Skip to main content
Rankori

Legal

Data Processing Agreement

Template version 1.2 · 28 August 2026

This is Rankori's standard Data Processing Agreement (DPA) — the terms under which we process personal data on your organization's behalf as your GDPR data processor.

This published template is incorporated by reference into your Terms of Service and applies by default to organizations subject to the GDPR, as described in our Privacy Policy. If your organization needs a signed, company-specific copy — for example for your own records or a vendor security review — contact contact@nuramidigital.com and we'll countersign one with your details filled in.

On this page

  1. Parties
  2. 1. Definitions
  3. 2. Subject Matter and Duration
  4. 3. Nature and Purpose of Processing
  5. 4. Type of Personal Data
  6. 5. Categories of Data Subjects
  7. 6. Obligations of the Processor
  8. 7. Obligations of the Controller
  9. 8. Security Measures (Article 32 GDPR)
  10. 9. Personal Data Breach Notification
  11. 10. Sub-processors
  12. 11. International Data Transfers
  13. 12. Term and Termination
  14. 13. Governing Law
  15. 14. Order of Precedence
  16. 15. Signature Block

Parties

This Data Processing Agreement (“DPA” or “Agreement”) is entered into between:

Controller (Customer):

Company name:

Registered address:

Registration number:

Contact name:

Contact email:

(“Controller” or “Customer”)

AND

Processor (Nurami Digital):

Nurami Digital B.V., the company operating the Rankori platform

Registered address: Bertus Aafjeslaan 1, 1187 VZ Amstelveen, Netherlands

Contact for data protection matters: contact@nuramidigital.com

(“Processor” or “Nurami Digital”)

Each a “Party”, together the “Parties”.

This DPA supplements and forms part of the Subscription Agreement, Terms of Service, or other master agreement (the “Main Agreement”) entered into between the Parties for access to and use of the Rankori SaaS platform (the “Service”).

1. Definitions

For the purposes of this DPA, the following definitions apply. Capitalised terms not defined herein shall have the meanings ascribed to them in the Main Agreement or in the GDPR.

“GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.

“Personal Data” means any information relating to an identified or identifiable natural person as defined in Article 4(1) GDPR.

“Processing” means any operation or set of operations performed on Personal Data, including collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure, dissemination, restriction, erasure, or destruction, as defined in Article 4(2) GDPR.

“Data Subject” means the natural person to whom Personal Data relates, as defined in Article 4(1) GDPR.

“Controller” means the natural or legal person that determines the purposes and means of the Processing of Personal Data, as defined in Article 4(7) GDPR. For the purposes of this DPA, the Controller is the Customer.

“Processor” means the natural or legal person that Processes Personal Data on behalf of the Controller, as defined in Article 4(8) GDPR. For the purposes of this DPA, the Processor is Nurami Digital.

“Sub-processor” means any third party engaged by the Processor to carry out Processing activities on behalf of the Controller.

“Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored, or otherwise processed, as defined in Article 4(12) GDPR.

“SCCs” means Standard Contractual Clauses for the transfer of Personal Data to third countries as adopted by the European Commission.

2. Subject Matter and Duration

2.1 Subject Matter. The Processor shall Process Personal Data on behalf of the Controller solely to provide the Rankori Service as described in the Main Agreement. The Processing encompasses the hosting, storage, and processing of the Controller's user and member data and business SEO data (keywords, competitor domains, SERP snapshots, ranking metrics, and reports) as required to deliver the Service.

2.2 Duration. This DPA is effective from the date the Main Agreement is executed and remains in force for the duration of the subscription term. It terminates automatically upon termination or expiry of the Main Agreement, subject to the data deletion obligations set out in Section 12.

3. Nature and Purpose of Processing

The Processor Processes Personal Data for the following purposes:

  • Hosting, storing, and processing SEO-related Personal Data as instructed by the Controller through the Rankori platform
  • Providing authenticated multi-user access to the Service (user authentication, session management, role-based access control)
  • Processing keyword tracking, SERP snapshot retrieval, and competitor intelligence on the Controller's behalf
  • Generating reports and exporting data in formats requested by the Controller
  • Sending transactional notifications (e.g. invitation emails, password resets, report delivery notifications) on behalf of the Controller
  • Maintaining audit logs and security monitoring for the protection of the Controller's data

All Processing is carried out only on the documented instructions of the Controller, as described in this DPA and the Main Agreement.

