1. Definitions
"Data Protection Law" means the EU GDPR, the UK GDPR and Data Protection Act 2018, the California Consumer Privacy Act as amended, and any other law that applies to the processing under this agreement. "Customer Data" means personal data that RankZap processes on your behalf as described in Annex I. "Sub-processor" means a third party RankZap engages to process Customer Data. "Controller", "processor", "data subject", "personal data", "processing" and "personal data breach" have the meanings given in Data Protection Law.
2. Roles and scope
You are the controller of Customer Data, or a processor acting on your own client's instructions, and RankZap is your processor. Where you are a processor, you warrant that your client's instructions permit you to appoint RankZap on these terms. This agreement applies for as long as RankZap processes Customer Data for you and survives termination of the Terms until that data is deleted or returned. RankZap is an independent controller of account data about you, as described in the Privacy notice; that processing is outside this agreement.
3. Instructions
RankZap will process Customer Data only on your documented instructions, which are: the Terms, this agreement, your configuration of the product (the integrations you connect, the reports you schedule, the recipients you add, the AI features you run) and any further written instruction you send. RankZap will tell you without delay if it believes an instruction infringes Data Protection Law, and may suspend that instruction until it is resolved. RankZap will not process Customer Data for its own purposes, sell it, or use it to train AI models.
4. Confidentiality
RankZap limits access to Customer Data to staff and contractors who need it to provide the service, and ensures they are bound by written confidentiality obligations.
5. Security
RankZap implements and maintains the technical and organisational measures in Annex II. Those measures may be updated, but not in a way that materially reduces the overall protection of Customer Data during the term.
6. Sub-processors
You give general authorisation for the Sub-processors listed at rankzapseo.com/sub-processors, which forms Annex III. RankZap will post changes to that page and email account holders at least 14 days before a new Sub-processor processes Customer Data. You may object within that period on reasonable data-protection grounds. If RankZap cannot address the objection, you may terminate the affected subscription and receive a pro-rata refund of prepaid fees. RankZap imposes data-protection obligations on each Sub-processor equivalent to those in this agreement and remains liable to you for their performance.
7. International transfers
RankZap's database is hosted in the United States and its application servers in India, and Sub-processors operate where stated in Annex III. For Customer Data subject to the EU GDPR, transfers to countries without an adequacy decision are made under the EU Standard Contractual Clauses (Commission Decision 2021/914), Module Two (controller to processor) or Module Three (processor to processor) as applicable, which are incorporated by reference with the options set out in Annex I. For Customer Data subject to the UK GDPR, the UK International Data Transfer Addendum to the EU SCCs applies in the same way. RankZap will carry out and document transfer risk assessments and apply the supplementary measures in Annex II.
8. Assistance
RankZap will, taking into account the nature of the processing, assist you by appropriate technical and organisational measures in responding to data subject requests, and will forward to you without delay any request it receives directly. RankZap will assist you with security, breach notification, data protection impact assessments and prior consultation with a supervisory authority, to the extent the information you need is not already available in the product or on these pages.
9. Personal data breach
RankZap will notify you without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Customer Data. The notice will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point, and will be updated as information becomes available. RankZap's notice is not an admission of fault.
10. Deletion and return
We retain account and workspace data while needed to provide the service. To request deletion or a data export, email hello@rankzapseo.com from your account address. We verify the request and respond within the time required by applicable law. We delete or anonymise data that is no longer needed, except records we must retain for billing, security, disputes or legal obligations. Backup copies may remain until their normal rotation; they are not used for routine processing, and deletion requests must be reapplied if a backup is restored. Contact us for the retention arrangements applicable to your data.
Disconnecting a Google or Bing integration removes its stored access token. Records retained for legal obligations are restricted to that purpose.
