Legal

Data Processing Agreement

These processing terms cover both Magdox products when incorporated into the customer's agreement. Complete the party, deployment and processing particulars and any required transfer annexes before covered processing begins, including a trial or proof of concept.

Last updated 9 October 2026.

1. Application and contracting parties

MAGDOX Private Limited, St No. 8, Arabinda Nagar, Barbani, Bardhaman, Hindustan Cables, West Bengal 713335, India, is the processor (Magdox). Customer is the entity identified in the accepted agreement. This DPA governs personal data processed on Customer's behalf through the ordered Code Security or FDIE Services, and prevails over conflicting commercial terms on that subject. Mandatory transfer clauses prevail where applicable. Visiting this page does not execute customer-specific transfer instruments.

A DPA is available to trial, evaluation and paid customers. Where law requires a processor agreement, it must be in force before that processing; availability does not depend on purchase value. Applicable data protection law means the law that actually governs the processing, including GDPR, UK GDPR, Swiss law or Indian law where and when applicable, rather than every law merely named here.

2. Roles and instructions

Customer acts as controller / Data Fiduciary, or as a processor authorised by its controller to appoint Magdox. Customer is responsible for lawful instructions, necessary notices, authority to supply the data and permissions for onward processing. Magdox processes only on documented instructions: the agreement, the selected product and deployment, and authorised configuration and requests.

Magdox will inform Customer if an instruction appears unlawful and may suspend that instruction while the parties resolve it. Where law requires processing beyond the instructions, Magdox will notify Customer before doing so unless prohibited. It will not sell Customer Data, use it for unrelated advertising or train models on it.

Where India's Digital Personal Data Protection Act, 2023 applies to the processing, this DPA is the contract under which Customer, as Data Fiduciary, engages Magdox as its Data Processor (section 8(2) of the Act). Magdox processes the personal data only on Customer's instructions, protects it with the measures in Annex C, tells Customer of a personal data breach under Section 8 so that Customer can meet its own notification duties, and erases it under Section 14 when the processing ends, unless the law requires its retention.

Magdox separately acts as controller for its own business, billing, security and relationship records as described in the Privacy Policy. For a local Code Security scan without upload, or a customer-operated FDIE deployment, data that never reaches Magdox is outside Magdox's custody. Any processor access through approved support or integrations remains covered; on-premises operation is not a blanket exemption.

3. Processing particulars: Annex A

Processing description
ItemCode SecurityFDIE
Subject matterUploaded findings, inventories, reports and explicitly authorised snippets; source analysis runs locallyFirmware images, configuration, recovered artifacts, analysis records, reports and release evidence in the chosen deployment
NatureReceive, validate, store, compare, retrieve, display, transmit, export and delete requested uploads; add, update or remove members as the customer's identity provider instructs through SCIMReceive, store, extract, analyse, execute supported binaries in restricted sandboxes, compare, display, export and delete authorised firmware/evidence; add, update or remove members as the customer's identity provider instructs through SCIM
PurposeSupply and secure source-security review, organisation administration and requested integrations/supportSupply and secure firmware analysis, evidence review, organisation administration and requested integrations/support
Duration / frequencyDuring trial/subscription and applicable return/deletion periods; continuous account operations and customer-requested scans/uploadsDuring trial/subscription and applicable return/deletion periods; customer-requested uploads, configured reassessments and administration
LocationIndia for hosted core data; provider exceptions and separately agreed customer-operated scopeIndia for shared core data; agreed dedicated or customer-operated location; provider exceptions

The Order Form or execution record completes the customer identity, product, organisation, deployment, duration, authorised contacts and any non-standard processing. An order does not authorise an unrelated use of the data.

