Last updated: 24 April 2026

Last updated: 24 April 2026 Version: 1.0
1. Parties and scope
This Data Processing Agreement ("DPA") forms part of the Terms of Service (or any superseding written agreement — the "Agreement") between:
TechMagic, of 41 Devonshire Street, Ground Floor, W1G 7AJ, United Kingdom ("Processor", "MagicScreen"); and
the entity identified on the Order Form ("Controller", "Customer").
It applies to the Processing of Personal Data by MagicScreen on behalf of the Customer in connection with the Service.
If there is a conflict between this DPA and the Agreement, this DPA prevails in relation to data protection matters.
2. Definitions
Terms not defined here have the meaning given in the UK GDPR or EU GDPR as applicable. In this DPA:
"Applicable Data Protection Law" means, as relevant to the Processing: UK GDPR; the UK Data Protection Act 2018; the EU General Data Protection Regulation (EU) 2016/679; and any implementing or supplementary legislation.
"Customer Personal Data" means Personal Data that MagicScreen Processes on behalf of Customer under the Agreement.
"Restricted Transfer" means a transfer of Customer Personal Data to a country not recognised as providing an adequate level of protection.
"Sub-processor" means a third party engaged by MagicScreen to Process Customer Personal Data.
3. Roles of the parties
Customer is the Controller of Customer Personal Data. MagicScreen is the Processor. Where required by Applicable Data Protection Law, MagicScreen will provide reasonable cooperation to Customer's data protection authority.
4. Processing instructions
4.1 Customer instructions
MagicScreen will Process Customer Personal Data only:
on documented instructions from Customer, including as set out in the Agreement, this DPA, and the Service's configuration; and
as required by applicable law (in which case MagicScreen will notify Customer unless prohibited).
4.2 Lawful instructions
Customer warrants that its instructions, and the Processing of Customer Personal Data under the Agreement, comply with Applicable Data Protection Law. Customer is responsible for the lawfulness of the Personal Data it provides and for obtaining any required consents or providing any required notices to data subjects (including candidates).
4.3 Notice of unlawful instructions
If MagicScreen considers an instruction to infringe Applicable Data Protection Law, it will inform Customer without undue delay.
5. Details of Processing
See Annex 1 for the subject matter, duration, nature and purpose, categories of data, categories of data subjects, and any special category data.
6. No use for other purposes
MagicScreen will not:
sell Customer Personal Data;
use Customer Personal Data for direct marketing;
combine Customer Personal Data with Personal Data MagicScreen holds for its own purposes; or
use Customer Personal Data to train AI models, except for service-specific, ephemeral, customer-isolated use strictly necessary to provide the Service (and never for general-purpose model training).
7. Personnel
MagicScreen will ensure that personnel authorised to Process Customer Personal Data:
are bound by contractual or statutory confidentiality obligations;
access Customer Personal Data on a need-to-know basis; and
receive appropriate training on data protection.
8. Security
MagicScreen will implement appropriate technical and organisational measures to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access — see Annex 2.
MagicScreen may update its security measures from time to time, provided the overall level of security is not reduced.
9. Sub-processing
9.1 General authorisation
Customer grants MagicScreen a general authorisation to engage Sub-processors, subject to this Section 9.
9.2 Current Sub-processors
The current list of Sub-processors is published at the Subprocessor List page on our website and reproduced in our Subprocessor List.
9.3 Notification of changes
MagicScreen will provide at least 30 days' prior notice of any new or replacement Sub-processor by email (where Customer has subscribed to updates) or by updating the published list.
9.4 Objection
Customer may object to a new Sub-processor on reasonable data protection grounds within the notice period. The parties will work in good faith to resolve the objection. If unresolved, Customer may terminate the affected part of the Service and receive a pro-rata refund of prepaid unused Fees.
9.5 Obligations on Sub-processors
MagicScreen will impose on each Sub-processor data protection obligations that are no less protective than those in this DPA and will remain liable for Sub-processors' acts and omissions.
10. Data subject rights
10.1 Assistance
MagicScreen will provide reasonable assistance to enable Customer to respond to requests from data subjects exercising their rights under Applicable Data Protection Law (access, rectification, erasure, restriction, portability, objection, not to be subject to automated decision-making).
10.2 Direct requests
If MagicScreen receives a request directly from a data subject (e.g. a candidate), it will promptly forward it to Customer and will not respond itself (unless legally required or instructed by Customer to do so).
11. Personal data breaches
MagicScreen will:
notify Customer without undue delay (and in any event within 72 hours) after becoming aware of a Personal Data Breach affecting Customer Personal Data;
provide information reasonably required to meet Customer's notification obligations, including the nature of the breach, categories and approximate numbers of data subjects and records affected, likely consequences, and measures taken or proposed; and
cooperate with Customer's investigation and remediation efforts.
This Section does not require MagicScreen to notify Customer of unsuccessful attempts or routine security events that did not result in a breach.
12. Assistance with DPIAs and prior consultation
MagicScreen will provide reasonable assistance to Customer with Data Protection Impact Assessments and prior consultations with supervisory authorities, taking into account the nature of Processing and the information available to MagicScreen.
13. International transfers
Where a Restricted Transfer occurs:
from the UK, the parties enter into the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses;
from the EEA, the parties enter into the EU Standard Contractual Clauses (2021/914), Module 2 (Controller to Processor) or Module 3 (Processor to Processor), as applicable.
