Privacy policy
What Magazengo does with personal data, why, for how long, and how to exercise your rights. Last updated: July 28, 2026.
This English translation is provided for convenience. In the event of any discrepancy, the French version prevails.
01
Two distinct roles
Magazengo is the controller for the data of merchants, visitors to the Magazengo website and people who contact the company. This policy describes those processing activities.
Magazengo is a processor for the data of the end customers of stores created with the service. In that case, the merchant determines the purposes and means of processing and responds to data subject requests. Magazengo’s commitments in that respect are set out in the data processing agreement. If you are a customer of a store, send your request to the merchant concerned, whose contact details appear in the legal notice of their store.
02
Controller and contact
The controller is DEVAXIS, whose full details appear in the legal notice. For any question about data protection, write to privacy@magazengo.com.
03
Processing activities
Only the data strictly necessary for each purpose is collected. Mandatory fields are indicated in the forms; if they are not filled in, the corresponding service cannot be provided.
| Purpose | Data | Legal basis | Retention |
|---|---|---|---|
| Creating and managing the merchant account | First and last name, email address, hashed password, sign-in identifier | Performance of the contract | Term of the contract, then 3 years from the last contact |
| Providing and administering the service | Store data, settings, content, admin activity logs | Performance of the contract | Term of the contract, then 30 days |
| Billing and accounting | Identity, contact details, billing identifiers, amounts, invoices, payment provider identifier | Legal obligation | 10 years from the end of the financial year |
| Support and customer relations | Contact details, content of exchanges, technical details needed for diagnosis | Performance of the contract and legitimate interest | 3 years from the last exchange |
| Demo requests and prospecting | Name, email address, company, website, plan under consideration, message | Consent and pre-contractual steps | 3 years from the last contact |
| Security, fraud and abuse prevention | IP address, technical headers, timestamps, authentication events, audit logs | Legitimate interest and legal obligation | 12 months for technical logs, 6 years for audit logs |
| Service improvement and audience measurement | Interface usage events, device type, pages viewed | Legitimate interest | 25 months |
| Handling reports and complaints | Identity of the reporting party, reported content, decision and reasoning | Legal obligation and legitimate interest | 5 years |
The periods given apply to the active database; beyond that, data may be archived with restricted access for the duration of the applicable limitation periods, then deleted or anonymised.
04
Source of the data
The data comes from the information you provide directly, from your use of the service, and from information passed on by the payment provider as part of subscription management. No data is acquired from data brokers.
05
Recipients and processors
The data is accessible only to authorised Magazengo staff, within the limits of their duties. It is also processed by providers acting on instruction and bound by a confidentiality undertaking: hosting and delivery, database and storage, payment provider, email delivery, audience measurement and artificial intelligence features.
The named and up-to-date list of these providers, their role and their location appears in the list of sub-processors.
Data may also be disclosed to administrative or judicial authorities where required by law, and to Magazengo’s legal advisers in defence of its rights.
06
Data location and transfers outside the European Union
Application data and store files are stored within the European Union. Audience measurement is carried out on the European infrastructure of the provider concerned.
Some providers are headquartered outside the European Union and may access the data from there for technical administration or support purposes. Such access is governed by the standard contractual clauses adopted by the European Commission on 4 June 2021, supplemented where necessary by additional technical and organisational measures and, where the provider is certified under it, by the EU–US Data Privacy Framework.
A copy of the safeguards in place can be obtained on request at privacy@magazengo.com.
07
Security
Magazengo implements technical and organisational measures appropriate to the risk: encryption of communications, password hashing, data partitioning per store, access control and permission management, logging of admin actions, regular backups with tested restoration, dependency reviews and up-to-date components. In the event of a data breach likely to result in a risk to the rights and freedoms of individuals, the French data protection authority (CNIL) is notified within 72 hours and the individuals concerned are informed where the risk is high.
08
Artificial intelligence
When you use the AI assistance features, the content of your instructions and the necessary context is sent to the model provider, on the basis of performance of the contract. This content is not used to train models. You are asked not to include sensitive data or third-party confidential information in it.
09
Automated decision-making and profiling
Magazengo makes no decision producing legal effects or significantly affecting you based solely on automated processing. Automated abuse and fraud detection systems may trigger a review; any suspension or termination measure is subject to human review and is reasoned.
10
Your rights
You have the rights of access, rectification, erasure, restriction, portability, objection to processing based on legitimate interest, withdrawal of consent at any time where processing is based on it, and the right to set instructions regarding what happens to your data after your death.
To exercise them, write to privacy@magazengo.com. You will receive a reply within one month, extendable by two months for complex requests. Proof of identity may be requested where there is reasonable doubt as to your identity.
You may lodge a complaint with the French data protection authority (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 — cnil.fr.
11
Cookies and trackers
The conditions under which cookies and trackers are placed and read, and how to refuse them, are set out in the cookie policy.
12
Changes
This policy may be updated to reflect legal or technical developments. In the event of a substantial change, the individuals concerned are informed by appropriate means. Last updated: July 28, 2026.