Legal

Data Processing Agreement

Details on how we process data on your behalf.

Last updated: June 20, 2026

This Data Processing Agreement ("DPA") forms part of the agreement between RankGrip and the customer using the Service ("Customer", "you", or "Controller"). It applies when RankGrip processes Customer Personal Data on behalf of Customer as a processor under applicable data protection laws, including the GDPR.

The Service is provided by:

Piyush Chandwani

Operating under the brand name RankGrip

Country of establishment: India

Email: [email protected]

By using the Service for business, organization, website, client, or workspace data, you agree to this DPA. This DPA supplements our Terms of Service and Privacy Policy. If there is a conflict between this DPA and the Terms of Service regarding the processing of Customer Personal Data, this DPA controls.

1. Definitions

Capitalized terms not defined in this DPA have the meanings given in the Terms of Service or applicable data protection law.

  • "Applicable Data Protection Laws" means all privacy, data protection, and data security laws applicable to the processing of Customer Personal Data, including the GDPR, UK GDPR, Swiss Federal Act on Data Protection, ePrivacy rules, and applicable US state privacy laws.
  • "Controller" means the party that determines the purposes and means of processing Customer Personal Data.
  • "Customer Personal Data" means personal data that Customer submits, connects, uploads, or otherwise makes available to RankGrip through the Service, and that RankGrip processes on Customer's behalf as processor.
  • "Data Subject" means an identified or identifiable natural person.
  • "GDPR" means Regulation (EU) 2016/679.
  • "Personal Data Breach" means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data.
  • "Processor" means the party that processes personal data on behalf of a controller.
  • "SCCs" means the Standard Contractual Clauses adopted by the European Commission for international personal data transfers.
  • "Service" means RankGrip's website, application, SEO tools, AI features, integrations, subscriptions, credits, support, and related services.
  • "Subprocessor" means a third party engaged by RankGrip to process Customer Personal Data on behalf of Customer.

2. Roles and Scope

For Customer Personal Data, Customer is the Controller and RankGrip is the Processor.

This DPA applies only to Customer Personal Data processed by RankGrip on behalf of Customer. It does not apply to personal data for which RankGrip acts as an independent controller, such as account registration data, billing records, direct support communications, marketing preferences, product analytics, security logs, and legal compliance records. Those processing activities are described in the Privacy Policy.

Customer is responsible for determining whether it acts as a controller, joint controller, processor, or other role for any data it submits to the Service. Customer is also responsible for its own customer, employee, contractor, end-user, and client relationships.

3. Processing Details

The subject matter, duration, nature, purpose, categories of data, and categories of data subjects are described in Annex I.

RankGrip will process Customer Personal Data only to provide, secure, maintain, support, and improve the Service, and only as instructed by Customer through:

  • The Terms of Service, this DPA, and any applicable order or written agreement.
  • Customer's use, configuration, prompts, requests, integrations, workspace settings, and instructions in the Service.
  • Written instructions accepted by RankGrip.
  • Requirements of applicable law.

RankGrip will inform Customer if, in RankGrip's reasonable opinion, an instruction violates Applicable Data Protection Laws, unless prohibited from doing so by law.

4. Customer Obligations

Customer represents and warrants that:

  • Customer has all rights, permissions, notices, consents, and lawful bases required to submit Customer Personal Data to the Service and instruct RankGrip to process it.
  • Customer will use the Service in compliance with Applicable Data Protection Laws.
  • Customer will not submit special category data, sensitive personal data, children's data, payment card data, government identifiers, health data, or similarly sensitive data unless the Service documentation expressly supports that use and Customer has a valid legal basis to do so.
  • Customer will provide legally required privacy notices to Data Subjects.
  • Customer will respond to Data Subject requests and regulator requests for which Customer is responsible.
  • Customer will configure integrations, users, roles, permissions, exports, sharing settings, and retention practices appropriately.
  • Customer will ensure it is authorized to connect each Google account, Search Console property, website, domain, organization, client account, or third-party integration.

Customer is responsible for reviewing AI outputs, SEO recommendations, generated tasks, exports, and reports before using or sharing them.

