Legal

Data Processing Agreement (DPA)

Version 1.0 - Effective 24 May 2026 - Magneety EU Ltd.

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Magneety EU Ltd ("Processor", "Magneety") and the Customer ("Controller") whose Magneety account is in use. It applies whenever Magneety processes Personal Data on the Customer's behalf in connection with the Magneety platform.

Where the Customer is established in the EU/EEA, UK, or Switzerland, this DPA gives effect to Article 28 GDPR / UK GDPR / Swiss FADP requirements. By using Magneety, the Customer accepts this DPA. A counter-signed PDF version is available on request to info@magneety.com.

1. Definitions

Capitalised terms have the meanings given in the GDPR. "Personal Data" means any information relating to an identified or identifiable natural person. "Data Subject" means the individual to whom the Personal Data relates. "Sub-processor" means any third party engaged by Magneety to process Personal Data on behalf of the Customer.

2. Subject matter, duration, nature, purpose

Subject matterProcessing of Personal Data as necessary for Magneety to deliver the Service per the Terms of Service.
DurationFor the term of the Customer's Magneety subscription, plus the legally-required retention period after termination.
Nature & purposeMarketing automation, social content management, paid ad campaign management, unified inbox, analytics, AI-generated content.
Categories of Data SubjectsCustomer's authorised users; Customer's end customers (where data flows from connected platforms like Shopify / Meta).
Categories of Personal DataUser account data (name, email, hashed password); Connected-account OAuth tokens (encrypted at rest); Inbox messages (DMs/comments); Order metadata (no individual customer PII in default config); IP / log data.

3. Processor obligations

Magneety shall:

  1. Process Personal Data only on documented instructions from the Customer, which for the purposes of GDPR Art. 28(3)(a) are those set out in the Terms of Service, this DPA, and any in-product configuration the Customer chooses.
  2. Ensure that persons authorised to process Personal Data have committed themselves to confidentiality.
  3. Implement appropriate technical and organisational measures (see Annex 1) to ensure a level of security appropriate to the risk.
  4. Assist the Customer in fulfilling their obligation to respond to requests for exercising Data Subject rights (see clause 5).
  5. Notify the Customer without undue delay (within 72 hours) after becoming aware of a Personal Data breach.
  6. At the choice of the Customer, delete or return all Personal Data after the end of the provision of services, and delete existing copies unless EU/Member State law requires storage.
  7. Make available to the Customer all information necessary to demonstrate compliance with Article 28 GDPR.

4. Sub-processors

The Customer grants general authorisation to Magneety to engage sub-processors. The current list is published at magneety.com/privacy (Section 8 - Sub-processors) and includes: Neon (database), Cloudflare R2 (file storage), Anthropic (AI), Replicate (image generation), Resend (transactional email), Stripe (payments), Sentry (error monitoring). Magneety will notify the Customer of any intended changes concerning the addition or replacement of sub-processors at least 30 days in advance via email + website notice, thereby giving the Customer the opportunity to object.

5. Data Subject rights

Magneety shall, insofar as possible, assist the Customer by appropriate technical and organisational measures, taking into account the nature of the processing, for the fulfilment of the Customer's obligation to respond to Data Subject requests under Articles 15-22 GDPR. Self-service tooling is provided in the Customer's account (export, deletion). Custom requests should be sent to info@magneety.com and will be actioned within 30 days.

6. International transfers

Magneety is established in Bulgaria (EU). Personal Data is primarily processed within the EU/EEA. Where transfers to third countries (e.g. United States, for Anthropic, Replicate, Resend, Sentry, Stripe) occur, Magneety relies on EU Standard Contractual Clauses (SCCs) and/or the EU-US Data Privacy Framework where applicable.

7. Audits

Magneety shall make available to the Customer all information necessary to demonstrate compliance with this DPA, and allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer. Audits shall be performed at the Customer's expense, scheduled with at least 30 days notice, conducted during normal business hours, and shall not unreasonably interfere with the Service or compromise other customers' confidentiality.

8. Liability

Each party's liability is governed by the Magneety Terms of Service. Nothing in this DPA reduces either party's obligations or rights under applicable data protection law.

9. Term and termination

This DPA is effective from the date the Customer first uses the Service and continues for as long as Magneety processes Personal Data on the Customer's behalf. Upon termination, Magneety shall delete or return all Personal Data within 90 days, subject to legal retention requirements (e.g. invoices, tax records).

Annex 1 - Technical and organisational measures

To request a counter-signed PDF version of this DPA, email info@magneety.com with your company legal name, registration number, and the name + title of the signatory.