Data Processing Agreement
MageMate
Part of Falcon Media
Brilweg 1
9801 GC Zuidhorn
The Netherlands
Email: hello@magemate.com
Phone: +31 (0)85 - 303 7 808
Chamber of Commerce: 72120134
VAT: NL001442949B86
Data Processing Agreement
Last updated: June 21, 2026
MageMate is a trade name operating under Falcon Media, located at Brilweg 1, 9801 GC Zuidhorn, The Netherlands, registered with the Dutch Chamber of Commerce under number 72120134.
1. Parties and definitions
This data processing agreement ("DPA") applies to the processing of personal data by:
- Processor: MageMate, trade name of Falcon Media.
- Controller: the customer that has an account with MageMate and uses the AI assistant service.
This DPA forms an integral part of the agreement between MageMate and the Client and has been drafted in accordance with Article 28 of the GDPR.
In this DPA, the following definitions apply:
- Personal data: any information relating to an identified or identifiable natural person (Article 4(1) GDPR).
- Processing: any operation performed on personal data (Article 4(2) GDPR).
- Data subject: the natural person to whom the personal data relates, including website visitors of the Client.
- Personal data breach: a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data.
2. Subject and duration of processing
MageMate processes personal data only on behalf of and for the benefit of the Client in the context of providing the AI assistant service. The processing takes place during the term of the agreement.
The processing includes receiving, storing, analyzing through AI, and making available chat conversations and contact details of website visitors. If the Magento integration is active, the processing also includes retrieving and processing Magento data to the extent necessary for the AI assistant and dashboard.
3. Nature and purpose of processing
The purpose of the processing is:
- Conducting automated chat conversations with website visitors through the AI assistant.
- Extracting and storing contact details (leads) voluntarily provided by website visitors.
- Making chat history and lead data available through the dashboard.
- Sending notifications to the Client about new leads.
4. Types of personal data
The following categories of personal data are processed:
- Chat messages: the content of conversations between website visitors and the AI assistant.
- Contact details: name, email address, and phone number, to the extent voluntarily provided.
- Technical data: anonymized IP address, browser information, and page URL.
- Magento data (if active): catalog data, product data, and, where enabled, order and customer data retrieved through the Magento API and processed to the extent necessary for the services.
5. Categories of data subjects
- Website visitors of the Client who interact with the AI assistant (chat widget).
6. Obligations of the Processor
MageMate undertakes to:
- Process personal data only on the basis of written instructions from the Client, unless otherwise required by law.
- Ensure that persons authorized to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
- Implement all required security measures in accordance with Article 32 GDPR.
- Comply with the conditions in this DPA regarding the engagement of subprocessors.
- Assist the Client in fulfilling its obligations regarding data subject rights (Articles 15 through 22 GDPR).
- Assist the Client in ensuring compliance with the obligations set out in Articles 32 through 36 GDPR.
- After termination of the agreement, delete or return all personal data, at the Client's choice, unless storage is legally required.
- Make available all information necessary to demonstrate compliance with this DPA and enable audits and inspections.
MageMate enables the Client, after reasonable prior notice of at least 30 days, to carry out audits or have audits carried out by an independent third party. Audits take place during office hours and at the Client's expense, unless the audit shows that MageMate does not comply with this DPA.
7. Obligations of the Controller
The Client is obliged to:
- Inform website visitors about the use of the AI assistant.
- Have a valid legal basis for the processing.
- Ensure that data subjects can exercise their GDPR rights.
- Inform MageMate in a timely manner about instructions relating to the processing.
8. Security measures
MageMate implements the following measures:
- Encryption: all sensitive personal data is stored encrypted (AES-256).
- IP anonymization: IP addresses are anonymized to /24 subnet.
- Secure connections: all communication takes place via HTTPS/TLS.
- Access control: token-based authentication.
- Two-factor authentication: available for all accounts.
- Audit logging: all account activities are logged.
