Last updated: September 28, 2026

1. Scope

This Data Processing Agreement ("DPA") forms part of the Terms and Conditions between RankCited ("Processor") and the client using the service ("Customer", the controller). It applies when RankCited processes personal data on the Customer's behalf and that processing is subject to the EU or UK GDPR, the Swiss FADP or US state privacy laws. Accepting the Terms accepts this DPA. A countersigned copy is available on request from [email protected].

Personal data RankCited processes for its own purposes (for example, account and billing data) is covered by our Privacy Policy, not this DPA.

2. Details of processing

  • Subject matter and purpose: providing the RankCited service — AI-visibility measurement, action plans, content and placements — as described in the Terms.
  • Duration: the term of the Customer's subscription, plus the deletion period in section 8.
  • Data subjects: the Customer's staff and contractors who use the service, and people named in brand material the Customer provides (for example, executives or authors).
  • Categories of data: names, business contact details, job titles, and any personal data contained in content, briefs or website material the Customer provides. The service is not designed for special-category data; the Customer should not submit it.

3. Processor obligations

RankCited will:

  • process Customer personal data only on the Customer's documented instructions, which are the Terms, this DPA and the Customer's use of the service, unless the law requires otherwise (in which case we will tell the Customer first where allowed);
  • ensure that staff with access are bound by confidentiality;
  • apply the security measures in section 6;
  • help the Customer respond to data-subject requests and with data protection impact assessments, as far as the service allows;
  • notify the Customer without undue delay, and in any case within 72 hours, after becoming aware of a personal data breach affecting Customer data, with the information the Customer needs to meet its own obligations;
  • not sell Customer personal data or use it for any purpose other than providing the service, including training AI models.

4. Subprocessors

The Customer authorises RankCited to use the subprocessors below. Each is bound by written terms that protect personal data at least as well as this DPA. We will update this list at least 30 days before adding or replacing a subprocessor; the Customer may object on reasonable data-protection grounds by emailing [email protected] within that period, and if we cannot resolve the objection the Customer may cancel the affected service.

SubprocessorPurposeData involved
Amazon Web ServicesHosting, database, file storage, email deliveryAll service data
StripePayments and invoicingBilling contact and payment data
OpenRouterRouting requests to AI models (including Google, Anthropic and Perplexity models)Prompts, brand and website text
OpenAIAI models for measurement and draftingPrompts, brand and website text
DataForSEOSearch, keyword and backlink dataDomains and keywords
GoogleWebsite analytics (with consent)Usage and device data

5. International transfers

RankCited and its subprocessors mainly process data in the United States and the European Union. For transfers of personal data from the EU, EEA, UK or Switzerland to a country without an adequacy decision, the parties rely on the European Commission's Standard Contractual Clauses (Module 2, controller to processor, and Module 3, processor to processor with our subprocessors), with the UK International Data Transfer Addendum and the Swiss adjustments where they apply, or on the recipient's certification under the EU-US Data Privacy Framework. These clauses are incorporated by reference.

6. Security measures

  • Encryption in transit (TLS) and at rest.
  • Access limited to staff who need it, with separate read-only and write database roles.
  • Passwords stored hashed; administrative access protected by strong authentication.
  • Hosted in AWS data centres with their physical and network controls.
  • Regular backups and logging of administrative and payment actions.

7. Audits

On written request, and no more than once a year unless a breach has occurred or a regulator requires it, RankCited will answer reasonable security questionnaires and provide the information needed to show compliance with this DPA.

8. Deletion at the end of the service

When the Customer's account closes, RankCited deletes Customer personal data within 30 days, unless the law requires us to keep it. The Customer can export its reports before closing. Backups roll off on their normal cycle, within 35 days.

9. Liability and precedence

Each party's liability under this DPA is subject to the limitations in the Terms. If this DPA conflicts with the Terms on the processing of personal data, this DPA prevails; if it conflicts with the Standard Contractual Clauses, the Clauses prevail.

10. Contact

Email: [email protected]

Mail: RankCited, 2803 Philadelphia Pike, Suite B #1019, Claymont, DE 19703, USA

From the blog