This data processing agreement ("DPA") forms part of the service agreement between the client ("Controller") and HAPPYCOMPANY LTD, trading as rankloop ("Processor"). rankloop is a trading name of HAPPYCOMPANY LTD, registered in England & Wales, company no. 14587760. Registered office: 128 City Road, London EC1V 2NX. It applies to the extent we process personal data on your behalf under UK GDPR.
1. Subject matter and duration
Processing is limited to delivering the managed SEO service and lasts for the term of the service agreement. In practice we process very little personal data: our service operates on site content and aggregated search metrics, not on your end users' personal data.
2. Nature and purpose
Accessing Google Search Console data, creating and publishing content via the access you grant, and reporting on performance.
3. Categories of data and data subjects
Business contact details of the Controller's staff (names, work emails, account identifiers used to grant access). We do not require access to customer databases or end-user personal data.
4. Processor obligations
We process personal data only on your documented instructions, and will inform you if an instruction appears to infringe UK GDPR. Staff and contractors with access are bound by confidentiality. We apply the security measures described on our Security page (least-privilege access, no shared passwords, encrypted secrets storage, audit logging); assist with data subject requests; assist with data protection impact assessments and your security obligations, taking into account the limited data we process; notify you of a personal data breach without undue delay and in any event within 48 hours of becoming aware of it; and delete or return personal data within 30 days of the end of the service, unless law requires retention.
5. Sub-processors
Infrastructure is self-hosted (EU — Telepoint data centre, Sofia, Bulgaria). Current sub-processors:
- Cloudflare (United States) — DNS/CDN and form bot protection for our own website.
- Anthropic (United States) — AI processing of website URLs, public page content and aggregated search metrics; no enquirer names or emails are sent to it.
- Google (United States) — Search Console API access to properties the Controller connects.
- Zernio — social publishing of approved content; receives post text and images only, no personal data.
Telegram is used for internal notifications to our own team; those alerts contain no personal data (only the domain concerned), so it does not act as a sub-processor.
Sub-processors are bound by equivalent data protection terms. We will give prior notice before engaging any new sub-processor that would process Controller personal data, with the right to object within 14 days.
6. International transfers
Our servers are in the EU (Telepoint data centre, Sofia, Bulgaria), which the UK recognises as providing adequate protection. Where a provider processes data outside the UK/EEA (for example in the United States), we rely on the UK International Data Transfer Addendum, the UK Extension to the EU-US Data Privacy Framework, or another safeguard permitted under UK GDPR.
7. Audit
We will make available information reasonably necessary to demonstrate compliance with this DPA, and allow audits with reasonable notice, no more than once per year unless required by a supervisory authority.
8. Liability
Liability under this DPA is subject to the limitations in our Terms of Service.
To receive a countersigned copy of this DPA, email [email protected].