GDPR
Last updated: October 10, 2026
This page explains how RankDebug meets the General Data Protection Regulation for people in the EU and EEA, and the equivalent UK and Swiss laws.
1. Controller
For account, billing and website data, the controller is:
Porter Bridge, LLC
131 Continental Dr, Suite 305
Newark, DE 19713
United States
For personal data inside data a customer connects or uploads, the customer is the controller and we are its processor under our DPA.
2. Legal bases
- Contract (Art. 6(1)(b)): operating your account and providing the service.
- Legitimate interests (Art. 6(1)(f)): securing the service, answering contact and demo requests, and understanding how our website is used.
- Consent (Art. 6(1)(a)): newsletters, which you can leave at any time.
- Legal obligation (Art. 6(1)(c)): keeping invoices and accounting records.
3. What we process
Account details of workspace users; aggregated search, analytics and CDN data from sources you connect; public pages fetched by our crawler; deploy metadata; files, comments and agent questions you submit; and website contact submissions. Our privacy policy describes each in detail.
4. Your rights
You have the right to access, rectify and erase your personal data, to restrict or object to its processing, to data portability, and to withdraw consent at any time.
Use our contact form to make a request. We respond within one month. If your data is held for a customer that controls it, we pass the request to that customer.
5. Subprocessors
We use providers in these categories: cloud infrastructure, email delivery, payment processing, AI processing, product analytics and error monitoring. The named list is part of our DPA and available to customers on request.
6. International transfers
We are based in the United States. Transfers of personal data from the EU, EEA, UK or Switzerland rely on the Standard Contractual Clauses or another valid safeguard.
7. Retention
Workspace data is kept while the workspace exists, because long-term history is part of the service. Account data is kept while your account is active. On a deletion request, we delete it except for records the law requires us to keep.
8. Security
Industry-standard encryption in transit and at rest, encrypted storage of credentials, read-only connections, per-workspace separation and limited staff access.
9. Breach notification
If a breach is likely to result in a risk to your rights, we notify the competent supervisory authority within 72 hours of becoming aware of it, and notify you directly where the risk is high.
10. Complaints
Please tell us first through our contact form. You also have the right to lodge a complaint with the supervisory authority where you live or work.