LEGAL

Data Processing Agreement.

Last updated: 9 August 2026. The Article 28 GDPR terms that apply when we process personal data on a customer's behalf.

Processor TMMA SRLS
Framework Article 28 GDPR
Last updated 9 August 2026

1. Roles and scope

This Data Processing Agreement ("DPA") forms part of the Terms of Service between TMMA SRLS ("Processor", "we") and the customer ("Controller", "you"). It applies whenever we process personal data on your behalf through the MessageMind platform.

You determine the purposes and means of that processing. We process only on your documented instructions, which include your configuration of the platform, the integrations you connect and the support requests you raise.

A signed counterpart is available on request. Where you have a negotiated DPA with us, that document prevails over this one.

2. Subject matter, duration and categories

ItemDetail
Subject matterProvision of the MessageMind AI communication platform
DurationFor the term of the Terms of Service, plus the retention periods in the Retention Schedule
Nature and purposeReceiving, storing, generating, routing and sending customer communication across connected channels
Types of personal dataNames, contact details, message and call content, booking and order details, device and usage metadata, and any other data you choose to submit
Categories of data subjectYour staff users, and the end customers, guests and prospects who communicate with you
Special categoriesNot required by the service. If you submit them you remain responsible for the additional conditions under Articles 9 and 10 GDPR

3. Processing on instructions

We process personal data only on your instructions, including for international transfers, unless EU or Italian law requires otherwise. In that case we inform you before processing unless the law forbids it on important grounds of public interest.

We will tell you if, in our opinion, an instruction infringes the GDPR or other applicable data-protection law.

4. Confidentiality of personnel

Personnel authorised to process personal data are bound by confidentiality obligations, receive access on a need-to-know basis and are instructed on their duties before access is granted.

5. Security of processing

We implement appropriate technical and organisational measures under Article 32 GDPR, including encryption in transit and at rest, least-privilege access with multi-factor authentication, logging and monitoring, environment segregation and encrypted backups. The current measures are described on the Security page, which forms part of this DPA.

We may update the measures as technology evolves, provided the level of protection is not reduced.

6. Sub-processors

You give general authorisation for us to engage sub-processors. The current list is published at /subprocessors. Each sub-processor is bound by written terms no less protective than this DPA, and we remain fully liable for their performance.

We give at least 30 days' notice before a new sub-processor starts processing your data, and you may object on reasonable data-protection grounds as described on that page.

7. Assistance with your obligations

Taking into account the nature of the processing, we assist you with appropriate measures in responding to data-subject requests. Where a request reaches us directly we do not respond on your behalf, except to confirm we act as processor, and we forward it to you without undue delay.

We also assist you, on request and taking into account the information available to us, with data-protection impact assessments, prior consultations and your security obligations under Articles 32 to 36 GDPR.

8. Personal data breach notification

We notify you without undue delay, and in any case within 48 hours of becoming aware of a personal data breach affecting your data. The notification describes the nature of the breach, the categories and approximate number of records concerned, the likely consequences and the measures taken or proposed.

Where full information is not available immediately, we provide it in phases as the investigation progresses. Notifying you does not constitute an admission of fault.

9. Deletion and return of data

On termination you may export your data for 30 days. After that we delete or anonymise personal data processed on your behalf within 90 days, and instruct sub-processors to do the same, except where EU or Italian law requires longer retention. Full periods are in the Retention Schedule.

10. Audits and information

We make available the information needed to demonstrate compliance with Article 28, and allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate.

Audits take place no more than once a year unless a regulator requires otherwise or a breach has occurred, with at least 30 days' notice, during business hours, without disrupting operations and subject to confidentiality. We may satisfy a request by providing our documentation where that reasonably answers it.

11. Personal data obtained from third-party platforms

When you connect a third-party platform, personal data may reach the service through that platform's API. Unless the platform's own partner terms provide otherwise, the platform operator and you each act as independent controllers of that data for your own purposes, and we act as your processor for what we process on your behalf.

Some platform API terms designate the integration partner as a separate and independent controller of API personal data. Where that applies to us, we process the data only to operate the integration you enabled, under the platform's terms and the limits in the Retention Schedule, and never to build profiles for our own marketing or to train shared models.

You remain responsible for the lawful basis on which you communicate with those individuals, for the notices given to them, and for complying with the connected platform's rules on contact, payments, off-platform communication and reviews. We will confirm our exact role for a specific platform on request during a security review.

12. International transfers, precedence and contact

Primary storage is in the EU. Where a transfer outside the EU/EEA is necessary, it takes place under an adequacy decision or the EU Standard Contractual Clauses, with supplementary measures where required. You mandate us to conclude SCCs with sub-processors on your behalf.

If this DPA conflicts with the Terms of Service on a data-protection matter, this DPA prevails. Everything else in the Terms continues to apply.

To request a signed copy or raise a data-protection matter: [email protected]. TMMA SRLS, Via Durazzo 28, 00195 Roma (RM), Italy.