Last updated: 20 August 2026
Magic EdTech respects your privacy. This Privacy Policy explains how Magic collects, uses, discloses, retains, and protects Personal Data, and the rights and choices available to you.
| Website and business data
Magic generally acts as the controller for website visitors, business contacts, prospects, marketing contacts, and applicants. |
Client service data
When a customer decides why and how data is processed in a Magic service, Magic generally acts as a processor or service provider. |
| Learner data
Learner and education data is handled under customer instructions, contracts, and any product-specific privacy notice. |
Sale of data
Magic does not sell Personal Data for money. Some advertising disclosures may be treated as a sale or sharing under certain U.S. laws. |
| Your choices
You can unsubscribe from marketing, manage website technology choices, and exercise applicable privacy rights. |
Privacy contact
Questions, requests, and complaints can be sent to mail@magicedtech.com. |
Contents
| 01 About this Policy | 10 How long we keep Personal Data |
| 02 Who is responsible for your Personal Data | 11 How we protect Personal Data |
| 03 Personal Data we collect | 12 Marketing, analytics, and website technologies |
| 04 Where Personal Data comes from | 13 Your privacy rights |
| 05 How and why we use Personal Data | 14 Children and learner privacy |
| 06 Customer-controlled data and learner data | 15 Third-party websites and services |
| 07 Recruitment, consultants, and FlexPro | 16 Privacy complaints |
| 08 How we disclose Personal Data | 17 Changes to this Policy |
| 09 International transfers | 18 Contact Magic EdTech |
1. About this Policy
This Policy applies when you visit the Magic EdTech website at magicedtech.com and related Magic EdTech pages (the “Site”), communicate with us, request a demo, access a resource, subscribe to communications, attend an event, or interact with us as a customer, prospect, partner, supplier, or other business contact.
It also applies when you apply for a role with Magic, are considered or engaged as a consultant or contractor, or use a Magic product or service in a context where Magic determines the purposes and means of processing your Personal Data.
This Policy does not replace:
- a customer, school, district, publisher, university, employer, or other organization’s own privacy notice when that organization controls the data;
- a product-specific or service-specific privacy notice, including any notice that applies to MagicBox or another Magic offering;
- the separate Cookie Policy, which explains cookies and similar technologies used on the Site; or
- an internal workforce privacy notice that applies to Magic employees or personnel.
Where a product-specific notice, collection notice, or contract is more specific than this Policy, the more specific document will govern that processing. To see our Cookie Policy, please visit this page.
2. Who is responsible for your Personal Data
In this Policy, “Magic”, “we”, “us”, and “our” mean Magic Software Inc. and, where the context requires, the Magic group entity identified in your contract or at the point Personal Data is collected. The Site identifies Magic Software Inc. as the Magic EdTech entity operating under the Magic EdTech brand.
For Personal Data collected through the Site and for general business contact, marketing, recruitment, and relationship-management activities, Magic Software Inc. generally acts as the data controller or business, unless we tell you that another Magic entity is responsible.
For many products and services, Magic processes Personal Data for a customer that decides why and how the data is used. In that situation, Magic acts as a processor or service provider, and the customer acts as the controller or business. Section 6 explains this distinction.
| Important role distinction
A person may interact with Magic in more than one role. For example, Magic may be a processor for a learner account created by a school, but a controller for the same person’s separate request to receive a Magic newsletter. |
3. Personal Data we collect
“Personal Data” means information that identifies, relates to, describes, or can reasonably be linked with an individual. It includes “personal information” and similar terms used in applicable privacy laws. It does not include data that has been anonymized or de-identified so that it cannot reasonably identify an individual.
