Legal

Security

The technical and organizational measures (TOMs) we apply to protect data. This page details the security commitment required by Article 32 GDPR under the data processing agreement (DPA).

Last updated: July 8, 2026

1. Overview

MagicDots applies appropriate technical and organizational measures to protect data against unauthorized access, loss, alteration or disclosure. This page describes these measures and constitutes the security annex (Article 32 GDPR) to the data processing agreement in the Privacy Policy.

2. Encryption

Data is encrypted in transit (HTTPS/TLS) between the browser, the application and the infrastructure. Data stored in the database is encrypted at rest at the storage layer provided by Supabase/PostgreSQL.

3. Authentication and access control

Account passwords are stored encrypted (hashed), never in plain text. Internal access to systems and data is restricted on a need-to-know basis.

Payments are processed by Stripe, a certified payment processor; MagicDots does not store full card data.

4. Data isolation between accounts (multi-tenant)

The platform is multi-tenant, and each merchant's data is logically isolated. We apply Row-Level Security rules to prevent one account from accessing another account's data.

5. Monitoring and logging

We technically monitor the platform and record events relevant to security and diagnostics. Error reporting is configured to exclude shoppers' personal data (PII scrubbing).

6. Sub-processors and data minimization

We use a limited set of trusted providers, listed at magicdots.io/subprocessors, each bound by equivalent data-protection obligations. The AI features receive only merchant-authored text, product-catalog information and aggregate statistics — not shoppers' personal data.

7. Security incident response

In the event of a breach of the security of shopper data, we will notify the merchant (the controller) without undue delay and, in any event, within 48 hours of becoming aware of the incident, providing the information set out in Article 33(3) GDPR to the extent available.

No system can guarantee absolute security; however, we are committed to applying appropriate measures and continuously improving them.

8. Vulnerability reporting

If you discover a possible security vulnerability, please contact us responsibly at contact@magicdots.io. We will review the report and take the necessary measures.

The Romanian-language version of this document is the official version and prevails in case of any discrepancy with translations.