Privacy Policy

Last updated August 2026

This Privacy Policy explains how Magdox Private Limited ("Magdox," "we," "us," or "our") collects, uses, discloses, and protects personal data in connection with the Magdox marketing website, the Magdox competitive-intelligence web application, and related services (together, the "Service"). This Policy constitutes an electronic record under the Information Technology Act, 2000, and is published in accordance with Rule 3(1)(a) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021. This Policy applies to visitors to our website, prospective and current customers, and authorized users of the Magdox platform acting on behalf of a customer organization.

If you do not agree with this Policy, please do not use the Service. The Service is intended for users who are at least 18 years old; see Section 15.

1. Our Roles: Controller vs. Processor

Magdox acts in different roles depending on the data involved:

As Controller: for account data (Section 2), marketing-site usage data, billing data, and other data we collect about our own customers and website visitors to operate our business, Magdox determines the purposes and means of processing and acts as the Data Controller.

As Processor: for the competitor names, keywords, and watch-list configuration a customer enters into Magdox, and the resulting signals the Service collects from public sources on that customer's behalf, Magdox acts solely as a Data Processor on that customer's instructions. This processing is additionally governed by our DPA, available to any paid-tier customer processing personal data subject to the DPDPA, GDPR, or a similar regime.

2. What Personal Data We Collect

Account data: name, work email, company name, and role, collected when you sign up or are added to a workspace.

Usage data. We automatically collect technical information when you use our website or platform, including IP address, browser type, device information, and analytics events (pages viewed, features used, timestamps).

Billing data. We do not directly collect or store your full payment card number, CVV, or bank account credentials. Payment processing is handled by Dodo Payments, which acts as the Merchant of Record for all paid transactions. Dodo Payments collects payment details, calculates and remits applicable taxes, and issues invoices on behalf of your purchase. Magdox stores only the subscription status, plan tier, and billing period dates received from Dodo Payments via webhook, for account and subscription management.

Watch-list content you configure. The competitor names, keywords, and signal preferences you configure in your watch list, and the resulting data monitored from public competitor pricing pages, public hiring-platform listings, and public news or funding feeds. This is not personal data of the website visitors or individuals it may incidentally reference (for example, a named executive in a news article), and is handled under the confidentiality commitments in our Terms of Service and DPA.

Documents you upload. If you upload pitch decks, PDFs, or other documents for AI-assisted extraction into battlecards, that content is processed solely to provide that feature to your organization and is not used to train any model.

Inquiries and demo requests. If you contact us, request a demo, or submit feedback through a form on our website or within the Service, we collect the name, email, phone number, company name, and message content you provide, so we can respond to you. This data is processed by Zoho Corporation (CRM and forms) on our behalf; see Section 8.

3. How We Use Your Data

We use personal data to: provide, operate, and authenticate access to the Service; process your configured watch lists and generate digests; process billing and manage subscriptions; provide customer support and respond to inquiries; send transactional communications such as digests, password resets, and billing notices; improve the Service through aggregated, de-identified analytics; protect the Service, including fraud monitoring and prevention; and, with your consent, send product updates and marketing communications, with an opt-out available in every email.

4. Why We Process Your Data

We process personal data on the following grounds: Contract, to provide the Service under our Terms of Service; Consent, for optional marketing communications and non-essential cookies, which you can withdraw at any time (Section 13); Legitimate business purposes, for security monitoring, fraud prevention, and improving the Service, balanced against your rights and interests; and Legal obligations, where necessary to comply with applicable law.

5. Cookies and Tracking

We use cookies, browser LocalStorage, and session tokens for essential site functionality. Beyond strictly necessary cookies, we use Mixpanel (product and website analytics) and Customer.io (lifecycle and marketing messaging) - both are consent-gated: they only load after you accept analytics cookies through our consent banner, and stay off by default. The Zoho Bookings scheduling widget embedded on our Demo page may set its own third-party cookie. Our Contact page submits directly to Zoho's Web-to-Lead form endpoint via a standard browser form submission. We do not permit any cookie on this site to be used for advertising or cross-site ad tracking. See our Cookie Policy for the full breakdown.

Do Not Track. No uniform technical standard for Do Not Track ("DNT") browser signals currently exists, so we do not currently respond to DNT signals.

6. Sharing and Sub-processors

We share personal data with a limited set of service providers who help us operate the Service, each bound by appropriate confidentiality and data protection terms: payment processing, cloud hosting, authentication, email delivery, CRM and scheduling, analytics and lifecycle messaging, and error monitoring. The current list of sub-processors, their purpose, and processing region, along with our change-notice and objection process, is maintained in our Data Processing Agreement rather than duplicated here.