| Category | Examples |
| Contact and identity data | Name, work email address, telephone number, postal address, country, online identifier, and other information used to identify or contact you. |
| Business and professional data | Employer or organization, role, job title, business interests, industry, relationship with Magic, procurement or account information, and how you heard about us. |
| Communications and content | Inquiries, form submissions, meeting notes, messages, support requests, feedback, survey responses, files, and other content you choose to send to Magic. |
| Account and service data | User or account ID, access role, authentication events, preferences, product configuration, license information, support history, and records of services provided. |
| Recruitment and consultant data | CV or resume, work history, education, skills, qualifications, certifications, languages, location, availability, rates, work samples, screening results, references, contracts, compliance evidence, project history, and performance information. |
| Technical and usage data | IP address, approximate location derived from IP address, browser, operating system, device type, cookie and other online identifiers, referring page, traffic source, search and campaign parameters, pages or features viewed or used, links and buttons selected, scrolling and navigation behavior, session-replay and heatmap information, form-interaction and submission events, conversion events, dates and times, diagnostic logs, security events, and other information about interaction with the Site. |
| Marketing and preference data | Newsletter and communication preferences, campaign source, advertising and attribution identifiers, event or resource interest, audience or segment information where applicable, conversion information, and information about whether a business email was delivered or opened, or whether a selected link was clicked. |
| Customer-controlled service data | Data a customer submits to or makes available through a service, which may include learner, educator, administrator, workforce, enrollment, content, assessment, engagement, accessibility, analytics, or institutional data. The exact fields depend on the customer and service. |
| Sensitive Personal Data | Where necessary and legally permitted, Magic may process information such as government identifiers, right-to-work documents, background-check results, health or disability information needed for an accommodation, or other data treated as sensitive by law. Magic does not ask for sensitive data in general website inquiry or marketing forms. |
Required information. Fields marked as required are needed to process the relevant request. If you do not provide required information, Magic may be unable to respond, create an account, evaluate an application, or provide the requested product or service. Other fields are optional.
Please do not submit learner data, health information, financial information, government identifiers, or other sensitive information through a general website form unless Magic specifically requests it through an approved channel.
4. Where Personal Data comes from
Magic may collect Personal Data from the following sources:
- directly from you, including through forms, email, calls, meetings, applications, support requests, accounts, and use of products or services;
- from your employer, customer, school, district, publisher, university, or another organization that authorizes your use of a Magic service;
- from customers, business partners, referrals, event organizers, and other people who introduce or authorize communication with you;
- from recruitment agencies, professional networks, referees, screening providers, and publicly available professional or business sources;
- automatically from your browser, device, network, cookies, pixels, tags, scripts, session-replay technologies, and other interactions with the Site or services;
- from service providers and platforms that support website analytics, behavioral analytics, tag management, search-performance and SEO reporting, customer relationship management, marketing automation, advertising, conversion measurement, communications, security, recruitment, or support; and
- from integrations or third-party services that you or a customer directs Magic to connect with a service.
Where Magic obtains Personal Data from a source other than you, we will provide any notice required by applicable law, unless an exception applies.
5. How and why we use Personal Data
Magic uses Personal Data only for specified and lawful purposes. The legal bases below apply where laws such as the EU GDPR or UK GDPR require a legal basis. The basis used can vary according to the relationship, the data, and the jurisdiction.
