Privacy & Data Protection
How Webmaster360 protects personal data: principles, measures and policies for GDPR-compliant processing, built on trust with publishers.
Last updated: July 22, 2026
1. Purpose and Scope
This page describes how TAGMOOD S.R.L. handles the protection of personal data within the scope of the Webmaster360 platform and clarifies the cases in which TAGMOOD acts:
- as a data processor, on behalf of the Customer;
- as an independent data controller, for its own purposes related to the management of the relationship, security and legal obligations.
This page concerns the Webmaster360 services and does not replace:
- the Data Processing Agreement, applicable to processing carried out on behalf of Customers;
- the privacy notices published by individual Customers on websites managed through Webmaster360;
- the Corporate Website Privacy Policy, applicable to the public website
webmaster360.it, commercial forms and browsing tools used on the corporate website.
2. Identity and Contacts
Controller: TAGMOOD S.R.L.
Registered office: Via Luigi Capuana n. 11, 95030 Tremestieri Etneo (CT), Italy
VAT ID and Tax Code: 05518210876
PEC: tagmood@pec.it
Privacy email: privacy@tagmood.it
Operational and security email: webmaster360@tagmood.it
TAGMOOD has not appointed a Data Protection Officer (DPO). Requests regarding data protection may be sent to the privacy address indicated above.
3. Roles in the Processing
3.1 TAGMOOD as Data Processor
In the ordinary provision of Webmaster360, the Customer determines the editorial and operational purposes of the processing and decides which data to enter, import, store, publish or submit to the platform’s features.
In such cases, TAGMOOD acts, as a rule, as a data processor on behalf of the Customer. This may relate, depending on the features activated, to:
- accounts of administrators, editors, journalists, authors and contributors;
- articles, drafts, pages, documents and multimedia content;
- data contained in editorial content;
- data collected through forms, comments, newsletters, notifications, quizzes and surveys;
- logs and technical information managed to provide and protect the service;
- backups and copies necessary for restoration;
- data sent to artificial intelligence features;
- data processed through integrations or APIs configured by the Customer.
Such processing is governed by:
- the Data Processing Agreement;
- Annex A — Description of Processing;
- Annex B — Technical and Organizational Measures;
- the Sub-processor List.
The Customer is responsible for the notices addressed to its users, employees, collaborators, readers and other data subjects, as well as for determining the applicable legal bases.
3.2 TAGMOOD as Independent Controller
TAGMOOD acts as an independent controller when it directly determines the purposes and essential means of specific activities connected to its own organization, the management of the relationship with the Customer, security or legal obligations.
The role must be assessed in relation to the individual activity. The fact that data passes through Webmaster360 does not automatically mean that TAGMOOD acts as a controller.
4. Processing Carried Out by TAGMOOD as Controller
4.1 Management of Customer Contacts and Service Relationship
Data processed:
- first and last name;
- professional email address;
- organization and role;
- data contained in communications;
- information relating to the contract, order and activated service.
Purposes:
- initiation and management of the relationship;
- operational communications;
- coordination of activities;
- management of renewals, changes and termination of the service;
- sending of necessary communications on the operation, security or changes to applicable documents.
Legal basis:
- performance of a contract or pre-contractual measures, where the data subject is a party to the relationship;
- legitimate interest of TAGMOOD and the Customer in managing the professional relationship, where the data subject acts as a contact for an organization.
Retention:
For the duration of the relationship and, thereafter, for the period necessary to handle residual obligations, requests or disputes, in compliance with applicable statutory time limits.
4.2 Technical Support and Operational Communications
Data processed:
- identity and email address of the requester;
- role and organization;
- content of the request;
- correspondence exchanged;
- files, screenshots and technical data voluntarily provided;
- information necessary to diagnose the problem.
Purposes:
- handling and resolution of requests;
- communications on the status of the service;
- verification of the quality of support;
- documentation of activities carried out;
- prevention of fraudulent or unauthorized requests.
Legal basis:
- performance of the service relationship;
- legitimate interest in the management of support, security and documentation of activities.
Retention:
For the time necessary to handle the request and any follow-ups. Support communications are normally retained for no more than 24 months from the closure of the request, unless further retention is necessary for legal obligations, security or protection of rights.
Where a support request involves access to data processed on behalf of the Customer, such access takes place within the scope of the processor role and in accordance with the DPA.
4.3 Security, Abuse Prevention and Platform Protection
Data processed:
- IP addresses;
- access date and time;
- account and session identifiers;
- user agent, browser, operating system and device;
- authentication events;
- administrative and technical logs;
- errors, traces and diagnostic information;
- reports of suspicious activities;
- information relating to unauthorized access attempts or improper use.
Purposes:
- protection of accounts, systems, infrastructure and data;
- prevention, detection and management of unauthorized access, fraud and malicious activities;
- incident analysis;
- verification of compliance with usage rules;
- protection of the rights and legitimate interests of TAGMOOD, Customers and users.
Legal basis:
- legitimate interest in system security and abuse prevention;
- compliance with legal obligations, where applicable.
Retention:
Relevant application and administrative logs are normally retained for 30 days. Data linked to an incident, investigation or dispute may be retained for longer, for the time necessary for the relevant management.
Activities carried out exclusively to ensure the security of processing performed on behalf of the Customer also remain subject to the DPA.
4.4 Vulnerability and Incident Reports
Data processed:
- name or pseudonym of the reporter;
- email address and other contact details voluntarily provided;
- content of the report;
- technical details, attachments and communications;
- information on verifications and measures adopted.
