Data Processing Agreement
This Data Processing Agreement governs how RankGrow processes customer personal data on behalf of customers when providing the RankGrow service.
Last updated: June 1, 2026
This Data Processing Agreement ("DPA") forms part of the agreement between RankGrow and the customer using the Service ("Customer", "you", or "Controller"). It applies when RankGrow processes Customer Personal Data on behalf of Customer as a processor under applicable data protection laws, including the GDPR.
The Service is provided by:
Bartosz Zagrodzki
Operating under the brand name RankGrow
Country of establishment: Poland
Email: hello@rankgrow.io
By using the Service for business, organization, website, client, or workspace data, you agree to this DPA. This DPA supplements our Terms of Service and Privacy Policy. If there is a conflict between this DPA and the Terms of Service regarding the processing of Customer Personal Data, this DPA controls.
1. Definitions
Capitalized terms not defined in this DPA have the meanings given in the Terms of Service or applicable data protection law.
- "Applicable Data Protection Laws" means all privacy, data protection, and data security laws applicable to the processing of Customer Personal Data, including the GDPR, UK GDPR, Swiss Federal Act on Data Protection, ePrivacy rules, and applicable US state privacy laws.
- "Controller" means the party that determines the purposes and means of processing Customer Personal Data.
- "Customer Personal Data" means personal data that Customer submits, connects, uploads, or otherwise makes available to RankGrow through the Service, and that RankGrow processes on Customer's behalf as processor.
- "Data Subject" means an identified or identifiable natural person.
- "GDPR" means Regulation (EU) 2016/679.
- "Personal Data Breach" means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data.
- "Processor" means the party that processes personal data on behalf of a controller.
- "SCCs" means the Standard Contractual Clauses adopted by the European Commission for international personal data transfers.
- "Service" means RankGrow's website, application, SEO tools, AI features, integrations, subscriptions, credits, support, and related services.
- "Subprocessor" means a third party engaged by RankGrow to process Customer Personal Data on behalf of Customer.
2. Roles and Scope
For Customer Personal Data, Customer is the Controller and RankGrow is the Processor.
This DPA applies only to Customer Personal Data processed by RankGrow on behalf of Customer. It does not apply to personal data for which RankGrow acts as an independent controller, such as account registration data, billing records, direct support communications, marketing preferences, product analytics, security logs, and legal compliance records. Those processing activities are described in the Privacy Policy.
Customer is responsible for determining whether it acts as a controller, joint controller, processor, or other role for any data it submits to the Service. Customer is also responsible for its own customer, employee, contractor, end-user, and client relationships.
3. Processing Details
The subject matter, duration, nature, purpose, categories of data, and categories of data subjects are described in Annex I.
RankGrow will process Customer Personal Data only to provide, secure, maintain, support, and improve the Service, and only as instructed by Customer through:
- The Terms of Service, this DPA, and any applicable order or written agreement.
- Customer's use, configuration, prompts, requests, integrations, workspace settings, and instructions in the Service.
- Written instructions accepted by RankGrow.
- Requirements of applicable law.
RankGrow will inform Customer if, in RankGrow's reasonable opinion, an instruction violates Applicable Data Protection Laws, unless prohibited from doing so by law.
4. Customer Obligations
Customer represents and warrants that:
- Customer has all rights, permissions, notices, consents, and lawful bases required to submit Customer Personal Data to the Service and instruct RankGrow to process it.
- Customer will use the Service in compliance with Applicable Data Protection Laws.
- Customer will not submit special category data, sensitive personal data, children's data, payment card data, government identifiers, health data, or similarly sensitive data unless the Service documentation expressly supports that use and Customer has a valid legal basis to do so.
- Customer will provide legally required privacy notices to Data Subjects.
- Customer will respond to Data Subject requests and regulator requests for which Customer is responsible.
- Customer will configure integrations, users, roles, permissions, exports, sharing settings, and retention practices appropriately.
- Customer will ensure it is authorized to connect each Google account, Search Console property, website, domain, organization, client account, or third-party integration.
