Data Processing Agreement
How Magtool processes Customer Data on behalf of Magtool account holders.
Last updated: 27 August 2026
This Data Processing Agreement ("DPA") forms part of the agreement between Miss Magnets ("Magtool", "we", "us", "Processor"), and the account holder or business using the Magtool service ("Customer", "you", "Controller").
This DPA applies where Magtool processes Personal Data on behalf of the Customer in connection with the Magtool service.
This DPA is incorporated into and forms part of the Magtool Terms of Service. By accepting the Terms of Service, creating or maintaining a Magtool account, or accessing or using the Magtool service, the Customer agrees to be bound by this DPA. The Customer is identified by the account and contact information maintained in Magtool's account records. No separate signature is required.
Contents
- Definitions and Applicable Law
- Roles of the Parties
- Subject Matter and Duration
- Nature and Purpose
- Categories of Data Subjects
- Types of Personal Data
- Customer Instructions
- Confidentiality and Access
- Security Measures
- Data Minimisation and Retention
- Sub-processors
- International Transfers
- Data Subject Rights
- Assistance
- Personal Data Breaches
- Deletion or Return
- Audits and Compliance
- Customer Responsibilities
- Payment Providers
- Liability
- Order of Precedence
- Changes and Notices
1. Definitions and Applicable Law
For the purposes of this DPA, "Personal Data", "Processing", "Controller", "Processor", "Data Subject", "Personal Data Breach" and related terms have the meanings given to them under applicable data protection law.
"Applicable Data Protection Law" means, as applicable, the UK GDPR, the Data Protection Act 2018, the EU General Data Protection Regulation (EU GDPR), and legislation implementing, supplementing or replacing those laws.
2. Roles of the Parties
For Personal Data relating directly to Magtool account holders, including account registration, billing, security, support and platform administration information, Magtool generally acts as an independent Controller.
For Personal Data submitted by guests, customers, event participants or storefront visitors through a Customer's Magtool stall, storefront, QR code, upload page, order flow or fulfilment tools ("Customer Data"), the Customer acts as Controller and Magtool acts as Processor.
The Customer determines the purposes for which Customer Data is collected and processed through Magtool.
3. Subject Matter and Duration
Magtool processes Customer Data for the purpose of providing and securing the Magtool service. This may include:
- photo upload and processing;
- generation of personalised print templates and PDF files;
- order management and fulfilment;
- operation of Customer storefronts and ordering pages;
- payment-status handling;
- transactional customer notifications;
- backup and recovery;
- technical support;
- security, abuse prevention and service administration.
Processing continues for the duration necessary to provide the relevant Service and is subject to the retention and deletion provisions described in this DPA.
4. Nature and Purpose of Processing
Magtool may collect, receive, store, organise, retrieve, display, transmit, generate, back up and delete Customer Data where necessary to:
- provide the Magtool service;
- carry out documented Customer instructions;
- maintain the security and integrity of the Service;
- provide requested technical support;
- comply with applicable law.
Magtool will not process Customer Data for unrelated purposes, behavioural advertising, sale of Personal Data or AI model training.
5. Categories of Data Subjects
Customer Data may relate to:
- Customers' own customers;
- guests uploading photographs through QR codes or storefront links;
- event participants;
- order recipients;
- storefront visitors who submit order or contact information.
6. Types of Personal Data
Depending on the Customer's configuration and use of Magtool, Customer Data may include:
- uploaded photographs and images;
- generated PDFs, print templates and order files;
- names, email addresses and telephone numbers;
- postal and delivery addresses;
- order notes, shipping or collection information;
- optional SMS notification preferences and telephone numbers;
- optional social-media consent status;
- payment and order references, payment status and checkout identifiers;
- order amounts, currencies and fulfilment information;
- technical information required to securely operate the Service.
Magtool does not store full payment-card numbers, full bank account credentials or customers' complete payment credentials. Payment information is entered and processed through the selected payment provider.
Technical and security data may also be processed in connection with use of the Service, including IP addresses, session information, timestamps, rate-limiting information and other limited technical data necessary for authentication, security, abuse prevention and reliable operation of the Service.
7. Customer Instructions
The Customer instructs Magtool to process Customer Data as necessary to provide the Service and in accordance with the Customer's configuration and use of Magtool.
