Data Processing Addendum
Last updated August 7, 2026
This Data Processing Addendum (the “DPA”) is incorporated into the agreement between DMA Labs, which operates rating.so (the “Processor”, “we”), and the customer that accepts our Terms of Service (the “Controller”, “you”). It governs any processing of personal data that we carry out on your behalf when you use rating.so for business, agency or client work. No signature is required — these terms take effect automatically upon such use. Should you require a countersigned copy, write to hello@rating.so.
1. Subject matter and duration
The subject matter of the processing is the provision of the rating.so service: Domain Rating and backlink monitoring, report generation, alerts and digests, and public pages. Processing continues for as long as you use the Service and thereafter only for the limited period set out in section 6 (Deletion and return).
2. Nature and purpose of processing
We host, store, transmit, analyse and display the data you submit to the Service; we deliver the email, Slack, webhook and Telegram notifications you have configured; and we process payments for your subscription. We do not process your data for any purpose of our own.
3. Categories of data and data subjects
Data subjects are the members of your team who hold accounts, together with any contacts whose details you supply to us — for instance, the recipients of white-label client reports.
Categories of personal data comprise names, email addresses, account identifiers, the OAuth tokens or webhook URLs belonging to integrations you connect, usage data, billing records, and the content of messages you send through the Service. Website metrics — Domain Rating, backlinks, referring domains and traffic figures — describe websites rather than identified or identifiable individuals and therefore fall outside these categories.
4. Our obligations as Processor
We process personal data solely on your documented instructions, which comprise this DPA, our agreement, and the configuration you apply within the Service, save where we are required to process data by law binding on us. Personnel authorised to access personal data are bound by an obligation of confidentiality. Taking into account the nature of the processing, we provide reasonable assistance with requests from data subjects exercising their rights and with your own obligations under Articles 32 to 36 GDPR. We will notify you without undue delay after becoming aware of any personal data breach affecting your data.
5. Security measures
We maintain appropriate technical and organisational measures, including transport-layer encryption (TLS) across all traffic, encryption at rest with our infrastructure providers, role-gated administrative access, hashed credentials, scoped access tokens, per-route rate limiting, and rolling encrypted backups. Payment card details are handled exclusively by Stripe and are never transmitted to or stored on our systems.
6. Deletion and return
You may export your data in CSV format at any time from Settings, where you may also delete your account. Deletion erases personal data from our production systems immediately and from rolling backups within a matter of weeks. Where retention is mandated by law — payment records held by Stripe, for example — such records are kept for the statutory period and no longer.
7. Sub-processors
You grant us general authorisation to engage sub-processors for the purposes described in section 2. Each sub-processor is bound by data protection obligations no less protective than those set out in this DPA, and we remain fully liable to you for their performance. We will give you reasonable prior notice of any intended addition or replacement of a sub-processor, to which you may object on reasonable data protection grounds. A current list of sub-processors is available on request to hello@rating.so.
8. International transfers
Where a sub-processor processes personal data outside the European Economic Area, that transfer is made under the EU–U.S. Data Privacy Framework or under the European Commission’s Standard Contractual Clauses. To the extent that a transfer from you to us requires them, the Standard Contractual Clauses (Module Two, controller to processor) are incorporated into this DPA by reference.
9. Audit
On request to hello@rating.so we will make available the information reasonably necessary to demonstrate compliance with this DPA, together with our Privacy Policy and our security documentation.
10. Contact
DMA Labs · hello@rating.so