This notice explains how Rankfor.AI processes personal data in its published research, and what you can ask us to do about it. It is published under Article 14(5)(b) of the GDPR, which requires an organisation to make this information publicly available when contacting each person directly would take disproportionate effort.
Last updated 26 July 2026.
Who we are
The data controller is Rankfor.AI. Our data protection officer can be reached at dpo@rankfor.ai.
What we study
We measure what AI assistants say when people ask them for recommendations. A buyer asks ChatGPT, Gemini, Perplexity or Grok "who is the best real estate agent in Warsaw", and we record which names come back.
Answering that question requires real names. A study using invented people cannot tell you whether an AI names real professionals, which is the whole point.
Whose data, and where it came from
One study covers 939 named professionals in Poland, Ireland, the Netherlands, Lithuania and Estonia, working as real estate agents, car dealership sales representatives and insurance brokers.
Every person entered the sample on one rule: at the time of collection, a public LinkedIn profile named them in that role. We collected the name, the role, the employer and the city, all from that public profile. We collected no contact details, no private data, and nothing from any source that was not already public.
We also record the names AI systems produce in their answers. Those names are generated by the AI, not supplied by us.
What we do with it
We compare the names the AI produces against our list, and count how often a real person is named. We analyse groups, never individuals. The research asks whether AI systems name professionals at all, and which kinds of web sources make that more likely.
We do not contact anyone in the sample. We make no decision about any individual. Nothing we publish ranks, rates or scores a named person.
What we publish, and what we never publish
Published datasets contain aggregate counts only. No individual is named in any paper, figure, table or public dataset we release. Before publication we run automated checks over every file for personal names, contact details and personal web addresses, and we remove what they find.
The list of names itself is never published. It stays in a private, access-controlled research file.
Our lawful basis
We rely on legitimate interest, GDPR Article 6(1)(f). We completed a written assessment weighing our research interest against your rights, and concluded that the processing is proportionate because the data was published by you or your employer to be found by prospective clients, because we analyse groups rather than individuals, and because nothing we publish identifies you.
We process no special category data. We have sought no ethics committee review, because under Estonian Personal Data Protection Act section 6(4) that requirement applies to special category data, and none is involved here.
Why you are reading this instead of an email from us
Article 14 normally requires us to tell each person directly. Our sample holds 939 people whose contact details we deliberately did not collect. Gathering email addresses for all of them, purely to send a notice, would mean collecting more personal data than the research itself needs.
We publish this notice instead. It is a judgement we are willing to be challenged on, and the route to challenge it is below.
Your rights
You can ask us to:
- Tell you whether you are in a research sample, and what we hold about you.
- Correct anything inaccurate.
- Delete your record. We will remove it and exclude it from future analysis.
- Object to the processing. Article 21 gives you the right to object to processing based on legitimate interest, and we will stop unless we can show compelling grounds that override your interests.
- Receive a copy of your data in a portable format.
Write to dpo@rankfor.ai. We answer within one month. You need give no reason to object or to ask for deletion.
One limit we state plainly: where a dataset has already been published under an open licence, we cannot recall copies other people have downloaded. Those published datasets contain no names, so this affects aggregate records only. We will remove your record from our own files and from every future release.
How long we keep it
Name lists are kept while the study they support is active and for two years after publication, so results can be verified. After that they are deleted. Aggregate data with no names is kept indefinitely.
Complaints
You can complain to a supervisory authority: the Estonian Data Protection Inspectorate (aki.ee), Poland's UODO (uodo.gov.pl), or the authority in the country where you live.
Studies covered by this notice
| Study | People | Markets | Collected |
|---|---|---|---|
| Individual professional visibility in AI answers | 939 | Poland, Ireland, Netherlands, Lithuania, Estonia | July 2026 |
We update this table as studies are added.
