Compliance

Compliance is a practice,
not a badge.

FixRank operates in a changing environment of data protection, AI, consumer, security, and technology requirements. Our approach is to understand which obligations apply, build proportionate controls, document important decisions, and update our practices as the product evolves.

We distinguish between legal obligations, internal practices, roadmap work, and formal certifications.

Last updated: August 2026

Our Approach

Know the requirement. Build the control. Keep the evidence.

Compliance should not be treated as a one-time exercise. As FixRank evolves, relevant requirements may change based on what information is processed, where users are located, which service providers are used, what product capabilities are introduced, whether deeper integrations or automation are added, and which laws and regulatory frameworks apply.

Our approach is to keep obligations proportionate to the service and review them as the product changes.

Understand

Identify the requirements relevant to the product and processing activity.

Implement

Put appropriate product, security, privacy, contractual, or organizational measures in place.

Document

Keep appropriate records of important decisions and practices.

Review

Revisit controls when the product, providers, risks, or regulatory environment change.

Accountability principle

This reflects the ICO accountability principle: organizations are responsible for compliance and need measures and records capable of demonstrating it.

Current Status

What we claim — and what we don’t.

Current practice
Privacy Notice

Published information about how personal information may be handled.

Security approach

Documented security principles and user responsibilities.

Responsible AI approach

Documented treatment of AI-generated and model-estimated output.

Terms of Service

Published conditions governing use of FixRank.

Ongoing / evolving
Privacy governance

Processes and documentation evolve as data flows and service providers change.

Security controls

Controls should expand as integrations and execution capabilities deepen.

AI governance

Review practices should evolve as models and automation become more capable.

Not claimed
SOC 2 certificationNot claimed
ISO 27001 certificationNot claimed
GDPR certificationNot claimed
HIPAA certification / complianceNot claimed
PCI DSS certification by FixRankNot claimed

If we have not earned a certification, we will not display the badge.

Data Protection

Data protection starts before the privacy notice.

Where data-protection law applies, FixRank should consider privacy throughout the lifecycle of processing rather than treating privacy as a document added after a feature ships. Relevant practices may include:

  • Understanding what personal information is processed
  • Identifying purposes for processing
  • Considering an appropriate lawful basis where required
  • Limiting information to what is necessary
  • Providing transparent privacy information
  • Using appropriate service-provider arrangements
  • Implementing proportionate security
  • Supporting applicable information rights
  • Reviewing higher-risk processing where needed

The ICO describes data protection by design and default as considering privacy from the start of activities involving personal data, and data minimisation requires personal data to be adequate, relevant and limited to what is necessary.

Read Privacy
United Kingdom

UK requirements may apply depending on the processing.

10x Galaxy Ltd is a UK company, so UK data-protection requirements may be relevant to FixRank’s operations depending on the processing involved. Relevant frameworks may include:

  • UK GDPR
  • Data Protection Act 2018
  • Applicable privacy and electronic communications requirements
  • Subsequent amendments and related legislation

This list does not mean every provision applies identically to every activity or user. What applies depends on the processing context, legal role, data involved, user location, purpose, and any applicable exemptions or requirements.

International Users

One service can face different rules in different places.

FixRank may be used by customers outside the United Kingdom. Data-protection, consumer, electronic communications, AI, and other rules can vary by jurisdiction.

FixRank should therefore avoid assuming that one UK-focused policy automatically resolves every international requirement. Where additional obligations apply, they should be assessed based on the relevant service, customer, and processing context.

Service Providers & Processors

Compliance extends to the services we depend on.

FixRank relies on specialist service providers for parts of its infrastructure and operations. Where a provider processes personal information on FixRank’s behalf, appropriate contractual and operational considerations may be required. This can include:

  • Understanding what information is shared
  • Understanding the purpose of processing
  • Reviewing relevant provider terms
  • Limiting access where practical
  • Documenting important provider relationships
  • Considering international processing where applicable

ICO accountability guidance identifies written contracts with processors and appropriate documentation as important accountability measures.

Scope note

A provider's own certifications belong to that provider's scope. We do not present them as FixRank certifications.

Security & Compliance

Security supports compliance. It does not replace it.

Appropriate security is part of responsible information handling, but compliance involves more than technical controls. Relevant areas can include:

  • Access controls
  • Account protection
  • Service monitoring
  • Secure development practices
  • Incident handling
  • Data handling procedures
  • Provider management
  • Documentation
  • User transparency

The appropriate measures depend on the risks and circumstances of the processing. ICO guidance similarly describes security measures as proportionate to risk and circumstances.

Read Security
AI & Regulatory Responsibility

AI adds responsibility, not immunity.

Using AI does not remove obligations that otherwise apply to a service. FixRank should continue assessing issues such as:

  • Transparency
  • Data protection
  • Model limitations
  • Appropriate human review
  • User expectations
  • Misleading or unsupported claims
  • Impact of automation
  • Changes in AI regulation

AI-generated output should not be presented as legally authoritative simply because it was produced by an AI system.

