Legal
Privacy Policy
This policy explains what personal data Rankori collects, why, who we share it with, and the rights you have over it — whether you're a visitor, a prospect, or a member of a customer organization.
1. Who We Are
Rankori is a multi-tenant Software-as-a-Service (SaaS) platform providing search visibility, keyword tracking, competitor intelligence, and LLM citation-visibility tools for businesses and agencies.
Data Controller / Business:
Nurami Digital B.V., the company operating the Rankori platform
Contact: contact@nuramidigital.com
Under the GDPR, Nurami Digital acts as the data controller for the personal data described in this policy. Under US state privacy laws, Nurami Digital acts as the business with respect to the personal information it collects about its own website visitors, prospects, and account users.
Scope. This policy covers personal data we collect about you as a visitor, prospect, account holder, or member of a customer organisation using Rankori. It does not govern the keyword, competitor, or SERP data itself, which is business data about search results and websites rather than personal data about you — except where such data incidentally includes personal information (for example, a named individual appearing in search results). Where a Rankori customer uses the platform to process personal data about its own end customers (for example, via the integrations described in Section 5.5), we act as a processor/service provider on that customer's behalf under the terms of our Data Processing Agreement, not as controller — that relationship is governed by the DPA, not this policy.
2. Summary of Key Points
This summary is for convenience only — the full sections below control.
- We collect account and identity data (name, email, password hash), technical and usage data, the business and SEO data you configure (keywords, domains, SERP snapshots, AI-visibility prompts), and billing data.
- We use it to run the service, secure your account, and bill you.
- We share data with a defined list of sub-processors (Section 8) covering hosting, email, payments, error monitoring, bot detection, and — for customers on AI Visibility plans — LLM providers. We do not sell your personal information or share it for cross-context behavioral advertising, and we run no advertising cookies.
- We retain data on the schedules in Section 11, and delete it on account or organisation deletion (Sections 17–18).
- If you are in the EEA, UK, or Switzerland, you have GDPR rights (Section 14). If you are a US resident in a state with a comprehensive privacy law, you have parallel rights under that law (Section 15).
- Questions or requests: contact@nuramidigital.com.
3. Table of Contents
See “On this page” above for a linked table of contents.
4. Key Definitions
| Term | Meaning |
|---|---|
| Personal Data / Personal Information | Information that identifies, relates to, or could reasonably be linked with an identified or identifiable individual. |
| Controller (GDPR) | The entity that determines the purposes and means of processing personal data — Nurami Digital, for the data described in this policy. |
| Processor (GDPR) / Service Provider (CCPA/CPRA) | An entity that processes personal data on a controller's or business's behalf and under its instructions — the role our sub-processors play for us, and the role we ourselves play for a customer's end-customer data under a DPA. |
| Sub-processor | A third party a processor engages to help process personal data on the controller's behalf (Section 8). |
| Organisation | A tenant workspace within Rankori. Every business record belongs to exactly one organisation. |
| Services | The Rankori web application, background workers, LLM orchestrator, and analytics engine, collectively. |
5. Information We Collect
5.1 Account and Identity Data
- Full name — provided at registration
- Email address — authentication, transactional notifications, account management
- Password — stored only as a salted scrypt hash, never in plaintext
5.2 Technical and Usage Data
- IP address — captured at login and in audit log entries for security and fraud prevention
- Session identifiers — stored in an HttpOnly, SameSite cookie to maintain your authenticated session
- Usage data — actions taken within the platform and timestamps of that activity, recorded in the audit log
- Browser and device information — user agent string, used for security logging
- Aggregate product analytics — page-view counts collected via a self-hosted Umami instance. Umami sets no cookies and does not track you across websites or sessions; we use it only to understand aggregate feature usage, never to build an individual profile of you. This tracking runs in production only.
- Bot-detection signals — when you register or request a password reset, hCaptcha evaluates your browser session to distinguish humans from automated abuse. See Section 8.
