Legal / DPA
Data Processing Agreement
How we process personal data on your behalf when your organization uses Magicite add-ons and services.
Proposed draft, subject to confirmation by legal counsel. This Data Processing Agreement ("DPA") forms part of the Terms of Service between Magicite ("we", "us", the "Processor") and the customer organization identified by its Microsoft Entra tenant (the "Customer", the "Controller"). It applies whenever we process personal data on the Customer's behalf in connection with the add-ons and this service. Customers who need a countersigned copy on file can contact legal@magicite.tech and we will execute the current version.
Roles and scope
The Customer is the controller and we are the processor of the personal data described below. Processing is limited to what operating the service requires: authenticating users, provisioning trials and subscriptions, issuing and validating licenses, delivering signed packages, invoicing, and support. Our add-ons are designed so that license validation and telemetry exclude the contents of the Customer's business records; the categories we process are limited to sign-in identity (name, work email or user principal name, object and tenant identifiers), billing and purchase-order contact details, environment identifiers, and standard request logs.
Processing on instructions
We process personal data only on the Customer's documented instructions, which are constituted by the Terms of Service, this DPA, and the Customer's use of the service, unless processing is required by law. If we believe an instruction infringes applicable data-protection law, we will inform the Customer before proceeding.
Confidentiality
Persons we authorize to process personal data are bound by confidentiality obligations and receive access on a least-privilege basis, as described in our Security overview.
Security measures
We implement appropriate technical and organizational measures: encryption in transit and at rest, tenant isolation of customer data, least-privilege and role-based access, server-side secret handling, and audit logging of package downloads and administrative actions. The measures are described in more detail in the Security overview, which forms part of this DPA.
Sub-processors
The Customer authorizes the following sub-processors: Microsoft Corporation (Microsoft Azure) for hosting, identity (Microsoft Entra), storage, and infrastructure. We will update this page before adding or replacing a sub-processor; continued use of the service after an update constitutes acceptance, and a Customer with a reasonable objection may terminate affected subscriptions. Proposed mechanism, subject to confirmation by legal counsel.
Assistance with data subject requests
Taking into account the nature of the processing, we will assist the Customer with appropriate technical and organizational measures in fulfilling its obligation to respond to data subject requests (access, correction, export, deletion, restriction, objection). Requests received by us directly from a data subject will be forwarded to the Customer without undue delay.
Personal data breach notification
We will notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's personal data, and will provide information reasonably required for the Customer to meet its own notification obligations, as it becomes available.
Deletion and return
On termination of the service relationship, we will delete or return personal data at the Customer's choice, subject to the retention obligations described in the Privacy Policy (records retained to meet legal, accounting, and audit obligations are kept for the periods stated there and then deleted).
International transfers
Personal data is hosted in Microsoft Azure regions. Where processing involves a transfer out of the data subject's jurisdiction, we rely on the safeguards available for that transfer, including Microsoft's data-protection commitments for Azure services. Proposed draft: specific transfer mechanisms (for example standard contractual clauses) are subject to confirmation by legal counsel.
Audit and information
We will make available information reasonably necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits conducted by the Customer or its mandated auditor, on reasonable notice and no more than once per year absent a specific incident. Azure's own platform controls are demonstrated through Microsoft's published audit reports rather than on-premise inspection.
Governing law
This DPA is governed by the laws of the State of Michigan, USA, consistent with the Terms of Service, except where the data-protection law applicable to the Customer's personal data requires otherwise.
Contact
Questions about this DPA or our processing? Email privacy@magicite.tech.