Data Processing Agreement
Last updated: 22 August 2026
1. Scope and roles
This Data Processing Agreement (the "DPA") forms part of the Terms of Service between the customer (the "Controller") and the operator of EdenRank (the "Processor"). It applies whenever EdenRank processes personal data contained in content, prompts, competitor lists, analytics connections, or account records that the customer provides, to the extent that data relates to identified or identifiable natural persons under Regulation (EU) 2016/679 ("GDPR").
2. Subject matter, duration, nature and purpose
The subject matter of processing is the provision of the EdenRank service: measuring whether AI answer engines mention and cite the customer's brand, generating drafts and published pages the customer approves, and reporting on the results. Processing lasts for the duration of the customer's subscription plus the deletion window described in section 8. The purpose is limited to providing and improving the contracted service; the Processor does not use customer personal data to train its own models and does not sell it.
3. Categories of data and data subjects
Typical categories: business contact data of the customer's users (name, work email), account credentials (stored hashed), billing metadata (handled by the payment sub-processor), website analytics identifiers where the customer connects them, and any personal data the customer chooses to include in prompts or content. Data subjects are the customer's staff and, where the customer submits such content, individuals mentioned in it. EdenRank is not designed for and must not be used to process special categories of data under Art. 9 GDPR.
4. Processor obligations
The Processor: (a) processes personal data only on the Controller's documented instructions, the Terms and this DPA being those instructions; (b) ensures persons authorised to process the data are bound by confidentiality; (c) implements the technical and organisational measures in section 6; (d) assists the Controller, insofar as possible, with data-subject requests under Arts. 12-23 GDPR and with the obligations in Arts. 32-36 GDPR; (e) makes available the information reasonably necessary to demonstrate compliance and allows audits as described in section 9; and (f) notifies the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data.
5. Sub-processors
The Controller grants general authorisation for the sub-processors listed below. The Processor will inform customers of intended additions or replacements by updating this page at least 14 days in advance, during which the Controller may object on reasonable data-protection grounds. Each sub-processor is bound by data-protection obligations no less protective than this DPA. Note that measuring AI answer engines necessarily sends the prompt text being measured to the engine being measured - that is the service itself.
| Sub-processor | Purpose | Processing location |
|---|---|---|
| DigitalOcean, LLC | Cloud infrastructure hosting (application and database) | EU/US |
| Cloudflare, Inc. | Content delivery network, DNS, DDoS protection | Global (EU entry points) |
| Dodo Payments | Payment processing, invoicing, tax handling | Per its own compliance program |
| Resend (Plus Five Five, Inc.) | Transactional email delivery | US |
| Anthropic, PBC | AI answer measurement (prompt text is sent for measurement) | US |
| OpenAI, LLC | AI answer measurement (prompt text is sent for measurement) | US |
| Google LLC (Gemini) | AI answer measurement (prompt text is sent for measurement) | US/EU |
| Perplexity AI, Inc. | AI answer measurement (prompt text is sent for measurement) | US |
| xAI Corp. | AI answer measurement (prompt text is sent for measurement) | US |
| Mistral AI | AI answer measurement (prompt text is sent for measurement) | EU |
| DeepSeek | AI answer measurement (prompt text is sent for measurement) | PRC |
| HasData | Search-results measurement (Google surfaces) | Per its own compliance program |
| Z.ai | Editorial image generation for published content | Per its own compliance program |
6. Security measures
Measures include: TLS in transit everywhere; passwords stored with adaptive hashing; single-use, hashed password-reset and magic-link tokens; RS256-signed sessions with global invalidation on reset; role- and tenant-scoped access controls; per-brand isolation of measurement and analytics data; encrypted, access-restricted backups with offsite copies; least-privilege production access limited to the operator; and audit logging of security-relevant events.
7. International transfers
Where processing involves transfers outside the EEA, the Processor relies on the European Commission's Standard Contractual Clauses with the relevant sub-processor, or that sub-processor's own recognised transfer mechanism, as applicable.
8. Deletion and return
On termination, the Controller may export its data via the account tools or by request. The Processor deletes the Controller's personal data within 90 days of termination, except where retention is required by law (for example, billing records), in which case the data is isolated and retained only as long as required.
9. Audits and contact
Not more than once per year, and under reasonable confidentiality, the Controller may request a written summary of the Processor's technical and organisational measures, or a review call, sufficient to demonstrate compliance with this DPA. Data-protection requests: see the contact details in the Privacy Policy.