according to Art. 28 GDPR · Version 2 · 7 September 2026
This Data Processing Agreement (“DPA”) is an addendum to the Terms of Service (“Agreement”) between Magic Pages e.U. (FN 674823m, Landesgericht Wels), represented by Jannis Fedoruk-Betschki (“Service Provider”, Data Processor) and the Customer (“Customer”, Data Controller), which incorporates by reference the Privacy Policy of Magic Pages (collectively, the “Agreement”). This DPA governs the processing of personal data under the Agreement.
1. Subject Matter of the Agreement
The subject of this DPA is the provision of Ghost CMS hosting services by the Service Provider to the Customer, which includes, but is not limited to, hosting and providing an internet site based on the open-source Content Management System “Ghost” (https://ghost.org), including the dispatch of newsletters.
This DPA supplements the general terms and conditions available at https://www.magicpages.co/legal/terms/.
2. Definitions
– “Personal Data” refers to any data relating to an identified or identifiable natural person processed on behalf of the Customer in the course of providing the Services.
– “Controller” means the entity which determines the purposes and means of the processing of Personal Data.
– “Processor” means the entity which processes Personal Data on behalf of the Controller.
– “Sub-processor” means any Processor engaged by the Service Provider to assist in fulfilling its obligations with respect to providing the Services under this DPA.
– “Data Protection Laws” means all applicable laws and regulations in relation to data protection and privacy that apply to the respective parties.
– “Security Incident” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Personal Data processed under this DPA.
3. Duration of the Agreement
This DPA is entered into for an indefinite duration and remains in force for as long as the Service Provider processes Personal Data on behalf of the Customer. It may be terminated by either party at the end of a given billing period. The right to terminate for cause remains unaffected.
Sections 10 (Deletion and Return of Personal Data) and 11.1 (Liability) survive termination of this DPA.
4. Roles and Responsibilities of the Parties
As between the Customer and Service Provider, the Customer is the Controller of Personal Data and the Service Provider is the Processor.
The Service Provider shall process Personal Data only on documented instructions from the Customer, including with regard to transfers of Personal Data to a third country, unless required to act without such instructions by Union or Member State law to which the Service Provider is subject. In such a case, the Service Provider shall inform the Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest.
The Agreement, this DPA, and the Customer’s use of the Services in accordance with the Agreement constitute the Customer’s complete and final documented instructions to the Service Provider.
The Service Provider shall immediately inform the Customer if, in its opinion, an instruction infringes the GDPR or other applicable Data Protection Laws.
The Customer is responsible for ensuring that it has a valid legal basis for the processing of Personal Data through the Services, and for the lawfulness of the Personal Data it or its data subjects introduce into the Services.
5. Sub-processors
The Customer grants the Service Provider general written authorisation to engage Sub-processors for the provision of the Services. The Sub-processors engaged at the time of conclusion of this DPA are listed in Annex B.
The Service Provider shall maintain an up-to-date list of Sub-processors at https://www.magicpages.co/legal/sub-processors/.
5.1 Notice of changes. The Service Provider shall notify the Customer by email of any intended addition or replacement of a Sub-processor at least fourteen (14) days before that Sub-processor begins processing Personal Data. Where a Sub-processor must be engaged at shorter notice to maintain the security or continuity of the Services, the Service Provider shall notify the Customer as early as reasonably possible and explain the reason for the shortened period.
5.2 Objection. The Customer may object to an intended change on reasonable data protection grounds by written notice to help@magicpages.co within fourteen (14) days of receiving the notice under Section 5.1.
5.3 Consequence of objection. Where the Customer objects, the parties shall discuss the objection in good faith. If the Service Provider is unable to provide the Services without the Sub-processor concerned, or cannot offer the Customer a commercially reasonable alternative, the Customer may terminate this DPA and the affected Services with effect from the date the Sub-processor is engaged, by written notice and without incurring termination fees. Fees paid in advance for the period after the effective date of such termination shall be refunded on a pro rata basis.
5.4 Obligations of Sub-processors. The Service Provider shall impose on each Sub-processor, by way of contract, data protection obligations that are no less protective than those set out in this DPA. The Service Provider remains fully liable to the Customer for the performance of each Sub-processor’s obligations.
6. International Data Transfers
Primary storage and processing of Personal Data takes place on servers located within the European Union.
Where the provision of the Services involves the transfer of Personal Data to a country outside the EU/EEA that is not the subject of an adequacy decision by the European Commission, the Service Provider shall ensure that such transfer is subject to appropriate safeguards under Chapter V GDPR. This is achieved through one or more of the following mechanisms, as applicable to the Sub-processor concerned:
– an adequacy decision by the European Commission;
– the Standard Contractual Clauses adopted by the European Commission under Implementing Decision (EU) 2021/914, as incorporated into the Service Provider’s agreement with the relevant Sub-processor; or
– another valid transfer mechanism under Chapter V GDPR.
