Privacy Policy

This Policy describes the principles of processing Personal Data that is submitted to Textmagic or that otherwise becomes available to Textmagic in connection with the use by the Clients and other users of the Website, Software, and Services. It explains how Textmagic processes Personal Data: (i) as a Controller for its own purposes, including account administration, billing, security and customer support; and (ii) as a Processor on behalf of Clients when providing the Services using Personal Data submitted by or on behalf of those Clients.

Please read this Policy carefully to understand the practices that Textmagic applies regarding processing of Personal Data. This Policy constitutes an integral part of the agreement entered into between the Clients and Textmagic. By viewing the Website and/or using the Software and Services, the Clients confirm that they have had an opportunity to review this Policy and understand how Textmagic describes its processing practices.

Upon initial registration with Textmagic, the Clients (via their authorized representatives) also confirm the above-said by clicking on the “Create My Account” button, which declares the Client´s acceptance of and consent to the processing of Personal Data as described in this Policy.

This Policy also includes data processing agreement provisions between the Clients (as Controllers of Personal Data) and Textmagic (as Processor of Personal Data) for the purposes of Article 28 of the EU GDPR and the UK GDPR. Where Textmagic processes Personal Data as Processor, Textmagic processes such data under the documented instructions of the relevant Client, unless applicable law requires otherwise.

Textmagic shall be entitled to unilaterally review and amend this Policy from time to time. Therefore, Textmagic advises to periodically review the Policy in the case of any changes to it.

Continued use of the Website, Software, and Services after changes to this Policy become effective indicates acceptance of the updated contractual terms where applicable. If a Client or other users do not agree with any or all terms of this Policy or any possible changes to it, then they should immediately close the Website and cease using the Software and Services. Textmagic has drafted this Policy in cooperation with its legal advisers having regard to applicable Data Protection Laws.

Textmagic does its best to ensure that the processing of Personal Data is in full compliance with applicable legal requirements.

  1. Definitions

    1. Client(s) means legal persons, who register themselves on the Website and use it and the Software in accordance with the Terms and this Policy for the purpose of using the Services.
    2. Data Subjects means all natural persons, whose personal data is submitted to Textmagic by the Clients or by the natural persons directly in connection with using the Website, Software, and the Services
    3. EU GDPR means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC.
    4. UK GDPR means Regulation (EU) 2016/679 as it forms part of the law of the United Kingdom as defined in the UK Data Protection Act.
    5. Data Protection Laws means the EU GDPR, the UK GDPR, the UK Data Protection Act 2018, the Data (Use and Access) Act 2025, applicable national laws implementing or supplementing the EU GDPR, and any other applicable data protection or privacy laws.
    6. DPA means the data processing agreement between Textmagic and the Client incorporated into this Policy.
    7. EU Standard Contractual Clauses means (i) the standard contractual clauses adopted by the European Commission on 4th June 2021 for the transfer of Personal Data to third countries pursuant to the GDPR; or (ii) such other standard contractual clauses that are approved by the European Commission for controller to processor transfers of Personal Data to a third country which has not received an Adequacy Decision.
    8. Policy means this privacy policy of Textmagic as amended from time to time.
    9. UK Addendum means the international data transfer addendum to the EU Standard Contractual Clauses issued under the UK GDPR and approved for use in relation to Restricted Transfers subject to the UK GDPR.
    10. IDTA means the international data transfer agreement issued under the UK GDPR and approved for use in relation to Restricted Transfers subject to the UK GDPR.
    11. Personal Data means any information relating to an identified or identifiable natural person (‘data subject’). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
    12. Processing means any operation or set of operations that is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
    13. Controller means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
    14. Processor means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
    15. Transfer means (i) a transfer of Personal Data from the Client to Textmagic; or (ii) an onward transfer of Personal Data from Textmagic to a subcontracted Processor or between two establishments of Textmagic; or (iii) a transfer of Personal Data from Textmagic to a third party designated by the Client (such as AI service providers) at the Client’s documented instruction.
    16. Restricted Transfer means a transfer of Personal Data to a country, a territory or specified sector within a country that: (i) is not subject to an adequacy decision under the EU GDPR or UK GDPR, as applicable; and (ii) is not subject to any derogation or exception that would permit the transfer of the Personal Data to the country, territory or sector in accordance with the EU GDPR or UK GDPR, as applicable to the Personal Data transfer.
    17. Service(s) means the information services offering a capability for generating, acquiring, transforming, processing, retrieving, submitting and making available Content to recipients via third-party communications and information services. Services are rendered via a Website-based online platform or by using the Software and includes the option to use AI Services to enhance the Services.
    18. Software means web-based interface, mobile app, and other downloadable and integrable software developed and maintained by Textmagic for the purpose of provision of the Services.
    19. Textmagic means Textmagic Limited, a limited liability company registered in England and Wales under company number 05286521 with the registered office at Salisbury House, Station Road, Cambridge, Cambridgeshire, CB1 2LA and all its affiliates. Textmagic’s affiliates are registered in the European Union, therefore, European Union’s personal data protection laws shall be applied in addition to the UK’s, including the EU GDPR.
    20. Terms means the terms of service of Textmagic that establish the terms and conditions of using the Website, Software, and Services by the Clients and other users.
    21. Website means the website of Textmagic www.textmagic.com.
  2. Personal Data that Textmagic Processes

