Version 1.0 · Effective: {{FACT_PENDING}} · For customers subject to GDPR / UK GDPR / similar regimes.
{{FACT_PENDING}} and will be finalised before
RankCause asks a customer to sign. Do not rely on this version as a
binding agreement; request an executed copy from our team instead.
Capitalised terms (“Personal Data”, “Processing”, “Controller”, “Processor”, “Data Subject”) have the meaning given in Article 4 of the GDPR (Regulation (EU) 2016/679). “Customer” means the paying RankCause account holder. “RankCause” means the entity operating the service at prism.com, incorporated in {{FACT_PENDING}}.
For all Personal Data processed on behalf of the Customer, RankCause acts as Processor and the Customer acts as Controller. This DPA applies in addition to our Terms of Service and Privacy Policy and prevails in case of conflict on data-protection matters.
The following categories are processed for the duration of the Customer’s subscription:
RankCause processes Personal Data only on the Customer’s documented instructions, which are: (a) providing the services described on the public pricing page; (b) billing and support; (c) complying with applicable law. Anything outside (a)–(c) requires explicit written instruction.
RankCause engages the following sub-processors, each bound by written terms offering at least the same level of protection as this DPA.
| Sub-processor | Purpose | Location |
|---|---|---|
| Stripe, Inc. | Payment processing (card, ACH) | US, EU |
| Coinbase Commerce | Cryptocurrency payment processing | US |
| {{FACT_PENDING}} (cloud host) | Application hosting | {{FACT_PENDING}} |
| {{FACT_PENDING}} (email provider) | Transactional email | {{FACT_PENDING}} |
| Plausible Analytics | Privacy-first website analytics (no cookies) | EU |
When a new sub-processor is added, RankCause will update this page at least 14 days before the change takes effect. Customers who object may terminate the affected subscription for a pro-rated refund of the unused period.
RankCause maintains appropriate technical and organisational measures including: encryption in transit (TLS 1.2+) and at rest (AES-256); role-based access control; audit logs for privileged actions; unique per-customer API tokens; least-privilege IAM on infrastructure; regular dependency and SAST scans; and documented incident response.
Where Personal Data is transferred outside the EEA / UK, RankCause relies on the EU Standard Contractual Clauses (SCCs) and, for UK transfers, the UK Addendum. A copy of the executed SCCs is available on request at {{FACT_PENDING}}.
RankCause will assist the Customer in responding to Data Subject requests (access, deletion, portability, objection, rectification) within the timeframes required by applicable law. Most requests can be serviced directly from the in-app account settings.
RankCause will notify affected Customers of a Personal Data breach without undue delay and in any event within 48 hours of becoming aware of it, via the account email on file, including the nature of the breach, categories and approximate numbers of affected Data Subjects, likely consequences, and measures taken.
Upon reasonable prior notice, RankCause will make available to the Customer the information necessary to demonstrate compliance with this DPA, including (where applicable) third-party audit reports such as SOC 2. On-site audits are subject to a confidentiality agreement and a commercially reasonable fee.
On termination, RankCause will delete all Personal Data within 30 days, unless a longer retention is required by law. The Customer may export all account data from the in-app export tool before termination. Backups containing Personal Data are purged on a 90-day rolling cycle.
This DPA remains in force for the duration of the Customer’s subscription and any period in which RankCause processes Personal Data on the Customer’s behalf thereafter.
This DPA is governed by the law of {{FACT_PENDING}} (matching the Master Service Agreement / Terms of Service).
Most customers don’t need a countersigned copy — accepting our Terms of Service and this DPA is sufficient. If your legal team requires a signed PDF, email {{FACT_PENDING}} with your legal entity name, and we’ll send a countersigned copy within 2 business days.
Request countersigned copy