Annex B to the DPA — Technical and Organizational Measures

Technical and organizational measures adopted by TAGMOOD S.R.L. to ensure the security of personal data processing within the scope of the Webmaster360 services.

Last updated: July 21, 2026

TAGMOOD applies, as relevant to the processing, the following measures.

This annex forms an integral part of the Webmaster360 DPA. For a less technical overview, please refer to the Security Overview.

1. Infrastructure and Isolation

  • application infrastructure and databases in the DigitalOcean AMS3 region, Amsterdam (Sub-processor);
  • separate database for each Customer;
  • dedicated application instance for each Customer;
  • media storage through Amazon S3 in the eu-west-1 region (Sub-processor);
  • external backups in the European eu-north-1 region (Sub-processor);
  • separation between production environment and backup copies.

2. Encryption and Communication Protection

  • HTTPS/TLS for connections to the Services;
  • encrypted connections to the managed database;
  • encryption at rest of the database according to the provider’s features;
  • server-side encryption of media stored on Amazon S3;
  • encryption of external backups during streaming using AES-256;
  • protection of backup encryption keys through asymmetric RSA encryption.

3. Identity and Access

  • access management according to the principle of least privilege;
  • multi-factor authentication available for administrators, editors and authors;
  • MFA currently optional;
  • credentials not stored in plain text;
  • manual and authorized management of creation, modification and revocation of accounts and roles;
  • TAGMOOD personnel access limited to support, maintenance, security or incident management needs.

4. Logging and Monitoring

  • recording of administrative access and relevant activities;
  • automatic monitoring and anomaly notifications;
  • application monitoring through Laravel Nightwatch (Sub-processor);
  • ordinary log retention for 30 days;
  • access to logs limited to authorized personnel;
  • use of Cloudflare for DNS, caching, Web Application Firewall and anti-bot protection (Sub-processor);

5. Backup and Restore

  • automatic daily backups of the managed database;
  • point-in-time database recovery according to the provider’s service;
  • daily external backups, retained for 7 days;
  • weekly external backups, retained for 4 weeks;
  • ordinary retention not exceeding 4 weeks;
  • backups separated from the production environment;
  • external backups encrypted;
  • periodic restore tests.

6. Secure Development and Change Management

  • separation of development, testing and production environments;
  • code review;
  • testing of changes before release;
  • automatic checks on dependencies and known vulnerabilities;
  • separation of application secrets from source code;
  • daily checking and application of available security updates based on criticality, compatibility and operational needs.

7. Vulnerability Management

  • vulnerability scans on Service components;
  • dependency monitoring;
  • security reporting channel: webmaster360@tagmood.it;
  • assessment and management of identified vulnerabilities.

As of the effective date of this DPA, TAGMOOD does not declare security certifications or the performance of independent penetration tests.

8. Personnel and Organization

  • confidentiality obligations;
  • periodic security training;
  • access limited to authorized persons only;
  • supplier evaluation before onboarding;
  • contractual agreements and DPAs with suppliers, where applicable.

9. Artificial Intelligence

Data sent to the AI features is processed by OpenAI (Sub-processor). For further details, please refer to the Security Overview.

  • use of AI features only when activated by the Customer;
  • sending to the provider of the prompts, content and instructions necessary for the requested function;
  • ability to disable AI features;
  • human review before publication;
  • no use of Customer Data by TAGMOOD to train its own or third-party models;
  • no voluntary opt-in by TAGMOOD to provider programs providing for the use of such data for training, unless otherwise instructed in writing by the Customer.