    1. For the purpose of provision of the Website, Software, and the Services, Textmagic processes the Personal Data that the Clients provide about themselves (i.e. the Client’s workers, representatives) and their own clients, who are the recipients of the Content generated and made available by the Clients via the Services. The types of such data are not restricted and depend on the decision of the Clients on how they want to use the Services and generally include the name, contact telephone number, email address but may also include avatars, country, addresses, etc.
    2. Textmagic keeps the register of the Personal Data that it processes in accordance with this Policy.
  3. Objectives of Processing of Personal Data

    1. Textmagic processes the Personal Data upon:
      1. Usage of the Software and Services by the Clients, including when they submit to Textmagic information about their clients (Textmagic is acting as Processor);
      2. Communication between Clients and/or Data Subjects and customer support of Textmagic in connection with the Website, Software, and Services (Textmagic is acting as Controller).
    2. Textmagic works closely with third parties (including, for example, business partners, communications service providers, information service providers such as email delivery providers, sub-contractors in technical, payment, and delivery services, advertising networks, analytics providers, search information providers, credit reference agencies, large language model providers) and may receive Personal Data from them or submit the Client’s Personal Data to them for the purposes of providing the Services and performing the contracts entered into with the Clients.
    3. Textmagic may send messages to the Clients by electronic means (e-mail or SMS) with information about improvements to the Website, Software and Services, new proposals, and developments (direct marketing). Textmagic sends such messages to the contact details provided by representatives of the Clients at the moment of registration or updated later. The Clients confirm hereby and guarantee that contact details provided by representatives of the Clients are at all times company details of the Clients, but not personal contact details of representatives and therefore Textmagic can use such contact details freely to send its marketing messages without any additional obstacles. The Clients may at any time unsubscribe from the newsletters by clicking on the corresponding specific link contained in each newsletter.
  4. Legal Basis for Processing Personal Data

