GDPR / DPA
Last updated: Aug 10, 2026
Our Commitment to Data Protection. Ratio Technologies, Inc. ("Ratio," "we," "us") is committed to protecting the personal data of our customers, their end users, and our own team in line with the EU General Data Protection Regulation (GDPR), the UK GDPR, and equivalent data protection laws in the jurisdictions where we operate. This page explains the roles we play under those laws, the categories of personal data involved in providing the Ratio Services, and how customers can request a signed Data Processing Addendum (DPA).
1. Controllers and processors.
When you create a Ratio account and use the Ratio Services, Ratio acts as a data controller for account and billing information we collect directly from you and your organization (for example, signup details, contact information, and payment records) and as a data processor for personal data your organization submits to us on behalf of your own customers or end users in the course of using the Ratio Services (for example, buyer information included in an Order). Where Ratio acts as a processor, our processing is governed by the Data Processing Addendum referenced below, which forms part of your agreement with Ratio.
2. What personal data we process.
Depending on how the Ratio Services are used, this may include: account holder and authorized-user contact details (name, email, phone); billing and payment information; buyer and transaction data submitted through Orders; and technical data such as device, browser, and log information collected when the Website or Services are used. We do not require or knowingly process special categories of personal data (such as health or biometric data) through the Ratio Services.
3. Legal basis for processing.
Where GDPR applies, we process personal data on one or more of the following bases: performance of a contract with you or your organization; compliance with a legal obligation; our legitimate interests in operating, securing, and improving the Ratio Services, provided those interests are not overridden by your rights; and, where required, your consent.
4. Your rights as a data subject.
Subject to applicable law, individuals whose personal data we process have the right to request access to their data, correct inaccurate data, request erasure, restrict or object to certain processing, request data portability, and lodge a complaint with a supervisory authority. To exercise any of these rights in connection with data Ratio controls directly, contact us using the details below; requests concerning data submitted by a Ratio customer about its own end users should generally be directed to that customer, who remains the controller of that data.
5. International data transfers.
Where personal data is transferred outside the country or region in which it was collected, including transfers out of the European Economic Area or the United Kingdom, Ratio relies on appropriate safeguards such as the European Commission's Standard Contractual Clauses (SCCs) or the UK's International Data Transfer Addendum, as applicable.
6. Sub-processors.
Ratio engages a limited number of third-party service providers (sub-processors) to help deliver the Ratio Services, such as cloud hosting, payment processing, identity verification, and customer support tooling. Each sub-processor is bound by contractual obligations consistent with GDPR requirements. A current list of sub-processors is available on request.
7. Data security.
We maintain administrative, technical, and physical safeguards designed to protect personal data against unauthorized access, disclosure, alteration, and destruction, including encryption in transit, access controls, and regular review of our security practices.
8. Data breach notification.
In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, Ratio will notify affected customers without undue delay so they can meet their own notification obligations under applicable law.
9. Data retention.
We retain personal data only for as long as necessary to provide the Ratio Services, comply with our legal and regulatory obligations, resolve disputes, and enforce our agreements, after which it is deleted or anonymized in accordance with our data retention practices.
10. Requesting a Data Processing Addendum (DPA).
Customers that need a signed Data Processing Addendum reflecting the terms above, including the applicable Standard Contractual Clauses, can request one by contacting legal@ratiotech.com.
11. Contact Ratio.
Questions about this page, our GDPR compliance program, or a specific data protection request can be sent to legal@ratiotech.com.
