Data Processing Agreement

This Data Processing Agreement ("DPA") forms part of the agreement between Miss Magnets ("Magtool", "we", "us", "Processor"), and the account holder or business using the Magtool service ("Customer", "you", "Controller").

This DPA applies where Magtool processes Personal Data on behalf of the Customer in connection with the Magtool service.

This DPA is incorporated into and forms part of the Magtool Terms of Service. By accepting the Terms of Service, creating or maintaining a Magtool account, or accessing or using the Magtool service, the Customer agrees to be bound by this DPA. The Customer is identified by the account and contact information maintained in Magtool's account records. No separate signature is required.

Contents

  1. Definitions and Applicable Law
  2. Roles of the Parties
  3. Subject Matter and Duration
  4. Nature and Purpose
  5. Categories of Data Subjects
  6. Types of Personal Data
  7. Customer Instructions
  8. Confidentiality and Access
  9. Security Measures
  10. Data Minimisation and Retention
  11. Sub-processors
  12. International Transfers
  13. Data Subject Rights
  14. Assistance
  15. Personal Data Breaches
  16. Deletion or Return
  17. Audits and Compliance
  18. Customer Responsibilities
  19. Payment Providers
  20. Liability
  21. Order of Precedence
  22. Changes and Notices

1. Definitions and Applicable Law

For the purposes of this DPA, "Personal Data", "Processing", "Controller", "Processor", "Data Subject", "Personal Data Breach" and related terms have the meanings given to them under applicable data protection law.

"Applicable Data Protection Law" means, as applicable, the UK GDPR, the Data Protection Act 2018, the EU General Data Protection Regulation (EU GDPR), and legislation implementing, supplementing or replacing those laws.

2. Roles of the Parties

For Personal Data relating directly to Magtool account holders, including account registration, billing, security, support and platform administration information, Magtool generally acts as an independent Controller.

For Personal Data submitted by guests, customers, event participants or storefront visitors through a Customer's Magtool stall, storefront, QR code, upload page, order flow or fulfilment tools ("Customer Data"), the Customer acts as Controller and Magtool acts as Processor.

The Customer determines the purposes for which Customer Data is collected and processed through Magtool.

3. Subject Matter and Duration

Magtool processes Customer Data for the purpose of providing and securing the Magtool service. This may include:

Processing continues for the duration necessary to provide the relevant Service and is subject to the retention and deletion provisions described in this DPA.

4. Nature and Purpose of Processing

Magtool may collect, receive, store, organise, retrieve, display, transmit, generate, back up and delete Customer Data where necessary to:

Magtool will not process Customer Data for unrelated purposes, behavioural advertising, sale of Personal Data or AI model training.

5. Categories of Data Subjects

Customer Data may relate to:

6. Types of Personal Data

Depending on the Customer's configuration and use of Magtool, Customer Data may include:

Magtool does not store full payment-card numbers, full bank account credentials or customers' complete payment credentials. Payment information is entered and processed through the selected payment provider.

Technical and security data may also be processed in connection with use of the Service, including IP addresses, session information, timestamps, rate-limiting information and other limited technical data necessary for authentication, security, abuse prevention and reliable operation of the Service.

7. Customer Instructions

The Customer instructs Magtool to process Customer Data as necessary to provide the Service and in accordance with the Customer's configuration and use of Magtool.

Magtool will process Customer Data only on documented instructions from the Customer, including with regard to transfers of Personal Data to another country or international organisation, unless processing is required by applicable law.

Where processing is required by law, Magtool will inform the Customer before processing unless the applicable law prohibits such notification.

Magtool will promptly inform the Customer if, in Magtool's reasonable opinion, a documented instruction infringes Applicable Data Protection Law.

8. Confidentiality and Access

Magtool will ensure that persons authorised to process Customer Data are subject to appropriate confidentiality obligations.

Access to Customer Data is restricted to authorised systems and personnel where reasonably necessary to operate, secure or maintain the Service.

Magtool administrative personnel may access Customer orders or associated Customer Data where reasonably necessary to provide technical support requested by the Customer, investigate a security or service issue, or comply with applicable law.

Customer Data will not be accessed for unrelated purposes.

9. Technical and Organisational Security Measures

Taking into account the state of the art, implementation costs, and the nature, scope, context and purposes of processing, as well as the risks to Data Subjects, Magtool will implement and maintain appropriate technical and organisational measures designed to meet the requirements of Article 32 of the UK GDPR and, where applicable, Article 32 of the EU GDPR.

