Privacy Policy
Last updated: 7/28/2026
This Privacy Policy explains how Fokisen Technology LLC ("Fokisen," "we," "us," or "our"), operator of the Magna247 platform ("Service"), collects, uses, discloses, and safeguards information. It applies to visitors to our websites, business customers who subscribe to Magna247 ("Customers"), authorized users within a Customer workspace ("Users"), and individuals whom our Customers contact through the Service ("End Contacts").
1. About Magna247
Magna247 is a business-to-business software-as-a-service platform that provides customer relationship management (CRM), outbound and inbound calling and SMS, email and newsletter delivery, workforce and sales operations tooling, and an AI assistant ("Maggie"). Our Customers are businesses that use Magna247 to communicate with their own leads, prospects, and customers. When we process End Contact data on behalf of a Customer, we act as a processor (or "service provider" under CCPA); the Customer is the controller (or "business") and is responsible for the lawful basis of that processing, including obtaining any required consents.
2. Information We Collect
2.1 From Customers and Users
- Account information: name, work email, hashed password, workspace name, role, phone number, profile settings, and communication preferences.
- Billing information: plan tier, subscription status, invoices, and usage counters. Payment card details are collected and stored by our payment processor (Stripe); we receive only tokens and metadata.
- Content you upload: CRM records, notes, files, templates, newsletter content, website builder content, sequences, and integration credentials (encrypted at rest where applicable).
- Usage and device data: log data, IP address, browser and device identifiers, feature interactions, timestamps, and error diagnostics.
- Communications with us: support requests, feedback, and survey responses.
2.2 About End Contacts (processed on behalf of Customers)
- Identifiers and contact details that Customers or their Users add, import, or capture through Magna247 forms, landing pages, or integrations (e.g., name, phone, email, address, company, job title).
- Communication records: call metadata, call recordings and transcripts (where enabled by the Customer), SMS and email content and delivery status, and engagement events (opens, clicks, replies).
- Consent and suppression signals: do-not-call, do-not-text, and email suppression status; STOP/START keyword events; unsubscribe events; and audit records of blocked outbound attempts.
3. How We Use Information
- Provide, operate, secure, and improve the Service.
- Authenticate Users, enforce access controls, and prevent abuse and fraud.
- Process payments and manage subscriptions and usage-based billing.
- Deliver support and send service, security, and administrative notices.
- Operate the Maggie AI assistant, which processes prompts and workspace data to generate responses. Prompts and outputs sent to our AI providers are not used by us to train third-party foundation models, and we contractually require the same of those providers where the option is available.
- Comply with legal obligations, respond to lawful requests, and enforce our Terms.
- With aggregated or de-identified data, analyze product performance and publish non-identifying statistics.
We do not sell personal information, and we do not "share" it for cross-context behavioral advertising as defined by the CCPA.
4. Subprocessors and Data Sharing
We share data with a limited set of vetted subprocessors that help us operate the Service, under written agreements requiring appropriate confidentiality and security safeguards. Our current subprocessors include:
- Supabase — managed Postgres database, authentication, storage, and serverless functions (hosting of Customer content and account data).
- Cloudflare — application hosting (Workers), CDN, DNS, DDoS protection, and Turnstile CAPTCHA on public forms.
- Twilio — voice calling, SMS delivery, and phone number provisioning (including isolated Customer subaccounts).
- OpenAI — powers the Maggie AI assistant (chat, voice, and realtime modes) and select AI-assisted features.
- Resend and Customer-configured SMTP providers — transactional email and newsletter delivery. Customers who connect their own SMTP mailbox route mail through their chosen provider.
- Stripe — payment processing, subscription management, and card storage.
- Openverse — proxied stock photo search within the website and newsletter builders (queries only; no account data shared).
- Meta, LinkedIn, and Google — only when a Customer explicitly connects the corresponding social account via OAuth for publishing or analytics.
We may also disclose information (i) to comply with law, legal process, or lawful requests from public authorities; (ii) to protect the rights, property, or safety of Fokisen, our Customers, or the public; or (iii) in connection with a merger, acquisition, financing, or sale of assets, in which case we will take reasonable steps to ensure your information continues to be protected. An up-to-date list of subprocessors is available on request to privacy@magna247.com.
5. Cookies, Analytics, and Tracking
We use strictly necessary cookies for authentication, session management, security (CSRF protection), and remembering workspace preferences. We operate a first-party analytics proxy ("Flock") that records aggregated, privacy-respecting usage events (such as page views and feature interactions) to help us improve the Service. Analytics events are not used for cross-site advertising, and we do not embed third-party advertising trackers on the authenticated application. Customer-built marketing pages served through the website builder may include tracking that the Customer configures; those are the Customer's responsibility.
6. Data Retention
We retain account, workspace, and content data for as long as the Customer's account is active and as needed to provide the Service. On cancellation, active workspace content is deleted or de-identified within thirty (30) days, subject to (i) reasonable operational backups, which are overwritten in the ordinary course, and (ii) records we are required to retain to comply with legal, tax, accounting, dispute-resolution, or fraud-prevention obligations. Suppression records (do-not-call, do-not-text, unsubscribe) are retained indefinitely as required by TCPA and CAN-SPAM. Customers may delete individual records from their workspace at any time.
7. Your Rights
Depending on where you live, you may have the right to: (i) access the personal information we hold about you; (ii) request correction of inaccurate data; (iii) request deletion; (iv) request a portable copy; (v) restrict or object to certain processing; and (vi) withdraw consent where processing is based on consent. Users can access, correct, or delete most of their information directly within workspace settings.
If you are an End Contact (someone contacted through Magna247 by one of our Customers), please direct rights requests to the Customer who contacted you; they control your data. We will assist that Customer in responding.
To exercise a right, email privacy@magna247.com. We will verify your identity before responding and will reply within the time frame required by applicable law.
8. California Residents (CCPA/CPRA)
In addition to the rights above, California residents have the right to (a) know what categories and specific pieces of personal information we have collected, the sources, the business purposes, and the categories of third parties with whom we share it; (b) request deletion; (c) request correction; (d) limit the use of sensitive personal information; and (e) not be discriminated against for exercising these rights. We do not sell personal information and do not share it for cross-context behavioral advertising. You may designate an authorized agent to submit requests on your behalf; we will require proof of authorization. Contact privacy@magna247.com.
9. International Transfers
We are based in the United States, and personal data is primarily processed in the U.S. Where required, we rely on Standard Contractual Clauses or other lawful transfer mechanisms with our subprocessors.
10. Security
We use encryption in transit (TLS), encryption at rest for sensitive credentials (AES-256-GCM), row-level security on our multi-tenant database, isolated Twilio subaccounts per Customer, secret management for API keys, and role-based access controls. No system is perfectly secure. Report suspected vulnerabilities to security@magna247.com.
11. Children
Magna247 is a business tool and is not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided data, contact us and we will delete it.
12. Changes to This Policy
We may update this Policy from time to time. Material changes will be communicated by email to account owners or via prominent in-app notice, with an updated "Last updated" date.
13. Contact Us
Fokisen Technology LLC
[ADDRESS ON FILE — contact legal@magna247.com]
Privacy: privacy@magna247.com
Security: security@magna247.com
Legal: legal@magna247.com
