Data Processing Agreement
Last updated: July 22, 2026
This Data Processing Agreement ("DPA") forms part of the agreement between you ("Customer") and Rank Monster and applies where Rank Monster processes personal data on the Customer's behalf in the course of providing the rankmonster.ai service. It reflects the parties' obligations under applicable data protection laws, including the EU/UK GDPR and the CCPA/CPRA.
1. Roles of the parties
For personal data processed through the service, the Customer is the controller (or "business" under the CCPA) and Rank Monster acts as the processor (or "service provider"). Rank Monster processes personal data only on documented instructions from the Customer, which include the use of the service as configured by the Customer.
2. Scope & nature of processing
- Subject matter — provision of the Rank Monster AI-visibility and content platform.
- Duration — for the term of the Customer's account, plus the retention period described below.
- Categories of data subjects — the Customer's authorized users and, where applicable, individuals referenced in content the Customer submits or generates.
- Categories of personal data — account details (name, email), authentication identifiers, usage data, and any personal data contained in URLs or content the Customer chooses to process.
- We do not intentionally process special categories of personal data, and ask that Customers not submit them.
3. Subprocessors
The Customer authorizes Rank Monster to engage subprocessors to provide the service. Our current subprocessors — including hosting, database, payment, email, and AI provider vendors — are listed in our Privacy Policy. We impose data protection obligations on each subprocessor no less protective than those in this DPA and remain responsible for their performance. We will give notice of material changes to our subprocessor list on request.
4. Security measures
Rank Monster maintains appropriate technical and organizational measures to protect personal data, including encryption in transit and at rest, access controls, and least-privilege administration. These are summarized on our Security page.
5. Data subject requests
Taking into account the nature of the processing, Rank Monster will assist the Customer, by appropriate technical and organizational measures and insofar as possible, in responding to requests from data subjects to exercise their rights (access, rectification, erasure, portability, and objection). Account owners can also action many of these directly from the dashboard.
6. International transfers
Where personal data is transferred outside the EEA, UK, or Switzerland, such transfers are made under an approved transfer mechanism (such as the Standard Contractual Clauses) or to a jurisdiction recognized as providing an adequate level of protection.
7. Personal data breaches
Rank Monster will notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's data, and will provide information reasonably necessary for the Customer to meet its own notification obligations.
8. Return & deletion
Upon termination of the account, Rank Monster will delete or return the Customer's personal data, except where retention is required by law. Residual copies may persist in encrypted backups for up to 30 days before being permanently removed.
9. Contact & execution
To request a countersigned copy of this DPA or to ask a question about how we process personal data, email [email protected].