Legal
Privacy Policy and Agreement
Effective Date: July 31, 2026
Rynk (“Rynk,” “we,” “us,” or “our”) is an AI-driven software company that helps small and midsize businesses improve how they are discovered and represented across AI assistants, such as ChatGPT, Gemini, Copilot, Perplexity, and Claude, and traditional search engines.
Our platform uses artificial intelligence, automated data processing, and machine-generated analysis to evaluate, recommend, and, where authorized by a client, implement changes to a client’s online presence, website content, business listings, and structured data.
This Privacy Policy explains what information we collect, where we obtain it, how we use and disclose it, how our AI systems process it, how long we retain it, and the choices available to you.
This Privacy Policy applies when you visit our website, create a Rynk account, communicate with us, or use our products and services collectively referred to as the “Services.”
This Privacy Policy is a notice of our privacy practices and does not replace or modify our Terms of Service, Data Processing Addendum, or any other agreement between Rynk and a client.
1. Information We Collect
We may collect the following categories of information:
Account and Contact Information
We may collect your name, business name, job title, email address, phone number, billing address, account identifiers, login credentials, and other information used to create and manage your Rynk account.
Business and Website Data
We may collect or process:
- Website URLs and website content;
- Business names, addresses, hours, contact details, and listings;
- Publicly available business information;
- Reviews, ratings, keywords, and search-related information;
- Structured data and website metadata;
- Website traffic and analytics;
- Search performance information;
- Business profiles and directory listings;
- Content, files, or records that you upload or connect to the Services; and
- Other information you authorize us to access to provide AI recommendations, analytics, and dashboards.
Business and website data may include personal information about business owners, employees, contractors, customers, reviewers, or other individuals.
Payment Information
Payments are processed through third-party payment processors. Rynk does not store complete payment card numbers. We may receive limited payment-related information, such as billing status, transaction date, payment method type, and the last four digits of a payment card.
Usage and Device Data
We may automatically collect information about how you access and use the Services, including:
- IP address;
- Browser type;
- Operating system;
- Device type and identifiers;
- Referring URLs;
- Pages viewed;
- Features used;
- Dates and times of access;
- Session activity;
- Error and diagnostic information; and
- Interactions with the Services.
This information may be collected through cookies, log files, software development kits, pixels, and similar technologies.
AI Interaction Data
We may process:
- Prompts;
- Queries;
- Instructions;
- Uploaded content;
- Feedback;
- User inputs;
- AI-generated outputs;
- Recommendations;
- Draft content;
- Suggested edits; and
- Other interactions with Rynk’s AI-enabled features.
Communications
We may collect information you provide when you contact us for sales, support, billing assistance, product feedback, or other communications.
Integration and Authentication Data
When you connect a third-party website, analytics provider, business listing, content management system, or other platform to Rynk, we may receive authentication tokens, permissions, account identifiers, configuration information, and data made available through that integration.
Where possible, Rynk uses access tokens or delegated permissions rather than collecting your third-party account password.
2. Sources of Information
We may obtain information from the following sources:
- Directly from you when you create an account, use the Services, submit a prompt, contact us, or provide information;
- From your employer, organization, account administrator, or another authorized user;
- From websites, business listings, search engines, online directories, review platforms, social media pages, and other publicly available sources;
- From third-party platforms and services that you connect to Rynk;
- From analytics, advertising, security, and technology service providers;
- Through cookies and similar technologies;
- From payment processors and billing providers; and
- Through our own analysis of information collected or provided through the Services.
Clients are responsible for ensuring that they have the necessary authority, permissions, and legal basis to provide personal information and other data to Rynk or authorize Rynk to access it.
3. How We Use Information
We may use information to:
- Create, administer, authenticate, and support user accounts;
- Operate, maintain, secure, and improve the Services;
- Analyze a client’s online presence;
- Generate visibility scores, reports, competitive comparisons, and recommendations;
- Develop content, structured data, business listing, and search-visibility recommendations;
- Create drafts and suggested edits for client review;
- Implement changes that have been authorized by a client;
- Provide dashboards, analytics, reporting, and performance measurements;
- Personalize the Services for a client or authorized user;
- Process payments and manage billing;
- Communicate about accounts, transactions, updates, security, and support requests;
- Respond to feedback and improve product functionality;
- Test and evaluate the performance, safety, and accuracy of the Services;
- Detect, investigate, and prevent fraud, misuse, unauthorized access, and security incidents;
- Maintain audit logs and enforce access controls;
- Comply with legal obligations;
- Establish, exercise, or defend legal claims; and
- Enforce our agreements and policies.