Those measures are designed, as appropriate to the relevant processing and risk, to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services; restore the availability of and access to Customer Data in a timely manner following a physical or technical incident; regularly test, assess and evaluate the effectiveness of security measures; and apply encryption or pseudonymisation where appropriate.

Measures include, where applicable:

Magtool may update its technical and organisational measures as technologies and risks change, provided that the overall level of protection for Customer Data is not materially reduced.

10. Data Minimisation and Retention

Magtool is designed to minimise the period for which Customer Personal Data is retained. Customer Personal Data is normally retained for no longer than approximately seven (7) days following the relevant order or upload.

This includes, where applicable, uploaded photographs and images; generated PDFs and print files; customer names, email addresses and telephone numbers; postal and delivery addresses; customer-entered notes; and other identifying or private information entered by the Customer's customer.

After the applicable retention period, Customer Personal Data is automatically purged from Magtool's active systems and backup storage.

The seven-day retention period applies to Personal Data submitted or generated as part of a customer's order or upload, including photographs, generated files, names, email addresses, telephone numbers, postal or delivery addresses, notes, and other customer-entered identifying information.

Limited technical and security data, such as IP addresses, session information, security events, timestamps and rate-limiting records, may be processed and retained separately for a reasonable period where necessary for security, abuse prevention, troubleshooting and reliable operation of the Service.

Magtool may retain a minimised order record after Customer Personal Data has been removed. Such records may contain information such as an internal order number, order date, amount, currency, payment method or status, fulfilment status and other operational information that does not identify the underlying individual.

Account information relating to the Magtool Customer itself is governed separately by Magtool's Privacy Policy and is retained while the Customer maintains an account or as otherwise necessary for contractual, accounting, tax, security or legal purposes. Magtool accounts are not automatically deleted solely because they have been inactive.

Customers may request deletion of their Magtool account in accordance with Magtool's Privacy Policy and applicable law.

11. Sub-processors

The Customer provides general authorisation for Magtool to engage sub-processors where reasonably necessary to provide the Service.

Current service providers involved in the processing of Customer Data may include:

The service providers listed above maintain their own privacy, data-protection and security documentation relevant to their respective services. Where applicable, providers may also make Data Processing Agreements, data-processing terms, international-transfer safeguards or other contractual privacy documentation available through their websites, account portals or upon request. Such documentation is governed by the respective provider's terms and may be updated from time to time.

Where Magtool relies on the Customer's general authorisation to appoint sub-processors, Magtool will provide mandatory notice through the Customer's Magtool account at login, and may also provide notice by email, before an intended addition or replacement takes effect. The notice will allow the Customer a reasonable opportunity to accept the change or object on reasonable data-protection grounds.

Magtool will consider any timely objection in good faith and work with the Customer to seek a reasonable resolution. If no reasonable resolution is available, the Customer may discontinue the affected Service or terminate its use of Magtool before the change takes effect.

Magtool will maintain a current list of applicable sub-processors and may provide links to relevant provider privacy, data-processing and international-transfer documentation.

12. International Data Transfers

Customer Data may be processed outside the United Kingdom or European Economic Area where this is necessary to provide the Service. For example, Magtool's Backblaze B2 backup storage is currently located in the United States.

Where Applicable Data Protection Law requires safeguards for an international transfer, Magtool will ensure that an appropriate lawful transfer mechanism applies.

Depending on the transfer and provider, these safeguards may include an applicable adequacy decision; European Commission Standard Contractual Clauses; the UK International Data Transfer Agreement; the UK Addendum to the European Commission Standard Contractual Clauses; an applicable recognised data privacy framework; or another transfer mechanism permitted under Applicable Data Protection Law.

Magtool will rely only on transfer mechanisms applicable to the relevant processing and provider.

13. Data Subject Rights

Taking into account the nature of the processing, Magtool will provide reasonable assistance to enable the Customer to fulfil its obligations in relation to Data Subject rights, including requests concerning access, correction, deletion, restriction of processing, portability, objection and other applicable rights.

Where a Data Subject contacts Magtool directly concerning Customer Data controlled by a Customer, Magtool may direct the Data Subject to the relevant Customer unless Magtool is legally required to respond directly.

14. Assistance With Data Protection Obligations

Taking into account the nature of the processing and the information reasonably available to Magtool, Magtool will provide reasonable assistance to the Customer with its obligations concerning security of processing, Personal Data Breaches, Data Protection Impact Assessments (DPIAs), and prior consultation with a competent supervisory authority where required by law.

15. Personal Data Breaches

Magtool will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Data.

Where information is reasonably available, Magtool will provide details concerning the nature of the breach; categories of Personal Data affected; categories or approximate number of affected Data Subjects where known; likely consequences where known; and measures taken or proposed to contain, investigate or mitigate the breach.