4. Type of Personal Data

The Processor Processes the following categories of Personal Data on behalf of the Controller:

  • Names — first and last names of the Controller's users
  • Email addresses — used for authentication, invitations, and transactional communications
  • IP addresses — captured in session and audit logs for security purposes
  • Job titles — if voluntarily provided by users in their profile
  • Usage metadata — actions taken within the platform, timestamps, page visits (associated with user identifiers)
  • Authentication credentials — password hashes (never plaintext passwords)
  • Organisation-related data — organisation name, membership roles, project configuration

The categories above constitute Personal Data strictly necessary to deliver the Service. Business SEO data (keywords, domains, SERP results) may contain personal data only if the Controller uses individual names as keywords or tracked terms. The Controller is responsible for ensuring any such data is processed lawfully.

5. Categories of Data Subjects

The Personal Data Processed under this DPA relates to the following categories of Data Subjects:

  • The Controller's employees who use the Rankori platform
  • The Controller's contractors or agency staff granted access to the platform
  • Other end users of the Rankori platform authorised by the Controller (e.g. clients of the Controller who are granted viewer access)

6. Obligations of the Processor

The Processor undertakes the following obligations:

6.1 Processing on Instructions Only. The Processor shall Process Personal Data only on the documented instructions of the Controller, including with regard to transfers of Personal Data to a third country or an international organisation, unless required to do so by Union or Member State law. In such a case, the Processor shall inform the Controller of that legal requirement prior to Processing, unless that law prohibits such information on grounds of public interest.

6.2 Confidentiality. The Processor shall ensure that persons authorised to Process Personal Data on its behalf are subject to a binding obligation of confidentiality, whether under a contractual or statutory obligation.

6.3 Security Measures. The Processor shall implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk in accordance with Article 32 GDPR. See Section 8 of this DPA for detail.

6.4 Sub-processors. The Processor shall not engage a Sub-processor without prior written authorisation from the Controller (general authorisation is deemed granted by the Controller's acceptance of this DPA for the Sub-processors listed in Section 10). The Processor shall notify the Controller of any intended change to the Sub-processor list at least 30 days in advance, giving the Controller the opportunity to object. If the Controller objects on reasonable data protection grounds, the Parties shall work in good faith to resolve the objection. The Processor shall impose data protection obligations on Sub-processors equivalent to those in this DPA.

6.5 Data Subject Rights. The Processor shall assist the Controller, by appropriate technical and organisational measures (insofar as this is possible), with the fulfilment of the Controller's obligations to respond to requests by Data Subjects exercising their rights under Chapter III of the GDPR. This includes providing access to export mechanisms (data portability) and account deletion capabilities available within the Service.

6.6 Compliance Assistance. The Processor shall assist the Controller in ensuring compliance with obligations under Articles 32 to 36 GDPR (security, breach notification, data protection impact assessments, prior consultation), taking into account the nature of Processing and the information available to the Processor.

6.7 Deletion or Return of Data. Upon termination of the Main Agreement, the Processor shall delete all Personal Data or return it to the Controller as described in Section 12.

6.8 Audit Rights. The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 GDPR, and shall allow for and contribute to audits and inspections conducted by the Controller or an auditor mandated by the Controller, subject to reasonable notice (not less than 30 days), confidentiality obligations, and agreement on scope and costs.

7. Obligations of the Controller

The Controller shall:

  • Ensure that it has a lawful basis for Processing Personal Data and for transferring it to the Processor
  • Provide the Processor with clear, documented instructions for all Processing
  • Ensure that Data Subjects have been informed of the Processing as required by GDPR Articles 13 and 14
  • Promptly inform the Processor if it believes any instruction given would violate applicable data protection law

8. Security Measures (Article 32 GDPR)

The Processor implements the following technical and organisational security measures:

8.1 Encryption

  • All Personal Data is encrypted in transit using TLS 1.2 or higher
  • Data at rest is encrypted using platform-managed encryption (Azure Storage Service Encryption / AES-256)
  • Sensitive configuration values (e.g. API credentials) are encrypted at the application layer using AES-256-GCM

8.2 Access Controls

  • Role-based access control (RBAC) enforced at the application layer: owner, admin, contributor, and reader roles with least-privilege permissions
  • Organisation-scoped tenant isolation: all data access is validated against the authenticated user's organisation membership
  • Administrative access to infrastructure is limited to authorised personnel only

8.3 Authentication

  • All user-facing authentication is managed via the Better Auth framework with configurable session expiry
  • Passwords are stored only as salted scrypt hashes, never in plaintext
  • Session tokens are HttpOnly, SameSite cookies

8.4 Audit Logging

  • All mutating operations are written to an immutable audit log with user ID, organisation ID, action type, and timestamp
  • Audit log entries are retained for as long as the Controller's organisation exists; an entry is anonymised (its user identifier replaced with a non-identifying placeholder) if the acting user deletes their account, and deleted outright when the organisation itself is deleted

8.5 Incident Response

  • The Processor maintains documented incident response procedures
  • On detection of a Personal Data Breach, the Processor will notify the Controller within 72 hours as required by Article 33 GDPR (see Section 9)

8.6 Availability and Resilience

  • The Service is deployed on Microsoft Azure with automated backups
  • Azure Monitor scheduled-query alerts on Application Insights detect operational failures; Application Insights captures and alerts on application errors

9. Personal Data Breach Notification

9.1 The Processor shall notify the Controller without undue delay and, where feasible, not later than 72 hours after becoming aware of a Personal Data Breach affecting the Controller's Personal Data.