Rynk does not sell personal information for monetary compensation.
4. Use of Customer Data for AI Training
Rynk does not use Client Data, customer prompts, customer inputs, or customer-specific AI outputs to train generalized artificial intelligence or machine-learning models without the client’s prior written approval.
For purposes of this Policy, “Client Data” means information submitted to, uploaded to, connected to, or processed through the Services on behalf of a client. Client Data includes nonpublic website information, connected analytics, prompts, instructions, files, drafts, reports, recommendations, and customer-specific AI outputs.
Written approval must be affirmative, specific, and provided by an authorized representative of the client. A client’s use of the Services alone does not constitute approval for model training.
Unless a client provides written approval, Rynk will not use Client Data to:
- Train or fine-tune a generalized Rynk model;
- Train a model for the benefit of unrelated customers;
- Permit a third-party AI provider to train its generalized models; or
- Develop commercial models or datasets unrelated to providing the Services to that client.
Rynk may use limited technical and operational information that does not identify a client or individual to maintain, secure, measure, and improve the Services. This may include aggregated statistics, de-identified product telemetry, error rates, latency measurements, feature usage, and security information.
Rynk will take reasonable measures designed to prevent de-identified information from being associated with an identifiable person or client and will not attempt to reidentify information that has been properly de-identified.
Rynk may use feedback voluntarily submitted by a user to evaluate and improve the Services. Where feedback contains Client Data or personal information, the restrictions described in this section continue to apply unless the client separately authorizes broader use in writing.
5. How Our AI Systems Process Information
Rynk’s Services use automated and AI-assisted processing to analyze connected data sources and generate outputs such as:
- Visibility scores;
- Content recommendations;
- Competitive comparisons;
- Website analyses;
- Structured-data recommendations;
- Business listing recommendations;
- Draft website content;
- Suggested edits;
- Reports; and
- Other machine-generated insights.
AI-generated outputs are probabilistic and may be incomplete, inaccurate, outdated, or inappropriate for a particular use. Clients and authorized users should independently review AI-generated recommendations and outputs before relying on, publishing, or implementing them.
Rynk may use third-party AI models and infrastructure providers to process information as part of delivering the Services. Rynk seeks to contractually restrict such providers from using Client Data for their own generalized model training unless the client has provided prior written approval.
Rynk personnel may access Client Data only where reasonably necessary to:
- Provide support requested by the client;
- Investigate security incidents or suspected misuse;
- Maintain or troubleshoot the Services;
- Perform client-authorized professional services;
- Comply with legal obligations; or
- Protect the rights and safety of Rynk, its clients, and others.
Access to Client Data is subject to appropriate authorization, confidentiality obligations, and access controls.
The Services are not intended to make decisions that produce legal or similarly significant effects concerning individuals without appropriate human review.
6. Rynk’s Role as Controller and Processor
Depending on the context, Rynk may act as either a controller of personal information or a processor acting on behalf of a client.
Rynk as a Controller
Rynk acts as a controller, or in an equivalent role under applicable privacy law, when it determines the purposes and means of processing personal information for its own business operations.
These controller activities may include processing information for:
- Account registration and administration;
- Billing and payment management;
- Direct communications with users;
- Sales and marketing;
- Website analytics;
- Product security;
- Fraud and abuse prevention;
- Legal compliance;
- Internal business operations; and
- Maintaining business and transaction records.
When Rynk acts as a controller, this Privacy Policy governs how Rynk processes personal information.
Rynk as a Processor
Rynk acts as a processor, service provider, contractor, or equivalent entity when it processes Client Data on behalf of a client and under the client’s instructions.
Processor activities may include:
- Analyzing client websites and online profiles;
- Processing connected analytics;
- Generating client-specific recommendations;
- Creating drafts and reports;
- Processing client prompts;
- Managing client-authorized website or listing changes; and
- Performing other processing described in the applicable service agreement.
When Rynk acts as a processor, the client generally determines why and how the personal information is processed. Individuals seeking to exercise rights concerning information processed by Rynk solely on behalf of a client should ordinarily direct their requests to that client.
