EnterRank

GDPR Compliance

Last updated 14 Jul 2026

How EnterRank meets its obligations under the General Data Protection Regulation, and how we help you meet yours.

1.Roles

For data about your own account, we are the controller. For the Google Business Profile data you connect — including the names and text of people who reviewed your business — you are the controller and we are your processor, acting only on your instructions.

2.Where data lives

Application data is hosted in the European Union. Where a sub-processor operates outside the EEA, transfers rely on Standard Contractual Clauses.

3.Security measures

Encryption in transit and at rest, least-privilege access with mandatory two-factor authentication for staff, audit logging of administrative actions, and separate environments for development and production.

4.Data subject requests

If a reviewer asks you to erase their data, you can delete the review record from your workspace and it is removed from our systems within 30 days, including backups on their normal rotation. We will assist with any request forwarded to us.

5.Breach notification

If we become aware of a personal data breach affecting your workspace, we will notify you without undue delay and in any case within 72 hours, with what we know at that point and what we are doing about it.

This document is provided for information and does not constitute legal advice. Review it with your own counsel before relying on it.