Last updated 29 July 2026
This agreement forms part of the Terms of Service and applies where Ratelytics processes personal data on your behalf.
It is written to satisfy Article 28 of the UK GDPR without making you hire someone to read it. No signature is needed: it applies automatically to every workspace.
You (the customer) are the controller. NextGen Software Ltd trading as Ratelytics (“Ratelytics”, “we”) is the processor. This agreement is governed by the UK GDPR and the Data Protection Act 2018, and by the laws of England and Wales, the same as the terms.
One exception, before any of this applies. The free autopsy teaser on ratelytics.io/autopsy can be used by anyone, with no account and no acceptance of the Terms. There is no customer and no workspace at that moment, so there is no controller for us to process on behalf of: for that visit Ratelytics is the controller of the computed findings it holds, and this agreement does not apply. The controller-and-processor framing in this document begins at account creation and covers everything from that point on. What is processed during a teaser, on what basis and for how long, is set out in the privacy policy under “What we collect” and “Retention and deletion”.
The subject matter is the personal data Ratelytics touches while running your workspace. The agreement lasts as long as your subscription does, plus the short window it takes to delete or return data afterwards.
Ratelytics reads usage and cost metadata from AI providers and, if you enable Company mode, revenue metadata from Stripe, using keys you supply. The purpose is to present spend, margins, reports and alerts back to you. Processing is storage, aggregation and display: never in your request path, and never prompts, completions or model content of any kind.
Separately, and only where a visitor asks for the free autopsy teaser before creating an account: a CSV they choose is parsed in memory to compute a sample report. The file is never written to storage. Only the computed findings are retained, against a random session token that is not linked to an email address, an IP address or a device fingerprint, and they are deleted two hours after they are produced whether or not a purchase follows. If a purchase does follow, those findings become the first content of the new workspace and this agreement applies to them from that moment.
Public pages that accept a file are rate limited, which requires recognising repeat requests from one network. A one-way hash of the requesting IP address is stored, never the address, salted with a secret that rotates daily, as a count per hash per hour rather than a record of individual requests, in a table sharing no key with the teaser findings and with no join path between the two. The counts are deleted by the hourly clean-up and exist for at most two hours. This is abuse-prevention processing carried out on Ratelytics’ own behalf, not on a customer’s; it is described here for completeness rather than because it forms part of the processing performed for you.
No special category data is expected or wanted. The service is not designed for it; do not send it.
You give general written authorisation for the subprocessors below. Each is bound by a contract imposing data protection obligations at least as protective as this agreement. We give at least 30 days' notice by email before adding or replacing one; you may object on reasonable data protection grounds, and if we cannot resolve the objection you may terminate and export.
| Subprocessor | Purpose | Location and transfer basis |
|---|---|---|
| Vercel | Hosting and edge network | US/EU: UK addendum to the EU SCCs |
| Neon | PostgreSQL database | US/EU: UK addendum to the EU SCCs |
| Stripe | Payments and billing | US/EU: UK addendum to the EU SCCs |
| Resend | Transactional email | US: UK addendum to the EU SCCs |
Where personal data leaves the UK, the transfer relies on UK adequacy regulations where they apply, and otherwise on the UK International Data Transfer Agreement or the UK addendum to the EU Standard Contractual Clauses, as noted in the table above.
Liability under this agreement is subject to the same cap and exclusions as the terms. Nothing limits liability that cannot lawfully be limited.
If this agreement and the terms conflict about the processing of personal data, this agreement wins. On everything else, the terms win.
Anything unclear, or your procurement team needs it on paper: email privacy@ratelytics.io.