5. RankGrip Processor Obligations

RankGrip will:

  • Process Customer Personal Data only on Customer's documented instructions.
  • Ensure that persons authorized to process Customer Personal Data are bound by confidentiality obligations.
  • Implement and maintain appropriate technical and organizational measures described in Annex II.
  • Assist Customer with Data Subject requests as described in Section 8.
  • Assist Customer with security, breach, data protection impact assessment, and consultation obligations where required by Applicable Data Protection Laws and taking into account the nature of processing and information available to RankGrip.
  • Use Subprocessors only as described in Section 7.
  • Delete or return Customer Personal Data as described in Section 10.
  • Make available information reasonably necessary to demonstrate compliance as described in Section 11.

6. Security Measures

RankGrip will implement appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.

Current measures are described in Annex II and include, as applicable:

  • Encryption in transit.
  • Encryption or cryptographic protection for sensitive OAuth credentials.
  • Access controls and least-privilege access.
  • Authentication and session controls.
  • Logging, monitoring, and error tracking.
  • Backup and recovery procedures.
  • Subprocessor review and contractual controls.
  • Incident response procedures.

Customer acknowledges that security measures may evolve over time, provided that RankGrip does not materially reduce the overall protection of Customer Personal Data.

7. Subprocessors

Customer grants RankGrip general authorization to engage Subprocessors to provide the Service.

Current Subprocessors and Subprocessor categories are listed in Annex III. RankGrip will impose data protection obligations on each Subprocessor that are no less protective, in substance, than those in this DPA, to the extent applicable to the Subprocessor's services.

RankGrip remains responsible for Subprocessors' processing of Customer Personal Data to the extent required by Applicable Data Protection Laws.

RankGrip may add or replace Subprocessors from time to time. RankGrip will provide notice by updating this DPA, the Privacy Policy, a subprocessors page if available, or by other reasonable means such as email or in-app notice for material changes.

Customer may object to a new Subprocessor on reasonable data protection grounds by contacting [email protected] within 15 days of notice. If RankGrip cannot reasonably address the objection, Customer may stop using the affected feature or terminate the affected Service according to the Terms of Service.

8. Data Subject Requests

Customer is responsible for responding to Data Subject requests relating to Customer Personal Data.

To the extent Customer cannot fulfill a request using the Service, RankGrip will provide reasonable assistance, taking into account the nature of processing and information available to RankGrip. Requests for assistance should be sent to [email protected].

If RankGrip receives a request directly from a Data Subject relating to Customer Personal Data, RankGrip may direct the Data Subject to Customer unless prohibited by law. RankGrip will not independently respond to the request except as required by law or authorized by Customer.

9. Personal Data Breach

RankGrip will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.

Where reasonably possible, the notice will include:

  • A description of the nature of the breach.
  • The categories and approximate number of affected Data Subjects and records, if known.
  • The likely consequences of the breach, if known.
  • Measures taken or proposed to address the breach.
  • Information reasonably available to help Customer meet notification obligations.

RankGrip may provide information in phases as it becomes available. RankGrip's notification of a Personal Data Breach is not an admission of fault or liability.

Customer is responsible for determining whether it must notify regulators, Data Subjects, customers, or other parties, unless Applicable Data Protection Laws require RankGrip to make a notification directly.

10. Deletion and Return

During the term of the Service, Customer may access, export, delete, or modify certain Customer Personal Data through the Service where features allow.

Upon termination of the Service or upon Customer's written request, RankGrip will delete or return Customer Personal Data within a reasonable period, unless retention is required or permitted by law, necessary for legal claims, security, fraud prevention, financial records, backups, or otherwise described in the Privacy Policy.

Backups containing Customer Personal Data are deleted or overwritten according to standard backup rotation, typically within 90 days.

RankGrip is not required to delete Customer Personal Data retained in anonymized, aggregated, or de-identified form that no longer identifies Customer or Data Subjects.

11. Audits and Compliance Information

RankGrip will make available information reasonably necessary to demonstrate compliance with this DPA, subject to confidentiality, security, and legal restrictions.