Magtool will process Customer Data only on documented instructions from the Customer, including with regard to transfers of Personal Data to another country or international organisation, unless processing is required by applicable law.
Where processing is required by law, Magtool will inform the Customer before processing unless the applicable law prohibits such notification.
Magtool will promptly inform the Customer if, in Magtool's reasonable opinion, a documented instruction infringes Applicable Data Protection Law.
8. Confidentiality and Access
Magtool will ensure that persons authorised to process Customer Data are subject to appropriate confidentiality obligations.
Access to Customer Data is restricted to authorised systems and personnel where reasonably necessary to operate, secure or maintain the Service.
Magtool administrative personnel may access Customer orders or associated Customer Data where reasonably necessary to provide technical support requested by the Customer, investigate a security or service issue, or comply with applicable law.
Customer Data will not be accessed for unrelated purposes.
9. Technical and Organisational Security Measures
Taking into account the state of the art, implementation costs, and the nature, scope, context and purposes of processing, as well as the risks to Data Subjects, Magtool will implement and maintain appropriate technical and organisational measures designed to meet the requirements of Article 32 of the UK GDPR and, where applicable, Article 32 of the EU GDPR.
Those measures are designed, as appropriate to the relevant processing and risk, to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services; restore the availability of and access to Customer Data in a timely manner following a physical or technical incident; regularly test, assess and evaluate the effectiveness of security measures; and apply encryption or pseudonymisation where appropriate.
Measures include, where applicable:
- HTTPS/TLS required for access to the production Service;
- secure password hashing;
- session and authentication controls;
- restricted administrative access;
- non-sequential and segregated user storage paths;
- access controls protecting private order records and backup data;
- rate limiting and abuse-prevention controls;
- private cloud backup storage;
- encryption of Backblaze B2 backup data at rest;
- encryption in transit when Customer Data is transferred to cloud storage;
- no storage of full payment-card details on Magtool servers;
- access limited to authorised systems and legitimate support, security and operational requirements.
Magtool may update its technical and organisational measures as technologies and risks change, provided that the overall level of protection for Customer Data is not materially reduced.
10. Data Minimisation and Retention
Magtool is designed to minimise the period for which Customer Personal Data is retained. Customer Personal Data is normally retained for no longer than approximately seven (7) days following the relevant order or upload.
This includes, where applicable, uploaded photographs and images; generated PDFs and print files; customer names, email addresses and telephone numbers; postal and delivery addresses; customer-entered notes; and other identifying or private information entered by the Customer's customer.
After the applicable retention period, Customer Personal Data is automatically purged from Magtool's active systems and backup storage.
The seven-day retention period applies to Personal Data submitted or generated as part of a customer's order or upload, including photographs, generated files, names, email addresses, telephone numbers, postal or delivery addresses, notes, and other customer-entered identifying information.
Limited technical and security data, such as IP addresses, session information, security events, timestamps and rate-limiting records, may be processed and retained separately for a reasonable period where necessary for security, abuse prevention, troubleshooting and reliable operation of the Service.
Magtool may retain a minimised order record after Customer Personal Data has been removed. Such records may contain information such as an internal order number, order date, amount, currency, payment method or status, fulfilment status and other operational information that does not identify the underlying individual.
Account information relating to the Magtool Customer itself is governed separately by Magtool's Privacy Policy and is retained while the Customer maintains an account or as otherwise necessary for contractual, accounting, tax, security or legal purposes. Magtool accounts are not automatically deleted solely because they have been inactive.
Customers may request deletion of their Magtool account in accordance with Magtool's Privacy Policy and applicable law.
11. Sub-processors
The Customer provides general authorisation for Magtool to engage sub-processors where reasonably necessary to provide the Service.
Current service providers involved in the processing of Customer Data may include:
- Backblaze B2: Private cloud storage and recovery of Customer order files and records. Magtool uses a Backblaze B2 bucket located in the United States (US East region). Customer backup data stored in B2 is private and server-side encryption at rest is enabled.
- Brevo: Transactional email delivery and, where enabled, transactional SMS notifications.
- Stripe: Payment processing, Stripe Connect functionality, checkout, payment status and related payment, fraud-prevention, security and compliance functionality. Depending upon the particular processing activity, Stripe may act as a Processor or as an independent Controller in accordance with its applicable terms and Data Processing Agreement.