- Password security: passwords are hashed with bcrypt.
- Rate limiting: API requests are limited to prevent misuse.
9. Subprocessors
The Client grants MageMate general written permission to engage subprocessors. MageMate informs the Client about changes to the list of subprocessors. The Client has the right to object to changes.
The following subprocessors are currently engaged:
SubprocessorPurposeLocationAnthropicAI processing of chat messages to generate responses.United States (SCCs)Meta Platforms (WhatsApp Business)WhatsApp notifications about leads and conversations if enabled.EU/US (SCCs)CloudflareSecurity and anti-bot protection.Worldwide (SCCs)SiteGroundStorage and processing of data on secure servers.EU/EEA
Appropriate data processing agreements have been concluded with each subprocessor. For transfers outside the EEA, the European Commission Standard Contractual Clauses (SCCs, version 2021/914) apply.
For subprocessors established outside the EEA, MageMate has carried out a Transfer Impact Assessment (TIA) to assess whether the level of protection in the recipient country is equivalent in practice to that within the EEA and whether the additional measures taken are adequate.
10. AI processing and training prohibition
- Personal data is not used in any way to train AI models.
- A data processing agreement has been concluded with Anthropic that safeguards this.
- Magento data is processed only to the extent necessary for the AI assistant, dashboard, and active Magento integration.
11. Special categories of personal data
It may occur that website visitors of the Client provide special categories of personal data through the AI assistant within the meaning of Article 9 GDPR, such as health data in the context of a personal injury lawyer or medical practice.
MageMate takes the following measures to protect special categories of personal data:
- Automatic detection: the system automatically detects when chat messages contain special categories of personal data, such as health, religion, sexual orientation, ethnic origin, political opinions, and criminal data.
- Filtering: data such as Dutch citizen service numbers (BSN), credit card numbers, IBAN numbers, and identity document numbers are automatically removed from messages before storage.
- AI instructions: the AI assistant is instructed never to actively ask for special categories of personal data.
- Encryption: all chat messages are stored encrypted (AES-256).
- Limited retention period: chat conversations are automatically deleted after a maximum of 180 days.
As controller, the Client is responsible for establishing a valid legal basis for the processing of special categories of personal data (Article 9(2) GDPR), such as explicit consent of the data subject (sub a) or necessity for the establishment, exercise, or defense of legal claims (sub f).
12. Personal data breach notification
MageMate informs the Client without undue delay, and where possible within 24 hours, after becoming aware of a personal data breach. The notification contains:
- The nature of the breach and the estimated number of data subjects.
- The likely consequences.
- The measures taken or proposed.
13. Data subject rights
In the event of requests from data subjects, MageMate will:
- Forward the request to the Client immediately.
- Assist the Client in responding to the request.
- Provide technical cooperation in carrying out the request.
14. Retention periods
- Chat conversations and messages: maximum 180 days.
- Lead data: for the duration of the subscription, maximum 6 months after termination.
- Technical log data: maximum 180 days.
After the retention period expires, data is automatically and permanently deleted.
15. Termination
Upon termination of the agreement, MageMate will:
- Return all personal data upon request (JSON export).
- After return or within 30 days after termination, permanently delete all data.
- Confirm in writing that all data has been deleted.
16. Liability
Liability under this DPA is governed by the liability provisions in MageMate's terms and conditions.
17. Governing law and disputes
This DPA is governed by Dutch law. Disputes will be submitted to the competent court in the Netherlands.
18. Contact
For questions about this data processing agreement, please contact:
MageMate
Part of Falcon Media
Brilweg 1
9801 GC Zuidhorn
The Netherlands
Email: hello@magemate.com
Phone: +31 (0)85 - 303 7 808
Chamber of Commerce: 72120134
VAT: NL001442949B86
Falcon Media · Chamber of Commerce 72120134 · VAT NL001442949B86 · hello@magemate.com