Data Processing Agreement
What personal data WebRankPage handles, in what capacity, and the commitments that come with it.
not yet published · InkWired Technologies Pvt. Ltd.
This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("Customer") and InkWired Technologies Pvt. Ltd. ("WebRankPage"). Its purpose is to state precisely what personal data WebRankPage handles and in what capacity, and to give you the assurances a data-protection review asks for. Where it conflicts with the Terms on the subject of data protection, this DPA prevails.
1. Roles of the parties
InkWired Technologies Pvt. Ltd. is the controller of the personal data you give us to run your account: your name, email, password hash, workspace and team data, billing details and usage records. How we handle it is set out in the Privacy Policy.
WebRankPage does not act as your processor, because you do not entrust us with anyone else's personal data. Section 3 explains why, and what follows from it.
2. Nature of the processing
| Item | Detail |
|---|---|
| Subject matter | Providing on-page SEO analysis of web pages you nominate |
| Duration | For the term of your account, plus the retention windows in the Privacy Policy |
| Purpose | Running your account, analysing the pages you submit, billing, and security |
| Categories of data subject | You and your team members. No other individuals. |
| Categories of personal data | Name, email, hashed password, workspace and role, billing name, address, state, country and GSTIN, IP address, request and API usage records |
| Special-category data | None requested and none required by the service. |
| End-user or visitor data | None. We collect nothing about the people who visit the sites you analyse. |
3. Why we are not your processor
Most tools in this category install a script on a customer's site, observe that site's visitors, and therefore handle personal data on the customer's behalf. WebRankPage works the other way round:
- Nothing is embedded. There is no snippet, no tag, and no runtime. Your site is unchanged by using us.
- We read from the outside. We request a page over HTTP exactly as a visitor or a search engine would, and analyse what the server sends back.
- We never see your visitors. No identifiers, no events, no traits, no cookies on their devices. Their existence is invisible to us.
- There is no ingestion API. Our API accepts URLs to analyse and returns reports; there is no endpoint through which you could send us personal data about anyone.
The practical consequence: using WebRankPage does not add a processor to your record of processing activities, there is no processing for you to instruct, and no controller-to-processor clauses are needed. The commitments below apply to your own account data, where we are the controller, and are given because a data-protection review reasonably asks for them either way.
One residue is worth naming. A public page can contain personal data its publisher chose to publish, and when we store an analysis of that page, that content is stored with it. We neither extract nor use it. If a stored analysis should be removed, write to [email protected].
4. Confidentiality
Personnel authorised to access personal data are bound by confidentiality obligations and access it only as needed to provide and support the service.
5. Security measures
We implement appropriate technical and organisational measures, including:
- Encryption of data in transit, and encryption at rest at the infrastructure level
- Passwords and API keys hashed one way before storage, so neither can be read back out of the database
- Workspace isolation enforced on our servers, so one customer's data is never reachable by another
- Protected session handling, cross-site request forgery protection, and brute-force protection on sign-in
- Least-data collection: we ask for a URL and an email address, and we do not ask for what we do not need
- Access controls, rate limiting, and logging for abuse prevention
6. Sub-processors
We engage service providers to help run the service, under data-protection obligations no less protective than this DPA, and we remain responsible for their performance. Our current providers are:
| Provider | Purpose | Location |
|---|---|---|
| Hosting and database provider | Application hosting, database, and data storage | India / United States |
| Cloudflare, Inc. | DNS, TLS, CDN, and DDoS protection | Global (US-headquartered) |
| Email delivery provider | Transactional and account email | United States |
| Google (PageSpeed Insights API) | Core Web Vitals field and lab data for a page being analysed, receives the URL only, never account data | Global (US-headquartered) |
| PayPal | Payment processing | Global |
We will give you reasonable notice of any new or replacement provider that handles your personal data, and you may object on reasonable data-protection grounds. To request the current list, contact [email protected].
7. International transfers
Your account data may be processed in India and in other countries where our providers operate (which may include the United States). Where we transfer personal data of EEA, UK, or Swiss data subjects to a country without an adequacy decision, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (and the UK Addendum), which are incorporated into this DPA by reference.
8. Assisting you
Taking into account the nature of the processing, we will assist you, insofar as possible, to:
- Exercise your rights of access, correction, erasure and portability. Your reports and history can be exported from the dashboard at any time, and deleting your account removes your data as described in the Privacy Policy.
- Meet your obligations for security, breach notification, and data-protection impact assessments, including by confirming in writing that no data about your users reaches us.
9. Personal data breach notification
We will notify you without undue delay after becoming aware of a personal data breach affecting your account data, and provide the information you reasonably need to meet your own obligations. Where we are the controller and the breach poses a risk to individuals' rights, we will also notify the relevant supervisory authority within 72 hours.
10. Return and deletion of data
You can export your reports and history from the dashboard at any time. When you delete your account, we delete your personal data within 30 days, except where retention is required by law (notably invoices, which tax law requires us to keep) or for a short period in routine backups, after which it is overwritten.
Stored analyses of public pages are not deleted with an account, because they describe public pages rather than people and are not tied to the account that requested them. If a particular stored analysis should be removed, ask us and we will remove it.
11. Audits
We will make available the information reasonably necessary to demonstrate compliance with this DPA and, on reasonable prior notice and subject to confidentiality, allow for audits limited to our processing of your personal data. Where available, we may satisfy audit requests by providing relevant certifications or reports.
12. Liability
Each party's liability under this DPA is subject to the limitations of liability in the Terms of Service.
13. Contact
For any matter relating to this DPA, contact us:
- Company: InkWired Technologies Pvt. Ltd.
- Address: C-101, Mahesh Nagar, Jaipur (Raj.) - 302015, India
- Email: [email protected]