Draft — not yet effective. Several fields on this page (effective date, incorporation country, sub-processor list, data-protection contact email, governing law) are marked {{FACT_PENDING}} and will be finalised before RankCause asks a customer to sign. Do not rely on this version as a binding agreement; request an executed copy from our team instead.
The short version. RankCause acts as a data processor when it processes any personal data on behalf of a customer. This DPA sets out our obligations, your obligations, the sub-processors we use, and how to get a countersigned copy. If you just need to sign it and move on, scroll to the bottom.

1. Definitions

Capitalised terms (“Personal Data”, “Processing”, “Controller”, “Processor”, “Data Subject”) have the meaning given in Article 4 of the GDPR (Regulation (EU) 2016/679). “Customer” means the paying RankCause account holder. “RankCause” means the entity operating the service at prism.com, incorporated in {{FACT_PENDING}}.

2. Scope & role

For all Personal Data processed on behalf of the Customer, RankCause acts as Processor and the Customer acts as Controller. This DPA applies in addition to our Terms of Service and Privacy Policy and prevails in case of conflict on data-protection matters.

3. What Personal Data is processed

The following categories are processed for the duration of the Customer’s subscription:

4. Processing purposes & instructions

RankCause processes Personal Data only on the Customer’s documented instructions, which are: (a) providing the services described on the public pricing page; (b) billing and support; (c) complying with applicable law. Anything outside (a)–(c) requires explicit written instruction.

5. Sub-processors

RankCause engages the following sub-processors, each bound by written terms offering at least the same level of protection as this DPA.

Sub-processorPurposeLocation
Stripe, Inc.Payment processing (card, ACH)US, EU
Coinbase CommerceCryptocurrency payment processingUS
{{FACT_PENDING}} (cloud host)Application hosting{{FACT_PENDING}}
{{FACT_PENDING}} (email provider)Transactional email{{FACT_PENDING}}
Plausible AnalyticsPrivacy-first website analytics (no cookies)EU

When a new sub-processor is added, RankCause will update this page at least 14 days before the change takes effect. Customers who object may terminate the affected subscription for a pro-rated refund of the unused period.

6. Security

RankCause maintains appropriate technical and organisational measures including: encryption in transit (TLS 1.2+) and at rest (AES-256); role-based access control; audit logs for privileged actions; unique per-customer API tokens; least-privilege IAM on infrastructure; regular dependency and SAST scans; and documented incident response.

7. International transfers

Where Personal Data is transferred outside the EEA / UK, RankCause relies on the EU Standard Contractual Clauses (SCCs) and, for UK transfers, the UK Addendum. A copy of the executed SCCs is available on request at {{FACT_PENDING}}.

8. Data subject requests

RankCause will assist the Customer in responding to Data Subject requests (access, deletion, portability, objection, rectification) within the timeframes required by applicable law. Most requests can be serviced directly from the in-app account settings.

9. Breach notification

RankCause will notify affected Customers of a Personal Data breach without undue delay and in any event within 48 hours of becoming aware of it, via the account email on file, including the nature of the breach, categories and approximate numbers of affected Data Subjects, likely consequences, and measures taken.

10. Audit

Upon reasonable prior notice, RankCause will make available to the Customer the information necessary to demonstrate compliance with this DPA, including (where applicable) third-party audit reports such as SOC 2. On-site audits are subject to a confidentiality agreement and a commercially reasonable fee.

11. Deletion or return of data

On termination, RankCause will delete all Personal Data within 30 days, unless a longer retention is required by law. The Customer may export all account data from the in-app export tool before termination. Backups containing Personal Data are purged on a 90-day rolling cycle.

12. Term

This DPA remains in force for the duration of the Customer’s subscription and any period in which RankCause processes Personal Data on the Customer’s behalf thereafter.

13. Governing law

This DPA is governed by the law of {{FACT_PENDING}} (matching the Master Service Agreement / Terms of Service).

Sign this DPA

Most customers don’t need a countersigned copy — accepting our Terms of Service and this DPA is sufficient. If your legal team requires a signed PDF, email {{FACT_PENDING}} with your legal entity name, and we’ll send a countersigned copy within 2 business days.

Request countersigned copy