5.3 Business and SEO Data (User-Provided)
- Keywords you configure for tracking
- Tracked domains — your website and competitor domains
- SERP snapshots and keyword ranking data (position, volume, difficulty, cost-per-click, and related metrics) retrieved on your behalf from our data provider
- Competitor intelligence data — overlap scores, visibility scores, and SERP-discovered competitor domains
- Site audit data — crawl results, page-level findings, issues, and backlink snapshots for URLs you submit
- Organisation and project configuration — organisation name, project settings, branding assets
- Reports — generated PDF and PowerPoint reports based on your data
- AI-visibility prompts and LLM responses — for customers on plans with AI Visibility enabled: the prompts you configure, the raw responses returned by third-party LLM providers when we run those prompts on your behalf, and the citations, brand and entity mentions, and sentiment we extract from those responses
5.4 Billing Data
- Subscription status — plan type and lifecycle state (trial, active, cancelled, locked)
- Payment processing data — handled entirely by Paddle, our payment processor and Merchant of Record. We do not store card numbers or full payment instrument details.
5.5 Information From Third Parties
If your organisation connects an integration (for example GA4, Google Search Console, Google Business Profile, Google Ads, Meta Ads, Facebook, Instagram, AdRoll, or CallRail), we receive the account-performance data that integration exposes, on your organisation's instructions, for display inside the platform. This data is processed under the terms of your organisation's DPA with us, not under this policy directly (see the Scope note in Section 1).
6. How We Use Your Information
- Providing and operating the Services (account management, keyword tracking, competitor analysis, site audits, report generation, AI-visibility scoring)
- Authenticating you and securing your account
- Billing and subscription management
- Security, fraud prevention, and audit logging
- Monitoring and improving service reliability (error telemetry via Application Insights, aggregate product analytics via Umami)
- Sending transactional communications (email verification, password reset, organisation invitations, report and notification delivery)
- Complying with legal obligations, including financial record-keeping
We do not currently operate a marketing mailing list. If we introduce one, it will be opt-in, and we will update this policy before doing so.
7. Legal Bases for Processing (GDPR)
| Purpose | Data Used | Lawful Basis |
|---|---|---|
| Account management and authentication | Name, email, password hash, session token | Performance of contract — Art. 6(1)(b) |
| Providing the SEO, audit, and AI-visibility service | Keywords, domains, SERP snapshots, ranking data, competitor data, audit results, reports | Performance of contract — Art. 6(1)(b) |
| Billing and payment processing | Email, subscription status, billing method | Performance of contract — Art. 6(1)(b); legal obligation — Art. 6(1)(c) |
| Security, fraud prevention, audit logging | IP address, session data, usage events, audit log | Legitimate interest — Art. 6(1)(f) |
| Service improvement and error monitoring | Usage data, aggregate product analytics, error telemetry | Legitimate interest — Art. 6(1)(f) |
| Bot detection on registration and password reset | Browser session signals passed to hCaptcha | Legitimate interest — Art. 6(1)(f), protecting the platform from automated abuse |
| Transactional emails | Email address | Performance of contract — Art. 6(1)(b) |
| Preventing repeated abuse of free-trial offers | Keyed, non-reversible hash of the signup email | Legitimate interest — Art. 6(1)(f) |
US state privacy laws do not require an enumerated “legal basis” in the GDPR sense; Section 15 covers the disclosures those laws do require.
9. International Transfers of Personal Data
Our infrastructure and primary data storage are located in the European Union. Several sub-processors listed in Section 8 are located in, or process data in, the United States. Where we transfer personal data originating in the EEA, UK, or Switzerland to a country not deemed to provide an adequate level of protection, we rely on the EU Standard Contractual Clauses — and the UK International Data Transfer Addendum where applicable — with each such sub-processor, together with supplementary technical and organisational measures where warranted.
11. How Long We Keep Your Information
Retention is enforced automatically by a nightly job. The windows marked configurable are set by an environment variable and may be shortened or lengthened; the values below are the defaults in force.
