Privacy Policy
Last updated: July 15, 2026
1. Introduction and Scope
This Privacy Policy explains how Magdox Private Limited (“Magdox,” “we,” “us,” or “our”) collects, uses, discloses, and protects personal data in connection with the FDIE (Firmware Delta Intelligence Engine) marketing website, the FDIE web application, and related services (together, the “Service”). This Policy applies to visitors to our website, prospective and current customers, and authorized users of the FDIE platform acting on behalf of a customer organization.
If you do not agree with this Policy, please do not use the Service. The Service is intended for users who are at least 18 years old; see Section 15.
2. Our Roles: Controller vs. Processor
Magdox acts in different roles depending on the data involved:
- As Controller: for account data (Section 4), marketing-site usage data, billing data, and other data we collect about our own customers and website visitors to operate our business, Magdox determines the purposes and means of processing and acts as the Data Controller.
- As Processor: for Customer Data (firmware images, configuration files, and any personal data incidentally contained within them) uploaded by a customer for analysis, Magdox acts solely as a Data Processor on that customer’s instructions. Our processing of Customer Data on a customer’s behalf is additionally governed by our DPA, which is available to any paid-tier customer processing personal data subject to the DPDPA or similar laws, not only Enterprise customers.
3. Data Controller Identity
- Entity: Magdox Private Limited
- Registered address: St No. 8, Arabinda Nagar, Barbani, Bardhaman, Hindustan Cables, West Bengal 713335, India
- Privacy contact: privacy@magdox.io
- Phone: +91 82175 75982
4. What Personal Data We Collect
Account data. When you sign up for FDIE or contact us, we collect information such as your name, work email address, company name, job title, and billing address.
Usage data. We automatically collect technical information when you use our website or platform, including IP address, browser type, device information, and analytics events (pages viewed, features used, timestamps).
Payment data. We do not directly collect or store your card number or card security code. Payment card details are collected and stored directly by our payment processor, Dodo Payments, through their own hosted checkout - we receive only confirmation that a payment succeeded or failed, along with your billing address and the last few digits of your card for your own reference on invoices. See Dodo Payments’ Privacy Policy for how they handle payment data.
Firmware and content data. Customers upload firmware images, configuration files, and related artifacts to the FDIE platform for analysis. This data is “Customer Data”: it belongs to the customer, is not personal data of website visitors, and is handled under the confidentiality commitments described in our Terms of Service and DPA. Where Customer Data incidentally contains personal data (for example, developer names embedded in firmware metadata), it is processed solely to provide the Service.
5. How We Use Your Data
We use personal data to:
- Provide, operate, and maintain the Service, including account creation, authentication, and account management
- Process billing and manage subscriptions, including orders, renewals, and payments
- Provide customer support and respond to inquiries
- Send administrative information, such as changes to our terms and policies
- Request feedback about your use of the Service
- Improve and develop new features, and identify usage trends
- Protect the Service, including fraud monitoring and prevention
- Send product updates, security advisories, and marketing communications (with an opt-out available in every email)
6. Why We Process Your Data
We process personal data on the following grounds:
- Contract: to provide the Service under our Terms of Service, including account management, order fulfillment, and responding to your inquiries
- Consent: for optional marketing communications and non-essential cookies. You can withdraw consent at any time - see Section 13
- Legitimate business purposes: for security monitoring and fraud prevention, identifying usage trends to improve the Service, and requesting feedback, each balanced against your rights and interests
- Legal obligations: where necessary to comply with applicable law, cooperate with a regulatory or law enforcement request, or exercise or defend our legal rights
7. Cookies and Tracking
We use cookies and similar technologies for essential site functionality. Our website sets strictly necessary cookies (session management and CSRF protection) and one functional cookie (your consent preference). The Cal.com scheduling widget embedded on our site sets its own third-party cookie, disclosed in our Cookie Policy. Our Contact page and newsletter signup submit directly to Zoho’s Web-to-Lead form endpoint without loading any script or setting any cookie. We do not set analytics or marketing cookies, and we do not permit third parties to use our Service for advertising or cross-site ad tracking of any kind. See our Cookie Policy for a full breakdown of cookie categories, the specific cookies in use, and how to manage your preferences.
Do Not Track. No uniform technical standard for Do Not Track (“DNT”) browser signals currently exists. Because there is no industry or legal consensus on how to interpret DNT, we do not currently respond to DNT signals. If a standard is adopted that we are required to follow, we will update this Policy accordingly.
