This Privacy Policy explains how Magmabajt DOOEL ("StaffMargin", "we", "us"), a limited company registered in North Macedonia under company number7399375 at Ul. Pando Kljashev br. 66 - 003V, handles personal data. For data you upload about your own employees and contacts, you are the controller and we act as your processor. For account and usage data described below, we are the controller.
1. Data we collect
Account data
Name, work email, organisation details and authentication data you provide when you create and manage an account.
Customer Data you upload
To produce margin reports you upload business data that can include employees' names, salary and cost figures, and client, project and partner details ("Customer Data"). We process this only to provide the Service on your instructions. You are responsible for having a lawful basis to share this personal data with us.
Usage data
Basic technical and usage information needed to run and secure the Service, such as log data and feature usage.
2. Payments
Payments are processed by Paddle.com as Merchant of Record. Paddle collects the billing and payment information needed to complete your purchase and is the controller of that payment data. We do not receive or store full card details. SeePaddle's Privacy Policy.
3. Analytics and cookies
We use Umami, a privacy-friendly, self-hosted analytics tool, to understand aggregate site usage. It does not use cookies, does not track you across other sites and does not collect personal data that identifies you. Because of this our marketing site does not need a cookie-consent banner. The application uses only the cookies strictly necessary to keep you signed in.
4. How we use data and our legal bases
- To provide and operate the Service, on the basis of performing our contract with you.
- To secure the Service and prevent abuse, on the basis of our legitimate interests.
- To process your payment, which Paddle carries out to perform your purchase.
- To meet legal, tax and accounting obligations.
We do not sell personal data and we do not use Customer Data to train models.
5. Sub-processors
We rely on a small set of providers to run the Service, including Paddle for payments, our cloud hosting provider for infrastructure, and Umami for self-hosted analytics. We require them to protect data consistent with this policy. A current list is available on request.
6. Security
Each customer's data is logically isolated so one tenant cannot read another's data, access is restricted, and data is encrypted in transit. No system is perfectly secure, but we take reasonable measures appropriate to the sensitivity of the data.
7. Retention
We keep account and Customer Data for as long as your account is active. After your account closes we delete or anonymise Customer Data within a reasonable period, except where we must keep records to meet legal or accounting obligations.
8. Your rights
Depending on where you live, you may have the right to access, correct, delete, port or restrict your personal data, and to object to certain processing. To exercise these rights, or if you are an employee whose data a customer uploaded, contact us atprivacy@staffmargin.com. Where the data was uploaded by a customer, we will direct the request to that customer as the controller. You can also complain to your local data protection authority.
9. International transfers
We may process data in countries other than your own. Where we do, we use appropriate safeguards such as standard contractual clauses to protect it.
10. Children
The Service is for businesses and is not directed to anyone under 18.
11. Changes
We may update this policy. If a change is material we will give reasonable notice. The "Last updated" date above shows the current version.
12. Contact
Privacy and data requests: privacy@staffmargin.com. General support: hello@staffmargin.com.