MagOneAI Platform Terms
The terms governing access to and use of the MagOneAI platform, deployed within your own cloud environment.
Magure Tech Middle East Ltd
DIFC registration CL8230 · Unit 195, Level 1, Gate Avenue — South Zone, DIFC, Dubai, UAE
These MagOneAI Platform Terms (the "Terms") govern access to and use of the MagOneAI platform provided by Magure Tech Middle East Ltd, DIFC registration CL8230, Unit 195, Level 1, Gate Avenue — South Zone, DIFC, Dubai, UAE ("Magure"), by the customer identified in the applicable Customer Order Form ("Customer").
Acceptance. By signing or otherwise accepting a Customer Order Form that references these Terms — whether the Customer Order Form is placed directly with Magure or through a Magure-authorised reseller (the "Reseller of Record") — Customer accepts these Terms. Customer's execution of the Customer Order Form constitutes execution of these Terms, which form a binding agreement solely between Customer and Magure. These Terms apply to every Customer Order Form irrespective of whether it expressly references them.
1Definitions
“Affiliate” — an entity that controls, is controlled by, or is under common control with a Party.
“Authorised User” — Customer’s employees, contractors, and Affiliate personnel authorised to use the Platform.
“Confidential Information” — non-public information disclosed by a Party that is marked confidential or would reasonably be understood as confidential.
“Customer Application” — workflows, agents, prompts, configurations, integrations, and business logic created by or for Customer using the Platform.
“Customer Cloud Environment” — the cloud, hybrid, or on-premise infrastructure designated by Customer in which the Platform is deployed.
“Customer Data” — data, content, and inputs provided by or for Customer to the Platform.
“Customer Order Form” — an ordering document specifying the Services, fees, and term, signed between Customer and the Reseller of Record (or, for a direct purchase, placed with Magure), by which Customer purchases the Services and accepts these Terms.
“Documentation” — Magure’s then-current product documentation for the Platform.
“End User” — a customer or user of Customer’s own services who interacts with a Customer Application.
“Foundation Model” — any AI model invoked through the Platform’s model gateway, whether third-party-hosted, open-weight, or Customer-deployed.
“Intellectual Property Rights” — all intellectual property rights worldwide, registered or unregistered, including patents, trademarks, copyright, design and database rights, trade secrets, and know-how.
“Magure Platform Technology” — the Platform, software, APIs, agent frameworks, orchestration engines, any Magure-proprietary models, templates, user interfaces, Documentation, and all underlying or derivative technology, excluding Customer Applications and Customer Data.
“Output” — content or results generated by the Platform from Customer’s inputs.
“Personal Data” — information relating to an identified or identifiable natural person under applicable law.
“Platform” — MagOneAI, Magure’s enterprise agentic AI platform, as deployed in the Customer Cloud Environment.
“Reseller of Record” — a reseller authorised by Magure in writing and named in a Customer Order Form.
“Services” — the Platform subscription and any implementation, managed, or professional services identified in a Customer Order Form.
“Support Terms” — Magure’s support and service-level terms (Schedule 1).
2The Platform and Deployment
2.1 Licence. Subject to these Terms, Magure grants Customer a non-exclusive, non-transferable, non-sublicensable right during the term for Authorised Users to access and use the Platform, deployed in the Customer Cloud Environment, for Customer’s internal business purposes.
2.2 Deployment split. The Platform runs within the Customer Cloud Environment. Customer procures and pays for all underlying infrastructure and all Foundation Model API consumption directly, and is responsible for the security, configuration, availability, backups, and disaster recovery of that environment up to the application layer, and for granting Magure least-privilege, time-bound access to deploy and support the Platform. Magure is responsible for the Platform software, its updates and security patches within the application layer, and for Services performed in a professional and workmanlike manner.
2.3 Model-agnostic. The Platform supports third-party-hosted, open-weight, and Customer-deployed Foundation Models. Magure provides the integration, gateway, orchestration, and observability, but is not the developer or licensor of any Foundation Model unless expressly identified as a Magure model in a Customer Order Form. Customer is responsible for its Foundation Models, including their performance, availability, and lifecycle.
3Orders, Reseller of Record, and Payment
3.1 Purchases through a Reseller of Record. Where Customer purchases through a Reseller of Record, all fees, invoicing, credit terms, and payment are solely between Customer and the Reseller of Record under their own agreement. Magure is not part of the payment flow and issues no invoices to Customer. Customer’s payment obligation to the Reseller of Record is independent of Magure’s performance, and Magure’s obligations under these Terms are not conditioned on Customer’s payment to the Reseller of Record.
3.2 Independence of the Parties; Separate Agreements. The Reseller of Record is an independent reseller under a separate agreement with Magure and is not Magure’s agent. Nothing in these Terms binds the Reseller of Record, and nothing in Customer’s agreement with the Reseller of Record binds Magure. Magure is not bound by, and has no liability for, any representation, warranty, service level, pricing, or other commitment made by the Reseller of Record that is not contained in these Terms, the Documentation, or a writing signed by Magure. Payment and commercial terms agreed between Customer and the Reseller of Record are not binding on Magure.
3.3 Direct obligations preserved. Other than the payment and invoicing arrangements in this Clause 3, all of Magure’s obligations and Customer’s rights under these Terms — deployment, intellectual property, confidentiality, data protection, warranties, service levels, AI provisions, and indemnities — apply directly between Magure and Customer, unaffected by the Reseller of Record.
3.4 Suspension. Magure may suspend the Platform on notice for non-payment of amounts owed to Magure under the Customer Order Form (whether by Customer or the Reseller of Record) beyond fifteen (15) days past due, or for security or legal risk caused by Customer’s use. Customer may avoid or lift such suspension by paying the outstanding amounts under its Customer Order Form directly to Magure, which discharges Customer’s corresponding obligation to the Reseller of Record to that extent.
3.5 Direct purchases. Where Customer purchases directly from Magure, Magure invoices Customer, payment is due within thirty (30) days of invoice date, undisputed late amounts accrue interest at 1.5% per month, and fees are exclusive of taxes.
3.6 Renewal price. Fees may increase by up to 5% year-on-year on each renewal, on at least thirty (30) days’ prior written notice.
3.7 Excluded costs. Foundation Model API consumption and Customer Cloud Environment costs are paid by Customer directly to the relevant providers and are not Magure fees.
4Customer Responsibilities and Acceptable Use
Customer is responsible for its Authorised Users and for safeguarding credentials, and for the accuracy, legality, and quality of Customer Data and obtaining all necessary rights and consents. Customer shall not, and shall not permit any user to:
- (a) use the Platform for any unlawful, harmful, or infringing purpose;
- (b) reverse-engineer, decompile, or attempt to derive the Platform’s source code, except as permitted by law;
- (c) circumvent security, authentication, rate-limiting, or model-safety controls;
- (d) develop a competing product or benchmark the Platform for competitive purposes;
- (e) sublicense, resell, rent, lease, or use the Platform in a service-bureau or commercial-hosting arrangement without Magure’s written consent;
- (f) use the Platform for prohibited AI practices under applicable law (e.g., social scoring, real-time biometric mass surveillance, manipulative or exploitative AI); or
- (g) use the Platform to make fully autonomous decisions producing legal or similarly significant effects on individuals without meaningful human oversight.
5Intellectual Property
5.1 Magure ownership. Magure and its licensors retain all right, title, and interest, including all Intellectual Property Rights, in the Magure Platform Technology. No ownership transfers to Customer by these Terms or by use of the Services.
5.2 Customer ownership. Customer retains all right, title, and interest in assets it creates using the Platform — workflows, agents, prompts, knowledge bases populated with Customer Data, integrations, custom interfaces, and other Customer Applications — and, as between the Parties, in Outputs (subject to Foundation Model provider terms and the nature of generative AI, meaning Outputs may not be unique or copyrightable in all jurisdictions). Where Customer fine-tunes a Foundation Model using Customer Data in the Customer Cloud Environment, the resulting model weights are Customer’s, subject only to the base model’s licence. Customer’s ownership survives termination.
5.3 No training on Customer Data. Magure shall not use Customer Data, Customer Applications, or Outputs to train or improve the Platform, any Foundation Model, or any model offered to others, except with Customer’s written consent or for Customer’s exclusive benefit. Magure may use aggregated, anonymised operational metrics that identify no Customer Data or Personal Data.
5.4 Professional-services deliverables. Magure retains its pre-existing and independently developed libraries, frameworks, accelerators, and reusable components (“Background IP”). Subject to full payment, Magure assigns to Customer the Customer-specific deliverables developed under a Customer Order Form, and grants Customer a perpetual, worldwide, non-exclusive, royalty-free licence to use any Background IP embedded in them. Improvements to the Platform itself remain Magure’s. Nothing prevents Magure from developing similar solutions for others, provided it does not use Customer’s Confidential Information, Customer Data, or Customer deliverables.
