Privacy Policy

Last updated 25 August 2026

Your privacy is important to us. This policy explains how Magnusson Analytica collects, uses, and protects your personal information. Each section starts with a short summary in plain language. If you want the full detail, open the section underneath it.

Who we are

Magnusson Analytica is the trading name of MAGNUSSON ANALYTICA LTD. We decide how and why your personal information is used on this website, which makes us the data controller for it. You can reach us about anything in this policy at contact@magnussonanalytica.com.

Read the full detail

The data controller for personal information collected through this website is:

  • Legal entity: MAGNUSSON ANALYTICA LTD
  • Registered company number: 14266204
  • Registered address: Charlton House 1 Rosemead, 9 Coopers Lane, Verwood, Dorset, BH31 7AZ, United Kingdom
  • Trading name: Magnusson Analytica
  • Contact for data protection queries: contact@magnussonanalytica.com

We operate from Sibiu, Romania, with an office in London, UK. Our typical delivery coverage includes Romania, UK, and wider Europe. Because we are established in both the UK and the EU, this policy is written to meet both UK GDPR and EU GDPR.

We have not appointed a Data Protection Officer, as we are not required to under Article 37. Data protection queries go to the address above and are handled by the founder.

What we collect

If you email us, book a call, or apply for a role, we collect what you send us: your name, contact details, and your message. If you allow analytics cookies, we also collect information about how you use this site. We do not ask for special category data and you should not send it to us.

Read the full detail

We collect three kinds of information:

  • Information you give us directly. When you email us: your name, email address, and the content of your message. When you book a consultation, the booking is handled by our scheduling provider and we receive the name, email address, and any details you enter there. When you apply for a role, we receive whatever you send us about your background, including any attachment.
  • Information collected automatically, only with your consent. If you accept analytics cookies, our analytics provider records pages viewed, clicks, form interactions, downloads, page performance, and a session recording of how pages were used. This is tied to a randomly generated device identifier, not to your name, unless you have separately identified yourself by contacting us.
  • Information collected for security. Standard server logs held by our hosting provider, and, on our password-protected client pages, a session cookie confirming you entered the right access code. These apply regardless of your cookie choices because the site cannot safely operate without them.

We do not knowingly collect special category data (health, ethnicity, political opinions, and similar) and we ask that you do not include it in a form message. We do not collect information from children, as this site is aimed at business audiences.

Why we use it, and our legal basis

We use your information to answer your enquiry, to consider your job application, to improve the site, and to keep it secure. The law requires us to have a specific basis for each of those. Where we rely on your consent, you can withdraw it at any time.

Read the full detail

Under Article 6 of the UK and EU GDPR we must have a lawful basis for each purpose. Ours are:

PurposeLegal basisNotes
Responding to an enquiry you send us, or a consultation you bookArticle 6(1)(b) — steps at your request before entering a contractWhere an enquiry is not about engaging us, we rely instead on legitimate interests (Article 6(1)(f)): our interest in answering people who contact us.
Considering a careers applicationArticle 6(1)(b) — steps at your request before entering a contractKeeping an unsuccessful application on file beyond the role applied for is done only with your consent.
Sending marketing and promotional communicationsArticle 6(1)(a) — your consentYou can withdraw consent at any time, by using the unsubscribe link or by emailing us. Withdrawing does not affect anything we did before you withdrew.
Contacting an existing or former client about services similar to those we have already deliveredArticle 6(1)(f) — legitimate interestsThe interest relied on is direct marketing of our own similar services to an existing business relationship. Where we rely on this, you have an absolute right to object under Article 21(2). If you object, we must stop, with no balancing test and no exceptions.
Understanding how the site is used, in order to improve itArticle 6(1)(a) — your consentGiven through the Analytics category in our cookie banner, and withdrawable at any time from Privacy Preferences in the footer.
Attributing an enquiry to the campaign or referrer it came fromArticle 6(1)(a) — your consentGiven through the Marketing category in our cookie banner.
Keeping the site secure and availableArticle 6(1)(f) — legitimate interestsThe interest relied on is protecting our site from abuse and keeping it running. We consider this to have a minimal privacy impact.
Controlling access to password-protected client pagesArticle 6(1)(f) — legitimate interestsThe interest relied on is keeping client-confidential material restricted to the people entitled to see it.

