Data Processing Addendum
These are our Article 28 processor terms. They are already in force for every customer, you do not need to request, negotiate or sign a separate copy.
On this page 11 sections
When this applies
This addendum forms part of the Terms of Use and applies whenever you use Magemcy to process personal data for which you are the controller, which, for a procurement tool, is essentially always: your suppliers’ contact people are personal data.
Publishing it as an in-force document rather than a template on request is deliberate. A DPA that only exists once a customer thinks to ask for one is not much of a commitment.
Roles and scope
You are the controller. You decide what personal data goes into your workspace and why. Magemcy is the processor, acting on your instructions.
- Subject matter: providing the Magemcy procurement platform.
- Duration: for as long as your subscription lasts, plus the deletion period below.
- Nature and purpose: hosting, storing, transmitting, displaying and analysing data so the service works.
- Types of personal data: business contact details of your staff and your suppliers’ staff; names, roles, email addresses, phone numbers; and whatever else you choose to record on a vendor, bid, order or invoice.
- Categories of data subject: your personnel, and your suppliers’ personnel.
Magemcy is not built for special-category data as defined in Article 9, and you should not put it there.
Our instructions
We process personal data only on your documented instructions. Your use of the product is the instruction: creating a vendor, inviting a supplier, running an evaluation. We also process where law requires it, and will tell you first unless the law forbids that.
We do not sell your data, do not use it for our own marketing, and do not use it to train AI models.
Confidentiality
Everyone with access is bound by confidentiality obligations, and access is limited to those who need it to run or support the service.
Security
We maintain the technical and organisational measures described on our security page, which forms part of this addendum: encryption in transit and at rest, tenant isolation enforced server-side, role-based access, audit records for privileged actions, and payment handling that keeps card data off our systems entirely.
That page also states plainly what we do not hold, no SOC 2, no ISO 27001, no completed third-party audit. We would rather that be visible in the document you are assessing than discovered later.
Subprocessors
You give general authorisation for us to engage subprocessors. The current list is published on subprocessors. Each is bound by written terms no less protective than these. We update that page before a new one begins processing, and you may object on reasonable data-protection grounds, if we cannot resolve it, you may terminate the affected subscription. We remain responsible for their performance.
Assisting with data subject rights
Much of this you can do yourself, immediately, which is faster than any assistance we could offer: search, correct, export and delete records inside your workspace, and delete the workspace itself.
Where you need more, we will help, taking into account the nature of the processing. If a data subject contacts us directly about data in your workspace, we will not respond substantively, we will tell them to contact you, and tell you.
Breach notification
We will notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information you need to meet your own obligations, what happened, which categories and roughly how many records, likely consequences, and what we are doing about it.
Audit
We will make available the information needed to demonstrate compliance with Article 28. In practice that means this addendum, our security and subprocessor pages, and answering your questions in writing, ask us.
We do not currently hold an audit report to send you, and we are not going to pretend otherwise. Where a customer has a legal obligation to audit, we will agree a reasonable approach, at your cost, on reasonable notice, not more than once a year unless a regulator requires it.
International transfers
Processing takes place in the United States. For transfers from the EEA, UK or Switzerland, the European Commission’s Standard Contractual Clauses (Decision 2021/914, Module Two, controller to processor) are incorporated into this addendum by reference, with the UK International Data Transfer Addendum where the UK GDPR applies. Where the Clauses require an option, the docking clause applies, and the governing law and forum follow the State of Florida, United States to the extent permitted.
Return and deletion
You can export your data at any time from within the product. On termination, and at your choice, we delete or return personal data, and delete existing copies except where law requires retention.
Backups age out on their normal cycle rather than being individually rewritten; nothing recovered from a backup is returned to active use. Operational records such as email delivery logs are deleted on the schedule published in our Privacy Notice, currently 90 days.
Questions about this addendum: our privacy contact.
If your organisation requires its own paper, tell us what it needs and we will look at it. But nothing here is contingent on that: these terms bind us today.
Questions about this policy?
A person reads every message. Get in touch and we’ll answer. Or ask Gero, our AI assistant, to walk you through what this page says - the answers explain, they don’t bind.