Skip to content
Ditap®
Back to Home

Data Processing Agreement (DPA)

Last updated: August 2026

0. About this document

This page describes the standard terms of our Data Processing Agreement (DPA) — it does not replace the signable document. If your company entrusts us with processing personal data (for example, when contracting managed infrastructure, hosting, or connectivity services where we process data on your behalf), request the PDF version ready for e-signature by writing to [email protected], stating your company name and the contracted service.

This document applies when DITAP acts as Processor on behalf of a client that is the Controller, under Art. 28 of Regulation (EU) 2016/679 (GDPR) and, where applicable, Argentina's Law 25.326 and Chile's Law 21.719.

1. Subject matter and parties

This DPA governs the processing of personal data that DITAP (Inversiones Tecnomagallanes SpA — Chile — and its current or future affiliated entities or legal representations in the other countries where it operates), as Processor, carries out on behalf of the client contracting our services ("the Controller"), within the framework of the main services agreement signed between both parties.

This DPA is an annex to the services agreement and is governed by the same commercial terms. In the event of a conflict between this DPA and the main agreement regarding data protection, this DPA prevails.

2. Definitions

For the purposes of this document, the terms "personal data," "processing," "Controller," "Processor," "data subject," and "personal data breach" have the meaning assigned by Art. 4 GDPR, and analogously the data protection regulations of Argentina and Chile where applicable.

"Sub-processor" means any third party to whom the Processor subcontracts part of the processing (for example, a hosting provider).

3. Duration

This DPA takes effect on the start date of the main services agreement and remains in force for as long as DITAP processes personal data on the Controller's behalf, even if the main agreement sets a different term for other obligations. It survives termination of the main agreement solely with respect to the return or deletion of data (Section 13) and confidentiality.

4. Nature and purpose of processing

DITAP processes personal data on the Controller's behalf solely to deliver the contracted service — for example: network infrastructure operation, hosting and systems monitoring, managed technical support, WiFi connectivity management, or processing of forms and communications tied to the service.

Processing is limited to what is strictly necessary to perform the service and to the Controller's documented instructions (including the initial instructions set out in the services agreement and this DPA).

5. Categories of data and data subjects

Categories of personal data DITAP may process, depending on the contracted service: identification and contact data of the Controller's employees or customers, IP addresses and network metadata, access and system usage logs, technical credentials for accessing the Controller's infrastructure, and contact data of guests or end users when the service includes managed WiFi connectivity.

Categories of data subjects: the Controller's employees, the Controller's customers or guests, and the Controller's suppliers where applicable.

Specific categories are detailed in the technical annex of each services agreement, since they vary depending on which division delivers the service (infrastructure, cloud, security, connectivity or hospitality).

6. Processor obligations

Under Art. 28(3) GDPR, DITAP undertakes to:

  • (a) Process personal data only on the Controller's documented instructions, unless required to do otherwise by law — in which case it will inform the Controller beforehand, unless prohibited by law on important grounds of public interest.
  • (b) Ensure that persons authorized to process the data are bound by confidentiality or are under an appropriate statutory obligation of confidentiality.
  • (c) Apply the technical and organizational measures described in Section 8 (Art. 32 GDPR).
  • (d) Respect the conditions for engaging another processor (sub-processor) set out in Section 9.
  • (e) Assist the Controller, insofar as reasonable, in responding to requests for exercising data subjects' rights.
  • (f) Assist the Controller in ensuring compliance with its security, breach-notification and impact-assessment obligations (Art. 32–36 GDPR), taking into account the nature of processing and the information available.
  • (g) At the Controller's choice, delete or return all personal data at the end of the service, and delete existing copies, unless retention is required by law (see Section 13).
  • (h) Make available to the Controller the information necessary to demonstrate compliance with these obligations, and allow for and contribute to audits (see Section 12).
  • 7. Confidentiality

    All DITAP personnel, contractors and collaborators with access to the Controller's personal data are bound by confidentiality agreements, and only access the data they need to perform their tasks (least-privilege principle).

