top of page

Privacy Policy

1. Introduction
Magic Creative Software Pte Ltd (a company incorporated in Singapore with its registered office at 68 Circular Road, #02-01 Singapore 049422) and its affiliated and related companies (“MCsoftware”, “we”, “us” or “our”) respect your privacy and are committed to protecting the personal data we hold about you. This Privacy Policy (“this Policy”) explains what personal data we collect, why we collect it, how we use and share it, and the rights and choices available to you.
 
As used throughout this Policy, “MCsoftware”, “we”, “us”, and “our” refer to Magic Creative Software Pte Ltd and, where applicable, its affiliated and related companies.  “You” and “your” refer to any individual whose personal data we process, including visitors to our website, users of our mobile application, prospective customers, customers, partners, and authorized users of our products and services.
 
Our Services include our website at www.magiccreative.io, our mobile application(s), all software and, cloud‑based and on‑premise products made available by MCsoftware (as listed and updated on our website from time to time), and any associated platforms, tools, or support channels we operate now or in the future (collectively, the ‘Services’).
 
Please read this Policy carefully. By accessing or using any part of the Services, you acknowledge that you have read and understood the practices described in this Policy.
 
2. Who We Are and Our Role in Processing Data
The way data protection law applies to us depends on the role we play in relation to your personal data. We act in two distinct capacities, depending on the context.
 
2.1 Where we act as a controller
For personal data that we collect through our website, our marketing activities, our sales and account management processes, our support channels, and our own business administration, MCsoftware (and, where relevant, its applicable affiliates involved in providing the Services or processing personal data) act as a controller. This means we decide why and how that data is processed, and this Policy governs that processing.
 
2.2 Where we act as a processor
When a customer uses the Services, the customer determines what data is entered, imported, or generated within the Services. This may include data about the customer’s employees, contractors, end users, or IT environment. In relation to such customer content, MCsoftware (and, where applicable, relevant affiliates acting on its behalf) act as a processor or service provider, and we process the data only on the documented instructions of the customer, who is the controller.
 
If you are an end user, employee, or contractor of one of our customers, and you have a question about how your personal data is handled within the Services, please contact that customer directly, as they determine how the Services are used. We will support our customers in responding to such requests in accordance with our agreements with them. Section 8 explains this in more detail.
 
3. Scope of This Policy
This Policy applies to personal data that MCsoftware processes as a controller in connection with our website and Services. It does not apply to:

  • Customer content that we process as a processor or service provider on behalf of our customers, which is governed by our agreement with each customer and that customer’s own privacy notices.

  • Third-party websites, applications, products, or services that we do not own or control, even where they are linked from our website or integrated with the Services.

  • Aggregated or anonymized information that can no longer reasonably be used to identify an individual.


4. Information We Collect
We collect personal data in several ways: information you provide to us, information we collect automatically when you use our website and Services, and information we receive from third parties.

4.1 Information you provide to us

  • Identity and contact details: such as your name, job title, employer, business email address, business telephone number, and country.

  • Account information: credentials and profile details created when you register for an account, a trial, an evaluation, or a customer portal.

  • In‑app submissions: content you upload or submit through the Services, such as forms, files, photos, messages, or other data you choose to provide.

  • Enquiry and interest information: the content of messages you send us through contact forms, demo requests, event registrations, and similar channels, including your areas of interest.

  • Support information: details you share when you contact our support team, including the nature of your issue and any information you choose to include in tickets or communications.

  • Commercial information: records relating to quotes, orders, contracts, and the products and Services you have purchased or expressed interest in.

  • Payment and billing details: billing contact, billing address, tax identifiers, and transaction records. Card and bank details are handled by our payment processors and are not stored by us in full.


4.2 Information we collect automatically
When you visit our website or use the Services, we and our service providers may automatically collect:

  • Device and connection data: IP address, browser type and version, operating system and device model, device identifiers (such as IDFA, GAID, device token, vendor ID), language and regional settings, and app version and installation source (for mobile applications).

  • Usage and Interaction data: pages, screens, and features viewed, buttons tapped and navigation paths, session duration and frequency, referring and exit pages, dates and times of access, and how you interact with content and features within the Services.

  • Mobile application permissions and sensor data: depending on your device settings and the features you use, we may collect: camera access, photo library or file access, microphone access, location data, push notification tokens, Bluetooth or nearby device data. You may control or disable these permissions through your device settings.

  • Analytics, diagnostics, and performance data: crash logs, error reports, performance metrics, aggregated analytics about how the Services are used.