Rynk will reasonably assist clients in responding to applicable privacy requests where required by law or contract.
Data Processing Addendum
Rynk offers a Data Processing Addendum, or “DPA,” governing Rynk’s processing of Client Data on behalf of clients.
The DPA addresses matters including:
- The subject matter and duration of processing;
- The nature and purposes of processing;
- The categories of personal information and affected individuals;
- Client instructions;
- Confidentiality;
- Information security;
- Use of subprocessors;
- Assistance with privacy-rights requests;
- Security incident notification;
- Deletion or return of Client Data;
- Audit and compliance obligations; and
- International data-transfer safeguards.
Where the DPA conflicts with this Privacy Policy regarding Rynk’s processing of Client Data as a processor, the DPA and the applicable client agreement will control.
Clients may request Rynk’s DPA by contacting privacy@rynk.ai.
7. How We Disclose Information
We may disclose information to the following categories of recipients:
Service Providers and Subprocessors
We may disclose information to vendors that provide services such as:
- Cloud hosting;
- Data storage;
- AI infrastructure;
- Analytics;
- Payment processing;
- Customer support;
- Email delivery;
- Authentication;
- Security monitoring;
- Logging;
- Error detection; and
- Other technical and professional services.
These providers may process information only as necessary to provide services to Rynk and are subject to contractual confidentiality, privacy, and security obligations where required.
AI Providers
We may transmit prompts, instructions, relevant context, or other information to third-party AI providers when necessary to provide AI-enabled features.
Rynk seeks to configure and contract with these providers so that Client Data is not used to train their generalized models unless the affected client has provided prior written approval.
AI Assistants, Search Engines, and Online Platforms
When a client authorizes publication or submission, Rynk may disclose approved content, business listings, website information, or structured data to search engines, AI assistants, business directories, content platforms, or other third-party services.
Information submitted to these platforms may become publicly available and may be indexed, cached, copied, transformed, or retained by third parties outside Rynk’s control.
Professional Advisers
We may disclose information to lawyers, accountants, auditors, insurers, consultants, and other professional advisers where reasonably necessary for legitimate business or legal purposes.
Legal and Safety Purposes
We may disclose information when we reasonably believe disclosure is necessary to:
- Comply with applicable law, regulation, court order, or lawful government request;
- Enforce our agreements;
- Investigate fraud, misuse, or security incidents;
- Protect the rights, property, or safety of Rynk, our clients, users, or others; or
- Establish, exercise, or defend legal claims.
Business Transactions
We may disclose information in connection with a proposed or completed merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar transaction.
Any recipient will be expected to process personal information in accordance with applicable law and any confidentiality commitments associated with the transaction.
With Your Direction or Consent
We may disclose information when you direct us to do so or provide consent.
8. Subprocessors
Rynk may engage subprocessors to support delivery of the Services. Subprocessors may include cloud infrastructure providers, AI model providers, analytics vendors, authentication providers, support platforms, and security vendors.
Rynk evaluates subprocessors based on factors such as:
- The nature of the information processed;
- Security and privacy practices;
- Data-location practices;
- Contractual protections;
- Retention practices;
- Use of information for model training;
- Incident-response capabilities; and
- Compliance with applicable data-protection requirements.
Where Rynk acts as a processor, subprocessors are required to process Client Data only for authorized purposes and in accordance with contractual obligations that are materially consistent with Rynk’s obligations to the client.
Rynk may maintain a current list of material subprocessors on its website or make the list available upon request. Clients may contact privacy@rynk.ai to request information about Rynk’s current subprocessors.
Where required by the applicable DPA, Rynk will provide notice of new material subprocessors and an opportunity for the client to raise reasonable data-protection concerns.
9. Client-Approved Changes to Online Content
The Services may recommend, draft, or implement changes to a client’s website, listings, content, or structured data based on AI-generated analysis.
Where client approval is required, Rynk will implement or publish a recommended change only after receiving approval from an authorized user or representative of the client.
Client approval authorizes Rynk to carry out the approved change. Clients are responsible for reviewing proposed changes for accuracy, suitability, legal compliance, brand alignment, and business impact before approval.
Approval of a change does not authorize Rynk to publish content that materially differs from what the client approved.