| Activity | Purpose | Legal basis |
| Enquiries, demos, resources, and events | Respond to questions, schedule meetings or demonstrations, provide requested materials, register attendance, follow up, and manage preferences. | Steps before a contract; contract; legitimate interests; consent where required. |
| Customer and business relationships | Establish and manage customer, partner, supplier, and consultant relationships; negotiate and perform contracts; manage accounts, projects, billing administration, and communications. | Contract; steps before a contract; legitimate interests; legal obligations. |
| Products, services, and support | Provide access, configure and operate services, authenticate users, deliver support, maintain records, monitor performance, and meet service commitments. | Contract; legitimate interests; legal obligations; customer instructions when Magic is a processor. |
| Security and service integrity | Protect accounts, systems, users, and data; detect and investigate misuse, fraud, vulnerabilities, and incidents; maintain logs; enforce terms. | Legitimate interests; legal obligations; contract. |
| Analytics, research, and improvement | Understand traffic sources and use of the Site and services; measure page, content, and feature engagement; review heatmaps and session-replay information; diagnose technical and usability issues; improve accessibility, quality, navigation, content, features, and user experience; and develop de-identified or aggregated insights. | Legitimate interests; consent where required for website technologies. |
| Recruitment and consultant management | Assess applications, verify qualifications, conduct permitted screening, match people to roles or projects, manage availability, contracts, assignments, and performance. | Steps before a contract; contract; legitimate interests; legal obligations; consent or another condition for sensitive data where required. |
| Marketing and relationship development | Send relevant business communications, newsletters, invitations, and information about Magic services; measure engagement and campaign performance; attribute enquiries, form submissions, and other conversions; understand engagement with advertising and marketing content; support advertising measurement and, where permitted and configured, audience creation or retargeting; and maintain consent and opt-out records. | Consent where required; legitimate interests for permitted business-to-business communications. |
| Legal, compliance, and corporate purposes | Comply with law, audits, tax and recordkeeping duties; respond to lawful requests; establish or defend claims; protect rights; support a merger, financing, acquisition, or sale. | Legal obligations; legitimate interests; contract. |
Legitimate interests. Where Magic relies on legitimate interests, those interests may include operating and securing the business, providing and improving services, managing professional relationships, recruiting and deploying qualified personnel, and communicating with relevant business contacts. Magic considers the impact on individuals and does not rely on this basis where rights and interests override Magic’s interests.
Sensitive Personal Data. Magic processes sensitive Personal Data only when necessary, proportionate, and permitted by law, for example with explicit consent, to meet employment or social-protection obligations, to establish or defend legal claims, or for another recognized legal condition.
De-identified and aggregated data. Magic may create and use statistics, analytics, and other information that has been aggregated or de-identified. Magic will not attempt to re-identify that information except to test whether de-identification is effective or as permitted by law.
6. Customer-controlled data and learner data
Magic works with education publishers, schools, districts, higher education institutions, workforce organizations, and other customers. A customer may provide Personal Data to Magic or authorize Magic to access data to deliver a contracted product or service.
When the customer determines why and how that data is processed, the customer is the controller or business, and Magic is its processor or service provider. Magic processes the data under the customer’s documented instructions, the applicable contract, and law. The customer is responsible for its own notices, lawful basis, and permissions.
The categories of data depend on the service and the customer’s configuration.
- Some services are hosted or operated by Magic, while others may operate in infrastructure controlled by the customer.
- Product-specific notices and contracts may provide more detailed rules for access, retention, deletion, data location, and security.
- Magic does not use customer-controlled learner data for Magic’s own independent direct marketing and does not sell that data for money.
- Magic may use de-identified or aggregated service information for security, reliability, reporting, and improvement when permitted by the contract and law.
Privacy requests for customer-controlled data. Contact the customer, school, district, publisher, university, employer, or other organization that provided the service. Magic will assist that organization in responding as required by contract and law. A request sent directly to Magic may be referred to the relevant customer.
Product-specific notices. Some products have a separate privacy notice. For example, the MagicBox Privacy Policy describes data practices specific to that platform.
7. Recruitment, consultants, and FlexPro
Magic collects and uses Personal Data to recruit employees and to identify, screen, engage, deploy, and manage consultants and contractors. Data may come from you, recruiters, professional or public sources, referees, screening providers, customers, and previous Magic projects.
Depending on the role, Magic may process qualifications, work history, skills, subject and grade-band expertise, tools, certifications, languages, location, availability, rates, work samples, test or review results, references, identity and right-to-work evidence, background-check results where lawful, contract and compliance records, project history, performance, and client feedback.
FlexPro supports consultant discovery and management. It can be used to filter and match consultants, document screens and approvals, record reviewer comments, and generate or display scores such as FlexScore. Magic teams and authorized customers may use these outputs alongside human review, role requirements, availability, compliance status, cost, prior performance, and other business criteria.
| Automated processing and scoring
Where applicable law gives you rights in relation to a decision based solely on automated processing that produces a legal or similarly significant effect, Magic will provide the required notice and safeguards. These may include information about the decision, a way to express your view, human review, or a way to contest the outcome. |
Magic may share an applicant or consultant profile with an authorized customer or hiring team when necessary for a role, assignment, or project, subject to the relevant relationship, notice, permissions, and contractual controls.
