Data Processing Agreement
1. Definitions
| Term | Meaning |
|---|---|
| Controller / Processor / Sub-processor / Data Subject / Personal Data / Processing | As defined in GDPR Article 4. |
| Applicable Data-Protection Law | All laws applicable to a party's Processing, including GDPR, UK GDPR, CCPA/CPRA, PIPEDA, and LGPD. |
| Standard Contractual Clauses (SCCs) | The clauses adopted by EU Commission Implementing Decision (EU) 2021/914. |
2. Roles and Scope
Controller
The customer (or the customer's end-customer, where the customer itself acts as a Processor).
Processor
MageRa Labs, Inc.
3. Processor Obligations
- Process Personal Data only on documented instructions from the Controller.
- Ensure that persons authorized to Process Personal Data are committed to confidentiality.
- Implement appropriate technical and organizational measures (see Schedule B).
- Engage Sub-processors only in accordance with Section 4.
- Assist the Controller with breach notification, impact assessments, and prior consultations.
- Delete or return all Personal Data after the end of the provision of the Service.
- Make available all information necessary to demonstrate compliance and allow audits.
4. Sub-processors
The Controller hereby grants general authorization to engage Sub-processors. The current list is published at magera.ca/dpa/subprocessors and is updated at least 30 days before any new Sub-processor begins Processing. The Controller may object to a new Sub-processor within 30 days of notice by writing to dpa@magera.ca.
5. International Transfers
Where Personal Data is transferred outside the EEA, UK, or other adequate jurisdiction, the parties agree that such transfers are governed by the Standard Contractual Clauses, incorporated by reference. Where MageRa engages a Sub-processor outside an adequate jurisdiction, MageRa will enter into SCCs with that Sub-processor.
6. Security of Processing
TLS 1.2+ encryption on all endpoints.
AES-256 encryption for databases, storage, and backups.
Least-privilege IAM; MFA for all production access; quarterly reviews.
Central audit logging; anomaly detection; 24/7 on-call.
7. Personal Data Breach Notification
72-hour notification window
MageRa will notify the Controller without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach. The notification will describe the nature of the breach, categories and approximate number of Data Subjects affected, likely consequences, and measures taken.
8. Data Subject Rights
MageRa will promptly notify the Controller of any request received directly from a Data Subject and will not respond except to acknowledge receipt and direct the Data Subject to the Controller, unless instructed otherwise in writing.
9. Audit Rights
The Controller may conduct an on-site audit no more than once per calendar year, on 30 days' prior written notice, at the Controller's expense. MageRa will make available summaries of its most recent third-party security assessments (SOC 2 Type II, ISO 27001, or equivalent).
10. Return or Deletion
Upon termination, MageRa will, at the Controller's choice, delete or return all Personal Data and delete existing copies, unless retention is required by law.
11–14. Liability, Precedence, Changes, Contact
- Liability: Subject to the limitations in the Terms of Service.
- Precedence: SCCs prevail over this DPA; this DPA prevails over the Terms for data-processing matters.
- Changes: Material changes communicated via banner or email.
Schedule A — Details of Processing
A.1 Subject Matter and Duration
MageRa Processes Personal Data for the purpose of providing, securing, and supporting the Service for the duration of the customer's subscription plus a reasonable wind-down period not to exceed 90 days.
A.2 Nature and Purpose
- Operating and maintaining the Service (authentication, billing, license fulfillment).
- Customer support and responding to support requests.
- Detecting, preventing, and addressing fraud, abuse, and security incidents.
- Aggregating usage analytics to improve the Service.
A.3 Categories of Data Subjects
- The Controller's employees, contractors, and end-users.
- The Controller's end-customers (where the Controller uses the Service to operate a store).
A.4 Categories of Personal Data
- Account data: name, email, hashed password, role.
- Billing data: billing contact, address, tax ID, payment-method token.
- End-customer data: name, email, address, order history, IP address.
- Support data: content of tickets, emails, chat transcripts.
- Technical data: IP, browser, device, pages viewed, timestamps.
Schedule B — Technical and Organizational Measures
Role-based access; MFA; documented on/offboarding; background checks.
AES-256 at rest; TLS 1.2+ in transit; database access logging; code review.
Redundant infrastructure; tested DR; incident-response plans.
Annual penetration testing; regular vulnerability scanning; timely remediation.
Due diligence; written DPA terms; ongoing compliance monitoring.
Designated DPO; written policies; periodic review and update.