Customer is responsible for reviewing AI outputs, SEO recommendations, generated tasks, exports, and reports before using or sharing them.
5. RankGrow Processor Obligations
RankGrow will:
- Process Customer Personal Data only on Customer's documented instructions.
- Ensure that persons authorized to process Customer Personal Data are bound by confidentiality obligations.
- Implement and maintain appropriate technical and organizational measures described in Annex II.
- Assist Customer with Data Subject requests as described in Section 8.
- Assist Customer with security, breach, data protection impact assessment, and consultation obligations where required by Applicable Data Protection Laws and taking into account the nature of processing and information available to RankGrow.
- Use Subprocessors only as described in Section 7.
- Delete or return Customer Personal Data as described in Section 10.
- Make available information reasonably necessary to demonstrate compliance as described in Section 11.
6. Security Measures
RankGrow will implement appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.
Current measures are described in Annex II and include, as applicable:
- Encryption in transit.
- Encryption or cryptographic protection for sensitive OAuth credentials.
- Access controls and least-privilege access.
- Authentication and session controls.
- Logging, monitoring, and error tracking.
- Backup and recovery procedures.
- Subprocessor review and contractual controls.
- Incident response procedures.
Customer acknowledges that security measures may evolve over time, provided that RankGrow does not materially reduce the overall protection of Customer Personal Data.
7. Subprocessors
Customer grants RankGrow general authorization to engage Subprocessors to provide the Service.
Current Subprocessors and Subprocessor categories are listed in Annex III. RankGrow will impose data protection obligations on each Subprocessor that are no less protective, in substance, than those in this DPA, to the extent applicable to the Subprocessor's services.
RankGrow remains responsible for Subprocessors' processing of Customer Personal Data to the extent required by Applicable Data Protection Laws.
RankGrow may add or replace Subprocessors from time to time. RankGrow will provide notice by updating this DPA, the Privacy Policy, a subprocessors page if available, or by other reasonable means such as email or in-app notice for material changes.
Customer may object to a new Subprocessor on reasonable data protection grounds by contacting hello@rankgrow.io within 15 days of notice. If RankGrow cannot reasonably address the objection, Customer may stop using the affected feature or terminate the affected Service according to the Terms of Service.
8. Data Subject Requests
Customer is responsible for responding to Data Subject requests relating to Customer Personal Data.
To the extent Customer cannot fulfill a request using the Service, RankGrow will provide reasonable assistance, taking into account the nature of processing and information available to RankGrow. Requests for assistance should be sent to hello@rankgrow.io.
If RankGrow receives a request directly from a Data Subject relating to Customer Personal Data, RankGrow may direct the Data Subject to Customer unless prohibited by law. RankGrow will not independently respond to the request except as required by law or authorized by Customer.
9. Personal Data Breach
RankGrow will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.
Where reasonably possible, the notice will include:
- A description of the nature of the breach.
- The categories and approximate number of affected Data Subjects and records, if known.
- The likely consequences of the breach, if known.
- Measures taken or proposed to address the breach.
- Information reasonably available to help Customer meet notification obligations.
RankGrow may provide information in phases as it becomes available. RankGrow's notification of a Personal Data Breach is not an admission of fault or liability.
Customer is responsible for determining whether it must notify regulators, Data Subjects, customers, or other parties, unless Applicable Data Protection Laws require RankGrow to make a notification directly.
10. Deletion and Return
During the term of the Service, Customer may access, export, delete, or modify certain Customer Personal Data through the Service where features allow.
Upon termination of the Service or upon Customer's written request, RankGrow will delete or return Customer Personal Data within a reasonable period, unless retention is required or permitted by law, necessary for legal claims, security, fraud prevention, financial records, backups, or otherwise described in the Privacy Policy.
Backups containing Customer Personal Data are deleted or overwritten according to standard backup rotation, typically within 90 days.
RankGrow is not required to delete Customer Personal Data retained in anonymized, aggregated, or de-identified form that no longer identifies Customer or Data Subjects.
11. Audits and Compliance Information
RankGrow will make available information reasonably necessary to demonstrate compliance with this DPA, subject to confidentiality, security, and legal restrictions.