5.5 Verification. Customer shall enable Magure to verify compliance with the licensed scope through Platform-generated logs and, on reasonable notice and no more than once per 12 months, a review of Customer’s use of the Magure Platform Technology.
6Customer Data and Data Protection
6.1 Customer Data resides at all times within the Customer Cloud Environment under Customer’s control and does not leave it except as Customer directs. Customer is the Controller of all Personal Data; Magure does not host or store Customer Data on Magure-controlled infrastructure in the standard deployment.
6.2 To the limited extent Magure processes Personal Data on Customer’s documented instructions (e.g., scoped support access or professional-services delivery), Magure acts as Processor only, and the Parties comply with the Data Processing Addendum (Schedule 2). Each Party complies with the data-protection and privacy laws applicable to it in connection with the Services. Customer, as Controller, is responsible for identifying the data-protection laws applicable to its Customer Data and its use of the Platform and for ensuring that its instructions to Magure comply with them.
6.3 Magure maintains an information-security programme certified to ISO 27001 and an AI-governance programme aligned with ISO 42001, and shall notify Customer without undue delay and within seventy-two (72) hours of any confirmed security incident affecting Customer Data within Magure’s control. Security of the Customer Cloud Environment is Customer’s responsibility.
6.4 Foundation Model providers are selected and contracted by Customer directly and are not Magure sub-processors; Magure is not responsible for their acts, availability, or data handling.
7AI-Specific Provisions
7.1 Probabilistic nature. Outputs are generated by AI, which is probabilistic; they may contain errors, biases, or fabricated information, may vary across executions, and are not guaranteed to be accurate, complete, or fit for any purpose.
7.2 Human oversight. Customer is responsible for appropriate human review of Outputs before reliance, and shall not deploy Outputs in high-risk use cases (legal, medical, financial, safety-critical, employment, credit, justice) without qualified human review. Outputs are not professional advice and shall not be represented as advice from Magure.
7.3 Customer’s AI compliance. Customer is responsible for determining that its use of the Platform and Outputs is permitted under the laws applicable to Customer — including any AI-specific laws or regulations that apply to it, such as the EU AI Act and applicable UAE AI regulations, in each case where applicable — and for fulfilling any resulting deployer or user obligations. Customer shall not use the Platform for prohibited AI practices or in violation of Foundation Model providers’ policies, and shall ensure that Platform agents do not make fully autonomous decisions producing legal or similarly significant effects on individuals without human review where required.
7.4 Bias and auditability. Magure does not warrant that Outputs are free of bias; Customer is responsible for evaluating Outputs for bias relative to its use case and population. Magure provides audit logs and traceability to support Customer’s oversight.
7.5 Foundation Model changes. Third-party Foundation Model providers may modify, deprecate, restrict, or reprice their models, and Customer-deployed models may be changed by their maintainers or by Customer; Customer’s relationship with those providers governs such changes. Magure will use commercially reasonable efforts to support current and successor models on the Platform gateway and will give reasonable notice where a model becomes unsupported, but is not liable for changes initiated by providers, maintainers, or Customer.
7.6 Open-source and open-weight model licences. Open-source and open-weight Foundation Models are subject to their own licence terms. Customer is responsible for reviewing and complying with those licences (including attribution, redistribution, and commercial-use restrictions) and for monitoring changes to them. Magure does not warrant that any such model is free of licence restrictions or fit for Customer’s intended use.
8Support and Service Levels
8.1 L3 only; L1/L2 by Customer or partner. Magure provides Level 3 (L3) platform support only — diagnosis and resolution of confirmed defects in the Magure Platform Technology — in accordance with the Support Terms (Schedule 1). Level 1 and Level 2 support are the responsibility of Customer and are provided by Customer or procured from a Magure-authorised partner (including the Reseller of Record) as a managed service, unless Customer procures L1 and/or L2 support directly from Magure as a managed service under a Customer Order Form. Except where Magure is expressly engaged to provide L1 and/or L2 managed services, Magure has no liability for the provision or performance of L1 or L2 support.
8.2 No service credits; exclusions. Magure shall use commercially reasonable efforts to meet the L3 targets in the Support Terms; resolution times are targets, not guarantees, and no service credits or other financial remedies attach to them. The L3 service levels exclude any unavailability, latency, or inaccuracy attributable to a Foundation Model (third-party-hosted or Customer-deployed), the Customer Cloud Environment, or Customer Applications. Customer’s exclusive remedy for the Platform’s failure to materially conform to the Documentation is set out in Clause 9.2.
9Warranties and Disclaimer
9.1 Each Party warrants it has authority to enter these Terms. Magure warrants that the Services will be performed in a professional and workmanlike manner, that the Platform will materially conform to the Documentation during the term, that Magure will not knowingly introduce malicious code, and that Magure has the right to grant the licences here.
9.2 Customer’s exclusive remedy for non-conformance is, at Magure’s option, correction within a reasonable period or, if not commercially feasible, refund of pre-paid fees for the non-conforming Services for the period after the defect was reported.
9.3 Disclaimer. EXCEPT AS EXPRESSLY STATED, THE PLATFORM, SERVICES, AND OUTPUTS ARE PROVIDED “AS IS” AND “AS AVAILABLE.” MAGURE DISCLAIMS ALL OTHER WARRANTIES, EXPRESS OR IMPLIED, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, NON-INFRINGEMENT, AND THAT THE SERVICES OR OUTPUTS WILL BE UNINTERRUPTED, ERROR-FREE, OR ACCURATE.
10Indemnification
10.1 Magure. Magure shall defend and indemnify Customer against third-party claims that the Magure Platform Technology infringes a third party’s Intellectual Property Rights, excluding claims arising from Customer Data, Outputs, Customer Applications, Customer modifications, combinations with non-Magure products, Foundation Models, or Customer-deployed models. Magure may procure the right to continue use, modify the Platform to be non-infringing, or terminate the affected Services with a pro-rata refund.
10.2 Customer. Customer shall defend and indemnify Magure against third-party claims arising from Customer Data, Customer’s use of Outputs, breach of Clause 4 (Acceptable Use) or Clause 7 (AI Provisions), Customer’s combination of the Platform with third-party products, End User claims, or Customer’s violation of applicable law.
10.3 Neither Party indemnifies the other for third-party IP claims arising from Outputs. The indemnified Party shall promptly notify the other, give it sole control of defence and settlement, and reasonably cooperate. This Clause states each Party’s sole liability for the third-party claims described.
11Limitation of Liability
11.1 Except for the exclusions below, each Party’s total aggregate liability shall not exceed the fees received by Magure in respect of the applicable Customer Order Form (whether from Customer or the Reseller of Record) in the six (6) months preceding the event giving rise to the claim.
11.2 Indirect damages. Neither Party is liable for indirect, incidental, special, consequential, exemplary, or punitive damages, including lost profits, revenue, data, business interruption, or goodwill.
11.3 The cap and exclusions do not apply to: breach of confidentiality; infringement of the other Party’s IP; gross negligence, wilful misconduct, or fraud; Customer’s payment obligations; Customer’s breach of Clause 4 or Clause 7; and liability that cannot be excluded by law.
12Confidentiality
Each Party shall use the other’s Confidential Information only to perform these Terms and protect it with no less than reasonable care. The obligation does not apply to information that is public through no fault of the recipient, was known without restriction before disclosure, is independently developed, or is lawfully obtained without restriction, and does not prevent disclosure required by law (with prompt notice where permitted). Confidentiality obligations survive five (5) years post-termination; trade secrets are protected for as long as they remain trade secrets.
13Term and Termination
13.1 These Terms commence on acceptance and continue until all Customer Order Forms have expired or terminated. Each Customer Order Form has an initial term of three (3) years unless otherwise stated, and renews for successive 12-month terms unless either Party gives 60 days’ notice of non-renewal; the Terms and each active Customer Order Form remain co-terminous.
13.2 Neither Party may terminate for convenience during a Customer Order Form’s initial term. Either Party may terminate for cause on written notice if the other materially breaches and fails to cure within thirty (30) days (ten (10) days for non-payment), or becomes insolvent.
13.3 Effects. Termination by Customer for Magure’s uncured cause entitles Customer to a pro-rata refund of pre-paid fees for unused periods; termination by Magure for Customer’s uncured cause (including non-payment) accelerates fees through the then-current term. On termination, for thirty (30) days Magure shall make Customer Data available for export in a standard format, after which Magure may delete Customer Data from systems it controls; each Party returns or destroys the other’s Confidential Information. Clauses 5, 6, 9, 10, 11, 12, 13.3, and 14 survive.
