laws apply and Customer is a "business" or "controller" and RankGrip is a "service provider", "contractor", or "processor", RankGrip will:
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service or other applicable written agreement, except to the extent such limitations are prohibited by Applicable Data Protection Laws.
This DPA remains in effect for as long as RankGrip processes Customer Personal Data on behalf of Customer.
Upon termination of the Terms of Service or the applicable service agreement, this DPA will terminate after RankGrip deletes or returns Customer Personal Data as described in Section 10, except for provisions that by their nature should survive, including confidentiality, security, deletion, audit, transfer, and liability provisions.
This DPA is governed by the laws of India, unless Applicable Data Protection Laws require otherwise.
The parties submit to the jurisdiction described in the Terms of Service, subject to mandatory rights under Applicable Data Protection Laws and the SCCs where applicable.
For questions about this DPA or data processing, contact:
RankGrip
Piyush Chandwani
Email: [email protected]
Customer / Controller: The individual, company, organization, agency, or other legal entity using the Service and determining the purposes and means of processing Customer Personal Data.
RankGrip / Processor: Piyush Chandwani operating under the brand name RankGrip.
Provision of RankGrip's AI-assisted SEO platform, including website analysis, Google Search Console integration, AI chat, SEO recommendations, task generation, reporting, subscriptions, support, security, and related Service functionality.
For the term of Customer's use of the Service and until Customer Personal Data is deleted or returned according to this DPA, the Terms of Service, and the Privacy Policy.
RankGrip may collect, receive, store, host, retrieve, query, transmit, analyze, generate, transform, display, delete, and otherwise process Customer Personal Data to:
Depending on Customer's use of the Service, Customer Personal Data may relate to:
Depending on Customer's use of the Service, Customer Personal Data may include:
The Service is not designed for processing special categories of personal data, sensitive personal information, payment card data, health data, government identifiers, children's data, or criminal offense data. Customer must not submit such data unless expressly agreed in writing and supported by appropriate safeguards.
RankGrip maintains technical and organizational measures appropriate to the nature, scope, context, and purposes of processing, including:
RankGrip uses the following Subprocessors and categories to provide the Service. Specific vendors may change as the Service evolves.
| Subprocessor or category | Purpose | Data processed | Location / transfer safeguard | | --- | --- | --- | --- | | Vercel or other hosting providers | Application hosting, deployment, edge/network services | Customer Personal Data, request data, technical data | EU/US or other regions; DPF, SCCs, or other safeguards where applicable | | Managed PostgreSQL database provider, such as Neon | Primary application database | Account, organization, chat, task, integration, OAuth metadata, and workspace data | EU/US or other regions; DPF, SCCs, or other safeguards where applicable | | Stripe | Payment processing, subscriptions, invoices, fraud prevention | Billing identifiers, transaction metadata, subscription status, contact and payment data | DPF, SCCs, or other safeguards where applicable | | Resend or email delivery providers | Transactional and service emails | Email addresses, names, email content, delivery metadata | DPF, SCCs, or other safeguards where applicable | | Google APIs | Google OAuth and Search Console integration | Google profile data, OAuth tokens, Search Console data | Google transfer safeguards and API terms | | Anthropic | AI model routing and generation | Prompts, messages, relevant context, tool results, model usage metadata | DPF, SCCs, or other safeguards where applicable | | DataForSEO | SEO metrics, keyword data, SERP data, backlink data, competitor data | Public domains, URLs, keywords, SEO queries, tool inputs and outputs | SCCs or other safeguards where applicable | | Firecrawl, Jina AI, Exa, Serper, or similar web data providers | Web search, page reading, crawling, and public web retrieval | URLs, public page content, search queries, crawl metadata | DPF, SCCs, or other safeguards where applicable | | PostHog | Product analytics, feature analytics, event tracking | Usage events, identifiers, device data, session metadata | DPF, SCCs, or other safeguards where applicable | | Sentry or monitoring providers | Error monitoring, logs, performance diagnostics | Error reports, stack traces, request metadata, IP address | DPF, SCCs, or other safeguards where applicable | | Object storage providers | File or asset storage where applicable | Uploaded or generated files and metadata | DPF, SCCs, or other safeguards where applicable |
Customer instructs RankGrip to process Customer Personal Data as necessary to:
Customer may provide additional instructions by configuring the Service or contacting [email protected]. RankGrip may decline instructions that are outside the scope of the Service, technically infeasible, unlawful, or would materially increase risk or cost without a separate written agreement.