Magnific AI procurement policy evidence
Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.
| Topic | Plan or tier | Risk | Their words | Source |
|---|---|---|---|---|
| DPA, audit rights & data residency | All applicable tiers | low | “Magnific enters into Standard Contractual Clauses (Art. 46.2.c) of the GDPR with all third-party model providers it offers.” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | medium | “Some of these external service providers are located outside the European Economic Area (EEA), so the processing of your personal data involves an international data transfer. Your data may be transferred outside the European Union in accordance with the terms established in this Privacy Policy, and in the specific information notices for certain tools, but will not be disclosed to third parties, except in cases expressly provided for in the applicable regulations or when necessary for the provision of the contracted services.” | Captured 2026-06-07Open source →Finding permalink → |
| Data retention | All applicable tiers | low | “personal data is retained for a maximum of 30 days after the generation of the Output.” | Captured 2026-06-07Open source →Finding permalink → |
| Data retention | All applicable tiers | medium | “We retain the personal information we collect only for as long as is reasonably necessary for the purposes described above or as communicated to you. For example, we will retain information as necessary to comply with our tax, accounting and record-keeping obligations, to provide you with the Services, and for an additional period of time as necessary to protect, defend or establish our rights, defend against potential claims and comply with our legal obligations. In some cases, instead of deleting your personal information, we may de-identify or aggregate it and use it in accordance with the CCPA.” | Captured 2026-06-07Open source →Finding permalink → |
| Data retention | All applicable tiers | low | “In relation to the sending of commercial communications, the data will be processed for three years from the last interaction with you, or until you decide to object, whichever occurs first.” | Captured 2026-06-07Open source →Finding permalink → |
| Data retention | All applicable tiers | low | “In relation to the data necessary to manage and fulfil our contractual relationships with users, your personal data is processed while the contractual relationship continues, and is subsequently kept blocked for a period of five years (until the statute of limitations for possible contractual liabilities or intellectual property rights claims) or six years (in relation to documentation for accounting purposes).” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “This option is possible thanks to the collaboration between Magnific and Google as joint controllers of the processing of your personal data, so that (i) you can identify yourself directly on said platform, (ii) they confirm to us that you are who you say you are, and (iii) we facilitate your registration as a registered user on Magnific. Magnific obtains from this platform, with your consent, your username, image and your email address for the purpose of registering you as a Magnific user. On the other hand, these platforms capture online identifiers (IP address), technical identifiers (of your device, as well as its advertising identifiers such as "Google ID") and record, each time you use their login, the date and time of your access to Magnific.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “The Magnific Group of Companies, with the purpose and interest of centralising administrative and business infrastructure functions and to benefit from the functional specialisation and compartmentalisation inherent to these corporate structures, will carry out intra-group personal data processing of providers, users and employees based on our legitimate corporate interests. These processing operations, depending on the case, are carried out mainly as data processor and exceptionally as joint controller (for the execution of strategic decisions of the Group). **Data origin:** each of the Group’s subsidiaries collects the relevant data directly from the data subject in each case. **Personal data subject to processing:** depending on the processing: basic identification and contact data, data necessary to perform the login (single login), economic and professional data, image, audio and video (contractual management of providers –creators and models), data and metadata from web browsing (IT and web security processing). ” | Captured 2026-06-07Open source →Finding permalink → |
Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.