top of page

GDPR

Last updated:

Sep 25, 2026

Magipic.ai
Last updated: September 25, 2026

Data Processing & GDPR. This page is for businesses that use Magipic to run event experiences and need to know, in one place, how we handle their guests' data as a processor. Our full Privacy Policy covers everything else. A signed Data Processing Agreement is available on request at [email protected].

1. Roles

You (the account holder, or your client when you run events for them) are the data controller of guest data. Magipic.ai is your data processor. We act only on your documented instructions, which are the settings you configure in the platform and any written instructions you give us.

2. What We Process for You

Guest photos and short videos, the AI images and videos generated from them, and the email address a guest gives to receive their result. Where you use guest lead capture, the fields you configure (for example name, company, job title).

3. Our Processor Commitments

  1. Purpose limitation: guest content is used only to generate and deliver results and to provide support to you. No secondary use.

  2. No AI training: guest photos, videos and outputs are never used to develop, train, fine-tune, evaluate or improve any AI or machine learning model, ours or anyone else's. Our sub-processors are bound by the same restriction.

  3. No biometrics: we do not identify people from their faces, do not create or store face templates or embeddings, and do not keep a biometric database.

  4. No marketing use of your content without your written approval.

  5. Confidentiality: our team and contractors are bound by confidentiality obligations and access guest content only when needed for support.

  6. Security: encryption in transit and at rest, access controls, per-client credentials, secure deletion.

  7. Retention and deletion: guest content is deleted automatically 30 days after the event ends, or within 7 days of your verified request, whichever is sooner. Backups are overwritten within 30 days.

  8. Breach notification: without undue delay and, where reasonably practicable, within 24 hours of confirming a breach affecting your data.

  9. Assistance: we help you respond to guest rights requests and to complete data protection or privacy impact assessments that involve our processing.

  10. Sub-processors: summarised below, full named list in Annex 2 of the DPA. We give account holders 14 days' notice by email before adding a new sub-processor that will handle guest content.

  11. Audit: we provide the information reasonably needed to demonstrate compliance, and we answer security questionnaires.

  12. End of service: on account closure we delete your data as described in point 7 unless the law requires us to keep specific records.

4. Sub-Processors That Handle Guest Content

Guest photos and outputs are processed by our cloud and API providers (for AI generation, and for hosting live galleries, in the United States) under their standard terms and data processing addenda, which prohibit using customer data to train or fine-tune AI models without our permission. We have given no training opt-in. Certain video filters run on specialist AI model providers that are bound by no-training terms and receive guest content only for the moment of generation. Two further providers touch guest data in transit only: our application hosting provider and our transactional email provider (both United States). All other providers handle account holder and website data only and never receive guest photos or outputs.

The full named list, with locations and contract terms, is Annex 2 of our Data Processing Agreement and is available on request. Account holders under a DPA get 14 days' notice before we add a sub-processor that handles guest content.

5. International Transfers

Guest content is processed in the United States. Transfers from the EEA and UK rely on the EU-US Data Privacy Framework where the provider is certified and otherwise on Standard Contractual Clauses with the UK Addendum. Israel holds EU and UK adequacy. Controllers in Quebec should note in their privacy impact assessment that guest data leaves Quebec.

6. Guest Rights Requests

Send them to [email protected] with the event name and date. We act within 7 days for deletion and within 30 days for access or export.

7. How to Get a DPA

Email [email protected] with your legal entity name and address. We return a signed DPA within 5 business days. Enterprise clients with their own paper: send it over, we review it.

bottom of page