Data Processing Agreement
Last updated: 26 August 2026
This agreement sets out how Magni Solutions ehf. handles personal data on behalf of a customer using Magni. It forms part of the subscription agreement between us and applies for as long as that agreement is in force.
It is written to meet Article 28 of the GDPR. Our privacy policy describes the same processing to the people whose data it is; this agreement states what we owe you, as our customer, about the data you put into Magni.
1. The parties
Magni Solutions ehf. (“Magni”, “we”, “us”), registration number 690426-1370, Gjáhella 4, 221 Hafnarfjörður, Iceland, and the organisation that subscribes to Magni (“you”).
Write to [email protected] about anything in this agreement.
2. Who decides what
You are the controller of the operational content you put into Magni — your assets, components, work orders, service reports, maintenance schedules, contacts, technicians, and the documents, photographs and scans you upload. You decide what goes in and why. We are your processor for that content and act on your instructions.
We are the controller, not your processor, for the accounts people hold in Magni, for the technical records we keep to run and secure the service, and for visitors to our public website. That processing is described in our privacy policy and sits outside this agreement.
Where one person appears on both sides — an employee of yours who holds an account and is also named in a work order — the split follows the data, not the person.
3. What we process for you
Annex I states the subject matter and duration of the processing, its nature and purpose, the categories of people involved and the types of personal data, as Article 28(3) requires.
4. Your instructions
We process your content only on your documented instructions. The subscription agreement, this agreement, and your own configuration and use of the platform are those instructions. Anything outside them needs to be in writing.
We do not use your content for our own purposes. We do not sell it, we do not use it for advertising, and we do not use it to train AI models. Nor may our AI provider: Anthropic's commercial terms bar it from training models on the content we send when one of your users asks for a draft service report.
If we believe an instruction breaks data protection law we will tell you, and we may hold that instruction until it is resolved.
5. Confidentiality
The people at Magni who can reach your content are bound to confidentiality, and are limited to those who need access to run the service, support you, or fix a fault.
6. Security
Annex II lists the measures in place. We may change them as the service changes, but not in a way that lowers the level of protection.
7. Sub-processors
You authorise the sub-processors listed in Annex III. Each is bound by data protection terms no weaker than the ones in this agreement, and we remain responsible to you for what they do with your content.
We will tell you at least 30 days before a new sub-processor starts processing your content, by email to the administrator contact on your account. If you object on reasonable data-protection grounds inside those 30 days, we will look for a way round it with you; if there is none, you may end the part of the service that depends on it.
Analytics on our public website is our own processing as controller and touches no content of yours, so the provider we use for it is not a sub-processor under this agreement.
8. Requests from the people whose data it is
If someone asks us to see, correct, delete or move data we hold for you, we will pass the request to you rather than act on it ourselves, and tell them we have done so.
We will help you answer inside the time the law gives you. Much of it you can do yourself: your content is yours to find, correct and delete in the platform.
We will also help with a data protection impact assessment or a prior consultation, so far as the information sits with us rather than with you.
9. If there is a breach
We will tell you about a personal data breach affecting your content without undue delay, and no later than 48 hours after we become aware of it. We will say what happened, which data and roughly how many people are affected, what we are doing about it, and who to talk to. If we do not know all of that at first, we will send what we have and follow up.
Notifying a supervisory authority and the people affected is your duty as controller. We will give you what you need to do it.
10. Where the data is
Our application and our database run in London, and our file storage is in Amsterdam. Annex III says where each sub-processor processes your content.
Iceland is in the EEA, so your content reaching us is not itself a restricted transfer. For the United Kingdom we rely on the European Commission's adequacy decision of 19 December 2025, which runs until 27 December 2031.
For a sub-processor in the United States we rely on the EU–US Data Privacy Framework where that provider is certified under it, and otherwise on the Standard Contractual Clauses annexed to Commission Implementing Decision (EU) 2021/914, Module Three, which we conclude with the provider. Annex I and Annex II supply the processing details and the security measures those clauses call for. Ask us which route applies to a given provider and we will send you a copy.
11. Audit and information
We will answer reasonable questions and security questionnaires about this processing, and give you what you need to show that you meet Article 28.
You may audit us once in any twelve months, and more often if a supervisory authority requires it or after a breach affecting your content. Give us 30 days' notice, keep what you learn confidential, and expect us to protect other customers' data and the running service while you do it.
12. When the agreement ends
On written request, and in any case within 30 days of the end of the subscription agreement, we delete your content and the records describing changes to it — or return it to you in a machine-readable form first, if you ask for that.
We keep only what the law requires us to keep, and we will tell you what that is. Backups age out on the cycle in Annex II rather than being edited.
13. Signing, precedence and changes
Accepting the subscription agreement accepts this agreement. Ask us if you need a countersigned copy for your records.
On the handling of personal data, this agreement prevails over the subscription agreement, and Standard Contractual Clauses prevail over this agreement. Liability under this agreement is subject to the limits in the subscription agreement, and the law and forum named there govern it.
We will tell you at least 30 days before a change to this agreement that affects you, through the application or by email.
Annex I — Details of the processing
| Item | Detail |
|---|---|
| Subject matter | Providing the Magni platform to you under the subscription agreement |
| Duration | The term of the subscription agreement, plus the deletion window in section 12 |
| Nature and purpose | Storing, organising, indexing, displaying, backing up and transmitting the content you enter so that you can manage industrial assets and the work done on them; producing the documents and reports you ask for; delivering an invitation email when you share a work order; producing a draft service report when one of your users asks for one |
| Categories of people | Your employees and contractors who hold Magni accounts; the technicians and contacts you record; the people you share a work order with; anyone named in the free text, documents or images you upload |
| Types of personal data | Name, email address, telephone number, work location, role, user identifier, sign-in and activity records, and whatever personal data appears in the free text, documents, photographs and scans you enter |
| Special categories | None. We do not ask for the categories listed in Article 9, and we ask you not to record them in Magni |
| Frequency | Continuous, for as long as you use the platform |
Annex II — Security measures
This is what protects your content today.
- Traffic between a browser and Magni is encrypted in transit.
- Every request is scoped on the server to the organisations the account belongs to, so one organisation cannot read another's content. The boundary is applied server-side, not in the browser.
- The managed database accepts connections only from our application and a short list of named addresses.
- Credentials and keys are held as platform secrets, never in source control.
- Changes made through the API are recorded with who made them, when, what was submitted and what came back.
- Documents and reports are rendered inside our own infrastructure rather than by an outside service.
- The managed database platform encrypts data at rest, takes a full backup every day, and keeps write-ahead logs so the cluster can be restored to any point in the previous seven days.
- Access to production is limited to the Magni personnel who need it.
We do not hold ISO 27001 or SOC 2 certification. If you need a specific control, ask and we will tell you whether we have it.
Annex III — Sub-processors
| Sub-processor | What it does | Where it processes |
|---|---|---|
| PropelAuth | Authentication, user accounts and organisation membership | United States |
| DigitalOcean | Application hosting and our managed database (London), and file storage (Amsterdam) | United Kingdom and Netherlands |
| SendGrid | Delivering the email that invites someone to a shared work order | United States |
| PostHog | Error reports, performance measurement and session recording | European Union and United States |
| Mapbox | Map tiles requested by the browser when a page shows a map | United States |
| Anthropic | Generating a draft service report when a user asks for one | United States |