Business Data Processing Addendum

Data-processing terms for business workspaces.

Business Data Processing Addendum

Version 1.0.0 — effective 27 August 2026

1. Parties and scope

This DPA forms part of the Terms between the business customer (controller) and Dominik Hladík, IČO 08325561, trading as RankGlide (processor). It applies to ordinary personal data submitted to private business workspaces. RankGlide remains controller for its own account, billing, security, telemetry and moderation processing.

2. Processing details and instructions

Subject matter: hosted visualisation, collaboration, storage, support, AI and MCP operations selected by the customer. Duration: the customer’s service term plus deletion/backup periods. Data subjects may include the customer’s staff, contractors, clients and other individuals represented in workspace data. Data may include names, business contact details, identifiers, rankings and other ordinary content.

The customer instructs RankGlide to process this data only to provide, secure and support the service, follow documented feature choices and comply with law. Additional instructions require written agreement. The customer is responsible for lawful collection, notices, legal basis, accuracy and user permissions.

3. Prohibited data

Do not submit special-category or sensitive data, health or biometric data, criminal-conviction data, government identifiers, payment-card data, authentication secrets, or children’s data. RankGlide is not designed for those categories. Notify us promptly if prohibited data is submitted so it can be isolated and deleted.

4. Confidentiality and security

Authorised personnel are bound by confidentiality. RankGlide uses access control, encryption in transit, credential separation, logging, vulnerability and incident processes, backup controls and data minimisation proportionate to risk. On request we provide information reasonably necessary to demonstrate compliance, subject to confidentiality and security restrictions.

5. Subprocessors and transfers

Authorised categories are Supabase; Firebase/Google hosting; Resend; Cloudflare Images; Stripe where relevant; Sentry; Google Tag Manager/analytics where consented; OpenAI; and Anthropic. RankGlide imposes data-protection duties appropriate to the service and remains responsible as required by law. Material new subprocessors receive advance notice through the service or email, with a reasonable right to object on documented data-protection grounds.

International transfers use adequacy decisions, EU Standard Contractual Clauses, the UK Addendum or another valid mechanism as applicable. The parties incorporate the appropriate controller-to-processor SCC module where required. Production subprocessors, locations and mechanisms must be verified before launch and are available on request.

6. Assistance, incidents and audits

Taking account of the processing, RankGlide assists with data-subject requests, impact assessments, regulator consultations and controller obligations. We notify the customer without undue delay after becoming aware of a personal-data breach affecting customer data and provide available information. Reasonable audit questions are permitted annually; on-site audit is reserved for material unresolved risk and must minimise disruption and protect other customers.

7. Return and deletion

Customers can export workspace data during service and the retrieval period. At termination, RankGlide deletes or returns customer data at the customer’s choice unless law requires retention. Production deletion completes within 30 days after the applicable deletion date; expired backup copies are removed within 90 days. Legal, fraud, security or moderation evidence is retained only where necessary and is pseudonymised where feasible.

8. Liability, priority and contact

The Terms’ liability framework applies to this DPA subject to mandatory law. This DPA prevails for conflicts about processor obligations. Czech and English versions are intended to be equivalent. Contact: [email protected].