Legal
Data processing agreement
How we process personal data for customers of MagpieCRM Cloud, under Article 28 of the UK GDPR and the EU GDPR.
Last updated 27 September 2026
This Data Processing Agreement ("DPA") forms part of the terms of service between Mr PNA Greenall, trading as MagpieCRM, of 35a Highbury Corner, London N5 1RA ("MagpieCRM", "we"), and the customer named in the account ("Customer", "you") for MagpieCRM Cloud (the "Service").
1. Roles
1.1 For personal data you put into, or obtain through, the Service ("Customer Personal Data"), you are the controller and we are your processor.
1.2 This includes people you find with prospect search. Whether and how you contact them, and your lawful basis for it, are your decisions as controller. The Service helps you meet your obligations (see Annex 2), but doesn't make those decisions for you.
1.3 For data about you as our customer (account holders, billing), we are a controller under our own privacy notice; this DPA doesn't cover that.
2. Instructions
2.1 We process Customer Personal Data only on your documented instructions: this agreement, your use and configuration of the Service, and any other instructions you give in writing that we agree are consistent with it.
2.2 We tell you if we believe an instruction breaks data protection law, unless the law forbids us to.
2.3 We don't sell Customer Personal Data or use it for our own purposes. Search results are not stored or shared between customers; only non-personal company information (such as a company's email format, or whether its mail server accepts every address) may be kept and reused to run the Service. The one exception is the list of people who have opted out, kept as keyed hashes, so that someone who objects is respected in every customer's workspace.
3. Confidentiality
Everyone we authorise to process Customer Personal Data is bound by confidentiality.
4. Security
We keep the technical and organisational measures in Annex 2, and may improve them, but won't reduce the overall level of protection.
5. Personal data breaches
We tell you without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data, with the information you need to meet your own notification duties, and help you respond.
6. Sub-processors
6.1 You authorise the sub-processors on our sub-processor list.
6.2 We tell you about any new or replacement sub-processor at least 30 days before it starts processing Customer Personal Data. If you object on reasonable data protection grounds, we'll discuss it in good faith; if we can't resolve it, you may end the affected part of the Service and get a refund of any prepaid fees for the rest of the period.
6.3 We put data protection terms on each sub-processor that are no less protective than this DPA, and we remain responsible to you for them.
7. International transfers
We only transfer Customer Personal Data outside the UK and EEA with a valid safeguard (an adequacy decision, the UK International Data Transfer Agreement or Addendum, or the EU Standard Contractual Clauses), as shown on the sub-processor list.
8. Helping you
8.1 Data subject requests. The Service lets you find, export, correct and delete contacts, stops unsubscribed contacts receiving campaigns, and keeps a suppression list so people who opt out aren't found or saved again through prospect search. We pass on any request we receive directly, and help with requests you can't handle yourself. Contact us at pele@magpiecrm.com.
8.2 Assessments. We give reasonable help with data protection impact assessments and consultations with a supervisory authority, as far as they concern the Service.
9. Deletion and return
9.1 You can export your data at any time during the subscription.
9.2 When the Service ends, we delete Customer Personal Data from the live Service within 30 days, unless the law requires us to keep it. Encrypted backups are overwritten on their normal cycle and are gone within three months.
10. Audits
We make available the information needed to show we meet this DPA, and allow and contribute to audits by you or an auditor you appoint, with reasonable notice, at most once a year unless there's been a breach or a regulator requires it, and subject to confidentiality.
11. Liability and precedence
Each party's liability under this DPA is subject to the limits in the main agreement. If this DPA and the main agreement conflict about personal data, this DPA wins.
Annex 1: Details of processing
| Subject matter | Providing MagpieCRM Cloud: prospect search, email finding and verification, contact and list management, email campaigns, forms, surveys, and the in-app copilot. |
|---|---|
| Duration | The subscription, plus the deletion periods in clause 9. |
| Nature and purpose | Storing, organising and displaying Customer Personal Data; finding and verifying business email addresses; sending the Customer's email campaigns and recording opens, clicks, bounces and unsubscribes; collecting form and survey responses. |
| Data subjects | The Customer's contacts and prospects (mostly business contacts), form and survey respondents, and the Customer's own users. |
| Categories of data | Names, work email addresses, job titles and seniority, company, company domain, country, professional profile URL, custom contact fields the Customer adds, email engagement (opens, clicks, bounces, unsubscribes), form and survey answers, notice and opt-out status, and users' login details. |
| Special category data | Not intended. The Customer must not use the Service for it. |
Annex 2: Security measures
- Separation: each customer runs their own copy of the app in its own container, with its own data folder and its own encryption keys; no customer's data is stored with another's.
- Encryption: HTTPS for all traffic; saved credentials encrypted at rest (AES-256-GCM); backups encrypted before they leave our servers.
- Access: customers sign in through our identity provider, with multi-factor authentication available, and enter their workspace with a one-time link; workspace sessions use HttpOnly cookies and end on the server at sign-out. Our own server access is by SSH key only, and our admin area sits behind a separate identity-checking gateway.
- Sending: email goes out only from domains the Customer has verified with DKIM and shown they own. Bounces mark the contact as bounced and spam complaints unsubscribe them automatically.
- Abuse monitoring: we watch each customer's sending volume, bounce and complaint rates, as counts only, never the content of their email, and pause sending that puts other customers' delivery at risk.
- Minimisation: prospect search results aren't stored; only the fields needed (name, job title, seniority, company, domain, country, profile URL) are kept when the Customer saves a contact. Profile lookups are held in memory for at most 24 hours. Logs record counts and outcomes, not names or email addresses.
- Opt-outs: unsubscribed contacts don't receive campaigns, and a suppression list, kept as keyed hashes, stops people who opted out being shown, revealed or saved from prospect search again. Every reveal and save is recorded in a disclosure log (as hashes) so the Customer can show where a contact came from.
- Verification: only addresses that are likely to exist are checked, under rate limits per mail provider and per company; no email is sent to the person during verification.
- Resilience: nightly encrypted backups with 14 daily, 8 weekly and 3 monthly copies; monitoring and alerts for the verification servers.
- Suppliers: sub-processors are chosen for their security and bound by written data protection terms.