Read Responsible AI
Autopilot & Future Execution

Deeper automation changes the compliance picture.

As FixRank moves toward future Autopilot and execution capabilities, new questions may arise around authorization, access scope, change approval, auditability, security, third-party integrations, responsibility for automated actions, and user control. These should be addressed as the relevant capability is designed and introduced.

Analysis
Recommendation
Approval
Execution

More capability should come with proportionate controls.

Roadmap capability

Autopilot is a roadmap capability and is not presented here as a current compliance control.

Consumer & Commercial Transparency

Clear product claims are part of trust.

FixRank should aim to communicate clearly about:

  • Plan pricing
  • Usage limits
  • Subscription terms
  • Renewal and cancellation behavior
  • Current features
  • Roadmap features
  • Estimates
  • AI-generated output
  • Search limitations

Marketing language should not contradict Terms, Privacy, Security, or Responsible AI disclosures.

Good

Autopilot — planned capability

Not good

Fully autonomous deployment today

when the capability has not shipped.

Good

Model-estimated AI visibility

Not good

Verified vendor data

where no direct vendor data exists.

Search Claims

Optimization is not a guarantee.

FixRank helps users analyze and improve aspects of search optimization. It does not control Google, Bing, ChatGPT, Gemini, Claude, Perplexity, or other search and AI systems.

Accordingly, FixRank should not guarantee:

  • Ranking position
  • Indexing
  • AI citation
  • Traffic
  • Recommendations
  • Conversions
  • Ranking lift

Marketing ambition and guaranteed outcome are not the same thing.

Records & Accountability

Good compliance leaves a trail.

Where appropriate, FixRank should maintain documentation relevant to important privacy, security, contractual, and operational decisions. Depending on the issue, this may include:

  • Policies
  • Data-processing records
  • Provider information
  • Contractual records
  • Security incidents
  • Consent records where relevant
  • Risk assessments
  • Decisions about higher-risk processing

This describes the compliance approach rather than a claim that every listed record already exists. ICO guidance specifically links accountability with documentation, appropriate security measures, processor contracts, and ongoing review.

Risk Assessments

Higher risk should receive greater scrutiny.

Where a new feature introduces materially different or higher-risk processing, FixRank should consider whether additional assessment is appropriate before deployment. Examples could include future functionality involving:

  • Deeper account integrations
  • Production write access
  • Sensitive personal information
  • Large-scale personal-data processing
  • Significant automated actions

This is an approach, not a statement that formal assessments have been completed for every feature.

Certifications

Certification status

Formal certifications can provide useful independent assurance when they are relevant and actually achieved. FixRank should only display a certification when:

  • The certification has been formally obtained
  • The scope includes the relevant FixRank service
  • The certification remains current
  • The claim can be verified
Current rule

No certification by implication.

We do not use logos or badges for SOC 2, ISO, GDPR, PCI DSS, HIPAA, Cyber Essentials, or other frameworks simply because a provider used by FixRank may have its own certification.

A cloud or payment provider’s certification does not automatically make FixRank itself certified.

PCI & Payments

Payment providers and FixRank are not the same compliance scope.

FixRank may use a specialist payment provider to process subscriptions. The payment provider may maintain its own security and compliance certifications. Those certifications apply according to that provider’s scope and do not automatically become FixRank certifications.

FixRank should avoid storing sensitive payment information unnecessarily and relies on the payment flow actually implemented.

Terms
Incidents & Regulatory Duties

Requirements may arise when something goes wrong.

Security or privacy incidents may create legal, contractual, or operational obligations depending on:

  • What happened
  • What information was involved
  • The affected individuals
  • The level of risk
  • Applicable law

FixRank assesses incidents based on the actual circumstances rather than promising that every incident will be reported publicly or to every regulator. No fixed notification timeline or incident-response service level is stated on this page.

Information Rights & Requests

Applicable rights should be supported.

Depending on applicable law and the context of processing, individuals may have rights relating to their personal information. Requests should be considered in accordance with:

  • The identity of the requester
  • Applicable legal requirements
  • Relevant exemptions
  • The nature of the information
  • FixRank's role in the processing
Privacy Request
FixRank is not legal advice.

Information on this Compliance page is provided to explain FixRank's approach to trust and regulatory responsibility. It is not legal advice and should not be treated as a substitute for advice from a qualified professional about a specific legal situation — especially for agencies or businesses using FixRank across different jurisdictions.

Updates

Compliance changes as the product changes.

This page may be updated as:

  • FixRank introduces new capabilities
  • Service providers change
  • Internal practices mature
  • Laws or regulatory guidance change
  • Certifications are obtained
  • The product expands into new markets

The most recent update date remains visible at the top of this page. No certification date or compliance roadmap is promised here.

Contact

Trust is stronger when claims can be verified.

FixRank will continue evolving its compliance practices as the product, customer base, service providers, and regulatory environment develop.

FixRank AI
Built by 10x Galaxy Ltd
United Kingdom