GDPR Compliance.
Data Subject Authority.
This statement defines how FixRank complies with the General Data Protection Regulation, UK GDPR, and safeguards user indexing data, templates, and search console integrations.
GDPR Access Gateway
Test the compliance system by submitting a simulated data rights query.
Overview
GDPR (General Data Protection Regulation) is a regulation in EU law on data protection and privacy in the European Union and the European Economic Area. FixRank is built from the ground up to respect individual privacy, enforce data minimization, and offer full transparency concerning metadata harvesting, GSC API authorization, and staging sandbox isolation.
Data Controller & Processor
Under GDPR, roles are clearly defined. FixRank acts as the Data Controller for organization profiles, workspace configurations, and billing details. FixRank acts as the Data Processor for all technical crawl assets, HTML templates, meta diagnostics, and ranking signals parsed from your registered websites.
Legal Base
We process personal and technical signals under the following explicit GDPR legal bases: Contractual Necessity (Art. 6(1)(b)) to perform crawling and render staging codes, Legitimate Interests (Art. 6(1)(f)) to secure our global Edge clusters and prevent denial-of-service crawling loops, and Consent (Art. 6(1)(a)) for account notifications and browser preferences.
Consent & Specific Processing
We obtain clear, unambiguous consent before establishing synchronizations with third-party tools like Google Search Console or GA4. You hold complete authority to instantly revoke this access at any moment via your workspace dashboard, which completely purges OAuth tokens.
Compliance with GDPR 2018
FixRank aligns all technical operations with the UK Data Protection Act 2018. We systematically assess telemetry pipelines to guarantee they are isolated, restricted, and encrypted by default.
Types of Data We Collect & How We Use It
We gather only the minimum data required to parse page canonicals, meta elements, and organic visibility indicators. We do not index or store unrelated personal content.
Purpose of Processing
Data processing is executed strictly to calculate organic visibility metrics, recommend HTML metadata patches, simulate crawlers, validate staging changes, and enforce enterprise network security.
Policies & Technical Actions
We maintain internal security guidelines covering patch deployment SLAs, dual-engineer validation for CI/CD updates, periodic network scans, and immediate incident containment workflows.
Infrastructure and Security
Our system is hosted across highly protected Amazon Web Services (AWS) data centers located within the EU (Dublin, Ireland) and the United Kingdom (London). Backups are fully encrypted using KMS systems, and environments maintain isolation at all runtime boundaries.
Key Safeguards
Key technical safeguards include: End-to-end HTTPS TLS 1.3 encryption in transit, strict RBAC, automated network anomaly detection, and continuous isolation of temporary crawl storage nodes.
Data Retention
Staged SEO templates and temporary crawler logs are automatically deleted on a rolling 7-to-30-day schedule. Account profiles are kept while active, and legal tax receipts are stored in accordance with statutory guidelines.
Third-Party Data Sharing
FixRank never sells site data or templates. Technical metrics are processed only by trusted, GDPR-compliant subprocessors (Edge hosting, transactional mail) who are contractually bound to the same strict data isolation guidelines.
Security Measures
In compliance with GDPR Article 32, we employ robust administrative and technical controls to guarantee operational security. This includes mandatory multi-factor authentication, routine code audits, and isolated staging testing frameworks.
Data Subject Rights
EU and UK residents possess statutory rights over their data. These include the right to access records, correct errors, request permanent deletion ('right to be forgotten'), restrict signal processing, and receive portable data bundles.
Data Flow & Subcontract
A complete technical diagram detailing our encryption boundaries, Cloudflare Edge caches, AWS database layers, and third-party subprocessor flow is available for review by enterprise security teams.
Contact Information
For compliance validation, standard contractual clauses (SCCs), or corporate agreements, reach out to our team at FixRank, Inc. (10x Galaxy Ltd). Email: hello@fixrank.ai or privacy@fixrank.ai.
Accessibility Compliance
FixRank is dedicated to ensuring WCAG 2.1 Level AA accessibility compliance across our dashboard interfaces. We continuously test keyboard navigation and contrast ratios to ensure maximum usability.
Data Protection Officer (DPO)
FixRank has designated a specialized internal Data Protection Officer to supervise all compliance, DPA reviews, and rights requests. You can contact them directly: dpo@fixrank.ai.
Changes to This Statement
We may adjust this GDPR Compliance Statement to reflect regulatory modifications or hosting updates. The updated versions will always be posted here with revised timestamps.
Consent Agreement
By creating a workspace, binding your site, or utilizing our autonomous SEO crawlers, you acknowledge that you have reviewed and consented to the data processing terms outlined in this compliance statement.
Statutory Privacy Safeguards
FixRank is built upon a foundations of absolute operational privacy. Every database table, GSC sync scope, and staging log follows strict data minimization bylaws, keeping your organizational assets fully secure.
Compliance Questions
Understand how we satisfy access requests and maintain sub-processor agreements.
Who is the primary Data Protection Officer (DPO) for FixRank?
FixRank's designated Data Protection Officer is reachable directly at dpo@fixrank.ai, handling all corporate audits and compliance inquiries.
How does FixRank guarantee compliant cross-border data transfers?
We deploy Standard Contractual Clauses (SCCs) and regional UK/EU Edge nodes ensuring transfers remain encrypted and fully protected against external leaks.
Can I request an immediate, complete purge of our site metrics?
Yes. In accordance with GDPR Article 17, workspace admins can trigger a permanent organization purge, invalidating OAuth tokens and deleting crawler diagnostics instantly.
Are the custom sandbox hotfixes aligned with Article 32 GDPR?
Yes. All staging environments, isolated VPC subnets, and code compilation pipelines employ robust security protocols satisfying strict administrative standards.