Last updated — June 16, 2026. Questions? help@climbo.com
This Data Processing Agreement ("DPA") forms part of the agreement, order form, terms of service, subscription agreement, or other written or electronic agreement ("Main Agreement") between the agency or individual ("Controller" or "Agency") accessing or using the Climbo platform, and:
Saaslink S.r.l., operating the platform known as Climbo, with registered office at Via Marsala 29H, 00185 Roma (RM), Italy
("Processor" or "Climbo")
Each a "Party" and together the "Parties".
This DPA governs the Processing of Personal Data by Climbo on behalf of the Agency in connection with the provision of the Climbo platform and related services.
The Agency acts as Controller of the Personal Data processed through the platform. Climbo acts as Processor and processes Personal Data only on behalf of and under the documented instructions of the Agency, except where required otherwise by applicable law.
For the purposes of this DPA:
Climbo shall process Personal Data only to provide the Services under the Main Agreement.
The subject matter, duration, nature, purpose, categories of Personal Data, and categories of Data Subjects are described in Annex 1.
The technical and organizational security measures are described in Annex 2.
The list of authorized Sub-processors is described in Annex 3.
Climbo shall process Personal Data only on documented instructions from the Agency, including with regard to transfers of Personal Data to a third country or international organization, unless required to do so by Union or Member State law.
The Agency's instructions are deemed to include:
If Climbo believes that an instruction infringes Applicable Data Protection Laws, Climbo shall inform the Agency without undue delay, unless prohibited by law.
The Agency is responsible for:
The Agency shall not use the Services to process special categories of Personal Data under Article 9 GDPR unless expressly agreed in writing with Climbo.
Climbo shall:
Climbo shall ensure that any personnel authorized to process Personal Data are subject to appropriate confidentiality obligations, whether contractual, statutory, or professional.
Climbo shall take reasonable steps to ensure that access to Personal Data is limited to personnel who need such access to provide the Services.
Climbo shall implement appropriate technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.
Such measures shall take into account the state of the art, implementation costs, nature, scope, context, and purposes of Processing, and the risk to Data Subjects.
The security measures are described in Annex 2.
Taking into account the nature of the Processing, Climbo shall assist the Agency, through appropriate technical and organizational measures where possible, in fulfilling its obligation to respond to requests from Data Subjects.
Such requests may include:
If Climbo receives a request directly from a Data Subject relating to Personal Data processed on behalf of the Agency, Climbo shall not respond substantively unless instructed by the Agency, except to confirm receipt and/or redirect the Data Subject to the Agency.
Climbo shall notify the Agency without undue delay after becoming aware of a Personal Data Breach affecting Personal Data processed on behalf of the Agency.
The notification shall include, where reasonably available:
Climbo shall reasonably cooperate with the Agency in investigating, mitigating, and documenting the breach.
The Agency remains responsible for notifying the competent Supervisory Authority and affected Data Subjects where required by Applicable Data Protection Laws.
The Agency grants Climbo general written authorization to engage Sub-processors to provide the Services.
Climbo shall maintain an up-to-date list of Sub-processors in Annex 3 or on a dedicated online page made available to the Agency.
Climbo shall inform the Agency of any intended addition or replacement of Sub-processors. The Agency may object to such change on reasonable data protection grounds within 30 days of notification.
If the Agency objects and the Parties cannot resolve the objection, the Agency may terminate the affected Services in accordance with the Main Agreement.
Climbo shall ensure that each Sub-processor is bound by written obligations that provide at least the same level of data protection as this DPA.
Climbo remains responsible for the performance of its Sub-processors' data protection obligations.
Climbo shall not transfer Personal Data outside the European Economic Area unless appropriate safeguards are in place under Applicable Data Protection Laws.
Where required, such safeguards may include:
The European Commission provides standard contractual clauses for controller-processor relationships and for international data transfers, which may be used where applicable.
Taking into account the nature of the Processing and the information available to Climbo, Climbo shall reasonably assist the Agency with its obligations under Articles 32 to 36 GDPR, including:
Climbo may charge reasonable fees for assistance that goes beyond standard platform functionality or support, unless the assistance is required because of Climbo's breach of this DPA.
