Effective date: 9 August 2026
Last updated: 9 August 2026
This Privacy Policy explains how BRAHMABIT SRL, operating the RankBIT platform (“RankBIT“, “we“, “us” or “our“), collects, uses, stores, shares and otherwise processes personal data when you:
- visit the RankBIT website;
- create a RankBIT account;
- purchase a subscription;
- use the RankBIT platform;
- communicate with us;
- request support;
- connect a website or other service to RankBIT;
- use RankBIT analytics, scanning, AI visibility monitoring or optimization functionality;
- otherwise interact with our Services.
We take the protection of personal data seriously and process personal data in accordance with applicable data-protection legislation, including Regulation (EU) 2016/679 (“GDPR“) and applicable Romanian legislation, including Law no. 190/2018. (EUR-Lex)
1. WHO WE ARE
The data controller responsible for the processing described in this Privacy Policy is:
RankBIT / BRAHMABIT SRL
VAT / CUI: RO39662046
Email: office@brahmabit.ro
Website: rankbit.ai
Website: [RANKBIT DOMAIN]
Privacy contact: [PRIVACY@DOMAIN.COM]
General support: [SUPPORT@DOMAIN.COM]
For certain data that our business customers upload, connect or otherwise provide to RankBIT for processing on their behalf, the customer may be the data controller and BRAHMABIT SRL may act as a data processor.
Those processing activities are additionally governed by our Data Processing Agreement.
2. WHAT IS RANKBIT?
RankBIT is an AI visibility, Generative Engine Optimization (“GEO”), Answer Engine Optimization (“AEO”) and digital visibility platform.
Depending on the selected Subscription, RankBIT may provide functionality involving:
- AI visibility monitoring;
- AI citation monitoring;
- AI Visibility Scores;
- competitor analysis;
- Share of Voice measurements;
- automated website scanning;
- structured-data analysis;
- schema optimization;
- content analysis;
- content recommendations;
- AI-generated content;
llms.txtanalysis;- crawler accessibility;
- product-feed optimization;
- e-commerce optimization;
- reporting;
- integrations;
- automated technical recommendations;
- managed optimization.
The data processed depends on which Services you use.
3. CATEGORIES OF PERSONAL DATA WE MAY PROCESS
We may process the following categories of information.
3.1 Account information
When you create an Account, we may collect:
- first name;
- last name;
- email address;
- username;
- encrypted or hashed password information;
- company name;
- account role;
- telephone number;
- profile information;
- preferred language;
- Account settings.
3.2 Billing and transaction information
When you purchase a Subscription, we may process:
- billing name;
- company name;
- billing address;
- country;
- VAT number;
- tax identification information;
- order number;
- Subscription plan;
- transaction amount;
- currency;
- payment status;
- payment processor reference;
- invoice information;
- Subscription renewal date;
- payment failure status;
- refund information.
Complete payment-card credentials may be processed directly by our payment service providers rather than being stored by RankBIT.
3.3 Business and project information
When configuring a RankBIT project, we may process:
- business name;
- website;
- domain;
- industry;
- geographic location;
- target markets;
- business description;
- products;
- services;
- competitors;
- keywords;
- customer personas;
- business contact details;
- business-profile information;
- brand information.
Much of this information may concern a company rather than an identifiable natural person, but where it identifies a natural person it may constitute personal data.
4. WEBSITE AND TECHNICAL INFORMATION
When you access our website or Platform, we may automatically collect technical information including:
- IP address;
- browser type;
- browser version;
- device type;
- operating system;
- approximate geographic information derived from IP;
- date and time of access;
- referring URL;
- pages visited;
- session information;
- login events;
- error logs;
- security logs;
- performance telemetry;
- cookies or similar identifiers.
Some of these data are used for security, fraud prevention, authentication, service operation and analytics.
5. PLATFORM USAGE INFORMATION
We may collect information about how you use RankBIT, including:
- features used;
- projects created;
- reports viewed;
- searches performed;
- scan configuration;
- prompts monitored;
- competitors configured;
- AI engines selected;
- generated recommendations;
- optimization history;
- integration status;
- user activity;
- account events;
- feature interactions.
