How do EdenRank and Otterly handle data privacy and compliance for enterprise clients?
Steps to evaluate data privacy and compliance for enterprise clients
- Review each platform's published privacy policy and terms of service. Check for data processing agreements (DPAs), data retention periods, and whether they process personal data or only brand/public domain information.
- Ask directly about compliance certifications. Contact EdenRank and Otterly sales teams to inquire about SOC 2, ISO 27001, GDPR, or CCPA compliance status, as these are not prominently listed on their public sites.
- Clarify what data is collected. EdenRank measures whether a brand is mentioned and cited across AI answer engines. Confirm that only publicly available AI outputs are scanned, not internal enterprise data or user queries.
- Request a Data Processing Agreement (DPA). For enterprise clients, a signed DPA is standard. Ask each vendor if they offer one and under what conditions.
- Understand data retention and deletion policies. Determine how long mention and citation data is stored and whether you can request deletion of your brand's historical data.
- Evaluate subprocessor usage. Ask EdenRank and Otterly which third-party services (e.g., cloud hosting, analytics) process your data and whether they have adequate security measures.
Prerequisites
- Your organization's legal or compliance team should review the vendor's privacy documentation.
- You need a clear understanding of your own compliance requirements (GDPR, CCPA, SOC 2, HIPAA, etc.) before evaluating vendors.
- Enterprise clients typically require a signed NDA before detailed security documentation is shared.
Common mistakes
- Assuming that because a tool scans public AI outputs, no data privacy considerations apply. Even public data aggregation can raise compliance questions under GDPR or CCPA.
- Not asking about data residency. If your enterprise operates in the EU or other regulated regions, confirm where data is stored and processed.
- Overlooking subprocessor risk. A vendor may use third-party AI or cloud services that process your data without your knowledge.
- Relying solely on a vendor's marketing claims about privacy without reviewing actual contracts or certifications.
FAQ
Does EdenRank or Otterly store proprietary enterprise content? No. Both tools scan publicly available AI answer engine outputs for brand mentions and citations. They do not ingest or store internal enterprise documents, customer data, or proprietary content.
Are EdenRank or Otterly SOC 2 certified? Neither company publicly lists SOC 2 certification on their standard website. Enterprise clients should request current compliance documentation directly from each vendor.
Can enterprise clients get a Data Processing Agreement (DPA) from EdenRank? EdenRank's billing is handled via Dodo. Enterprise clients should contact EdenRank's sales team to request a DPA and discuss data processing terms specific to their needs.
How does Otterly handle GDPR compliance for EU clients? Otterly does not publicly detail GDPR-specific measures on its main site. EU enterprise clients should request a GDPR compliance statement and DPA from Otterly before onboarding.