Trust Center

Research / Education Processing Addendum

Supplements the Standard Data Processing Agreement.

Last updated: Version 1.0 - 21 September 2026

Project details to complete

Complete the following particulars for the Project. Where a field is left blank, no additional commitment beyond the Standard DPA is made for that item.

  • Research / education purpose

    Describe the research, education or structured-learning purpose the Project serves.

  • Pilot / project identifier

    The internal name or reference number that identifies this Project.

  • Controller identity

    Full legal name and address of the controlling research institution or programme.

  • Participant categories

    The categories of data subjects in the Project (e.g. students, cohort members, research participants).

  • Project-specific retention period

    How long Project personal data is retained in active systems for this Project.

  • Maximum retention after time-point T2

    The defined end point T2 (e.g. study close, cohort end) and the maximum period data may be retained after it.

  • Backup residual period

    The residual period Project data may persist in encrypted backups after active deletion, not to exceed one year.

  • Project-specific breach-notification period

    Complete only if Magif has agreed a specific notification period for this Project; otherwise the Standard DPA applies.

  • Project-specific subprocessor-notice period

    Complete only if Magif has agreed a specific advance-notice period for this Project; otherwise the Standard DPA applies.

  • Research publication / controller-role transfer terms

    Complete only if relevant to the Project; otherwise leave blank and no such terms apply.

This Research / Education Processing Addendum (the "Addendum") is entered into between Magif and the Controller identified below, and supplements the Standard Data Processing Agreement (the "Standard DPA") already in force between the parties. It applies only to the defined research, education or structured-learning deployment described in Section 1 (the "Project") and takes effect for that Project on the date signed by both parties.

Magif is VW-CODING, SASU, 121 quai de Valmy, 75010 Paris, France, registered with the RCS of Paris under number 914 650 387 ("Magif"). Magif acts as processor for the Project on behalf of the Controller, who acts as controller for the personal data processed under the Project.

This Addendum does not replace the Standard DPA. All terms of the Standard DPA continue to apply to the Project except where this Addendum states otherwise. Where a term of this Addendum conflicts with a term of the Standard DPA, the term that is more protective of the research or education participants prevails for the defined Project. Capitalised terms not defined here have the meaning given in the Standard DPA.

This Addendum is optional. It exists so that universities, structured learning programmes and similar institutions can agree Project-specific retention, deletion, research-data and governance commitments in addition to the baseline protections of the Standard DPA. Where a field below is left blank, no additional commitment beyond the Standard DPA is made for that item.

1. Project scope and purpose

This Addendum governs a single defined Project. The Project is described by the following particulars, completed by the parties for this Project:

  • Research / education purpose: [__________]
  • Pilot / project identifier: [__________]
  • Controller identity: [__________]
  • Categories of participants: [__________]

Magif processes Project personal data only for the purpose stated above and only on the documented instructions of the Controller. Magif does not process Project personal data for any purpose outside the Project scope defined in this Section, except where required by applicable law, in which case Magif informs the Controller before processing unless the law prohibits such notice.

Where any particular in this Section is left blank, the corresponding scope, purpose or category is governed by the Standard DPA and the Controller's separate documented instructions.

2. Retention for the Project

Magif retains Project personal data in active systems only for the period the parties agree for this Project.

  • Project-specific retention period: [__________]
  • Defined end point T2 and maximum retention after T2: [__________]

On expiry of the applicable period, Magif deletes the Project personal data from active systems in accordance with Section 3. Where a retention field above is left blank, the retention periods of the Standard DPA apply and no shorter or longer Project-specific period is promised.

Magif does not extend Project retention beyond the agreed period without the Controller's documented instruction, save where retention is required by applicable law.

3. Backups and residual copies

Project personal data held in Magif backups is encrypted. Backups expire on a rolling schedule, and Magif's backup retention does not exceed one year.

When Project personal data is deleted from active systems, residual copies may persist in encrypted backups until those backups expire on their normal rolling schedule. During that residual window, the data remains encrypted and is not restored to active use except to recover the service after an incident.

  • Backup residual period for this Project: [__________]

Where the backup residual field is left blank, the residual period is the normal rolling expiry described above, which is at most one year.

4. Deletion rights

Magif supports the following deletion capabilities for the Project, on the Controller's documented instruction:

  • Participant-level deletion: Magif deletes the Project personal data of an individual participant on request.
  • Whole-study deletion: Magif deletes all Project personal data for the Project on request.