8. How we disclose Personal Data
Magic may disclose Personal Data to the following categories of recipients:
Magic group companies, offices, and authorized personnel that need the information for the purposes described in this Policy;
- customers, schools, districts, publishers, universities, employers, or business partners connected with the relevant service, request, role, or project;
- service providers and platforms that support cloud hosting, infrastructure, cybersecurity, website analytics, behavioral analytics, tag management, search-performance and SEO reporting, customer relationship management, marketing automation, email and communications, advertising, conversion measurement, social-media marketing, support, recruitment, screening, document management, professional services, and business operations;
- professional advisers, auditors, insurers, banks, and other organizations that support legal, financial, compliance, risk, or corporate matters;
- courts, regulators, law enforcement, public authorities, and other parties when disclosure is legally required or reasonably necessary to protect rights, safety, systems, users, or the public;
- a buyer, investor, lender, successor, or other relevant party in connection with a proposed or completed merger, financing, acquisition, reorganization, insolvency, or transfer of assets; and
- other recipients at your direction or with your authorization, including integrations selected by you or a customer.
These recipients may act as Magic’s processor or service provider, or as a separate controller or business, depending on the service, contractual arrangement, configuration, and applicable law. Where a recipient processes Personal Data on Magic’s behalf, Magic applies appropriate due diligence and contractual confidentiality, security, and data-protection requirements.
Magic does not sell Personal Data for monetary consideration. Depending on the technologies used and the law that applies, certain disclosures for targeted advertising or cross-context behavioral advertising may be treated as a “sale” or “sharing” even when no money is exchanged. Where applicable, Magic will provide a way to opt out through the Site’s privacy or cookie controls or through the contact methods in this Policy.
Where applicable, Magic provides a way to opt out through the Do Not Sell or Share My Personal Information page, the Site’s privacy controls, recognised browser-based opt-out signals, or the contact methods identified in this Policy.
9. International transfers
Magic operates from locations including the United States, India, and the United Kingdom, and may use service providers in other countries. As a result, Personal Data may be transferred to or accessed from a country whose privacy laws differ from those where you live.
Where a restricted international transfer requires safeguards, Magic uses an approved legal mechanism appropriate to the transfer. This may include an adequacy decision, the European Commission Standard Contractual Clauses, the UK International Data Transfer Agreement or UK Addendum, contractual protections, or another mechanism recognized by applicable law.
Data location and transfer arrangements for customer-controlled service data may also be set out in the customer contract, data processing agreement, or product-specific documentation. You may contact the Privacy Team for further information about applicable safeguards, subject to appropriate confidentiality and redaction.
10. How long we keep Personal Data
Magic keeps Personal Data only for as long as reasonably necessary for the purpose for which it was collected, including to perform a contract, maintain security and service continuity, meet legal or regulatory duties, resolve disputes, enforce agreements, and establish or defend claims.
| Record type | Retention approach |
| Website inquiries and business contacts | For the period needed to respond, manage the relationship, follow up on a legitimate business request, and meet legal or claims requirements. |
| Marketing records | Until you opt out, the address becomes invalid, or Magic no longer has a lawful purpose. Magic may retain a minimal suppression record to respect an opt-out. |
| Website analytics and advertising data | For the period needed to understand Site use, diagnose issues, measure website and campaign performance, attribute conversions, and maintain consent or opt-out records, subject to Magic’s settings, provider controls, legal requirements, and the purposes described in this Policy. Cookie- and technology-specific durations are described in the Cookie Policy. |
| Customer and service data | According to the customer contract, product-specific notice, documented instructions, deletion requirements, legal obligations, and backup or disaster-recovery cycles. |
| Recruitment and consultant records | For the recruitment or engagement process, any permitted talent-pool period, the working relationship, and a further period needed for legal, tax, compliance, audit, or claims purposes. |
| Security and technical logs | For a period proportionate to operational, diagnostic, fraud-prevention, and security needs, subject to legal and contractual requirements. |
| Corporate and legal records | For the period required by applicable corporate, tax, accounting, audit, insurance, regulatory, and limitation rules. |
When Personal Data is no longer required, Magic deletes it, anonymizes or de-identifies it, or securely isolates it until deletion is possible. Residual copies may remain temporarily in backups or archives and will be protected from ordinary use until overwritten or deleted under the applicable schedule.