- Square / Block: Payment processing, Square account connections, checkout/payment functionality, payment status and related fraud-prevention, security and compliance functionality. Depending upon the particular processing activity, Square / Block may act as a Processor or as an independent Controller in accordance with its applicable terms and data-processing arrangements.
- Hawk Host: Application hosting, database hosting, application file storage, server infrastructure and related hosting services required to operate Magtool.
The service providers listed above maintain their own privacy, data-protection and security documentation relevant to their respective services. Where applicable, providers may also make Data Processing Agreements, data-processing terms, international-transfer safeguards or other contractual privacy documentation available through their websites, account portals or upon request. Such documentation is governed by the respective provider's terms and may be updated from time to time.
Where Magtool relies on the Customer's general authorisation to appoint sub-processors, Magtool will provide mandatory notice through the Customer's Magtool account at login, and may also provide notice by email, before an intended addition or replacement takes effect. The notice will allow the Customer a reasonable opportunity to accept the change or object on reasonable data-protection grounds.
Magtool will consider any timely objection in good faith and work with the Customer to seek a reasonable resolution. If no reasonable resolution is available, the Customer may discontinue the affected Service or terminate its use of Magtool before the change takes effect.
Magtool will maintain a current list of applicable sub-processors and may provide links to relevant provider privacy, data-processing and international-transfer documentation.
12. International Data Transfers
Customer Data may be processed outside the United Kingdom or European Economic Area where this is necessary to provide the Service. For example, Magtool's Backblaze B2 backup storage is currently located in the United States.
Where Applicable Data Protection Law requires safeguards for an international transfer, Magtool will ensure that an appropriate lawful transfer mechanism applies.
Depending on the transfer and provider, these safeguards may include an applicable adequacy decision; European Commission Standard Contractual Clauses; the UK International Data Transfer Agreement; the UK Addendum to the European Commission Standard Contractual Clauses; an applicable recognised data privacy framework; or another transfer mechanism permitted under Applicable Data Protection Law.
Magtool will rely only on transfer mechanisms applicable to the relevant processing and provider.
13. Data Subject Rights
Taking into account the nature of the processing, Magtool will provide reasonable assistance to enable the Customer to fulfil its obligations in relation to Data Subject rights, including requests concerning access, correction, deletion, restriction of processing, portability, objection and other applicable rights.
Where a Data Subject contacts Magtool directly concerning Customer Data controlled by a Customer, Magtool may direct the Data Subject to the relevant Customer unless Magtool is legally required to respond directly.
14. Assistance With Data Protection Obligations
Taking into account the nature of the processing and the information reasonably available to Magtool, Magtool will provide reasonable assistance to the Customer with its obligations concerning security of processing, Personal Data Breaches, Data Protection Impact Assessments (DPIAs), and prior consultation with a competent supervisory authority where required by law.
15. Personal Data Breaches
Magtool will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Data.
Where information is reasonably available, Magtool will provide details concerning the nature of the breach; categories of Personal Data affected; categories or approximate number of affected Data Subjects where known; likely consequences where known; and measures taken or proposed to contain, investigate or mitigate the breach.
Where all information is not immediately available, Magtool may provide information in phases as it becomes available. The Customer remains responsible for determining whether notification to a supervisory authority or affected Data Subjects is required in its capacity as Controller.
16. Deletion or Return of Customer Data
During normal operation, Customer Personal Data is automatically deleted in accordance with the retention periods described in Section 10.
Following termination of the Services, Magtool will, at the Customer's choice, delete or return all remaining Customer Data and securely delete existing copies unless applicable law requires continued storage.
Where immediate deletion from backup or recovery systems is not technically practicable, Customer Data will remain protected from ordinary use and will be deleted in accordance with Magtool's normal backup deletion cycle.
Data that Magtool processes separately as an independent Controller, including applicable account, billing, security or legal records, is not Customer Data for the purposes of this section and may be retained in accordance with Magtool's Privacy Policy and applicable law.
17. Audits and Compliance Information
Magtool will make available to the Customer reasonable information necessary to demonstrate compliance with the Processor obligations contained in this DPA.
Magtool will allow for and contribute to audits and inspections conducted by the Customer or an independent auditor appointed by the Customer where reasonably necessary to demonstrate compliance with Article 28 and this DPA, subject to reasonable advance notice.