This allows us to operate, secure and improve the Platform.
6. CONNECTED WEBSITE INFORMATION
If you connect a website or e-commerce store to RankBIT, we may process information available through that website or integration, including:
- page URLs;
- website content;
- metadata;
- structured data;
- schema markup;
- product information;
- product feeds;
- category information;
- technical website information;
- crawler configuration;
- site architecture;
- publicly available contact information.
RankBIT is designed primarily to analyze business and website information rather than unnecessary personal information.
7. INTEGRATION DATA
Where you authorize an integration, RankBIT may receive data from third-party services.
Depending on the integration, this could include:
- account identifiers;
- analytics information;
- website information;
- search-performance information;
- CMS information;
- product-feed data;
- e-commerce information;
- authentication tokens;
- API credentials;
- service configuration.
We process integration information only to the extent reasonably necessary to provide the functionality requested by you.
8. ACCESS CREDENTIALS AND TOKENS
Some RankBIT Services may require authentication with third-party systems.
We may therefore process:
- API keys;
- API tokens;
- OAuth tokens;
- integration credentials;
- temporary authentication credentials;
- access permissions.
Where technically possible, credentials should be stored using appropriate encryption or secure credential-management mechanisms.
Customers should provide only the permissions necessary for RankBIT to perform the requested Services.
9. SUPPORT AND COMMUNICATION DATA
If you contact us, we may process:
- name;
- email;
- phone number;
- company;
- message contents;
- attachments;
- technical diagnostic information;
- support history;
- Account information.
We may retain support communications as necessary to resolve issues, document requests and improve our Services.
10. AI PROMPTS AND AI ANALYSIS
RankBIT may generate, store or process prompts designed to evaluate how businesses appear in AI-powered systems.
These may include queries such as:
- product discovery queries;
- local-business queries;
- recommendation queries;
- competitor comparisons;
- brand-discovery queries;
- service queries.
Where possible, customers should avoid including unnecessary personal data, special-category personal data or confidential information in prompts submitted to AI systems.
11. AI-GENERATED INFORMATION
RankBIT may use artificial intelligence to generate:
- analyses;
- recommendations;
- reports;
- summaries;
- content suggestions;
- optimization instructions;
- competitive analyses;
- technical recommendations.
Inputs and outputs may be processed by RankBIT and, where necessary, by third-party AI infrastructure providers.
Where an AI provider is used as a subprocessor for customer personal data, its use may additionally be governed by the DPA and our subprocessor arrangements.
12. INFORMATION OBTAINED FROM PUBLIC SOURCES
RankBIT may analyze publicly accessible information concerning:
- websites;
- businesses;
- products;
- brands;
- competitors;
- search results;
- AI responses.
Where publicly accessible information contains personal data, it remains personal data and is handled in accordance with applicable law where GDPR applies.
13. PURPOSES AND LEGAL BASES FOR PROCESSING
Under GDPR, personal-data processing must have an applicable legal basis. RankBIT may rely principally on contractual necessity, legal obligations, legitimate interests or consent depending on the processing activity. GDPR Article 13 requires the controller to disclose the purposes and applicable legal bases. (EUR-Lex)
Providing RankBIT Services
We process information to:
- create your Account;
- authenticate users;
- provide subscriptions;
- operate projects;
- provide reports;
- run scans;
- provide integrations;
- deliver requested optimizations.
Legal basis: performance of a contract or steps taken before entering into a contract.
Billing and subscription administration
We process information to:
- process purchases;
- issue invoices;
- administer subscriptions;
- collect recurring payments;
- handle refunds;
- manage failed payments.
Legal basis: contract and applicable legal obligations.
Accounting and taxation
We may retain transaction and invoice information to satisfy statutory accounting, tax and financial obligations.
Legal basis: legal obligation.
Security and fraud prevention
We may process:
- IP addresses;
- authentication events;
- logs;
- device information;
- transaction signals;
to prevent:
- unauthorized access;
- fraud;
- abuse;
- cyberattacks;
- security incidents.
Legal basis: legitimate interests and, where applicable, legal obligations.
Our legitimate interest is protecting RankBIT, our customers, infrastructure and users.
