# Magoven Data Processing Agreement — Summary

**Entity:** Magoven (Pty) Ltd (Republic of South Africa)  
**Product:** Magoven One and entitled suite apps (magMeet, magWork, magMail, MagDocs, MagDrive, magCalendar, NetSpeed)  
**Contact:** info@magoven.io · +27 87 250 1000  
**Last updated:** 14 July 2026

> This document is a plain-language summary for procurement and vendor assessment. The signed Data Processing / operator agreement controls over this summary.

## 1. Roles

For organisation customers, Magoven typically acts as an **operator** (processor) of personal information on the customer's documented instructions. The customer remains the **responsible party** (controller) for workplace personal information they place in Magoven products.

## 2. Scope of processing

Magoven processes personal information solely to deliver Magoven One and entitled suite applications, including authentication, tenancy, licensing, collaboration features, support, and security monitoring.

## 3. Key commitments (high level)

- **Purpose limitation** — processing only as needed to provide the Services
- **Confidentiality** — staff access controls and confidentiality obligations
- **Security** — technical and organisational measures appropriate to the risk
- **Subprocessors** — vetted operators with flow-down obligations; current list via info@magoven.io
- **Data subject requests** — reasonable assistance with POPIA-related enquiries
- **Incidents** — security incident notification and cooperation per agreement terms
- **End of service** — return or deletion of personal information, subject to legal retention

## 4. Retention

Customers may configure organisation retention policy targets in Magoven One (meetings, mail, files). Magoven retains operational logs and backups for a commercially reasonable window required for security, continuity, and legal obligations.

## 5. International transfers

Where data is hosted or processed using operators outside South Africa, Magoven uses contractual and organisational measures consistent with applicable law and the DPA.

## 6. Assurance

Magoven maintains product security controls (SSO/SCIM, domain verification, audit export, guest access, policy enforcement). Magoven does **not** currently claim completed SOC 2 Type II or ISO/IEC 27001 certification. Request the live controls packet instead of relying on marketing logos.

## 7. Request the signed template

Email **info@magoven.io** with subject “DPA request” including your organisation name, package interest, and preferred contact. For security questionnaires, use the same address with subject “Security questionnaire”.

---

© Magoven (Pty) Ltd. Not legal advice.