| Data Category | Retention Period |
|---|---|
| Active sessions | Expire 7 days after they were last refreshed; expired session records are purged by the nightly job |
| Verification tokens (email verification, password reset) | Deleted 7 days after the token itself expires — a short grace period for delivery delays |
| Keyword and SERP snapshots | 365 days (configurable); older records purged automatically |
| Site audit data (audit runs, crawled pages, issues, backlink snapshots) | 90 days (configurable); older records purged automatically |
| AI-visibility LLM responses (raw response text and archived response objects) | 90 days (configurable). The citations, mentions, and computed visibility scores derived from a response are retained separately on the keyword/SERP snapshot schedule above, since they no longer contain the underlying response text |
| Usage snapshots (plan and quota accounting) | 400 days (configurable) |
| Payment-provider webhook events | 30 days (configurable) |
| Audit log | Retained for as long as the organisation exists. Entries are anonymised when a user deletes their account, and deleted outright when the organisation is deleted (Section 17) |
| Account data (name, email, organisation memberships) | Deleted when an account-deletion request is processed (Section 17) |
| Organisation data (projects, keywords, rankings, reports, audits, integrations) | Deleted when an organisation-deletion request is processed (Section 17) |
| Billing and subscription records | 7 years from the transaction, in compliance with legal accounting and tax obligations — Art. 6(1)(c) GDPR |
| Trial-eligibility ledger (a keyed, non-reversible HMAC hash of the email that started a free trial) | Retained indefinitely, including after organisation deletion — legitimate interest, Art. 6(1)(f), preventing repeated abuse of free-trial offers |
12. How We Protect Your Information
- Passwords are stored only as salted scrypt hashes, never in plaintext.
- Integration access tokens and SERP-provider credentials are encrypted at rest with AES-256-GCM before being written to the database, and are decrypted only inside the relevant connector code — never in application route handlers.
- Report share tokens are generated with a cryptographically secure random number generator and compared using a timing-safe comparison, to resist both guessing and timing attacks.
- Every business record is scoped to an organisation. Every query against tenant data enforces that scope, and every mutating action requires an explicit permission check, so one customer's data is not reachable from another customer's session.
- Requests that change data are validated against the request origin to prevent cross-site request forgery.
- Data in transit is encrypted using TLS.
- Sensitive account actions are rate-limited, and all password reset events revoke every existing session for that account.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your account credentials confidential.
13. Children's Privacy
Rankori is a business-to-business platform intended for professional use by adults. It is not directed to, and we do not knowingly collect personal information from, individuals under 16. If we learn that we have inadvertently collected such information, we will delete it. Contact contact@nuramidigital.com if you believe a child has provided us with personal information.
14. Your Privacy Rights — GDPR / UK / Switzerland
If you are located in the EEA, UK, or Switzerland, you have the following rights:
- Right of access (Art. 15): a copy of the personal data we hold about you.
- Right to rectification (Art. 16): correction of inaccurate or incomplete personal data.
- Right to erasure (Art. 17): deletion of your personal data where no overriding ground exists for us to continue processing it. Billing records are retained for the legally required 7-year period even after account deletion.
- Right to data portability (Art. 20): a machine-readable copy of the personal data you provided to us.
- Right to restriction of processing (Art. 18): restriction of processing in certain circumstances, such as while a rectification request is being resolved.
- Right to object (Art. 21): objection to processing carried out on the basis of legitimate interest. We will stop unless we can demonstrate compelling legitimate grounds that override your interests.
- Right to withdraw consent (Art. 7(3)): where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.
- Right to lodge a complaint: with your local supervisory authority. For the Netherlands this is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl). You may also contact the authority in your own country of residence.
To exercise any of these rights, contact contact@nuramidigital.com. We aim to respond within 30 days.
15. Your Privacy Rights — US State Privacy Laws
If you are a resident of California, Virginia, Colorado, Connecticut, Utah, or another US state with a comprehensive consumer privacy law, that law generally gives you the right to:
- Know and access — request what personal information we have collected about you and why.
- Delete — request deletion of your personal information, subject to legal exceptions such as our 7-year billing-record retention obligation.
- Correct — request correction of inaccurate personal information.
- Data portability — receive your personal information in a portable format.
- Opt out of sale or sharing — as stated in Section 8, we do not sell personal information and do not share it for cross-context behavioral advertising. There is accordingly nothing to opt out of; we describe the right for completeness and will honour it if our practices ever change.
- Opt out of targeted advertising — we do not serve targeted advertising, so this right is likewise not currently engaged.
- Limit the use of Sensitive Personal Information — we do not collect Sensitive Personal Information as defined under the CPRA, such as government identification numbers, precise geolocation, health data, or biometric data, in the ordinary operation of the Services.
- Non-discrimination — we will not discriminate against you for exercising any of these rights.
- Appeal — if we decline a request, you may appeal, and our decision will explain how.
How to exercise these rights: email contact@nuramidigital.com. We will verify your identity, typically by confirming that you control the account email address, before acting on the request. We will respond within 45 days, extendable once by a further 45 days where permitted by law. You may use an authorised agent to submit a request on your behalf; we may require proof of that agent's authorisation.