9.2 The notification shall include, to the extent the information is available at the time:

  • A description of the nature of the breach, including where possible the categories and approximate number of Data Subjects and records affected
  • The contact details of the Processor's data protection contact (contact@nuramidigital.com)
  • A description of the likely consequences of the breach
  • A description of the measures taken or proposed to address the breach, including mitigation measures

9.3 Where all required information cannot be provided simultaneously, the Processor may provide it in phases without undue further delay.

9.4 The Controller is responsible for notifying the relevant supervisory authority and affected Data Subjects where required by Articles 33 and 34 GDPR.

10. Sub-processors

The Controller hereby grants general authorisation for the Processor to engage the following Sub-processors as of the effective date of this DPA:

Sub-processorPurposeLocation
DataForSEOSERP data retrieval, keyword metrics, related keyword discoveryEU (Lithuania)
ResendTransactional email deliveryUSA (SCCs apply)
PaddlePayment processing and subscription managementUSA / UK (SCCs apply)
hCaptcha (Intuition Machines, Inc.)Bot detection on registration and password resetUSA (SCCs apply)
Microsoft AzureCloud infrastructure, compute, storage, and database hosting, plus error and performance monitoring (Application Insights)EU (Netherlands / West Europe)
OpenAIRuns AI-visibility prompts and returns responses (Controller organisations with the AI Visibility feature enabled only)USA (SCCs apply)
Perplexity AIRuns AI-visibility prompts and returns responses, including source citations (Controller organisations with the AI Visibility feature enabled only)USA (SCCs apply)
Google (Gemini API)Runs AI-visibility prompts and returns responses (Controller organisations with the AI Visibility feature enabled only)USA (SCCs apply)

The Processor shall notify the Controller at least 30 days before engaging any new Sub-processor or replacing an existing one, providing the Controller with the opportunity to object. Objections must be raised in writing within 14 days of the notice. If the Parties cannot resolve the objection, the Controller may terminate the Main Agreement without penalty within 30 days of the notification.

11. International Data Transfers

Where the Processing involves a transfer of Personal Data to a country outside the European Economic Area (EEA) that has not been granted an adequacy decision by the European Commission, such transfer shall be carried out only:

  • On the basis of the Standard Contractual Clauses (SCCs) as adopted by the European Commission (Decision 2021/914), incorporated by reference into this DPA; or
  • On the basis of another appropriate safeguard as permitted under Chapter V of the GDPR

Sub-processors located outside the EEA (Resend, Paddle, hCaptcha, OpenAI, Perplexity AI, Google) are engaged subject to SCCs or equivalent transfer mechanisms. The Processor shall maintain records of applicable transfer mechanisms and make them available to the Controller on request.

12. Term and Termination

12.1 This DPA terminates upon termination or expiry of the Main Agreement.

12.2 Upon termination, the Processor shall, at the Controller's election:

  • Delete all Personal Data relating to the Controller within 30 days of the termination date; or
  • Return all Personal Data in a machine-readable format within 30 days, after which the Processor shall securely delete all copies

12.3 The Processor shall provide written confirmation of deletion upon request.

12.4 Notwithstanding the above, the Processor may retain Personal Data to the extent required by applicable Union or Member State law (e.g. retention of billing records for 7 years under accounting legislation), provided that the Processor ensures the confidentiality of such data and Processes it only to the extent necessary for the purpose of the legal obligation.

13. Governing Law

This DPA is governed by the laws of the European Union and, where applicable, the laws of the Member State in which the Controller is established. Any disputes arising under this DPA shall be resolved in accordance with the dispute resolution provisions of the Main Agreement.

14. Order of Precedence

In the event of any conflict between this DPA and the Main Agreement with respect to the Processing of Personal Data, this DPA shall prevail.

15. Signature Block

By signing below, the authorised representatives of each Party agree to be bound by the terms of this Data Processing Agreement.

Controller (Customer)

Company name:

Authorised signatory name:

Title:

Signature:

Date:

Processor (Nurami Digital)

Authorised signatory name:

Title:

Signature:

Date:

Contact for data protection enquiries: contact@nuramidigital.com

© 2026 Nurami Digital B.V.
Pricing Terms of Service Privacy Policy Data Processing Agreement Refund & Cancellation Policy