# Data Processing Agreement (DPA)

Effective Date: February 26, 2026

## 1. Introduction and Applicability

This Data Processing Agreement ("DPA") is executed between:

- **Data Controller**: You, the RankWizAI customer ("Customer")
- **Data Processor**: RankWizAI and its affiliates ("Processor" or "we")

This DPA applies when Customer uses RankWizAI in jurisdictions with data protection laws (GDPR, CCPA, LGPD, PIPEDA, etc.) and when personal data is processed in the course of providing the Service.

This DPA supplements the Terms of Service. In the event of conflict, this DPA shall prevail with respect to data processing obligations.

**Applicability**: This DPA is automatically incorporated into the Terms of Service when:
- Customer is located in the EU/EEA (GDPR applies)
- Customer is handling California residents' data (CCPA applies)
- Customer is located in Brazil, Canada, Singapore, Australia, or other jurisdictions with data protection laws

For other jurisdictions without specific data protection requirements, this DPA provides best-practice commitments.

## 2. Scope of Data Processing

### 2.1 Processing Activities

Under the Terms of Service, Customer engages Processor to:

| Processing Activity | Data Categories | Purpose | Lawful Basis (Customer Determines) |
|---|---|---|---|
| **Account and site management** | Account information (name, email) | Create/manage Customer account; link WordPress sites | Performance of contract |
| **Google Search Console sync** | Site domain, GSC property identifiers, search metrics (impressions, clicks, position, CTR, device/country segments) | Retrieve and display search analytics | Performance of contract; legitimate interest |
| **WordPress content inventory** | Post/page titles, URLs, content, metadata, author information | Synchronize content for analysis and publishing | Performance of contract |
| **SEO analysis** | All synchronized data above | Generate findings, recommendations, opportunity detection | Performance of contract |
| **AI content generation** | Page content, keywords, metadata, custom instructions | Generate content rewrite drafts via OpenAI API | Performance of contract |
| **Content publishing** | Post/page content, metadata | Publish/update content on WordPress site via REST API | Performance of contract |
| **Audit logging** | User actions, IP addresses, timestamps, email addresses | Security monitoring, compliance, abuse prevention | Legitimate interest; legal obligation |
| **Service improvement** | Aggregated/anonymized usage metrics, performance data | Analyze trends, debug issues, improve features | Legitimate interest |

### 2.2 Data Categories

Customer may provide or authorize us to access:

- **Account data**: Name, email, password hash, phone number, organization
- **Site connectivity data**: WordPress site URLs, domain names, site descriptions
- **Google Search Console data**: OAuth tokens, search metrics, property information
- **WordPress data**: All published posts, pages, custom post types, media, author metadata
- **Content data**: Page content, custom instructions, analysis parameters
- **Payment data** (if applicable): Billing name, address, email, payment card token (via Stripe)
- **Communication data**: Support emails, tickets, attachments
- **Log data**: IP addresses, user actions, timestamps, browser/device info
- **Credentials**: OpenAI API keys, WordPress HMAC secrets, GSC OAuth tokens

### 2.3 Data Subjects

Personal data may relate to:
- **Account holders** (users of RankWizAI)
- **Administrators** of connected WordPress sites
- **Editors or contributors** whose actions are logged in RankWizAI
- **Website visitors** (indirectly, if their data appears in WordPress posts or GSC metrics)

Customer is responsible for obtaining all necessary consents and providing privacy notices to data subjects.

### 2.4 Duration

Data processing continues for the duration of the subscription, plus 30 days post-termination (soft-delete period), after which data is permanently deleted (except legally required retention).