4. People and data categories: Annex A continued

Data subjects and categories
PeoplePossible personal data
Customer staff and authorised contractorsName, work email, role, permissions, identity-provider identifiers and SCIM provisioning attributes, authentication/audit events including temporary sign-in locks, IP address, keyed hashes of sign-in networks and approximate location
Individuals referenced in customer contentDeveloper names, file paths, branch labels and approved code snippets; firmware metadata, configuration, strings or records containing incidental personal data
Recipients and support contactsEmail addresses, requested report recipients, support correspondence and supplied diagnostic records

Authentication factors, credentials or customer content can qualify as sensitive information under some laws. Customer should minimise it, avoid live payment-card data and agree appropriate safeguards before supplying special-category or otherwise regulated datasets. Secret-scanner upload redaction in Code Security does not establish that firmware or every other metadata field is free of sensitive data.

5. Subprocessors: Annex B

Customer gives general authorisation for applicable subprocessors in the Service Providers and Subprocessors register. The following infrastructure, application and monitoring tables are part of that register; a provider used for Magdox's independent controller activities is not thereby a subprocessor of uploaded Customer Data.

This edition describes the AWS hosting profile that Code Security and FDIE have run on since 5 October 2026. Existing signed orders and processing terms continue until validly changed. Confirm the profile for your organisation before relying on a location, retention period or recovery objective.

Hosting and delivery
ProviderProduct / purposeProcessing location
Amazon Web Services (AWS)Hosting for both products: compute, FDIE analysis, sign-in, databases, storage, backups and secrets.India (Mumbai)
Amazon Web Services (CloudFront and edge security)Content delivery, TLS and web application firewall for both products.Global edge network; edge logs kept in the USA for 14 days, then in India for 180 days
Cloudflare, Inc.DNS, bot checks on website forms, the magdox.io website, which holds a website form briefly when MAGDOX CRM cannot be reached, and the network in front of MAGDOX CRM's public address (crm.magdox.io), which carries the CRM's email links and forms and the messages the products and the website send to it. Product traffic does not pass through Cloudflare.Global network
Application and business services
ProviderProduct / purpose and roleProcessing location
Amazon Web Services (Amazon SES)Transactional, security and invitation email for both products, and email from MAGDOX CRM: confirmations, opted-in newsletters, onboarding and support replies.India (Mumbai; MAGDOX CRM's newsletters and campaigns from Hyderabad); recipients' mail systems may be elsewhere
Oracle Corporation (Oracle Cloud Infrastructure)Hosting for MAGDOX CRM: enquiries, sign-up, billing and support records. No source code or firmware.India (Mumbai)
Zoho Corporation (Zoho Mail, Zoho Forms and Zoho Books)Email for our @magdox.io addresses, including privacy, grievance, security and support correspondence; the optional feedback survey linked from the last onboarding email; and our accounting records, including invoices for customers we bill directly.India (Zoho's India data centre)
Cal.com, Inc.Scheduling meetings with prospects and customers.USA
Zoom Video Communications, Inc.Meetings with prospects and customers; recorded only with notice and consent.USA
Diagnostics, analytics and sign-in location
ProviderProduct / purposeProcessing location
Sentry (Functional Software, Inc.)Filtered error diagnostics for both products and the website, and performance diagnostics for the Code Security dashboard and FDIE. No session replay or request bodies.USA
PostHog, Inc.Optional usage analytics for the website, the Code Security dashboard and FDIE, only with consent; FDIE's events reach PostHog through FDIE's own relay, without your IP address. No recordings, form contents, source code or firmware.USA
IPinfo Inc.FDIE sign-in location for the organisation audit log; receives the IP address.USA

Dodo Payments processes the sale as an independent controller/merchant of record, not as a DPA subprocessor. Customer-selected identity, model, source-control and webhook providers are separately governed by Customer's choices and agreements. Magdox remains responsible for providers it appoints under this DPA and must impose materially equivalent applicable processor protections.

Before a new subprocessor begins covered processing, Magdox will provide at least 14 days' advance notice through the register and email to affected customers' designated contacts. Customer may object on reasonable data-protection grounds within that period at privacy@magdox.io. The parties will work on mitigation or a commercially reasonable alternative. If unresolved, Customer may terminate the affected service, with refund of prepaid unused fees for the terminated portion. Notice is not a substitute for a required transfer safeguard.

