GDPR Portal

GDPR Compliance.
Data Subject Authority.

This statement defines how FixRank complies with the General Data Protection Regulation, UK GDPR, and safeguards user indexing data, templates, and search console integrations.

Search compliance parameters
Table of Contents
Rights Simulator

GDPR Access Gateway

Test the compliance system by submitting a simulated data rights query.

LAST UPDATED: APRIL 2026STATUS: CERTIFIED GDPA
1

Overview

GDPR (General Data Protection Regulation) is a regulation in EU law on data protection and privacy in the European Union and the European Economic Area. FixRank is built from the ground up to respect individual privacy, enforce data minimization, and offer full transparency concerning metadata harvesting, GSC API authorization, and staging sandbox isolation.

LIMIT: FixRank is fully compliant with EU GDPR and UK GDPR standards.
2

Data Controller & Processor

Under GDPR, roles are clearly defined. FixRank acts as the Data Controller for organization profiles, workspace configurations, and billing details. FixRank acts as the Data Processor for all technical crawl assets, HTML templates, meta diagnostics, and ranking signals parsed from your registered websites.

5

Compliance with GDPR 2018

FixRank aligns all technical operations with the UK Data Protection Act 2018. We systematically assess telemetry pipelines to guarantee they are isolated, restricted, and encrypted by default.

No unnecessary tracking or profile-building.
Clear, granular cookie consent controls.
Strict data processing contracts with all cloud service vendors.
6

Types of Data We Collect & How We Use It

We gather only the minimum data required to parse page canonicals, meta elements, and organic visibility indicators. We do not index or store unrelated personal content.

Identity Data: Workspace admin name and primary billing address.
Technical Signals: Crawled page HTML nodes, site structured JSON-LD, and GSC performance rates.
Oauth Telemetry: Secure, AES-256 encrypted authentication keys.
7

Purpose of Processing

Data processing is executed strictly to calculate organic visibility metrics, recommend HTML metadata patches, simulate crawlers, validate staging changes, and enforce enterprise network security.

8

Policies & Technical Actions

We maintain internal security guidelines covering patch deployment SLAs, dual-engineer validation for CI/CD updates, periodic network scans, and immediate incident containment workflows.

9

Infrastructure and Security

Our system is hosted across highly protected Amazon Web Services (AWS) data centers located within the EU (Dublin, Ireland) and the United Kingdom (London). Backups are fully encrypted using KMS systems, and environments maintain isolation at all runtime boundaries.

10

Key Safeguards

Key technical safeguards include: End-to-end HTTPS TLS 1.3 encryption in transit, strict RBAC, automated network anomaly detection, and continuous isolation of temporary crawl storage nodes.

LIMIT: Crawl databases maintain strict database separation to protect workspace boundaries.
11

Data Retention

Staged SEO templates and temporary crawler logs are automatically deleted on a rolling 7-to-30-day schedule. Account profiles are kept while active, and legal tax receipts are stored in accordance with statutory guidelines.

12

Third-Party Data Sharing

FixRank never sells site data or templates. Technical metrics are processed only by trusted, GDPR-compliant subprocessors (Edge hosting, transactional mail) who are contractually bound to the same strict data isolation guidelines.

13

Security Measures

In compliance with GDPR Article 32, we employ robust administrative and technical controls to guarantee operational security. This includes mandatory multi-factor authentication, routine code audits, and isolated staging testing frameworks.

14

Data Subject Rights

EU and UK residents possess statutory rights over their data. These include the right to access records, correct errors, request permanent deletion ('right to be forgotten'), restrict signal processing, and receive portable data bundles.

LIMIT: All validated rights requests are legally processed and satisfied within 30 days.
15

Data Flow & Subcontract

A complete technical diagram detailing our encryption boundaries, Cloudflare Edge caches, AWS database layers, and third-party subprocessor flow is available for review by enterprise security teams.

16

Contact Information

For compliance validation, standard contractual clauses (SCCs), or corporate agreements, reach out to our team at FixRank, Inc. (10x Galaxy Ltd). Email: hello@fixrank.ai or privacy@fixrank.ai.

17

Accessibility Compliance

FixRank is dedicated to ensuring WCAG 2.1 Level AA accessibility compliance across our dashboard interfaces. We continuously test keyboard navigation and contrast ratios to ensure maximum usability.

18

Data Protection Officer (DPO)

FixRank has designated a specialized internal Data Protection Officer to supervise all compliance, DPA reviews, and rights requests. You can contact them directly: dpo@fixrank.ai.

LIMIT: Our DPO routinely audits crawler scripts to enforce absolute privacy-by-design standards.
19

Changes to This Statement

We may adjust this GDPR Compliance Statement to reflect regulatory modifications or hosting updates. The updated versions will always be posted here with revised timestamps.

isolated secure staging

Statutory Privacy Safeguards

FixRank is built upon a foundations of absolute operational privacy. Every database table, GSC sync scope, and staging log follows strict data minimization bylaws, keeping your organizational assets fully secure.

Art. 32 GDPRCompliant Security
Art. 17 GDPRAbsolute Purge
[ Statutory Integrity ]

Compliance Questions

Understand how we satisfy access requests and maintain sub-processor agreements.

Who is the primary Data Protection Officer (DPO) for FixRank?

FixRank's designated Data Protection Officer is reachable directly at dpo@fixrank.ai, handling all corporate audits and compliance inquiries.

How does FixRank guarantee compliant cross-border data transfers?

We deploy Standard Contractual Clauses (SCCs) and regional UK/EU Edge nodes ensuring transfers remain encrypted and fully protected against external leaks.

Can I request an immediate, complete purge of our site metrics?

Yes. In accordance with GDPR Article 17, workspace admins can trigger a permanent organization purge, invalidating OAuth tokens and deleting crawler diagnostics instantly.

Are the custom sandbox hotfixes aligned with Article 32 GDPR?

Yes. All staging environments, isolated VPC subnets, and code compilation pipelines employ robust security protocols satisfying strict administrative standards.