14General
Governing law is that of the DIFC; disputes are escalated to senior executives and, failing resolution within thirty (30) days, finally settled by arbitration under the Dubai International Arbitration Centre (DIAC) rules, seated in the DIFC, in English, by a sole arbitrator, save that either Party may seek injunctive relief to protect its IP or Confidential Information. Neither Party may assign these Terms without the other’s consent, except to an Affiliate or in connection with a merger or sale of substantially all assets. Magure may use subcontractors, remaining responsible for their performance. The Parties are independent contractors. Neither uses the other’s marks in marketing without consent, except Magure may identify Customer in customer lists with Customer’s approval. Each Party maintains appropriate insurance (general liability, professional indemnity, cyber). Neither Party is liable for delay caused by events beyond its reasonable control; if such an event continues beyond ninety (90) days, either Party may terminate the affected Services. Each Party complies with applicable anti-corruption and sanctions laws. These Terms, together with each Customer Order Form and the Schedules, are the entire agreement and supersede prior understandings and any Customer purchase-order terms. In conflict, the Customer Order Form prevails over these Terms only in respect of the commercial terms it expressly covers (e.g., fees, quantities, billing); in all other respects these Terms prevail over the Customer Order Form, and these Terms prevail over the Schedules. Amendments must be in writing; Magure may update the Documentation provided it does not materially reduce Customer’s rights. These Terms may be accepted, and Customer Order Forms signed, by electronic signature and in counterparts.
Schedule 1 — Support Terms
Level 3 (L3) Platform Support · MagOneAI Platform Terms
This Schedule 1 forms part of the MagOneAI Platform Terms (the “Terms”) between Magure Tech Middle East Ltd (“Magure”) and Customer. Capitalised terms used but not defined in this Schedule have the meanings given in the Terms. This Schedule is the “Support Terms” referred to in Clause 1 and Clause 8 of the Terms. In the event of any conflict between this Schedule and the Terms, the Terms prevail (Clause 14 of the Terms).
1. Scope of L3 Support
1.1 What Magure provides. Magure provides Level 3 (L3) platform support only, comprising: (a) diagnosis of issues escalated to Magure and confirmed to arise from a defect in the Magure Platform Technology; (b) resolution of such confirmed defects by correction, patch, update, or documented workaround; (c) root-cause analysis for Severity 1 issues; and (d) technical guidance to the Customer’s or partner’s L2 team on the correct operation of the Platform in accordance with the Documentation.
1.2 What L3 is not. L3 support is defect support. It does not include end-user assistance, monitoring, incident triage, environment administration, configuration, development, content or knowledge-base management, or any other operational activity, all of which fall within L1 and L2.
1.3 No availability commitment. The Platform is deployed and operated within the Customer Cloud Environment, which is under Customer’s control. Accordingly, Magure gives no uptime, availability, or performance commitment in respect of the Platform, and nothing in this Schedule shall be construed as one. The targets in Clause 5 are response and resolution targets for defect handling only.
2. The Support Model and the L1 / L2 Boundary
2.1 Allocation of support tiers. Support is delivered in tiers. Level 1 and Level 2 support are the responsibility of Customer, and are provided by Customer’s own personnel or procured by Customer from a Magure-authorised partner (including the Reseller of Record) as a managed service, unless Customer expressly procures L1 and/or L2 support from Magure as a managed service under a Customer Order Form. Except where Magure is expressly engaged in a Customer Order Form to provide L1 and/or L2 managed services, Magure has no liability for the provision, availability, or performance of L1 or L2 support.
2.2 Tier responsibilities. The following table records the allocation of responsibility between the tiers.
| Tier | Responsible party | Scope |
|---|---|---|
| L1 | Customer, or its Reseller of Record / Magure-authorised partner (or Magure, only if expressly procured) | First-line contact for Authorised Users and End Users; ticket intake, logging and classification; password, access and licence-assignment requests; how-to and usage questions answered from the Documentation; known-issue and FAQ resolution; user communications and status updates. |
| L2 | Customer, or its Reseller of Record / Magure-authorised partner (or Magure, only if expressly procured) | Technical triage and reproduction of reported issues; log, trace and audit-record review; verification that the Customer Cloud Environment, network, identity provider, integrations, credentials and Foundation Model endpoints are correctly configured and operating; Customer Application, workflow, agent, prompt, guardrail and knowledge-base investigation and correction; applying Platform updates released by Magure; determining that an issue is not attributable to the matters listed in Clause 6 before escalating to L3. |
| L3 | Magure | Diagnosis and resolution of confirmed defects in the Magure Platform Technology; correction, patch, update or documented workaround; Severity 1 root-cause analysis; technical guidance to the L2 team; release of Platform updates and security patches within the application layer. |
2.3 Single point of escalation. Where a Reseller of Record or other Magure-authorised partner provides L1 and L2 support to Customer, that partner is the sole channel for escalating issues to Magure’s L3 team, and Magure may deal with that partner as Customer’s authorised representative for support purposes. This operational arrangement does not affect Magure’s obligations under the Terms, which continue to run directly between Magure and Customer (Clause 3.3 of the Terms), nor does it make Magure responsible for the partner’s acts or omissions.
2.4 Prerequisite to escalation. An issue may be escalated to L3 only after L1 and L2 have been performed and the issue has been reproduced and documented. Magure may decline to accept, or may return to L2, any escalation that has not completed L2 triage, that cannot be reproduced, or for which the information required by Clause 4.3 has not been provided.
2.5 Misdirected escalations. Where Magure investigates an escalation and determines that the issue is not caused by a defect in the Magure Platform Technology, Magure will report its findings and the issue will be returned to Customer or its partner. Magure may charge for such investigation at its then-current professional-services rates where the escalation was made in breach of Clause 2.4, or where the same issue is re-escalated after having been returned with findings, save that no charge applies to the first such investigation in any twelve (12) month period.
3. Coverage Hours
3.1 Standard support hours. Standard support hours are Sunday to Thursday, 09:00 to 18:00 Gulf Standard Time (GST, UTC+4), excluding public holidays in the United Arab Emirates as published by Magure (“Business Hours”). A “Business Day” is a day on which Business Hours occur, and a period expressed in Business Days means that number of consecutive Business Days. A “Business Hour” is an hour falling within Business Hours.
3.2 Severity 1 out-of-hours cover. Severity 1 issues correctly submitted through the designated Severity 1 channel are accepted twenty-four (24) hours a day, seven (7) days a week, including public holidays.
3.3 Measurement of elapsed time. For Severity 1, target times run continuously from acceptance of the ticket. For Severity 2, 3 and 4, target times run only during Business Hours and are suspended outside them. All target times are suspended for any period during which Magure is awaiting information, access, a decision, or a test window from Customer or its partner, or is prevented from proceeding by a matter listed in Clause 6.
3.4 Extended coverage. Coverage beyond that set out in this Clause 3 (including follow-the-sun, named or dedicated support resources, or a Forward Deployed Engineer, being a Magure engineer embedded with Customer or its partner on a dedicated basis) is available only where expressly procured in a Customer Order Form and is not included in the Platform subscription.
4. Contacts, Channels and Ticket Submission
4.1 Designated channel. Escalations must be submitted through the support channel notified by Magure from time to time (support portal or the designated support email address), with the Severity 1 telephone or on-call channel used in addition for Severity 1 issues. Requests raised through any other route — including direct approaches to individual Magure personnel, project channels, or social or messaging applications — are not tickets and no target times apply to them.
4.2 Authorised support contacts. Customer (or, where applicable, its Reseller of Record) shall nominate up to three (3) named, suitably trained technical contacts authorised to raise L3 escalations, and shall keep those details current. Magure may decline escalations from persons who are not nominated contacts.
4.3 Required information. Each escalation shall include, at a minimum: the affected environment and Platform version; the proposed severity and its business justification; steps to reproduce; the actual and expected behaviour; the time of first occurrence and whether the issue is recurring; relevant logs, traces, correlation identifiers and screenshots; the Foundation Model(s) and integrations involved; and a summary of the L1 and L2 steps already taken and their outcome.
4.4 Acknowledgement and tracking. Magure will acknowledge and assign a reference to each properly submitted escalation. Target times run from the point at which Magure accepts the escalation as complete under Clause 4.3.
