Skip to content
Tagmaps
Product
GTM Controller Test GTM candidates before controlled publishes. Privacy Testing Test consent, CMP, GPC, and regional policies. Website Scanning Capture live-site activity and monitor changes. Tag & Technology Inventory Identify vendors, requests, and initiator chains.
Teams
Privacy & compliance Turn policies into repeatable tests and evidence. Marketing & analytics Ship tags with visibility and controlled publishing. Agencies & consultants Audit and monitor authorized client sites.
Pricing Learn FAQ
Log in Free trial
Product
GTM Controller Test GTM candidates before controlled publishes. Privacy Testing Test consent, CMP, GPC, and regional policies. Website Scanning Capture live-site activity and monitor changes. Tag & Technology Inventory Identify vendors, requests, and initiator chains.
Teams
Privacy & compliance Turn policies into repeatable tests and evidence. Marketing & analytics Ship tags with visibility and controlled publishing. Agencies & consultants Audit and monitor authorized client sites.
Pricing Learn FAQ
Log in

Legal

Data Processing Agreement

Tagmaps, LLC

Effective date: August 22, 2026

Version: 2026-08-22

This Data Processing Agreement ("DPA") is part of the agreement between Tagmaps, LLC ("Tagmaps") and the organization using the Tagmaps Service ("Customer"). It applies only when Tagmaps processes personal data on Customer's behalf to provide the Service ("Customer Personal Data").

Customer accepts this DPA when its authorized representative accepts the Tagmaps Terms of Service, starts a trial, subscribes, signs an order form that references the Service, or otherwise instructs Tagmaps to process Customer Personal Data. No separate signature or checkbox is required. The account, order form, or other Agreement record identifies Customer and the accepting representative.

If Tagmaps determines the purposes and means of processing—for example, for website analytics, billing, security, support, or its business relationship with Customer—Tagmaps acts as a controller and the Privacy Policy applies instead of this DPA.


1. Roles and instructions

Customer is the controller of Customer Personal Data. If Customer processes personal data for another controller, Customer is a processor and Tagmaps is Customer's subprocessor. For US state privacy laws, Tagmaps acts as Customer's service provider, contractor, or processor, as applicable.

Tagmaps will process Customer Personal Data only:

  • on Customer's documented instructions, including the Agreement, Customer's configuration, and authorized use of the Service;
  • as needed to provide, secure, support, and maintain the Service; or
  • where applicable law requires it.

If law requires processing outside Customer's instructions, Tagmaps will notify Customer first unless the law prohibits notice. Tagmaps will promptly tell Customer if it reasonably believes an instruction violates applicable data-protection law and may pause the affected processing while the parties resolve the issue.

Customer is responsible for its instructions, the lawfulness and accuracy of Customer Personal Data, required notices and permissions, and responding to people whose data Customer controls. Customer should not intentionally submit special-category data, highly sensitive information, children's data, live credentials, or secrets unless Tagmaps has agreed in writing.

The processing details are in Schedule 1.


2. Tagmaps' processor duties

Tagmaps will:

  1. ensure that people authorized to process Customer Personal Data are bound by confidentiality;
  2. maintain the security measures in Schedule 2;
  3. use subprocessors only under Section 3;
  4. taking into account the nature of the processing, reasonably assist Customer with requests to access, correct, delete, restrict, port, opt out of, or otherwise exercise rights over Customer Personal Data;
  5. reasonably assist Customer with security, breach notification, data-protection impact assessments, and regulator consultations, taking into account the processing and information available to Tagmaps;
  6. notify Customer without undue delay after becoming aware of a confirmed personal-data breach affecting Customer Personal Data;
  7. return or delete Customer Personal Data as described in Section 4;
  8. provide information reasonably necessary to demonstrate compliance with this DPA and support audits under Section 5; and
  9. notify Customer if Tagmaps determines it can no longer meet a material obligation under this DPA or applicable data-protection law.

If Tagmaps receives a request or regulator inquiry specifically about Customer Personal Data, Tagmaps will refer it to Customer and notify Customer unless law prohibits doing so. Tagmaps will not respond for Customer except on Customer's documented instruction or as required by law.

A breach notice will include the information reasonably available to Tagmaps that Customer needs for its own response. Tagmaps may provide information in stages as the investigation develops. A notice is not an admission of fault.


3. Subprocessors

Customer gives Tagmaps general written authorization to use the subprocessors on the Subprocessors page as it exists when Customer accepts this DPA. That page is incorporated into this DPA as the current subprocessor list.

Tagmaps will:

  • use a written contract requiring each subprocessor to protect Customer Personal Data to a standard materially consistent with this DPA;
  • remain responsible for the subprocessor's processing as required by applicable law; and
  • give reasonable advance notice of a new or replacement subprocessor by email to Customer's account administrator or by a conspicuous Service notice.