Service improvement
We may analyze Platform usage to:
- diagnose problems;
- understand feature usage;
- improve performance;
- improve UX;
- improve RankBIT functionality.
Legal basis: legitimate interests.
Where legally required, consent will be obtained.
Customer support
We process communications and Account information to respond to requests.
Legal basis: contract and/or legitimate interests.
Marketing communications
Where permitted, we may send information about:
- new RankBIT functionality;
- product updates;
- promotions;
- relevant services.
Depending on applicable law and circumstances, this may rely on consent or another legally permitted basis.
You can unsubscribe from optional marketing communications at any time.
14. COOKIES AND SIMILAR TECHNOLOGIES
We may use:
- cookies;
- local storage;
- session storage;
- tracking pixels;
- similar technologies.
These are described separately in our Cookie Policy.
Romanian Law 506/2004 provides that storing information or accessing information stored on a user’s terminal equipment generally requires the user’s agreement and prior information, subject to applicable statutory exceptions.
Cookies that legally require consent will not be intentionally activated before obtaining valid consent through our consent-management mechanism.
15. WHO MAY RECEIVE PERSONAL DATA?
Depending on the Service, personal data may be disclosed to categories of recipients including:
- cloud hosting providers;
- infrastructure providers;
- payment processors;
- transactional email providers;
- customer-support providers;
- analytics providers;
- cybersecurity providers;
- AI service providers;
- software providers;
- professional advisers;
- accountants;
- legal advisers;
- contractors acting under appropriate confidentiality obligations;
- competent authorities where required by law.
We seek to limit disclosures to what is reasonably necessary for the relevant purpose.
16. SUBPROCESSORS
Where BRAHMABIT SRL acts as processor on behalf of a customer, certain suppliers may act as subprocessors.
A current list may be provided through:
[SUBPROCESSOR PAGE URL]
or upon request at:
[PRIVACY EMAIL]
The DPA governs the engagement of subprocessors for customer-controlled personal data.
17. THIRD-PARTY AI PROVIDERS
Certain RankBIT functionality may interact with third-party AI models or APIs.
Information submitted to an AI provider will depend on the relevant RankBIT feature.
We aim to minimize unnecessary personal information submitted to such systems.
Customers must not intentionally submit highly sensitive or unnecessary personal information through AI-analysis features unless RankBIT has expressly confirmed that such processing is appropriate for the relevant Service.
18. INTERNATIONAL DATA TRANSFERS
Some service providers may process information outside Romania or the European Economic Area.
Where GDPR applies, international transfers must satisfy the requirements of Chapter V GDPR. Article 44 requires controllers and processors to ensure that the GDPR level of protection is not undermined by transfers to third countries. (EUR-Lex)
Depending on the destination and provider, RankBIT may rely on:
- European Commission adequacy decisions;
- Standard Contractual Clauses;
- supplementary safeguards;
- another valid transfer mechanism under applicable law.
The European Commission’s current Standard Contractual Clauses for relevant third-country transfers were adopted through Implementing Decision (EU) 2021/914. (EUR-Lex)
19. DATA RETENTION
We retain personal data only for as long as reasonably necessary for the purposes for which it was collected and for applicable legal, contractual, security and dispute-resolution requirements.
Retention periods may vary depending on the data.
Examples include:
Account data
Usually retained while the Account remains active and for a reasonable period thereafter where necessary.
Subscription information
Retained as necessary for subscription management and applicable financial and accounting requirements.
Invoices and tax records
Retained for applicable statutory periods.
Security logs
May be retained for a limited period appropriate for cybersecurity, fraud prevention and incident investigation.
Support tickets
May be retained where necessary to maintain support history and defend legal claims.
Customer project data
Generally retained while the customer has an active Service and for a reasonable deletion period following termination.
Specific contractual retention provisions may be established in an enterprise agreement or DPA.
20. ACCOUNT DELETION
Customers may request Account deletion by contacting:
[PRIVACY EMAIL]
Deletion may not result in immediate removal of every record.
We may retain information where required for:
- tax;
- accounting;
- legal obligations;
- fraud prevention;
- security;
- exercise or defence of legal claims;
- backup integrity.