5. Severity Levels and Target Times
5.1 Severity definitions. Severity is determined by the operational impact of the issue on the production environment, as set out below.
| Severity | Definition | Illustrative examples |
|---|---|---|
| Severity 1 — Critical | A confirmed defect in the Magure Platform Technology renders the production Platform wholly inoperable, or causes a confirmed loss or corruption of Customer Data or a confirmed security breach within the application layer, and no workaround exists. | Platform will not start or is unreachable in production; orchestration engine fails for all workflows; confirmed unauthorised access through a Platform defect. |
| Severity 2 — Major | A confirmed defect materially degrades a core production function or materially impairs a significant group of Authorised Users, and no reasonable workaround exists. | A category of agent or workflow consistently fails; the model gateway fails for a supported provider; audit logging is not recording. |
| Severity 3 — Minor | A confirmed defect affects a non-core function, or affects a core function but a reasonable workaround exists. | An interface element renders incorrectly; a report or export is inaccurate; a non-blocking error appears in logs. |
| Severity 4 — Low | A question, cosmetic issue, documentation error, or request for information or enhancement, with no operational impact. | Documentation clarification; cosmetic layout issue; feature request. |
5.2 Classification. Customer proposes the severity on submission. Magure may, acting reasonably and on notice to Customer with its reasons, reclassify a ticket to reflect its actual operational impact as defined in Clause 5.1, and shall reclassify upwards where the impact is greater than proposed. Severity 1 and Severity 2 apply only to production environments; issues in development, test, staging or sandbox environments are treated as Severity 3 or below.
5.3 Target times. Magure shall use commercially reasonable efforts to meet the following targets.
| Severity | Target initial response | Target workaround or mitigation | Target resolution |
|---|---|---|---|
| Severity 1 | One (1) hour, 24×7 | Eight (8) hours of continuous effort from acceptance | Permanent correction in an emergency patch or the next scheduled release, as Magure determines appropriate |
| Severity 2 | Four (4) Business Hours | Three (3) Business Days | Correction in the next scheduled maintenance release |
| Severity 3 | One (1) Business Day | Five (5) Business Days | Correction in a future release, at Magure’s discretion as to scheduling |
| Severity 4 | Three (3) Business Days | Not applicable | Addressed through the Documentation or the product backlog; no commitment to implement |
5.4 Targets are not guarantees; no service credits. The times, intervals, and periods set out in this Schedule — including those in Clauses 4.4, 5.3, 7.3, and 9.2 — are targets to be pursued using commercially reasonable efforts. They are not guarantees, warranties, or conditions, and no service credit, rebate, liquidated sum, or other financial remedy attaches to them, whether under this Schedule, the Terms, or any Customer Order Form. Customer’s exclusive remedy for the Platform’s failure to materially conform to the Documentation is set out in Clause 9.2 of the Terms.
5.5 Resolution by workaround. A ticket is resolved when Magure has supplied a correction, patch, update, configuration change, or documented workaround that removes or materially reduces the operational impact of the issue, or when the issue is determined not to arise from a defect in the Magure Platform Technology. A documented workaround is a valid resolution and reduces the severity of the ticket accordingly.
5.6 Closure. Magure may close a ticket where Customer confirms resolution, or where Magure has requested information, access, or confirmation from Customer or its partner and has received no substantive response within ten (10) Business Days of a written reminder. A closed ticket may be reopened within thirty (30) days if the same issue recurs.
6. Exclusions
6.1 Excluded causes. For the purposes of Clause 8.2 of the Terms, and without limiting the exclusions stated there, the L3 service levels and target times do not apply to, and Magure has no obligation under this Schedule in respect of, any unavailability, latency, degradation, error, or inaccuracy attributable to:
- (a) any Foundation Model, whether third-party-hosted, open-weight, or Customer-deployed, including its output quality, accuracy, bias, availability, rate limits, deprecation, repricing, or change by its provider, maintainer, or Customer;
- (b) the Customer Cloud Environment, including its infrastructure, compute, storage, networking, identity and access management, security configuration, capacity, backups, and disaster recovery, and any act or omission of its provider;
- (c) Customer Applications, including workflows, agents, prompts, guardrails, configurations, business logic, knowledge-base content, and integrations created by or for Customer;
- (d) Customer Data, including its accuracy, completeness, legality, format, or volume;
- (e) any third-party product, system, API, network, or connector not supplied by Magure, and any integration with it;
- (f) use of the Platform other than in accordance with the Documentation or the Terms, including any use prohibited by Clause 4 or Clause 7 of the Terms;
- (g) any modification of the Magure Platform Technology by any person other than Magure or a person acting under Magure’s written direction;
- (h) Customer’s failure to implement an update, patch, correction, or workaround made available by Magure, or to operate a supported version under Clause 7.2 of this Schedule;
- (i) any failure by Customer or its partner to perform L1 or L2 support, or to provide the access, information, or cooperation required by Clause 8 of this Schedule; or
- (j) any event beyond Magure’s reasonable control, or any suspension permitted by Clause 3.4 of the Terms.
Each matter in this Clause 6.1 records the allocation of operational responsibility already made by Clauses 2.2, 2.3, 6.1, 6.3, and 8.2 of the Terms, and is to be read as giving effect to those Clauses rather than as conflicting with them.
6.2 Chargeable activity. The following are not included in L3 support and are provided only where expressly procured under a Customer Order Form: L1 and L2 managed services; implementation, integration, migration, and configuration; development of or changes to Customer Applications; performance tuning of Customer Applications or Foundation Models; data loading, cleansing, or knowledge-base curation; training and enablement; on-site attendance; environment builds, upgrades, or restores performed by Magure on Customer’s behalf; assistance with third-party products; and Forward Deployed Engineers or other named resources.
7. Releases, Versions and Maintenance
7.1 Updates. Magure makes updates, patches, and new releases of the Platform available in accordance with its release practices. Installation of updates within the Customer Cloud Environment is an L2 activity and is Customer’s responsibility unless Magure is expressly engaged to perform it.
7.2 Supported versions. L3 support is provided for the current major release of the Platform and the immediately preceding major release only. Where Customer operates an unsupported version, Magure’s sole obligation is to advise the update path, and no target times apply until Customer has updated to a supported version.
7.3 Security patches. Magure will notify Customer of security patches within the application layer as they are released, together with an indication of severity. Customer is responsible for applying them promptly. Security of the Customer Cloud Environment remains Customer’s responsibility under Clause 6.3 of the Terms.
7.4 Maintenance windows. Where an activity requires Platform downtime within the Customer Cloud Environment, it will be scheduled with Customer in advance. Magure does not schedule or control downtime in the Customer Cloud Environment.
8. Customer and Partner Obligations
8.1 Access. Customer shall grant Magure least-privilege, time-bound access to the Customer Cloud Environment sufficient to diagnose and resolve escalated issues, together with access to relevant logs, traces, and audit records, in accordance with Clause 2.2 of the Terms. Magure’s target times do not run for any period during which such access has been requested and not provided.
8.2 Cooperation. Customer shall, and shall procure that its partner shall: perform L1 and L2 support competently; provide the information required by Clause 4.3; make suitably qualified personnel available; provide a representative test environment where required; implement corrections and workarounds promptly; and test and confirm resolution.
8.3 Data minimisation in support. Customer shall not transmit Personal Data or other sensitive data to Magure in support tickets except where strictly necessary to diagnose the issue and no less intrusive alternative exists, and shall redact or anonymise wherever practicable. Where Magure does process Personal Data in the course of support, it does so as Processor on Customer’s documented instructions in accordance with Clause 6.2 of the Terms and Schedule 2.
8.4 Remote access. Support is delivered remotely. Any on-site attendance is chargeable and requires reasonable notice, and is subject to Customer providing site access, security clearances, and a safe working environment.
9. Escalation
9.1 Escalation path. Where Customer considers that a ticket is not progressing appropriately, it may escalate in the following order, allowing a reasonable interval at each stage: (a) the assigned Magure support engineer; (b) the Magure support lead; (c) the Magure engineering or delivery manager; and (d) a Magure executive sponsor. Contact details for each stage will be notified by Magure and kept current.
9.2 Severity 1 escalation. For an unresolved Severity 1 issue, Magure shall use commercially reasonable efforts to provide status updates at intervals of no more than four (4) hours until a workaround or resolution is in place, and to provide a written root-cause analysis within ten (10) Business Days of resolution. These are targets to which Clause 5.4 applies.
9.3 Relationship to dispute resolution. This Clause 9 is an operational escalation path. It does not limit, and is without prejudice to, the dispute-resolution and arbitration provisions in Clause 14 of the Terms.