11. How we protect Personal Data
Magic uses administrative, technical, and physical safeguards designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Measures are selected according to the nature, volume, context, and risk of the processing and may include:
- role-based access controls and least-privilege access;
- authentication controls, including multi-factor authentication where appropriate;
- encryption in transit and at rest where appropriate;
- network, endpoint, cloud, logging, monitoring, vulnerability, and incident-response controls;
- confidentiality duties, training, policies, and access reviews;
- vendor security and privacy due diligence and contractual requirements; and
- business continuity, backup, and recovery procedures.
No website, network, transmission, or storage system can be guaranteed to be completely secure. You are responsible for protecting your credentials and devices and for notifying Magic promptly if you suspect unauthorized access or a security issue.
Magic maintains processes to assess and respond to suspected Personal Data incidents and will notify affected individuals, customers, or authorities when required by law or contract.
12. Marketing, analytics, and website technologies
Magic may send relevant business-to-business information about services, resources, events, and insights to customers, prospects, and professional contacts. Magic may use delivery, open, and click information to measure and improve communications where permitted by law.
You can unsubscribe from marketing at any time by using the unsubscribe link in an email or by contacting Magic. An opt-out will not stop service, security, account, legal, or other non-marketing communications that Magic needs to send.
Website analytics and tracking technologies. Magic uses cookies, pixels, tags, scripts, session-replay technologies, and similar technologies on the Site to understand how visitors use the Site, improve content and usability, diagnose technical issues, measure website, search, and campaign performance, attribute inquiries and conversions, and support advertising measurement and audience-related activities where permitted.
Depending on the technology and configuration, the information collected may include IP address, approximate location derived from IP address, browser and device information, cookie or other online identifiers, referring source, search and campaign parameters, pages viewed, links or buttons selected, scrolling and navigation behavior, session-replay and heatmap information, form-interaction and submission events, and advertising conversion events.
- The Site currently uses or integrates the following services, depending on the page and consent configuration:
- Google services, including Google Analytics 4, Google Tag Manager, Google reCAPTCHA, Google Ads and DoubleClick technologies, and YouTube embedded content;
- Microsoft services, including Microsoft Clarity, Microsoft Advertising, and Bing technologies;
- HubSpot for website analytics, forms, customer relationship management, and marketing automation;
- Cloudflare for website security and bot management, and CookieYes for cookie-consent and preference management;
- LinkedIn and Meta technologies for social features, campaign measurement, attribution, and, where configured, audience creation or retargeting; and
- Factors.ai, ZoomInfo, WordPress and related plugins, Posts View Counter, and Google Search Console for website functionality, engagement analysis, business-visitor insights, content-view measurement, and search-performance reporting.
These providers may receive online identifiers, device and usage data, and campaign or conversion information. Depending on the service, contractual arrangement, and applicable law, a provider may process Personal Data on Magic’s behalf or for its own purposes under its privacy terms.
Magic uses non-essential functional, analytics, performance, and advertisement technologies only where permitted by law and, where required, after obtaining consent. You can manage available choices through the Site’s cookie or privacy controls. The separate Cookie Policy lists the current cookie names or patterns, assigned categories, providers, purposes, and additional controls, and should be kept aligned with the live Cookie Settings panel.