## 3. Customer as Data Controller

### 3.1 Controller Responsibilities

Customer (as data controller) is responsible for:

1. **Lawful basis**: Determining and documenting the lawful basis for processing (consent, contract, legitimate interest, etc.)
2. **Privacy notices**: Providing privacy notices to data subjects explaining data collection and processing
3. **Data subject rights**: Responding to data subject access, deletion, portability, and objection requests
4. **Consent management**: Obtaining and managing user consent where required
5. **Lawful use of connected data**: Ensuring data collected from GSC, WordPress, and other sources is processed lawfully
6. **Prohibitions**: Not using the Service for unlawful purposes or prohibited uses (see Terms of Service Section 2.3)
7. **Third-party data**: Informing data subjects about Processor's involvement and third-party disclosures

### 3.2 Data Accuracy

Customer is responsible for ensuring the accuracy and completeness of data provided to Processor. Customer will notify Processor of any inaccuracies or if data must be corrected or restricted.

## 4. Processor Obligations

### 4.1 Processing Per Instructions

Processor commits to:

- **Process only per documented instructions**: Data is processed only per Customer's written instructions in the Terms of Service and this DPA. Additional processing requires written authorization.

- **Exception for legal obligations**: Processor may process data if required by law (court order, regulatory request, law enforcement). Processor will notify Customer before complying (unless legally prohibited).

- **No independent use**: Processor will not use Customer data for Processor's own business purposes, marketing, or product development.

### 4.2 Confidentiality

Processor ensures that:

- **Authorized personnel only**: Only employees, contractors, and sub-processors with a need to know access Customer data
- **Confidentiality obligations**: All personnel with access are bound by confidentiality agreements or employment contracts with confidentiality provisions
- **Termination of access**: Upon termination of employment or engagement, access to Customer data is revoked

### 4.3 International Transfers

**Data Transfers from EU/EEA:**

If Customer is located in the EU/EEA or provides personal data of EU/EEA residents, Processor ensures:

1. **Transfer mechanisms**:
   - Transfers to countries with EU adequacy decisions (if applicable)
   - Transfers to third countries governed by Standard Contractual Clauses (SCCs) — EU version as of June 2021
   - Supplementary technical and organizational measures addressing transfer risks (encryption, access controls, data minimization)

2. **Sub-processor transfers**: Processor requires all sub-processors to implement equivalent safeguards

3. **Transfer impact assessment**: Customer may request Processor's assessment of transfer risks; Processor will provide documentation upon reasonable request

4. **Supplementary safeguards**:
   - End-to-end encryption for sensitive credentials (OAuth tokens, API keys)
   - Geofencing or data residency controls (if available)
   - Regular transfer mechanism reviews

**Processor data processing locations:**
- Primary: [INSERT PRIMARY DATA CENTER LOCATION, E.G., "AWS US-EAST-1"]
- Backup: [INSERT BACKUP LOCATION, E.G., "AWS EU-CENTRAL-1"]
- Sub-processors: Google (GSC API), OpenAI (content generation), Stripe (payments), [INSERT HOSTING PROVIDER]

Customer acknowledges and consents to these processing locations.

## 5. Sub-Processors and Sub-Contractors

### 5.1 Sub-Processor List

Processor engages the following sub-processors to assist in providing the Service:

| Sub-Processor | Services | Data Categories | Location |
|---|---|---|---|
| **Google** | Google Search Console API | GSC tokens, search metrics | US/EU |
| **OpenAI** | AI content generation | Page content, keywords, custom instructions, OpenAI API key | US |
| **WordPress** | REST API (your site) | Post/page data, metadata | Your server location |
| **Stripe** | Payment processing | Billing name, email, address, tokenized payment info | US |
| **[Hosting Provider]** | Cloud infrastructure, database hosting | All account and operational data | [INSERT LOCATIONS] |
| **[Email Service Provider]** | Transactional and marketing emails | Name, email, email content | US/EU |
| **[Analytics Provider]** | Usage analytics and monitoring | Anonymized usage data, IP address, device info | [INSERT LOCATION] |

### 5.2 Sub-Processor Changes

Processor may add or replace sub-processors if:

1. Processor provides written notice to Customer at least 30 days before the change
2. Customer has the right to object to new sub-processors based on concerns about:
   - Data protection compliance
   - Security or confidentiality practices
   - Conflict of interest
3. If Customer objects, Customer may:
   - Terminate the affected Service without penalty
   - Request a meeting to discuss concerns
4. If concerns are not resolved, Customer may terminate the entire Service

### 5.3 Sub-Processor Agreements

Processor ensures all sub-processors:

- Execute written data processing agreements (or equivalent contractual commitments)
- Comply with GDPR Article 28 requirements and equivalent protections
- Are bound by confidentiality and security obligations equivalent to Processor's
- Permit audits and inspections by Customer or Customer's auditors

Processor remains liable for sub-processor performance and compliance.