Deletion applies to active systems on receipt of a valid instruction. Residual copies in encrypted backups are handled as described in Section 3 and are removed when those backups expire.

Magif does not train any model on, and does not otherwise reuse, Project personal data that is scheduled for or subject to a deletion instruction.

5. Deletion confirmation

On the Controller's request, Magif provides written confirmation when Project study data has been deleted from active systems, and states the date on which active deletion was completed and the residual backup window that then applies under Section 3.

Such confirmation is provided for participant-level deletion and for whole-study deletion. Magif provides this confirmation on request rather than automatically for every deletion, unless the parties agree otherwise for the Project.

6. No training on Project content

Magif does not use customer or participant content from the Project to train, fine-tune or otherwise develop any machine-learning model.

Project content is processed solely to deliver the service for the Project. It is not incorporated into training data, evaluation sets or model-improvement pipelines.

7. No use for general product improvement where agreed

Where the parties agree in the Standard DPA or in this Addendum that Project content will not be used for general product improvement, Magif does not use Project content to improve, benchmark or develop its general products or services outside the delivery of the Project.

This commitment applies to the extent the parties have contractually agreed it. Absent such agreement, the Standard DPA governs any product-improvement processing.

8. Restricted support access

Access to Project personal data by Magif support and engineering personnel is restricted to a need-to-know basis. Only personnel who require access to operate the service, resolve a support request or respond to an incident for the Project may access Project personal data, and only to the extent needed for that task.

Magif's personnel are bound by confidentiality obligations. Magif does not represent that access to conversation content is currently logged; any such logging commitment, if agreed, would be recorded separately and is not promised by this Addendum.

9. Processing location

Core processing of Project personal data takes place in the European Union. Details of Magif's processing locations and infrastructure are published at /trust/data-residency.

Any transfer outside the European Union is handled in accordance with the Standard DPA, including appropriate safeguards.

10. Incident contact and breach notification

The Controller may raise a security or data-protection incident concerning the Project through the incident contact channel set out in the Standard DPA. Magif notifies the Controller of a personal data breach affecting the Project without undue delay after becoming aware of it, in accordance with the Standard DPA.

  • Project-specific breach-notification period: [__________]

Where the field above is completed, Magif notifies the Controller within that period for the Project. Where it is left blank, the breach-notification timing of the Standard DPA applies and no separate Project-specific period is promised.

11. Subprocessors

Magif engages subprocessors in accordance with the Standard DPA, and gives the Controller notice of intended changes to subprocessors so that the Controller may object.

  • Project-specific subprocessor-notice period: [__________]

Where the field above is completed, Magif gives the Controller that period of advance notice of subprocessor changes for the Project. Where it is left blank, the subprocessor-notice period of the Standard DPA applies and no separate Project-specific period is promised.

12. Research publication and transfer of controller role

This Section applies only where the parties complete it for the Project. It is otherwise not in force and imposes no obligation.

  • Research publication / controller-role transfer terms: [__________]

Where completed, these terms govern any agreed handling of research outputs, publication of anonymised or aggregated results, and any transfer of the controller role for the Project. Where left blank, no research-publication or controller-role-transfer terms are agreed under this Addendum, and the roles and responsibilities in the Standard DPA continue unchanged.

13. Order of precedence and term

This Addendum supplements and is governed by the Standard DPA. Where this Addendum conflicts with the Standard DPA, the term more protective of the Project's research or education participants prevails for the defined Project.

This Addendum takes effect for the Project when signed by both parties and remains in force for the duration of the Project and until Project personal data has been deleted in accordance with Sections 2 to 5. Blank fields in this Addendum indicate that no Project-specific commitment beyond the Standard DPA has been agreed for that item.

Signatures

Processor

Magif (VW-CODING, SASU)
Name:
Title:
Signature:
Date:

Controller / Research institution

Legal entity:
Project:
Name:
Title:
Signature:
Date:

How to execute this agreement

Download or print the current agreement, complete the customer details and sign it. Send the signed copy to [email protected]. An authorised Magif representative will countersign and return the executed agreement.

  1. Open the full contract on this page.
  2. Print it or download the PDF.
  3. Fill in the controller / customer company details.
  4. Sign it.
  5. Email the signed copy to [email protected].
  6. Magif countersigns.
  7. Magif returns the fully executed copy.
No NDA is required.