Magni

Data Processing Agreement

Last updated: 26 August 2026

This agreement sets out how Magni Solutions ehf. handles personal data on behalf of a customer using Magni. It forms part of the subscription agreement between us and applies for as long as that agreement is in force.

It is written to meet Article 28 of the GDPR. Our privacy policy describes the same processing to the people whose data it is; this agreement states what we owe you, as our customer, about the data you put into Magni.

1. The parties

Magni Solutions ehf. (“Magni”, “we”, “us”), registration number 690426-1370, Gjáhella 4, 221 Hafnarfjörður, Iceland, and the organisation that subscribes to Magni (“you”).

Write to [email protected] about anything in this agreement.

2. Who decides what

You are the controller of the operational content you put into Magni — your assets, components, work orders, service reports, maintenance schedules, contacts, technicians, and the documents, photographs and scans you upload. You decide what goes in and why. We are your processor for that content and act on your instructions.

We are the controller, not your processor, for the accounts people hold in Magni, for the technical records we keep to run and secure the service, and for visitors to our public website. That processing is described in our privacy policy and sits outside this agreement.

Where one person appears on both sides — an employee of yours who holds an account and is also named in a work order — the split follows the data, not the person.

3. What we process for you

Annex I states the subject matter and duration of the processing, its nature and purpose, the categories of people involved and the types of personal data, as Article 28(3) requires.

4. Your instructions

We process your content only on your documented instructions. The subscription agreement, this agreement, and your own configuration and use of the platform are those instructions. Anything outside them needs to be in writing.

We do not use your content for our own purposes. We do not sell it, we do not use it for advertising, and we do not use it to train AI models. Nor may our AI provider: Anthropic's commercial terms bar it from training models on the content we send when one of your users asks for a draft service report.

If we believe an instruction breaks data protection law we will tell you, and we may hold that instruction until it is resolved.

5. Confidentiality

The people at Magni who can reach your content are bound to confidentiality, and are limited to those who need access to run the service, support you, or fix a fault.

6. Security

Annex II lists the measures in place. We may change them as the service changes, but not in a way that lowers the level of protection.

7. Sub-processors

You authorise the sub-processors listed in Annex III. Each is bound by data protection terms no weaker than the ones in this agreement, and we remain responsible to you for what they do with your content.

We will tell you at least 30 days before a new sub-processor starts processing your content, by email to the administrator contact on your account. If you object on reasonable data-protection grounds inside those 30 days, we will look for a way round it with you; if there is none, you may end the part of the service that depends on it.

Analytics on our public website is our own processing as controller and touches no content of yours, so the provider we use for it is not a sub-processor under this agreement.

8. Requests from the people whose data it is

If someone asks us to see, correct, delete or move data we hold for you, we will pass the request to you rather than act on it ourselves, and tell them we have done so.

We will help you answer inside the time the law gives you. Much of it you can do yourself: your content is yours to find, correct and delete in the platform.

We will also help with a data protection impact assessment or a prior consultation, so far as the information sits with us rather than with you.

9. If there is a breach

We will tell you about a personal data breach affecting your content without undue delay, and no later than 48 hours after we become aware of it. We will say what happened, which data and roughly how many people are affected, what we are doing about it, and who to talk to. If we do not know all of that at first, we will send what we have and follow up.

Notifying a supervisory authority and the people affected is your duty as controller. We will give you what you need to do it.

10. Where the data is

Our application and our database run in London, and our file storage is in Amsterdam. Annex III says where each sub-processor processes your content.

Iceland is in the EEA, so your content reaching us is not itself a restricted transfer. For the United Kingdom we rely on the European Commission's adequacy decision of 19 December 2025, which runs until 27 December 2031.

For a sub-processor in the United States we rely on the EU–US Data Privacy Framework where that provider is certified under it, and otherwise on the Standard Contractual Clauses annexed to Commission Implementing Decision (EU) 2021/914, Module Three, which we conclude with the provider. Annex I and Annex II supply the processing details and the security measures those clauses call for. Ask us which route applies to a given provider and we will send you a copy.

11. Audit and information

We will answer reasonable questions and security questionnaires about this processing, and give you what you need to show that you meet Article 28.

You may audit us once in any twelve months, and more often if a supervisory authority requires it or after a breach affecting your content. Give us 30 days' notice, keep what you learn confidential, and expect us to protect other customers' data and the running service while you do it.

12. When the agreement ends

On written request, and in any case within 30 days of the end of the subscription agreement, we delete your content and the records describing changes to it — or return it to you in a machine-readable form first, if you ask for that.

We keep only what the law requires us to keep, and we will tell you what that is. Backups age out on the cycle in Annex II rather than being edited.

13. Signing, precedence and changes

Accepting the subscription agreement accepts this agreement. Ask us if you need a countersigned copy for your records.

On the handling of personal data, this agreement prevails over the subscription agreement, and Standard Contractual Clauses prevail over this agreement. Liability under this agreement is subject to the limits in the subscription agreement, and the law and forum named there govern it.

We will tell you at least 30 days before a change to this agreement that affects you, through the application or by email.

Annex I — Details of the processing

ItemDetail
Subject matterProviding the Magni platform to you under the subscription agreement
DurationThe term of the subscription agreement, plus the deletion window in section 12
Nature and purposeStoring, organising, indexing, displaying, backing up and transmitting the content you enter so that you can manage industrial assets and the work done on them; producing the documents and reports you ask for; delivering an invitation email when you share a work order; producing a draft service report when one of your users asks for one
Categories of peopleYour employees and contractors who hold Magni accounts; the technicians and contacts you record; the people you share a work order with; anyone named in the free text, documents or images you upload
Types of personal dataName, email address, telephone number, work location, role, user identifier, sign-in and activity records, and whatever personal data appears in the free text, documents, photographs and scans you enter
Special categoriesNone. We do not ask for the categories listed in Article 9, and we ask you not to record them in Magni
FrequencyContinuous, for as long as you use the platform

Annex II — Security measures

This is what protects your content today.

We do not hold ISO 27001 or SOC 2 certification. If you need a specific control, ask and we will tell you whether we have it.

Annex III — Sub-processors

Sub-processorWhat it doesWhere it processes
PropelAuthAuthentication, user accounts and organisation membershipUnited States
DigitalOceanApplication hosting and our managed database (London), and file storage (Amsterdam)United Kingdom and Netherlands
SendGridDelivering the email that invites someone to a shared work orderUnited States
PostHogError reports, performance measurement and session recordingEuropean Union and United States
MapboxMap tiles requested by the browser when a page shows a mapUnited States
AnthropicGenerating a draft service report when a user asks for oneUnited States