Data Processing Agreement
Last updated: July 15, 2026
1. Purpose
This page summarizes the Data Processing Agreement (“DPA”) that governs Magdox Private Limited’s processing of personal data on behalf of customers as part of the FDIE Service, consistent with the processor obligations under India’s Digital Personal Data Protection Act, 2023 (DPDPA) and equivalent provisions of other applicable data protection laws. A fully executable DPA is available to any paid-tier customer processing personal data subject to the DPDPA or a similar regime, not only Enterprise customers.
2. Roles
For personal data processed through the Service:
- Customer acts as the Data Controller
- Magdox acts as the Data Processor, processing personal data only on the Customer’s documented instructions
3. Subject Matter, Duration, Nature and Purpose of Processing
Magdox processes personal data solely for the purpose of providing the FDIE platform: firmware security analysis, compliance reporting, account management, and related support. Processing continues for the duration of the underlying subscription agreement.
4. Categories of Data Subjects and Personal Data
- Data subjects: the Customer’s authorized users (employees and contractors), and to the extent present in uploaded firmware metadata, individuals referenced therein (for example, developer names or email addresses embedded in build artifacts)
- Categories of personal data: names, work email addresses, roles and permissions, authentication logs, and any personal data incidentally contained within uploaded firmware images or configuration files
5. Sub-processor Authorization and Change Notice
Magdox is authorized to engage the following sub-processors to process personal data under this DPA, each bound by data protection obligations no less protective than those in the DPA:
Infrastructure
| Vendor | Purpose | Location |
|---|---|---|
| Oracle Cloud Infrastructure (Oracle Corporation) | Application hosting and data storage | IN, US, and EU - customer-selected at signup |
Application Services
| Vendor | Purpose | Location |
|---|---|---|
| Zoho Corporation | CRM (contact/lead management), support ticketing, and email marketing/newsletter | India |
| Zoho Corporation (ZeptoMail) | Transactional email delivery (account/system notifications) | India |
| Dodo Payments | Billing and subscription payment processing | India |
| Cal.com, Inc. | Demo scheduling/booking | USA |
| Zoom Video Communications, Inc. | Demo calls and sales meetings | USA |
Monitoring
| Vendor | Purpose | Location |
|---|---|---|
| Sentry (Functional Software, Inc.) | Error tracking and application performance monitoring | USA |
Before engaging a new sub-processor to process personal data under this DPA, Magdox will provide at least 10 days’ advance notice by posting an update to this list and, for customers with a signed DPA on file, by direct email. Customer may object on reasonable data protection grounds within that notice period by contacting privacy@magdox.io; Magdox will work with Customer in good faith to address the objection, which may include providing a commercially reasonable alternative.
6. Data Subject Rights Assistance
Magdox will provide reasonable assistance to the Customer in responding to data principal requests (access, correction, erasure, and others) relating to personal data processed under the DPA. See our DPDPA rights page for the general process.
7. Security Measures
Magdox implements the technical and organizational security measures described in Privacy Policy Section 11 and on our Security and Trust page, including encryption in transit and at rest, access controls, and audit logging.
8. Breach Notification
In the event of a personal data breach affecting Customer Data, Magdox will notify the affected Customer without undue delay, and in any case within 72 hours of becoming aware of the breach, providing available details to support the Customer’s own notification obligations. This is the same 72-hour commitment stated in our Privacy Policy Section 12, which applies to all customers regardless of whether a signed DPA is in place; this DPA sets out the process for Customer Data specifically.
9. International Transfers
Where personal data is transferred across borders, Magdox complies with applicable cross-border data transfer requirements under the DPDPA, the GDPR, and other applicable law. Where required, Magdox puts appropriate contractual safeguards in place, including Standard Contractual Clauses for transfers of personal data out of the European Economic Area, the United Kingdom, or Switzerland.
10. Audit Rights
Customers with a signed DPA may request reasonable audits of Magdox’s compliance with the DPA, subject to confidentiality obligations and reasonable notice, as set out in the full executable DPA. Audits may be satisfied, at Magdox’s option, by providing a recent third-party audit report or security questionnaire response covering the relevant period, where available.
11. Request a Signed DPA
Any paid-tier customer can request a fully executed DPA from our team.
12. Full Agreement
A full executable DPA is available upon request.