Last updated: June 26, 2026 · Effective: June 26, 2026
This Data Processing Addendum ("DPA") forms part of the agreement between Sky Vista Consulting ("Service Provider") and the customer agency ("Business") for use of the Rankrop™ platform (the "Service"). It reflects the parties' agreement regarding the processing of Personal Information under applicable US privacy laws, primarily the California Consumer Privacy Act (CCPA) and its amendment the CPRA.
This DPA applies to all Personal Information that the Business submits to or generates within the Service. The Service Provider will process such data only on the Business's documented instructions, as set forth in the Terms of Service and this DPA, except where required by applicable US law.
The parties acknowledge that the Service Provider processes Personal Information as a "service provider" under the CCPA, and not as a "third party" or "contractor" that receives Personal Information for its own commercial purposes.
The categories of Personal Information processed under this DPA may include:
Sensitive Personal Information (as defined by CPRA §1798.140(ae)) should not be submitted to the Service. The Service is not designed to process data revealing racial or ethnic origin, health conditions, genetic or biometric data, financial account access credentials, or data concerning minors.
Sky Vista Consulting, acting as a Service Provider under California Civil Code §1798.140(ag), certifies that it understands and will comply with the following restrictions:
CCPA Service Provider Certification. Sky Vista Consulting shall not sell or share the Business's Personal Information; shall not retain, use, or disclose it for any commercial purpose other than performing the Service; shall not retain, use, or disclose it outside the direct business relationship between the parties; and shall not combine it with Personal Information received from or on behalf of another source.
Sky Vista Consulting's obligations as a data processor / service provider extend to the following additional US state privacy laws where applicable:
For each of the above, the Service Provider agrees to process Personal Information only on the Business's documented instructions and to implement appropriate technical and organizational measures as described in Section 7.
The Business authorizes the Service Provider to engage the sub-processors listed below to assist in providing the Service. The Service Provider will notify the Business at least 30 days before engaging a new sub-processor or making material changes to existing sub-processor arrangements.
| Sub-Processor | Purpose | Location |
|---|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure & hosting | USA |
| Laravel Forge | Server management & deployment | USA |
| Stripe, Inc. | Payment processing & billing | USA |
| Anthropic, PBC | AI features (one-shot; no training on customer data) | USA |
| SendGrid (Twilio) | Transactional email delivery | USA |
| Postmark (Wildbit) | Transactional email delivery | USA |
| SerpAPI | Search results data retrieval | USA |
| Sentry (Functional Software) | Application error monitoring | USA |
Each sub-processor is bound by a written agreement requiring them to protect Personal Information to standards at least as protective as this DPA.
The Service Provider implements the following technical and organizational security measures appropriate to the risk of processing:
See /security for the full security overview.
The Service Provider will assist the Business in responding to Consumer rights requests under applicable US privacy laws, including requests for access, correction, deletion, portability, and opt-out of sale/sharing.
Most requests can be fulfilled directly through the Service:
For requests requiring additional assistance from the Service Provider, contact privacy@skyvistaconsulting.com. The Service Provider will respond within timeframes required by applicable law (45 days under CCPA, extendable to 90 days with notice).
In the event the Service Provider becomes aware of a Security Incident involving unauthorized access to, disclosure of, or loss of Personal Information belonging to the Business, the Service Provider will:
The Service Provider will make available to the Business information reasonably necessary to demonstrate compliance with this DPA upon written request. This may include completing security questionnaires or sharing relevant policies.
Third-party security audit reports, where available, will be shared under confidentiality with Business customers on Enterprise plans upon written request to legal@skyvistaconsulting.com.
Upon termination or expiration of the Service, the Business may export all Personal Information via CSV within a 30-day window. After that period:
To request immediate deletion of Personal Information, email support@skyvistaconsulting.com.
Applies only if you process personal data of EU, UK, or Swiss data subjects
For customers who are established in the EU, UK, or Switzerland or who process personal data of individuals in those jurisdictions within the Service, the following additional terms apply:
For purposes of the EU General Data Protection Regulation 2016/679 ("GDPR") and UK GDPR: the Business acts as the Controller and Sky Vista Consulting acts as the Processor, as those terms are defined in Article 4 GDPR.
The Business represents that it has a valid legal basis under GDPR Article 6 for any personal data it submits to the Service, and that it has provided required notices to data subjects.
Where Personal Data is transferred from the EU/UK/Switzerland to the USA, the parties rely on the EU Standard Contractual Clauses (SCCs) pursuant to Commission Implementing Decision (EU) 2021/914, Module 2 (Controller-to-Processor), which are incorporated by reference into this DPA. Customers who require executed SCCs should email legal@skyvistaconsulting.com.
The Service Provider will assist the Controller in responding to data subject requests under GDPR Articles 15–22 (access, rectification, erasure, restriction, portability, and objection) within the timeframes prescribed by GDPR.
The Service Provider maintains records of processing activities carried out on behalf of Controllers as required by GDPR Article 30(2).
In the event of a conflict between this DPA and the Terms of Service with respect to the processing of Personal Information, this DPA shall prevail. In the event of a conflict between the US provisions (Sections 1–11) and the GDPR Addendum (Section 12) with respect to EU/UK personal data, Section 12 prevails.
This DPA is effective upon the Business's acceptance of the Terms of Service and is incorporated therein by reference. No separate signature is required for the DPA terms to be binding.
Customers requiring a countersigned copy of this DPA, or a standalone CCPA Service Provider Agreement or GDPR Data Processing Agreement with executed SCCs, should email legal@skyvistaconsulting.com. We will execute and return a signed copy within 10 business days.