1. Introduction and Scope
This Privacy Policy explains how MAGDOX Private Limited (“Magdox,” “we,” “us,” or “our”) collects, uses, discloses, and protects personal data in connection with the FDIE (Firmware Delta Intelligence Engine) marketing website, the FDIE web application, and related services (together, the “Service”). This Policy constitutes an electronic record under the Information Technology Act, 2000. This Policy applies to visitors to our website, prospective and current customers, and authorized users of the FDIE platform acting on behalf of a customer organization.
This Policy is a notice about our processing; reading it or using the Service does not, by itself, give consent to optional processing. The Service is intended for users who are at least 18 years old; see Section 15.
2. Our Roles: Controller vs. Processor
Magdox acts in different roles depending on the data involved:
- As Controller: for account data (Section 4), marketing-site usage data, billing data, and other data we collect about our own customers and website visitors to operate our business, Magdox determines the purposes and means of processing and acts as the Data Controller.
- As Processor: for Customer Data (firmware images, configuration files, and any personal data incidentally contained within them) uploaded by a customer for analysis, Magdox acts solely as a Data Processor on that customer’s instructions.
Account data about a customer’s authorized users (names, work email addresses, roles and permissions, authentication logs) appears in both roles, for different purposes. Magdox processes it as controller to operate and secure the Service, bill the customer and meet its own legal obligations; the retention and rights sections of this Policy apply to that use. The same records are also processed as processor when the customer administers its own users inside FDIE, and the DPA governs that use, including deletion or return on termination. Neither role permits sale of the data or its use for model training. Our processing of Customer Data on a customer’s behalf is additionally governed by our DPA, which is available to customers, including trial and proof-of-concept participants, before processing that requires a DPA begins.
3. Data Controller Identity
- Entity: MAGDOX Private Limited
- Registered address: St No. 8, Arabinda Nagar, Barbani, Bardhaman, Hindustan Cables, West Bengal 713335, India
- Privacy contact: [email protected]
Privacy and grievance contact. You may raise a grievance directly with our designated contact below. The DPDPA has a phased commencement; our DPDPA notice distinguishes current commitments from rights taking effect under that timetable:
- Name: Manish Sharma
- Designation: Founder and CEO
- Email: [email protected]
- Response time: within 30 days of receipt
If you are not satisfied with our response, applicable law may provide a right to complain to a regulator. See our DPDPA rights page for the commencement and escalation qualifications in India.
4. What Personal Data We Collect
Account data. When you sign up for FDIE or contact us, we collect information such as your name, work email address, company name, job title, and billing address.
Usage data. On the FDIE platform we automatically collect technical information such as IP address, browser type, device information, and product events (features used, timestamps) in application and audit logs. On the marketing website we run no analytics; the only technical data recorded is the standard request log kept by our hosting provider (IP address, user agent, page requested, timestamp), which we use for security and capacity purposes.
Sign-in location. We use the sign-in IP address to obtain an approximate location from IPinfo for security and the organization audit log. IPinfo receives the queried IP address; we do not request GPS or precise device location.
Communications and meetings. We process the details you submit in enquiries, support tickets and bookings. If you join a video meeting, the meeting provider processes call audio/video and participation details. Any recording requires advance notice and any consent required by law.
Authentication data. Depending on your sign-in method, we process password hashes, session identifiers, authentication factors, recovery information and identity-provider claims to authenticate and protect your account. These are restricted security records, not marketing data.
Billing data. Subscriptions are invoiced directly by MAGDOX Private Limited and settled by bank transfer. The billing data we hold is limited to your billing contact and address, your organisation’s tax or registration identifiers where required on an invoice, purchase order references, and the remittance details our bank reports back to us when an invoice is settled.
Firmware and content data. Customers upload firmware images, configuration files, and related artifacts to the FDIE platform for analysis. This data is “Customer Data”: ownership remains with the customer or its licensors; it may contain personal data and is handled under the confidentiality commitments described in our Terms of Service and DPA. Where Customer Data incidentally contains personal data (for example, developer names embedded in firmware metadata), it is processed solely to provide the Service.
5. How We Use Your Data
We use personal data to:
- Provide, operate, and maintain the Service, including account creation, authentication, and account management
- Issue invoices and manage subscriptions, including orders and renewals
- Provide customer support and respond to inquiries
- Send administrative information, such as changes to our terms and policies
- Request feedback about your use of the Service
- Improve and develop new features, and identify usage trends
- Protect the Service, including fraud monitoring and prevention
- Send product updates, security advisories, and marketing communications (with an opt-out available in every email)
6. Why We Process Your Data
Where the GDPR or UK GDPR applies, we use the following bases according to the purpose and the individual relationship:
- Contract: to perform a contract with you or take steps you request before entering it. Where the customer is your employer, routine business contact and account administration may instead rely on our legitimate interests in serving that organization.
