Data Processing Addendum

Last updated: 28 June 2026

This Data Processing Addendum (“DPA”) forms part of the Terms of Service between TECH RACCOONS LTD (company number 16336615), registered in England and Wales (“RankPine”, “we”, “Processor”), and the customer agreeing to those Terms (“you”, “Customer”, “Controller”). It applies where, and to the extent that, we process Customer Personal Data on your behalf in providing the Service.

If you require a countersigned copy of this DPA for your records, email [email protected].

1. Definitions

Capitalised terms not defined here have the meaning given in the Terms of Service. “Data Protection Laws” means all laws applicable to the processing of personal data under the Terms, including the UK GDPR, the EU General Data Protection Regulation (Regulation 2016/679) (“EU GDPR”), and the Data Protection Act 2018. “Controller”, “Processor”, “Data Subject”, “Personal Data”, “processing”, and “Sub-processor” have the meanings given in the Data Protection Laws. “Customer Personal Data” means Personal Data contained in Customer Content that we process on your behalf. “UK Addendum” means the International Data Transfer Addendum to the EU Standard Contractual Clauses issued by the UK Information Commissioner. “Standard Contractual Clauses” or “SCCs” means the clauses approved under EU Commission Implementing Decision 2021/914.

2. Roles and scope of processing

As between the parties, you are the Controller and we are the Processor of Customer Personal Data. Where you are yourself a processor acting on behalf of a third-party controller, you appoint us as your sub-processor, and you confirm you have the authority to do so. We will process Customer Personal Data only on your documented instructions, including as set out in this DPA and the Terms, and as necessary to provide and support the Service, unless required to do otherwise by law (in which case we will inform you, unless the law prohibits it). The subject matter, duration, nature, and purpose of the processing, the types of Personal Data, and the categories of Data Subjects are set out in Annex 1.

3. Our obligations as Processor

We will:

  • process Customer Personal Data only on your documented instructions;
  • ensure that personnel authorised to process Customer Personal Data are bound by appropriate confidentiality obligations;
  • implement and maintain the technical and organisational security measures described in Annex 2, appropriate to the risk;
  • respect the conditions in Section 5 for engaging Sub-processors;
  • taking into account the nature of the processing, assist you by appropriate technical and organisational measures, insofar as possible, to respond to requests from Data Subjects exercising their rights;
  • assist you in ensuring compliance with your obligations relating to the security of processing, breach notification, data protection impact assessments, and prior consultation, taking into account the information available to us;
  • at your choice, delete or return Customer Personal Data as described in Section 10; and
  • make available to you the information reasonably necessary to demonstrate compliance with this DPA, as described in Section 9.

If we believe an instruction infringes Data Protection Laws, we will inform you (unless the law prohibits it).

4. Your obligations as Controller

You will:

  • ensure you have a lawful basis, and have provided all required notices and obtained all required consents, for the Customer Personal Data you submit to the Service and for us to process it as described;
  • ensure your instructions for the processing comply with Data Protection Laws; and
  • be responsible for the accuracy, quality, and legality of Customer Personal Data and the means by which you acquired it.

5. Sub-processors

You grant us general authorisation to engage Sub-processors to process Customer Personal Data in order to provide the Service. Our current Sub-processors are listed in Annex 3 (and in our Privacy Policy). We impose on each Sub-processor data-protection obligations that are no less protective than those in this DPA, and we remain responsible to you for each Sub-processor’s performance.

We will give you reasonable notice of any intended addition or replacement of a Sub-processor (for example by updating the list and, where you ask us to, notifying you by email). If you reasonably object on data-protection grounds, you may tell us within 30 days and we will work in good faith to address your concern; if we cannot, you may, as your sole remedy, terminate the affected part of the Service.

6. International transfers

Where our provision of the Service involves transferring Customer Personal Data outside the UK or EEA to a country without an adequacy decision, the parties agree that the SCCs (for EU transfers) and the UK Addendum (for UK transfers) are incorporated into this DPA by reference and apply to that transfer, with you as “data exporter” and us (or the relevant Sub-processor) as “data importer”, completed with the details in the Annexes. The relevant modules and options of the SCCs apply according to the parties’ roles.

