Skip to main content
Legal

Privacy policy

What Magazengo does with personal data, why, for how long, and how to exercise your rights. Last updated: July 28, 2026.

This English translation is provided for convenience. In the event of any discrepancy, the French version prevails.

01

Two distinct roles

Magazengo is the controller for the data of merchants, visitors to the Magazengo website and people who contact the company. This policy describes those processing activities.

Magazengo is a processor for the data of the end customers of stores created with the service. In that case, the merchant determines the purposes and means of processing and responds to data subject requests. Magazengo’s commitments in that respect are set out in the data processing agreement. If you are a customer of a store, send your request to the merchant concerned, whose contact details appear in the legal notice of their store.

02

Controller and contact

The controller is DEVAXIS, whose full details appear in the legal notice. For any question about data protection, write to privacy@magazengo.com.

03

Processing activities

Only the data strictly necessary for each purpose is collected. Mandatory fields are indicated in the forms; if they are not filled in, the corresponding service cannot be provided.

PurposeDataLegal basisRetention
Creating and managing the merchant accountFirst and last name, email address, hashed password, sign-in identifierPerformance of the contractTerm of the contract, then 3 years from the last contact
Providing and administering the serviceStore data, settings, content, admin activity logsPerformance of the contractTerm of the contract, then 30 days
Billing and accountingIdentity, contact details, billing identifiers, amounts, invoices, payment provider identifierLegal obligation10 years from the end of the financial year
Support and customer relationsContact details, content of exchanges, technical details needed for diagnosisPerformance of the contract and legitimate interest3 years from the last exchange
Demo requests and prospectingName, email address, company, website, plan under consideration, messageConsent and pre-contractual steps3 years from the last contact
Security, fraud and abuse preventionIP address, technical headers, timestamps, authentication events, audit logsLegitimate interest and legal obligation12 months for technical logs, 6 years for audit logs
Service improvement and audience measurementInterface usage events, device type, pages viewedLegitimate interest25 months
Handling reports and complaintsIdentity of the reporting party, reported content, decision and reasoningLegal obligation and legitimate interest5 years

The periods given apply to the active database; beyond that, data may be archived with restricted access for the duration of the applicable limitation periods, then deleted or anonymised.

04

Source of the data

The data comes from the information you provide directly, from your use of the service, and from information passed on by the payment provider as part of subscription management. No data is acquired from data brokers.

05

Recipients and processors

The data is accessible only to authorised Magazengo staff, within the limits of their duties. It is also processed by providers acting on instruction and bound by a confidentiality undertaking: hosting and delivery, database and storage, payment provider, email delivery, audience measurement and artificial intelligence features.

The named and up-to-date list of these providers, their role and their location appears in the list of sub-processors.

Data may also be disclosed to administrative or judicial authorities where required by law, and to Magazengo’s legal advisers in defence of its rights.

06

Data location and transfers outside the European Union

Application data and store files are stored within the European Union. Audience measurement is carried out on the European infrastructure of the provider concerned.

Some providers are headquartered outside the European Union and may access the data from there for technical administration or support purposes. Such access is governed by the standard contractual clauses adopted by the European Commission on 4 June 2021, supplemented where necessary by additional technical and organisational measures and, where the provider is certified under it, by the EU–US Data Privacy Framework.

A copy of the safeguards in place can be obtained on request at privacy@magazengo.com.

07

Security

Magazengo implements technical and organisational measures appropriate to the risk: encryption of communications, password hashing, data partitioning per store, access control and permission management, logging of admin actions, regular backups with tested restoration, dependency reviews and up-to-date components. In the event of a data breach likely to result in a risk to the rights and freedoms of individuals, the French data protection authority (CNIL) is notified within 72 hours and the individuals concerned are informed where the risk is high.

08

Artificial intelligence

When you use the AI assistance features, the content of your instructions and the necessary context is sent to the model provider, on the basis of performance of the contract. This content is not used to train models. You are asked not to include sensitive data or third-party confidential information in it.

09

Automated decision-making and profiling

Magazengo makes no decision producing legal effects or significantly affecting you based solely on automated processing. Automated abuse and fraud detection systems may trigger a review; any suspension or termination measure is subject to human review and is reasoned.

10

Your rights

You have the rights of access, rectification, erasure, restriction, portability, objection to processing based on legitimate interest, withdrawal of consent at any time where processing is based on it, and the right to set instructions regarding what happens to your data after your death.

To exercise them, write to privacy@magazengo.com. You will receive a reply within one month, extendable by two months for complex requests. Proof of identity may be requested where there is reasonable doubt as to your identity.

You may lodge a complaint with the French data protection authority (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 — cnil.fr.

11

Cookies and trackers

The conditions under which cookies and trackers are placed and read, and how to refuse them, are set out in the cookie policy.

12

Changes

This policy may be updated to reflect legal or technical developments. In the event of a substantial change, the individuals concerned are informed by appropriate means. Last updated: July 28, 2026.