Purposes:
- receiving, assessing and managing vulnerability reports;
- communicating with the reporter;
- protecting the platform and the affected parties;
- documenting analysis and resolution activities.
Legal basis:
- legitimate interest in service security;
- compliance with legal obligations, where applicable.
Retention:
For the period necessary for the verification, resolution and documentation of the report and, thereafter, for the time necessary for the protection of rights or the handling of any legal obligations.
4.5 Legal Compliance and Protection of Rights
Data processed:
The data reasonably necessary in relation to the request, obligation or dispute.
Purposes:
- compliance with regulatory, tax, accounting or administrative obligations;
- responding to requests from authorities;
- handling of complaints and disputes;
- establishment, exercise or defence of legal rights.
Legal basis:
- compliance with a legal obligation;
- legitimate interest in the protection of rights;
- establishment, exercise or defence of a right in judicial or extrajudicial proceedings.
Retention:
For the periods provided for by law and, in the event of a dispute, for the time necessary for the relevant management.
5. Data That TAGMOOD Does Not Use for Independent Purposes
Unless otherwise provided by a specific notice or agreement, TAGMOOD does not use for its own independent purposes:
- articles, drafts and editorial archives of Customers;
- reader data collected from Customers’ websites;
- Customers’ newsletter lists;
- comments, forms, quizzes or survey responses;
- prompts and content sent to AI features;
- photographs, videos or documents uploaded by the Customer;
- data extracted from Customers’ databases.
TAGMOOD does not sell Customer Data and does not use it to create its own advertising profiles.
TAGMOOD does not use Customer Data to train its own or third-party artificial intelligence models and does not voluntarily opt in to AI provider programs that provide for the use of such data for training, unless otherwise instructed in writing by the Customer.
6. Origin of Data
Data processed by TAGMOOD as controller may be collected:
- directly from the data subject;
- from the Customer or an authorized contact;
- during the use of the platform;
- from security and monitoring systems;
- from technical suppliers involved in the provision of the service;
- from authorities or authorized parties, where provided for by law.
Where data is provided by the Customer, the latter is responsible for having collected and communicated it lawfully.
7. Nature of Provision
The provision of data necessary for the management of the relationship, support and security is required in order to use the relevant services or receive assistance.
Failure to provide the necessary data may prevent:
- the activation or management of the relationship;
- the identification of the authorized contact;
- the handling of a request;
- secure access to or use of the platform;
- compliance with legal obligations.
8. Recipients and Suppliers
Data may be processed by:
- authorized TAGMOOD personnel and collaborators;
- legal, tax, technical or security consultants;
- infrastructure, storage, backup, monitoring, network protection and artificial intelligence suppliers;
- communication and support suppliers;
- public authorities or other parties authorized by law.
Where a supplier processes data on behalf of TAGMOOD, it is designated as a processor or sub-processor according to the applicable role.
The list of suppliers that may process data for the provision of Webmaster360 is available on the Sub-processors page.
9. International Transfers
The main services are configured, where technically available, in regions of the European Economic Area.
Some suppliers, however, operate through global organizations or infrastructures. Data may therefore be processed or made accessible from countries outside the EEA.
Where required, TAGMOOD uses mechanisms provided for by Applicable Law, such as:
- adequacy decisions;
- standard contractual clauses approved by the European Commission;
- further contractual, technical or organizational safeguards.
Further information on locations and suppliers is available on the Sub-processors page.
10. Security Measures
TAGMOOD adopts technical and organizational measures proportionate to the risks, including:
- HTTPS/TLS;
- logical separation of Customers through separate databases and dedicated instances;
- access management according to the principle of least privilege;
- multi-factor authentication available;
- logging and monitoring;
- separate and encrypted backups;
- periodic restore tests;
- separation of development, testing and production environments;
- code review;
- checks on dependencies and vulnerabilities;
- staff training and confidentiality obligations.
Further information is available in the:
11. Automated Decisions and Profiling
TAGMOOD does not adopt, as an independent controller within the scope described on this page, decisions based solely on automated processing that produce legal effects or similarly significantly affect data subjects.
The Webmaster360 AI features produce content, suggestions or processing intended for review by authorized users. The Customer remains responsible for editorial decisions and any publication.
12. Minors and Special Categories of Data
The Webmaster360 administrative and support services are not specifically intended for minors.
TAGMOOD does not ordinarily require special categories of data or data relating to criminal offences to manage the relationship, support or security. Data subjects are invited not to include unnecessary sensitive data in communications.
Special categories, criminal offence data and data relating to minors that may be present in content managed by Customers are processed by TAGMOOD on behalf of the Customer in accordance with the DPA.
13. Data Subjects’ Rights
Where TAGMOOD acts as a controller, the data subject may exercise, within the limits and under the conditions provided for by Applicable Law, the rights of:
- access;
- rectification;
- erasure;
- restriction of processing;
- objection;
- portability, where applicable;
- withdrawal of consent, where processing is based on consent.
Requests may be sent to:
TAGMOOD may request information necessary to verify the identity of the requester and to identify the data concerned.
Where a request concerns data processed on behalf of a Customer, TAGMOOD shall forward it to the competent controller Customer and provide the assistance provided for by the DPA.
The data subject also has the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali) or the competent supervisory authority.
14. Changes to This Page
TAGMOOD may update this page to reflect regulatory, organizational, technical or service changes.
Each version shall bear the relevant effective date and last update date. Material changes shall be communicated through reasonable channels where required by law or by the nature of the processing.
