Rankrop
Features How It Works Who It's For Pricing Contact
Sign in Start free trial →
Legal

Data Processing Addendum

Last updated: June 26, 2026  ·  Effective: June 26, 2026

Privacy Policy Terms of Service Data Processing Security
On this page 1. Definitions 2. Scope & Instructions 3. Categories of Data 4. CCPA Service Provider 5. Other US State Laws 6. Sub-Processors 7. Security Measures 8. Consumer Requests 9. Data Breach Notification 10. Audits & Compliance 11. Deletion of Data 12. EU / UK Customers 13. Order of Precedence 14. Execution

This Data Processing Addendum ("DPA") forms part of the agreement between Sky Vista Consulting ("Service Provider") and the customer agency ("Business") for use of the Rankrop™ platform (the "Service"). It reflects the parties' agreement regarding the processing of Personal Information under applicable US privacy laws, primarily the California Consumer Privacy Act (CCPA) and its amendment the CPRA.

01 Definitions

  • Business means the customer agency that determines the purposes and means of processing Personal Information — the entity subscribing to the Service.
  • Service Provider means Sky Vista Consulting, which processes Personal Information on behalf of the Business solely to provide the Service.
  • Consumer means a natural person who is a resident of California or another US state with applicable privacy law protections, including the Business's personnel and clients.
  • Personal Information means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to a particular individual or household, as defined under applicable US state privacy laws.
  • Sale / Share has the meanings given under CCPA §1798.140(ad) and (ah) — disclosing Personal Information to a third party for monetary or other valuable consideration, or for cross-context behavioral advertising.
  • Processing means any operation performed on Personal Information, including collection, storage, use, disclosure, or deletion.

02 Scope & Instructions

This DPA applies to all Personal Information that the Business submits to or generates within the Service. The Service Provider will process such data only on the Business's documented instructions, as set forth in the Terms of Service and this DPA, except where required by applicable US law.

The parties acknowledge that the Service Provider processes Personal Information as a "service provider" under the CCPA, and not as a "third party" or "contractor" that receives Personal Information for its own commercial purposes.

03 Categories of Personal Information

The categories of Personal Information processed under this DPA may include:

  • Identifiers: Name, email address, IP address, account credentials, business identity
  • Professional or employment information: Job title, company name, business role
  • Commercial information: Subscription records, billing details, transaction history
  • Internet or electronic network activity: Service usage logs, audit entries, browser data
  • Client data submitted by the Business: Contact details, business names, addresses, and similar data about the Business's own customers stored within the Service

Sensitive Personal Information (as defined by CPRA §1798.140(ae)) should not be submitted to the Service. The Service is not designed to process data revealing racial or ethnic origin, health conditions, genetic or biometric data, financial account access credentials, or data concerning minors.

04 CCPA Service Provider Obligations

Sky Vista Consulting, acting as a Service Provider under California Civil Code §1798.140(ag), certifies that it understands and will comply with the following restrictions:

CCPA Service Provider Certification. Sky Vista Consulting shall not sell or share the Business's Personal Information; shall not retain, use, or disclose it for any commercial purpose other than performing the Service; shall not retain, use, or disclose it outside the direct business relationship between the parties; and shall not combine it with Personal Information received from or on behalf of another source.

Specific obligations

  • No Sale or Sharing. The Service Provider shall not sell or share (as defined under CCPA) Personal Information provided by the Business.
  • Purpose Limitation. The Service Provider shall process Personal Information solely for the specific business purpose of providing the Service, as described in the Terms of Service.
  • No Unauthorized Combination. The Service Provider shall not combine Business Personal Information with Personal Information collected from other sources outside the scope of the Service.
  • Notification of Legal Requirements. The Service Provider shall promptly notify the Business if it determines it can no longer meet its obligations under this DPA.
  • Cooperation on Consumer Rights. The Service Provider shall cooperate with the Business to fulfill Consumer rights requests as described in Section 8.

05 Other US State Privacy Laws

Sky Vista Consulting's obligations as a data processor / service provider extend to the following additional US state privacy laws where applicable:

  • Virginia CDPA (VCDPA): Service Provider acts as a "processor" as defined under Va. Code §59.1-575.
  • Colorado Privacy Act (CPA): Service Provider acts as a "processor" as defined under C.R.S. §6-1-1303.
  • Connecticut Data Privacy Act (CTDPA): Service Provider acts as a "processor" as defined under Conn. Gen. Stat. §42-515.
  • Utah Consumer Privacy Act (UCPA): Service Provider acts as a "controller" or "processor" depending on context, as defined under Utah Code §13-61-101.
  • Texas Data Privacy and Security Act (TDPSA): Service Provider acts as a "processor" as defined thereunder.
  • Nevada Revised Statutes Chapter 603A: Service Provider does not sell or license covered information as defined under Nevada law.

For each of the above, the Service Provider agrees to process Personal Information only on the Business's documented instructions and to implement appropriate technical and organizational measures as described in Section 7.

06 Sub-Processors

The Business authorizes the Service Provider to engage the sub-processors listed below to assist in providing the Service. The Service Provider will notify the Business at least 30 days before engaging a new sub-processor or making material changes to existing sub-processor arrangements.