Where required by Applicable Data Protection Laws, Customer may request an audit no more than once per 12 months, unless a Personal Data Breach or regulator request justifies an additional audit. Audits must:

  • Be requested with at least 30 days' written notice.
  • Be limited to the processing of Customer Personal Data.
  • Occur during normal business hours.
  • Avoid unreasonable disruption to RankGrip's operations.
  • Be conducted by personnel or auditors bound by confidentiality.
  • Not compromise the security, privacy, or confidentiality of other customers, systems, or Subprocessors.

RankGrip may satisfy audit requests by providing security documentation, policies, summaries, third-party reports, questionnaires, or written responses. On-site audits are permitted only where legally required and where remote documentation is insufficient.

Customer is responsible for its own audit costs and will reimburse RankGrip for reasonable costs of support for audits that are unusually broad, frequent, or time-consuming, unless prohibited by law.

12. International Transfers

RankGrip is established in India, but the Service may involve transfers of Customer Personal Data to countries outside the European Economic Area, United Kingdom, or Switzerland, including the United States.

Where RankGrip transfers Customer Personal Data internationally, RankGrip will use appropriate transfer mechanisms as required by Applicable Data Protection Laws, such as:

  • Adequacy decisions.
  • EU-US Data Privacy Framework, UK Extension, or Swiss-US Data Privacy Framework where applicable.
  • Standard Contractual Clauses.
  • UK International Data Transfer Addendum or UK International Data Transfer Agreement.
  • Supplementary measures where required.

If SCCs are required for a transfer from Customer to RankGrip, the parties incorporate the SCCs as follows:

  • Module Two (Controller to Processor) applies where Customer is a controller and RankGrip is a processor.
  • Module Three (Processor to Processor) applies where Customer is a processor and RankGrip is a subprocessor.
  • Clause 7 optional docking clause applies.
  • Clause 9 Option 2 general written authorization for Subprocessors applies, with notice as described in Section 7.
  • Clause 11 optional language does not apply.
  • For Clause 17 and Clause 18, the governing law and forum will be India, unless the SCCs require otherwise.
  • Annexes I, II, and III of this DPA serve as the SCC annexes.

For UK transfers, the SCCs are modified by the UK International Data Transfer Addendum. For Swiss transfers, references to the GDPR include the Swiss Federal Act on Data Protection where applicable, and the Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority where required.

13. Google API Data

If Customer connects Google Search Console, RankGrip processes Google API data only as necessary to provide requested Search Console, URL inspection, SEO analysis, chat, task, and reporting features.

RankGrip's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including Limited Use requirements.

RankGrip will not:

  • Sell Google user data.
  • Use Google user data for advertising.
  • Use Google user data to train generalized AI models.
  • Allow humans to read Google user data except where necessary for security, support, legal compliance, debugging, or with Customer's consent.

Customer is responsible for ensuring it has authority to connect each Google account and Search Console property and for honoring any obligations it has to its own users, clients, or Data Subjects.

14. AI Processing

RankGrip uses AI features to provide SEO analysis, chat responses, recommendations, summaries, and tasks.

When Customer uses AI features, RankGrip may send relevant prompts, messages, website data, Search Console excerpts, tool results, and context to AI Subprocessors. RankGrip uses those Subprocessors only to provide the requested feature and related Service functionality.

RankGrip does not use Customer Personal Data or Google user data to train generalized AI models. Customer acknowledges that AI outputs may contain Customer Personal Data if Customer includes such data in prompts, connected sources, or context.

Customer is responsible for deciding what Customer Personal Data to submit to AI features and for reviewing generated outputs before using or sharing them.

15. US State Privacy Laws

Where US state privacy laws apply and Customer is a "business" or "controller" and RankGrip is a "service provider", "contractor", or "processor", RankGrip will:

  • Process Customer Personal Data only for the business purposes described in this DPA and the Terms of Service.
  • Not sell Customer Personal Data.
  • Not share Customer Personal Data for cross-context behavioral advertising.
  • Not retain, use, or disclose Customer Personal Data outside the direct business relationship except as permitted by applicable law.
  • Assist Customer with consumer requests as required by applicable law.
  • Require Subprocessors to comply with applicable obligations.