21. BACKUPS
Information deleted from active systems may remain temporarily in secured backups until those backups are overwritten through normal retention cycles.
Backup data is not intended to be restored except for legitimate recovery or continuity purposes.
22. SECURITY
We implement technical and organizational measures designed to protect personal data.
Depending on the relevant system, these may include:
- encryption in transit;
- encryption at rest where appropriate;
- access controls;
- role-based permissions;
- strong authentication;
- credential management;
- backups;
- logging;
- monitoring;
- patch management;
- malware protection;
- infrastructure security;
- incident-response procedures;
- employee or contractor confidentiality requirements.
GDPR Article 32 requires controllers and processors to implement technical and organizational measures appropriate to the risk, potentially including encryption, resilience, restoration capabilities and regular security testing. (EUR-Lex)
No online system can nevertheless be guaranteed to be completely immune from unauthorized access or security incidents.
23. PERSONAL DATA BREACHES
If we become aware of a personal-data breach, we will take reasonable steps to investigate, contain and remediate it.
Where BRAHMABIT SRL acts as controller, legally required notifications will be made in accordance with applicable data-protection legislation.
GDPR provides that controllers must notify the competent supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of a qualifying breach; processors must notify the relevant controller without undue delay. (EUR-Lex)
Where we act as processor, our obligations are further addressed in the DPA.
24. YOUR GDPR RIGHTS
Subject to applicable conditions and exemptions, individuals may have rights including:
- right of access;
- right to rectification;
- right to erasure;
- right to restriction;
- right to data portability;
- right to object;
- right to withdraw consent;
- rights relating to certain automated decisions.
The Romanian supervisory authority similarly identifies access, rectification, erasure, restriction, portability, objection and rights concerning solely automated decisions among GDPR rights. (Data Protection)
25. HOW TO EXERCISE YOUR RIGHTS
Requests may be sent to:
[PRIVACY EMAIL]
Please provide enough information to enable us to identify:
- you;
- the relevant Account;
- the right being exercised.
We may request reasonable identity verification where necessary to avoid unauthorized disclosure or deletion of data.
26. WITHDRAWING CONSENT
Where processing relies upon your consent, you may withdraw that consent at any time.
Withdrawal does not affect the lawfulness of processing performed before withdrawal.
For cookie consent, preferences can be changed through:
Cookie Settings
or the consent-management interface available on the website.
27. RIGHT TO OBJECT
Where processing is based on legitimate interests, you may have the right to object based on circumstances relating to your particular situation.
For qualifying direct marketing, you may object at any time.
28. COMPLAINTS TO THE SUPERVISORY AUTHORITY
You also have the right to lodge a complaint with a competent data-protection supervisory authority.
For Romania, the competent authority is:
Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal — ANSPDCP
ANSPDCP provides an electronic complaint process and accepts qualifying complaints under GDPR. (Data Protection)
Its currently published headquarters are at 28–30 General Gheorghe Magheru Boulevard, District 1, Bucharest, Romania. (Data Protection)
29. AUTOMATED DECISION-MAKING
RankBIT may automatically:
- calculate scores;
- classify visibility;
- generate recommendations;
- detect technical issues;
- prioritize optimization actions.
These functions are designed primarily as analytics and operational tools.
Unless explicitly stated otherwise, RankBIT does not intend such scoring alone to produce legal or similarly significant effects concerning natural persons.
30. CHILDREN
RankBIT is a business-oriented service and is not intended for children.
We do not knowingly design the Platform to solicit personal information from children.
If you believe a child has provided personal data to RankBIT inappropriately, please contact us.
31. LINKS TO THIRD-PARTY SERVICES
RankBIT may contain links or integrations with third-party websites and services.
Their privacy practices are governed by their own privacy notices, and RankBIT is not responsible for processing independently performed by those third parties.
32. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy where necessary to reflect:
- Service changes;
- new features;
- legal requirements;
- security changes;
- processing changes.
The latest version will display its revision date.
Where required by applicable law, we will provide additional notice of material changes.
33. CONTACT
Questions concerning privacy may be sent to:
RankBIT / BRAHMABIT SRL
VAT / CUI: RO39662046
Email: office@brahmabit.ro
Website: rankbit.ai