Customer may object before the new subprocessor begins processing based on reasonable data-protection grounds. The parties will try in good faith to resolve the objection. If they cannot, Customer may stop using the affected feature or terminate the affected Service. Where an urgent security, legal, or continuity issue makes advance notice impracticable, Tagmaps may make the change and notify Customer promptly afterward.

A website, endpoint, Google resource, or other recipient Customer selects is not a Tagmaps subprocessor merely because the Service sends Customer-directed data or requests to it.


4. Return and deletion

During the Agreement, Customer may use available export and deletion controls or send an authenticated instruction to privacy@tagmaps.io.

When the Agreement ends, Customer may request an available export within 30 days. Unless Customer instructs Tagmaps to return data instead, Customer instructs Tagmaps to delete Customer Personal Data from active systems without undue delay through Tagmaps' verified deletion process.

Tagmaps may retain:

  • copies in routine backups until they are overwritten through the normal backup cycle, provided they remain protected and are not restored to ordinary use;
  • data that applicable law, a legal hold, security, fraud prevention, or a legal claim requires Tagmaps to retain, provided it is isolated from ordinary use and deleted when the reason ends; and
  • properly de-identified data that cannot reasonably identify Customer or a person, except where another binding commitment prohibits that retention.

Tagmaps will confirm completion on request. The Service does not currently provide an automated, self-service tenant-wide post-termination purge; the deletion process is verified and may be manual.


5. Information and audits

Tagmaps will provide information reasonably necessary to demonstrate compliance with this DPA, which may include a security summary, architecture or data-flow information, relevant policies, and completed questionnaires.

Customer may conduct one reasonable compliance review in a 12-month period. Customer may request an additional review after a breach affecting its data, when a regulator requires it, or when Customer has reasonable evidence of material noncompliance.

Reviews should begin with available documents and a remote questionnaire. An inspection must be reasonably necessary, scheduled on reasonable notice during normal business hours, avoid unnecessary disruption, protect other customers and Tagmaps confidential information, and be performed by Customer or an independent auditor that is not a Tagmaps competitor and is bound by confidentiality.

Customer pays its audit costs and Tagmaps' reasonable incremental costs for a custom inspection unless the inspection identifies material noncompliance by Tagmaps. Nothing in this section limits a regulator's lawful authority.


6. International transfers

Customer understands that Tagmaps is based in the United States, primarily hosts the Service in the United States, may scan from supported locations selected by Customer, and may use subprocessors in the locations shown on the Subprocessors page.

For a transfer of Customer Personal Data that requires an approved transfer mechanism (a "Restricted Transfer"):

6.1 EEA

The European Commission Standard Contractual Clauses adopted by Decision (EU) 2021/914 (the "EU SCCs") are incorporated by reference:

  • Module 2 applies when Customer is a controller and Tagmaps is a processor;
  • Module 3 applies when Customer is a processor and Tagmaps is a subprocessor;
  • Clause 7 applies;
  • Clause 9, Option 2 applies with the notice process in Section 3;
  • the optional language in Clause 11 does not apply;
  • Ireland is the governing member-state law under Clause 17;
  • Irish courts have jurisdiction under Clause 18;
  • Schedule 1 completes Annex I.B, Schedule 2 completes Annex II, and the Subprocessors page completes Annex III; and
  • the competent supervisory authority is determined under Clause 13.

Customer is the data exporter and Tagmaps is the data importer. Customer's name, address, contact, role, relevant activities, and signature details are the details in its account, order form, DPA request, or other Agreement record. Tagmaps' importer details are in Section 10. Customer will provide reasonably requested missing exporter or underlying-controller details needed to complete the EU SCCs.

6.2 United Kingdom

The current UK International Data Transfer Addendum to the EU SCCs (the "UK Addendum") is incorporated for a Restricted Transfer governed by UK data-protection law. The parties and selections are the same as those used for the EU SCCs above; Schedule 1, Schedule 2, and the Subprocessors page provide the Appendix Information. Neither party may terminate the Addendum solely because the UK Information Commissioner issues a revised approved form.

6.3 Switzerland

For a Restricted Transfer governed by Swiss data-protection law, the EU SCCs apply with the adaptations required to recognize Switzerland, the Swiss Federal Act on Data Protection, the Federal Data Protection and Information Commissioner, and Swiss data-subject rights.

The applicable official transfer terms control over conflicting liability, governing-law, dispute, or order-of-precedence terms. Each party will reasonably cooperate to complete missing details, assess the transfer, and adopt a replacement mechanism if an existing mechanism becomes invalid.

Official forms are available from:

  • European Commission — Standard Contractual Clauses
  • UK ICO — International Data Transfer Agreement and Addendum

7. US state privacy terms

Where US state privacy law applies to Customer Personal Data, Tagmaps will:

  • process it only for the specific purposes in Schedule 1 and Customer's documented instructions;
  • not sell it, share it for cross-context behavioral advertising, or use it for targeted advertising;
  • not retain, use, or disclose it outside the direct business relationship except as permitted by law;
  • not combine it with personal data from another source except as permitted by law and needed to provide the Service;
  • provide the same level of privacy protection applicable law requires of a service provider, contractor, or processor;
  • notify Customer if Tagmaps determines it can no longer meet an applicable obligation; and
  • allow Customer to take reasonable steps to monitor, stop, and remediate unauthorized processing, using the review process in Section 5.

