Last updated: 24 April 2026 Version: 1.0

1. Parties and scope

This Data Processing Agreement ("DPA") forms part of the Terms of Service (or any superseding written agreement — the "Agreement") between:

  • TechMagic, of 41 Devonshire Street, Ground Floor, W1G 7AJ, United Kingdom ("Processor", "MagicScreen"); and

  • the entity identified on the Order Form ("Controller", "Customer").

It applies to the Processing of Personal Data by MagicScreen on behalf of the Customer in connection with the Service.

If there is a conflict between this DPA and the Agreement, this DPA prevails in relation to data protection matters.

2. Definitions

Terms not defined here have the meaning given in the UK GDPR or EU GDPR as applicable. In this DPA:

  • "Applicable Data Protection Law" means, as relevant to the Processing: UK GDPR; the UK Data Protection Act 2018; the EU General Data Protection Regulation (EU) 2016/679; and any implementing or supplementary legislation.

  • "Customer Personal Data" means Personal Data that MagicScreen Processes on behalf of Customer under the Agreement.

  • "Restricted Transfer" means a transfer of Customer Personal Data to a country not recognised as providing an adequate level of protection.

  • "Sub-processor" means a third party engaged by MagicScreen to Process Customer Personal Data.

3. Roles of the parties

Customer is the Controller of Customer Personal Data. MagicScreen is the Processor. Where required by Applicable Data Protection Law, MagicScreen will provide reasonable cooperation to Customer's data protection authority.

4. Processing instructions

4.1 Customer instructions

MagicScreen will Process Customer Personal Data only:

  • on documented instructions from Customer, including as set out in the Agreement, this DPA, and the Service's configuration; and

  • as required by applicable law (in which case MagicScreen will notify Customer unless prohibited).

4.2 Lawful instructions

Customer warrants that its instructions, and the Processing of Customer Personal Data under the Agreement, comply with Applicable Data Protection Law. Customer is responsible for the lawfulness of the Personal Data it provides and for obtaining any required consents or providing any required notices to data subjects (including candidates).

4.3 Notice of unlawful instructions

If MagicScreen considers an instruction to infringe Applicable Data Protection Law, it will inform Customer without undue delay.

5. Details of Processing

See Annex 1 for the subject matter, duration, nature and purpose, categories of data, categories of data subjects, and any special category data.

6. No use for other purposes

MagicScreen will not:

  • sell Customer Personal Data;

  • use Customer Personal Data for direct marketing;

  • combine Customer Personal Data with Personal Data MagicScreen holds for its own purposes; or

  • use Customer Personal Data to train AI models, except for service-specific, ephemeral, customer-isolated use strictly necessary to provide the Service (and never for general-purpose model training).

7. Personnel

MagicScreen will ensure that personnel authorised to Process Customer Personal Data:

  • are bound by contractual or statutory confidentiality obligations;

  • access Customer Personal Data on a need-to-know basis; and

  • receive appropriate training on data protection.

8. Security

MagicScreen will implement appropriate technical and organisational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access — see Annex 2.

MagicScreen may update its security measures from time to time, provided the overall level of security is not reduced.

9. Sub-processing

9.1 General authorisation

Customer grants MagicScreen a general authorisation to engage Sub-processors, subject to this Section 9.

9.2 Current Sub-processors

The current list of Sub-processors is published at the Subprocessor List page on our website and reproduced in our Subprocessor List.

9.3 Notification of changes

MagicScreen will provide at least 30 days' prior notice of any new or replacement Sub-processor by email (where Customer has subscribed to updates) or by updating the published list.

9.4 Objection

Customer may object to a new Sub-processor on reasonable data protection grounds within the notice period. The parties will work in good faith to resolve the objection. If unresolved, Customer may terminate the affected part of the Service and receive a pro-rata refund of prepaid unused Fees.

9.5 Obligations on Sub-processors

MagicScreen will impose on each Sub-processor data protection obligations that are no less protective than those in this DPA and will remain liable for Sub-processors' acts and omissions.

10. Data subject rights

10.1 Assistance

MagicScreen will provide reasonable assistance to enable Customer to respond to requests from data subjects exercising their rights under Applicable Data Protection Law (access, rectification, erasure, restriction, portability, objection, not to be subject to automated decision-making).

10.2 Direct requests

If MagicScreen receives a request directly from a data subject (e.g. a candidate), it will promptly forward it to Customer and will not respond itself (unless legally required or instructed by Customer to do so).

11. Personal data breaches

MagicScreen will:

  • notify Customer without undue delay (and in any event within 72 hours) after becoming aware of a Personal Data Breach affecting Customer Personal Data;

  • provide information reasonably required to meet Customer's notification obligations, including the nature of the breach, categories and approximate numbers of data subjects and records affected, likely consequences, and measures taken or proposed; and

  • cooperate with Customer's investigation and remediation efforts.

This Section does not require MagicScreen to notify Customer of unsuccessful attempts or routine security events that did not result in a breach.

12. Assistance with DPIAs and prior consultation

MagicScreen will provide reasonable assistance to Customer with Data Protection Impact Assessments and prior consultations with supervisory authorities, taking into account the nature of Processing and the information available to MagicScreen.

13. International transfers

Where a Restricted Transfer occurs:

  • from the UK, the parties enter into the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses;

  • from the EEA, the parties enter into the EU Standard Contractual Clauses (2021/914), Module 2 (Controller to Processor) or Module 3 (Processor to Processor), as applicable.

