MageSentinel
Legal

Data Processing Agreement

The terms on which we process personal data on your behalf under Article 28 GDPR.

Last updated: 2026-09-04

Who is who

For everything MageSentinel captures from your storefront — run outcomes, screenshots, traces, network and console logs — you are the controller and we are the processor. You decide which stores are monitored and what a monitored page contains; we act on your instructions.

For your own account and billing records — the name and email of the people you invite, sign-in times, invoices — we are the controller, and the Privacy Policy governs that data instead.

This agreement applies from the moment you start using the service and lasts as long as we process personal data for you. Where it conflicts with the Terms of Service on data protection, this agreement wins.

What we process, and why

Subject matter and purpose: running synthetic checkout and uptime checks against the stores you nominate, storing the results, and alerting you when they fail.

Duration: for the life of your account, plus the retention periods below.

Categories of data subjects: your customers, where their data appears in a page we visit, and your own staff who use the dashboard.

Categories of personal data: whatever your storefront renders into a checked page. Typically that is the synthetic test identity we submit; it can include real customer data if your store displays it to the session we drive.

We never require special-category data, and you should not configure a monitor whose path exposes it.

Our instructions come from you

We process personal data only on your documented instructions. Configuring a monitor is an instruction; so is a support request asking us to look at a run.

If the law requires us to process data beyond your instructions, we will tell you before doing so unless that law forbids the notice.

If we believe an instruction breaches the GDPR, we will say so rather than carry it out silently.

Confidentiality and access

Access to customer data is limited to the people who need it to run and support the service, each bound by confidentiality obligations that survive their engagement.

Support staff read your evidence only when handling a request you raised, or when diagnosing a fault that affects your account.

Security measures

Evidence is redacted at the point of capture, before it reaches disk: cookies, authorisation headers, session and CSRF tokens, passwords and card numbers are stripped there rather than cleaned up afterwards.

Traffic to the dashboard and the API is encrypted in transit. Stored monitor credentials are encrypted at rest. Passwords are hashed with a salted key-derivation function and are never recoverable.

Access to the dashboard is authenticated per user, with optional two-factor authentication, revocable sessions and per-organisation isolation enforced on every query.

Databases are backed up nightly and each backup is read back automatically to prove it can be restored.

Sub-processors

We use sub-processors for hosting, email delivery and payment processing. Each is engaged under a written contract imposing the same obligations as this agreement, and we remain liable for their performance.

Write to [email protected] for the current list. We will give you notice of an intended change in good time, and you may object on reasonable data-protection grounds; if we cannot resolve the objection you may terminate the affected service.

Helping you meet your obligations

Data subject requests: if someone contacts us directly about data we hold for you, we will not answer for you — we will pass the request on and help you respond within the statutory deadline.

Breach notification: we will tell you without undue delay after becoming aware of a personal data breach affecting your data, with what we know at the time and updates as we learn more.

We will give you the information you reasonably need for a data protection impact assessment or prior consultation with a supervisory authority.

Deletion and return

Evidence from runs is deleted automatically after your plan’s retention window — between 3 and 90 days.

You can export or delete your data from the dashboard at any time; deletion through the interface is immediate and not reversible.

When your account closes we delete the personal data we process for you within 30 days, except where law requires us to keep a record. Backups age out on their own retention schedule and are not selectively edited.

Audits and transfers

We will make available the information needed to show we meet these obligations, and will accommodate an audit by you or an auditor you appoint, on reasonable notice, no more than once a year unless a supervisory authority or a breach requires otherwise.

Where a sub-processor operates outside the EEA, the transfer relies on Standard Contractual Clauses or an adequacy decision.

Signing it

Using the service constitutes acceptance of these terms, and for most customers no signature is needed. If your procurement process requires a countersigned copy, or your own DPA template, write to [email protected] and we will arrange it.