16. Liability

Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service or other applicable written agreement, except to the extent such limitations are prohibited by Applicable Data Protection Laws.

17. Term and Termination

This DPA remains in effect for as long as RankGrip processes Customer Personal Data on behalf of Customer.

Upon termination of the Terms of Service or the applicable service agreement, this DPA will terminate after RankGrip deletes or returns Customer Personal Data as described in Section 10, except for provisions that by their nature should survive, including confidentiality, security, deletion, audit, transfer, and liability provisions.

18. Governing Law

This DPA is governed by the laws of India, unless Applicable Data Protection Laws require otherwise.

The parties submit to the jurisdiction described in the Terms of Service, subject to mandatory rights under Applicable Data Protection Laws and the SCCs where applicable.

19. Contact

For questions about this DPA or data processing, contact:

RankGrip

Piyush Chandwani

Email: [email protected]

Annex I: Processing Details

A. Parties

Customer / Controller: The individual, company, organization, agency, or other legal entity using the Service and determining the purposes and means of processing Customer Personal Data.

RankGrip / Processor: Piyush Chandwani operating under the brand name RankGrip.

B. Subject Matter

Provision of RankGrip's AI-assisted SEO platform, including website analysis, Google Search Console integration, AI chat, SEO recommendations, task generation, reporting, subscriptions, support, security, and related Service functionality.

C. Duration

For the term of Customer's use of the Service and until Customer Personal Data is deleted or returned according to this DPA, the Terms of Service, and the Privacy Policy.

D. Nature and Purpose of Processing

RankGrip may collect, receive, store, host, retrieve, query, transmit, analyze, generate, transform, display, delete, and otherwise process Customer Personal Data to:

  • Provide SEO analysis and recommendations.
  • Operate Google Search Console integration.
  • Query and inspect Search Console properties and URLs.
  • Crawl and analyze websites and public web pages.
  • Generate AI chat responses, summaries, task lists, and reports.
  • Manage organizations, websites, members, roles, and permissions.
  • Provide usage credits, limits, and billing-related feature access.
  • Provide support, troubleshooting, security, logging, monitoring, and abuse prevention.
  • Comply with Customer instructions, legal obligations, and the Terms of Service.

E. Categories of Data Subjects

Depending on Customer's use of the Service, Customer Personal Data may relate to:

  • Customer's employees, contractors, representatives, and team members.
  • Customer's clients and client representatives.
  • Website owners, authors, editors, contributors, or contacts.
  • Users or visitors reflected in Google Search Console or other connected datasets.
  • Individuals whose personal data appears in prompts, pages, URLs, page content, metadata, chat messages, tasks, notes, exports, reports, or connected sources.

F. Categories of Customer Personal Data

Depending on Customer's use of the Service, Customer Personal Data may include:

  • Names, email addresses, avatars, roles, organization membership, and account identifiers.
  • Organization names, website domains, URLs, sitemap URLs, competitors, markets, notes, task data, and workflow metadata.
  • Chat messages, prompts, instructions, uploaded or pasted text, tool outputs, generated outputs, and reports.
  • Google account profile data, OAuth connection metadata, Search Console property identifiers, query data, page data, device and country data, clicks, impressions, CTR, average position, URL inspection results, crawl status, indexing data, and related metadata.
  • Public page content, headings, metadata, links, schema, robots directives, technical SEO findings, and crawl results.
  • Usage metadata, feature interactions, request metadata, logs, error reports, IP addresses, device data, and user agent data where processed on Customer's behalf.

G. Sensitive Data

The Service is not designed for processing special categories of personal data, sensitive personal information, payment card data, health data, government identifiers, children's data, or criminal offense data. Customer must not submit such data unless expressly agreed in writing and supported by appropriate safeguards.

