Legal  /  DPA

Data Processing Agreement

How we process personal data on your behalf when your organization uses Magicite add-ons and services.


Proposed draft, subject to confirmation by legal counsel. This Data Processing Agreement ("DPA") forms part of the Terms of Service between Magicite ("we", "us", the "Processor") and the customer organization identified by its Microsoft Entra tenant (the "Customer", the "Controller"). It applies whenever we process personal data on the Customer's behalf in connection with the add-ons and this service. Customers who need a countersigned copy on file can contact legal@magicite.tech and we will execute the current version.

Roles and scope

The Customer is the controller and we are the processor of the personal data described below. Processing is limited to what operating the service requires: authenticating users, provisioning trials and subscriptions, issuing and validating licenses, delivering signed packages, invoicing, and support. Our add-ons are designed so that license validation and telemetry exclude the contents of the Customer's business records; the categories we process are limited to sign-in identity (name, work email or user principal name, object and tenant identifiers), billing and purchase-order contact details, environment identifiers, and standard request logs.

Processing on instructions

We process personal data only on the Customer's documented instructions, which are constituted by the Terms of Service, this DPA, and the Customer's use of the service, unless processing is required by law. If we believe an instruction infringes applicable data-protection law, we will inform the Customer before proceeding.

Confidentiality

Persons we authorize to process personal data are bound by confidentiality obligations and receive access on a least-privilege basis, as described in our Security overview.

Security measures

We implement appropriate technical and organizational measures: encryption in transit and at rest, tenant isolation of customer data, least-privilege and role-based access, server-side secret handling, and audit logging of package downloads and administrative actions. The measures are described in more detail in the Security overview, which forms part of this DPA.

Sub-processors

The Customer authorizes the following sub-processors: Microsoft Corporation (Microsoft Azure) for hosting, identity (Microsoft Entra), storage, and infrastructure. We will update this page before adding or replacing a sub-processor; continued use of the service after an update constitutes acceptance, and a Customer with a reasonable objection may terminate affected subscriptions. Proposed mechanism, subject to confirmation by legal counsel.

Assistance with data subject requests

Taking into account the nature of the processing, we will assist the Customer with appropriate technical and organizational measures in fulfilling its obligation to respond to data subject requests (access, correction, export, deletion, restriction, objection). Requests received by us directly from a data subject will be forwarded to the Customer without undue delay.

Personal data breach notification

We will notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's personal data, and will provide information reasonably required for the Customer to meet its own notification obligations, as it becomes available.

Deletion and return

On termination of the service relationship, we will delete or return personal data at the Customer's choice, subject to the retention obligations described in the Privacy Policy (records retained to meet legal, accounting, and audit obligations are kept for the periods stated there and then deleted).

International transfers

Personal data is hosted in Microsoft Azure regions. Where processing involves a transfer out of the data subject's jurisdiction, we rely on the safeguards available for that transfer, including Microsoft's data-protection commitments for Azure services. Proposed draft: specific transfer mechanisms (for example standard contractual clauses) are subject to confirmation by legal counsel.

Audit and information

We will make available information reasonably necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits conducted by the Customer or its mandated auditor, on reasonable notice and no more than once per year absent a specific incident. Azure's own platform controls are demonstrated through Microsoft's published audit reports rather than on-premise inspection.

Governing law

This DPA is governed by the laws of the State of Michigan, USA, consistent with the Terms of Service, except where the data-protection law applicable to the Customer's personal data requires otherwise.

Contact

Questions about this DPA or our processing? Email privacy@magicite.tech.

An unhandled error has occurred. Reload ๐Ÿ—™

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please retry or reload the page.