GDPR
How Magemcy handles personal data under the EU and UK General Data Protection Regulation, and what we can give you if you are assessing us as a supplier.
On this page 10 sections
Our position
We are a United States company. GDPR applies to us where we offer services to people in the EEA or the UK, and we work to meet it for everyone rather than maintaining two standards.
The practical consequence: the rights described here are available to any Magemcy user who asks, wherever they are.
When we are the controller, and when the processor
| Data | Our role | Who decides |
|---|---|---|
| Your account, billing, support and website enquiries | Controller | Us |
| A customer's vendor registry, tenders, orders and invoices | Processor | The customer |
| Assistant conversations on this website | Controller | Us |
| Assistant conversations inside a customer's workspace | Processor | The customer |
Where we are the processor, we act only on the customer’s documented instructions. Those instructions and the Article 28 terms are in our Data Processing Addendum, which forms part of the agreement automatically, you do not need to negotiate or sign a separate copy.
Lawful bases
We rely on performance of a contract for the service itself, legitimate interests for security, abuse prevention and answering enquiries, consent for anything optional, and legal obligation where the law requires. The article-by-article table is in our Privacy Notice.
We do not carry out automated decision-making with legal or similarly significant effects. AI evaluation scores bids for a human to review; no award, order or payment happens without a person deciding.
Data subject rights
| Right | Article | How to use it |
|---|---|---|
| Access | 15 | Export from Settings, or ask us |
| Rectification | 16 | Edit in the app, or ask us |
| Erasure | 17 | Delete your account in Settings, or ask us |
| Restriction | 18 | Ask us |
| Portability | 20 | Export from Settings, machine-readable JSON and CSV |
| Object | 21 | Ask us; we stop unless we have compelling grounds |
| Withdraw consent | 7(3) | Cookie settings, or ask us |
| Complain | 77 | Your supervisory authority, we would rather you asked us first |
Requests go through Your Privacy Choices or our privacy contact. We respond within one month, extendable by two further months for complex requests, and we will tell you if we extend.
If your data is in a customer’s workspace, they are the controller. Send the request to them; if you send it to us, we will forward it and help them answer.
International transfers
Data is processed in the United States. For transfers from the EEA, the UK or Switzerland we rely on the European Commission’s Standard Contractual Clauses (Decision 2021/914) with the UK International Data Transfer Addendum where relevant, together with the technical measures on our security page: encryption in transit and at rest, tenant isolation enforced server-side, and access limited to what an operator needs.
Subprocessors
The current list, with what each one handles and where, is on subprocessors. Each is engaged under Article 28 terms. We give notice before adding a new one, and customers may object.
Security measures (Article 32)
- Encryption in transit (TLS) and at rest.
- Tenant isolation enforced by server-side rules, not by the interface, the boundary holds even if a client is compromised.
- Role-based access within a workspace, and least privilege for platform operators.
- An audit record for every privileged platform action.
- Payment data handled entirely by our payment processor; card details never reach us.
- Single-use, expiring, approver-bound tokens for email approvals.
- Automated retention limits on operational data.
Detail, and how to report a vulnerability, is on security.
Breach notification
Where we are the controller and a breach is likely to result in a risk to your rights, we notify the relevant supervisory authority within 72 hours of becoming aware, and notify you without undue delay where the risk is high. Where we are the processor, we notify the affected customer without undue delay so they can meet their own obligations.
DPO and representatives
Our processing does not meet the Article 37 thresholds that require a Data Protection Officer, so we have not appointed one. Privacy questions go to our privacy contact, which is monitored by the people who can actually act on them.
We have not appointed an Article 27 representative in the EU or the UK. Rather than imply otherwise, we say so plainly: if you are in either and want to raise something, write to us directly and we will answer.
If you are reviewing us as a supplier
Everything a standard vendor assessment asks for is published:
- Data Processing Addendum: Article 28 terms, already in force.
- Subprocessors: who, what and where.
- Security: technical and organisational measures.
- Business continuity: resilience and recovery.
- AI disclosure: what is sent where, and what is not.
If your review needs something not covered here, ask us rather than assuming the answer.
GDPR has no certification scheme that a company can simply hold, so nobody can honestly say they are 'GDPR certified', including us. What follows is what we actually do.
Questions about this policy?
A person reads every message. Get in touch and we’ll answer. Or ask Gero, our AI assistant, to walk you through what this page says - his answers explain, they don’t bind.