## 6. Data Subject Rights Assistance

### 6.1 Cooperation

Processor will cooperate with Customer in fulfilling data subject rights requests:

| Right | Processor Assistance |
|---|---|
| **Access** | Provide Customer with copies of personal data; Customer is responsible for responding to data subject |
| **Rectification** | Correct or update data upon Customer's written instruction |
| **Deletion/Erasure** | Delete data upon Customer's written instruction, except where legal retention applies |
| **Restriction** | Mark data as restricted upon Customer's instruction; continue processing only for storage unless data subject consents |
| **Portability** | Provide data in machine-readable format (CSV, JSON) upon Customer's instruction and written request from data subject |
| **Objection** | Upon receiving an objection, Processor will temporarily restrict processing pending Customer's instructions |

### 6.2 Timeline

Processor will respond to Customer instructions within:
- **Urgent requests** (security breaches, law enforcement): 24 hours
- **Standard requests** (data access, deletion): 5 business days
- **Complex requests** (large data sets, portability): 15 business days

Customer is responsible for responding to the data subject within applicable legal timelines (30 days for GDPR, 45 days for CCPA, etc.).

## 7. Security and Technical Measures

### 7.1 Security Standards

Processor implements technical and organizational security measures including:

**Access Control:**
- Role-based access control (RBAC); principle of least privilege
- Multi-factor authentication (MFA) for all administrator accounts
- Encryption of credentials used by employees to access systems

**Data Encryption:**
- Encryption in transit: TLS 1.2+ for all data in flight
- Encryption at rest: AES-256-CBC for sensitive credentials (OAuth tokens, API keys, HMAC secrets)
- Database encryption at rest (e.g., AWS RDS encryption, encrypted MySQL)

**Monitoring and Logging:**
- Audit logs of all sensitive operations (login, API calls, data access)
- Intrusion detection and prevention systems (IDS/IPS)
- Database activity monitoring
- Automated alerts for suspicious activity
- Log retention for 30–90 days; older logs purged automatically

**Vulnerability Management:**
- Regular security audits and penetration testing (at least annually)
- Code scanning for vulnerabilities (SAST/DAST)
- Dependency scanning for vulnerable libraries
- Patch management: critical patches applied within 24–48 hours; standard patches within 1–2 weeks

**Business Continuity:**
- Redundant infrastructure and automatic failover
- Database backups: daily, retained for 30 days
- Disaster recovery plan tested annually
- Recovery Time Objective (RTO): [INSERT, E.G., "4 hours"]
- Recovery Point Objective (RPO): [INSERT, E.G., "1 hour"]

**Personnel Security:**
- Background checks for employees with access to data
- Security training and awareness programs
- Confidentiality and non-disclosure agreements
- Restricted access to production systems
- Off-boarding procedures to revoke access

### 7.2 Security Certification

Processor maintains or works toward:
- **[SELECT APPLICABLE]**:
  - SOC 2 Type II certification (annual audit; can be shared with Customer)
  - ISO 27001 certification
  - ISO 27018 (cloud privacy)
  - NIST Cybersecurity Framework compliance

Customer may request current audit reports; Processor will share SOC 2 Type II summaries under NDA.

### 7.3 Limitations

While Processor implements industry-standard security, no system is completely secure. Residual risks include:
- Zero-day vulnerabilities (unknown to the security community)
- Insider threats (employee misconduct, compromised accounts)
- Advanced persistent threats (nation-state or sophisticated attacks)
- Physical attacks on data centers
- Third-party compromises

Customer remains responsible for protecting API keys, OAuth tokens, and account credentials.