Customer discloses Customer Personal Data to Tagmaps only for the business purposes in Schedule 1. Tagmaps will not receive Customer Personal Data as payment or consideration for the Service.


8. Liability and term

Liability under this DPA is subject to the exclusions and limits in the Agreement. Those limits do not reduce a person's rights or either party's liability where applicable law or the transfer terms do not allow the limitation.

This DPA begins when accepted and continues while Tagmaps processes Customer Personal Data. Terms protecting retained data continue until that data is deleted or returned.


9. Changes

Tagmaps may update this DPA to reflect changes in law or the Service. A material change that reduces Customer's rights or adds a material Customer obligation will take effect only after at least 30 days' email or in-product notice. Customer may object before the effective date and stop using the affected Service if the parties cannot resolve the objection.

Tagmaps may update the Subprocessors page under Section 3 and may update incorporated transfer terms when an authority replaces or revises an approved form. Tagmaps will not materially reduce protection of Customer Personal Data through an update.

The version shown at the top applies to new acceptances. Tagmaps will preserve the version associated with an existing acceptance record.


Schedule 1 — Processing details

Subject matter and duration

Tagmaps processes Customer Personal Data to provide the Service for the Agreement term and the return, deletion, backup, and legally required retention periods in Section 4.

Nature and purposes

Processing may include collecting, hosting, organizing, retrieving, analyzing, classifying, transmitting, displaying, exporting, securing, backing up, and deleting Customer Personal Data to:

  • administer Customer's workspace, users, roles, authentication, and permissions;
  • execute Customer-directed website scans, privacy tests, consent actions, schedules, and reports;
  • capture and classify technical artifacts such as cookies, storage, page content, screenshots, scripts, requests, responses, and consent behavior;
  • provide Customer-enabled Google Tag Manager functions;
  • send transactional notifications and provide support; and
  • secure, debug, maintain, and recover the Service.

Categories of people

Depending on Customer's use, Customer Personal Data may concern:

  • Customer administrators, Authorized Users, and personnel;
  • visitors to websites Customer directs Tagmaps to scan or test;
  • people identifiable in page content, URLs, cookies, storage, screenshots, or network traffic; and
  • people identifiable in Customer-connected Google resources.

Types of personal data

Customer Personal Data may include:

  • business contact, user, tenant, role, permission, and authentication identifiers controlled by Customer;
  • target domains, URLs, paths, scan configuration, test instructions, and selected locations;
  • cookie and storage names and values, IP addresses, hostnames, request and response metadata, browser data, page text and metadata, screenshots, consent content, and timestamps;
  • scan results, findings, evidence, and reviewer actions;
  • Google OAuth credentials and Google Tag Manager resource metadata; and
  • transactional recipient addresses and operational or security records associated with Customer's use.

The Service is not intended for Customer to submit special-category data, children's data, live credentials, or unrelated sensitive information. Scans of public websites may encounter such data incidentally.

Customer rights and obligations

Customer may configure the Service, issue lawful instructions, access available results, request assistance, export available data, and request return or deletion. Customer has the responsibilities in Section 1 and the Agreement.


Schedule 2 — Security measures

Tagmaps maintains measures appropriate to the Service and processing risk, including:

  • TLS for supported data in transit and encryption provided by AWS-managed services for supported production storage;
  • tenant-scoped application authorization, least-privilege administrative access, and multi-factor authentication for AWS administrative access;
  • managed secrets instead of credentials committed to source code;
  • separation of ordinary development activity from production access;
  • logging and monitoring for material security and operational events;
  • change review, automated tests, dependency review, and source scanning for covered systems;
  • AWS network, availability, backup, and physical-security controls for the managed services used by Tagmaps;
  • purpose limitation and restricted access to raw scan artifacts;
  • incident investigation and recovery procedures; and
  • authenticated export and deletion procedures, including a verified manual process where automation is unavailable.

Tagmaps may update these measures as the Service changes, provided the overall protection is not materially reduced.


10. Contact and importer details

Tagmaps, LLC

New York Department of State ID 7824396

c/o Registered Agents Inc.

418 Broadway, Ste. R

Albany, NY 12207

United States

DPA and legal notices: legal@tagmaps.io

Privacy instructions, exports, and deletion: privacy@tagmaps.io

Security and breach coordination: security@tagmaps.io

Tagmaps

Website privacy controls

Product

  • GTM Controller
  • Pricing
  • FAQ

Company

  • Learn
  • Contact

Legal

  • Privacy
  • Cookie notice
  • Security
  • Subprocessors
  • DPA
  • Terms of service
  • Cookie settings
© 2026 Tagmaps, LLC.