Legal

Data Processing Agreement — Summary

Download Markdown · · Request signed DPA

Entity: Magoven (Pty) Ltd (Republic of South Africa)
Contact: [email protected] · +27 87 250 1000
Last updated: 14 July 2026

This page is a plain-language summary for procurement and vendor assessment. The signed Data Processing / operator agreement controls over this summary. It is not legal advice.

1. Roles

For organisation customers, Magoven typically acts as an operator (processor) of personal information on the customer's documented instructions. The customer remains the responsible party (controller) for workplace personal information placed in Magoven products.

2. Scope of processing

Magoven processes personal information solely to deliver Magoven One and entitled suite applications — authentication, tenancy, licensing, collaboration, support, and security monitoring.

3. Key commitments

  • Purpose limitation — processing only as needed to provide the Services
  • Confidentiality and staff access controls
  • Technical and organisational security measures appropriate to the risk
  • Use of subprocessors with flow-down obligations (list via [email protected])
  • Assistance with data subject requests and POPIA-related enquiries
  • Security incident notification and reasonable cooperation
  • Return or deletion of personal information at end of service, subject to legal retention

4. Retention

Customers may configure organisation retention targets in Magoven One (meetings, mail, files). Magoven retains operational logs and backups for a commercially reasonable window required for security, continuity, and legal obligations.

5. Assurance

Magoven maintains product security controls described on Security and the Trust Centre. Magoven does not currently claim completed SOC 2 Type II or ISO/IEC 27001 certification.

6. Next steps

Questions? Contact us or email [email protected].