← Back to Climbo

Data Processing Agreement

Last updated — June 16, 2026. Questions? help@climbo.com

This Data Processing Agreement ("DPA") forms part of the agreement, order form, terms of service, subscription agreement, or other written or electronic agreement ("Main Agreement") between the agency or individual ("Controller" or "Agency") accessing or using the Climbo platform, and:

Saaslink S.r.l., operating the platform known as Climbo, with registered office at Via Marsala 29H, 00185 Roma (RM), Italy

("Processor" or "Climbo")

Each a "Party" and together the "Parties".

1. Purpose

This DPA governs the Processing of Personal Data by Climbo on behalf of the Agency in connection with the provision of the Climbo platform and related services.

The Agency acts as Controller of the Personal Data processed through the platform. Climbo acts as Processor and processes Personal Data only on behalf of and under the documented instructions of the Agency, except where required otherwise by applicable law.

2. Definitions

For the purposes of this DPA:

  • "Applicable Data Protection Laws" means Regulation (EU) 2016/679, the General Data Protection Regulation ("GDPR"), and any applicable national data protection laws.
  • "Personal Data", "Processing", "Controller", "Processor", "Data Subject", "Personal Data Breach", and "Supervisory Authority" have the meanings given to them under the GDPR.
  • "Services" means the Climbo platform and any related services provided to the Agency, including review management, messaging, listing management, social media scheduling, campaigns, chat aggregation, customer contact management, and other related features.
  • "Sub-processor" means any third party engaged by Climbo to process Personal Data on behalf of the Agency.

3. Scope of Processing

Climbo shall process Personal Data only to provide the Services under the Main Agreement.

The subject matter, duration, nature, purpose, categories of Personal Data, and categories of Data Subjects are described in Annex 1.

The technical and organizational security measures are described in Annex 2.

The list of authorized Sub-processors is described in Annex 3.

4. Instructions from the Controller

Climbo shall process Personal Data only on documented instructions from the Agency, including with regard to transfers of Personal Data to a third country or international organization, unless required to do so by Union or Member State law.

The Agency's instructions are deemed to include:

  • the configuration and use of the Services by the Agency and its authorized users;
  • the processing required to provide, maintain, secure, and improve the Services;
  • the processing required to provide technical support;
  • any additional written instructions agreed by the Parties.

If Climbo believes that an instruction infringes Applicable Data Protection Laws, Climbo shall inform the Agency without undue delay, unless prohibited by law.

5. Controller Responsibilities

The Agency is responsible for:

  • determining the purposes and means of the Processing;
  • ensuring that it has a valid legal basis for collecting and processing Personal Data;
  • providing all required privacy notices to Data Subjects;
  • obtaining any required consent, including for marketing, SMS, WhatsApp, email, or other communications;
  • ensuring that Personal Data uploaded or imported into Climbo is accurate, lawful, and relevant;
  • responding to Data Subject requests, unless assistance from Climbo is required;
  • ensuring that its use of the Services complies with Applicable Data Protection Laws.

The Agency shall not use the Services to process special categories of Personal Data under Article 9 GDPR unless expressly agreed in writing with Climbo.

6. Processor Responsibilities

Climbo shall:

  • process Personal Data only in accordance with this DPA and the Agency's documented instructions;
  • ensure that persons authorized to process Personal Data are bound by confidentiality obligations;
  • implement appropriate technical and organizational measures to protect Personal Data;
  • assist the Agency, where reasonably possible, in responding to Data Subject requests;
  • assist the Agency with security, breach notification, data protection impact assessments, and prior consultations where required;
  • make available information reasonably necessary to demonstrate compliance with this DPA;
  • delete or return Personal Data after the end of the Services, unless retention is required by law;
  • ensure that Sub-processors are bound by written data protection obligations no less protective than those in this DPA.

7. Confidentiality

Climbo shall ensure that any personnel authorized to process Personal Data are subject to appropriate confidentiality obligations, whether contractual, statutory, or professional.