7. Assistance with Data Subject requests and assessments

Taking into account the nature of the processing, we will provide reasonable assistance to help you respond to requests from Data Subjects and to fulfil your obligations in relation to security, breach notification, data protection impact assessments, and consultation with supervisory authorities. If a Data Subject contacts us directly about Customer Personal Data, we will, where lawful, forward the request to you and not respond ourselves except on your instructions.

8. Personal data breaches

We will notify you without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide information reasonably available to us to help you meet your breach-notification obligations. Our notification is not an acknowledgement of fault or liability.

9. Audits

We will make available information reasonably necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. Audits are subject to reasonable notice, no more than once per year (unless required by a supervisory authority or following a breach), conducted during normal business hours, subject to confidentiality, and in a manner that does not disrupt our operations or compromise the security of other customers’ data. We may satisfy audit requests by providing relevant certifications, reports, or summaries of our controls.

10. Return and deletion

On expiry or termination of the Service, or earlier on your request, we will delete or return Customer Personal Data and delete existing copies, unless retention is required by law. Residual copies in routine backups are deleted in accordance with our backup-rotation schedule. You can also delete sites and your account, and export your articles, directly in the Service at any time.

11. Liability

Each party’s liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service.

12. General

This DPA is governed by the same law, and subject to the same jurisdiction, as the Terms of Service. If there is a conflict between this DPA and the Terms in relation to the processing of Customer Personal Data, this DPA prevails. If any provision is found unenforceable, the rest remains in effect.


Annex 1 — Details of processing

  • Subject matter: our provision of the RankPine Service to you.
  • Duration: for the term of the Terms of Service, plus any period until deletion or return of Customer Personal Data under Section 10.
  • Nature and purpose: hosting, storing, and processing Customer Content to research, generate, schedule, and publish SEO content to the destinations you connect, and to operate, secure, support, and improve the Service.
  • Types of Personal Data: any Personal Data contained in the site configuration, briefs, audiences, source material, search-console data, and generated content you provide or that the Service produces. The Service is not designed for, and you should not submit, special categories of Personal Data.
  • Categories of Data Subjects: as determined by you — typically your personnel, and any individuals referenced in the content you submit or generate.

Annex 2 — Technical and organisational measures

We maintain measures appropriate to the risk, including:

  • encryption in transit (HTTPS) and encryption at rest of integration credentials and OAuth tokens (AES-256-GCM);
  • strict tenant isolation enforced in the data layer, preventing one customer from accessing another’s data;
  • access controls on a least-privilege basis and protection of authentication credentials;
  • rate-limiting, abuse prevention, and protection against server-side request forgery;
  • audit logging of sensitive operations, and a practice of never logging secrets;
  • regular backups and the ability to restore availability after an incident; and
  • processes for testing and reviewing the effectiveness of these measures.

Annex 3 — Sub-processors

We engage the Sub-processors below to process Customer Personal Data. The current list is also maintained in our Privacy Policy.

  • Anthropic — AI text generation — United States.
  • Google — AI text and image generation, sign-in, and Search Console — United States / global.
  • DataForSEO — keyword data — Estonia.
  • Polar — payments and subscriptions — United States / EU.
  • Resend — transactional email — United States.
  • Swetrix — cookieless analytics, error tracking, and session replay — United Kingdom.
  • Hetzner — hosting of servers and database — Germany (EU).
  • Cloudflare — object storage (R2) for generated images and content delivery — United States / global.

Destinations you choose to connect (such as your CMS or webhook endpoints) receive content at your instruction and act under your control, not as our Sub-processors.

Contact

Questions about this DPA: [email protected] or [email protected]. TECH RACCOONS LTD, registered office 3rd Floor, 86-90 Paul Street, London, EC2A 4NE, United Kingdom. Please contact us by email — we do not accept communications by post.