Data Processing Agreement

How we process data on your behalf

The agreement required by article 28 of the GDPR between you, controller of the data that appears in your content, and us, who process it on your behalf. Next to every article, in plain words, the same content in ten seconds.

Version 1.0 · in force from 4 September 2026 · integral part of the terms of service · Leggi in italiano (the binding text)

1. Parties and subject matter

This agreement supplements RankGrove’s terms of service (article 14) and governs the processing of personal data that Delion S.r.l.s. (Via Fausto Coppi 72, 00142 Rome, Italy, VAT IT14456891002, the “Processor”) carries out on behalf of the customer (the “Controller”) in providing the service, under article 28 of Regulation (EU) 2016/679.

It is accepted together with the terms of service, at sign-up, and lasts for the whole relationship. For the customer’s own data (account, billing) Delion is an independent controller: that processing is described in the privacy notice.

2. Nature, purpose, duration

The processing consists of receiving, storing, processing with artificial-intelligence systems and publishing on the Controller’s site the content of its project, and of keeping versions and a delivery log. The purpose is one: providing the service described in the terms of service.

It lasts as long as the subscription, plus the 30-day export window after the account is closed.

3. Data and data subjects

Categories of data: the personal data the Controller enters in the brief, in the project settings and in the articles, or that appears in content already on its site and read by the service: typically names, roles, quotes, business contact details. Categories of data subjects: collaborators, customers, suppliers and people mentioned by the Controller.

The service is not designed for special categories of data (health, orientation, political opinions, criminal data): the Controller undertakes not to enter them. The plugin installed on the Controller’s WordPress does not collect data about the site’s visitors.

4. Controller’s instructions

The Processor processes data only on documented instructions from the Controller. The instructions are these terms, the project configuration and the actions the Controller performs in the application (approving, publishing, regenerating, deleting). Further instructions are given in writing to info@delion.it.

If, in our view, an instruction infringes the GDPR or other data-protection law, we inform the Controller immediately before carrying it out.

5. Confidentiality of personnel

Persons authorised to process the data are bound to confidentiality by contract and trained on data-protection rules. Access to customer data is limited to those who need it to provide or support the service, and is logged.

6. Security measures

The Processor implements the technical and organisational measures of article 32 of the GDPR, including: encrypted connections; passwords stored only as hashes; connection keys encrypted in the database; server access restricted to authorised persons and logged; separation between customers (every request is bound to the organisation of the person making it, verified by automated tests at every release); encrypted backups kept with a provider other than the one hosting the database; plugin updates installable only when signed; log of operations and access.

The measures are updated over time to the state of the art; a change never lowers the level of protection.

7. Sub-processors

The Controller gives general authorisation for the sub-processors listed below, who receive only the data needed for their activity and are bound by contract to the same obligations as this agreement.

Sub-processorActivityCountry and safeguard
Scaleway SASServers, database, email sendingFrance (EU)
Cloudflare Inc.Image storage and backupsEU, standard contractual clauses
Anthropic PBC, OpenAI OpCo LLC, Google LLCText and image generationUnited States, Data Privacy Framework or standard contractual clauses; no training on data sent through the API
Stripe Payments Europe LtdPaymentsIreland (EU)
TeamSystem S.p.A. (Fatture in Cloud)Electronic invoicingItaly

Changes to the list are notified to the Controller by email at least 30 days in advance. The Controller may object on legitimate grounds within that period: in that case it may terminate the service with immediate effect, and the fees for the unused period are refunded, as an exception to article 8 of the terms. The Processor remains fully liable to the Controller for the sub-processors’ performance.

8. Transfers outside the European Union

Data is hosted in the European Union. Transfers to artificial-intelligence model providers in the United States rely on the adequacy decision for the Data Privacy Framework, where the provider is certified, or on the European Commission’s standard contractual clauses, with supplementary measures as needed. These providers receive briefs, topics and texts in progress; never the Controller’s account or billing data.

9. Assistance to the Controller

Taking into account the nature of the processing, the Processor assists the Controller in responding to data-subject requests (access, rectification, erasure, restriction, portability, objection): the application lets the Controller correct and delete content on its own; for the rest we reply within 10 days of the request. We also assist the Controller with impact assessments and consultations with the authority, as far as our processing is concerned.

Requests that a data subject addresses directly to us and that concern processing on behalf of the Controller are forwarded to the Controller without a substantive reply, unless instructed otherwise.

10. Data breaches

The Processor notifies the Controller of any personal-data breach concerning processing on its behalf without undue delay, and in any case within 48 hours of becoming aware of it, with the information available: nature of the breach, categories and approximate number of data subjects and records, likely consequences, measures taken or proposed. Missing information follows as soon as available. Notification to the authority and to data subjects remains with the Controller, whom the Processor assists.

11. End of processing

When the account is closed the Controller has 30 days to export all data from the application, in readable formats. After that the Processor deletes the personal data and existing copies, except where the law requires retention (billing data, consent records). Backups are overwritten in their ordinary cycle, within fifteen days. Articles already published on the Controller’s site stay where they are, under its control.

12. Audits

The Processor makes available to the Controller the information needed to demonstrate compliance with this agreement: description of security measures, list of sub-processors, results of internal checks. On written, reasoned request with 30 days’ notice, the Controller or an independent auditor appointed by it and bound to confidentiality may carry out an audit, once a year and during working hours, without accessing other customers’ data. Audit costs are borne by the Controller, unless material breaches emerge.

13. Liability and governing law

Liability between the parties is governed by article 82 of the GDPR and, to the extent the law allows, by article 16 of the terms of service. This agreement is governed by Italian law; the Court of Rome has jurisdiction. In case of conflict between this agreement and the terms of service, this agreement prevails on the processing of personal data.

This agreement is written in Italian. This English version is a courtesy translation: in case of discrepancy the Italian text prevails.

Delion S.r.l.s. · Via Fausto Coppi 72, 00142 Rome, Italy · Tax code and VAT IT14456891002 · info@delion.it