## 8. Breach Notification

### 8.1 Processor Obligations

If Processor experiences a confirmed personal data breach, Processor will:

1. **Investigate**: Determine scope, nature, and affected data/individuals within 24 hours of discovery
2. **Notify Customer**: Provide notice to Customer **within 24 hours** of confirmation (or no later than 48 hours), including:
   - Date and time of the breach
   - Data categories and approximate number of affected individuals
   - Likely consequences
   - Measures taken or proposed to address the breach
   - Processor's contact for further information
3. **Preserve evidence**: Maintain forensic evidence; cooperate with law enforcement and regulators
4. **Assist with notification**: Provide Customer with information needed to notify affected individuals and regulators within their legal timelines

### 8.2 Processor Not Liable for Customer Delays

Customer is responsible for notifying affected individuals and regulatory authorities within applicable legal timelines:
- **GDPR**: Within 72 hours of becoming aware
- **CCPA**: Per California regulations
- **Other**: Per applicable jurisdiction

Processor will assist Customer but is not liable if Customer delays notification.

### 8.3 Breach Disclosure

Processor will not publicly disclose the breach without prior written consent from Customer, except:
- As required by law or regulatory order
- To notify affected individuals
- To cooperate with law enforcement

## 9. Audit Rights and Inspections

### 9.1 Audit Rights

Customer may:

1. **Request audit information**: Request documentation of Processor's security practices, data handling procedures, and compliance measures
2. **Conduct audits**: Upon reasonable notice (at least 30 days), conduct on-site audits of Processor's systems and procedures during business hours
3. **Third-party audits**: Engage independent auditors to audit Processor on Customer's behalf; Processor will cooperate

### 9.2 SOC 2 Reports

Processor will provide Customer with a current SOC 2 Type II audit report (if available) under NDA. Such reports satisfy audit rights requirements.

### 9.3 Frequency and Scope

- **Annual audit**: At minimum, Processor will undergo independent security audit (SOC 2 Type II or equivalent) annually
- **Customer-initiated audits**: Customer may conduct no more than one on-site audit per calendar year, except for cause (suspected breach, compliance concern)
- **Emergency audits**: If Processor experiences a breach or regulatory investigation, Customer may request an emergency audit

### 9.4 Costs

- Processor's SOC 2 or equivalent report: Processor bears cost
- Customer-initiated on-site audits: Customer bears reasonable costs (Processor staff time, facility access)
- Third-party auditors: Customer bears cost

## 10. Data Deletion and Return

### 10.1 Upon Termination

Upon termination or expiration of the subscription:

1. **Soft delete period (30 days)**: Data is marked as soft-deleted; Customer may recover data during this period
2. **Permanent deletion (after 30 days)**: All personal data is permanently deleted from production systems, backups, and archives
3. **Exceptions**: Processor may retain data if:
   - Legal obligation requires retention (e.g., tax records, litigation hold)
   - Data is aggregated or anonymized (cannot identify individuals)
   - Data is retained for legitimate interest (e.g., billing records)

### 10.2 Deletion Certification

Upon Customer's request, Processor will provide written certification that all personal data has been deleted, signed by an officer of Processor.

### 10.3 Data Portability

At any time (before or after termination), Customer may request personal data in a portable format:
- **Format**: CSV, JSON, or other structured format
- **Scope**: All personal data collected and processed by Processor
- **Timeline**: Within 15 business days of request
- **Cost**: No charge for first export per year; subsequent exports at Processor's cost recovery rate

## 11. International Data Transfers (Detail)

### 11.1 Standard Contractual Clauses (SCCs)

For transfers from the EU/EEA to countries without adequacy decisions, Processor and Customer execute Standard Contractual Clauses in accordance with:
- **EU SCCs**: Commission Decision 2021/914 (June 2021 version)
- **UK addendum**: UK International Data Transfer Addendum (if UK data is in scope)
- **Correct module**: Module 2 (Controller to Processor) unless Customer is also a processor

### 11.2 Supplementary Transfer Safeguards

To address transfer risks (particularly re: post-Schrems II environment):