The transfer mechanism applicable to each Sub-processor is identified in Annex B. On request, the Service Provider shall provide the Customer with information about the safeguards in place.
7. Security
7.1 Security Measures. Considering the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing as well as the risk to the rights and freedoms of natural persons, the Service Provider shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk. The measures in place at the time of conclusion of this DPA are described in Annex C.
The Service Provider may update these measures over time, provided that the level of security is not materially reduced.
7.2 Confidentiality of Processing. The Service Provider shall ensure that any person authorised to process Personal Data is under an appropriate obligation of confidentiality, whether contractual or statutory.
7.3 Security Incident Response. Upon becoming aware of a Security Incident, the Service Provider shall notify the Customer without undue delay and in any event within forty-eight (48) hours of becoming aware of it.
7.4 Content of Notification. A notification under Section 7.3 shall, to the extent the information is available to the Service Provider at the time, include:
– a description of the nature of the Security Incident;
– the categories of Personal Data concerned;
– the approximate number of data subjects and records affected;
– the likely consequences of the Security Incident;
– the measures taken or proposed to address the Security Incident and to mitigate its adverse effects; and
– a contact point at the Service Provider from which further information can be obtained.
Where and insofar as this information cannot be provided in full at the same time, it shall be provided in phases without further undue delay. The Service Provider shall continue to provide the Customer with timely information as it becomes known or as reasonably requested by the Customer, so as to enable the Customer to meet its own obligations under Arts. 33 and 34 GDPR.
8. Assistance and Cooperation
8.1 Data Subject Requests. To the extent that the Customer is unable to independently access the relevant Personal Data within the Services, the Service Provider shall provide reasonable cooperation to assist the Customer by appropriate technical and organisational measures, insofar as possible, to respond to any requests from data subjects exercising their rights under Chapter III GDPR.
Where the Service Provider receives a request directly from a data subject relating to Personal Data processed on behalf of the Customer, it shall not respond to the request itself, but shall forward it to the Customer without undue delay.
8.2 Assistance with Arts. 32 to 36 GDPR. Taking into account the nature of the processing and the information available to it, the Service Provider shall provide reasonable assistance to the Customer in ensuring compliance with the Customer’s obligations under Arts. 32 to 36 GDPR, including security of processing, notification of personal data breaches to the supervisory authority and to data subjects, data protection impact assessments, and prior consultation.
8.3 Requests from Authorities. The Service Provider shall notify the Customer without undue delay of any legally binding request for disclosure of Personal Data by a law enforcement or other public authority, unless prohibited from doing so by law. The Service Provider shall not disclose Personal Data to any authority except where required to do so by applicable law.
9. Audits and Evidence of Compliance
9.1 Information. The Service Provider shall make available to the Customer all information necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR and this DPA. It shall do so by providing, on written request:
– the description of technical and organisational measures set out in Annex C, and any updates to it;
– written responses to a reasonable data protection or information security questionnaire, no more than once per calendar year;
– the current list of Sub-processors and information about the transfer safeguards in place; and
– any relevant certification or third-party audit report held by the Service Provider or its Sub-processors.
The parties agree that the provision of this information is the primary means by which the Service Provider demonstrates compliance, and that it satisfies the Customer’s audit rights under Art. 28(3)(h) GDPR in the ordinary course.
9.2 Inspections. The Customer may request an on-site or remote inspection only where (a) a competent supervisory authority requires it, or (b) a Security Incident affecting the Customer’s Personal Data has been confirmed, and in either case the information provided under Section 9.1 is not sufficient to address the matter.
Such an inspection is subject to the following conditions:
– it shall be requested in writing with at least fourteen (14) days’ prior notice and take place during normal business hours;
– it shall be conducted remotely where this is sufficient to achieve its purpose;
– it shall be limited in scope to the processing of the Customer’s Personal Data, and shall not extend to shared infrastructure, systems, or documentation where access would compromise the security or confidentiality of other customers’ data;
– it may be carried out no more than once per calendar year;
– any auditor mandated by the Customer shall not be a competitor of the Service Provider and shall be bound by appropriate confidentiality obligations;
– the Customer shall bear its own costs and the costs of any auditor it mandates, and shall reimburse the Service Provider for time spent supporting the inspection at the Service Provider’s standard rate of EUR 120 per hour.
10. Deletion and Return of Personal Data
10.1 Export during the term. The Customer may at any time export Personal Data held in its Ghost instance using the export functions available within the Services, including the Ghost administration interface, the available APIs, and the backup functionality described in the Agreement. The Service Provider shall provide reasonable assistance on request.
10.2 On termination. Upon termination or expiry of the Agreement, the Customer may, within thirty (30) days, request the return of Personal Data in a structured, commonly used and machine-readable format, or request its deletion. Absent such a request, the Service Provider shall delete Personal Data from the Services in accordance with Section 10.3.