    1. Textmagic processes Personal Data in accordance with Data Protection Laws applicable to Textmagic, its affiliates, the Clients, the Website, Software and Services, and the relevant processing activities.
    2. Textmagic processes Personal Data submitted to it by the Clients based on the contracts with the Clients for the purpose of using the Website, Software, and Services and to the extent that this data is provided by the Clients.
    3. In accordance with Article 4 (7) of the EU GDPR and the UK GDPR, as applicable, the Clients are the Controllers of Personal Data that they submit to Textmagic for the purpose of using the Website, Software, and Services, including the data regarding clients of the Clients that the Clients submit to generate, acquire, transform, retrieve and make available to and from their clients as recipients. According to Article 4 (8) of the EU GDPR and the UK GDPR, as applicable, Textmagic acts as the Processor on the Client’s behalf when processing the Personal Data submitted by the Client. Therefore, the Clients:
      1. Are fully responsible for the processing of Personal Data that they submit to Textmagic;
      2. Guarantee to Textmagic explicitly that the Clients in order to use the Website, Software and Services have all the necessary consents and/or other legal grounds from Data Subjects for lawful processing of Personal Data and for instructing Textmagic to process such Personal Data;
      3. Confirm that they have provided all required notices to Data Subjects and obtained all necessary consents or other legal grounds for submitting Personal Data to Textmagic and instructing Textmagic to process such data;
      4. Have a full overview of Personal Data that they submit to Textmagic and guarantee that all such data that they submit is necessary for use by them of the Website, Software, and Services and is kept up-to-date;
      5. Oblige to inform Textmagic immediately of the expiry of legal grounds for the processing, modification, inaccuracy, or change to the Personal Data that the Clients submit to Textmagic.
    4. When using Services for direct marketing, the Clients are responsible for complying with all the legal requirements in connection with direct marketing and data subjects’ rights. Textmagic is only providing the platform for processing, generating and making available Content to recipients via third-party communications and information service providers, but the Clients are solely responsible for their Content processed while using the Services. The Clients understand that there are different legal rules for direct marketing in different countries. When the Services are used for direct marketing, the Clients must comply with all requirements for direct marketing of the country, where the receiver of the direct marketing Content is residing. For instance, in the EU and the UK, the Clients are obliged to include in the direct marketing Content information on how the Data Subject can opt out of direct marketing and there are also certain requirements for the content and sending of commercial Content.
    5. Textmagic processes the personal data provided by the Client only to the extent necessary to provide the Services in accordance with the Terms and on documented instructions from the Client. Textmagic shall comply with all applicable Data Protection Laws in the processing of Client Personal Data and not process Client Personal Data other than on the relevant Client’s documented instructions, unless required to do so by applicable law. The Clients provide these instructions through their configuration and use of the Services, account settings, support requests, other documented communications, and the Terms and DPA. The instructions of the Clients for processing of Personal Data must always comply with the applicable Data Protection Laws and Textmagic reserves to itself the right to refuse to fulfill the instructions that are in the opinion of Textmagic unlawful. Textmagic shall promptly inform the Client if, in Textmagic’s opinion, any of the instructions regarding the processing of Client Personal Data breach any applicable Data Protection Laws, unless applicable law prohibits such information.
    6. Textmagic shall also take steps to ensure that any person acting under the authority of Textmagic who has access to Client Personal Data shall only process the Client Personal Data on the documented instructions of the Client.
    7. Textmagic shall act as data controller and itself determine the purposes of processing the Clients’ Personal Data only in the limited cases where Textmagic is processing Personal Data of the Client’s representatives or workers specifically for the purpose of administration and management of the contract with the Client, i.e. upon registering the Client’s user account on the Website, processing the Client’s payment for the Services, customer service communications with the Client etc. In such cases, where Textmagic is processing the Client’s Personal Data for the purpose of entering into or managing the contract with the Client, the legal basis for personal data processing is Article 6(1)(b) of the EU GDPR or UK GDPR, as applicable – processing is necessary for the performance of a contract.
  5. Data Subjects’ Rights

