Data Processing Addendum
Last updated June 1, 2026.
1. Roles
For most personal data processed through Master, the customer is the Controller and Master is the Processor. Where Master processes data for its own purposes (billing, security), Master is the Controller for that data.
2. Subject-matter and duration
Processing covers the data the customer submits to Master and lasts for the term of the underlying agreement, plus retention periods set out in the Privacy Policy.
3. Sub-processors
Master engages sub-processors to provide hosting, payments, email and AI services. A current list with locations is maintained at master-magic.dev/security. Customers are notified before new sub-processors are engaged.
4. Security measures
Technical and organisational measures include encryption in transit (TLS 1.2+) and at rest (AES-256), row-level security, role-based access, audit logging, secret management, regular backups, vulnerability scanning and an incident response runbook.
5. International transfers
Where personal data is transferred outside the EEA, Master relies on the EU Standard Contractual Clauses (Modules 2 / 3 as applicable) and the UK Addendum, plus supplementary measures where required.
6. Data subject rights
Master assists the customer in responding to data-subject requests via account tools and direct support, taking into account the nature of the processing.
7. Breach notification
Master will notify the customer without undue delay (and in any case within 72 hours of becoming aware) of any personal data breach affecting customer data.
8. Audits
Master makes available the information necessary to demonstrate compliance, including security questionnaires (CAIQ-Lite, SIG-Lite) and the latest pen-test summary under NDA.
9. Return and deletion
On termination, Master returns or deletes customer personal data within 30 days, except where retention is required by law.
10. Liability
Liability under this DPA is subject to the limitation of liability in the main agreement.
