Data processing agreement
Magazengo’s commitments when it processes the data of a merchant’s store customers on their behalf. Version 2.0 — July 28, 2026.
This English translation is provided for convenience. In the event of any discrepancy, the French version prevails.
01
Purpose and status of the parties
This agreement supplements the terms and conditions and sets out the respective obligations of the customer (the “Merchant”) and DEVAXIS (“Magazengo”) regarding the processing of the personal data of the store’s end customers and visitors. It is entered into pursuant to article 28 of Regulation (EU) 2016/679 (the “GDPR”) and is accepted by the Merchant upon subscription.
The Merchant is the controller: they determine the purposes and means of processing, ensure they have a legal basis, inform data subjects and respond to their requests. Magazengo is the processor: it processes this data solely on the Merchant’s documented instructions.
02
Description of the processing
Subject matter and nature. Hosting, storage, structuring, consultation, transmission and deletion of the data required to operate the Merchant’s online store.
Purposes. Enabling the display of the catalog, the management of customer accounts, order placement and tracking, the delivery of transactional emails, the production of audience statistics and the security of the store.
Duration. The term of the subscription, extended by the retrieval and deletion periods set out below.
Categories of data subjects. The Merchant’s customers and prospects, store visitors, and the people designated by the Merchant as users of their admin area.
Categories of data. Identity and contact details, delivery and billing addresses, order content and history, exchanges with customer service, sign-in credentials, technical connection and browsing data. No complete payment card data is stored by Magazengo; payment is handled by the payment provider.
The Merchant undertakes not to process, by means of the service, special categories of data within the meaning of article 9 GDPR, or data relating to criminal convictions, without having first informed Magazengo and agreed in writing on the additional measures required.
03
Merchant’s instructions
Magazengo processes the data solely on the Merchant’s documented instructions, consisting of this agreement, the terms and conditions and the settings configured by the Merchant in their admin area. Magazengo informs the Merchant if an instruction appears to infringe the GDPR or another data protection provision, and may suspend its execution pending written confirmation. Magazengo may process the data where required to do so by Union or Member State law; in that case it informs the Merchant before processing, unless prohibited by law.
04
Confidentiality and personnel
Magazengo ensures that persons authorised to process the data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, receive the necessary training, and access the data only to the extent strictly required by their duties.
05
Security
Magazengo implements the appropriate technical and organisational measures required by article 32 GDPR, in particular:
- — encryption of data in transit and encryption of data at rest;
- — logical partitioning of data per store and systematic checks that data belongs to the store being queried;
- — permission management based on the principle of least privilege and strong authentication for admin access;
- — logging of admin actions and retention of audit logs;
- — regular, encrypted backups with a periodically tested restoration procedure;
- — keeping components up to date, reviewing dependencies and fixing vulnerabilities according to their severity;
- — a documented procedure for handling incidents and data breaches.
The Merchant remains responsible for the measures within their own scope, in particular the strength and confidentiality of their users’ credentials, the management of the access they grant, and the security of the code and extensions they add to their store.
06
Sub-processors
The Merchant gives Magazengo general authorisation to use the sub-processors listed below. Magazengo contractually imposes on them data protection obligations equivalent to those in this agreement and remains fully liable to the Merchant for their performance.
Magazengo informs the Merchant of any addition or replacement of a sub-processor at least thirty (30) days before it takes effect. The Merchant may object on legitimate and documented grounds within that period; failing a reasonable alternative, either party may terminate the subscription without charge or penalty, with amounts corresponding to periods not provided being refunded.
| Sub-processor | Role | Location | Safeguards |
|---|---|---|---|
| Supabase | Database and storage of store files | European Union | Processing within the European Union |
| Vercel | Application hosting, page delivery and technical logs | European Union, with support from the United States | Standard contractual clauses |
| Stripe | Payment collection and subscription management | Ireland, with access from the United States | Standard contractual clauses |
| Resend | Delivery of transactional emails | United States | Standard contractual clauses |
| PostHog | Audience measurement for stores and the merchant area | European Union | Processing within the European Union |
| Mistral AI | Artificial intelligence assistance and generation features | France | Processing within the European Union |
07
Transfers outside the European Union
Store data is stored within the European Union. Where a sub-processor may access the data from a third country, the transfer is governed by the standard contractual clauses adopted by the European Commission on 4 June 2021, supplemented where necessary by additional technical and organisational measures and, where the provider is certified under it, by the EU–US Data Privacy Framework. A copy of the safeguards is provided on request.
08
Assistance to the Merchant
Taking into account the nature of the processing, Magazengo assists the Merchant in:
- — responding to data subject requests, by providing the access, export, rectification and deletion functions of their admin area; if a request is sent directly to Magazengo, it forwards it to the Merchant without delay and does not respond to it itself;
- — ensuring compliance with the obligations of security, breach notification and, where required, carrying out a data protection impact assessment, by providing the necessary technical information.
The self-service functions mentioned above are included in every plan and allow the Merchant to respond to data subject requests themselves within the statutory deadlines. Any request for additional bespoke work or assistance (manual handling of a request, specific extraction, support with an impact assessment or with managing a breach) is subject to a prior quote. This charging does not prevent Magazengo from performing its assistance obligations under article 28 GDPR, nor the Merchant from meeting their own statutory deadlines.
09
Data breaches
Magazengo notifies the Merchant of any personal data breach concerning them as soon as possible and no later than forty-eight (48) hours after becoming aware of it. The notification describes the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences and the measures taken or proposed. It is for the Merchant, as controller, to notify the supervisory authority and to inform the data subjects where applicable.
10
Documentation and audit
Magazengo makes available to the Merchant the information necessary to demonstrate compliance with the obligations of this agreement. The Merchant may request, at most once per calendar year and subject to reasonable notice of thirty (30) days, a completed security questionnaire or, where applicable, the available audit or certification reports. An on-site audit carried out by an independent third party that is not a competitor of Magazengo may be arranged where those materials prove insufficient or following a data breach; it is then subject to a confidentiality undertaking, conducted during business hours without disrupting operations, and its costs are borne by the Merchant unless a significant breach attributable to Magazengo is established.
11
Fate of the data at the end of the contract
When provision of the service ends, the Merchant has thirty (30) days to export the data from their admin area. Once that period expires, and according to the choice expressed by the Merchant, Magazengo deletes the data or returns it in a structured and commonly used format, then deletes existing copies. Excepted from this is data whose retention is required by Union or Member State law, in particular accounting records, as well as encrypted backups subject to automatic rotation not exceeding thirty-five (35) days, which remain inaccessible in day-to-day operations.
12
Contact
Any request relating to this agreement should be sent to privacy@magazengo.com. The processing activities for which Magazengo acts as controller are described in the privacy policy.