Legal center

Data Processing Addendum

Version: August 21, 2026. This DPA supplements the Terms where Rankelo processes personal data for a business customer.

Roles and instructions

The customer determines the purpose and lawful basis for customer data and is the data fiduciary, controller, or equivalent role under applicable law. Brandsap acts as a processor or data processor for that data and processes it only to provide and secure Rankelo, follow documented customer configuration, comply with law, and perform obligations in the Terms. Account, billing, security, and direct support data may be processed by Brandsap for its own legitimate service purposes as described in the Privacy Policy.

Customer obligations

The customer will provide lawful instructions, required notices, valid consents or other legal grounds, accurate data-subject responses, and appropriate permissions for crawled sites, connected accounts, repositories, and publishing targets. The customer will not submit special-category, payment-authentication, child, patient, or similarly regulated data without a written agreement covering that use.

Confidentiality and security

Brandsap limits access to authorized persons and uses measures including tenant controls, credential encryption, server-side sessions, request validation, audit logs, restricted internal services, dependency scanning, backups, and incident procedures. Measures may evolve without materially reducing overall protection.

Subprocessors and transfers

Brandsap may use subprocessors listed on the Subprocessors page. Customer authorizes those providers subject to appropriate data-protection obligations. Material changes will be published with reasonable notice. Providers may process data internationally; the parties will use legally required safeguards for applicable transfers.

Requests, incidents, deletion, and audits

Taking account of the processing, Brandsap will reasonably assist with verified data-subject requests, security incidents, impact assessments, and regulator inquiries. Brandsap will notify the customer without undue delay after confirming a breach affecting customer data where required. At termination, data is returned or deleted under published retention periods unless law requires retention. On reasonable written request, Brandsap will provide available security and compliance information; intrusive audits require necessity, confidentiality, minimal disruption, and allocation of reasonable costs.

Conflict and review

This DPA controls over conflicting Terms only for its subject. Governing law follows the Terms unless mandatory data-protection law requires otherwise. Contact contact@brandsap.com to request an executed or jurisdiction-specific addendum. Professional review is recommended before relying on this general DPA for regulated or cross-border processing.