    1. Taking into account the nature of the processing, Textmagic shall assist the Clients with appropriate technical and organizational measures, insofar as this is possible, for the fulfillment of the Clients´ obligation to respond to requests for exercising of Data Subject’s rights under applicable Data Protection Laws, including the right of access to Personal Data by Data Subjects, right to rectification, right to be forgotten, right to restriction of processing, etc. Textmagic shall accept instructions for the fulfillment of the rights of Data Subjects only from the Clients. Should the Data Subjects approach Textmagic with the requests for the fulfillment of their rights, Textmagic shall inform the Clients and act according to instructions from the Clients. Obligation to delete the data of Data Subjects shall always remain with the Clients and Textmagic shall not undertake deletion for and on behalf of the Clients, unless otherwise explicitly stipulated in the Policy or Terms.
    2. Where Textmagic processes Personal Data as Controller, Data Subjects may exercise their rights under applicable Data Protection Laws.
    3. Textmagic shall assist the Clients in ensuring compliance with the obligations relating to ensuring security of the processing of Personal Data as established by applicable Data Protection Laws while taking into account the nature of processing and the information available to Textmagic.
    4. Textmagic does not itself use automated or AI-enabled functionality within the Services to make decisions about Data Subjects that are based solely on automated processing, including profiling, and that produce legal effects concerning them or similarly significantly affect them.
  6. Audit Rights

    1. Textmagic shall make available to the Clients all information necessary to demonstrate compliance with the obligations laid down in Article 28 of the EU GDPR and the UK GDPR, as applicable, and allow for and contribute to audits, including inspections, conducted by the Clients or another auditor mandated by the Clients (all at the expense of the Clients). On-site audits and inspections must be agreed with Textmagic in advance, be conducted during normal working hours, and not unreasonably disturb the everyday activity and business of Textmagic. Right to audits and inspections does not extend to the facilities and premises of Third Parties.
  7. Transfer of Personal Data to Third Parties

    1. In the course of providing the Services and access to the Website and Software, Textmagic uses different third-party service providers, to whom it may also transfer Personal Data (herein: Third Parties). By virtue of this clause, the Clients are duly informed and expressly authorize, totally or partially, to use the Third-Party service providers detailed in Annex III and transfer Personal Data to them, as it may be required for the purpose of providing the Services.
    2. Textmagic shall inform the Clients of any intended changes concerning the addition or replacement of Third-Party processors by publishing the changes on the Website in Annex III to this Policy or by other appropriate notice. Textmagic shall not appoint or disclose Personal Data to any Third-Party service provider, unless required or authorised by the Client. Textmagic has the right to stop providing Services to the Clients who object to the change concerning the addition or replacement of Third-Party processors.
    3. Textmagic has entered into individual service provision contracts with some of the Third-Party service providers. With others, the relationships are based on the general terms of service of these service providers. Prior to entering into relationships with Third-Party service providers, Textmagic shall take reasonable steps to ensure that they are subject to written obligations which, in substance, provide at least the same level of data protection as this Policy and applicable Data Protection Laws and, if applicable, the EU Standard Contractual Clauses, UK Addendum or IDTA. Textmagic carefully screens the ongoing relationships with Third-Party service providers and in case of their non-compliance shall immediately terminate relationships with them.
    4. Additionally, Textmagic may disclose/transfer Personal Data to Third Parties:
      1. Under applicable law, including laws outside the locations of Textmagic, its affiliates or Data Subjects;
      2. To comply with legal processes;
      3. To respond to requests from the public and government authorities including public and government authorities outside the locations of Textmagic and its affiliates;
      4. To enforce this Policy or Terms, to protect operations, the rights, privacy, safety, or property of Textmagic, and/or to pursue available remedies or limit the damages.
    5. Textmagic makes its best efforts to limit the amount of Personal Data that it transfers for processing to Third Parties as it is necessary for the provision of specific Services or to pursue specific goals.
    6. The Website and Software may contain links that redirect to other websites. For example, when accessing services of a third party such as PayPal when making a payment. This Policy does not apply to such third-party websites, which Textmagic does not operate, and Textmagic does not accept any responsibility or liability for these policies. Textmagic advises reviewing the privacy policies of those third parties.
    7. The Services include the option for the Clients to enhance the Services by using AI Services, including AI-powered features that support customer communications, content creation and improvement, compliance and security-related functions. These AI Services are powered by large language models (LLM) provided by Third-Party providers. By virtue of this clause, the Clients are duly informed and expressly agree that by using the AI Services, all information and Content (including Personal Data contained therein) disclosed via the AI Services is disclosed to and processed by the Third-Party LLM providers on the basis of the data processing policies and rules established by such Third-Party LLM providers. The Third-Party LLM providers are detailed in Annex III. For AI Services selected and provided by Textmagic, Textmagic contractually restricts the relevant Third-Party AI Provider from using Client Content to train or otherwise improve its services. Additional information about the use of AI Services and the relevant data processing policies of the Third-Party LLM providers are available in the Annex to the Terms available at https://www.textmagic.com/terms-of-service/#ai-services
    8. The Services may allow Clients to connect their Textmagic account to third-party AI assistants or applications, such as OpenAI’s ChatGPT or Anthropic’s Claude, through authorised integrations using the Model Context Protocol (“MCP”). When a Client authorises such a connection and uses the connected application through the Client’s own account or workspace to request information or perform an action, Textmagic may receive task-specific instructions and disclose the information necessary to fulfil the Client’s request, such as account information, contacts, messages, conversation records and action results, subject to the permissions granted by the Client and the access rights of the authenticated Textmagic user. Information disclosed to a connected application is processed by its provider under its own terms, privacy policy and account settings, as applicable. Clients may revoke the connection at any time. Revoking the connection prevents future access. Textmagic does not request or reconstruct a user’s complete conversation history with the connected application and processes only the information transmitted for the relevant request. Any Personal Data retained by Textmagic in connection with the integration is retained in accordance with Section 11 and Annex I.
  8. Transfer of Personal Data to Third Countries