Audits must be proportionate to the nature and risk of the processing; avoid unnecessary disruption to the Service; respect the confidentiality and security of other Magtool customers; and not require disclosure of information that would materially compromise the security of Magtool or another customer.
Where appropriate, Magtool may satisfy an audit request by providing relevant documentation, security information, compliance materials or responses to reasonable written questions.
18. Customer Responsibilities
The Customer is responsible for:
- ensuring a lawful basis exists for collection and processing of Customer Data;
- providing appropriate privacy information to its customers and guests;
- collecting only Personal Data reasonably required for its purposes;
- obtaining required permissions or consents;
- appropriate arrangements when processing children's Personal Data or photographs;
- required consent for SMS, marketing, event photography or social-media use;
- appropriately handling Data Subject requests;
- ensuring its instructions to Magtool comply with Applicable Data Protection Law;
- applicable payment, tax, consumer-protection and local data-protection requirements.
19. Payment Providers
Where the Customer enables Stripe or Square, the relevant payment services are also governed by that provider's applicable terms and privacy documentation.
Stripe and Square / Block may act independently as Controllers for certain activities including payment processing, identity verification, fraud prevention, risk management, regulatory compliance and platform security.
Magtool does not determine the purposes and means of processing undertaken independently by those providers in their capacity as Controllers. Magtool does not receive or store customers' complete payment-card credentials.
20. Liability and Relationship With Main Agreement
This DPA forms part of the agreement governing the Customer's use of Magtool. Except where Applicable Data Protection Law requires otherwise, liability arising under this DPA is subject to the applicable limitations and exclusions of liability contained in the Magtool Terms of Service.
Nothing in this DPA limits either party's obligations or liability to the extent such limitation is prohibited by Applicable Data Protection Law.
21. Order of Precedence
If this DPA conflicts with the Magtool Terms of Service or Privacy Policy concerning Magtool's processing of Customer Data as Processor, this DPA will prevail to the extent of that conflict.
22. Changes to this DPA and Notices
Magtool may update this DPA where reasonably necessary to reflect changes to the Service, Applicable Data Protection Law, security practices or processing arrangements.
For future material changes to this DPA, Magtool will provide mandatory notice through the Customer's Magtool account at login before the revised terms take effect, and may also provide notice by email. Where acceptance of revised terms is required, the Customer may accept the revised DPA and continue using the Service or decline and discontinue use of the Service.
Notices concerning intended additions or replacements of sub-processors will be handled in accordance with Section 11.
Schedule 1 — Details of Processing
Subject matter:
Provision of the Magtool personalised-product ordering, photograph processing, order-management and related services.
Duration:
For the duration of the relevant processing required to provide the Service, subject to Magtool's approximately seven-day Customer Personal Data retention policy and the deletion provisions of this DPA.
Nature of processing:
Collection, receipt, storage, organisation, retrieval, display, generation, transmission, backup, recovery and deletion.
Purpose:
Providing and securing the Magtool Service in accordance with the Customer's instructions.
Data subjects:
Customers, guests, event participants, order recipients and other individuals submitting information through a Customer's Magtool service.
Personal Data:
Photographs, names, contact information, delivery information, order information, customer-entered notes and associated information described in Section 6.
Special-category data:
Magtool does not require Customers to submit special-category Personal Data as part of the ordinary operation of the Service. Customers should not intentionally submit special-category Personal Data unless necessary, lawful and appropriately protected.
Retention:
Customer identifying information, uploaded photographs, generated files and other Customer Personal Data are normally automatically purged approximately seven days after the relevant order or upload. Minimised non-identifying order records may be retained.
Schedule 2 — Technical and Organisational Measures
Magtool's measures currently include:
- mandatory HTTPS/TLS for production Service access;
- secure password hashing;
- authentication and session controls;
- restricted administrative access;
- segregated and non-sequential user storage paths;
- access controls protecting private order data;
- rate limiting and abuse-prevention controls;
- private Backblaze B2 backup storage;
- encryption at rest enabled for Backblaze B2 backup data;
- encrypted transmission to cloud storage;
- automatic purging of Customer Personal Data after approximately seven days;
- payment-card information processed directly by specialist payment providers;
- support access limited to authorised personnel and legitimate support requirements.
These measures may evolve as the Service and available security technologies develop.
Data Protection Contact
Data protection enquiries relating to this DPA may be sent to contact@missmagnets.com.