Separately from GDPR, storing or reading cookies on your device requires your consent under the ePrivacy rules, unless the cookie is strictly necessary to provide the service you asked for. That is why analytics and marketing cookies stay off until you turn them on.

Cookies and similar technologies

Strictly necessary cookies keep the site working and cannot be turned off. Analytics and marketing cookies are off until you actively accept them, and you can change your mind at any time from Privacy Preferences in the footer. The full list of what we set is below.

Read the full detail

Under the General Data Protection Regulation (GDPR), organisations are required to obtain valid consent from individuals for the processing of their personal data. Consent must be freely given, specific, informed, and unambiguous.

When you first visit, we ask which categories of cookies you allow. Nothing in the Analytics or Marketing categories is set before you accept it, and no box is pre-ticked. Rejecting is a single click, in the same place and at the same size as accepting. That is how we meet each part of the standard above: the choice is free because refusing costs you nothing, specific because each category is decided separately, informed because the table below lists every cookie before you decide, and unambiguous because nothing is set until you take a clear affirmative action.

to see or change your current choices.

These are the cookies and local storage entries this site can set:

NameProviderCategoryPurposeDurationType
ma_cookie_consentMagnusson Analytica (first party)necessaryStores which cookie categories you accepted, and when, so we do not ask again and can evidence your choice.12 monthsCookie
ma_consent_logMagnusson Analytica (first party)necessaryA local record of your recent cookie choices with timestamps. Never leaves your browser.Until you clear site dataLocal storage
srf_session, raiffeisen_sessionMagnusson Analytica (first party)necessaryKeeps you signed in to a password-protected client page after you enter its access code. Only set if you use one of those pages.12 hoursCookie (HttpOnly)
AMP_*AmplitudeanalyticsIdentifies your browser and current session so page views and clicks can be grouped into a single visit. Contains a randomly generated device ID, not your name.12 monthsCookie
AMP_SR_START_*Amplitude (session replay)analyticsMarks when session recording began, so a recording is not double-counted across page navigations.24 hoursLocal storage
AMP_MKTG_*AmplitudemarketingStores the campaign parameters and referring site you arrived from, so we can attribute an enquiry to the channel that produced it.12 monthsCookie

We do not run advertising pixels, we do not use a tag manager, and we do not sell or share your information with advertising networks.

Who we share it with

We do not sell your information. We do share it with a small number of suppliers who run parts of this site for us: our analytics tool, our booking calendar, and our host. Each acts on our instructions under a contract.

Read the full detail

We share personal information with the following categories of recipient, all of whom act as our processors under Article 28 contracts:

  • Analytics provider — Amplitude. Receives site usage data and session recordings. Only if you accept analytics cookies.
  • Scheduling provider — Notion. Runs the booking calendar our “book a consultation” links point to. If you book, you are handing your details to that calendar, and the booking details reach us from it.
  • Hosting and content delivery — Vercel. Serves the site and holds standard server logs.
  • Email. Messages you send us are held in our business email system in the ordinary way.

Typefaces are served from our own domain rather than from a font network, so displaying this site does not disclose your IP address to a third party.

We may also disclose information to professional advisers, or to a public authority where we are legally required to. We do not sell personal information, and we do not share it for anyone else’s marketing.

Where your information goes

Some of our suppliers are based in the United States, so your information leaves the UK and EU when we use them. Where that happens, we rely on the safeguards the law requires for international transfers.

Read the full detail

The following processing involves a transfer outside the UK and EEA:

  • Amplitude — our account is configured to Amplitude’s US region, so analytics data and session recordings are processed in the United States.
  • Notion (scheduling) — also processes data in the United States.

For these transfers we rely on the European Commission’s Standard Contractual Clauses, together with the UK International Data Transfer Addendum for transfers from the UK, and on the EU–US Data Privacy Framework where the supplier is certified under it. You can request a copy of the safeguards in place by emailing contact@magnussonanalytica.com.

