Last updated August 2026
This page summarizes the Data Processing Agreement ("DPA") that governs Magdox Private Limited's processing of personal data on behalf of customers as part of the Magdox Service, consistent with processor obligations under India's Digital Personal Data Protection Act, 2023 (DPDPA), the GDPR, and equivalent provisions of applicable data protection laws. A fully executable DPA is available to any paid-tier customer processing personal data subject to the DPDPA or a similar regime.
For personal data processed through the Service: the Customer acts as the Data Controller (or Data Fiduciary under DPDPA); Magdox acts as the Data Processor, processing personal data only on the Customer's documented instructions.
Magdox processes personal data solely for the purpose of providing the Magdox platform: competitor watch-list monitoring, digest generation, account management, and related technical support. Processing continues for the duration of the underlying subscription agreement.
Data subjects: the Customer's authorized users (employees and contractors), and, to the extent present in monitored public sources, individuals referenced therein (for example, a named executive in a news article or job posting).
Categories of personal data: names, work email addresses, roles and permissions, authentication logs, and any personal data incidentally contained within monitored public pricing pages, hiring listings, or news coverage.
Magdox is authorized to engage the following sub-processors to process personal data under this DPA, each bound by data protection obligations no less protective than those in the DPA.
| Sub-processor | Purpose | Data Region |
|---|---|---|
| Oracle Cloud Infrastructure (OCI) | Application hosting and data storage | India |
| Zoho Corporation | CRM, contact/lead management, and demo scheduling | India |
| Zoho Corporation (ZeptoMail) | Transactional email delivery | India |
| Dodo Payments | Payment processing, billing, tax calculation, and invoicing (Merchant of Record) | United States |
| WorkOS | Authentication and user management | United States |
| Sentry (Functional Software, Inc.) | Error tracking and application performance monitoring | United States |
| Mixpanel | Product and website analytics (consent-gated) | United States |
| Customer.io | Marketing automation and lifecycle messaging (consent-gated) | United States |
Before engaging a new sub-processor to process personal data under this DPA, Magdox will provide at least 14 days' advance notice by posting an update to this list and, for customers with a signed DPA on file, by direct email. Customer may object on reasonable data protection grounds within that notice period by contacting [email protected]; Magdox will work with Customer in good faith to address the objection, which may include providing a commercially reasonable alternative.
Magdox will provide reasonable assistance to the Customer in responding to data principal requests (access, correction, erasure, and others) relating to personal data processed under the DPA. See our DPDPA Rights page for the general process. Magdox will also provide reasonable assistance to Customer in conducting Data Protection Impact Assessments and prior consultations with supervisory authorities where required by applicable law.
Magdox implements the technical and organizational security measures described in our Privacy Policy and Security page, including encryption in transit and at rest, access controls, and audit logging.
In the event of a personal data breach affecting Customer data, Magdox will notify the affected Customer without undue delay, and in any case within 72 hours of becoming aware of the breach, providing available details to support the Customer's own notification obligations.
Where personal data is transferred across borders, Magdox complies with applicable cross-border data transfer requirements under the DPDPA, the GDPR, and other applicable law, including Standard Contractual Clauses where required.
Customers with a signed DPA may request reasonable audits of Magdox's compliance with the DPA, subject to confidentiality obligations and reasonable notice. Audits may be satisfied, at Magdox's option, by providing a recent third-party audit report or security questionnaire response covering the relevant period.
Upon termination of the subscription and written request from the Customer, Magdox will delete or return all personal data processed under this DPA within 30 business days, unless required by applicable law to retain it. A written certificate of deletion is available on request.
Any paid-tier customer can request a fully executed DPA from our team via our Contact section.
This DPA is governed by and construed in accordance with the laws of India, including the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023. Any disputes arising under this DPA will be resolved in the competent courts of West Bengal, India.