Back to Home
EU Regulation 2016/679 (GDPR)

Personal Data Processing & Privacy Policy

Last updated: September 2026 • Valid for all European Union visitors and users

11. Data Controller

The Data Controller for data collected through the Magic Page platform (https://magic.inxa.one) is:

INXA ONE Tech Network / Magic Page Team

Privacy & DPO Contact Email: [email protected]

Geographical Scope: European Union & European Economic Area (EEA)

22. Types of Data Collected and Purposes

We only process data strictly necessary to provide platform functionality:

  • Authentication Data (Authors): XCircle cryptographic tokens (.json) and unique identifier. We do not store plain-text passwords.
  • Profile & Publication Data: Display name, biography, avatar image, banner, and published article content.
  • Navigation & Geolocation Data: Visitors IP address used solely to determine country language for instant AI translation (not stored permanently).
  • Magazine Newsletter: Email address voluntarily provided by readers to receive new article notifications.
  • Payments & Subscriptions (Stripe): Entirely processed by Stripe Payments Europe Ltd. No credit card data resides on our servers.

33. Legal Bases for Processing (Art. 6 GDPR)

Data processing is grounded on the following legal bases:

Contract Performance

Publishing service delivery, personal magazine profile management, and subscriber paywall access.

Explicit Consent

Voluntary magazine newsletter subscription, revocable with 1 click at any time.

Legitimate Interest & Security

Anti-bot protection with Cloudflare Turnstile, abuse prevention, and infrastructure safety.

Legal Obligations

Retention of accounting and tax records related to Stripe subscription platform fees.

44. Data Processing with Artificial Intelligence

Magic Page integrates advanced neural models (DeepSeek AI and Google Gemini) for real-time multilingual translation:

• No Personal Data Sent to AI: Only the public article text is sent to the translation neural engines.

• No Training on User Content: Service agreements with AI providers strictly prohibit training models on user data.

• Encrypted Neural Cache: Generated translations are stored in the internal database to eliminate latency and redundant calls.

55. Sub-processors (Third Parties)

We partner with industry-leading, certified infrastructure providers:

Cloudflare Inc.

DDoS mitigation, global CDN, and Turnstile anti-bot verification (Data Privacy Framework).

Stripe Payments Europe Ltd.

Payment processing, paywall, and creator subscriptions (Ireland, EU).

DeepSeek AI & Google Cloud

Neural multilingual translation engines (SCC / DPA).

66. Data Subject Rights (Arts. 15-22 GDPR)

As an EU resident, you have the right at any time to:

Access & Portability (Arts. 15, 20)

Download all your personal data, publications, and settings in open JSON format from your Dashboard.

Erasure / Right to be Forgotten (Art. 17)

Permanently delete your account, published articles, and all associated data with 1 click.

Rectification (Art. 16)

Modify and update your profile details and publications independently from your Dashboard.

Objection & Revocation (Art. 21)

Unsubscribe from newsletters in 1 click or cancel Stripe subscriptions at any moment.

Need to exercise your privacy rights or get support?You can manage your data directly from your Dashboard or write to [email protected].

7. Right to Lodge a Complaint with a Supervisory Authority

You have the right to lodge a complaint with the competent Data Protection Authority in the EU Member State where you reside or work.