8. Sharing and Sub-processors
We share personal data with a limited set of service providers who help us operate the Service, each bound by appropriate confidentiality and data protection terms. The categories of service providers we share personal data with include: payment processors, cloud computing and website hosting providers, user account authentication services, communication and email delivery tools, sales and marketing tools, performance monitoring tools, data storage providers, product engineering and issue-tracking tools, and, where legally required, government or regulatory authorities. The current list of sub-processor categories, their purpose, and processing region, along with our change-notice and objection process, is maintained in one place, our Data Processing Agreement, rather than duplicated here.
We do not sell personal data, and we do not share personal data for cross-context behavioral advertising.
Notice of new sub-processors. Before engaging a new sub-processor that will process personal data on behalf of paid-tier customers, we will provide at least 10 days’ advance notice by posting an update to this page and, for Enterprise customers, by email to the billing or technical contact on file. If you reasonably object to a new sub-processor on data protection grounds, contact privacy@magdox.io within that notice period and we will work with you in good faith to address the objection, which may include making a commercially reasonable alternative available.
Business transfers. If Magdox is involved in a merger, acquisition, financing, or sale of all or substantially all of its assets, personal data may be transferred as part of that transaction. We will notify you before your personal data becomes subject to a different privacy policy as a result.
9. International Data Transfers
Our servers are located in India. Where personal data is transferred outside of the jurisdiction in which it was collected, including to our service providers located in the United States, India, Australia, and other countries, we comply with applicable cross-border data transfer requirements under the DPDPA, the GDPR, and other applicable law. Where required, we put appropriate contractual safeguards in place with our service providers, including the European Commission’s Standard Contractual Clauses for transfers of personal data out of the European Economic Area, the United Kingdom, or Switzerland. Our Data Processing Agreement, which includes these Standard Contractual Clauses, is available at /legal/dpa/.
10. Data Retention
- Account data is retained for the duration of your contract with us, plus 90 days thereafter for legal and accounting purposes.
- Uploaded firmware images and analysis results are retained according to the retention policy configured by your organization’s administrators within FDIE. Where no custom retention period is configured, we retain this data for the duration of the active subscription plus 90 days, after which it is deleted unless a longer period is required by law.
- Technical and usage log data (Section 4) is retained on a rolling 1-year basis, independent of how long your account remains active, since indefinite retention of raw technical logs serves no purpose beyond that window.
- You may request deletion of your data at any time as described in Section 13.
11. Data Security Measures
We implement technical and organizational measures designed to protect personal data. See our Security and Trust page for a detailed, plain-language description of our encryption, access-control, and audit logging practices.
12. Breach Notification
In the event of a personal data breach affecting your data, we will notify affected individuals or customers without undue delay, and in any case within 72 hours of becoming aware of the breach, providing the information reasonably available to us at that time. This commitment applies to all customers and website visitors, not only those with an Enterprise DPA in place; Enterprise customers’ DPA contains additional detail on the process for Customer Data specifically.
13. Your Rights (Global)
Depending on your location, you may have rights over the personal data we hold about you, which commonly include the right to access, correct, delete, restrict or object to processing, receive your data in a portable format, and withdraw consent. The regional sections below identify the specific regime that applies to you; where more than one could apply, contact us and we will apply the more protective standard.
13.1 India (DPDPA)
See our dedicated DPDPA rights page for your rights as a Data Principal under India’s Digital Personal Data Protection Act, 2023, including how to escalate a grievance to our Grievance Officer and the Data Protection Board of India.
13.2 United States
If you are a resident of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, or Virginia, you may have rights under that state’s comprehensive privacy law, which commonly include:
- The right to know whether we are processing your personal data, and to access it
- The right to correct inaccuracies in your personal data
- The right to request deletion of your personal data
- The right to obtain a copy of the personal data you previously provided to us
- The right to non-discrimination for exercising any of these rights
- The right to opt out of targeted advertising, the sale of personal data, or profiling used for decisions with legal or similarly significant effects - Magdox does not engage in any of these three practices today, so there is nothing to opt out of, but you retain the right to ask
Depending on your state, you may also have the right to: know the categories of personal data we process; obtain a list of the categories, or in some states the specific identities, of third parties we’ve disclosed personal data to; understand how any profiling of your data works; and limit the use of sensitive personal data. Magdox does not process sensitive personal data (see Section 4) and does not perform profiling that produces legal or similarly significant effects (see Section 14).