Additional terms governing:
- Client responsibilities;
- Authorized approvers;
- Publication procedures;
- Rollbacks;
- Third-party platform actions;
- Performance disclaimers;
- Warranty limitations; and
- Limitations of liability
are contained in Rynk’s Terms of Service or applicable client agreement.
Nothing in this Privacy Policy waives or limits rights or remedies that cannot lawfully be waived or limited.
10. Cookies and Tracking Technologies
We use cookies and similar technologies to:
- Operate and secure our website and dashboard;
- Authenticate users;
- Maintain user sessions;
- Remember settings and preferences;
- Understand how the Services are used;
- Diagnose errors;
- Measure product performance; and
- Improve user experience.
Depending on our practices and your location, we may request consent before using certain nonessential cookies.
You may manage cookies through your browser settings or through any cookie-preference tool made available through the Services. Disabling certain cookies may prevent some features from operating properly.
Where required by applicable law, Rynk will provide additional disclosures and choices concerning targeted advertising, cross-context behavioral advertising, or the sale or sharing of personal information.
11. Data Retention
We retain personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy, including providing the Services, maintaining security, complying with legal obligations, resolving disputes, and enforcing agreements.
Unless a different period is stated in a client agreement, DPA, or applicable law, Rynk generally applies the following retention periods:
- Account and profile information: Retained for the duration of the account and generally deleted or de-identified within 30 days after account closure, unless continued retention is required for legal, security, billing, or dispute-resolution purposes.
- Client Data: Retained for the duration of the client relationship and generally deleted or returned within 30 days after termination or expiration of the Services, subject to the applicable client agreement and DPA.
- AI prompts and customer-specific outputs: Retained while the account is active and generally deleted within 30 days after account closure or termination, unless the client requests earlier deletion or a different period applies under the client agreement.
- Connected-system credentials and access tokens: Retained while the applicable integration remains active and revoked or deleted when the integration is disconnected or the account is closed.
- Security and access logs: Generally retained for up to 12 months, unless a longer period is reasonably necessary to investigate a security incident, prevent fraud, or comply with law.
- Support and business communications: Generally retained for up to three years after the communication or closure of the related matter.
- Billing, tax, and transaction records: Generally retained for up to seven years or for another period required by applicable tax, accounting, or legal obligations.
- Cookie and analytics information: Retained according to the duration of the applicable cookie or analytics configuration, which may vary depending on the technology used.
- Backups: Deleted information may remain in encrypted backups for up to 90 days before being overwritten through Rynk’s ordinary backup cycle.
We may retain information for a longer period when reasonably necessary to:
- Comply with law;
- Preserve evidence;
- Exercise or defend legal claims;
- Investigate fraud or security incidents;
- Enforce an agreement; or
- Honor a legal hold.
When information is no longer required, we may delete, aggregate, anonymize, or de-identify it.
Information published to third-party websites, search engines, AI assistants, directories, or other platforms may remain available after it has been deleted from Rynk’s systems. Rynk may not be able to delete information retained or independently processed by those third parties.
12. Data Security
Rynk uses commercially reasonable administrative, technical, and physical safeguards designed to protect information against unauthorized access, loss, misuse, alteration, or disclosure.
Depending on the nature of the Services and information involved, safeguards may include:
- Encryption in transit;
- Encryption at rest where appropriate;
- Role-based access controls;
- Multifactor authentication;
- Logging and monitoring;
- Secure software-development practices;
- Vulnerability management;
- Vendor risk management;
- Employee confidentiality requirements;
- Incident-response procedures; and
- Backup and recovery controls.
No system, transmission method, or storage environment can be guaranteed to be completely secure. Rynk therefore cannot guarantee absolute security.
If Rynk identifies a security incident involving personal information, it will investigate and provide legally required notifications to affected clients, individuals, regulators, or other parties.
Clients are responsible for maintaining the confidentiality of their login credentials, restricting account access to authorized users, and promptly notifying Rynk of suspected unauthorized access.
13. International Processing and Data Transfers
Rynk and its service providers may process information in the United States and other countries where Rynk or its providers maintain operations.
These countries may have privacy and data-protection laws that differ from the laws of the country in which you are located.
When Rynk transfers personal information across national borders, it takes reasonable measures designed to protect the information in accordance with this Privacy Policy and applicable law.
