Data Processing Agreement (DPA)
Last updated: 20.07.2026
This Data Processing Agreement ("DPA"), when you use the rankzupAI service operated by rankzupAI as a corporate customer, agency or reseller ("Customer"), governs the roles and obligations of the parties within the scope of Law No. 6698 on the Protection of Personal Data ("KVKK") and the relevant secondary legislation. This document must be read together with the KVKK Disclosure Notice and the Privacy Policy, and is consistent with them.
1. Definitions and Parties
- Data Controller: the party determining the purposes and means of processing personal data.
- Data Processor: the party processing personal data in accordance with the instructions of the data controller.
- Data Subject: the natural person whose personal data is processed (the Customer's end users, employees, etc.).
- Sub-processor: the third-party processors that rankzupAI uses to provide the service.
2. Determination of Roles
rankzupAI has a dual role with respect to the personal data within the scope of the service:
- As data controller: with respect to the Customer's own account information (authorized person's full name, email, session/IP data, billing data), rankzupAI is the data controller for its own legitimate purposes.
- As data processor: with respect to the content that the Customer enters into the panel and processes through the service (project data, monitoring queries, competitor lists, etc.), rankzupAI is the data processor acting in accordance with the Customer's instructions. The Customer determines the scope and purpose of this content.
3. Subject, Duration and Purpose of Processing
- Subject: Measuring, reporting and monitoring the brand's visibility on artificial intelligence platforms (OpenAI/ChatGPT, Google/Gemini).
- Duration: For as long as the Customer's subscription is active; when the agreement ends, the deletion/return provisions in Article 8 below apply.
- Purpose: Solely the provision, maintenance and reporting of the service to the Customer.
4. Categories of Data Processed
The following categories of data are processed within the scope of the service (consistent with the KVKK Disclosure Notice):
- Identity and contact data: the authorized user's full name and email address.
- Transaction security data: IP address, session/cookie identifiers, login and last-seen timestamps.
- Usage (log) data: in-panel actions, scan/report requests, quota usage.
- Payment/invoice data: the name/legal title and billing information on the bank transfer receipt. Card data (number, expiry, CVV) is never collected or stored in any way.
- Customer content: project name, brand/competitor names, industry information and monitoring queries. As a rule this content is commercial/publicly available information, and ensuring it contains no personal data is the Customer's responsibility (see Article 6).
5. Sub-processors
rankzupAI relies on the following sub-processors to provide the service. The Customer is deemed to have approved this list; in the event of a material change to the list, the Customer is informed a reasonable time in advance.
- OpenAI — artificial intelligence visibility measurement (ChatGPT/web search API).
- Google (Gemini) — artificial intelligence visibility measurement (grounding API).
- Anthropic (Claude) and xAI (Grok) — AI visibility measurement when the optional engine is selected (official APIs).
- SerpAPI — search result/citation verification data.
- SMTP email provider — sending account and notification emails.
- Server hosting / infrastructure provider — running the application and the database.
- Telegram — only for the alert channel connected by the Customer at their own request.
6. Principle of No Personal Data Transfer to LLM APIs (KVKK Art. 9)
The core architectural principle of rankzupAI is that no personal data (full name, email, IP, Turkish ID number, etc.) is sent to the APIs of the artificial intelligence providers listed in Article 5 above (OpenAI, Google, Anthropic, xAI, DataForSEO). Only the brand name, product/service information, industry and monitoring query text required for the measurement are transmitted to these APIs.
Thanks to this principle, the fact that the infrastructures of those providers are located abroad (e.g. the USA) does not trigger a regime of transferring personal data abroad within the meaning of KVKK Article 9; because the transmitted information is not of the nature of personal data. rankzupAI designs and operates the system so as to preserve this principle.
Customer obligation: The Customer (and the users accessing the panel) undertake not to enter personal data belonging to natural persons (e.g. "is Dr. Ahmet Yılmaz's clinic good") into monitoring queries and project fields. Queries must be brand-, product- and industry-focused. If the Customer enters personal data contrary to this rule, the resulting KVKK liability belongs to the Customer; rankzupAI is not obliged to inspect the nature of this content.
7. Data Security Measures
- Passwords are stored irreversibly with argon2; plaintext passwords are not kept.
- All client-server communication is encrypted with HTTPS/TLS.
- Form submissions are protected with a CSRF token; session cookies are HttpOnly and Secure.
- Access is limited to persons authorized solely for operating the service (least-privilege principle).
- Regular database backups are taken; backups are retained for a limited period.
8. Data Retention, Return and Deletion
Upon termination of the agreement, at the Customer's request the Customer content is deleted, destroyed or (if requested) returned within a reasonable period. Without prejudice to statutory retention obligations (e.g. tax/invoice records), any remaining personal data is deleted, destroyed or anonymized at the end of this period. For details, see KVKK Disclosure Notice, Article 6.
9. Data Breach Notification (72-Hour Commitment)
When rankzupAI detects a breach affecting personal data security, it informs the relevant data controller/Customer without delay and within at most 72 hours; it shares reasonable information about the nature of the breach, the affected data categories, its likely consequences and the measures taken/recommended. rankzupAI provides reasonable support to the Customer in notifications to be made to the Personal Data Protection Authority and to the data subjects. The breach response procedure is documented in the operational handbook (RUNBOOK).
10. Support for Data Subject Rights
rankzupAI provides reasonable technical and administrative support to the Customer so that data subjects can exercise their rights under KVKK Article 11 (access, correction, deletion, objection, etc.). Requests that reach rankzupAI directly and relate to data under the Customer's responsibility are forwarded to the relevant Customer without delay.
11. Contact
For questions regarding this DPA and corporate procurement processes, you can reach us at kvkk@rankzup.ai. A wet-ink/electronically signed version can be provided for corporate customers requesting a signed copy.