    8. Technical and organizational security measures

    Consistent with the measures described in Section 9 of our Privacy Policy (ditap.io/en/privacy), DITAP implements at a minimum:

  • Encryption in transit (TLS 1.3) and at rest (AES-256) for the data it processes.
  • Multi-factor authentication (MFA) on administrative systems that grant access to the Controller's data.
  • Role-based access control and least-privilege principle.
  • Technical logging and monitoring of errors and incidents (see our Cookie Policy, Section 6, on our use of Sentry for this purpose).
  • Regular backups and disaster-recovery procedures.
  • Periodic review of these measures as the state of the art evolves.
  • Service-specific technical detail is documented in the security annex of the relevant contract.

    9. Sub-processors

    The Controller gives DITAP general authorization to engage the sub-processors necessary to deliver the service (for example, hosting, CDN or transactional email providers), provided DITAP:

  • Imposes on each sub-processor, by contract, data protection obligations equivalent to those of this DPA.
  • Maintains an up-to-date list of sub-processors available at /trust/sub-processors, and informs the Controller of any intended changes (addition or replacement of sub-processors), giving it a reasonable opportunity to object on justified data-protection grounds.
  • Remains fully liable to the Controller for the performance of each sub-processor's obligations.
  • The complete, current list of sub-processors is also available on request at [email protected].

    10. International data transfers

    Where processing involves a transfer of personal data outside the European Economic Area (for example, to sub-processors with infrastructure in the United States), DITAP ensures an adequate safeguard exists under Chapter V GDPR — typically Standard Contractual Clauses (SCCs) issued by the European Commission — before making such a transfer. Provider-level detail is in Section 4 of our Privacy Policy (ditap.io/en/privacy).

    11. Personal data breach notification

    If DITAP becomes aware of a breach affecting the Controller's personal data, it will notify the Controller without undue delay and in any case within 48 hours of becoming aware of it, with the information available at that time about its nature, the categories and approximate number of data and data subjects affected, the likely consequences, and the measures taken or proposed to address it — so the Controller can meet its own 72-hour notification duty to the supervisory authority (Art. 33 GDPR).

    12. Audits and compliance verification

    DITAP makes available to the Controller the information reasonably necessary to demonstrate compliance with this DPA, and allows for audits — including inspections — conducted by the Controller or an external auditor it appoints, with at least 30 days' reasonable notice, during business hours, without interfering with the operation of other clients, and subject to a confidentiality agreement. Reasonable audit costs are borne by the Controller, unless the audit reveals a material breach of this DPA by DITAP.

    13. Return or deletion of data at termination

    At the end of the service, and at the Controller's choice, DITAP will delete or return all personal data processed on its behalf, and delete existing copies, within a reasonable period (30 days by default), unless a legal obligation requires retention for a longer period — in which case DITAP will inform the Controller and limit processing to what is strictly necessary to comply with that obligation.

    14. Liability

    Each party is liable to the other and to supervisory authorities according to its role (Controller or Processor) as set out in the GDPR and applicable law. Nothing in this DPA limits data subjects' rights against either party.

    15. Term and governing law

    This DPA is governed by the same law applicable to the main services agreement (see Section 12 of our Terms and Conditions, ditap.io/en/terms, for jurisdiction-specific detail: Argentina, Chile or Italy/EU). It remains in force for as long as personal data is processed on the Controller's behalf, as indicated in Section 3.

    16. Contact and signable version

    To request the signable version of this DPA, resolve questions about its scope, or coordinate signing a contract-specific technical annex: [email protected].

  • Processor: DITAP (Inversiones Tecnomagallanes SpA — Chile — and its current or future affiliated entities or legal representations in the other countries where it operates)
  • Email: [email protected]
  • Operations: Argentina, Chile, Italy