    1. In connection with providing the Services, as well as some specific development works, troubleshooting of service issues, data storage or other necessary services, Textmagic may transfer Client Personal Data to Third-Party sub-processors, some of which may be established or process data outside the European Economic Area or the United Kingdom (hereinafter: Third Countries).
    2. Data protection levels in Third Countries might differ from the corresponding level of the European Economic Area or the United Kingdom, and some Third Countries might have a lower level of data protection.
    3. Textmagic shall apply appropriate safeguards when transferring Personal Data to Third Countries under applicable Data Protection Laws. In particular, Textmagic shall only transfer Personal Data to Third Countries if:
      1. the Third-Party sub-processor located in a Third Country is subject to, or agrees to be bound by, the EU Standard Contractual Clauses under Module Three, the UK Addendum to the EU Standard Contractual Clauses, or the IDTA, as applicable to the relevant transfer;
      2. the transfer of Personal Data is to a country benefitting from an adequacy decision pursuant to Article 45 of the EU GDPR or UK adequacy decision under UK GDPR, as applicable;
      3. the Third Party otherwise ensures appropriate safeguards pursuant to Articles 46 or 47 of the EU GDPR or the corresponding provisions of the UK GDPR, as applicable, with respect to the processing in question;
      4. the transfer of Personal Data is necessary for the establishment, exercise or defence of legal claims in the context of specific administrative, regulatory or judicial proceedings; or
      5. the transfer of Personal Data is necessary in order to protect the vital interests of the Data Subject or of another natural person.
    4. For Restricted Transfers subject to the EU GDPR, Textmagic shall rely on an adequacy decision, the EU Standard Contractual Clauses, supplementary measures and a transfer assessment where required, or another safeguard or derogation permitted by the EU GDPR.
    5. For Restricted Transfers subject to the UK GDPR, Textmagic shall rely on UK adequacy regulations, the IDTA, the UK Addendum to the EU Standard Contractual Clauses, supplementary measures and any required transfer risk assessment or data protection test, or another safeguard or exception permitted by the UK GDPR.
    6. Textmagic shall not carry out a Restricted Transfer (as data exporter) to a Third-Party sub-processor unless it obtains prior authorisation from the Client for such transfer. The Client hereby provides prior authorisation for Textmagic to carry out the Restricted Transfers to its Third-Party sub-processors as set out in Annex III to this Policy.
    7. In addition to the above, when transferring the Personal Data to Third Countries, the measures detailed in Annex II and any supplementary measures required by applicable Data Protection Laws shall be applied.
  9. Safety Measures for Protection of Personal Data