How long we keep it

We keep enquiry and application data for 24 months after we last hear from you, then delete it. If you become a client, we keep the records for as long as we work together plus the period accounting law requires. Analytics data expires on its own.

Read the full detail
DataRetention period
Contact form enquiries, and the email thread that follows24 months after our last contact with you, unless a client relationship begins.
Records relating to a client engagementFor the duration of the engagement, then for 6 years to meet UK statutory accounting and limitation periods.
Careers applications from unsuccessful candidates24 months after the outcome is communicated, so we can consider you for similar roles. Tell us and we will delete it sooner.
Marketing contact detailsUntil you withdraw consent or object, then removed from the sending list and retained only as a suppression record so we do not contact you again.
Analytics data and session recordingsPer our analytics provider’s retention settings. The related cookies expire after 12 months.
Your cookie consent record12 months, after which we ask you again.
Server and security logsAs retained by our hosting provider, typically no more than 30 days.

Your rights

You can ask to see your information, correct it, delete it, restrict or object to how we use it, or receive a copy to take elsewhere. Where we rely on consent, you can withdraw it at any time. Email contact@magnussonanalytica.com and we will respond within one month.

Read the full detail

You have the following rights over your personal information:

  • Access. Ask whether we hold information about you, and get a copy of it.
  • Rectification. Have inaccurate information corrected, or incomplete information completed.
  • Erasure. Ask us to delete your information, where we no longer need it, where you withdraw the consent it relied on, or where you object and we have no overriding grounds.
  • Restriction. Ask us to pause using your information while a dispute about its accuracy or our grounds is resolved.
  • Portability. Receive the information you gave us in a structured, commonly used, machine-readable format, or have us send it to another provider where technically feasible. This applies to information processed by consent or contract.
  • Objection. Object to processing based on legitimate interests. For direct marketing this right is absolute: if you object, we stop, and we do not weigh it against our interests.
  • Withdrawing consent. Where processing relies on consent, withdraw it at any time. For cookies, use Privacy Preferences in the footer. For marketing emails, use the unsubscribe link or email us. Withdrawal does not affect processing carried out before you withdrew.

To exercise any of these, email contact@magnussonanalytica.com. We will respond within one month. If a request is complex we may extend that by up to two further months, and we will tell you if so. There is no charge unless a request is manifestly unfounded or excessive. We may need to verify your identity before acting.

Complaints

If you think we have handled your information badly, please tell us first so we can put it right. You also have the right to complain to a data protection regulator, and you can do that without coming to us first.

Read the full detail

Please contact us at contact@magnussonanalytica.com in the first instance.

You also have the right to lodge a complaint with the supervisory authority in the country where you live or work, or where you think the problem occurred. Given where we operate, the two most likely to be relevant are:

  • United Kingdom — Information Commissioner’s Office (ICO), ico.org.uk.
  • Romania — Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), dataprotection.ro.

If you are in another EU member state, you may complain to your own national supervisory authority instead.

Security and compliance posture

We apply a risk-aware operating model designed to protect personal information and client analytics environments. This section describes how we work day to day; it is not a substitute for the rights described above.

Read the full detail
  • Access is limited to assigned team members and scoped to project needs (least-privilege access).
  • We request and process only the data required for agreed services (data minimisation).
  • Implementation and reporting updates are documented so teams can review what changed and why.
  • We can align project onboarding with your NDA, DPA, and internal security review requirements.
  • We review active access during engagements and remove tool access when it is no longer required.

This page describes our general privacy and security posture and does not replace client-specific contractual terms.

Contact

For any privacy, security, or compliance question about this policy, contact us at contact@magnussonanalytica.com, or write to MAGNUSSON ANALYTICA LTD, Charlton House 1 Rosemead, 9 Coopers Lane, Verwood, Dorset, BH31 7AZ, United Kingdom.

If we change this policy substantively, we will update the “last updated” date at the top of the page. Where a change affects what you have consented to, we will ask for your consent again.

We use strictly necessary cookies to make this site work. We would also like to set analytics and marketing cookies to understand how the site is used and which channels bring people here. These are off unless you turn them on, and you can change your mind at any time from “Privacy Preferences” in the footer. Read our privacy policy