Where required by Applicable Data Protection Laws, Customer may request an audit no more than once per 12 months, unless a Personal Data Breach or regulator request justifies an additional audit. Audits must:
- Be requested with at least 30 days' written notice.
- Be limited to the processing of Customer Personal Data.
- Occur during normal business hours.
- Avoid unreasonable disruption to RankGrow's operations.
- Be conducted by personnel or auditors bound by confidentiality.
- Not compromise the security, privacy, or confidentiality of other customers, systems, or Subprocessors.
RankGrow may satisfy audit requests by providing security documentation, policies, summaries, third-party reports, questionnaires, or written responses. On-site audits are permitted only where legally required and where remote documentation is insufficient.
Customer is responsible for its own audit costs and will reimburse RankGrow for reasonable costs of support for audits that are unusually broad, frequent, or time-consuming, unless prohibited by law.
12. International Transfers
RankGrow is established in Poland, but the Service may involve transfers of Customer Personal Data to countries outside the European Economic Area, United Kingdom, or Switzerland, including the United States.
Where RankGrow transfers Customer Personal Data internationally, RankGrow will use appropriate transfer mechanisms as required by Applicable Data Protection Laws, such as:
- Adequacy decisions.
- EU-US Data Privacy Framework, UK Extension, or Swiss-US Data Privacy Framework where applicable.
- Standard Contractual Clauses.
- UK International Data Transfer Addendum or UK International Data Transfer Agreement.
- Supplementary measures where required.
If SCCs are required for a transfer from Customer to RankGrow, the parties incorporate the SCCs as follows:
- Module Two (Controller to Processor) applies where Customer is a controller and RankGrow is a processor.
- Module Three (Processor to Processor) applies where Customer is a processor and RankGrow is a subprocessor.
- Clause 7 optional docking clause applies.
- Clause 9 Option 2 general written authorization for Subprocessors applies, with notice as described in Section 7.
- Clause 11 optional language does not apply.
- For Clause 17 and Clause 18, the governing law and forum will be Poland, unless the SCCs require otherwise.
- Annexes I, II, and III of this DPA serve as the SCC annexes.
For UK transfers, the SCCs are modified by the UK International Data Transfer Addendum. For Swiss transfers, references to the GDPR include the Swiss Federal Act on Data Protection where applicable, and the Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority where required.
13. Google API Data
If Customer connects Google Search Console, RankGrow processes Google API data only as necessary to provide requested Search Console, URL inspection, SEO analysis, chat, task, and reporting features.
RankGrow's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including Limited Use requirements.
RankGrow will not:
- Sell Google user data.
- Use Google user data for advertising.
- Use Google user data to train generalized AI models.
- Allow humans to read Google user data except where necessary for security, support, legal compliance, debugging, or with Customer's consent.
Customer is responsible for ensuring it has authority to connect each Google account and Search Console property and for honoring any obligations it has to its own users, clients, or Data Subjects.
14. AI Processing
RankGrow uses AI features to provide SEO analysis, chat responses, recommendations, summaries, and tasks.
When Customer uses AI features, RankGrow may send relevant prompts, messages, website data, Search Console excerpts, tool results, and context to AI Subprocessors. RankGrow uses those Subprocessors only to provide the requested feature and related Service functionality.
RankGrow does not use Customer Personal Data or Google user data to train generalized AI models. Customer acknowledges that AI outputs may contain Customer Personal Data if Customer includes such data in prompts, connected sources, or context.
Customer is responsible for deciding what Customer Personal Data to submit to AI features and for reviewing generated outputs before using or sharing them.
15. US State Privacy Laws
Where US state privacy laws apply and Customer is a "business" or "controller" and RankGrow is a "service provider", "contractor", or "processor", RankGrow will:
- Process Customer Personal Data only for the business purposes described in this DPA and the Terms of Service.
- Not sell Customer Personal Data.
- Not share Customer Personal Data for cross-context behavioral advertising.
- Not retain, use, or disclose Customer Personal Data outside the direct business relationship except as permitted by applicable law.
