Legal

Legal & Compliance

Last updated: 17 July 2026

Magoven (Pty) Ltd builds Magoven One and the Magoven suite — magMeet, magWork, magMail, MagDocs, MagDrive, magCalendar, and NetSpeed — for South African organisations that need practical governance, POPIA-aware processing, and local commercial support. This page summarises how legal and compliance topics fit together. It is not legal advice.

1. Corporate identity

  • Legal entity: Magoven (Pty) Ltd (Republic of South Africa)
  • Primary contact: [email protected] · +27 87 250 1000
  • Commercial contracts and DPAs: available on request for enterprise packages

2. POPIA alignment

Magoven designs Magoven One controls to support responsible-party customers under POPIA, including:

  • Organisation tenancy with roles, groups, and least-privilege administration
  • DNS domain verification to reduce spoofed org claims
  • Optional SSO (OIDC/SAML) and SCIM provisioning for workforce lifecycle
  • Guest access with limited app surface and expiring tokens
  • Audit export (CSV/JSON) for SSO, membership, and SCIM events
  • Policy hooks for meetings, sharing, and external collaboration

Customers remain responsible parties for most workplace personal information they place in Magoven products. See our Privacy Policy and Trust Centre.

3. Data Processing Agreements (DPA)

Enterprise customers may request a Magoven Data Processing / operator agreement covering purpose limitation, confidentiality, security measures, subprocessor use, assistance with data subject requests, breach notice, and return or deletion of personal information at end of engagement. Request via Contact Sales or [email protected]. A plain-language summary appears in the Trust Centre.

4. Security programme & assurance roadmap

Magoven maintains technical and organisational security measures described on our Security page and Trust Centre. We are investing in formal assurance documentation suitable for vendor reviews (policies, risk assessments, access control, change management). Magoven does not currently claim completed SOC 2 Type II or ISO/IEC 27001 certification. Where we reference a roadmap, it describes intent — not a live certification. Procurement teams should rely on our current controls packet and responses to questionnaires rather than assumed logos.

5. Subprocessors

Magoven uses vetted operators for hosting, email, payments, and related infrastructure. A current list is available to customers under NDA or standard procurement process via [email protected]. Material changes are communicated per DPA terms where applicable.

6. Document map

7. Global privacy frameworks

Magoven designs controls to support customers subject to multiple regimes. The table below is a high-level summary — your contract and Privacy Policy govern specifics.

  • POPIA (South Africa) — primary framework; Information Officer enquiries via [email protected]
  • GDPR / UK GDPR — DPA, subprocessors, cross-border safeguards, assistance with data subject requests
  • CCPA / CPRA (California) — no sale of personal information; know/delete/correct via data rights portal
  • LGPD (Brazil), PIPEDA (Canada), PDPA (Singapore), Privacy Act (Australia), APPI (Japan) — rights handled case-by-case per local law

Signed-in users: Privacy & data rights. Public API: /api/public/compliance-config for suite app integration.

8. Law enforcement and government requests

Magoven reviews legal requests for Customer Content carefully and discloses only when we believe disclosure is required by applicable law. Where legally permitted, we notify the affected customer.

9. Compliance pack requests

For security questionnaires, SIG-style forms, penetration-test summaries (when available), insurance certificates, or signed DPAs, email [email protected] with your organisation name and timeline, or use Magoven One Contact Sales.

Questions? Contact us or email [email protected].