Data Processing Addendum (DPA)
Standard contractual commitments and data protection safeguards governing controller-processor interactions.
Legal Notice
This document constitutes a binding agreement for MagnusOp merchants and platform users. If you have questions regarding these terms, please contact our compliance team at [email protected].
Scope & Applicability
This Data Processing Addendum ("DPA") supplements the MagnusOp Terms of Service and applies where MagnusOp processes Personal Data on behalf of the Merchant in the course of providing multi-tenant commerce services.
Roles of the Parties
The Merchant acts as the Data Controller (determining the purposes and means of customer data processing), and MagnusOp acts as the Data Processor. MagnusOp processes Personal Data strictly pursuant to documented merchant instructions.
Technical & Organizational Security Measures
MagnusOp implements comprehensive technical measures to protect Personal Data against unauthorized access, accidental loss, and destruction:
- End-to-end TLS encryption for all data in transit.
- Database-level tenant isolation enforced by PostgreSQL Row Level Security (RLS).
- Automated daily encrypted backups with point-in-time recovery capabilities.
- Mandatory two-factor authentication (TOTP) for platform operations staff.
Data Breach Notification
In the event of a confirmed security incident affecting Personal Data, MagnusOp will notify affected merchants without undue delay (and in any event within 48 hours of becoming aware of the breach), providing reasonable details and mitigation guidance.