Climbo shall take reasonable steps to ensure that access to Personal Data is limited to personnel who need such access to provide the Services.

8. Security Measures

Climbo shall implement appropriate technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.

Such measures shall take into account the state of the art, implementation costs, nature, scope, context, and purposes of Processing, and the risk to Data Subjects.

The security measures are described in Annex 2.

9. Data Subject Requests

Taking into account the nature of the Processing, Climbo shall assist the Agency, through appropriate technical and organizational measures where possible, in fulfilling its obligation to respond to requests from Data Subjects.

Such requests may include:

  • access;
  • rectification;
  • erasure;
  • restriction;
  • portability;
  • objection;
  • withdrawal of consent, where applicable.

If Climbo receives a request directly from a Data Subject relating to Personal Data processed on behalf of the Agency, Climbo shall not respond substantively unless instructed by the Agency, except to confirm receipt and/or redirect the Data Subject to the Agency.

10. Personal Data Breach

Climbo shall notify the Agency without undue delay after becoming aware of a Personal Data Breach affecting Personal Data processed on behalf of the Agency.

The notification shall include, where reasonably available:

  • the nature of the breach;
  • the categories and approximate number of affected Data Subjects;
  • the categories and approximate number of affected records;
  • the likely consequences of the breach;
  • the measures taken or proposed to address the breach;
  • the contact point for further information.

Climbo shall reasonably cooperate with the Agency in investigating, mitigating, and documenting the breach.

The Agency remains responsible for notifying the competent Supervisory Authority and affected Data Subjects where required by Applicable Data Protection Laws.

11. Sub-processors

The Agency grants Climbo general written authorization to engage Sub-processors to provide the Services.

Climbo shall maintain an up-to-date list of Sub-processors in Annex 3 or on a dedicated online page made available to the Agency.

Climbo shall inform the Agency of any intended addition or replacement of Sub-processors. The Agency may object to such change on reasonable data protection grounds within 30 days of notification.

If the Agency objects and the Parties cannot resolve the objection, the Agency may terminate the affected Services in accordance with the Main Agreement.

Climbo shall ensure that each Sub-processor is bound by written obligations that provide at least the same level of data protection as this DPA.

Climbo remains responsible for the performance of its Sub-processors' data protection obligations.

12. International Transfers

Climbo shall not transfer Personal Data outside the European Economic Area unless appropriate safeguards are in place under Applicable Data Protection Laws.

Where required, such safeguards may include:

  • an adequacy decision by the European Commission;
  • Standard Contractual Clauses approved by the European Commission;
  • supplementary measures where necessary;
  • another valid transfer mechanism under Applicable Data Protection Laws.

The European Commission provides standard contractual clauses for controller-processor relationships and for international data transfers, which may be used where applicable.

13. Assistance with Compliance

Taking into account the nature of the Processing and the information available to Climbo, Climbo shall reasonably assist the Agency with its obligations under Articles 32 to 36 GDPR, including:

  • security of Processing;
  • Personal Data Breach notifications;
  • data protection impact assessments;
  • prior consultation with Supervisory Authorities, where required.

Climbo may charge reasonable fees for assistance that goes beyond standard platform functionality or support, unless the assistance is required because of Climbo's breach of this DPA.

14. Audits and Compliance Information

Climbo shall make available to the Agency information reasonably necessary to demonstrate compliance with this DPA.

The Agency may request an audit of Climbo's compliance with this DPA, subject to the following conditions:

  • the audit must be conducted during normal business hours;
  • the Agency must provide reasonable prior written notice;
  • the audit must not disrupt Climbo's operations or compromise the security or confidentiality of other customers;
  • the auditor must be independent and bound by confidentiality obligations;
  • the audit may be limited to relevant documentation, policies, certifications, or security summaries where appropriate.

Climbo may refuse or limit access to systems, environments, or information where such access would create security, confidentiality, or operational risks.