11. Audit
RankZap will make available the information necessary to demonstrate compliance with this agreement, including the Annexes, the current Sub-processor list, and summaries of any third-party security assessments. No more than once a year, or after a personal data breach, you may audit RankZap's compliance on at least 30 days' written notice, during business hours, without unreasonable disruption, and subject to confidentiality. RankZap may satisfy an audit by written responses and documentation where these reasonably address your request.
12. Liability
Each party's liability under this agreement is subject to the limitations and exclusions in the Terms. Nothing in this agreement limits liability that cannot be limited under Data Protection Law.
13. Precedence
If this agreement conflicts with the Terms, this agreement prevails for the processing of Customer Data. If the Standard Contractual Clauses conflict with this agreement, the Clauses prevail.
Annex I. Details of the processing
| Subject matter | Provision of the RankZap SEO reporting, audit, content and AI-visibility service. |
|---|---|
| Duration | The term of your subscription plus the deletion period in section 10. |
| Nature and purpose | Collecting data from integrations you connect, crawling websites you own or manage, storing and analysing it, generating reports and drafts, and delivering reports to recipients you name. |
| Categories of data subjects | Your clients' staff and contacts named as report recipients; individuals whose data appears in connected analytics (aggregated, no direct identifiers); reviewers appearing in public Places listings; authors and contacts named on crawled pages. |
| Categories of personal data | Names, email addresses and phone numbers of report recipients; reviewer names and review text from public Places listings; names, roles and contact details published on crawled pages; aggregated search and traffic statistics. No special-category data is intended; you must not connect sources that contain it. |
| Frequency | Continuous, according to the schedules you configure. |
| SCC options | Clause 7 docking: included. Clause 9: Option 2, general authorisation, 14 days' notice. Clause 11: optional redress not included. Clause 13 and 17: the law of the EU member state in which the data exporter is established, or Ireland where it has none. Clause 18: courts of the same state. Annex I.C competent supervisory authority: that of the data exporter. |
| UK Addendum | Table 1 parties as above; Table 2 the SCCs as completed here; Table 3 the Annexes to this agreement; Table 4 either party may end the Addendum as set out in section 19 of it. |
Annex II. Technical and organisational measures
- Encryption. HTTPS for browser and API connections to our service. Audits can request public HTTP pages to identify insecure URLs. Database encrypted at rest. Integration tokens, publishing credentials and LLM API keys encrypted with AES-256-GCM using a key held outside the database.
- Access control. Role-based access in the product; per-workspace isolation of client data; production server access is restricted to authorised administrators using SSH keys.
- Least data. Integrations use read-only scopes where Google and Microsoft offer them. Paddle acts as an independent controller for its payment services and is not a sub-processor under this agreement. Google user data is used only to provide user-facing features, in line with Google's API Services User Data Policy, including the Limited Use requirements.
- AI processing. RankZap does not train models on Customer Data. AI requests are sent to the selected model provider for the configured task. With your own key, that provider may still be OpenRouter if you select it; review its data terms before supplying confidential data.
- Availability. Hosting and database services are provided by DigitalOcean and MongoDB Atlas. Contact us for current backup and recovery arrangements; RankZap does not claim SOC 2 or ISO 27001 certification.
- Logging and monitoring. Authentication events and administrative actions are logged and retained for investigation.
- Secure development. Dependencies scanned and updated; changes reviewed before deployment; secrets never stored in source control.
- Incident response. A 48-hour customer notice commitment after awareness of a relevant breach (section 9).
- Supplementary transfer measures. Encryption in transit and at rest as above; a policy of challenging and minimising any government access request and notifying the customer where lawful.
- Personnel. Confidentiality terms for everyone with production access.
Annex III. Sub-processors
The current list, locations and change-notice process are maintained at rankzapseo.com/sub-processors.
Contact
Data protection contact: hello@rankzapseo.com. Postal address: House # 116-Dc, ArvoSol Technologies, 2nd floor, D Block, Garden Town Phase III, Sialkot Road, Gujranwala 52250, Punjab, Pakistan.