Both the UK IDTA/Addendum and the EU SCCs are incorporated by reference and deemed executed on the Effective Date of this DPA, with the Customer as "data exporter" and MagicScreen as "data importer". Optional clauses are elected as set out in Annex 3.
14. Return or deletion
On expiry or termination of the Agreement, MagicScreen will, at Customer's choice:
make Customer Personal Data available for export for 30 days; and thereafter
delete or anonymise Customer Personal Data from MagicScreen's production systems within 60 days, and from backups within its standard backup retention period (not exceeding 12 months),
except to the extent retention is required by law.
On request, MagicScreen will certify compliance with this Section in writing.
15. Audits
15.1 Information obligation
MagicScreen will make available to Customer the information necessary to demonstrate compliance with Art. 28 UK/EU GDPR.
15.2 Audit rights
Customer may audit MagicScreen's compliance with this DPA once per year, or more frequently if required by a supervisory authority or following a Personal Data Breach. Audits will:
be conducted on at least 30 days' prior written notice;
take place during normal business hours;
be subject to MagicScreen's confidentiality and security policies;
not unreasonably interfere with MagicScreen's business; and
at Customer's cost (except where the audit identifies a material breach, in which case MagicScreen bears reasonable audit costs).
MagicScreen may satisfy audit requests by providing recent independent audit reports (e.g. ISO 27001, SOC 2), unless Customer can show why these are not sufficient.
16. Liability
The liability of each party under this DPA is subject to the limitations and exclusions set out in the Agreement.
17. Term
This DPA is effective from the Effective Date of the Agreement and remains in force for as long as MagicScreen Processes Customer Personal Data on Customer's behalf. Sections that by their nature should survive (including 6, 8, 11, 14, 15, and 16) survive termination.
Annex 1 — Details of Processing
Subject matter: provision of the MagicScreen candidate screening platform to Customer.
Duration: the term of the Agreement plus any period during which MagicScreen continues to hold Customer Personal Data pursuant to Section 14.
Nature and purpose:
- hosting and storing Customer Personal Data;
- running AI-assisted screening workflows (text, audio, and/or video input) configured by Customer;
- generating scores, summaries, and recommendations for human review by Customer;
- providing analytics and reporting to Customer;
- providing technical support.
Categories of data subjects:
- Customer's employees and authorised Users;
- Candidates whose data is processed by Customer using the Service.
Categories of Personal Data:
- Identification data (name, email, phone)
- Professional data (CV, work history, skills, qualifications, references)
- Application data (cover letters, application answers)
- Interview responses (text, audio, and/or video recordings)
- Candidate-generated content
- Usage metadata (timestamps, device and browser information)
- AI-generated outputs associated with the above
Special category / sensitive data: Customer should not submit special category data or criminal offence data unless expressly configured and justified. If it does, the Processing relies on the lawful basis and condition identified by Customer.
Frequency of Processing: continuous, for the duration of the Agreement.
Annex 2 — Technical and Organisational Measures
MagicScreen implements the following security measures:
Access control
- Role-based access control; least-privilege principles
- Mandatory multi-factor authentication for employee access to production
- Quarterly access reviews
Encryption
- TLS 1.2+ in transit
- AES-256 at rest
Network security
- Web Application Firewall; DDoS protection
- Network segmentation between environments
Application security
- Secure Software Development Lifecycle
- Dependency scanning; static analysis
- Annual third-party penetration testing
- Responsible disclosure: security vulnerabilities can be reported to hello@techmagic.co
Operational security
- Centralised logging and monitoring
- Incident response plan with defined severity levels and response times
- Business continuity and disaster recovery plans with tested RTO/RPO
- Documented backup policy with encrypted backups
Personnel
- Background checks where lawful
- Mandatory security and data protection training
- Confidentiality obligations
Physical security
- Production Processing is hosted in ISO 27001–certified data centres operated by our hosting Sub-processor
- TechMagic's Ukraine operational offices (Lviv) apply physical access controls, CCTV, and visitor logging; personnel access to production systems is via encrypted remote session only
Certifications / attestations - TechMagic publishes its current security certifications at https://www.techmagic.co/certifications. Specific certifications applicable to the MagicScreen Service will be updated here as they are confirmed.
Annex 3 — International Transfers
UK IDTA / UK Addendum elections:
- Table 1: Parties and signatures — per the Agreement and this DPA.
- Table 2: Transfer Details — per Annex 1 above.
- Table 3: Appendix Information — Annex 1 and Annex 2 of this DPA.
- Table 4: Ending the IDTA when the Approved Addendum Changes — either party may end the IDTA as set out in the Approved Addendum.
EU SCCs (2021/914) elections:
- Module: 2 (C2P) or 3 (P2P) as applicable.
- Clause 7 (Docking): not used.
- Clause 9 (Sub-processors): Option 2 (general authorisation), 30 days' notice.
- Clause 11 (Redress): optional language not used.
- Clause 17 (Governing law): law of Ireland (or, where the data exporter is established in another EU/EEA Member State, the law of that Member State).
- Clause 18 (Forum and jurisdiction): courts of Ireland (or, where the data exporter is established in another EU/EEA Member State, the courts of that Member State).
- Annex I.A Parties: per the Agreement.
- Annex I.B Description of Transfer: Annex 1 above.
- Annex I.C Competent Supervisory Authority: the Irish Data Protection Commission, unless the data exporter has a different lead supervisory authority designated.
- Annex II Technical and Organisational Measures: Annex 2 above.
- Annex III List of Sub-processors: the Subprocessor List page on our website.