10.3 Deletion. The Service Provider shall delete Personal Data from the active production environment within thirty (30) days of termination or expiry of the Agreement, in accordance with the Terms of Service.
10.4 Backups. Personal Data contained in backup copies is deleted in the ordinary course of the backup rotation cycle and is fully removed no later than three (3) months after deletion from the production environment. Until deletion, such data remains subject to the security measures set out in Annex C and is not processed for any purpose other than restoration and disaster recovery.
10.5 Legal retention. The Service Provider may retain Personal Data to the extent and for as long as required by Union or Member State law, in which case it shall ensure the confidentiality of that data and process it only to the extent necessary for the purpose of the retention obligation.
10.6 Confirmation. The Service Provider shall confirm deletion in writing on request.
11. Miscellaneous
11.1 Liability. Each party shall be liable for damages it causes by processing the Personal Data subject to this DPA. Art. 82 GDPR remains unaffected. The limitations of liability set out in the Agreement apply to this DPA to the extent permitted by applicable law.
11.2 Governing Law. This DPA is governed by the laws of Austria. Any changes to this DPA require the written consent of both parties. This DPA prevails over any conflicting terms of the Agreement.
11.3 Legal Effects. This DPA is intended to supplement the terms of the Agreement. Except as explicitly modified or supplemented by this DPA, the terms of the Agreement remain unchanged and in full force and effect. In the event of any conflict between this DPA and the Agreement, the terms of this DPA will prevail to the extent of the conflict.
11.4 Severability. If any provision of this DPA is held to be invalid or unenforceable, the remaining provisions remain in full force and effect. The invalid provision shall be replaced by a valid provision that most closely reflects the original intent.
11.5 Compliance with GDPR. This DPA is designed to ensure compliance with the strict standards of data protection in the European Union, specifically the GDPR.
Annex A: Details of Data Processing
A.1 Categories of Data Subjects
The Personal Data processed under this DPA may concern the following categories of data subjects:
– Visitors to the Customer’s website
– Newsletter subscribers and registered members of the Customer’s website
A.2 Categories of Personal Data
– Email addresses
– Names (where provided by data subjects)
– IP addresses
– Browser and device metadata (user agent, referrer)
– Newsletter engagement data (open/click tracking)
– Subscription and membership status
– Any additional data the Customer collects through their Ghost instance
No special categories of personal data within the meaning of Art. 9 GDPR are processed under this DPA, unless the Customer introduces such data into its Ghost instance on its own initiative and responsibility.
A.3 Nature and Purpose of Processing
The processing is carried out for the purpose of providing Ghost CMS hosting services, including website hosting, newsletter delivery, and member management.
The nature of the processing comprises hosting, storage, transmission, backup, restoration, and deletion of Personal Data, as well as the technical operations necessary to deliver the Services.
A.4 Duration of Processing
Personal Data is processed for the duration of the Agreement, followed by the deletion and return periods set out in Section 10 of this DPA.
Annex B: Sub-processors
The Customer consents to the use of the following Sub-processors. The Service Provider shall maintain an up-to-date list of Sub-processors at https://www.magicpages.co/legal/sub-processors/ and notify the Customer by email of any intended changes in accordance with Section 5.
| Sub-processor | Purpose | Processing location | Transfer mechanism |
|---|---|---|---|
| Hetzner Online GmbH | Server hosting, data storage | Germany (EU) | Not applicable, EU only |
| Cloudflare, Inc. | CDN, DNS, Web Application Firewall | EU with global edge network | Standard Contractual Clauses, as incorporated in Cloudflare’s Data Processing Addendum |
| Mailgun Technologies, Inc. (Sinch) | Transactional and newsletter email delivery | EU region (message processing and storage in the EU); administrative access from the US possible | Standard Contractual Clauses, as incorporated in Sinch’s Data Processing Agreement |
Annex C: Technical and Organisational Measures
The Service Provider implements the following measures to protect Personal Data:
– Encryption in transit: All data transmitted via TLS/SSL encryption
– Encryption at rest: Server disks use full-disk encryption
– Access control: SSH key-based authentication only; no password access to servers
– Server location: All primary data stored on servers within the European Union
– Backups: Automated daily backups with encrypted storage, retained for three (3) months
– Network security: Cloudflare WAF and DDoS protection for all hosted sites
– Confidentiality: All persons with access to Personal Data are bound by confidentiality obligations
– Monitoring: Automated server and service monitoring with alerting
– Availability: Service availability target as set out in the Service Level Agreement at https://www.magicpages.co/legal/sla/
– Separation: Each Customer’s Ghost instance runs in a separate container with its own database, isolating Customer data from that of other customers
Last updated: 07 September 2026