Annex II: Technical and Organizational Measures

RankGrip maintains technical and organizational measures appropriate to the nature, scope, context, and purposes of processing, including:

  • Encryption in transit: HTTPS/TLS for data transmitted between users, the Service, and relevant APIs.
  • Credential protection: Sensitive OAuth tokens are encrypted or cryptographically protected before storage where supported by the Service.
  • Access controls: Access to production systems and Customer Personal Data is restricted to authorized personnel and service accounts with a business need.
  • Authentication: Account access uses authenticated sessions and may support social login, magic links, and two-factor authentication features.
  • Authorization: Organization roles and permissions help restrict user access within customer workspaces.
  • Least privilege: Internal access is limited based on role and need.
  • Logging and monitoring: Logs, error monitoring, and operational telemetry are used to detect and investigate reliability and security issues.
  • Backups and recovery: Backups are maintained to support recovery from accidental loss or service incidents.
  • Network and infrastructure security: The Service is hosted with reputable cloud and infrastructure providers that maintain physical, network, and operational security measures.
  • Subprocessor controls: Subprocessors are reviewed for appropriate security and contractual commitments.
  • Incident response: Procedures are maintained to identify, investigate, mitigate, and notify about security incidents.
  • Data minimization: RankGrip seeks to process only data needed to provide requested features.
  • Separation of environments: Development and production practices are designed to reduce unauthorized access to production data.
  • Confidentiality: Personnel with access to Customer Personal Data are bound by confidentiality obligations.

Annex III: Subprocessors

RankGrip uses the following Subprocessors and categories to provide the Service. Specific vendors may change as the Service evolves.

| Subprocessor or category | Purpose | Data processed | Location / transfer safeguard | | --- | --- | --- | --- | | Vercel or other hosting providers | Application hosting, deployment, edge/network services | Customer Personal Data, request data, technical data | EU/US or other regions; DPF, SCCs, or other safeguards where applicable | | Managed PostgreSQL database provider, such as Neon | Primary application database | Account, organization, chat, task, integration, OAuth metadata, and workspace data | EU/US or other regions; DPF, SCCs, or other safeguards where applicable | | Stripe | Payment processing, subscriptions, invoices, fraud prevention | Billing identifiers, transaction metadata, subscription status, contact and payment data | DPF, SCCs, or other safeguards where applicable | | Resend or email delivery providers | Transactional and service emails | Email addresses, names, email content, delivery metadata | DPF, SCCs, or other safeguards where applicable | | Google APIs | Google OAuth and Search Console integration | Google profile data, OAuth tokens, Search Console data | Google transfer safeguards and API terms | | Anthropic | AI model routing and generation | Prompts, messages, relevant context, tool results, model usage metadata | DPF, SCCs, or other safeguards where applicable | | DataForSEO | SEO metrics, keyword data, SERP data, backlink data, competitor data | Public domains, URLs, keywords, SEO queries, tool inputs and outputs | SCCs or other safeguards where applicable | | Firecrawl, Jina AI, Exa, Serper, or similar web data providers | Web search, page reading, crawling, and public web retrieval | URLs, public page content, search queries, crawl metadata | DPF, SCCs, or other safeguards where applicable | | PostHog | Product analytics, feature analytics, event tracking | Usage events, identifiers, device data, session metadata | DPF, SCCs, or other safeguards where applicable | | Sentry or monitoring providers | Error monitoring, logs, performance diagnostics | Error reports, stack traces, request metadata, IP address | DPF, SCCs, or other safeguards where applicable | | Object storage providers | File or asset storage where applicable | Uploaded or generated files and metadata | DPF, SCCs, or other safeguards where applicable |

Annex IV: Customer Instructions

Customer instructs RankGrip to process Customer Personal Data as necessary to:

  • Provide the Service selected and configured by Customer.
  • Process prompts, chats, integrations, websites, Search Console data, tasks, reports, and generated outputs.
  • Use Subprocessors listed in Annex III.
  • Transfer Customer Personal Data as described in Section 12.
  • Secure, monitor, troubleshoot, and support the Service.
  • Comply with applicable law and valid legal process.

Customer may provide additional instructions by configuring the Service or contacting [email protected]. RankGrip may decline instructions that are outside the scope of the Service, technically infeasible, unlawful, or would materially increase risk or cost without a separate written agreement.