- Consent: for optional marketing or storage technologies where required. Withdrawal is available without affecting earlier lawful processing.
- Legitimate interests: to operate and secure the Service, prevent fraud, manage business relationships and improve service reliability, balanced against individuals’ rights. You may object to this processing.
- Legal obligation: to meet applicable requirements, such as statutory recordkeeping. A request from an authority is assessed against the applicable law; it does not automatically authorize disclosure.
These GDPR bases are not interchangeable with the grounds available under other laws. In India, applicable requirements must be assessed under the law in force; when the DPDPA’s substantive processing provisions commence, processing must rely on consent or a permitted legitimate use under that Act. See the DPDPA notice.
7. Cookies and Tracking
FDIE uses essential session and CSRF cookies and browser storage for selected interface preferences. The marketing site’s own code does not set analytics or advertising cookies. Cloudflare Web Analytics measures aggregate page views through a cookieless script from cloudflareinsights.com; it records the page, referrer, browser type and load timing, and does not store anything on your device or build a profile of you. The booking calendar is served by Zoho Bookings from magdox.zohobookings.in as an embedded frame, with no Zoho script on our pages; it loads only when you click a booking button or open the Demo page. These requests disclose technical connection data to Zoho, and embedded content may use its own storage. Booked meetings are held on Zoom. Cloudflare may set security cookies depending on the enabled protection features, including without an interactive challenge. Contact and newsletter forms send submitted data through our relay to Zoho CRM; newsletters are delivered through Zoho Campaigns. See the Cookie Policy for the first-party inventory, third-party context and browser controls. Absence of a banner is not a statement that third-party requests or storage never occur.
Do Not Track. No uniform technical standard for Do Not Track (“DNT”) browser signals currently exists. Because there is no industry or legal consensus on how to interpret DNT, we do not currently respond to DNT signals. If a standard is adopted that we are required to follow, we will update this Policy accordingly.
Global Privacy Control. We do not sell personal data or share it for cross-context behavioral advertising. GPC signals concern those uses, not the service-provider disclosures described below. Any future change would require an updated notice and applicable opt-out controls before it begins.
8. Sharing and Sub-processors
We share personal data with a limited set of service providers who help us operate the Service, each bound by appropriate confidentiality and data protection terms. They include: cloud hosting and content delivery (Oracle Cloud Infrastructure for the platform; Cloudflare for the marketing website and its forms); CRM, support ticketing and marketing email (Zoho); transactional email delivery (ZeptoMail, a Zoho service); demo scheduling (Zoho Bookings) and video meetings (Zoom); error monitoring (Sentry); and sign-in geolocation (IPinfo). We have no payment processor, because we invoice directly. We may also disclose personal data to government or regulatory authorities where legally required. The current list of sub-processor categories, their purpose, and processing region, along with our change-notice and objection process, is maintained in one place, our Data Processing Agreement, rather than duplicated here.
We do not sell personal data, and we do not share personal data for cross-context behavioral advertising.
Notice of new sub-processors. Before engaging a new sub-processor that will process personal data on behalf of customers, including trial customers, we will provide at least 14 days’ advance notice by posting an update to the sub-processor list in our DPA and by email to the affected customer’s designated contact. If you reasonably object to a new sub-processor on data protection grounds, contact [email protected] within that notice period and we will work with you in good faith to address the objection, which may include making a commercially reasonable alternative available.
Business transfers. If Magdox is involved in a merger, acquisition, financing, or sale of all or substantially all of its assets, personal data may be transferred as part of that transaction. We will notify you before your personal data becomes subject to a different privacy policy as a result.
9. International Data Transfers
The FDIE platform is hosted in India. Customers that need their data kept outside India can deploy FDIE on-premises in their own environment. Hosting in India does not mean all processing stays there: listed providers, email delivery, support and customer-configured integrations may involve other countries. Cloudflare uses a global network. The DPA provider list describes these purposes and regions.
Where required for a restricted transfer, the parties must put an applicable transfer mechanism in place before that transfer: for example, the EU Standard Contractual Clauses with the appropriate module and completed annexes; the UK IDTA or EU clauses with the UK Addendum; or clauses adapted for Swiss law. Required transfer assessments and supplementary measures are part of that process. A region choice, acceptance of the Terms of Service or this public notice does not itself complete a transfer agreement. Contact [email protected] for the safeguards applicable to your deployment and a copy, subject to appropriate redactions.