    1. Textmagic shall implement appropriate technical and organisational measures to protect Personal Data, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of Processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons. This includes (but is not limited to) the following measures: (i) the pseudonymisation and encryption of Personal Data; (ii) the ability to ensure the on-going confidentiality, integrity, availability and resilience of processing systems and services; (iii) the ability to restore the availability and access to Personal Data in a timely manner in the event of a physical or technical incident; (iv) a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing of Personal Data. In assessing the appropriate level of security, account shall be taken in particular of the risks that are presented by the processing of Personal Data, in particular from accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Personal Data processed.
    2. The technical and organisational measures detailed in Annex II shall be at all times adhered to by Textmagic as the minimum security standard. The Client acknowledges that the technical and organisational measures are subject to development and review and that Textmagic may use alternative suitable measures to those detailed in Annex II, provided that such measures are no less onerous than the measures contained in this Policy and Annex II.
    3. Textmagic shall ensure that all employees, agents, officers and contractors involved in the handling of Personal Data: (i) are aware of the confidential nature of the Personal Data and (ii) are contractually bound to keep the Personal Data confidential.
  10. Personal Data Breach

    1. Textmagic shall notify the Client without undue delay upon becoming aware of a Personal Data breach affecting Personal Data of the Client, providing the Client with sufficient information to allow the Client to meet any obligations to report or inform Data Subjects of the Personal Data breach under applicable Data Protection Laws.
    2. Textmagic shall co-operate with the Client and take reasonable commercial steps as are directed by the Client to assist in the investigation, mitigation and remediation of each such Personal Data breach.
  11. Retention Periods

    1. Textmagic shall preserve Personal Data only for as long as required for the Website, Software and Services by the Clients, to comply with legal obligations, to resolve disputes and enforce agreements, and no longer than applicable law permits preservation. The detailed retention periods and principles are provided in Annex I and applicable Data Protection Laws.
    2. The Clients confirm that they agree with the provided retention periods and guarantee to inform and obtain necessary approvals from their clients and representatives for application of such retention periods.
  12. Data Protection Officer

    1. Textmagic has designated as the Data Protection Officer the attorney-at-law and partner from the law firm Eversheds Sutherland, Tambet Toomela, contact information: +372 6229990, e-mail [email protected]
  13. Contact Information

    1. Should the Clients or Data Subjects have any questions regarding this Policy or the processing of Personal Data, or wish to make a data protection complaint, they are welcome to contact Textmagic with all such requests, inquiries or complaints via e-mail: [email protected]. Where UK data protection law applies, Textmagic will acknowledge receipt of data protection complaints within 30 days and take appropriate steps to investigate and respond without undue delay. Individuals also have the right to complain to the UK Information Commissioner’s Office where UK data protection law applies or to the competent EEA supervisory authority where the EU GDPR applies.
    2. Clients, Data Subjects and other persons may also use [email protected] to report security concerns, suspected vulnerabilities or other security-related complaints concerning the Website, Software or Services. Textmagic will take appropriate steps to review and respond to such reports.