10. General
10.1 Changes to this Schedule. Magure may propose an update to this Schedule from time to time to reflect changes in its support practices, provided that no update shall materially reduce the level of support described here during the then-current term of a Customer Order Form. Magure shall give Customer not less than thirty (30) days’ written notice of a proposed update, and the update takes effect as an agreed amendment for the purposes of Clause 14 of the Terms unless Customer objects in writing within that period, in which case the version of this Schedule then in force continues to apply for the remainder of the then-current term of each affected Customer Order Form.
10.2 Language and records. Support is provided in English. Magure’s ticket records are the record of support activity in the absence of manifest error.
10.3 No third-party rights. Nothing in this Schedule confers any right on a Reseller of Record, partner, End User, or other third party, save that Magure may deal with a partner as contemplated by Clause 2.3.
Schedule 2 — Data Processing Addendum
MagOneAI Platform Terms
This Data Processing Addendum (“DPA”) forms Schedule 2 to the MagOneAI Platform Terms (the “Terms”) between Magure Tech Middle East Ltd (“Magure”) and Customer, and is the Data Processing Addendum referred to in Clause 6.2 of the Terms. Capitalised terms used but not defined in this DPA have the meanings given in the Terms. Precedence is governed by Clause 14 of the Terms: in the event of any conflict between this DPA and the Terms, the Terms prevail. Subject always to that Clause, and to the extent the Terms do not otherwise provide, this DPA is intended to prevail over a Customer Order Form in respect of the processing of Personal Data, and over Schedules 1 and 3 in respect of any data-protection matter.
1. Definitions
“Controller” — the person who, alone or jointly with others, determines the purposes and means of the processing of Personal Data.
“Data Protection Laws” — the data protection and privacy laws applicable to a Party in connection with the Services, as determined in accordance with Clause 6.2 of the Terms. This DPA is drafted to operate independently of any particular jurisdiction; where a specific law requires additional or different terms, the Parties shall agree an addendum to this DPA under Clause 14.3.
“Data Subject” — the identified or identifiable natural person to whom Personal Data relates.
“Data Subject Request” — a request from a Data Subject to exercise a right in relation to their Personal Data under Data Protection Laws.
“In-Scope Personal Data” — Personal Data forming part of Customer Data that Magure processes on Customer’s behalf in the circumstances described in Clause 3.1. It does not include Personal Data that remains within the Customer Cloud Environment without being accessed by Magure.
“Personal Data Breach” — a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, In-Scope Personal Data.
“Processor” — the person who processes Personal Data on behalf of the Controller.
“processing” — any operation performed on Personal Data, whether or not by automated means, and “process” and “processed” are construed accordingly.
“Sub-processor” — a third party engaged by Magure to process In-Scope Personal Data on Magure’s behalf in the performance of the Services.
2. Roles of the Parties
2.1 Customer is Controller. Customer is the Controller of all Personal Data comprised in Customer Data. Customer determines the purposes and means of processing, decides what Personal Data is introduced into the Platform, and configures the Customer Applications that process it.
2.2 Magure is Processor. To the limited extent that Magure processes In-Scope Personal Data, it does so solely as Processor acting on Customer’s documented instructions. Magure does not determine the purposes or means of processing In-Scope Personal Data and does not act as Controller in respect of it.
2.3 Magure as Controller of its own data. The reference in Clause 6.1 of the Terms to Customer being the Controller of all Personal Data is to Personal Data comprised in Customer Data. It does not extend to Personal Data that Magure processes for the administration of its own business, in respect of which Magure acts as Controller — such as the business-contact details of Customer’s and its partner’s personnel used for contract administration, invoicing, relationship management, and the identification and routing of support correspondence, together with security and access logging of Magure’s own systems and records of Magure’s own personnel. Such processing is outside the scope of this DPA and is governed by the Data Protection Laws applicable to Magure. Where the same item of data is both held by Magure for its own administration and contained in material submitted to Magure under Clause 3.1, it is Controller-side data in the former capacity and In-Scope Personal Data in the latter.
2.4 Where Customer is itself a Processor. Where Customer processes Personal Data as a processor on behalf of a third-party controller, Customer warrants that it has that controller’s authority to appoint Magure as a sub-processor on the terms of this DPA and to give the instructions it gives, and that those instructions are consistent with that controller’s instructions to Customer. References to Customer as Controller are construed accordingly, and Magure’s obligations run only to Customer.
3. Scope and Nature of the Processing
3.1 Limited processing by design. The Platform is deployed within the Customer Cloud Environment. Customer Data resides at all times within that environment under Customer’s control and does not leave it except as Customer directs, and Magure does not host or store Customer Data on Magure-controlled infrastructure in the standard deployment (Clause 6.1 of the Terms). Accordingly, Magure processes In-Scope Personal Data only where and to the extent that Customer requests or permits it to do so, namely: (a) during scoped, least-privilege, time-bound support access to the Customer Cloud Environment granted by Customer under Clause 2.2 of the Terms; (b) where Customer or its partner includes Personal Data in a support ticket, log extract, trace, screenshot, or reproduction case submitted to Magure; (c) in the delivery of implementation, managed, or professional services expressly procured from Magure under a Customer Order Form; and (d) where Magure reviews Platform-generated logs to verify compliance with the licensed scope under Clause 5.5 of the Terms, and in the generation of the aggregated, anonymised operational metrics permitted by Clause 5.3 of the Terms, in each case limited to what is necessary for that purpose and with identifiers minimised or removed wherever the purpose can still be achieved.
3.2 Description of the processing. The details required to be recorded under Data Protection Laws are set out below.
| Item | Detail |
|---|---|
| Subject matter | Magure’s performance of the Services under the Terms and each Customer Order Form. |
| Nature and purpose | Diagnosis and resolution of confirmed defects in the Magure Platform Technology (Level 3 support); and, where expressly procured, implementation, migration, configuration, managed services, and professional services. Processing is limited to what is necessary for those purposes. |
| Types of processing operations | Access, viewing, retrieval, consultation, reproduction in a test case, temporary storage of diagnostic material, transmission to authorised Magure personnel, and erasure. Magure does not carry out routine bulk processing of In-Scope Personal Data. |
| Categories of Data Subjects | Determined by Customer. Typically Customer’s Authorised Users and personnel and, where present in Customer Data, Customer’s own customers, End Users, suppliers, and other individuals whose data Customer chooses to process on the Platform. |
| Categories of Personal Data | Determined by Customer. Magure does not select or control the Personal Data introduced into the Platform. Typically identifiers and contact details, account and authentication data, activity and audit-log data, and any Personal Data contained in Customer Data, prompts, knowledge bases, or Outputs. |
| Special-category or sensitive data | Not required for the Services. Customer shall not introduce special-category, sensitive, children’s, or similarly protected Personal Data into a support ticket or other material provided to Magure except where strictly necessary and after applying the minimisation required by Clause 4.4 of this DPA and Clause 8.3 of Schedule 1. |
| Duration | For the term of the Terms and each Customer Order Form, and thereafter only for the limited period permitted by Clause 11. |
| Frequency | Occasional and event-driven. Processing occurs only when triggered by a support escalation or a procured service engagement. |
3.3 Foundation Model providers and infrastructure providers. Foundation Model providers and the providers of the Customer Cloud Environment are selected, contracted, and instructed by Customer directly. They are Customer’s own processors or controllers as the case may be, and are not Magure Sub-processors. Magure is not responsible for their acts, omissions, availability, or data handling (Clause 6.4 of the Terms). Customer is responsible for the terms on which it engages them, including any data-processing terms and transfer mechanism required between Customer and those providers.
4. Magure’s Obligations
4.1 Documented instructions. Magure shall process In-Scope Personal Data only on Customer’s documented instructions, which comprise the Terms, this DPA, each Customer Order Form, and any further written instruction agreed by the Parties. Magure shall not process In-Scope Personal Data for its own purposes.
4.2 Unlawful or out-of-scope instructions. If Magure considers, acting reasonably, that an instruction infringes Data Protection Laws or falls outside the scope of the Services, it shall inform Customer without undue delay and may suspend performance of that instruction until the matter is resolved, without liability for the resulting delay. Magure is not obliged to, and does not, provide legal advice on the lawfulness of Customer’s instructions; Customer remains responsible for that assessment under Clause 6.2 of the Terms. Where Magure is required by a law applicable to it to process In-Scope Personal Data otherwise than on Customer’s instructions, it shall inform Customer of that requirement before processing unless that law prohibits it.
4.3 Confidentiality of personnel. Magure shall ensure that persons authorised to process In-Scope Personal Data are subject to an appropriate duty of confidentiality, are granted access on a least-privilege, need-to-know basis, and have received appropriate training in data protection and information security.
