Data Processing Agreement (DPA)
Data processing agreement pursuant to Article 28 of EU Regulation 2016/679 (GDPR) between TAGMOOD S.R.L. (Processor) and the Customer (Controller).
Last updated: July 21, 2026
1. Parties and Application
This Data Processing Agreement (“DPA”) governs the processing of personal data carried out by:
TAGMOOD S.R.L.
Via Luigi Capuana n. 11
95030 Tremestieri Etneo (CT), Italy
VAT ID and Tax Code: 05518210876
PEC: tagmood@pec.it
Privacy email: privacy@tagmood.it
Operational email: webmaster360@tagmood.it
Legal representative: Fabio Salamone
hereinafter “TAGMOOD” or the “Processor”,
on behalf of the entity identified as the customer in the contract, commercial order, or other agreement relating to the Webmaster360 services, hereinafter the “Customer” or the “Controller”.
The DPA applies when referenced in the agreement between TAGMOOD and the Customer relating to the Webmaster360 services (“Main Agreement”) and forms an integral part thereof solely with respect to the processing of personal data carried out by TAGMOOD on behalf of the Customer.
The Customer determines the purposes and essential means of the processing. TAGMOOD processes personal data on behalf of the Customer and in accordance with its documented instructions.
2. Definitions
For the purposes of this DPA:
- “Personal data”, “processing”, “data subject”, “controller”, “processor”, “personal data breach” and “supervisory authority” shall have the meaning ascribed to them by Regulation (EU) 2016/679 (“GDPR”);
- “Customer Data” means the personal data processed by TAGMOOD on behalf of the Customer through the Webmaster360 services;
- “Services” means the Webmaster360 services purchased, activated or used by the Customer;
- “Sub-processor” means an entity engaged by TAGMOOD to process Customer Data in connection with the provision of the Services;
- “Applicable Law” means the GDPR and any further data protection provisions applicable to the processing governed by this DPA.
3. Subject Matter, Scope and Duration
This DPA applies to the processing described in Annex A — Description of Processing.
Processing shall continue for the entire term of the Main Agreement and, thereafter, for the period strictly necessary for the return or deletion of Customer Data in accordance with this DPA.
The DPA does not govern processing for which TAGMOOD acts as an independent controller, including, where applicable:
- commercial and administrative management of the relationship;
- invoicing and accounting;
- management of contractual contacts;
- protection of TAGMOOD’s rights;
- compliance with legal obligations;
- processing of data collected through the public corporate website of Webmaster360;
- activities for which TAGMOOD independently determines the purposes and essential means.
Such processing is governed by the applicable TAGMOOD privacy notices.
4. Documented Instructions
TAGMOOD processes Customer Data exclusively on the basis of the Customer’s documented instructions, unless processing is required by applicable EU or national law.
Documented instructions include:
- the Main Agreement;
- this DPA;
- the configurations set by authorized users;
- the operations performed through the admin panel;
- requests submitted through authorized support channels;
- any further written instructions agreed between the Parties.
TAGMOOD shall inform the Customer without undue delay if it believes that an instruction infringes Applicable Law. TAGMOOD may suspend the execution of the specific instruction or functionality concerned for the time necessary to verify its compliance and receive correct instructions.
Where processing is required by law, TAGMOOD shall inform the Customer in advance, unless the law prohibits such communication for important reasons of public interest.
5. Obligations of TAGMOOD
TAGMOOD undertakes to:
- process Customer Data exclusively to provide, maintain, protect and support the Services;
- ensure that persons authorized to process the data are bound by legal or contractual confidentiality obligations;
- limit access to Customer Data to what is necessary for the assigned activities;
- adopt the technical and organizational measures described in Annex B — Technical and Organizational Measures;
- engage Sub-processors in accordance with Article 9;
- assist the Customer in fulfilling obligations relating to data subjects’ rights, security, data breaches, impact assessments and prior consultations;
- delete or return Customer Data upon termination of the Services in accordance with Article 13;
- make available the information reasonably necessary to demonstrate compliance with this DPA;
- inform the Customer of any legally binding requests for access to Customer Data, unless prohibited by law;
- not use Customer Data for independent purposes incompatible with this DPA.
