NEW MageRa Multi-Vendor Marketplace is live — turn your Magento 2 store into a multi-seller platform with one composer require. See the extension →
MageRa
Home Extensions Services About Blog Contact
My account

Your cart

Your cart is empty

Browse the catalog and add extensions to your cart.

Browse extensions
Subtotal

Tax calculated at checkout.

View full cart Checkout
Home Data Processing Agreement
COMPLIANCE

Data Processing Agreement

This Data Processing Agreement ("DPA") forms part of the agreement between MageRa Labs, Inc. ("Processor") and the customer ("Controller") for the purchase and use of MageRa's Magento 2 extensions and related services (the "Service"). It is incorporated by reference into, and supplements, the MageRa Terms of Service and the applicable EULA. It reflects the parties' agreement with respect to the Processing of Personal Data in connection with the Service, and is intended to satisfy the requirements of GDPR Article 28 and analogous data-protection laws.

1. Definitions

TermMeaning
Controller / Processor / Sub-processor / Data Subject / Personal Data / ProcessingAs defined in GDPR Article 4.
Applicable Data-Protection LawAll laws applicable to a party's Processing, including GDPR, UK GDPR, CCPA/CPRA, PIPEDA, and LGPD.
Standard Contractual Clauses (SCCs)The clauses adopted by EU Commission Implementing Decision (EU) 2021/914.

2. Roles and Scope

Controller

The customer (or the customer's end-customer, where the customer itself acts as a Processor).

Processor

MageRa Labs, Inc.

3. Processor Obligations

  1. Process Personal Data only on documented instructions from the Controller.
  2. Ensure that persons authorized to Process Personal Data are committed to confidentiality.
  3. Implement appropriate technical and organizational measures (see Schedule B).
  4. Engage Sub-processors only in accordance with Section 4.
  5. Assist the Controller with breach notification, impact assessments, and prior consultations.
  6. Delete or return all Personal Data after the end of the provision of the Service.
  7. Make available all information necessary to demonstrate compliance and allow audits.

4. Sub-processors

The Controller hereby grants general authorization to engage Sub-processors. The current list is published at magera.ca/dpa/subprocessors and is updated at least 30 days before any new Sub-processor begins Processing. The Controller may object to a new Sub-processor within 30 days of notice by writing to dpa@magera.ca.

5. International Transfers

Where Personal Data is transferred outside the EEA, UK, or other adequate jurisdiction, the parties agree that such transfers are governed by the Standard Contractual Clauses, incorporated by reference. Where MageRa engages a Sub-processor outside an adequate jurisdiction, MageRa will enter into SCCs with that Sub-processor.

6. Security of Processing

In Transit

TLS 1.2+ encryption on all endpoints.

At Rest

AES-256 encryption for databases, storage, and backups.

Access

Least-privilege IAM; MFA for all production access; quarterly reviews.

Monitoring

Central audit logging; anomaly detection; 24/7 on-call.

7. Personal Data Breach Notification

72-hour notification window

MageRa will notify the Controller without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach. The notification will describe the nature of the breach, categories and approximate number of Data Subjects affected, likely consequences, and measures taken.

8. Data Subject Rights

MageRa will promptly notify the Controller of any request received directly from a Data Subject and will not respond except to acknowledge receipt and direct the Data Subject to the Controller, unless instructed otherwise in writing.

9. Audit Rights

The Controller may conduct an on-site audit no more than once per calendar year, on 30 days' prior written notice, at the Controller's expense. MageRa will make available summaries of its most recent third-party security assessments (SOC 2 Type II, ISO 27001, or equivalent).

10. Return or Deletion

Upon termination, MageRa will, at the Controller's choice, delete or return all Personal Data and delete existing copies, unless retention is required by law.

11–14. Liability, Precedence, Changes, Contact

  • Liability: Subject to the limitations in the Terms of Service.
  • Precedence: SCCs prevail over this DPA; this DPA prevails over the Terms for data-processing matters.
  • Changes: Material changes communicated via banner or email.

Schedule A — Details of Processing

A.1 Subject Matter and Duration

MageRa Processes Personal Data for the purpose of providing, securing, and supporting the Service for the duration of the customer's subscription plus a reasonable wind-down period not to exceed 90 days.

A.2 Nature and Purpose

  • Operating and maintaining the Service (authentication, billing, license fulfillment).
  • Customer support and responding to support requests.
  • Detecting, preventing, and addressing fraud, abuse, and security incidents.
  • Aggregating usage analytics to improve the Service.

A.3 Categories of Data Subjects

  • The Controller's employees, contractors, and end-users.
  • The Controller's end-customers (where the Controller uses the Service to operate a store).

A.4 Categories of Personal Data

  • Account data: name, email, hashed password, role.
  • Billing data: billing contact, address, tax ID, payment-method token.
  • End-customer data: name, email, address, order history, IP address.
  • Support data: content of tickets, emails, chat transcripts.
  • Technical data: IP, browser, device, pages viewed, timestamps.

Schedule B — Technical and Organizational Measures

Confidentiality

Role-based access; MFA; documented on/offboarding; background checks.

Integrity

AES-256 at rest; TLS 1.2+ in transit; database access logging; code review.

Availability

Redundant infrastructure; tested DR; incident-response plans.

Testing

Annual penetration testing; regular vulnerability scanning; timely remediation.

Sub-processors

Due diligence; written DPA terms; ongoing compliance monitoring.

Governance

Designated DPO; written policies; periodic review and update.

Contact

Data Protection Officer: dpa@magera.ca
Last updated July 25, 2026 · MageRa
MageRa

Premium Magento 2 extensions — composer-first, Hyvä-ready, full source code.

Extensions

  • All extensions
  • Services

Company

  • About
  • Contact
  • Support
  • Blog

Legal

  • Privacy policy
  • Terms of service
  • EULA / License
  • Cookie policy

Security & Compliance

  • Security
  • Data Processing Agreement
© 2026 MageRa. All rights reserved.
Magento 2 · Adobe Commerce · Hyvä