4.4 Data minimisation in support. Magure shall request only such access and material as is necessary to diagnose and resolve the issue at hand, shall prefer anonymised, redacted, or synthetic material where it would be sufficient, and shall not extract, copy, or retain In-Scope Personal Data beyond what is necessary for the purpose and duration of the task. Correspondingly, Customer shall not provide, and shall procure that its partner does not provide, Magure with Personal Data in a support ticket, log extract, trace, screenshot, reproduction case, or other material except where strictly necessary to diagnose the issue and no less intrusive alternative exists, and shall redact, anonymise, or substitute synthetic data wherever practicable (see also Clause 8.3 of Schedule 1). This Clause 4.4 imposes obligations on both Parties.
4.5 Security. Magure shall implement and maintain appropriate technical and organisational measures to protect In-Scope Personal Data against a Personal Data Breach, having regard to the state of the art, the costs of implementation, and the nature, scope, context, and purposes of the processing and the risks to Data Subjects. Those measures are described in Clause 5.
4.6 No training on Customer Data. Magure shall not use Customer Data, Customer Applications, or Outputs — including any In-Scope Personal Data — to train or improve the Platform, any Foundation Model, or any model offered to others, except with Customer’s written consent or for Customer’s exclusive benefit. Magure may use aggregated, anonymised operational metrics that identify no Customer Data or Personal Data (Clause 5.3 of the Terms).
4.7 Records. Magure shall maintain a record of the categories of processing carried out on Customer’s behalf and shall make it available to Customer on reasonable request.
4.8 Third-party AI tools. Magure shall not input In-Scope Personal Data into any third-party artificial-intelligence or machine-learning service — including AI coding assistants, diagnostic copilots, transcription services, and general-purpose model APIs — unless that service is engaged as a Sub-processor and listed in Schedule 3, is contracted on terms that prohibit the use of the input for training or model improvement, and the input has been minimised in accordance with Clause 4.4. This Clause 4.8 applies in addition to, and does not limit, Clause 4.6.
5. Security Measures
5.1 Certified programme. Magure maintains an information-security programme certified to ISO 27001 and an AI-governance programme aligned with ISO 42001 (Clause 6.3 of the Terms), and shall maintain those certifications or equivalent successors during the term.
5.2 Measures. Magure’s measures include, at a minimum:
- (a) Access control — role-based access on least-privilege principles; multi-factor authentication for Magure personnel; time-bound, individually attributable, and revocable access to the Customer Cloud Environment granted only for a specific support or service task; prompt revocation on role change or departure;
- (b) Encryption — encryption of Personal Data in transit using industry-standard transport security and at rest where held on Magure-controlled systems; managed secret storage for credentials, which are never stored in plain text or in ticketing systems;
- (c) Segregation — logical separation of Customer’s support material from that of other customers; no cross-customer access;
- (d) Logging and traceability — audit logging of Magure personnel access to the Customer Cloud Environment and of administrative actions, retained for a period consistent with Magure’s security policy and available to Customer on request;
- (e) Resilience and integrity — vulnerability management and patching within the application layer, secure development practices, change control, malicious-code controls, and testing of the effectiveness of measures on a periodic basis;
- (f) Personnel — background screening to the extent permitted by applicable law, written confidentiality undertakings, and periodic security and data-protection training;
- (g) Incident management — a documented incident-response process covering detection, triage, containment, notification, and post-incident review; and
- (h) Business continuity — documented continuity and recovery arrangements for Magure’s own systems.
5.3 Evolution of measures. Magure may update its measures from time to time provided the overall level of security is not materially reduced.
5.4 Customer’s security responsibilities. Security of the Customer Cloud Environment, including its infrastructure, network, identity and access management, encryption configuration, backups, and disaster recovery, is Customer’s responsibility (Clauses 2.2 and 6.3 of the Terms). Customer is responsible for configuring the Platform’s access controls, retention settings, and guardrails appropriately for the Personal Data it chooses to process, and for the security of credentials issued to its Authorised Users.
6. Sub-processing
6.1 General authorisation. Customer grants Magure general authorisation to engage Sub-processors to process In-Scope Personal Data, subject to this Clause 6. The Sub-processors authorised as at the date of the applicable Customer Order Form are listed in Schedule 3.
6.2 Terms imposed on Sub-processors. Magure shall engage each Sub-processor under a written contract imposing data-protection and security obligations that are, in substance and taking into account the nature and scale of the services performed by that Sub-processor, materially equivalent to the relevant obligations in this DPA. Where a Sub-processor is a large-scale provider of standardised services contracting on its own published data-processing terms, Magure satisfies this Clause by engaging that Sub-processor on those terms, provided Magure has assessed them as affording materially equivalent protection. Magure remains fully liable to Customer for the performance of each Sub-processor’s obligations.
6.3 Changes and objection. Magure shall give Customer at least thirty (30) days’ prior notice of the addition or replacement of a Sub-processor, save that where a Sub-processor must be replaced at short notice for reasons of security, service continuity, or legal compulsion, Magure may make the replacement immediately and shall notify Customer as soon as reasonably practicable, in which case the objection period runs from the date of that notice. Customer may object on reasonable, documented data-protection grounds within fifteen (15) days of notice, in which case the Parties shall discuss the objection in good faith and Magure may, at its option, propose a commercially reasonable alternative arrangement or refrain from using that Sub-processor in respect of Customer. Where neither is reasonably practicable, Customer may give notice of non-renewal of the affected Customer Order Form in accordance with Clause 13.1 of the Terms, to take effect at the end of the then-current term. For the avoidance of doubt, an objection under this Clause 6.3 does not give rise to a right to terminate during the initial term of a Customer Order Form (Clause 13.2 of the Terms) and does not give rise to any refund; Magure is not part of the payment flow where Customer purchases through a Reseller of Record (Clause 3.1 of the Terms). The remedy in this Clause is Customer’s sole remedy for an unresolved objection.
6.4 Not Sub-processors. For the avoidance of doubt, the following are not Magure Sub-processors: Foundation Model providers; the provider of the Customer Cloud Environment; any third-party product, connector, or API contracted by Customer; and the Reseller of Record or any other partner engaged by Customer to provide L1 or L2 support or other services.
7. Data Subject Requests
7.1 Customer handles requests. Customer Data, including In-Scope Personal Data, resides within the Customer Cloud Environment under Customer’s control, and the Platform provides functionality, as described in the Documentation, by which Customer may locate, export, correct, restrict, and delete Personal Data within it. Customer is therefore responsible for responding to Data Subject Requests, using that functionality together with its own administrative access to the Customer Cloud Environment. Nothing in this Clause is a warranty as to the Platform beyond the warranty given in Clause 9.1 of the Terms, and Clause 9.3 of the Terms applies.
7.2 Magure’s assistance. Magure shall not respond to a Data Subject Request relating to In-Scope Personal Data except on Customer’s documented instruction or where required by a law applicable to Magure. Magure shall notify Customer without undue delay of any such request it receives directly, and shall provide reasonable assistance to Customer in responding, taking into account the nature of the processing and the information available to Magure. Assistance beyond the functionality of the Platform and beyond a de minimis level of effort is chargeable at Magure’s then-current professional-services rates.
8. Personal Data Breach
8.1 Notification. Magure shall notify Customer without undue delay, and in any event within seventy-two (72) hours, of becoming aware of a confirmed Personal Data Breach affecting In-Scope Personal Data within Magure’s control (consistent with Clause 6.3 of the Terms).
8.2 Contents of notice. The notification shall include, to the extent then known and as further information becomes available: the nature of the breach and the categories and approximate volume of Personal Data and Data Subjects affected; the likely consequences; the measures taken or proposed to address it and mitigate its effects; and a contact point for further information.
8.3 Cooperation and remediation. Magure shall take reasonable steps to contain and remediate the breach and shall provide Customer with reasonable cooperation and information to enable Customer to meet its own notification obligations under Data Protection Laws. Cooperation is provided at Magure’s cost where the breach arose within Magure’s control; where the incident did not arise within Magure’s control, assistance beyond the provision of information already held by Magure is chargeable at Magure’s then-current professional-services rates.
8.4 Customer’s environment. A security incident affecting the Customer Cloud Environment, Customer Applications, or Customer’s own systems, credentials, or personnel is Customer’s responsibility to detect, manage, and notify. Magure’s notification obligation under this Clause 8 applies only to breaches within Magure’s control.
8.5 No admission. Notification or assistance under this Clause 8 is not, and shall not be construed as, an acknowledgement of fault or liability by Magure.
