Your data security is our top priority. Magia Menu is built with enterprise-grade security and compliance with international standards.
Magia Menu is responsible for specific security areas, while venues manage their own operations.
We can provide security documentation and compliance evidence upon request.
Click to view detailed documentation for each standard
Full compliance with EU General Data Protection Regulation
View Privacy PolicyClear policies on how long we keep your data
View PolicyPayment data handled by certified Level 1 processor (Iyzico)
VerifiedAll data encrypted in transit with latest protocols
ActiveMagia Menu uses the SAQ-A compliance model to fully outsource payment processing to PCI DSS certified third-party providers.
We work with Iyzico and other regional PCI DSS compliant providers.
Magia Menu acts as a data controller for platform services data processing. We determine how user data should be processed.
When processing order data for venues, we act as a data processor executing the venues instructions.
For business accounts, we provide comprehensive Data Processing Agreements that meet GDPR requirements.
Under GDPR, you have comprehensive rights regarding your data.
Note: SLA times shown are our internal targets. The GDPR statutory maximum is 30 days for all DSAR requests, extendable to 90 days for complex cases.
Request a copy of all data about you
Request correction of incorrect data
Request deletion of your data
Receive your data in machine-readable format
You can submit requests through your profile settings in the app or by emailing magiamenu@gmail.com.
We implement security measures based on OWASP principles and industry best practices.
Note: We are stating that we adopt security practices based on industry-recognized methodologies, not claiming any official certification.
All data is encrypted at rest using AES-256 encryption. Your information is protected even in storage.
All data in transit is protected with the latest TLS 1.3 encryption protocol.
Role-based access control ensures only authorized personnel can access sensitive data.
Automated daily backups with 30-day retention ensure your data is never lost.
Continuous security monitoring and instant alerts for any suspicious activity.
Dedicated security team with documented incident response procedures.
Magia Menu uses a flexible role-based access control (RBAC) system where venues can define custom roles tailored to their needs.
Full access to venue management, staff, settings, reports, and billing
Can browse menus, place orders, and view own order history
Venue owners can create unlimited custom roles with granular permissions. Examples:
All permission changes are logged for security audit.
24 hours
Maximum data loss equals daily backup interval
4 hours
Target time to restore service after disaster
| Type | Schedule | Retention | Encrypted |
|---|---|---|---|
| Daily Backups | 03:00 UTC | 30 days | |
| Weekly Backups | Sundays 04:00 UTC | 12 weeks | |
| Monthly Backups | 1st of month 05:00 UTC | 3 months |
Backup integrity is verified during creation. Full restore testing is performed before major updates.
We never store your payment card details. All payment processing is handled by PCI DSS Level 1 certified provider:
If you have any security concerns or want to report a vulnerability, our security team is here to help.
Contact Security Team