GDPR at magnetchat
Last updated: August 19, 2026
A lead magnet is a personal data collection machine, so before your team runs one on magnetchat, someone in legal will have questions. This page answers them in the order they usually come. Every claim here is also a clause in the DPA or a line in the privacy policy, so your reviewer can check the primary source instead of taking this page's word for it.
Who is the controller of our leads' data?
You are. This is the load-bearing answer, and it is architectural, not aspirational.
Under GDPR, whoever decides why and how personal data is collected is the controller. That is you. magnetchat is your processor: we run the document, the chat and the capture on your behalf, on your instructions, and report it all back to you.
The product is built around that split. The gate names your company, not ours. Your privacy policy is linked right on it. The data lands in your workspace, and tenant isolation means no other customer can ever read it. Your lead never becomes our lead.
Do we need to sign a DPA?
No. The data processing agreement forms part of the terms of service and takes effect automatically for every customer, from the free first magnet up. There is no enterprise tier where the paperwork starts. If procurement wants a countersigned copy, email privacy@magnetchat.com.
The DPA covers what a reviewer expects it to cover: subject matter and duration, confidentiality and security obligations, breach notification, data subject rights assistance, deletion, audit, and subprocessor change control with 14 days' notice and a right to object.
What is recorded when a lead comes in?
Two paths, both leaving a record.
Inbound — someone finds your magnet and hits the gate: the gate states in your name that their details, reading activity and chat go to you, and links your policy. When they submit, magnetchat records the timestamp and the exact version of the notice they saw. Not a boolean. The version. When someone asks "what did this person actually consent to," there is an answer.
Outbound — you send a known contact a personal link that skips the gate: skipping the form does not mean skipping the notice. On first visit they see who the link identifies them as and that their reading is shared with you, and their acknowledgment is recorded the same way. If the link was forwarded and the reader is not who it says, one click on "Not you?" releases the session so the wrong person's reading never lands on the right person's record.
What personal data does magnetchat process, exactly?
| Data | Why it exists |
|---|---|
| Name, work email, company | The gate capture, or the personal link you created |
| Chat transcript | The reader's questions, answered from your document |
| Reading behavior (pages, time) | The engagement evidence your follow-up runs on |
| Qualification answers | The questions you configured, answered in the chat |
| AI-generated brief | A summary of the above, for your sales team |
That is the inventory. No browsing history, no cross-site profile, no enrichment bought from a data broker. Everything in the table exists because the reader typed it or read it, and all of it is visible to them while it happens: the chat is the interface.
Does the AI train on our leads' data?
No. The DPA makes this contractual: lead data is never used to train models, never sold, and never used for our own marketing. The AI (Google's Gemini) processes each conversation to answer that reader's questions from your document. Server-side processing artifacts at Google expire on Google's retention schedule, at most 55 days, and Google acts as a subprocessor under the same instructions.
What runs in the reading experience?
Nothing. This is the answer that tends to end the meeting.
The reader, the page your lead actually spends time on, loads no analytics, no tag manager, no pixels, no fingerprinting. It sets exactly one cookie: an httpOnly session cookie so a returning reader can resume their conversation. Strictly necessary, which is why there is no cookie banner between your lead and your content. Your lead magnet stays a document with a helpful chat beside it, not a surveillance surface.
(Our own marketing site, the one you are reading now, does use analytics, and loads it only after you consent. The standard we hold your leads' experience to, we hold ours to first.)
How do leads exercise their rights?
Access, correction, deletion, export, objection: a lead emails privacy@magnetchat.com or contacts you directly, and requests are honored within 30 days. You are informed when a deletion request about your lead comes to us directly.
Erasure reaches everything the lead left behind: the contact, every conversation and transcript, every event, and the copies of their details inside webhook payloads already queued to your CRM. Database backups age out within 30 days.
Where does the data live, and what about EU transfers?
Data is hosted in the United States by the subprocessors listed in the privacy policy. For EU/EEA and UK personal data, the EU standard contractual clauses (controller-to-processor module) and the UK addendum are incorporated into the DPA by reference, with you as data exporter. Subprocessor changes come with 14 days' email notice; if you object on reasonable data protection grounds and we can't resolve it, you can terminate with a pro-rata refund.
What happens when we leave?
Delete your account in settings and the erasure is immediate and complete: every lead, conversation, transcript, brief and uploaded document goes with it, subscriptions are canceled, stored files are removed, and backups age out within 30 days. Archiving a single magnet stops new collection while keeping the leads you already captured. There is no export ransom and no retention "for product improvement." Your leads were never ours to keep.
The honest close
Nobody can stamp a product "GDPR certified"; no such certification exists, and a vendor claiming one has told you something useful about their other claims. What a vendor can do is make the controller-processor split real in the architecture, put the DPA one click away, record consent specifically enough to answer questions about it, and keep the reading experience clean enough that there is nothing to disclose.
That is what we built. Your legal team is welcome to verify it: the DPA and privacy policy are public, and privacy@magnetchat.com answers questions from reviewers, not just customers. When they're done, the first magnet is free, and the paperwork is already in effect by the time it's live.