Last updated 25 August 2026
Your privacy is important to us. This policy explains how Magnusson Analytica collects, uses, and protects your personal information. Each section starts with a short summary in plain language. If you want the full detail, open the section underneath it.
Magnusson Analytica is the trading name of MAGNUSSON ANALYTICA LTD. We decide how and why your personal information is used on this website, which makes us the data controller for it. You can reach us about anything in this policy at contact@magnussonanalytica.com.
The data controller for personal information collected through this website is:
We operate from Sibiu, Romania, with an office in London, UK. Our typical delivery coverage includes Romania, UK, and wider Europe. Because we are established in both the UK and the EU, this policy is written to meet both UK GDPR and EU GDPR.
We have not appointed a Data Protection Officer, as we are not required to under Article 37. Data protection queries go to the address above and are handled by the founder.
If you email us, book a call, or apply for a role, we collect what you send us: your name, contact details, and your message. If you allow analytics cookies, we also collect information about how you use this site. We do not ask for special category data and you should not send it to us.
We collect three kinds of information:
We do not knowingly collect special category data (health, ethnicity, political opinions, and similar) and we ask that you do not include it in a form message. We do not collect information from children, as this site is aimed at business audiences.
We use your information to answer your enquiry, to consider your job application, to improve the site, and to keep it secure. The law requires us to have a specific basis for each of those. Where we rely on your consent, you can withdraw it at any time.
Under Article 6 of the UK and EU GDPR we must have a lawful basis for each purpose. Ours are:
| Purpose | Legal basis | Notes |
|---|---|---|
| Responding to an enquiry you send us, or a consultation you book | Article 6(1)(b) — steps at your request before entering a contract | Where an enquiry is not about engaging us, we rely instead on legitimate interests (Article 6(1)(f)): our interest in answering people who contact us. |
| Considering a careers application | Article 6(1)(b) — steps at your request before entering a contract | Keeping an unsuccessful application on file beyond the role applied for is done only with your consent. |
| Sending marketing and promotional communications | Article 6(1)(a) — your consent | You can withdraw consent at any time, by using the unsubscribe link or by emailing us. Withdrawing does not affect anything we did before you withdrew. |
| Contacting an existing or former client about services similar to those we have already delivered | Article 6(1)(f) — legitimate interests | The interest relied on is direct marketing of our own similar services to an existing business relationship. Where we rely on this, you have an absolute right to object under Article 21(2). If you object, we must stop, with no balancing test and no exceptions. |
| Understanding how the site is used, in order to improve it | Article 6(1)(a) — your consent | Given through the Analytics category in our cookie banner, and withdrawable at any time from Privacy Preferences in the footer. |
| Attributing an enquiry to the campaign or referrer it came from | Article 6(1)(a) — your consent | Given through the Marketing category in our cookie banner. |
| Keeping the site secure and available | Article 6(1)(f) — legitimate interests | The interest relied on is protecting our site from abuse and keeping it running. We consider this to have a minimal privacy impact. |
| Controlling access to password-protected client pages | Article 6(1)(f) — legitimate interests | The interest relied on is keeping client-confidential material restricted to the people entitled to see it. |
Separately from GDPR, storing or reading cookies on your device requires your consent under the ePrivacy rules, unless the cookie is strictly necessary to provide the service you asked for. That is why analytics and marketing cookies stay off until you turn them on.
Strictly necessary cookies keep the site working and cannot be turned off. Analytics and marketing cookies are off until you actively accept them, and you can change your mind at any time from Privacy Preferences in the footer. The full list of what we set is below.
Under the General Data Protection Regulation (GDPR), organisations are required to obtain valid consent from individuals for the processing of their personal data. Consent must be freely given, specific, informed, and unambiguous.
When you first visit, we ask which categories of cookies you allow. Nothing in the Analytics or Marketing categories is set before you accept it, and no box is pre-ticked. Rejecting is a single click, in the same place and at the same size as accepting. That is how we meet each part of the standard above: the choice is free because refusing costs you nothing, specific because each category is decided separately, informed because the table below lists every cookie before you decide, and unambiguous because nothing is set until you take a clear affirmative action.
to see or change your current choices.