  • Cookies and similar technologies: as described in Section 6 below. Where required by applicable law, we collect this information only with your consent, which you can manage through our cookie controls.


4.3 Information we receive from third parties

  • Business partners and resellers: where a partner refers you to us or manages an account on your behalf, they may share your contact and account details with us.

  • Public and commercial sources: professional and business information from public registries, professional networking platforms, and reputable data providers, used to verify details and to understand potential business needs.

  • Authentication providers: if you choose to sign in using a third‑party login (such as Google or Apple), we receive basic profile information necessary to authenticate your account and enable access to the Services.

  • Analytics, attribution and advertising providers: aggregated insights about how visitors and users find and engage with the Services, including installation source, referral information, and high‑level usage trends. This information does not allow us to identify individual users.


5. How We Use Your Information
We use personal data for the purposes set out below. Where the law requires a legal basis for processing, the table indicates the basis we rely on. The terminology of legal bases varies between jurisdictions; the principles described here are intended to apply across the markets in which we operate.

How We Use Your Information.jpg

We do not sell your personal data. Where we rely on legitimate interests, we balance those interests against your rights and freedoms, and you may object as described in Section 12.

6. Cookies and Similar Technologies
Our website and certain parts of the Services use cookies and similar technologies to make the site work, remember your preferences, understand how the Services are used, and, where you allow it , support marketing. Cookies are small files placed on your device. Similar technologies include pixels, tags, SDKs, and local storage used in web and mobile environments.

We use the following broad categories:

  • Strictly necessary: required for the website and the Services to function and to keep them secure. These cannot be switched off in our systems.

  • Functional: remember your choices and improve your experience.

  • Analytics: help us understand how visitors and users interact with the Services so we can improve them.

  • Marketing: used to deliver and measure content that may be relevant to you, including attribution and referral tracking.


Where required by law, we request your consent before placing non-essential cookies or similar technologies. You can change your choices at any time through the cookie settings on our website or your browser controls. Disabling some cookies may affect how the website or certain features of the Services function.

7. How We Share Your Information
We share personal data only where necessary and with appropriate safeguards. We may share it with the following categories of recipients:

  • MCsoftware group companies: affiliates and related entities involved in providing the Services or supporting internal operations.

  • Service providers: vendors who process data on our behalf, such as hosting, cloud infrastructure, customer relationship management, email and communications, analytics and attribution partners, authentication providers, mobile SDK providers, and payment processing. They act on our instructions and are bound by confidentiality and data protection obligations.

  • Business partners and resellers: where you engage with us through a partner, or a partner manages your account, we share only the information needed to support that relationship.

  • Professional advisers: such as auditors, lawyers, and accountants, where needed for legitimate business purposes.

  • Corporate transactions: in connection with a merger, acquisition, financing, reorganization, or sale of assets, in which case personal data may be transferred subject to appropriate protections.

  • Authorities and legal requirements: where we are required to disclose data to comply with law, regulation, legal process, or an enforceable governmental request, or to protect our rights, users, or the public.


We do not disclose personal data to third parties for their own independent marketing without your consent. Customer content that we process as a processor on behalf of our customers is shared only according to the customer’s instructions, as described in Section 2. 

8. Customer Data Processed Through Our Products
When our customers use the Services, they may store and process personal data within their instances of the Services as part of their use of the Services. In relation to that data:

  • The customer is the controller and decides what data is processed and for what purpose.

  • MCsoftware acts as a processor and processes customer content only to provide, maintain, secure, and support the Services, in accordance with the customer’s documented instructions and our agreement with the customer.

  • The customer determines the categories of personal data it chooses to store in the Services and is responsible for providing appropriate privacy notices to individuals whose data it processes.

  • We apply technical and organizational security measures to protect customer content, as described in Section 11 and in our agreements.

  • For self-hosted deployments, where the customer operates in its own environment, the customer is responsible for the operation and security of that environment, and our processing is limited to the support and services we are engaged to provide.


If you wish to exercise privacy rights over data held within a customer’s instance of our products, please contact the relevant customer, who is responsible for responding. We will assist our customers in responding to such requests under our agreements.
 

9. International Data Transfers

MCsoftware operates across Southeast Asia, Hong Kong, and other markets. Personal data may be transferred to, stored in, or accessed from countries other than the one in which you are located, including by our affiliates and service providers. These countries may have data protection laws that differ from those in your country.

Where we transfer personal data across borders, we take steps to ensure it remains protected. These safeguards may include relying on adequacy decisions where available, entering into appropriate contractual safeguards such as standard contractual clauses, and applying additional technical and organizational measures such as encryption, access controls, and data minimization.  These protections apply whether the data is processed in our cloud environment or accessed for support purposes in a self-hosted deployment. You may request more information about the safeguards we use by contacting us as set out in Section 16.

