Regulatory & Standards Compliance
Frameworks, data sovereignty commitments, and payment security standards implemented across MagnusOp.
Legal Notice
This document constitutes a binding agreement for MagnusOp merchants and platform users. If you have questions regarding these terms, please contact our compliance team at [email protected].
Data Protection Regulations (NDPR & GDPR)
MagnusOp is architected to satisfy the stringent requirements of the Nigeria Data Protection Regulation (NDPR) and the European Union General Data Protection Regulation (GDPR). Our system includes built-in data minimization, encryption at rest, and automated data subject rights fulfillment tools.
Payment Card Industry Data Security Standards (PCI-DSS)
MagnusOp adheres to PCI-DSS Level 1 compliance requirements. Raw credit card data never touches or persists on our application servers. Payment tokenization, inline checkout iframes, and settlement workflows are handled directly by PCI-certified payment partners (Paystack and Flutterwave).
Immutable Audit Logging & Governance
All administrative actions, merchant support sessions, and platform mutations are recorded in append-only audit tables with tamper-evident HMAC device signatures. Table permissions for audit records strictly revoke UPDATE and DELETE privileges from public roles.