10. Data Retention
- Ordinary account data is retained for the duration of your contract plus a 90-day post-contract window before scheduled deletion begins, subject to earlier valid deletion instructions. Statutory billing, tax and accounting records are separate: they are retained for the period the applicable law requires, rather than automatically erased after 90 days.
- Uploaded firmware images and analysis results are retained according to the retention policy configured by your organization’s administrators within FDIE. Where no custom retention period is configured, the post-subscription retention window is 90 days. Firmware then enters a 30-day recoverable deletion window before scheduled permanent removal. These are separate stages; the 90-day mark is not a claim that every stored copy has already been erased. An earlier valid erasure instruction under the DPA is handled separately.
- Technical and usage log data (Section 4) is retained on a rolling 1-year basis, independent of how long your account remains active, since indefinite retention of raw technical logs serves no purpose beyond that window.
- You may request deletion of your data at any time as described in Section 13.
The clocks above, and those in the Terms and the DPA, fit together as follows. A valid earlier deletion instruction takes priority over a general retention window. Restricted backups and records that law requires us to retain are handled separately; these exceptions do not permit continued use for unrelated purposes.
Scroll horizontally to see all columns.
| Event | What happens | When |
|---|---|---|
| Free trial ends without a subscription | Access is suspended; the organisation and its data are kept so you can subscribe later | Retained 30 days (Terms §7), then eligible for deletion |
| Paid subscription ends | Ordinary access ends with the paid term; an export arrangement follows, subject to security restrictions | At least 30 days to export (Terms §19), unless you request earlier deletion |
| Default deletion after a subscription ends | Account deletion is scheduled; firmware and results enter recoverable deletion | Starts after 90 days; firmware purge follows a further 30-day window |
| Written deletion request under the DPA | Personal data processed under the DPA is deleted or returned; certificate on request | Within 30 business days (DPA §13) |
| Account deletion requested in the product | The account enters the displayed deletion workflow; shared organization data requires the appropriate authority | 30-day grace before account purge; associated firmware then follows its deletion window |
| Firmware deleted by a user in the product | Soft-deleted and recoverable, then purged | Purged 30 days after deletion |
| Technical and usage logs | Rolling deletion regardless of account status | 1 year (this Section) |
| Audit log | Retained for administrators, longer on request | 1 year (Plan page) |
| Backups | Copies are isolated from ordinary use and expire under the deployment’s documented backup lifecycle; replication alone is not a backup | Request the deployment-specific retention and deletion schedule (Addendum §7.2) |
11. Data Security Measures
We implement technical and organizational measures designed to protect personal data. See our Security and Trust page for a detailed, plain-language description of our encryption, access-control, and audit logging practices.
12. Breach Notification
In the event of a personal data breach affecting your data, we will notify affected individuals or customers without undue delay, and in any case within 72 hours of becoming aware of the breach, providing the information reasonably available to us at that time. This commitment applies to trial and paid customers and website visitors. The 72-hour limit is a contractual outer limit, not permission to delay an earlier notification required by law. For Customer Data we notify the customer as controller, assist its response and coordinate communications to its data subjects. Controller notifications to regulators and individuals have their own legal conditions and deadlines; the customer remains responsible for its decisions. We provide further information in phases as it becomes available.
13. Your Rights (Global)
Depending on your location, you may have rights over the personal data we hold about you, which commonly include the right to access, correct, delete, restrict or object to processing, receive your data in a portable format, and withdraw consent. The regional sections below identify the specific regime that applies to you; where more than one could apply, contact us and we will apply the more protective standard.
13.1 India (DPDPA)
See our dedicated DPDPA rights page for your rights as a Data Principal under India’s Digital Personal Data Protection Act, 2023, including how to escalate a grievance to our Grievance Officer and the Data Protection Board of India.
13.2 United States
If you are a resident of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, or Virginia, you may have rights under that state’s comprehensive privacy law, which commonly include:
- The right to know whether we are processing your personal data, and to access it
- The right to correct inaccuracies in your personal data
- The right to request deletion of your personal data
- The right to obtain a copy of the personal data you previously provided to us
- The right to non-discrimination for exercising any of these rights
- The right to opt out of targeted advertising, the sale of personal data, or profiling used for decisions with legal or similarly significant effects. Magdox does not engage in any of these three practices today, so there is nothing to opt out of, but you retain the right to ask
Depending on your state, you may also have the right to: know the categories of personal data we process; obtain a list of the categories, or in some states the specific identities, of third parties we’ve disclosed personal data to; understand how any profiling of your data works; and limit the use of sensitive personal data. Authentication credentials may fall within a statutory sensitive-information category, and uploaded content can incidentally contain sensitive data. We use such data only for the disclosed service and security purposes and do not use it for advertising. We do not perform profiling that produces legal or similarly significant effects (Section 14).