- Assist Customer with consumer requests as required by applicable law.
- Require Subprocessors to comply with applicable obligations.
16. Liability
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service or other applicable written agreement, except to the extent such limitations are prohibited by Applicable Data Protection Laws.
17. Term and Termination
This DPA remains in effect for as long as RankGrow processes Customer Personal Data on behalf of Customer.
Upon termination of the Terms of Service or the applicable service agreement, this DPA will terminate after RankGrow deletes or returns Customer Personal Data as described in Section 10, except for provisions that by their nature should survive, including confidentiality, security, deletion, audit, transfer, and liability provisions.
18. Governing Law
This DPA is governed by the laws of Poland, unless Applicable Data Protection Laws require otherwise.
The parties submit to the jurisdiction described in the Terms of Service, subject to mandatory rights under Applicable Data Protection Laws and the SCCs where applicable.
19. Contact
For questions about this DPA or data processing, contact:
RankGrow
Bartosz Zagrodzki
Email: hello@rankgrow.io
Annex I: Processing Details
A. Parties
Customer / Controller: The individual, company, organization, agency, or other legal entity using the Service and determining the purposes and means of processing Customer Personal Data.
RankGrow / Processor: Bartosz Zagrodzki operating under the brand name RankGrow.
B. Subject Matter
Provision of RankGrow's AI-assisted SEO platform, including website analysis, Google Search Console integration, AI chat, SEO recommendations, task generation, reporting, subscriptions, support, security, and related Service functionality.
C. Duration
For the term of Customer's use of the Service and until Customer Personal Data is deleted or returned according to this DPA, the Terms of Service, and the Privacy Policy.
D. Nature and Purpose of Processing
RankGrow may collect, receive, store, host, retrieve, query, transmit, analyze, generate, transform, display, delete, and otherwise process Customer Personal Data to:
- Provide SEO analysis and recommendations.
- Operate Google Search Console integration.
- Query and inspect Search Console properties and URLs.
- Crawl and analyze websites and public web pages.
- Generate AI chat responses, summaries, task lists, and reports.
- Manage organizations, websites, members, roles, and permissions.
- Provide usage credits, limits, and billing-related feature access.
- Provide support, troubleshooting, security, logging, monitoring, and abuse prevention.
- Comply with Customer instructions, legal obligations, and the Terms of Service.
E. Categories of Data Subjects
Depending on Customer's use of the Service, Customer Personal Data may relate to:
- Customer's employees, contractors, representatives, and team members.
- Customer's clients and client representatives.
- Website owners, authors, editors, contributors, or contacts.
- Users or visitors reflected in Google Search Console or other connected datasets.
- Individuals whose personal data appears in prompts, pages, URLs, page content, metadata, chat messages, tasks, notes, exports, reports, or connected sources.
F. Categories of Customer Personal Data
Depending on Customer's use of the Service, Customer Personal Data may include:
- Names, email addresses, avatars, roles, organization membership, and account identifiers.
- Organization names, website domains, URLs, sitemap URLs, competitors, markets, notes, task data, and workflow metadata.
- Chat messages, prompts, instructions, uploaded or pasted text, tool outputs, generated outputs, and reports.
- Google account profile data, OAuth connection metadata, Search Console property identifiers, query data, page data, device and country data, clicks, impressions, CTR, average position, URL inspection results, crawl status, indexing data, and related metadata.
- Public page content, headings, metadata, links, schema, robots directives, technical SEO findings, and crawl results.
- Usage metadata, feature interactions, request metadata, logs, error reports, IP addresses, device data, and user agent data where processed on Customer's behalf.
G. Sensitive Data
The Service is not designed for processing special categories of personal data, sensitive personal information, payment card data, health data, government identifiers, children's data, or criminal offense data. Customer must not submit such data unless expressly agreed in writing and supported by appropriate safeguards.
Annex II: Technical and Organizational Measures
RankGrow maintains technical and organizational measures appropriate to the nature, scope, context, and purposes of processing, including:
- Encryption in transit: HTTPS/TLS for data transmitted between users, the Service, and relevant APIs.