10. Data Retention

We keep personal data only for as long as we need it for the purposes described in this Policy, after which we delete it or anonymize it. The appropriate retention period depends on the type of data and the reason we hold it. When determining retention periods, we consider:

  • How long we need the data to provide the Services, maintain your account and manage our relationship with you.

  • Legal, tax, accounting, and regulatory requirements that oblige us to retain records.

  • Where retention is necessary to establish, exercise, or defend legal claims or to support investigations.

  • Our legitimate interests in maintaining accurate business records, ensuring security, and preventing misuse.

 

Where personal data is no longer required, we securely dispose of it. Aggregated or anonymized data that can no longer identify you may be retained for longer analytics, research or security purposes.

Retention of customer content stored within a customer’s instance of the Services is determined by the customer, as described in Section 8.

11. How We Protect Your Information

We maintain technical and organizational measures designed to protect personal data against unauthorized access, loss, misuse, alteration, and disclosure. These measures follow industry-standard security practices and may include access controls, encryption in transit and at rest, network and application security controls, monitoring and logging, secure development and testing practices, staff confidentiality obligations, data center and physical security, and supplier due diligence. We also maintain incident response procedures to detect, investigate, and address potential security events.

These protections apply whether the data is processed in our cloud environment or accessed for support purposes in a self‑hosted deployment. Customers who operate the Services in their own environment are responsible for securing that environment, as described in Section 8.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. We encourage you to use strong, unique credentials, keep your access details confidential, and to notify us promptly if you suspect any unauthorized use of your account.

12. Your Privacy Rights

Subject to applicable law and to any conditions and exemptions that apply, you may have the following rights in relation to your personal data that we process as a controller:

  • Access: to ask whether we hold personal data about you and to obtain a copy.

  • Correction: to ask us to correct data that is inaccurate or incomplete.

  • Deletion: to ask us to delete personal data where there is no longer a valid reason for us to keep it.

  • Restriction and objection: to ask us to limit, or to object to, certain processing, including direct marketing and processing based on legitimate interests.

  • Portability: to receive certain data in a structured, commonly used, machine readable format, where applicable.

  • Withdrawal of consent: to withdraw consent at any time where we rely on consent, without affecting processing carried out before withdrawal.

  • Complaint: to lodge a complaint with the relevant data protection authority in your jurisdiction.

 

To exercise any of these rights, please contact us using the details in Section 16. We may need to request additional information to verify your identity before responding. We will respond within the timeframe required by applicable law. There is normally no charge, although we may apply a reasonable fee or decline a request where the law permits, for example where a request is manifestly unfounded or excessive. If we decline a request, we will explain the reason unless the law prevents us from doing so.

13. Children’s Privacy

Our website and Services are intended for businesses and their authorized representatives and are not directed at children. We do not knowingly collect personal data from children or provide Services intended for children under applicable laws. If you believe a child has provided us with personal data, please contact us and we will take appropriate steps to delete it.

14. Third-Party Websites and Services

Our website and Services may contain links to, or integrations with, third-party websites, applications, and services that we do not control. This Policy does not apply to those third parties, and we are not responsible for their privacy practices. We encourage you to review the privacy notices of any third party before providing them with personal data. Information about how we share personal data with third parties, including service providers and integration partners, is set out in Section 7.

15. Changes to This Privacy Policy

We may update this Policy from time to time to reflect changes in our practices, the Services, or legal requirements. When we make material changes, we will update the effective date at the top of this document and, where appropriate, provide additional notice, such as through your account or by email. Your continued use of the Services after an updated Policy becomes effective indicates that you have read and understood the changes. We encourage you to review this Policy periodically. We may retain previous versions of this Policy as required by law.

16. How to Contact Us and Raise Concerns

If you have questions about this Policy or you wish to exercise your privacy rights in relation to personal data that we process as a controller, you may contact us using the details below:

Entity: Magic Creative Software Pte Ltd
Privacy contact: Chief Data Privacy Officer
Email: dpo@magiccreative.io
Postal address: 68 Circular Road, #02-01, Singapore, 049422
Data protection officer: Chief Data Privacy Officer

Requests relating to customer content stored within a customer’s instance of the Services should be directed to the relevant customer, as described in Section 8.

We may need to request additional information to verify your identity before responding. If you are not satisfied with our response, you have the right to contact the data protection authority in your country. We would, however, appreciate the opportunity to address your concerns directly before you do so.

bottom of page