Categories of personal information collected and disclosed in the past 12 months, using the categories defined under California’s privacy law as a common reference point other states’ laws substantially overlap with:
Scroll horizontally to see all columns.
| Category | Collected | Disclosed to service providers |
|---|---|---|
| Identifiers (name, email, IP address) | Yes | Yes |
| Personal information under the California Customer Records statute (name, billing address, job title) | Yes | Yes |
| Protected classification characteristics (race, gender, age, etc.) | No | No |
| Commercial information (subscription plan, billing history) | Yes | Yes |
| Biometric information | No | No |
| Internet or network activity | Yes | Yes |
| Geolocation data (IP-derived, approximate only; we do not collect GPS or precise location) | Yes | Yes |
| Audio, visual, or sensory data | If you participate in a video meeting | Meeting provider, for the call; recording only with advance notice and any required consent |
| Professional or employment information (job title) | Yes | Yes |
| Education records | No | No |
| Inferences or profiles built from the above | No | No |
| Sensitive personal information | Authentication credentials; potentially data in customer-supplied content | Restricted service providers where necessary for the disclosed purpose |
We retain Identifiers, California Customer Records information, and Professional/employment information for as long as you have an account with us, plus 90 days (Section 10). We retain Internet activity and Geolocation data on a rolling 1-year basis (Section 10). Commercial and statutory billing records follow the legal-retention exceptions in Section 10.
We have not sold or shared (as defined under applicable US state law) any personal information in the preceding 12 months. We have disclosed Identifiers, California Customer Records information, Commercial information, Internet activity, Geolocation data, and Professional/employment information to the categories of service providers described in Section 8, for the business purposes described in Section 5.
Authorized agents. You may designate an authorized agent to submit a request on your behalf under applicable state law. We may require proof that the agent has been validly authorized before acting on the request.
Verification. When you submit a rights request, we will verify your identity using the information already associated with your account, or, if necessary, by requesting additional information solely for identity-verification and fraud-prevention purposes.
Appeals. If we decline to act on your request, you may appeal by emailing [email protected]. We will respond in writing with the outcome of the appeal and our reasoning. If your appeal is denied, some states allow you to further complain to your state Attorney General.
13.3 European Economic Area, UK, and Switzerland (GDPR)
Where the GDPR, UK GDPR or Swiss Federal Act on Data Protection applies to our processing, you have the rights provided by that law. The rights and their exceptions differ between these regimes. You can ask to see the data we hold about you, ask us to correct it if it is wrong, or ask us to delete it. You can also restrict or object to how we process your data, including processing based on our legitimate interests, and ask for a copy of your data in a portable format. Where we process something based on your consent, you can withdraw that consent at any time, though this will not affect anything we did before you withdrew it. Section 6 explains the legal basis we rely on for each type of processing. To exercise any of these rights, contact [email protected].
If you believe we are unlawfully processing your personal data, you have the right to complain to your Member State’s data protection authority, the UK’s Information Commissioner’s Office, or, if you are in Switzerland, the Federal Data Protection and Information Commissioner.
13.4 How to Exercise Any of These Rights
To submit a request under any of the regimes above, contact [email protected] or use our Contact page, including your name, the email address associated with your account (if any), and a description of your request. Do not send passwords, authentication codes or identity documents unless we specifically request a necessary, secure verification step. We respond within the applicable legal deadline; for GDPR requests this is normally one month, with any permitted extension and its reason communicated within that month. If the request concerns a customer-controlled workspace, we will assist or refer it to that customer as appropriate.
14. Automated Analysis and Decision Support
FDIE’s compliance scores, CVE findings, and risk ratings are generated by deterministic, rule-based static analysis and sandboxed dynamic analysis (not generative AI or machine learning) and are intended as decision-support information for your security and engineering teams. They are not used by Magdox to make any solely-automated decision producing legal or similarly significant effects about an individual, and we do not build profiles of individuals from this data. See Terms of Service Section 15 for the scope and limitations of this analysis.
15. Children’s Privacy
The Service is not directed at, and is not intended for use by, individuals under the age of 18. We do not knowingly collect personal data from anyone under 18. If we learn that we have collected personal data from someone under 18, we will take reasonable steps to delete it and deactivate the associated account. Contact [email protected] if you believe we may have collected data from a minor.
16. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via the website or by email to registered account holders. The “Last updated” date at the top of this page reflects the most recent revision. Prior versions are archived and available on request.
17. Contact
Questions about this Privacy Policy can be sent to [email protected] or via our Contact page, or by post to:
MAGDOX Private Limited
St No. 8, Arabinda Nagar, Barbani, Bardhaman, Hindustan Cables, West Bengal 713335, India