Climbo shall make available to the Agency information reasonably necessary to demonstrate compliance with this DPA.
The Agency may request an audit of Climbo's compliance with this DPA, subject to the following conditions:
Climbo may refuse or limit access to systems, environments, or information where such access would create security, confidentiality, or operational risks.
Upon termination or expiry of the Services, Climbo shall, at the Agency's choice, delete or return Personal Data processed on behalf of the Agency, unless retention is required by applicable law.
The Agency may export available data through the platform or request assistance from Climbo where technically feasible.
After deletion, Climbo may retain limited backup copies for a reasonable period, provided that such copies remain protected and are deleted according to Climbo's backup retention schedule.
Personal Data shall be retained for the duration of the Services unless:
The Agency is responsible for defining its own retention periods for Personal Data processed through the Services.
Climbo may process aggregated, anonymized, or statistical data for analytics, security, product improvement, and business purposes, provided that such data cannot reasonably identify the Agency, its clients, or any Data Subject.
Such data shall not be considered Personal Data under this DPA.
Where the Services include AI-assisted features, such as review replies, social content generation, blog content generation, ranking analysis, or similar features, Climbo shall process Personal Data only as necessary to provide those features.
The Agency is responsible for reviewing AI-generated outputs before publication or use where required.
Climbo shall not intentionally use Agency Personal Data to train general-purpose AI models unless expressly agreed in writing with the Agency.
Where the Agency uses the Services to send SMS, WhatsApp, email, review requests, campaigns, or other communications, the Agency is responsible for:
Climbo acts as Processor when enabling the Agency to send such communications through the Services.
The liability of each Party under this DPA shall be subject to the limitations and exclusions of liability set out in the Main Agreement, unless prohibited by Applicable Data Protection Laws.
Nothing in this DPA limits either Party's liability where such limitation is not permitted by law.
In the event of conflict between this DPA and the Main Agreement, this DPA shall prevail with respect to the Processing of Personal Data.
In the event of conflict between this DPA and any applicable Standard Contractual Clauses, the Standard Contractual Clauses shall prevail to the extent of the conflict.
This DPA shall be governed by the law specified in the Main Agreement.
If no governing law is specified, this DPA shall be governed by the laws of Italy, unless mandatory data protection law requires otherwise.
This DPA remains in effect for as long as Climbo processes Personal Data on behalf of the Agency.
The Processing of Personal Data by Climbo on behalf of the Agency in connection with the provision of the Climbo platform and related services.
For the duration of the Main Agreement and until Personal Data is deleted or returned in accordance with this DPA.
Climbo processes Personal Data to provide, maintain, secure, support, and improve the Services, including:
Personal Data may relate to:
Personal Data may include:
The Services are not intended to process special categories of Personal Data under Article 9 GDPR.
The Agency shall not upload or process special category data through the Services unless expressly authorized in writing by Climbo and subject to additional safeguards.
Continuous, for the duration of the Services.
Processing operations may include:
Climbo shall maintain appropriate technical and organizational measures, which may include:
Climbo should keep this list updated and notify Agencies of any material changes in accordance with Section 11.
| Sub-processor | Purpose | Location / Transfer Mechanism |
|---|---|---|
| {{ s.name }} | {{ s.purpose }} | {{ s.location }} |
The Agency instructs Climbo to process Personal Data as necessary to:
This Data Processing Agreement constitutes a legally binding and enforceable data processing agreement between the Agency and Saaslink S.r.l. (Climbo) for the purposes of Article 28 of Regulation (EU) 2016/679 (GDPR).
By accessing or using the Climbo platform, the Agency acknowledges that it has read, understood, and agrees to be bound by the terms of this DPA. Acceptance may occur through electronic means, including by clicking an acceptance button, by signing up for the Services, or by continuing to use the Services after this DPA has been made available.
Saaslink S.r.l. — Via Marsala 29H, 00185 Roma (RM), Italy — help@climbo.com