Sub-Processor Purpose Location
Amazon Web Services (AWS)Cloud infrastructure & hostingUSA
Laravel ForgeServer management & deploymentUSA
Stripe, Inc.Payment processing & billingUSA
Anthropic, PBCAI features (one-shot; no training on customer data)USA
SendGrid (Twilio)Transactional email deliveryUSA
Postmark (Wildbit)Transactional email deliveryUSA
SerpAPISearch results data retrievalUSA
Sentry (Functional Software)Application error monitoringUSA

Each sub-processor is bound by a written agreement requiring them to protect Personal Information to standards at least as protective as this DPA.

07 Security Measures

The Service Provider implements the following technical and organizational security measures appropriate to the risk of processing:

  • TLS 1.3 encryption for all Personal Information in transit
  • AES-256 encryption at rest for sensitive fields (API keys, OAuth tokens, 2FA secrets, recovery codes)
  • Per-workspace data isolation enforced at the database query level via Eloquent global scopes
  • Two-factor authentication (TOTP) available and admin-enforceable for all accounts
  • Role-based access controls and comprehensive audit logging
  • Brute-force rate limiting and session security controls
  • Regular security patching, dependency updates, and vulnerability assessments
  • Daily encrypted database backups with point-in-time restore capability

See /security for the full security overview.

08 Consumer / Data Subject Requests

The Service Provider will assist the Business in responding to Consumer rights requests under applicable US privacy laws, including requests for access, correction, deletion, portability, and opt-out of sale/sharing.

Most requests can be fulfilled directly through the Service:

  • Data export: Workspace admins can export all data as CSV files via the Service
  • Account deletion: Available via Settings in the Service, or by contacting support
  • Correction: Users can update their own account information within the Service

For requests requiring additional assistance from the Service Provider, contact privacy@skyvistaconsulting.com. The Service Provider will respond within timeframes required by applicable law (45 days under CCPA, extendable to 90 days with notice).

09 Data Breach Notification

In the event the Service Provider becomes aware of a Security Incident involving unauthorized access to, disclosure of, or loss of Personal Information belonging to the Business, the Service Provider will:

  • Notify the Business without undue delay, and in any event within 72 hours of becoming aware of the breach
  • Provide a description of the nature of the breach, the categories and approximate number of individuals affected, and the likely consequences
  • Describe measures taken or proposed to address the breach, including mitigation steps
  • Cooperate with the Business to fulfill any notification obligations to Consumers or regulatory authorities under applicable US state breach notification laws

10 Audits & Compliance Demonstration

The Service Provider will make available to the Business information reasonably necessary to demonstrate compliance with this DPA upon written request. This may include completing security questionnaires or sharing relevant policies.

Third-party security audit reports, where available, will be shared under confidentiality with Business customers on Enterprise plans upon written request to legal@skyvistaconsulting.com.

11 Return & Deletion of Data

Upon termination or expiration of the Service, the Business may export all Personal Information via CSV within a 30-day window. After that period:

  • The Service Provider will delete all Personal Information within 60 days, unless legally required to retain it
  • Backup copies will be purged on their normal rotation schedule (maximum 90 days)
  • Audit logs and billing records may be retained for 7 years as required by US law

To request immediate deletion of Personal Information, email support@skyvistaconsulting.com.

12 EU / UK Customers — GDPR Addendum

Applies only if you process personal data of EU, UK, or Swiss data subjects

For customers who are established in the EU, UK, or Switzerland or who process personal data of individuals in those jurisdictions within the Service, the following additional terms apply:

Roles under GDPR

For purposes of the EU General Data Protection Regulation 2016/679 ("GDPR") and UK GDPR: the Business acts as the Controller and Sky Vista Consulting acts as the Processor, as those terms are defined in Article 4 GDPR.

Legal basis

The Business represents that it has a valid legal basis under GDPR Article 6 for any personal data it submits to the Service, and that it has provided required notices to data subjects.

International transfers

Where Personal Data is transferred from the EU/UK/Switzerland to the USA, the parties rely on the EU Standard Contractual Clauses (SCCs) pursuant to Commission Implementing Decision (EU) 2021/914, Module 2 (Controller-to-Processor), which are incorporated by reference into this DPA. Customers who require executed SCCs should email legal@skyvistaconsulting.com.

Data subject rights

The Service Provider will assist the Controller in responding to data subject requests under GDPR Articles 15–22 (access, rectification, erasure, restriction, portability, and objection) within the timeframes prescribed by GDPR.

Records of processing

The Service Provider maintains records of processing activities carried out on behalf of Controllers as required by GDPR Article 30(2).

13 Order of Precedence

In the event of a conflict between this DPA and the Terms of Service with respect to the processing of Personal Information, this DPA shall prevail. In the event of a conflict between the US provisions (Sections 1–11) and the GDPR Addendum (Section 12) with respect to EU/UK personal data, Section 12 prevails.

14 Execution

This DPA is effective upon the Business's acceptance of the Terms of Service and is incorporated therein by reference. No separate signature is required for the DPA terms to be binding.

Customers requiring a countersigned copy of this DPA, or a standalone CCPA Service Provider Agreement or GDPR Data Processing Agreement with executed SCCs, should email legal@skyvistaconsulting.com. We will execute and return a signed copy within 10 business days.

Sky Vista Consulting
Las Vegas, Nevada, USA
legal@skyvistaconsulting.com  ·  +1 702-763-2606
Rankrop

The SEO operating system for agencies. Scale clients, not headcount.

Product

  • Features
  • Pricing
  • Who It's For
  • How It Works

Company

  • Contact
  • Support
  • Help Center

Legal

  • Privacy
  • Terms
  • Data Processing
  • Security
© 2026 Skyvista Consulting. All rights reserved. hello@skyvistaconsulting.com