TAGMOOD personnel may access Customer Data only when necessary for support, maintenance, security, incident management or troubleshooting.
6. Obligations of the Customer
The Customer, as data controller, is responsible for:
- determining the purposes and legal bases of the processing carried out through the Services;
- providing data subjects with the notices required by law and obtaining any necessary consents;
- issuing documented instructions that are lawful and consistent with the Main Agreement and this DPA;
- ensuring that data entered, imported, published or processed is relevant and limited to what is necessary;
- correctly configuring accounts, roles, permissions, features and integrations;
- protecting authorized users’ credentials and promptly revoking access that is no longer needed;
- assessing the lawfulness of published editorial content and personal data;
- adopting the required safeguards where the processing concerns special categories of data, criminal offence data or data relating to minors;
- using artificial intelligence features in compliance with Applicable Law, limiting the data sent to what is necessary;
- informing TAGMOOD without undue delay of compromised credentials, unauthorized use or other circumstances relevant to security.
The Customer retains editorial control and responsibility over content managed through Webmaster360. TAGMOOD does not independently decide which news, content or personal data should be collected or published, nor does it determine the legal basis for publication.
The Customer’s obligations do not limit the obligations directly attributed to TAGMOOD by Applicable Law.
7. Confidentiality
TAGMOOD ensures that persons authorized to process Customer Data:
- access the data only to the extent necessary;
- are bound by confidentiality obligations;
- receive adequate instructions and training on data protection and security;
- use the data exclusively for the provision, maintenance, security and support of the Services.
Confidentiality obligations continue to apply even after the termination of the assignment or the relationship with TAGMOOD.
8. Security of Processing
Taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing, as well as the risks to the rights and freedoms of natural persons, TAGMOOD adopts technical and organizational measures appropriate to the risk.
The applicable measures are described in Annex B — Technical and Organizational Measures and, for general informational purposes, in the Security Overview.
TAGMOOD may update or replace such measures during the term of the relationship based on technical evolution, risks, infrastructure and Services, provided this does not result in a material reduction of the overall level of protection.
9. Sub-processors
The Customer generally authorizes TAGMOOD to engage the Sub-processors necessary for the provision of the Services.
The Sub-processors used as of the effective date of this DPA are listed in the Sub-processor List. The updated list is published at:
TAGMOOD shall inform the Customer of the intention to add or replace a Sub-processor with at least 30 days’ notice, by:
- updating the public list; and
- sending an email communication to the administrative or privacy address associated with the Customer.
The Customer may object within the notice period exclusively for documented and reasonable grounds relating to the protection of personal data.
In the event of an objection, the Parties shall cooperate in good faith to identify a reasonable solution, which may include supplementary measures, an alternative configuration or the deactivation of the affected functionality. Where no reasonable solution is available, the Customer may terminate the service or functionality directly affected, in accordance with the Main Agreement.
TAGMOOD shall impose on Sub-processors data protection obligations substantially equivalent to those applicable to TAGMOOD under this DPA and shall remain liable to the Customer for the performance of the obligations entrusted to the Sub-processors.
10. International Transfers
TAGMOOD configures, where technically available, the main services in regions located within the European Economic Area.
The main locations configured as of the effective date are:
- DigitalOcean
AMS3, Amsterdam, Netherlands, for application infrastructure and databases; - Amazon Web Services
eu-west-1, Ireland, for multimedia content storage; - SimpleStorage
eu-north-1, in the European Union, for external backup copies.
The use of regions located in the EEA does not exclude the possibility that certain Sub-processors, affiliates or suppliers may access, transmit or process data from countries outside the EEA.
Where processing involves a transfer to a country not recognized by the European Commission as adequate, TAGMOOD shall ensure that the transfer is governed by a mechanism permitted by Applicable Law, including:
- an adequacy decision;
- standard contractual clauses approved by the European Commission;
- another valid mechanism provided for by law;
- any supplementary technical, organizational or contractual measures, where necessary.