Both the UK IDTA/Addendum and the EU SCCs are incorporated by reference and deemed executed on the Effective Date of this DPA, with the Customer as "data exporter" and MagicScreen as "data importer". Optional clauses are elected as set out in Annex 3.

14. Return or deletion

On expiry or termination of the Agreement, MagicScreen will, at Customer's choice:

  • make Customer Personal Data available for export for 30 days; and thereafter

  • delete or anonymise Customer Personal Data from MagicScreen's production systems within 60 days, and from backups within its standard backup retention period (not exceeding 12 months),

except to the extent retention is required by law.

On request, MagicScreen will certify compliance with this Section in writing.

15. Audits

15.1 Information obligation

MagicScreen will make available to Customer the information necessary to demonstrate compliance with Art. 28 UK/EU GDPR.

15.2 Audit rights

Customer may audit MagicScreen's compliance with this DPA once per year, or more frequently if required by a supervisory authority or following a Personal Data Breach. Audits will:

  • be conducted on at least 30 days' prior written notice;

  • take place during normal business hours;

  • be subject to MagicScreen's confidentiality and security policies;

  • not unreasonably interfere with MagicScreen's business; and

  • at Customer's cost (except where the audit identifies a material breach, in which case MagicScreen bears reasonable audit costs).

MagicScreen may satisfy audit requests by providing recent independent audit reports (e.g. ISO 27001, SOC 2), unless Customer can show why these are not sufficient.

16. Liability

The liability of each party under this DPA is subject to the limitations and exclusions set out in the Agreement.

17. Term

This DPA is effective from the Effective Date of the Agreement and remains in force for as long as MagicScreen Processes Customer Personal Data on Customer's behalf. Sections that by their nature should survive (including 6, 8, 11, 14, 15, and 16) survive termination.

Annex 1 — Details of Processing

Subject matter: provision of the MagicScreen candidate screening platform to Customer.

Duration: the term of the Agreement plus any period during which MagicScreen continues to hold Customer Personal Data pursuant to Section 14.

Nature and purpose:

- hosting and storing Customer Personal Data;

- running AI-assisted screening workflows (text, audio, and/or video input) configured by Customer;

- generating scores, summaries, and recommendations for human review by Customer;

- providing analytics and reporting to Customer;

- providing technical support.


Categories of data subjects:

- Customer's employees and authorised Users;

- Candidates whose data is processed by Customer using the Service.


Categories of Personal Data:

- Identification data (name, email, phone)

- Professional data (CV, work history, skills, qualifications, references)

- Application data (cover letters, application answers)

- Interview responses (text, audio, and/or video recordings)

- Candidate-generated content

- Usage metadata (timestamps, device and browser information)

- AI-generated outputs associated with the above


Special category / sensitive data: Customer should not submit special category data or criminal offence data unless expressly configured and justified. If it does, the Processing relies on the lawful basis and condition identified by Customer.

Frequency of Processing: continuous, for the duration of the Agreement.

Annex 2 — Technical and Organisational Measures

MagicScreen implements the following security measures:

Access control

- Role-based access control; least-privilege principles

- Mandatory multi-factor authentication for employee access to production

- Quarterly access reviews


Encryption

- TLS 1.2+ in transit

- AES-256 at rest


Network security

- Web Application Firewall; DDoS protection

- Network segmentation between environments


Application security

- Secure Software Development Lifecycle

- Dependency scanning; static analysis

- Annual third-party penetration testing

- Responsible disclosure: security vulnerabilities can be reported to hello@techmagic.co


Operational security

- Centralised logging and monitoring

- Incident response plan with defined severity levels and response times

- Business continuity and disaster recovery plans with tested RTO/RPO

- Documented backup policy with encrypted backups


Personnel

- Background checks where lawful

- Mandatory security and data protection training

- Confidentiality obligations


Physical security

- Production Processing is hosted in ISO 27001–certified data centres operated by our hosting Sub-processor

- TechMagic's Ukraine operational offices (Lviv) apply physical access controls, CCTV, and visitor logging; personnel access to production systems is via encrypted remote session only


Certifications / attestations - TechMagic publishes its current security certifications at https://www.techmagic.co/certifications. Specific certifications applicable to the MagicScreen Service will be updated here as they are confirmed.

Annex 3 — International Transfers

UK IDTA / UK Addendum elections:

- Table 1: Parties and signatures — per the Agreement and this DPA.

- Table 2: Transfer Details — per Annex 1 above.

- Table 3: Appendix Information — Annex 1 and Annex 2 of this DPA.

- Table 4: Ending the IDTA when the Approved Addendum Changes — either party may end the IDTA as set out in the Approved Addendum.


EU SCCs (2021/914) elections:

- Module: 2 (C2P) or 3 (P2P) as applicable.

- Clause 7 (Docking): not used.

- Clause 9 (Sub-processors): Option 2 (general authorisation), 30 days' notice.

- Clause 11 (Redress): optional language not used.

- Clause 17 (Governing law): law of Ireland (or, where the data exporter is established in another EU/EEA Member State, the law of that Member State).

- Clause 18 (Forum and jurisdiction): courts of Ireland (or, where the data exporter is established in another EU/EEA Member State, the courts of that Member State).

- Annex I.A Parties: per the Agreement.

- Annex I.B Description of Transfer: Annex 1 above.

- Annex I.C Competent Supervisory Authority: the Irish Data Protection Commission, unless the data exporter has a different lead supervisory authority designated.

- Annex II Technical and Organisational Measures: Annex 2 above.

- Annex III List of Sub-processors: the Subprocessor List page on our website.