We do not sell personal data, and we do not share personal data for cross-context behavioral advertising.

Notice of new sub-processors. Before engaging a new sub-processor that will process personal data on behalf of paid-tier customers, we will provide at least 14 days' advance notice by posting an update to our DPA and, for customers with a signed DPA on file, by email. If you reasonably object on data protection grounds, contact [email protected] within that notice period and we will work with you in good faith to address the objection.

Business transfers. If Magdox is involved in a merger, acquisition, financing, or sale of all or substantially all of its assets, personal data may be transferred as part of that transaction. We will notify you before your personal data becomes subject to a different privacy policy as a result.

7. International Data Transfers

Our servers are located in India. Where personal data is transferred outside the jurisdiction in which it was collected, including to service providers located in the United States, India, and other countries, we comply with applicable cross-border data transfer requirements under the DPDPA, the GDPR, and other applicable law, including Standard Contractual Clauses where required. Our Data Processing Agreement is available at /legal/dpa.

8. Data Retention

Account data is retained for the duration of your contract with us, plus 90 days thereafter for legal and accounting purposes. Monitored signal data and generated digests are retained according to the retention period configured in Settings → Organization; where none is configured, we retain them for the duration of the active subscription plus 90 days. A scheduled job enforces these windows automatically and permanently deletes data that falls outside them. Watch-list configuration (the competitors you choose to track) is retained until you delete it or close your account, so that removing a competitor from active tracking does not destroy your historical record. Technical and usage log data is retained on a rolling 1-year basis. You may request deletion of your data at any time as described in Section 11.

9. Data Security Measures

We implement technical and organizational measures designed to protect personal data, including encryption in transit and at rest, role-based access controls, and audit logging. See our Security page for a detailed, plain-language description.

10. Breach Notification

In the event of a personal data breach affecting your data, we will notify affected individuals or customers without undue delay, and in any case within 72 hours of becoming aware of the breach, providing the information reasonably available to us at that time.

11. Your Rights (Global)

Depending on your location, you may have rights over the personal data we hold about you, commonly including the right to access, correct, delete, restrict or object to processing, receive your data in a portable format, and withdraw consent.

India (DPDPA). See our dedicated DPDPA Rights page for your rights as a Data Principal under India's Digital Personal Data Protection Act, 2023, including how to escalate a grievance to our Grievance Officer and the Data Protection Board of India.

European Economic Area, UK, and Switzerland (GDPR). If you are located in the EEA, the UK, or Switzerland, applicable GDPR law gives you the right to access, correct, delete, restrict, or object to how we process your data, and to receive a portable copy. Where we rely on your consent, you can withdraw it at any time. To exercise any of these rights, contact [email protected]. You also have the right to complain to your Member State's data protection authority, the UK's Information Commissioner's Office, or the Swiss Federal Data Protection and Information Commissioner.

United States. If you are a resident of a US state with a comprehensive privacy law, you may have the right to know whether we process your personal data and access it, correct inaccuracies, request deletion, obtain a copy of data you provided, and non-discrimination for exercising these rights. You also have the right to opt out of targeted advertising, sale of personal data, or profiling used for legally significant decisions - Magdox does not engage in any of these three practices today. We do not process sensitive personal information and have not sold or shared any personal information in the preceding 12 months. To exercise a right or appeal a decision, contact [email protected].

To submit a request under any regime above, contact [email protected] or use our Contact section, including your name, the email associated with your account (if any), and a description of the right you wish to exercise.

12. AI-Generated Content

Digest summaries, battlecards, and insights are generated using an AI provider of your organization's own choosing (bring-your-own-key: OpenAI, Anthropic, Gemini, Azure OpenAI, DeepSeek, Kimi, Qwen, or any compatible custom endpoint). Your content is sent to that provider solely to generate the requested output for your organization and is never used by Magdox or any AI provider to train a model on our behalf. AI-generated output is decision-support information for your team, not a substitute for professional judgment.

13. Children's Privacy

The Service is not directed at, and is not intended for use by, individuals under the age of 18. We do not knowingly collect personal data from anyone under 18. If we learn that we have collected personal data from someone under 18, we will take reasonable steps to delete it and deactivate the associated account.

14. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via the website or by email to registered account holders. The "Last updated" date at the top of this page reflects the most recent revision.

15. Contact

Questions about this Privacy Policy can be sent to [email protected] or by post to:

Magdox Private Limited
St No. 8, Arabinda Nagar, Barbani, Bardhaman, Hindustan Cables, West Bengal 713335, India