16. Do-Not-Track and Global Privacy Control Signals
Some browsers offer a “Do Not Track” (DNT) signal. There is no accepted industry standard for how a website must respond to it, and we do not currently treat DNT traffic differently. Because we neither sell nor share personal information and serve no targeted advertising, a Global Privacy Control (GPC) signal has no substantive effect on our processing today. We will treat a GPC signal as a valid opt-out of sale or sharing under the CCPA/CPRA if our practices ever change to include either.
17. Data Deletion
Account deletion
You may delete your Rankori account at any time:
- In-app: use “Delete my account” in Account Settings and confirm when prompted.
- By contacting us: email contact@nuramidigital.com and we will process your request within 30 days.
If you are the sole owner of an organisation, that organisation must first be transferred to another owner or deleted — we will tell you which organisations are blocking the request. This protects the other members of the organisation and any data they rely on.
Once an account deletion completes:
- Your name, email address, credentials, and active sessions are permanently deleted.
- Any outstanding email-verification and password-reset tokens for your address are deleted.
- Existing audit log entries that referenced you are anonymised — your user identifier is replaced with a non-identifying placeholder — so the security record of what happened survives without remaining linked to you.
- Billing and subscription records are retained for 7 years as required by law, and are no longer associated with a live account.
- Organisation data is not deleted by deleting your account. Keywords, rankings, reports, audits, and integrations belong to the organisation rather than to you individually, and remain available to its other members. To remove that data, delete the organisation itself.
Organisation deletion
An organisation owner may permanently delete an organisation and all of its data via “Delete Organisation” in the organisation's Settings, confirming by typing the organisation's identifier. An organisation with an active subscription must be cancelled first.
Deletion is processed as a background job shortly after the request. Once complete:
- All projects, keywords, rankings, reports, site audits, integrations, prompt libraries, and AI-visibility runs belonging to the organisation are permanently deleted.
- Uploaded files and generated exports — branding logos, report PDFs and PowerPoint files, and archived raw LLM responses — are deleted from object storage.
- The organisation's audit log is deleted outright.
- Retained by design: billing and subscription records (7 years, as above), usage snapshots used for plan and quota accounting, and the trial-eligibility ledger entry described below.
- The trial-eligibility ledger keeps a keyed, non-reversible hash derived from the email address that started the free trial. It does not identify you directly, cannot be reversed back into your email address, and exists solely to stop the same person from obtaining unlimited free trials by repeatedly creating and deleting organisations. This is retained under our legitimate interest in preventing abuse of free-trial offers (Art. 6(1)(f) GDPR).
18. Data Portability
You can download a copy of your personal data at any time:
- In-app: use “Download my data” in Account Settings. This produces a
rankori-data-export.jsonfile. - By contacting us: email contact@nuramidigital.com.
The export contains the personal data we hold about you: your profile (identifier, name, email address, and account creation date), every organisation you belong to (name, identifier, your role, and the date you joined), and a per-organisation summary of the data associated with your memberships, given as counts of keywords, tracked competitors, and reports.
It does not include raw keyword or SERP data, site audit results, report contents, or payment records. That material is operational business data belonging to the organisation rather than personal data about you, and is available to organisation members directly inside the platform. If you need it in another form, contact us.
19. Governing Law
For personal data of individuals in the EEA, UK, or Switzerland, this policy and our processing are governed by the GDPR (Regulation (EU) 2016/679) and applicable national implementing legislation. For personal information of US residents, the applicable US state privacy law governs the rights described in Section 15. Our operations are based in the European Union.
20. Changes to This Policy
We may update this policy from time to time to reflect changes in our practices, technologies, legal requirements, or other operational reasons.
For material changes — changes that affect how we use your personal data, or that reduce your rights — we will notify you by email to the address associated with your account, and by a notice in the platform, at least 14 days before the change takes effect. Minor or editorial changes update the version and date above without individual notice.
If you continue to use Rankori after a material change takes effect, we will take that as acknowledgement of the updated policy. If you do not agree with the changes, you may delete your account before they take effect.
21. Contact Us
Email: contact@nuramidigital.com
Subject line: “Data Protection Request — [Your Name]”
We aim to respond to all requests within 30 days, or within the statutory period that applies under Sections 14 and 15.