13. Your privacy rights
Depending on where you live and the law that applies, you may have some or all of the following rights. These rights can be subject to conditions, exceptions, and identity verification.
| Right | What it may allow you to do |
| Access or know | Ask whether Magic processes your Personal Data and request access to it and related information. |
| Correction | Ask Magic to correct inaccurate or incomplete Personal Data. |
| Deletion or erasure | Ask Magic to delete Personal Data when the applicable legal conditions are met. |
| Restriction | Ask Magic to restrict certain processing in circumstances provided by law. |
| Portability | Receive certain Personal Data in a structured, commonly used, machine-readable format and, where feasible, have it transmitted to another organization. |
| Object | Object to processing based on legitimate interests and object at any time to direct marketing. |
| Withdraw consent | Withdraw consent at any time for future processing that relies on consent. Withdrawal does not affect processing already carried out lawfully. |
| Automated decisions | Request safeguards available under applicable law for certain decisions based solely on automated processing, including profiling. |
| Complaint | Raise a complaint with Magic and, where applicable, with a competent privacy or data-protection authority. |
Additional regional rights
EEA, United Kingdom, and certain other jurisdictions. Rights may include access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and safeguards relating to solely automated decisions. You may also complain to the data-protection authority where you live, work, or believe an infringement occurred.
India. Where applicable, rights may include obtaining information about processing, correction, completion, updating or erasure, grievance redressal, and nomination of another person to exercise rights in circumstances recognized by law.
California and certain other U.S. states. Where applicable, rights may include knowing or accessing Personal Data, correction, deletion, portability, opting out of sale, sharing, or targeted advertising, limiting certain uses of sensitive Personal Data, appealing a denied request, using an authorized agent, and receiving equal service and pricing when exercising a privacy right. Magic will not discriminate against you for exercising an applicable right.
Website technology and targeted advertising choices. Where available, you can use the Site’s cookie or privacy settings to accept, reject, or change choices for non-essential functional, analytics, performance, and advertisement technologies. Where applicable law provides a right to opt out of sale, sharing, or targeted advertising, you may exercise that right through our Do Not Sell or Share My Personal Information page, the Site’s privacy controls, a recognised opt-out preference signal, or by contacting Magic using the details in Section 18.
How to make a request
Email mail@magicedtech.com or write to Magic using the details in Section 18. Describe the right you want to exercise and provide enough information to identify the relevant records and your relationship with Magic. Magic may ask for reasonable information to verify your identity and authority. An authorized agent may be required to provide proof of authorization.
Magic will respond within the time required by applicable law and will explain any extension, denial, or available appeal process. Magic generally does not charge a fee, but may do so where a law permits a fee for requests that are manifestly unfounded, excessive, or repetitive.
For Personal Data controlled by a Magic customer, contact that customer first. Magic will support the customer’s response as required. Magic may need to preserve some information despite a request, for example to meet legal obligations, protect security, maintain an opt-out record, complete a requested transaction, or establish or defend claims.
For access, correction, deletion, portability, or similar requests, Magic may ask for reasonable information to verify your identity and authority. For a request to opt out of sale, sharing, or targeted advertising, Magic will not require full identity verification and will request only the information reasonably necessary to identify and apply the request. An authorised agent may be required to provide proof of authorisation.
What happens if you submit an opt-out request
Where applicable law gives you the right to opt out of the sale or sharing of Personal Data or its use for targeted advertising, you may submit a request through our Do Not Sell or Share My Personal Information form or through another privacy control we make available.
