Data Processing Agreement
Last updated 13 August 2026
This Data Processing Agreement (“DPA”) is entered into between the Customer (“Controller”) and TechMagic UK Ltd (“Processor”, “MagicCV”) and forms part of the Terms of Service. In the event of conflict between this DPA and the Terms as regards the processing of personal data, this DPA prevails.
Draft — not in force
This document still contains unresolved items, marked below. It is not binding and is excluded from search engines until they are resolved.
1. Subject matter and duration
Processor processes personal data on Controller's behalf for the duration of the Terms, for the purpose of providing the Service.
2. Nature and purpose of processing
Storage, parsing, search, matching, generation, and export of CV/profile data, including AI-assisted reshaping of CVs against briefs supplied by Controller.
3. Categories of data subjects
Controller's consultants, employees, contractors, or other personnel whose CV/profile data is uploaded to the Service.
4. Categories of personal data
Name, contact details, employment/project history, skills, certifications, education, languages, availability, and any other data Controller chooses to include.
Controller must not upload or otherwise submit to the Service any special category data (Art. 9 GDPR) or data relating to criminal convictions and offences (Art. 10 GDPR), under any circumstances. The Service is not designed or intended to process such data, and Processor accepts no responsibility for special category data submitted in breach of this clause; Controller remains solely liable for any such submission.
5. Controller's instructions
Processor will process personal data only on Controller's documented instructions, including regarding international transfers, unless required to do otherwise by law (in which case Processor will inform Controller, unless prohibited by law).
Controller is solely responsible for informing its consultants, employees, or their representatives, where and to the extent required by applicable law (including Art. 26(7) of the EU AI Act, where applicable), that their personal data or profile may be evaluated using an AI system in connection with the Service, before any such evaluation takes place with respect to them.
Processor will not use CV Data to train, fine-tune, retrain, or otherwise improve any AI model, whether for Processor's own purposes or those of any third party, unless and until Controller has given its prior, explicit, and documented instruction authorising such use for specified purposes. Processor does not rely on its own legitimate interest as a basis for any such use. Absent such an instruction, CV Data is used solely to provide the Service.
6. Confidentiality
Processor ensures that persons authorised to process personal data are bound by confidentiality obligations.
7. Security (Art. 32)
Processor implements the technical and organisational measures summarised in Annex B.
8. Sub-processors
Controller provides general authorisation for Processor to engage sub-processors listed in Annex A, or as updated from time to time. Processor will notify Controller of any intended change at least 30 days in advance via the notification mechanism described in Annex A, during which Controller may object on reasonable data-protection grounds. Processor imposes data protection obligations on sub-processors no less protective than this DPA.
9. Assistance to Controller
Processor will reasonably assist Controller in responding to data subject requests and in meeting obligations under Art. 32–36 GDPR (security, breach notification, DPIA, prior consultation), taking into account the nature of processing and information available to Processor.
10. Personal data breach
Processor will notify Controller without undue delay, and in any event within 48 hours of becoming aware, of any personal data breach affecting Controller's data, with information reasonably available at the time, supplemented as further information becomes available.
11. Deletion or return of data
On termination of the Terms, Processor will, at Controller's choice, delete or return all personal data, and delete existing copies, within 30 days, unless retention is required by law. Independently of termination, where an individual data subject (user) is deleted from the Service, Processor will delete all associated personal data, including backups, within 3 months of that deletion. Where Controller's account is suspended for non-payment or breach of the Terms rather than terminated, Processor will retain personal data without further processing beyond storage for up to 30 days during the suspension period; if the suspension is not resolved within that period, deletion will proceed as set out in this Section.
12. Audit rights
Processor will make available information reasonably necessary to demonstrate compliance with this DPA and Art. 28 GDPR, and will allow for and contribute to audits, including inspections, conducted by Controller or an auditor mandated by Controller, subject to reasonable advance notice, confidentiality, and no more than once per year absent cause.
13. International transfers
Where personal data is transferred outside the UK/EEA, the parties will rely on an adequacy decision or execute the applicable transfer mechanism described in Annex C.
14. Liability
UnresolvedLiability under this DPA is subject to the limitations set out in the Terms, except that liability for data protection breaches is addressed as agreed in the Terms' limitation of liability clause. [See Terms Section 15 — pending finalisation.]
Annex A — Sub-processors
UnresolvedProcessor currently engages the following sub-processors. This list is reviewed regularly and updated as sub-processors change; Controller may subscribe to change notifications at [link — email/RSS subscription mechanism]. Entries below are placeholders pending confirmation from the product/engineering team.
| Sub-processor | Service provided | Location / transfer mechanism | Data categories |
|---|---|---|---|
| Cloud hosting provider — AWS | Hosting and storage of application data | EU | All Service data |
| AI model provider — Gemini | AI-assisted CV parsing and generation | EU | CV/profile data submitted for processing |
| E-mail delivery provider — Google | Transactional e-mail delivery | EU | hello@techmagic.co |
| Payment processor — Stripe | Billing and payment processing | UK | Billing contact data — hello@techmagic.co (no full card data stored by MagicCV) |
| Analytics provider — Posthog, GA4 | Website/product analytics | EU | Usage data, device/browser data |
Last reviewed: 13.08.2026.
Annex B — Security & Trust measures
B.1 Technical and organisational measures
- Encryption of personal data in transit and at rest.
- Access controls based on the principle of least privilege; logging and monitoring of access to production systems for every employee.
- Regular security testing / vulnerability scanning every quarter.
- Employee security training and background checks are mandatory steps before onboarding for every employee.
B.2 Certifications
Processor holds ISO 27001, ISO 9001, and ISO 37001 certification. Certificate details are available to customers and prospective customers on request at hello@techmagic.co.
B.3 Data protection contact
Processor has designated Mykhailo Butusov as its internal data protection / privacy contact for general enquiries. Contact: hello@techmagic.co
Separately, and in addition to the above, Processor has appointed an EU representative under Art. 27 GDPR, as set out in Section 1 of the Terms of Service. This is a distinct role from the data protection contact above and does not replace it.
B.4 Vulnerability disclosure
Processor accepts reports of potential security vulnerabilities at hello@techmagic.co. Processor will acknowledge receipt within 1 business day and work with the reporter to investigate and, where warranted, remediate the issue. Reporters are asked not to access, modify, or exfiltrate Controller or data subject data in the course of testing.
B.5 Incident response
Processor maintains an incident response process covering detection, containment, notification (see Section 10), and post-incident review.
Annex C — International transfer mechanism
Unresolved[To be completed once sub-processor locations are confirmed.]
Where offered, Controller may select its preferred hosting region for Customer Data (e.g. EU/EEA or other region); data will not be transferred outside the selected region without Controller's explicit instruction, except as necessary for support or as disclosed in Annex A. Where transfers outside the UK/EEA occur, Processor relies on the UK International Data Transfer Addendum and/or the EU Standard Contractual Clauses (2021 modules), incorporated by reference.