15. Return and Deletion of Personal Data

Upon termination or expiry of the Services, Climbo shall, at the Agency's choice, delete or return Personal Data processed on behalf of the Agency, unless retention is required by applicable law.

The Agency may export available data through the platform or request assistance from Climbo where technically feasible.

After deletion, Climbo may retain limited backup copies for a reasonable period, provided that such copies remain protected and are deleted according to Climbo's backup retention schedule.

16. Data Retention

Personal Data shall be retained for the duration of the Services unless:

  • the Agency deletes the data;
  • the Agency requests deletion;
  • the Main Agreement requires deletion;
  • applicable law requires longer retention.

The Agency is responsible for defining its own retention periods for Personal Data processed through the Services.

17. Use of Aggregated or Anonymized Data

Climbo may process aggregated, anonymized, or statistical data for analytics, security, product improvement, and business purposes, provided that such data cannot reasonably identify the Agency, its clients, or any Data Subject.

Such data shall not be considered Personal Data under this DPA.

18. AI and Automated Features

Where the Services include AI-assisted features, such as review replies, social content generation, blog content generation, ranking analysis, or similar features, Climbo shall process Personal Data only as necessary to provide those features.

The Agency is responsible for reviewing AI-generated outputs before publication or use where required.

Climbo shall not intentionally use Agency Personal Data to train general-purpose AI models unless expressly agreed in writing with the Agency.

19. Messaging and Communications

Where the Agency uses the Services to send SMS, WhatsApp, email, review requests, campaigns, or other communications, the Agency is responsible for:

  • obtaining valid consent or another lawful basis;
  • ensuring that recipients have received appropriate privacy notices;
  • respecting opt-out, unsubscribe, and objection requests;
  • complying with marketing, telecom, and anti-spam rules applicable in the relevant jurisdiction;
  • ensuring that message content is lawful and accurate.

Climbo acts as Processor when enabling the Agency to send such communications through the Services.

20. Limitation of Liability

The liability of each Party under this DPA shall be subject to the limitations and exclusions of liability set out in the Main Agreement, unless prohibited by Applicable Data Protection Laws.

Nothing in this DPA limits either Party's liability where such limitation is not permitted by law.

21. Order of Precedence

In the event of conflict between this DPA and the Main Agreement, this DPA shall prevail with respect to the Processing of Personal Data.

In the event of conflict between this DPA and any applicable Standard Contractual Clauses, the Standard Contractual Clauses shall prevail to the extent of the conflict.

22. Governing Law

This DPA shall be governed by the law specified in the Main Agreement.

If no governing law is specified, this DPA shall be governed by the laws of Italy, unless mandatory data protection law requires otherwise.

23. Term

This DPA remains in effect for as long as Climbo processes Personal Data on behalf of the Agency.

Annex 1 — Details of Processing

1. Subject Matter

The Processing of Personal Data by Climbo on behalf of the Agency in connection with the provision of the Climbo platform and related services.

2. Duration

For the duration of the Main Agreement and until Personal Data is deleted or returned in accordance with this DPA.

3. Nature and Purpose of Processing

Climbo processes Personal Data to provide, maintain, secure, support, and improve the Services, including:

  • creating and managing Agency accounts;
  • creating and managing client business accounts;
  • importing, storing, and organizing customer contacts;
  • sending review requests, messages, campaigns, and notifications;
  • managing reviews and review replies;
  • managing business listings and business profile data;
  • scheduling and publishing social media content;
  • aggregating and managing customer conversations;
  • generating AI-assisted content where enabled;
  • providing analytics, reporting, and platform functionality;
  • providing technical support;
  • ensuring platform security, fraud prevention, logging, and troubleshooting.

4. Categories of Data Subjects

Personal Data may relate to:

  • Agency owners, staff, and authorized users;
  • Agency clients and their staff;
  • local business customers and contacts;
  • review authors;
  • message recipients;
  • website visitors or leads, where imported or collected through the Services;
  • support contacts.

