Skip to main content
Main content

Data Processing Agreement

Last updated: 22 August 2026

1. Scope and roles

This Data Processing Agreement (the "DPA") forms part of the Terms of Service between the customer (the "Controller") and the operator of EdenRank (the "Processor"). It applies whenever EdenRank processes personal data contained in content, prompts, competitor lists, analytics connections, or account records that the customer provides, to the extent that data relates to identified or identifiable natural persons under Regulation (EU) 2016/679 ("GDPR").

2. Subject matter, duration, nature and purpose

The subject matter of processing is the provision of the EdenRank service: measuring whether AI answer engines mention and cite the customer's brand, generating drafts and published pages the customer approves, and reporting on the results. Processing lasts for the duration of the customer's subscription plus the deletion window described in section 8. The purpose is limited to providing and improving the contracted service; the Processor does not use customer personal data to train its own models and does not sell it.

3. Categories of data and data subjects

Typical categories: business contact data of the customer's users (name, work email), account credentials (stored hashed), billing metadata (handled by the payment sub-processor), website analytics identifiers where the customer connects them, and any personal data the customer chooses to include in prompts or content. Data subjects are the customer's staff and, where the customer submits such content, individuals mentioned in it. EdenRank is not designed for and must not be used to process special categories of data under Art. 9 GDPR.

4. Processor obligations

The Processor: (a) processes personal data only on the Controller's documented instructions, the Terms and this DPA being those instructions; (b) ensures persons authorised to process the data are bound by confidentiality; (c) implements the technical and organisational measures in section 6; (d) assists the Controller, insofar as possible, with data-subject requests under Arts. 12-23 GDPR and with the obligations in Arts. 32-36 GDPR; (e) makes available the information reasonably necessary to demonstrate compliance and allows audits as described in section 9; and (f) notifies the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data.

5. Sub-processors

The Controller grants general authorisation for the sub-processors listed below. The Processor will inform customers of intended additions or replacements by updating this page at least 14 days in advance, during which the Controller may object on reasonable data-protection grounds. Each sub-processor is bound by data-protection obligations no less protective than this DPA. Note that measuring AI answer engines necessarily sends the prompt text being measured to the engine being measured - that is the service itself.

Sub-processorPurposeProcessing location
DigitalOcean, LLCCloud infrastructure hosting (application and database)EU/US
Cloudflare, Inc.Content delivery network, DNS, DDoS protectionGlobal (EU entry points)
Dodo PaymentsPayment processing, invoicing, tax handlingPer its own compliance program
Resend (Plus Five Five, Inc.)Transactional email deliveryUS
Anthropic, PBCAI answer measurement (prompt text is sent for measurement)US
OpenAI, LLCAI answer measurement (prompt text is sent for measurement)US
Google LLC (Gemini)AI answer measurement (prompt text is sent for measurement)US/EU
Perplexity AI, Inc.AI answer measurement (prompt text is sent for measurement)US
xAI Corp.AI answer measurement (prompt text is sent for measurement)US
Mistral AIAI answer measurement (prompt text is sent for measurement)EU
DeepSeekAI answer measurement (prompt text is sent for measurement)PRC
HasDataSearch-results measurement (Google surfaces)Per its own compliance program
Z.aiEditorial image generation for published contentPer its own compliance program

6. Security measures

Measures include: TLS in transit everywhere; passwords stored with adaptive hashing; single-use, hashed password-reset and magic-link tokens; RS256-signed sessions with global invalidation on reset; role- and tenant-scoped access controls; per-brand isolation of measurement and analytics data; encrypted, access-restricted backups with offsite copies; least-privilege production access limited to the operator; and audit logging of security-relevant events.

7. International transfers

Where processing involves transfers outside the EEA, the Processor relies on the European Commission's Standard Contractual Clauses with the relevant sub-processor, or that sub-processor's own recognised transfer mechanism, as applicable.

8. Deletion and return

On termination, the Controller may export its data via the account tools or by request. The Processor deletes the Controller's personal data within 90 days of termination, except where retention is required by law (for example, billing records), in which case the data is isolated and retained only as long as required.

9. Audits and contact

Not more than once per year, and under reasonable confidentiality, the Controller may request a written summary of the Processor's technical and organisational measures, or a review call, sufficient to demonstrate compliance with this DPA. Data-protection requests: see the contact details in the Privacy Policy.