After we receive your request, Magic will:
- acknowledge receipt of the request using the contact information you provide, where appropriate;
- use the information submitted through the form only to identify the relevant records, browser, device, or profile, process the request, and maintain an appropriate record of our response;
- not require you to create an account to submit the request;
- ask only for information reasonably necessary to apply the request. An opt-out request generally does not require full identity verification, although we may need limited information to identify the Personal Data, browser, device, or profile covered by the request;
- stop future sale or sharing of the applicable Personal Data and, where required by law, its use for targeted or cross-context behavioural advertising, as soon as reasonably feasible and within the period required by applicable law. Where California law applies, we will process the request no later than 15 business days after receiving it;
- apply the request to the browser or device from which it is submitted and, where we can reasonably associate the request with you, to other relevant records or profiles;
- notify relevant third parties of the request and direct them to comply where required by applicable law;
- retain a limited record of the request so that we can continue to honour your choice and demonstrate compliance; and
- confirm when the request has been processed. If we cannot comply with all or part of a request, we will explain the reason and provide information about any review or appeal rights available under applicable law.
A request submitted through the form may not automatically apply to another browser or device that Magic cannot reasonably associate with you. You may therefore need to submit a request from each browser or device or use a legally recognised opt-out preference signal, such as Global Privacy Control. Where required by law, Magic will treat a valid opt-out preference signal as a request to opt out for the relevant browser or device and any associated profile we can identify.
You may use an authorised agent to submit an opt-out request on your behalf. We may ask the agent to provide written evidence that you have authorised them to act for you.
Magic will not discriminate against you for exercising an applicable privacy right. If you later choose to opt back in, you may change your preference through the privacy controls we make available. Where California law applies, Magic will not ask you to opt back in for at least 12 months after your opt-out request.
14. Children and learner privacy
The general Magic EdTech Site is intended for business users and job applicants and is not directed to children. Children should not submit Personal Data through the Site’s general inquiry, marketing, resource, or careers channels without appropriate adult involvement and a lawful basis.
Some Magic products and services support education and may process learner data, including data relating to minors. In those contexts, Magic generally processes the data on behalf of a school, district, publisher, university, employer, or other customer under the customer’s instructions, contract, and applicable education and children’s privacy laws. A product-specific notice may explain additional practices and safeguards.
Parents, guardians, and learners seeking access, correction, deletion, or other rights for customer-controlled learner data should contact the relevant school, district, publisher, institution, or customer first. If Magic learns that Personal Data was collected directly from a child through a channel not intended for children and without the authorization required by law, Magic will take appropriate steps to delete or otherwise address it.
15. Third-party websites and services
The Site and Magic services may contain links, social-media features, embedded content, or integrations provided by other organizations. Those organizations may collect information directly from you and apply their own privacy terms. Magic does not control and is not responsible for the privacy practices, security, or content of third-party services. Review their notices before providing Personal Data or enabling an integration.
16. Privacy complaints
Magic aims to resolve privacy questions and complaints fairly and promptly. Send a complaint to mail@magicedtech.com with enough detail for Magic to understand the issue. Magic will acknowledge, investigate, keep you informed as appropriate, and communicate the outcome in accordance with applicable law.
You may also have the right to complain to a competent regulator, including the Information Commissioner’s Office in the United Kingdom, an EU or EEA data-protection authority, the relevant authority in India, or a competent U.S. state regulator, depending on the law that applies. Magic encourages you to contact the Privacy Team first, but doing so does not limit your right to approach a regulator.
17. Changes to this Policy
Magic may update this Policy to reflect changes in services, technology, law, or data practices. The revised Policy will be posted on the Site with an updated date. Where a change materially affects how Magic uses Personal Data, Magic will provide any additional notice or choice required by law or contract.
18. Contact Magic EdTech
For questions, rights requests, or complaints about this Policy or Magic’s handling of Personal Data, contact the Privacy Team. For the Site and general business-contact processing, the responsible entity is generally Magic Software Inc., unless another Magic entity is identified at collection or in your contract.
| Contact point | Details |
| Privacy and data-protection inquiries | mail@magicedtech.com |
| General enquiries | marketing@magicedtech.com |
| United States office | Paramount Building, 1501 Broadway, 28th Floor, New York, NY 10036, USA |
| India office | 3rd & 4th Floor, Tower B, Smartworks Corporate Park, Sector 125, Noida 201303, India |
| United Kingdom office | Epworth House, 25 City Road, London, Greater London EC1Y 1AA, United Kingdom |