Where all information is not immediately available, Magtool may provide information in phases as it becomes available. The Customer remains responsible for determining whether notification to a supervisory authority or affected Data Subjects is required in its capacity as Controller.

16. Deletion or Return of Customer Data

During normal operation, Customer Personal Data is automatically deleted in accordance with the retention periods described in Section 10.

Following termination of the Services, Magtool will, at the Customer's choice, delete or return all remaining Customer Data and securely delete existing copies unless applicable law requires continued storage.

Where immediate deletion from backup or recovery systems is not technically practicable, Customer Data will remain protected from ordinary use and will be deleted in accordance with Magtool's normal backup deletion cycle.

Data that Magtool processes separately as an independent Controller, including applicable account, billing, security or legal records, is not Customer Data for the purposes of this section and may be retained in accordance with Magtool's Privacy Policy and applicable law.

17. Audits and Compliance Information

Magtool will make available to the Customer reasonable information necessary to demonstrate compliance with the Processor obligations contained in this DPA.

Magtool will allow for and contribute to audits and inspections conducted by the Customer or an independent auditor appointed by the Customer where reasonably necessary to demonstrate compliance with Article 28 and this DPA, subject to reasonable advance notice.

Audits must be proportionate to the nature and risk of the processing; avoid unnecessary disruption to the Service; respect the confidentiality and security of other Magtool customers; and not require disclosure of information that would materially compromise the security of Magtool or another customer.

Where appropriate, Magtool may satisfy an audit request by providing relevant documentation, security information, compliance materials or responses to reasonable written questions.

18. Customer Responsibilities

The Customer is responsible for:

19. Payment Providers

Where the Customer enables Stripe or Square, the relevant payment services are also governed by that provider's applicable terms and privacy documentation.

Stripe and Square / Block may act independently as Controllers for certain activities including payment processing, identity verification, fraud prevention, risk management, regulatory compliance and platform security.

Magtool does not determine the purposes and means of processing undertaken independently by those providers in their capacity as Controllers. Magtool does not receive or store customers' complete payment-card credentials.

20. Liability and Relationship With Main Agreement

This DPA forms part of the agreement governing the Customer's use of Magtool. Except where Applicable Data Protection Law requires otherwise, liability arising under this DPA is subject to the applicable limitations and exclusions of liability contained in the Magtool Terms of Service.

Nothing in this DPA limits either party's obligations or liability to the extent such limitation is prohibited by Applicable Data Protection Law.

21. Order of Precedence

If this DPA conflicts with the Magtool Terms of Service or Privacy Policy concerning Magtool's processing of Customer Data as Processor, this DPA will prevail to the extent of that conflict.

22. Changes to this DPA and Notices

Magtool may update this DPA where reasonably necessary to reflect changes to the Service, Applicable Data Protection Law, security practices or processing arrangements.

For future material changes to this DPA, Magtool will provide mandatory notice through the Customer's Magtool account at login before the revised terms take effect, and may also provide notice by email. Where acceptance of revised terms is required, the Customer may accept the revised DPA and continue using the Service or decline and discontinue use of the Service.

Notices concerning intended additions or replacements of sub-processors will be handled in accordance with Section 11.

Schedule 1 — Details of Processing

Subject matter:
Provision of the Magtool personalised-product ordering, photograph processing, order-management and related services.

Duration:
For the duration of the relevant processing required to provide the Service, subject to Magtool's approximately seven-day Customer Personal Data retention policy and the deletion provisions of this DPA.

Nature of processing:
Collection, receipt, storage, organisation, retrieval, display, generation, transmission, backup, recovery and deletion.

Purpose:
Providing and securing the Magtool Service in accordance with the Customer's instructions.

Data subjects:
Customers, guests, event participants, order recipients and other individuals submitting information through a Customer's Magtool service.

Personal Data:
Photographs, names, contact information, delivery information, order information, customer-entered notes and associated information described in Section 6.

Special-category data:
Magtool does not require Customers to submit special-category Personal Data as part of the ordinary operation of the Service. Customers should not intentionally submit special-category Personal Data unless necessary, lawful and appropriately protected.

Retention:
Customer identifying information, uploaded photographs, generated files and other Customer Personal Data are normally automatically purged approximately seven days after the relevant order or upload. Minimised non-identifying order records may be retained.

Schedule 2 — Technical and Organisational Measures

Magtool's measures currently include:

These measures may evolve as the Service and available security technologies develop.

Data Protection Contact

Data protection enquiries relating to this DPA may be sent to contact@missmagnets.com.