These are the cookies and local storage entries this site can set:
| Name | Provider | Category | Purpose | Duration | Type |
|---|---|---|---|---|---|
ma_cookie_consent | Magnusson Analytica (first party) | necessary | Stores which cookie categories you accepted, and when, so we do not ask again and can evidence your choice. | 12 months | Cookie |
ma_consent_log | Magnusson Analytica (first party) | necessary | A local record of your recent cookie choices with timestamps. Never leaves your browser. | Until you clear site data | Local storage |
srf_session, raiffeisen_session | Magnusson Analytica (first party) | necessary | Keeps you signed in to a password-protected client page after you enter its access code. Only set if you use one of those pages. | 12 hours | Cookie (HttpOnly) |
AMP_* | Amplitude | analytics | Identifies your browser and current session so page views and clicks can be grouped into a single visit. Contains a randomly generated device ID, not your name. | 12 months | Cookie |
AMP_SR_START_* | Amplitude (session replay) | analytics | Marks when session recording began, so a recording is not double-counted across page navigations. | 24 hours | Local storage |
AMP_MKTG_* | Amplitude | marketing | Stores the campaign parameters and referring site you arrived from, so we can attribute an enquiry to the channel that produced it. | 12 months | Cookie |
We do not run advertising pixels, we do not use a tag manager, and we do not sell or share your information with advertising networks.
We do not sell your information. We do share it with a small number of suppliers who run parts of this site for us: our analytics tool, our booking calendar, and our host. Each acts on our instructions under a contract.
We share personal information with the following categories of recipient, all of whom act as our processors under Article 28 contracts:
Typefaces are served from our own domain rather than from a font network, so displaying this site does not disclose your IP address to a third party.
We may also disclose information to professional advisers, or to a public authority where we are legally required to. We do not sell personal information, and we do not share it for anyone else’s marketing.
Some of our suppliers are based in the United States, so your information leaves the UK and EU when we use them. Where that happens, we rely on the safeguards the law requires for international transfers.
The following processing involves a transfer outside the UK and EEA:
For these transfers we rely on the European Commission’s Standard Contractual Clauses, together with the UK International Data Transfer Addendum for transfers from the UK, and on the EU–US Data Privacy Framework where the supplier is certified under it. You can request a copy of the safeguards in place by emailing contact@magnussonanalytica.com.
We keep enquiry and application data for 24 months after we last hear from you, then delete it. If you become a client, we keep the records for as long as we work together plus the period accounting law requires. Analytics data expires on its own.
| Data | Retention period |
|---|---|
| Contact form enquiries, and the email thread that follows | 24 months after our last contact with you, unless a client relationship begins. |
| Records relating to a client engagement | For the duration of the engagement, then for 6 years to meet UK statutory accounting and limitation periods. |
| Careers applications from unsuccessful candidates | 24 months after the outcome is communicated, so we can consider you for similar roles. Tell us and we will delete it sooner. |
| Marketing contact details | Until you withdraw consent or object, then removed from the sending list and retained only as a suppression record so we do not contact you again. |
| Analytics data and session recordings | Per our analytics provider’s retention settings. The related cookies expire after 12 months. |
| Your cookie consent record | 12 months, after which we ask you again. |
| Server and security logs | As retained by our hosting provider, typically no more than 30 days. |
You can ask to see your information, correct it, delete it, restrict or object to how we use it, or receive a copy to take elsewhere. Where we rely on consent, you can withdraw it at any time. Email contact@magnussonanalytica.com and we will respond within one month.
You have the following rights over your personal information:
To exercise any of these, email contact@magnussonanalytica.com. We will respond within one month. If a request is complex we may extend that by up to two further months, and we will tell you if so. There is no charge unless a request is manifestly unfounded or excessive. We may need to verify your identity before acting.
If you think we have handled your information badly, please tell us first so we can put it right. You also have the right to complain to a data protection regulator, and you can do that without coming to us first.
Please contact us at contact@magnussonanalytica.com in the first instance.
You also have the right to lodge a complaint with the supervisory authority in the country where you live or work, or where you think the problem occurred. Given where we operate, the two most likely to be relevant are:
If you are in another EU member state, you may complain to your own national supervisory authority instead.
We apply a risk-aware operating model designed to protect personal information and client analytics environments. This section describes how we work day to day; it is not a substitute for the rights described above.
This page describes our general privacy and security posture and does not replace client-specific contractual terms.
For any privacy, security, or compliance question about this policy, contact us at contact@magnussonanalytica.com, or write to MAGNUSSON ANALYTICA LTD, Charlton House 1 Rosemead, 9 Coopers Lane, Verwood, Dorset, BH31 7AZ, United Kingdom.
If we change this policy substantively, we will update the “last updated” date at the top of the page. Where a change affects what you have consented to, we will ask for your consent again.