9. Assistance with Assessments and Regulators
9.1 Taking into account the nature of the processing and the information available to it, Magure shall provide Customer with reasonable assistance in relation to data-protection impact assessments, risk assessments, and any prior consultation with, or enquiry from, a competent supervisory or regulatory authority, in each case to the extent the matter relates to Magure’s processing of In-Scope Personal Data.
9.2 Assistance under this Clause 9 beyond the provision of Magure’s standard documentation, certifications, and security summaries is chargeable at Magure’s then-current professional-services rates. Customer remains responsible for carrying out any assessment required of it and for its engagement with its regulators.
9.3 Magure shall notify Customer of any legally binding request from a public authority for disclosure of In-Scope Personal Data, unless prohibited from doing so, and shall use reasonable efforts, where it is lawfully able to do so and where the challenge is not manifestly futile, to challenge any request that appears to Magure to be unlawful or excessive. Magure is not liable for the outcome of any such challenge, and the reasonable cost of a challenge pursued at Customer’s request is for Customer’s account.
10. Audit and Information
10.1 Documentation first. Magure shall make available to Customer the information reasonably necessary to demonstrate compliance with this DPA, which shall in the first instance be satisfied by providing Magure’s then-current certifications, audit summaries, security-measure descriptions, and responses to a reasonable security questionnaire.
10.2 On-site or remote audit. Where the information provided under Clause 10.1 is not sufficient to demonstrate compliance, Customer may, on not less than thirty (30) days’ prior written notice, no more than once in any twelve (12) month period, and during Magure’s normal business hours, audit Magure’s compliance with this DPA. An additional audit may be conducted where required by a competent supervisory authority or following a confirmed Personal Data Breach affecting Customer.
10.3 Conditions. Any audit shall: be conducted at Customer’s cost; be limited in scope to Magure’s processing of In-Scope Personal Data; not require disclosure of information relating to any other customer of Magure, or of Magure’s Confidential Information or trade secrets beyond what is necessary; not be conducted by a competitor of Magure; be carried out by personnel or an independent auditor bound by written confidentiality obligations no less protective than Clause 12 of the Terms; and be conducted so as to cause minimum disruption to Magure’s operations. Magure may require the auditor to sign a reasonable non-disclosure agreement before access is granted.
10.4 Findings. Audit findings are the Confidential Information of both Parties. The Parties shall discuss any material finding in good faith, and Magure shall remediate confirmed non-compliance with this DPA within a reasonable period at its own cost.
11. Retention, Return and Deletion
11.1 Retention during the term. Magure shall retain In-Scope Personal Data only for as long as necessary for the purpose for which it was provided. Diagnostic material provided in support tickets shall be deleted from Magure’s systems in accordance with Magure’s retention policy once the ticket has been closed and any applicable reopening period under Schedule 1 has expired.
11.2 On termination. On expiry or termination of the Terms, Magure shall, at Customer’s election, return or delete In-Scope Personal Data in its possession or control, together with existing copies, within a reasonable period. During the term, Magure shall delete specified In-Scope Personal Data on Customer’s written request within a reasonable period, save to the extent the material is required for an open support ticket or service engagement, or is subject to Clause 11.3. Because Customer Data resides in the Customer Cloud Environment, Customer retains continuous access to it and Clause 13.3 of the Terms governs export from any Magure-controlled system.
11.3 Permitted retention. Magure may retain In-Scope Personal Data to the extent required by a law applicable to it, where reasonably necessary to establish, exercise, or defend legal claims, where necessary to complete an open support ticket or service engagement, or where held in routine encrypted backups or immutable security and audit logs pending expiry of the applicable retention cycle, provided that in each case Magure isolates the data from active processing, applies the protections of this DPA to it for so long as it is retained, and deletes it on expiry of the retention period or the legal requirement.
12. International Transfers
12.1 Location of processing. Customer determines the location of the Customer Cloud Environment and therefore the location at which Customer Data is stored and processed. Magure accesses that environment remotely from the locations of its personnel and, where applicable, of the Sub-processors listed in Schedule 3.
12.2 Transfer mechanism. Where a transfer of In-Scope Personal Data to Magure, or between Magure and a Sub-processor, is a restricted or regulated transfer under Data Protection Laws applicable to Customer, the Parties shall put in place, and comply with, the transfer mechanism required by those laws — which may include standard contractual clauses, an approved certification or code of conduct, binding corporate rules, an adequacy determination, or a permitted derogation. On Customer’s written request, Magure shall negotiate in good faith and, acting reasonably, enter into the applicable standard contractual clauses or equivalent instrument, in the form prescribed by that law and in the module and configuration appropriate to the Parties’ actual roles and to the limited processing described in Clause 3.1, provided that Magure is not obliged to enter into any instrument in respect of a law that does not apply to the Services or to Customer’s use of them. On execution, that instrument is incorporated into this DPA and prevails over this DPA to the extent of any conflict, but only in respect of the transfer to which it relates and only to the extent that the relevant law does not permit the Parties to agree otherwise; in all other respects Clauses 14.1 and 14.4 of this DPA and Clauses 11 and 14 of the Terms continue to apply.
12.3 Customer’s determination. Customer, as Controller, is responsible for determining which Data Protection Laws apply to its Customer Data and whether a transfer mechanism is required (Clause 6.2 of the Terms), and shall notify Magure of any such requirement. Magure is not responsible for identifying the Data Protection Laws applicable to Customer.
13. Customer’s Obligations and Warranties
13.1 Customer warrants and undertakes that: (a) it has provided all notices and has a valid legal basis for the processing of Personal Data it introduces into or processes through the Platform, and for its disclosure to Magure; (b) its instructions to Magure comply with the Data Protection Laws applicable to it; (c) the Personal Data it provides is accurate and lawfully obtained, and it has all rights and consents necessary for the processing contemplated by the Terms; (d) it has assessed whether the Platform and its configuration are appropriate for the categories of Personal Data it processes, including any special-category, sensitive, children’s, financial, or health data; and (e) it will not provide Magure with Personal Data in breach of Customer’s minimisation obligation in Clause 4.4 of this DPA or Clause 8.3 of Schedule 1.
13.2 Customer shall indemnify Magure in accordance with Clause 10.2 of the Terms in respect of third-party claims arising from Customer Data, including claims by Data Subjects or regulators arising from Customer’s determination of the purposes and means of processing, its instructions, or its configuration of the Platform.
13.3 Transparency and AI. Customer is responsible for informing Data Subjects, where required by Data Protection Laws or applicable AI regulation, that AI processing is applied to their Personal Data, and for any obligations relating to automated decision-making. Customer shall not use the Platform to make fully autonomous decisions producing legal or similarly significant effects on individuals without meaningful human oversight (Clauses 4 and 7.3 of the Terms).
14. General
14.1 Liability. Each Party’s liability arising out of or in connection with this DPA is subject to the exclusions and limitations in Clause 11 of the Terms. Liability under this DPA and under the Terms is aggregated and does not apply cumulatively; nothing in this DPA increases either Party’s liability beyond the limits in Clause 11 of the Terms, save to the extent that a limitation is not permitted by Data Protection Laws.
14.2 Term. This DPA takes effect on acceptance of the Terms and continues for so long as Magure processes, or is entitled to process, In-Scope Personal Data. Clauses 4.6, 4.8, 8.5, 10.4, 11, 12, 13, and 14 survive its termination.
14.3 Amendment. The Parties shall negotiate in good faith any amendment to this DPA reasonably required to reflect a change in Data Protection Laws applicable to Customer, or the requirements of a competent supervisory authority. Magure may propose an update to this DPA to reflect changes in law or in its processing practices, provided no update materially reduces the protections afforded to In-Scope Personal Data. Magure shall give Customer not less than thirty (30) days’ written notice of a proposed update, and the update takes effect as an agreed amendment for the purposes of Clause 14 of the Terms unless Customer objects in writing within that period, in which case the version of this DPA then in force continues to apply for the remainder of the then-current term of each affected Customer Order Form.
14.4 Governing law and disputes. This DPA is governed by, and disputes under it are resolved in accordance with, Clause 14 of the Terms, save where Data Protection Laws applicable to Customer mandate otherwise in respect of a particular matter.
14.5 Severance and precedence. If any provision of this DPA is held invalid or unenforceable, the remainder continues in full force. Subject always to Clause 14 of the Terms, as between the Schedules this DPA prevails on any data-protection matter, Schedule 1 prevails on any support matter, and Schedule 3 prevails as to the identity of authorised Sub-processors. This DPA replaces any pre-existing data-processing terms between the Parties in respect of the Services.
14.6 No separate signature required. This DPA is incorporated into the Terms and is accepted when Customer accepts the Terms in accordance with the Acceptance provision of the Terms. The Parties may execute this DPA separately where a Party’s internal requirements or Data Protection Laws so require, but separate execution is not a condition of its effectiveness.