- Credential protection: Sensitive OAuth tokens are encrypted or cryptographically protected before storage where supported by the Service.
- Access controls: Access to production systems and Customer Personal Data is restricted to authorized personnel and service accounts with a business need.
- Authentication: Account access uses authenticated sessions and may support social login, magic links, and two-factor authentication features.
- Authorization: Organization roles and permissions help restrict user access within customer workspaces.
- Least privilege: Internal access is limited based on role and need.
- Logging and monitoring: Logs, error monitoring, and operational telemetry are used to detect and investigate reliability and security issues.
- Backups and recovery: Backups are maintained to support recovery from accidental loss or service incidents.
- Network and infrastructure security: The Service is hosted with reputable cloud and infrastructure providers that maintain physical, network, and operational security measures.
- Subprocessor controls: Subprocessors are reviewed for appropriate security and contractual commitments.
- Incident response: Procedures are maintained to identify, investigate, mitigate, and notify about security incidents.
- Data minimization: RankGrow seeks to process only data needed to provide requested features.
- Separation of environments: Development and production practices are designed to reduce unauthorized access to production data.
- Confidentiality: Personnel with access to Customer Personal Data are bound by confidentiality obligations.
Annex III: Subprocessors
RankGrow uses the following Subprocessors and categories to provide the Service. Specific vendors may change as the Service evolves.
| Subprocessor or category | Purpose | Data processed | Location / transfer safeguard |
|---|---|---|---|
| Vercel or other hosting providers | Application hosting, deployment, edge/network services | Customer Personal Data, request data, technical data | EU/US or other regions; DPF, SCCs, or other safeguards where applicable |
| Managed PostgreSQL database provider, such as Neon | Primary application database | Account, organization, chat, task, integration, OAuth metadata, and workspace data | EU/US or other regions; DPF, SCCs, or other safeguards where applicable |
| Stripe | Payment processing, subscriptions, invoices, fraud prevention | Billing identifiers, transaction metadata, subscription status, contact and payment data | DPF, SCCs, or other safeguards where applicable |
| Resend or email delivery providers | Transactional and service emails | Email addresses, names, email content, delivery metadata | DPF, SCCs, or other safeguards where applicable |
| Google APIs | Google OAuth and Search Console integration | Google profile data, OAuth tokens, Search Console data | Google transfer safeguards and API terms |
| Anthropic | AI model routing and generation | Prompts, messages, relevant context, tool results, model usage metadata | DPF, SCCs, or other safeguards where applicable |
| DataForSEO | SEO metrics, keyword data, SERP data, backlink data, competitor data | Public domains, URLs, keywords, SEO queries, tool inputs and outputs | SCCs or other safeguards where applicable |
| Firecrawl, Jina AI, Exa, Serper, or similar web data providers | Web search, page reading, crawling, and public web retrieval | URLs, public page content, search queries, crawl metadata | DPF, SCCs, or other safeguards where applicable |
| PostHog | Product analytics, feature analytics, event tracking | Usage events, identifiers, device data, session metadata | DPF, SCCs, or other safeguards where applicable |
| Sentry or monitoring providers | Error monitoring, logs, performance diagnostics | Error reports, stack traces, request metadata, IP address | DPF, SCCs, or other safeguards where applicable |
| Object storage providers | File or asset storage where applicable | Uploaded or generated files and metadata | DPF, SCCs, or other safeguards where applicable |
Annex IV: Customer Instructions
Customer instructs RankGrow to process Customer Personal Data as necessary to:
- Provide the Service selected and configured by Customer.
- Process prompts, chats, integrations, websites, Search Console data, tasks, reports, and generated outputs.
- Use Subprocessors listed in Annex III.
- Transfer Customer Personal Data as described in Section 12.
- Secure, monitor, troubleshoot, and support the Service.
- Comply with applicable law and valid legal process.
Customer may provide additional instructions by configuring the Service or contacting hello@rankgrow.io. RankGrow may decline instructions that are outside the scope of the Service, technically infeasible, unlawful, or would materially increase risk or cost without a separate written agreement.