1. Purpose
This page summarizes the processing terms available for FDIE; it is not a substitute for an executed DPA with the parties, processing details and any required transfer annexes completed. A DPA is available to customers, including trial and proof-of-concept participants. Where applicable law requires a processor agreement, it must be in place before the relevant processing starts; eligibility is not dependent on payment. MAGDOX Private Limited is the contracting service provider.
2. Roles
For personal data processed through the Service:
- Customer acts as controller/Data Fiduciary, or as a processor appointing Magdox as a sub-processor with the necessary upstream authorization
- Magdox acts as the Data Processor (the DPDPA uses the same term), processing personal data only on the Customer’s documented instructions. Magdox’s separate controller activities, including its own billing and business administration, are described in the Privacy Policy
3. Subject Matter, Duration, Nature and Purpose of Processing
Magdox processes personal data solely for the purpose of providing the FDIE SaaS platform: firmware security analysis, compliance reporting, account management, and related technical support. Processing continues during the agreed trial, evaluation or subscription and the documented return/deletion period. This includes receiving, storing, analyzing, retrieving, exporting and deleting the data. The customer is responsible for lawful instructions, required notices, and authority to supply the data.
In that role Magdox:
- processes personal data only on the Customer’s documented instructions, and informs the Customer if an instruction appears to breach applicable law or if a law requires processing outside those instructions;
- ensures that every person authorised to process personal data is bound by a contractual or statutory duty of confidentiality;
- keeps a record of the processing carried out on the Customer’s behalf and makes it available on request; and
- does not sell personal data or use it for Magdox’s own purposes, including the training of any model.
4. Categories of Data Subjects and Personal Data
- Data subjects: the Customer’s authorized users (employees and contractors), and to the extent present in uploaded firmware metadata, individuals referenced therein (for example, developer names or email addresses embedded in build artifacts)
- Categories of personal data: names, work email addresses, roles and permissions, authentication logs, and any personal data incidentally contained within uploaded firmware images or configuration files
5. Sub-processor Authorization and Change Notice
The following inventory identifies providers by service purpose. Not every provider processes Customer Data under every DPA: sales, newsletter and booking providers may support Magdox’s separate controller activities. The executed DPA identifies the applicable processing chain and authorizes its sub-processors. Magdox remains responsible for its sub-processors’ performance of the applicable processing obligations and imposes the required equivalent protections.
Infrastructure
Scroll horizontally to see all columns.
| Vendor | Purpose | Data Region |
|---|---|---|
| Oracle Cloud Infrastructure (OCI) | Hosting and storage for the FDIE platform: application, database, firmware images and analysis results | India |
| Cloudflare, Inc. | Website hosting, DNS, TLS and edge delivery; contact and newsletter form relay to Zoho CRM | Global |
The FDIE platform is hosted on OCI in India: Mumbai (ap-mumbai-1) as the primary region and Hyderabad (ap-hyderabad-1) for disaster recovery. The deployment arrangement is agreed in the Order Form before provisioning. Customers that need their data kept outside India can deploy FDIE on-premises in their own environment, where OCI is not a sub-processor. Cloudflare serves the marketing website.
Application services
Scroll horizontally to see all columns.
| Vendor | Purpose | Data Region |
|---|---|---|
| Zoho Corporation (Zoho CRM) | CRM (contact/lead management) | India |
| Zoho Corporation (Zoho Desk) | Support ticketing | India |
| Zoho Corporation (Zoho Campaigns) | Email marketing and newsletter | India |
| Zoho Corporation (ZeptoMail) | Transactional email: verification, security codes, alerts and user-requested report delivery | India |
| Zoho Corporation (Zoho Bookings) | Demo and fit check scheduling | India |
| Zoom Video Communications, Inc. | Video meetings for demos, fit checks and sales calls | USA |
Monitoring
Scroll horizontally to see all columns.
| Vendor | Purpose | Data Region |
|---|---|---|
| Sentry (Functional Software, Inc.) | Error and performance monitoring; receives stack traces, endpoint names and technical identifiers, never request or response bodies | USA |
| ipinfo.io (IPinfo Inc.) | Sign-in IP geolocation for the customer’s audit log; receives the IP address only | USA |
Automatic request-body capture is disabled in Sentry. It is not an upload or report-delivery destination.
