Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the Master Subscription Agreement between Hoozi Enterprises LLC, a Wyoming limited liability company doing business as AI Rankly ("AI Rankly"), and Customer. It applies where AI Rankly processes personal data on Customer's behalf.
For that processing, Customer is the controller and AI Rankly is the processor. Where Customer is itself a processor for its own client, AI Rankly is a sub-processor and this DPA applies accordingly.
1. Definitions
"Applicable Data Protection Law" means the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, and any other privacy law applicable to the processing. "Controller", "processor", "sub-processor", "data subject", "personal data" and "processing" have the meanings given in the GDPR.
2. Subject matter and nature of the processing
Subject matter: provision of the AI Rankly platform. Duration: the term of the subscription, plus the retention period in section 9. Nature and purpose: hosting, storing, analysing and displaying data so that Customer can measure and improve its visibility in AI answer engines.
3. Categories of data subject and personal data
The personal data processed is limited and largely incidental. It comprises:
- Account users: name, business email address, password hash, role and permissions, and product usage and audit logs
- Billing contacts: name, business email, billing address and payment metadata (card details are handled by our payment processor and do not reach our systems)
- Personal data appearing incidentally inside Customer Data: for example a founder's or executive's name appearing in a tracked prompt, in an AI-generated answer, in a cited source page, or in outreach contact records the Customer chooses to store
4. Special category data
The Service is not designed for special categories of personal data as defined in GDPR Article 9, nor for children's data. Customer agrees not to submit such data through the Service. If Customer does so, it does so on its own responsibility and must have a lawful basis for it.
5. Our obligations as processor
AI Rankly will:
- process personal data only on Customer's documented instructions, which include this DPA, the Agreement, and Customer's use of the product's features, unless required otherwise by law, in which case we will inform Customer unless the law prohibits it. Section 7.1 describes the one activity carried out for our own purposes, and it operates on de-identified data rather than personal data
- ensure that personnel authorised to process personal data are bound by confidentiality
- implement the technical and organisational measures described in section 8
- assist Customer, taking into account the nature of the processing, in responding to data subject requests, and in meeting its obligations under GDPR Articles 32 to 36
- make available the information necessary to demonstrate compliance with Article 28, and allow for and contribute to audits as set out in section 10
- notify Customer without undue delay after becoming aware of a personal data breach affecting Customer's personal data, with the information available at the time and updates as the investigation proceeds
6. Customer's obligations as controller
Customer is responsible for the lawfulness of the personal data it submits and of our processing of it on its instructions. That includes having a lawful basis, providing any required notice to data subjects, and not instructing us to process data in a way that breaches Applicable Data Protection Law.
7. Sub-processors
Customer gives AI Rankly general written authorisation to engage sub-processors. We impose data protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain liable for their performance.
Our current sub-processors are listed below. We will give at least thirty days' notice before adding or replacing one, and Customer may object on reasonable data protection grounds, in which case the parties will work in good faith to find a resolution. If none is available, Customer may terminate the affected subscription and receive a refund of prepaid fees for the remaining term.
| Sub-processor | Purpose | Location |
|---|---|---|
| Vercel Inc. | Application and website hosting | United States |
| Google LLC | Website analytics (Google Analytics 4) | United States |
| Stripe, Inc. | Subscription billing and payment processing | United States |
| HubSpot, Inc. | Demo scheduling and customer relationship management | United States |
7.1 Aggregated data and model training
AI Rankly derives aggregated and de-identified data from operating the Service and uses it to train and improve its own internal models. This is set out in section 5.1 of the Master Subscription Agreement.
The boundary matters for this DPA, so to state it plainly: AI Rankly does not train its models on personal data processed on Customer's behalf. De-identification is applied before any data enters a training process, and AI Rankly does not attempt to re-identify it. Once data has been aggregated and de-identified to that standard it is no longer personal data, and Applicable Data Protection Law does not apply to it.
To the extent any residual processing required to produce aggregated data is regarded as processing for AI Rankly's own purposes, AI Rankly acts as controller for that limited activity, relies on its legitimate interest in maintaining and improving the accuracy of the Service, and remains bound by the commitments in section 5.1 of the Agreement, including that no model output surfaces one customer's content or identity to another.
Enterprise Customers may opt out of contributing to model training in their order form.
| Sub-processor | Purpose | Location |
|---|---|---|
| Vercel Inc. | Application and website hosting | United States |
| Google LLC | Website analytics (Google Analytics 4) | United States |
| Stripe, Inc. | Subscription billing and payment processing | United States |
| HubSpot, Inc. | Demo scheduling and customer relationship management | United States |
8. Security
Taking into account the state of the art and the risks presented, we maintain technical and organisational measures appropriate to the processing, including: encryption of data in transit using TLS and at rest; role-based access control with least privilege; multi-factor authentication for administrative access; network isolation and secrets management; logging and monitoring of access to production systems; regular dependency and vulnerability patching; and background-checked personnel bound by confidentiality.
Security enquiries and vulnerability reports: security@airankly.io.
9. Retention, return and deletion
We retain personal data for as long as the account is active. Customer may export its data at any time. On termination, we make the data available for export for thirty days, after which we delete or irreversibly de-identify it within ninety days, except where retention is required by law, in which case we isolate it and stop active processing.
Backups are deleted on their ordinary rolling cycle, which does not exceed thirty five days.
10. Audits
On reasonable written request, and no more than once in any twelve month period unless required by a supervisory authority or following a personal data breach, we will provide the information reasonably necessary to demonstrate compliance with this DPA. Where Customer requires an on-site audit, the parties will agree scope, timing and cost in advance, and the auditor must be bound by confidentiality and must not be a competitor of AI Rankly.
11. International transfers
AI Rankly and its sub-processors are located in the United States. Where personal data is transferred from the European Economic Area, the United Kingdom or Switzerland, the transfer is made under the European Commission's Standard Contractual Clauses (Decision 2021/914), Module Two (controller to processor) or Module Three (processor to processor) as applicable, together with the UK International Data Transfer Addendum where the UK GDPR applies. Those clauses are incorporated into this DPA by reference and prevail over it in the event of conflict.
AI Rankly will carry out and document a transfer impact assessment on request and will implement supplementary measures where required.
12. Liability
Each party's liability under this DPA is subject to the limitations and exclusions in the Agreement.
13. Contact
Data protection enquiries: privacy@airankly.io. We have not appointed a Data Protection Officer, as we do not meet the criteria in GDPR Article 37; enquiries are handled by our privacy contact.
Hoozi Enterprises LLC, a Wyoming limited liability company doing business as AI Rankly. 1021 E Lincolnway, Suite 7103, Cheyenne, WY 82001. Questions about this document: legal@airankly.io.