5. Categories of Personal Data

Personal Data may include:

  • first and last name;
  • email address;
  • phone number;
  • business name;
  • business address;
  • job title or role;
  • customer contact details;
  • review content and review metadata;
  • message content;
  • communication preferences;
  • opt-in and opt-out status;
  • social media profile information where connected;
  • Google Business Profile or listing information;
  • account login and authentication data;
  • billing and subscription metadata;
  • technical logs, IP addresses, device data, timestamps, and usage data;
  • support communications.

6. Special Categories of Personal Data

The Services are not intended to process special categories of Personal Data under Article 9 GDPR.

The Agency shall not upload or process special category data through the Services unless expressly authorized in writing by Climbo and subject to additional safeguards.

7. Frequency of Processing

Continuous, for the duration of the Services.

8. Processing Operations

Processing operations may include:

  • collection;
  • recording;
  • storage;
  • organization;
  • structuring;
  • retrieval;
  • consultation;
  • transmission;
  • disclosure to authorized Sub-processors;
  • alignment or combination;
  • restriction;
  • erasure;
  • destruction.

Annex 2 — Technical and Organizational Measures

Climbo shall maintain appropriate technical and organizational measures, which may include:

1. Access Control

  • role-based access controls;
  • restricted access to production systems;
  • authentication requirements for authorized users;
  • internal access limited to personnel with a business need;
  • account permission management.

2. Security of Systems

  • secure hosting infrastructure;
  • firewall and network security controls;
  • monitoring of systems and services;
  • protection against unauthorized access;
  • secure configuration practices.

3. Encryption

  • encryption in transit where technically feasible;
  • encryption at rest where supported by infrastructure providers;
  • secure handling of credentials, tokens, and secrets.

4. Confidentiality

  • confidentiality obligations for personnel;
  • limited internal access to customer data;
  • internal policies for secure data handling.

5. Availability and Resilience

  • backup and recovery procedures;
  • infrastructure monitoring;
  • incident response procedures;
  • service continuity practices.

6. Logging and Monitoring

  • application and system logs;
  • security and error monitoring;
  • audit trails where technically available;
  • monitoring for suspicious or abnormal activity.

7. Data Minimization

  • processing limited to what is necessary to provide the Services;
  • restricted access to Personal Data;
  • deletion or anonymization where appropriate.

8. Vendor Management

  • assessment of Sub-processors;
  • written agreements with Sub-processors;
  • use of reputable infrastructure and service providers;
  • review of security and privacy measures where appropriate.

9. Incident Management

  • internal breach escalation process;
  • investigation and mitigation procedures;
  • notification to affected controllers where required;
  • documentation of security incidents.

Annex 3 — Authorized Sub-processors

Climbo should keep this list updated and notify Agencies of any material changes in accordance with Section 11.

Sub-processor Purpose Location / Transfer Mechanism
{{ s.name }} {{ s.purpose }} {{ s.location }}

Annex 4 — Controller Instructions

The Agency instructs Climbo to process Personal Data as necessary to:

  • provide the Services;
  • create and manage user accounts;
  • host and store Personal Data;
  • process customer contacts and communication data;
  • send messages, review requests, and campaigns;
  • connect and synchronize third-party integrations;
  • provide customer support;
  • secure and monitor the Services;
  • comply with applicable legal obligations;
  • delete or return Personal Data upon termination, where applicable.

Legal Effect of this Document

This Data Processing Agreement constitutes a legally binding and enforceable data processing agreement between the Agency and Saaslink S.r.l. (Climbo) for the purposes of Article 28 of Regulation (EU) 2016/679 (GDPR).

By accessing or using the Climbo platform, the Agency acknowledges that it has read, understood, and agrees to be bound by the terms of this DPA. Acceptance may occur through electronic means, including by clicking an acceptance button, by signing up for the Services, or by continuing to use the Services after this DPA has been made available.

Saaslink S.r.l. — Via Marsala 29H, 00185 Roma (RM), Italy — help@climbo.com