**Encryption:**
- Personal data transferred to non-adequate countries is encrypted at rest (AES-256-CBC or stronger)
- Decryption keys are stored separately
- Encryption keys are not transferred to non-adequate countries (remain in EU/EEA where possible)

**Data minimization:**
- Only data strictly necessary for Service provision is transferred
- GSC metrics and WordPress content may be geo-restricted to EU regions (if available via hosting provider)

**Technical controls:**
- Data access is role-based and logged
- Bulk data exports are logged and require approval
- Sub-processor transfers are limited to those providing essential services

**Contractual safeguards:**
- Sub-processors bound by equivalent SCCs
- Sub-processors prohibited from further transfers without consent

### 11.3 Transfer Impact Assessment (TIA)

Customer may request Processor's transfer impact assessment (TIA). Processor will provide a summary identifying:
- Applicable legal frameworks in destination countries
- Government access/surveillance laws
- Processor's mitigation measures
- Residual risks

Full TIA documents may be shared under mutual NDA.

### 11.4 Suspension of Transfers

If a court invalidates the SCCs or an adequacy decision is revoked (e.g., future Schrems decisions), Processor may:
1. Suspend data transfers to the affected country pending new safeguards
2. Notify Customer and discuss alternative arrangements
3. Offer data residency options (if available and cost-feasible)

## 12. Data Protection Impact Assessment (DPIA)

### 12.1 Cooperation

If Customer's processing activities involve:
- Large-scale processing of personal data
- Processing of special categories (health, race, political views, etc.)
- Systematic monitoring
- Automated decision-making with legal effects

Then Customer may conduct a DPIA. Processor will:
- Provide information about Processor's processing activities and security measures
- Respond to Customer's questions within 10 business days
- Assist in identifying risks and mitigating measures
- Not charge for reasonable cooperation (excessive requests charged at cost recovery)

## 13. Limitations of Liability

### 13.1 Standard Limitation

The liability limitations in the Terms of Service apply to this DPA. Additionally:

- **Processor not liable for**: Customer's violation of data protection laws, failure to obtain consents, failure to provide privacy notices, or use of the Service for unlawful purposes
- **Customer indemnifies Processor**: For claims arising from Customer's processing instructions or data processing practices

### 13.2 Exception for Data Breaches

If a breach is caused by Processor's negligence, gross negligence, or willful misconduct:
- **Liability is not capped** for that specific breach
- **But overall liability** remains subject to the liability caps in the Terms of Service (maximum: amount paid in 12 months, or $100)
- **Customer's remedies**: In case of material breach, Customer may suspend new data transfers or terminate the Service

## 14. Modification and Amendments

This DPA may be amended if:

1. **Required by law**: If data protection laws change such that this DPA no longer complies, Processor may update it with 30 days' notice
2. **By mutual agreement**: Processor and Customer may agree in writing to amend specific provisions
3. **Standard clauses updates**: If EU SCCs are updated by the European Commission, Processor will implement updates within 90 days

Non-material amendments (clarifications, contact updates) take effect immediately. Material amendments require 30 days' notice.

## 15. Contact Information

For data processing inquiries, audit requests, or concerns:

**Data Protection Officer (DPO)** [if applicable]:
Email: dpo@rankwiz.ai

**Privacy Team:**
Email: privacy@rankwiz.ai

**Data Controller** (Customer):
You are responsible for providing us with accurate contact information and updating it if it changes.

## 16. Miscellaneous

### 16.1 Entire Agreement

This DPA, together with the Terms of Service and other referenced policies, constitutes the entire agreement regarding data processing. Prior agreements and understandings are superseded.

### 16.2 Governing Law

This DPA is governed by the laws of [INSERT JURISDICTION]. For EU/EEA residents, GDPR applies regardless of the chosen jurisdiction.

### 16.3 Severability

If any provision is invalid or unenforceable, remaining provisions continue in effect.

### 16.4 No Third-Party Beneficiaries

This DPA is between Processor and Customer only. No third parties (including data subjects) have enforceable rights, except as expressly required by law (e.g., GDPR Article 80).

---

**Version 1.0** | Effective Date: [DATE TO BE SET]