Where required, Rynk may rely on recognized transfer mechanisms, including:
- Adequacy decisions;
- The European Commission’s Standard Contractual Clauses;
- The United Kingdom’s International Data Transfer Addendum or International Data Transfer Agreement;
- Contractual protections with recipients;
- Consent where legally permitted; or
- Another valid transfer mechanism recognized under applicable law.
Where Rynk acts as a processor, international transfer requirements may also be addressed in the applicable DPA.
You may contact privacy@rynk.ai to request additional information regarding applicable international transfer safeguards.
14. Your Rights and Choices
Depending on your location and applicable law, you may have the right to:
- Confirm whether we process your personal information;
- Access your personal information;
- Correct inaccurate personal information;
- Request deletion of personal information;
- Obtain a portable copy of certain personal information;
- Object to or restrict certain processing;
- Withdraw consent where processing is based on consent;
- Opt out of certain sales, sharing, targeted advertising, or qualifying profiling;
- Limit certain uses of sensitive personal information;
- Appeal a decision concerning a privacy request; and
- Lodge a complaint with an applicable regulatory authority.
Rynk will not discriminate against you for exercising a privacy right protected by applicable law.
To submit a privacy request, contact:
Email: privacy@rynk.ai
Your request should describe the right you wish to exercise and identify the information or account involved.
We may request additional information to reasonably verify your identity and authority to make the request. We will use verification information only to process and document the request.
Where permitted by law, an authorized agent may submit a request on your behalf. We may require evidence of the agent’s authority and may ask you to verify your identity directly.
If we deny a request, you may have the right to appeal by emailing privacy@rynk.ai and including “Privacy Request Appeal” in the subject line.
Where Rynk processes personal information solely as a processor for a client, we may refer your request to the applicable client or instruct you to contact that client directly.
15. Marketing Communications
You may opt out of promotional email communications by using the unsubscribe link contained in the email or by contacting us.
Even after opting out of marketing communications, you may continue to receive non-promotional communications regarding:
- Your account;
- Transactions;
- Billing;
- Security;
- Service changes;
- Support matters; and
- Other administrative issues.
16. Sensitive Personal Information
The Services are designed primarily to process business and website information. Users should not submit highly sensitive personal information unless it is necessary for an authorized use and permitted under the applicable agreement.
Unless specifically authorized, users should not submit:
- Government identification numbers;
- Complete financial account information;
- Medical or health information;
- Biometric identifiers;
- Precise geolocation information;
- Passwords for third-party services;
- Information about children; or
- Other highly sensitive or legally protected information.
If Rynk learns that prohibited or unnecessary sensitive information has been submitted, it may delete or restrict access to that information.
17. Children’s Privacy
The Services are intended for business users and are not directed to children.
Individuals must be at least 18 years old, or the age of legal majority in their jurisdiction, to create a Rynk account unless an authorized organization has established a legally compliant arrangement permitting otherwise.
We do not knowingly collect personal information directly from children through the Services. If you believe a child has provided personal information to Rynk, contact privacy@rynk.ai so that we can review and take appropriate action.
18. Third-Party Links and Platforms
The Services may link to, integrate with, retrieve information from, or publish information to third-party websites, AI assistants, search engines, analytics providers, directories, and other platforms.
This Privacy Policy does not govern the independent privacy practices of third parties that Rynk does not control.
Third parties may independently collect, retain, use, modify, index, or disclose information according to their own terms and privacy policies. We encourage you to review those policies before connecting an account or authorizing publication.
Rynk is not responsible for the privacy or data-handling practices of third parties that process information independently from Rynk.
19. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in:
- Our Services;
- Technology;
- AI providers;
- Data-processing practices;
- Legal requirements;
- Security practices; or
- Business operations.
We will post the revised Privacy Policy with a new “Last Updated” date.
Where required by law or appropriate based on the nature of the change, we may provide additional notice through the Services, by email, or through another reasonable method.
If a change would materially expand Rynk’s use of Client Data for model training or another materially different purpose, Rynk will not apply that use retroactively without any notice, consent, or written approval required by applicable law and our contractual commitments.
20. Contact Us
If you have questions about this Privacy Policy, Rynk’s privacy practices, the DPA, subprocessors, international transfers, or a privacy-rights request, contact us at:
Rynk
Legal entity: Rynk.ai, Inc.
Mailing address: 16803 Dallas Parkway, Suite 300, Addison TX 75001
Email: privacy@rynk.ai
Website: rynk.ai