Legal
Privacy policy
Magnifi works with business data, reviews and platform connections belonging to our customers. Below is exactly what we process, why, for how long and with whom we share it.
Last updated: 8 August 2026
1. Who is responsible
Magnifi is a service of Superworkx B.V. (trading as Social Roots), Bruistensingel 500, 5232 AH 's-Hertogenbosch, the Netherlands. Email magnifi@socialroots.nl, phone +31 88 999 8778.
We are the controller for our account holders' data. For data you process about your own customers through Magnifi (such as review texts and reviewer names) you are the controller and we act as processor.
2. What we process
Account data: name, email address, password hash or Google sign-in, language preference and role within the account.
Business data: business name, address, phone number, website, category, opening hours and location settings.
Platform data: reviews, ratings, reviewer texts and names, published replies, directory listings and opening hours as shown on external platforms.
Connection data: OAuth access and refresh tokens for connected platforms such as Google Business Profile. These are stored encrypted and are reachable only by our server, never by the browser.
Usage data: scans performed, scores, tasks, sessions and events such as 'scan started' or 'checkout started'.
Billing data: subscription status, plan and invoice history. We do not process card details ourselves; those go directly to our payment provider.
3. Why we use it
To deliver the service: run scans, fetch and answer reviews, keep opening hours in sync, measure visibility and build action lists.
To perform the agreement and handle billing.
For security, abuse prevention and troubleshooting.
For product improvement based on aggregated, non-identifiable statistics.
We do not sell data and do not use customer data for advertising or third-party profiling.
4. Legal bases
Performance of the contract for everything needed to make Magnifi work.
Legitimate interest for security, fraud prevention and product improvement.
Legal obligation for accounting and tax retention.
Consent for optional connections and non-essential cookies, withdrawable at any time.
5. Google user data and Limited Use
When you connect your Google Business Profile we request the business.manage scope plus your basic profile (openid, email, profile). With it we read your location data, opening hours and reviews, and publish the replies and changes you approved or configured through your automation rules.
Magnifi's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
In practice: we use Google data only to provide the features you see in Magnifi, we do not sell it, we do not use it for advertising, and we do not share it with third parties except as needed to provide the service, to comply with the law, or with your explicit consent.
We do not use Google user data to train generalised AI or machine learning models. The AI models that draft replies receive only the context of that single review, and those providers do not use the input for model training.
You can disconnect at any time in Magnifi, and revoke access from your Google Account under Security and Third-party apps with account access. On disconnect we delete the stored tokens immediately.
6. Processors and recipients
Hosting, database, authentication and server functions: our cloud infrastructure with storage in the European Union.
Payments: our payment provider processes payments and subscriptions.
AI models for drafting review replies and copy, under the condition that input is not used for model training.
Connected platforms such as Google Business Profile, solely to read and publish the data you authorised.
Email delivery for account and system notifications.
Data processing agreements are in place with all of these parties. Transfers outside the EEA rely on the European Commission's standard contractual clauses.
7. Retention
Account data is kept while your account is active.
After cancellation your data stays readable for 90 days so you can export or return. After that we delete the content data.
OAuth tokens are deleted immediately when a connection is removed or the account is deleted.
Invoicing and accounting records are kept for seven years due to statutory retention rules.
Aggregated, non-identifiable statistics may be kept longer.
8. Security
All connections run over TLS and data is stored encrypted.
Access is isolated per account with row level security, so an account can only reach its own data.
Tokens for connected platforms are server-side only and are never sent to the browser.
Internal access is limited to staff who need it for support or maintenance.
9. Your rights
You have the right to access, rectification, erasure, restriction, objection and data portability.
Send a request to magnifi@socialroots.nl. We respond within 30 days.
If you disagree with how we handled it, you can lodge a complaint with the Dutch Data Protection Authority.
10. Cookies
We set functional cookies required for sign-in and to remember your language and session.
Analytics events are stored in our own environment and used only in aggregate to improve the service.
We do not set advertising cookies and do not share data with ad networks.
11. Changes
We may update this policy as the service evolves. For material changes we notify account holders by email. The current version is always on this page.
Questions about this page?
Email us and we reply within two working days.
Superworkx B.V. (Social Roots) · Bruistensingel 500 · 5232 AH 's-Hertogenbosch · Nederland
Terms and conditions