Certain services, including Cloudflare, Laravel and OpenAI, operate through internationally distributed infrastructures or organizations. TAGMOOD uses such services on the basis of their respective contracts and standard Data Processing Agreements.
TAGMOOD does not guarantee that all Customer Data is processed exclusively within the European Economic Area.
Where a transfer mechanism is no longer valid or adequate, TAGMOOD shall assess the adoption of an alternative mechanism, supplementary measures, a change in configuration or provider, or the suspension of the transfer or function concerned.
11. Data Subject Requests
Taking into account the nature of the processing, TAGMOOD shall assist the Customer, through appropriate technical and organizational measures, in fulfilling obligations relating to requests for the exercise of data subjects’ rights.
Assistance may cover, where technically applicable:
- searching for and locating data;
- access and export;
- rectification and updating;
- erasure;
- restriction of processing;
- portability;
- handling of objections;
- retrieval of available information about the processing.
The Customer remains responsible for verifying the identity of the requester, assessing the request, determining the response and the final communication to the data subject.
Where TAGMOOD directly receives a request relating to Customer Data:
- it shall inform the Customer without undue delay and, where possible, within 3 working days;
- it shall forward the request and the available information necessary to identify its scope;
- it shall not respond on the merits or directly execute the request, except under documented instructions from the Customer or legal obligations;
- it may inform the data subject that the request has been forwarded to the competent controller.
12. Personal Data Breaches
Where TAGMOOD becomes aware of a breach of Customer Data, it shall inform the Customer without undue delay and, where possible, within 48 hours of ascertaining the breach.
The notification shall be sent to the contact person indicated in the Main Agreement or in subsequent authorized communications. In the absence of a specific contact, it may be sent to the administrative or privacy address associated with the Customer.
The notification shall contain, to the extent the information is available:
- nature of the breach;
- date or estimated period of the event;
- systems and Services affected;
- categories and approximate number of data subjects;
- categories and approximate volume of data involved;
- likely consequences;
- measures taken or proposed to contain and resolve the event;
- measures that may be suggested to the Customer;
- contact point at TAGMOOD.
If it is not possible to provide all the information at once, TAGMOOD shall send an initial notification with the available information and supplement it progressively without undue delay.
TAGMOOD shall reasonably cooperate with the Customer to assess the impact, contain the event, and prepare the information necessary for any notifications to the authority and communications to data subjects.
The Customer remains responsible for deciding whether to notify the supervisory authority and communicate to data subjects, unless otherwise provided by law.
TAGMOOD shall document the breaches of which it becomes aware and may share the documentation in a limited or redacted form to protect system security, other customers’ data, trade secrets and third-party confidential information.
13. Return and Deletion
Upon termination of the Services, the Customer may request the return of Customer Data within 30 days.
Data extractable from the database shall be made available in a commonly used structured format, typically JSON or XML. Multimedia content may be provided in archive form.
The format, technical methods and timing of the export may depend on the volume and nature of the data.
Unless otherwise instructed in writing by the Customer, TAGMOOD shall delete or render permanently inaccessible the Customer Data present in production environments within 30 days of the termination of the Services.
Copies present in backup systems shall be overwritten or deleted in accordance with their retention cycle, which does not ordinarily exceed four weeks. During such period:
- the data remains protected;
- it is not used for ordinary purposes;
- it may be restored exclusively for operational continuity, security or incident recovery needs.
Where a backup containing Customer Data is restored, TAGMOOD shall reapply the deletion request to the restored data as soon as technically possible.
Before termination or within the export period, the Customer may request:
- the return of the data and subsequent deletion; or
- deletion without prior return.
In the absence of instructions within 30 days of termination, TAGMOOD shall proceed with deletion in accordance with the above methods.
TAGMOOD may retain specific data beyond such terms exclusively where necessary to comply with a legal obligation or for the establishment, exercise or defence of a legal claim. In such cases, the data shall be isolated and processed solely for the purpose justifying its retention.
At the Customer’s request, TAGMOOD shall provide written confirmation of the deletion, without prejudice to copies still present in backups during their ordinary cycle.