Categories of personal information collected and disclosed in the past 12 months, using the categories defined under California’s privacy law as a common reference point other states’ laws substantially overlap with:
| Category | Collected | Disclosed to service providers |
|---|---|---|
| Identifiers (name, email, IP address) | Yes | Yes |
| Personal information under the California Customer Records statute (name, billing address, job title) | Yes | Yes |
| Protected classification characteristics (race, gender, age, etc.) | No | No |
| Commercial information (subscription plan, billing history) | Yes | Yes |
| Biometric information | No | No |
| Internet or network activity | Yes | Yes |
| Geolocation data (IP-derived, approximate only - we do not collect GPS or precise location) | Yes | Yes |
| Audio, visual, or sensory data | No | No |
| Professional or employment information (job title) | Yes | Yes |
| Education records | No | No |
| Inferences or profiles built from the above | No | No |
| Sensitive personal information | No | No |
We retain Identifiers, California Customer Records information, and Professional/employment information for as long as you have an account with us, plus 90 days (Section 10). We retain Internet activity and Geolocation data on a rolling 1-year basis (Section 10). We retain Commercial information for as long as you have an account with us.
We have not sold or shared (as defined under applicable US state law) any personal information in the preceding 12 months. We have disclosed Identifiers, California Customer Records information, Commercial information, Internet activity, Geolocation data, and Professional/employment information to the categories of service providers described in Section 8, for the business purposes described in Section 5.
Authorized agents. You may designate an authorized agent to submit a request on your behalf under applicable state law. We may require proof that the agent has been validly authorized before acting on the request.
Verification. When you submit a rights request, we will verify your identity using the information already associated with your account, or, if necessary, by requesting additional information solely for identity-verification and fraud-prevention purposes.
Appeals. If we decline to act on your request, you may appeal by emailing privacy@magdox.io. We will respond in writing with the outcome of the appeal and our reasoning. If your appeal is denied, some states allow you to further complain to your state Attorney General.
13.3 European Economic Area, UK, and Switzerland (GDPR)
If you are located in the European Economic Area, the United Kingdom, or Switzerland, the GDPR (or the UK GDPR or Swiss Federal Act on Data Protection, as applicable) gives you a set of rights over your personal data. You can ask to see the data we hold about you, ask us to correct it if it is wrong, or ask us to delete it. You can also restrict or object to how we process your data, including processing based on our legitimate interests, and ask for a copy of your data in a portable format. Where we process something based on your consent, you can withdraw that consent at any time, though this will not affect anything we did before you withdrew it. Section 6 explains the legal basis we rely on for each type of processing. To exercise any of these rights, contact privacy@magdox.io.
If you believe we are unlawfully processing your personal data, you have the right to complain to your Member State’s data protection authority, the UK’s Information Commissioner’s Office, or, if you are in Switzerland, the Federal Data Protection and Information Commissioner.
13.4 How to Exercise Any of These Rights
To submit a request under any of the regimes above, contact privacy@magdox.io or use our Contact page, including your name, the email address associated with your account (if any), a description of the right you wish to exercise, and any information that helps us verify your identity.
14. Automated Analysis and Decision Support
FDIE’s compliance scores, CVE findings, and risk ratings are generated by deterministic, rule-based static analysis (not generative AI or machine learning) and are intended as decision-support information for your security and engineering teams. They are not used by Magdox to make any solely-automated decision producing legal or similarly significant effects about an individual, and we do not build profiles of individuals from this data. See Terms of Service Section 15 for the scope and limitations of this analysis.
15. Children’s Privacy
The Service is not directed at, and is not intended for use by, individuals under the age of 18. We do not knowingly collect personal data from anyone under 18. If we learn that we have collected personal data from someone under 18, we will take reasonable steps to delete it and deactivate the associated account. Contact privacy@magdox.io if you believe we may have collected data from a minor.
16. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via the website or by email to registered account holders. The “Last updated” date at the top of this page reflects the most recent revision. Prior versions are archived and available on request.
17. Contact
Questions about this Privacy Policy can be sent to privacy@magdox.io or via our Contact page, or by post to:
Magdox Private Limited St No. 8, Arabinda Nagar, Barbani, Bardhaman, Hindustan Cables, West Bengal 713335, India