6. Confidentiality, rights and assistance

Magdox restricts personal-data access to authorised personnel bound by contractual or statutory confidentiality and provides instructions appropriate to their work. It keeps records required of it by applicable processor law.

Magdox will promptly forward a data-subject request relating to Customer's controlled data and will not independently determine the response except on Customer's instructions or as legally required. Taking account of the processing and information available, it will reasonably assist access, correction, erasure, restriction, portability, objection and other applicable rights, and Customer's DPIAs and prior consultation with authorities.

A verified request about Magdox's independent controller processing is handled under the Privacy Policy. Customer will provide timely instructions and proportionate identity verification; neither party should request passwords or MFA codes as evidence. Assistance terms may address reasonable additional work, but cannot defeat assistance required by law.

7. Technical and organisational measures: Annex C

The Information Security Addendum forms Annex C and distinguishes the two products and their deployment profiles. Measures include protected transport and storage, access control, confidentiality, tenant-scoped permissions, relevant audit records, vulnerability handling and recovery arrangements. Magdox will maintain protection appropriate to the risk and will not materially reduce its overall level during the agreed processing.

Customer-operated hosts, identity providers, firewall rules and backups remain Customer's responsibility unless the order assigns them to Magdox. Customer controls who receives exports or data sent through integrations. A description of measures is not a guarantee against every defect or evidence of a certification.

For an activated AWS deployment, Annex C includes scoped workload access, encrypted databases/storage/backups, Secrets Manager, CloudTrail/CloudWatch monitoring and the product-specific restoration procedures. The selected profile may scale automatically within limits, but autoscaling and Multi-AZ availability do not constitute cross-region disaster recovery or a contractual recovery time.

8. Personal data breach

Magdox will notify the affected Customer without undue delay after becoming aware of a personal data breach affecting its data, and in any event within 72 hours, or earlier when applicable law requires. This commitment applies to trials as well as paid use. The outer limit is not permission to postpone available notice.

Notice will contain the available nature and scope, affected categories and approximate numbers where known, likely consequences, mitigation, contact point and relevant actions. Information can be provided in phases without undue additional delay. Magdox will investigate, contain and cooperate with Customer's response, retaining appropriate incident records. Notice is not an admission of liability. Customer determines its own regulatory and data-subject notifications, subject to the law; Magdox's independent notification duties remain.

Each party will give the other the information it reasonably needs to meet its duties under the CERT-In Directions of 28 April 2022, including reporting a cyber security incident to CERT-In within six hours of noticing it.

9. Restricted transfers: Annex D

Before a restricted international transfer, the parties must identify exporter/importer roles and implement a valid mechanism. Where appropriate this can be the EU Standard Contractual Clauses in Decision 2021/914 (Module Two for controller-to-processor or Module Three for processor-to-processor), with completed annexes; the UK IDTA or UK Addendum; and necessary Swiss adaptations. Any adequacy reliance, transfer assessment and supplementary safeguards must fit the actual processing chain.

The execution record must identify parties and contacts, transfer description/frequency, categories, safeguards, applicable supervisory authority and legally permitted governing law/forum. These are not invented by this public template. A provider listing, server location, checkout acceptance or reference to SCCs alone does not complete those instruments. Mandatory transfer terms and enforceable data-subject rights prevail over inconsistent commercial caps, jurisdiction or instructions.

Selecting AWS infrastructure in India does not restrict every processing path to India. Global CDN delivery and service metadata, edge logs kept in the USA for 14 days before their India copy, Amazon SES onward delivery, FDIE's library lookups in the public OSV.dev database, support and customer-enabled providers must be included in the transfer assessment. A new location or provider is subject to the notice, instruction and safeguard requirements of this DPA before the affected processing begins.

10. Compliance information and audits

Magdox will make information reasonably necessary to demonstrate compliance available and allow audits and inspections by Customer or its mandated independent auditor as required by applicable law. Available reports, questionnaires and evidence can reduce duplication but cannot replace an audit that is legally required.