14. Assistance with Privacy Compliance
Taking into account the nature of the processing and the information available, TAGMOOD shall provide reasonable assistance to the Customer in relation to:
- security of processing;
- assessment and management of personal data breaches;
- data protection impact assessments;
- any prior consultations with the supervisory authority.
Assistance may include:
- information on the technical features of the Service;
- description of the technical and organizational measures;
- information on Sub-processors and locations;
- reasonably available information on data flows;
- cooperation in identifying technically applicable mitigation measures.
The Customer remains responsible for assessing the need to carry out an impact assessment, its content, and any consultation of the authority.
The reasonably necessary ordinary assistance is included in the Service. For exceptional, customized or particularly burdensome activities, TAGMOOD may request reimbursement of reasonable costs, subject to prior communication and approval of an estimate.
No additional costs shall be charged where the assistance is required due to a breach or non-compliance attributable to TAGMOOD.
15. Information, Audits and Inspections
TAGMOOD shall make available the information reasonably necessary to demonstrate compliance with the obligations under Article 28 GDPR and this DPA.
The information may include:
- Security Overview;
- updated list of Sub-processors;
- information on technical and organizational measures;
- responses to reasonable questionnaires;
- confirmations relating to backups and restore tests;
- redacted summaries of available vulnerability scans;
- further relevant evidence available at TAGMOOD.
The Customer shall primarily use documentation and remote verifications.
Where such information is not reasonably sufficient, the Customer may request an audit under the following conditions:
- no more than once per calendar year, except in the case of data breaches, requests from the authority or substantiated indications of a material non-compliance;
- with at least 30 days’ written notice, except in justified urgent cases;
- during normal business hours;
- by qualified personnel or an independent auditor that is not a competitor of TAGMOOD;
- in compliance with confidentiality obligations;
- without access to other customers’ data, systems or confidential information;
- without compromising the security, availability or operation of the Services.
The costs of the audit shall be borne by the Customer, unless the audit finds a material non-compliance attributable to TAGMOOD.
16. Authority Requests
Where TAGMOOD receives a legally binding request from a public authority relating to Customer Data, TAGMOOD shall:
- verify, within reasonable limits, the validity and scope of the request;
- inform the Customer before disclosure, unless prohibited by law;
- disclose only the data requested and necessary;
- document the request and the response, to the extent permitted by law;
- assess the possibility of challenging manifestly unlawful or excessive requests, where reasonable and permitted.
Where the law prohibits communication to the Customer, TAGMOOD may provide aggregated or deferred information as soon as the prohibition ceases to apply.
17. Versions and Updates
TAGMOOD may update this DPA to reflect regulatory, organizational, technical or Service changes.
Each version shall bear an identification number and an effective date.
Material changes shall be communicated to the Customer with at least 30 days’ notice, unless a shorter period is necessary to comply with the law or address an urgent security risk.
Updates shall not result in a material reduction of the overall level of protection of Customer Data. Changes requiring the Customer’s consent under the law or the Main Agreement shall become effective only upon such consent.
18. Effectiveness and Relationship with the Main Agreement
This DPA applies when referenced in the Main Agreement.
In the event of a conflict, the DPA shall prevail exclusively with respect to matters relating to the protection of personal data.
For matters not expressly governed by this DPA, including applicable law, jurisdiction, fees, contractual liability, duration, suspension and termination of the Service, the Main Agreement shall apply.
The termination of the Main Agreement shall result in the termination of this DPA, without prejudice to obligations that continue to apply by their nature or by law, including those relating to confidentiality, data return and deletion.
Annexes
This DPA is supplemented by the following annexes, which form an integral and substantial part thereof:
- Annex A — Description of Processing — Subject matter, services, nature, purposes, operations, categories of data subjects and personal data.
- Annex B — Technical and Organizational Measures — Infrastructure, encryption, access, logging, backup, development, vulnerabilities, personnel, AI.
- Sub-processor List — Authorized sub-processors with service, purpose and location.
For inquiries relating to this DPA:
- Privacy: privacy@tagmood.it
- Operations and security: webmaster360@tagmood.it
- PEC: tagmood@pec.it