Schedule 3 — Sub-processors
MagOneAI Platform Terms · Data Processing Addendum (Schedule 2)
This Schedule 3 forms part of the MagOneAI Platform Terms (the “Terms”) and of the Data Processing Addendum at Schedule 2 (the “DPA”) between Magure Tech Middle East Ltd (“Magure”) and Customer. Capitalised terms used but not defined in this Schedule have the meanings given in the Terms and the DPA. This Schedule is the list of authorised Sub-processors referred to in Clause 6.1 of the DPA. In the event of any conflict between this Schedule and the Terms, the Terms prevail (Clause 14 of the Terms).
1. Why this list is short
1.1 No processing of Customer Data in the standard deployment. The Platform is deployed within the Customer Cloud Environment. Customer Data resides at all times within that environment under Customer’s control and does not leave it except as Customer directs, and Magure does not host or store Customer Data on Magure-controlled infrastructure in the standard deployment (Clause 6.1 of the Terms). No Sub-processor listed in this Schedule hosts, stores, or has access to the Customer Cloud Environment or to Customer Data held within it.
1.2 What the listed Sub-processors do. The Sub-processors in Clause 2 are the business systems through which Magure receives, records, and communicates about support escalations and service engagements. They may therefore process In-Scope Personal Data only to the extent that Customer or its partner chooses to include Personal Data in a support ticket, log extract, trace, screenshot, reproduction case, or correspondence submitted to Magure. Customer can materially limit — and in most cases eliminate — this processing by applying the data-minimisation requirements in Clause 4.4 of the DPA and Clause 8.3 of Schedule 1.
1.3 No third-party AI tools. Magure does not input In-Scope Personal Data into any third-party artificial-intelligence or machine-learning service unless that service is engaged as a Sub-processor, is listed in Clause 2, and is contracted on terms prohibiting use of the input for training or model improvement (Clause 4.8 of the DPA). No such service is listed in Clause 2 as at the date of this Schedule.
1.4 Magure personnel. Support and professional services are delivered by Magure’s own personnel. Any Magure Affiliate that delivers such services on Magure’s behalf is treated as a Sub-processor; Clause 3 records the position on Affiliates.
2. Authorised Sub-processors
2.1 The following Sub-processors are authorised as at the version date of this Schedule stated above. The list in force at any time is the list in the version most recently notified or published before the relevant processing (Clause 4.5).
| Sub-processor | Service provided to Magure | Nature of any In-Scope Personal Data processed | Processing locations |
|---|---|---|---|
| Atlassian (Jira) | Support ticketing and issue tracking | Ticket content submitted by Customer or its partner: contact details of the reporting user, and any Personal Data contained in descriptions, logs, traces, screenshots, or attachments that Customer chooses to include. Magure does not require Personal Data in tickets. | European Union and United States |
| Microsoft (Microsoft 365) | Business email, collaboration, meetings and document storage | Correspondence and meeting content relating to support escalations and service engagements: contact details of Customer’s personnel and any Personal Data they choose to include in correspondence or attachments. | United Arab Emirates, European Union and United States |
| GitHub (Microsoft) | Source-code management and engineering issue tracking for the Magure Platform Technology | None in normal operation. Magure’s policy is that Customer Data and Personal Data are not placed in source-code repositories. Personal Data may be processed only in the exceptional case where a defect can be reproduced solely by reference to a Customer-supplied artefact, and then only after minimisation under Clause 4.4 of the DPA. | European Union and United States |
2.2 Processing locations. Processing locations are those of the relevant provider’s service configuration and its own sub-processing arrangements, and are stated to the best of Magure’s knowledge as at the date of this Schedule. Providers may change region availability; Magure will update this Schedule in accordance with Clause 4. Where a change of location constitutes a restricted or regulated transfer under the Data Protection Laws applicable to Customer, Clause 12 of the DPA applies.
2.3 Terms with Sub-processors. Each Sub-processor listed above is a large-scale provider of standardised services and is engaged on terms that Magure has assessed as affording protection materially equivalent to the relevant obligations in the DPA, in accordance with Clause 6.2 of the DPA. Magure remains fully liable to Customer for each Sub-processor’s performance. Copies of the applicable provider data-processing terms are available to Customer on request.
3. Magure Affiliates
3.1 Position as at the version date. As at the version date of this Schedule, no Magure Affiliate processes In-Scope Personal Data. Support and professional services are delivered solely by personnel of Magure Tech Middle East Ltd.
3.2 Future engagement of an Affiliate. Any Magure Affiliate that processes In-Scope Personal Data in the delivery of support or professional services on Magure’s behalf acts as a Sub-processor, is bound by intra-group terms imposing data-protection obligations materially equivalent to those in the DPA, and shall be added to Clause 2 in accordance with Clause 4 before it begins processing.
4. Notification of Changes and Right to Object
4.1 General authorisation. Customer’s general authorisation for Magure to engage Sub-processors is given in Clause 6.1 of the DPA and extends to the Sub-processors listed in this Schedule and to any addition or replacement notified under this Clause 4.
4.2 Notice. Magure shall give Customer at least thirty (30) days’ prior notice of the addition or replacement of a Sub-processor, stating the identity of the Sub-processor, the service it provides, the nature of the processing, and its processing locations. Notice may be given by email to Customer’s notified contact or through the support portal, in each case accompanied by, or referring to, an updated version of this Schedule. An updated version notified in accordance with this Clause takes effect as an agreed amendment for the purposes of Clause 14 of the Terms on expiry of the objection period in Clause 4.3 without objection, or on resolution of an objection under Clause 6.3 of the DPA.
4.3 Objection. Customer may object to an addition or replacement on reasonable, documented data-protection grounds within fifteen (15) days of notice. The consequences of an objection, and Customer’s remedy where an objection cannot be resolved, are set out in Clause 6.3 of the DPA.
4.4 Replacement in an emergency. Where a Sub-processor must be replaced at short notice for reasons of security, continuity, or legal compulsion, Magure may make the replacement immediately and shall notify Customer as soon as reasonably practicable, in which case Customer’s objection right under Clause 4.3 applies from the date of that notice.
4.5 Current version. The current version of this Schedule is available on request from Magure. The version in force is the version notified or published most recently before the relevant processing.
5. Parties that are NOT Magure Sub-processors
5.1 The following are engaged, selected, or contracted by Customer, not by Magure, and are not Magure Sub-processors. Magure is not responsible for their acts, omissions, availability, or data handling, and any data-processing terms and transfer mechanism required in respect of them are a matter between Customer and the relevant party:
- (a) Foundation Model providers — whether third-party-hosted, open-weight, or Customer-deployed (Clause 6.4 of the Terms and Clause 3.3 of the DPA);
- (b) The provider of the Customer Cloud Environment — the cloud, hybrid, or on-premise infrastructure in which the Platform is deployed, which Customer procures and pays for directly (Clause 2.2 of the Terms);
- (c) Third-party products, systems, APIs, connectors, and MCP servers contracted or registered by Customer and integrated with the Platform; and
- (d) The Reseller of Record and any other partner engaged by Customer to provide L1 or L2 support, implementation, managed services, or other services. Such a partner is an independent contracting party and, where it processes Personal Data for Customer, does so under its own agreement with Customer (Clause 3.2 of the Terms and Clause 6.4 of the DPA).
6. Magure’s Own Processing as Controller
6.1 The systems listed below are used by Magure in the administration of its own business. In respect of the data held in them, Magure acts as Controller under Clause 2.3 of the DPA, not as Processor on Customer’s behalf. They are recorded here for transparency only. They are not Sub-processors, and the notification and objection mechanism in Clause 4 does not apply to them.
| System | Purpose | Data |
|---|---|---|
| HubSpot | Customer-relationship management, sales and marketing administration | Business-contact details of Customer’s and partner personnel (name, business email, business telephone, job title, employer) and records of commercial correspondence. No Customer Data. |
| Microsoft 365 / Atlassian / GitHub | Internal business administration, corporate records, and product engineering | Magure’s own corporate, personnel, and engineering records. No Customer Data. |
6.2 Where a system appears both in this Clause 6 and in Clause 2, it does so because it serves both functions: it is a Sub-processor only in respect of In-Scope Personal Data processed on Customer’s behalf as described in Clause 2, and a Controller-side system in respect of Magure’s own business data as described in this Clause 6.
MagOneAI Platform Terms · Version 1.0 · Effective 16 August 2026. © 2026 Magure Tech Middle East Ltd. This document is provided for reference; the executed Customer Order Form and Schedules constitute the binding agreement.