Legal

DPDPA Notice

Your rights under India's Digital Personal Data Protection Act, 2023 (DPDPA) as a user of MAGDOX Code Security or FDIE, or a visitor to this website, and how to exercise them. It supplements the Privacy Policy.

Last updated 9 October 2026.

1. Our commitment

MAGDOX Private Limited provides this notice for this website, MAGDOX Code Security and FDIE, including their hosted services and customer support for licensed installations. The DPDPA and its rules have a phased commencement. Under the November 2025 notifications, the principal processing obligations and individual rights take effect eighteen months after publication, in May 2027; specified provisions, including section 6(9), follow a separate one-year timetable. As of 9 October 2026, this page must not be read as saying the substantive duties or rights scheduled for later commencement are already in force. We accept privacy requests now under the commitments below and any law already applicable.

Sources: the Ministry of Electronics and Information Technology's commencement notification G.S.R. 843(E) and the notified Digital Personal Data Protection Rules, 2025, both published on meity.gov.in. Later effective amendments govern if the timetable changes.

2. Key terms under the DPDPA

  • Data Fiduciary: the party determining the purpose and means of processing. MAGDOX has this role for its own account and business processing; a customer may have it for personal data in its uploaded findings, firmware, configuration, reports or support material, with MAGDOX acting as processor.
  • Data Principal: the individual to whom the personal data relates (you).
  • Personal data: any data about an individual who is identifiable by or in relation to such data.

3. Your rights as a Data Principal

When the relevant provisions apply and are in force, they provide the following rights, subject to their statutory conditions. You may contact us about these requests now:

  • Access information: obtain a summary of the personal data we hold about you and the processing carried out on it
  • Correction and erasure: ask us to correct inaccurate or incomplete personal data, update it, or erase data no longer necessary for the purpose it was collected, subject to legal retention requirements
  • Grievance redressal: have a readily available means to register a complaint about how we process your personal data
  • Nominate: nominate another individual to exercise these rights on your behalf in the event of your death or incapacity
  • Withdraw consent: withdraw consent at any time where processing is based on consent, as easily as it was given. To stop optional scan or digest emails, change your notification settings in the dashboard or contact privacy@magdox.io; withdrawal does not affect the lawfulness of processing carried out before it

Where MAGDOX processes your data inside a customer's Code Security uploads or FDIE firmware, reports and evidence, we route your request to that customer and assist it. For an on-premises installation, the customer controls the local data; we can assist with information that is actually available to us and any separately shared support material.

4. How to exercise your rights

To submit a request, contact privacy@magdox.io or use our Contact page with "Data Principal Request" as the subject. Include:

  • Your name and the email address associated with your account (if any)
  • A description of the right you wish to exercise
  • Any information that helps us verify your identity

To have a Code Security or FDIE account deleted, ask your organisation's Super Admin. The Super Admin can also delete the whole organisation in the product, or write to privacy@magdox.io. Privacy Policy Section 13.4 describes the 30-day deletion schedule and what is kept after erasure.

5. Grievance Officer and escalation to the Data Protection Board

If you are not satisfied with our response to your request, contact our designated grievance contact below. A statutory complaint to the Data Protection Board depends on the relevant provisions being in force, the Board's applicable procedure and exhaustion of the available grievance process. This page does not promise an already-operative complaint route for provisions that have not commenced.

  • Grievance Officer: Manish Sharma
  • Designation: Founder and CEO
  • Email: grievance@magdox.io
  • Acknowledgement: within 24 hours of receipt
  • Resolution: within 15 days of receipt

Personal data breaches. If a personal data breach affects your personal data, we will notify you and the Data Protection Board of India when those obligations apply, in the form and within the time required by the provisions then in force. Independently of that, we notify affected individuals within 72 hours of becoming aware of a breach (Privacy Policy, Section 12).

6. Response timeframe

We aim to respond to a request within 30 days of receipt, with proportionate identity verification where necessary. Any longer period must be permitted by applicable law; we explain the reason and revised timing. Grievances follow the shorter times in Section 5. Do not send passwords or authentication codes with a request.

7. Related pages

  • Privacy Policy: full details on data collection and use
  • Cookie Policy: cookies and browser storage
  • Data Processing Agreement: available before covered processing begins, including evaluations