ANNEX I – PERSONAL DATA RETENTION PERIODS

Textmagic shall delete the Personal Data submitted by the Clients according to the following principles:

  1. Personal contact data provided by the Clients and Content of the Clients shall be preserved for 60+60 days after the Client has filed a claim to delete such data.
  2. Initial data files submitted by the Clients shall be deleted after 60 days since data is imported to the system of Textmagic.
  3. Attachments that the Clients submit to be sent to recipients together with Content shall be preserved for a maximum of 60 days and then shall be deleted. As attachments the Clients may not upload any Personal Data.
  4. Log files with the activities of the Clients on the Website shall be preserved for a maximum of 1 month and audit log files shall be preserved for 2 years.
  5. In case of closing an account, the Clients must accept the deletion of contacts and Content.
  6. Contacts will be deleted after 60 days and messages after 60+60 days since the Client has given acceptance for closing an account or Textmagic has decided to close the Client’s account.
  7. The Clients shall have an opportunity to renew their accounts at any time (except deleted contacts and Content).
  8. Any Personal Data retained by Textmagic in connection with Connected Applications, such as applications stipulated in section 7.8, is retained in accordance with the retention period applicable to the relevant category of data under this Annex. Any information retained by the Connected Application provider is subject to that provider’s own terms, privacy policy and account settings.

ANNEX II — TECHNICAL AND ORGANISATIONAL MEASURES INCLUDING TECHNICAL AND ORGANISATIONAL MEASURES TO ENSURE THE SECURITY OF THE DATA

The following technical and organizational measures are implemented by Textmagic at all times to ensure an appropriate level of security, taking into account the nature, scope, context, and purpose of the processing, and the risks to the rights and freedoms of natural persons.

  1. Textmagic stores all Personal Data on secured servers. The security measures pertaining to the servers where the Personal Data is stored include the following:
    1. Access to the servers is protected with individual accounts, usernames, and passwords for each authorized person (employees/subcontractors);
    2. Textmagic is keeping track and a log of all activities on the servers;
    3. Textmagic can immediately close access to the servers to any authorized persons;
    4. Access to the servers is restricted in terms of (a) persons, who have access to it, (b) information, to which authorized persons have access according to the essence of their working duties, (c) actions that authorized persons can perform with Personal Data stored on the servers;
    5. Textmagic keeps reviewing, who of the authorized persons are actually required to have access to Personal Data and, if access is not required, will withdraw the right of access.
  2. Additional technical security measures implemented by Textmagic include the following:
    1. Pseudonymization and Encryption of Personal Data:
      1. Data is encrypted in transit and at rest using TLS 1.2, AES-256 encryption, and SHA2 signatures;
      2. Passwords are stored using cryptographic hash functions, and single sign-on (SSO) is available for authentication;
    2. Ensuring Confidentiality, Integrity, Availability, and Resilience:
      1. Access controls are enforced via role-based authorization (RBAC) and least privilege principles;
      2. Security monitoring tools (e.g., AWS CloudTrail, Blackfire.io, Bugsnag, Pingdom, Sentry) track system performance and detect anomalies;
    3. Restoring Data Availability in Case of Incidents:
      1. Daily automatic backups are stored for at least 60 days, with a maximum retention period of three years;
      2. Backups are hosted on OVHCloud (France/Germany) and AWS (USA), with restoration tests conducted annually;
    4. Testing and Evaluating Security Measures:
      1. Third-party security audits verify the effectiveness of security controls;
      2. System changes are tested before deployment, requiring peer reviews and approvals;
    5. User Identification and Authorization:
      1. Multi-factor authentication (MFA) is required for AWS, Bitbucket, Google Admin, and Cloudflare;
    6. Data Protection During Transmission and Storage:
      1. TLS encryption for all traffic in transit;
      2. AWS and OVHCloud storage encryption ensures secure data storage;
    7. Event Logging and System Configuration:
      1. Logs are retained for 30 days for auditing and anomaly detection;
      2. Default security configurations are enforced through Infrastructure as Code (IaC) methodologies;
    8. Internal IT and Security Governance. Security policies cover:
      1. Acceptable Use, Access Control, Business Continuity, Change Management, Data Retention, Encryption, Risk Management, Secure Development, and Vendor Management.
    9. Data Minimization, Quality, Retention, Accountability, and Portability:
      1. Data retention is limited based on contractual and regulatory requirements:
      2. Customers can request data deletion within 60 days.
      3. Data classification policies govern access and handling of sensitive data.
  3. Organisational measures implemented by Textmagic include the following:
    1. Regular penetration testing and independent third-party security audits are conducted annually;
    2. Incident response and risk management plans are in place and tested annually;
    3. Annual security training is mandatory for employees;
    4. Third-party security audits verify the effectiveness of security controls;
    5. Quarterly access reviews are conducted for all critical systems;
    6. Annual security meetings are conducted with senior management to review risks and compliance.
  4. Measures for ensuring the Physical Security of Data Processing Locations are as follows:
    1. Textmagic has door locks and/or door access cards in offices from where Personal Data can be accessed;
    2. Textmagic’s offices are secured with locked external doors, security cameras, and access card systems;
    3. Visitors must sign in with security before entering internal areas.
  5. In addition, Textmagic shall:
    1. Periodically monitor its internal processes and the technical and organizational measures to ensure that the processing of Personal Data is in accordance with the applicable law. Textmagic shall also monitor the processing of Personal Data conducted by Third Parties as much as possible;
    2. Notify the Clients in the most expedient time possible under the circumstances and without unreasonable delay and, where feasible, not later than 72 hours after having become aware of any accidental, unauthorized, or unlawful destruction, loss, alteration, or disclosure of, or access to, Personal Data (herein: Security Breach). In consultation with the Clients, Textmagic shall take appropriate measures to secure the data and limit any possible detrimental effect on the Data Subjects;
    3. Cooperate with the Clients and provide them with information and assistance, where reasonably possible, in connection with Security Breaches, including in communication with supervisory authorities and Data Subjects;
    4. Cooperate and assist the Clients in conducting processing impact assessments, if applicable.
  6. Access for the Clients to the personal cabinets on the Website is protected with individual usernames and passwords. The Clients are responsible for keeping passwords confidential. The Clients are obliged not to share passwords with anyone. In case of suspicion of unauthorized access to personal cabinets of the Clients and/or Personal Data, the Clients are obliged to immediately inform Textmagic thereof.
  7. Textmagic shall ensure that all its employees, contractors, agents, suppliers and consultants, who have access to the Personal Data are fully aware of and abide by their legal duties and responsibilities.
  8. Employees and other contractors of Textmagic are obliged by binding agreements not to disclose or make available for use to anyone other than Textmagic during their agreement with Textmagic and eternally after its termination any Personal Data that they may have access to during their agreements with Textmagic.