Before engaging a new sub-processor to process personal data under this DPA, Magdox will provide at least 14 days’ advance notice by posting an update to this list and by direct email to affected customers’ designated contacts. Customer may object on reasonable data protection grounds within that notice period by contacting [email protected]; Magdox will work with Customer in good faith to address the objection, which may include providing a commercially reasonable alternative.
6. Data Subject Rights & DPIA Assistance
Magdox will provide reasonable assistance to the Customer in responding to data principal requests (access, correction, erasure, and others) relating to personal data processed under the DPA. See our DPDPA rights page for the general process.
Taking into account the nature of processing and information available to Magdox, Magdox will also provide reasonable assistance to Customer in conducting Data Protection Impact Assessments (DPIAs) and prior consultations with supervisory authorities where required by applicable data protection law.
7. Security Measures
Magdox implements the technical and organizational security measures described in Privacy Policy Section 11 and in our Information Security Addendum, including encryption in transit and at rest, access controls, and audit logging.
8. Breach Notification
In the event of a personal data breach affecting Customer Data, Magdox will notify the affected Customer without undue delay, and in any case within 72 hours of becoming aware of the breach, providing available details to support the Customer’s own notification obligations. This applies to trial and paid accounts. The 72-hour limit does not permit waiting where earlier notice is required. Magdox supplies available details, follows up as facts are established and assists the customer’s assessment and notifications; the customer controls its own regulatory submissions.
9. International Transfers
Restricted transfers require the mechanism appropriate to the applicable law, completed before transfer. This may include EU SCCs with the appropriate module and annexes, the UK IDTA or EU SCCs plus the UK Addendum, and Swiss-specific adaptations where needed. Transfer assessments and supplementary measures must be addressed for the actual processing chain, including IPinfo and any other applicable provider in Section 5. Listing a vendor here is not evidence that a particular customer’s transfer documents have been executed. The governing-law, jurisdiction and rights provisions in mandatory transfer clauses prevail over conflicting commercial terms.
See the ICO’s UK transfer-clause guidance and the FDPIC’s cross-border transfer guidance.
10. Audit Rights
Magdox makes compliance information available and permits audits and inspections by the customer or its mandated independent auditor as required by the applicable DPA and law. Reasonable confidentiality, scope, notice and security arrangements protect other customers. A questionnaire or available independent report may help satisfy a request but does not give Magdox a unilateral right to exclude a legally required audit.
11. Request a Signed DPA
Contact our team to complete a DPA before the processing that requires it begins, including during a trial or proof of concept.
12. Full Agreement
A full executable DPA is available upon request. Questions about this DPA, and objections to a new sub-processor, go to [email protected].
13. Data Deletion on Termination
At the end of processing, the customer chooses return or deletion of personal data processed on its behalf, including existing copies, unless applicable law requires storage. A written request is not required merely to activate the default termination deletion schedule in Privacy Policy Section 10. A specific return/deletion instruction is handled within 30 business days, or an earlier period required by law or the executed DPA. Any export window is subject to an earlier valid deletion instruction.
Backups remain protected and unavailable for ordinary processing until expiry under the documented deployment lifecycle. Deletion instructions must be reapplied if a backup is restored. Any legally required retention is restricted to that purpose and does not create a general right to keep Customer Data for fraud prevention or possible future claims. Magdox’s separate statutory business records are governed by the Privacy Policy. A written deletion confirmation identifies any legally required or backup copies still awaiting expiry.
14. Governing Law
This DPA is governed by and construed in accordance with the laws of India, including the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023. The executed DPA may specify a different governing law or forum. Mandatory transfer-clause provisions and non-waivable data-subject rights take precedence over conflicting Indian-law or venue terms.