Privacy Policy
This policy explains what personal data Rankdesk collects, why we collect it, how long we keep it and what you can do about it. It applies to our website and to the Rankdesk application.
1. Who we are
Rankdesk is the controller of the personal data described in this policy. You can reach us at the address below or by email.
RankdeskHurksestraat 195652 AH EindhovenThe Netherlandshi@rankdesk.ai2. Data we collect
We keep data collection limited to what the service needs to work.
- Account data: name, email address, password hash or Google account identifier, and the workspace or projects you create.
- Project data: your website URL, language, competitors, keywords, brand settings and the content generated for you.
- Connection data: credentials or API keys you add to publish to your own CMS. These are stored encrypted and used only to publish on your instruction.
- Billing data: plan, subscription status, invoices and the payment identifiers we receive from our payment processor. We never see or store your full card details.
- Technical data: IP address, browser type, device type, pages visited and error logs, collected to keep the service secure and stable.
- Support data: the content of messages you send us by email or through the app.
3. Why we use it
- To provide the service: creating your account, researching your site, generating content and publishing it where you tell us to. Legal basis: performance of a contract.
- To bill you and prevent abuse of trials. Legal basis: performance of a contract and legitimate interest.
- To secure, debug and improve the product. Legal basis: legitimate interest.
- To send product and marketing email. Legal basis: consent or legitimate interest for existing customers. You can unsubscribe at any time.
- To meet legal obligations such as tax and accounting rules. Legal basis: legal obligation.
4. AI generated content
Rankdesk uses third party AI models to research and write content. Your prompts, project settings and reference material are sent to those providers so they can return a result. We use providers that do not train their models on business API data. Do not paste sensitive personal data into briefs, prompts or keyword lists.
5. Sharing and subprocessors
We do not sell personal data. We share it only with service providers who process it on our behalf under a data processing agreement.
- Hosting and database infrastructure.
- AI model providers used for research, writing and images.
- Payment processing and invoicing.
- Email delivery and customer support tooling.
- Privacy friendly product analytics and error monitoring.
Where a provider is located outside the European Economic Area, transfers are covered by the European Commission Standard Contractual Clauses or an adequacy decision.
6. Retention
- Account and project data: for as long as your account is active. After you delete your account, data is removed within 30 days, except where we must keep it longer by law.
- Trial accounts that never convert are deleted automatically, including all project content.
- Invoices and accounting records: seven years, as required by Dutch tax law.
- Technical logs: up to 12 months.
7. Cookies
We use functional cookies to keep you signed in and to remember your language, and analytics cookies to understand how the site is used. Non essential cookies are only set with your consent, and you can withdraw that consent at any time in your browser settings.
8. Security
Data is encrypted in transit and at rest. Access to production data is limited to the people who need it, protected by strong authentication, and every project is isolated by row level access rules. No system is perfect, so if you spot a vulnerability, please email us instead of disclosing it publicly.
9. Your rights
Under the GDPR you can request access to your data, correction, deletion, restriction of processing, portability, and you can object to processing based on legitimate interest. Email us and we will respond within one month.
If you are not satisfied with our response, you can file a complaint with the Dutch Data Protection Authority, Autoriteit Persoonsgegevens.
10. Changes
We may update this policy as the product changes. Material changes are announced by email or in the app before they take effect.
This policy is governed by the law of The Netherlands.