ANNEX III — LIST OF SUB-PROCESSORS

The Client has authorized the use of the following sub-processors by Textmagic:

  1. Server service providers, including OVHCloud (France, Germany) and AWS (USA);
  2. Website, Software, and Services development services, including software development, analytical data processing, PHP and JavaScript errors tracking, including Cloudflare, GitLab, Bugsnag;
  3. Providers of safety measures, including fraud protection, protection, and encryption of Textmagic traffic, email domain authority detection tool, including Cloudflare
  4. Device management and security service providers, including JumpCloud;
  5. E-mail and online messaging service providers, including Slack, GSuite;
  6. Task and documentation management services, including Jira / Confluence;
  7. Email delivery service providers, including Postmark;
  8. SMS sending/receiving and virtual number providers, including Bandwidth, Vonage, Reach Interactive, Tyntec, Twilio;
  9. Fraud detection and GeoIP location services, including MaxMind;
  10. Identity verification service providers, including Veriff;
  11. Bookkeeping and payment service providers, including PayPal and Stripe;
  12. Customer support service providers, including Zendesk;
  13. Large language model providers, including OpenAI Ireland Ltd (for Clients located in the EEA or Switzerland) or OpenAI LLC (for Clients located in anywhere else other than the EEA or Switzerland), and Anthropic Ireland, Limited.
DATED: 28 July 2026