The parties will agree reasonable notice, scope, confidentiality and secure access to protect other customers and operations. Urgent incident or regulator requirements may need shorter notice. No unrelated customer data, production secrets or destructive testing is authorised. Reasonable arrangements must not obstruct a supervisory authority or a legally required inspection; identified deficiencies will be addressed appropriately.

11. California service-provider terms

Where the CCPA applies, Magdox acts as Customer's service provider or contractor for the product-specific cybersecurity purposes in Annex A. It will not sell or share covered personal information, use it beyond those purposes or the direct business relationship, or combine it with other customers' or independently collected information, except as expressly permitted by applicable CCPA rules.

Magdox will provide the required level of protection, assist Customer's consumer requests, assessments and audits, and promptly notify Customer if it can no longer comply. Customer may take reasonable steps to verify compliance and stop or remedy unauthorised processing. Applicable downstream providers must accept equivalent restrictions. Magdox acknowledges these obligations and commits to comply. These terms apply only to the covered processing; independent-controller activities remain disclosed separately.

12. Contact and execution

Complete the DPA and any annexes through privacy@magdox.io. The customer execution record identifies its legal entity, privacy contact, product(s), deployment, authorised instructions and any sensitive-data scope. Each party's authorised representative signs or accepts through the agreed contracting mechanism before covered processing begins.

13. Changes and relationship with the agreement

This DPA follows the agreed amendment process. Updating a web page does not retroactively replace an executed version. If a legal change makes a provision insufficient, the parties will work on the required amendment or a lawful alternative before continuing affected processing. The commercial agreement's liability allocation applies only to the extent lawful and consistent with mandatory transfer clauses and data-subject rights.

14. Return, deletion and retained copies

At the end of covered processing Customer chooses return or deletion of personal data, including copies, unless law requires retention. Default termination deletion does not require a separate written request. Magdox will implement a specific valid instruction within 30 business days or sooner where law or the executed DPA requires. An earlier valid deletion instruction takes priority over an export window.

Accounts and organisations are deleted on a 30-day schedule. Customer's Super Admin deletes members' accounts and can delete the whole organisation in the product; Magdox staff can also delete either at Customer's request (privacy@magdox.io), on the same schedule or, for a verified reason, at once. A scheduled deletion signs everyone affected out at once and stops their sessions, API keys and tokens; while an organisation's deletion is pending its renewal and processing pause. The data is kept for 30 days, during which the deletion can be cancelled, and is then erased. Privacy Policy Section 13.4 lists what is kept after erasure, including Code Security's risk-management records, which are kept by design: an organisation holding risk teams, asset context or verification evidence keeps its name, settings and those records, while its members' accounts are anonymised and its access, tokens and integrations are deleted as for any other organisation.

Code Security's findings and FDIE's firmware have different lifecycle schedules in the Privacy Policy. An account's deletion is not necessarily authority to erase a shared organisation's data. Restricted backups remain unavailable for ordinary processing and expire under the applicable documented lifecycle; deletion instructions must be reapplied if a backup is restored. Magdox will identify any backup copies awaiting expiry or mandatory retained data in a requested deletion confirmation.

The AWS infrastructure retention table in the Privacy Policy and Annex C distinguishes 35-day recovery points from object-version and protected audit lifecycles. Deleting a live object or account does not by itself erase prior versions, identity migration volumes or recovery copies. Restricted residual copies must be identified, protected and limited to their justified purpose; a generic backup exception does not override an earlier non-waivable erasure duty. Recovery safeguards and retention periods must be reconciled with the customer's lawful instructions before activation.

Legally retained records are limited to the required purpose, protected and deleted when the duty ends. This exception is not a general licence to retain Customer Data for speculative claims, product improvement or marketing. Customer's exported copies and its own on-premises backups remain under Customer's controls.

15. Governing provisions and survival

Indian law and the forum in the commercial agreement apply except where a signed agreement or mandatory transfer terms provide otherwise. Nothing limits non-waivable data-subject or regulatory rights. Confidentiality, security, transfer protection and deletion duties continue for personal data retained after the commercial term until processing lawfully ends.