Applications open, taking on a few SaaS clients for Q3 2026. Engagements from $5,000/mo. See how it works

Privacy policy

We collect very little, we do not sell any of it, and you can ask us to delete it at any time. The detail below exists because the law requires specifics and because procurement teams need to see them.

Last updated 27 July 2026 · Applies to authoritymagnet.com

The short version

What this policy says

We collect very little, we do not sell any of it, and you can ask us to delete it at any time. Analytics tells us which pages are read. The application form tells us who wants to work with us. That is close to the whole picture.

The detail below exists because privacy law requires specifics, and because procurement teams need to see them. If you only want the summary, you have already read it.

We sell data Never Ad cookies None Deletion requests Honored within 30 days Updated July 2026

Who we are

Authority Magnet is a SaaS SEO agency operating from Jamshedpur, Jharkhand, India, serving clients principally in the United States, the United Kingdom and Canada. For the personal data described in this policy, Authority Magnet is the data controller.

For anything relating to privacy, including access and deletion requests, contact hello@authoritymagnet.com. Requests are handled by Mohammad Qaiser, who is responsible for data protection here.

This policy covers authoritymagnet.com and any forms or emails connected to it. It does not cover PRWiz, which operates its own policy at prwiz.com, or any third-party site we link to.

Collection

What we collect, and how

Three groups of people, three different sets of data. Nothing is bought from data brokers or scraped.

Personal data collected by category of person
WhoWhat we collectHow we get it
Website visitorsIP address, browser and device type, pages viewed, referring source, approximate city-level locationAnalytics, when you consent to it
Applicants and enquirersName, work email, company, website, and whatever you write in the messageYou type it into the application form or email us
Newsletter subscribersEmail address, and whether you opened or clickedYou subscribe on the blog
ClientsBusiness contact details, billing details, and access to your analytics, Search Console, CMS and CRMYou provide it during onboarding
Anyone emailing usThe content of the correspondenceYou send it
What we deliberately do not collect

No advertising identifiers, no cross-site tracking pixels, no fingerprinting, no purchased contact lists, and no special category data such as health, religion or political opinion. We have no reason to want any of it.

Why we use it, and our legal basis

If you are in the UK or EEA, the law requires us to name a lawful basis for each use. Here they are.

  • To reply to your enquiry. Basis: taking steps at your request before entering a contract. Without your email we cannot answer you.
  • To deliver an engagement. Basis: performance of a contract. This covers billing, reporting and everything we do for a client.
  • To understand how the site is used. Basis: consent, given through the cookie banner where required. Decline it and the site works exactly the same.
  • To send the newsletter. Basis: consent. One click unsubscribes, and the link is in every email.
  • To keep records and meet tax obligations. Basis: legal obligation under Indian accounting and tax law.
  • To secure the site and prevent abuse. Basis: legitimate interest in keeping the service working and spam out of our inbox.

We do not use automated decision-making or profiling that produces legal or similarly significant effects. No algorithm decides whether we take you on as a client; a person reads every application.

Cookies and analytics

We run analytics to see which pages get read and which do not. That is genuinely the extent of the ambition.

  • Essential cookies keep the site working and record your cookie choice. These cannot be switched off and do not identify you.
  • Analytics cookies measure page views, referral sources and rough location. Where consent is required, these load only after you agree.
  • No advertising or retargeting cookies. We do not run ads and we do not build audiences for anyone else.
  • You can change your mind at any time through the cookie settings link in the footer, or by clearing cookies in your browser.
  • We honor Global Privacy Control. If your browser sends a GPC signal, we treat it as an opt-out of non-essential tracking.
Declining costs you nothing

No content is gated behind consent, nothing is degraded, and you will not be asked again on every page. We would rather have accurate analytics from people who agreed than complete analytics from people who were worn down.

Processors

Who else touches your data

We use third-party services to run the business. Each one is bound by a data processing agreement and may only act on our instructions.

Third-party subprocessors and their purpose
ServicePurposeWhere data sits
Website hostingServing this site and processing form submissionsUnited States and European Union
Transactional emailDelivering form notifications and repliesUnited States and European Union
AnalyticsMeasuring page views and traffic sourcesUnited States and European Union
Email and calendarCorrespondence and schedulingUnited States
AccountingInvoicing and statutory recordsIndia
Payment processingCollecting client paymentsUnited States, United Kingdom, India

We will name the specific providers on request. We do not sell, rent or trade personal data, and we do not share it with advertisers. We would disclose data if legally compelled by a valid order, and we would tell you unless the order forbids it.

International transfers

This one matters more for us than for most agencies, so it gets its own section rather than a footnote.

Our team works from India. Our infrastructure sits in the United States and the European Union. Most of our clients are in the United States, the United Kingdom and Canada. That means personal data routinely crosses borders, including being accessed from India.

  • For UK and EEA data, India has no adequacy decision, so transfers rely on the EU Standard Contractual Clauses and the UK International Data Transfer Addendum. We sign these with clients who need them, and we have them in place with our own providers.
  • We run a transfer risk assessment and apply the safeguards described under security below, including encryption in transit and least-privilege access.
  • For Canadian clients, we tell you plainly that data is processed outside Canada and is therefore subject to the laws of the countries involved, as PIPEDA expects.
  • You can ask for the paperwork. If your legal team wants the executed clauses before signing, ask and we will send them.
Retention

How long we keep things

We delete on a schedule rather than hoarding by default. You can always ask us to delete sooner.

Data retention periods
DataKept forWhy
Enquiries that do not become clients24 monthsPeople often return after a year. After two, it is clutter.
Client records and correspondenceEngagement plus 7 yearsIndian tax and accounting law
Invoices and financial records7 yearsStatutory requirement
Newsletter subscribersUntil you unsubscribeConsent lasts until withdrawn
Analytics data14 monthsEnough for year-on-year comparison, no more
Access credentials to your systemsRevoked at offboardingConfirmed to you in writing
BackupsUp to 90 daysDeleted data may persist in backups until they cycle out
Your control

Your rights

Which rights you have depends on where you live, but our practice is to honor all of them for everyone rather than checking your address first.

Access
A copy of what we hold about you, in a readable format.
Correction
Fix anything inaccurate or incomplete.
Deletion
Erase it, except records we must keep for tax law.
Portability
Receive it in a structured, machine-readable file.
Objection
Object to processing based on legitimate interest.
Restriction
Have us pause processing while a dispute is resolved.
Withdraw consent
At any time, without affecting what came before.
No retaliation
Exercising any right never changes how we treat you.
How to exercise them

Email hello@authoritymagnet.com with what you want. We respond within 30 days, free of charge. We may ask you to confirm your identity, but only enough to be sure we are not handing your data to someone else. If you are unhappy with our answer, you can complain to your data protection authority: the ICO in the UK, your national authority in the EEA, the OPC in Canada, or the Data Protection Board in India.

Client data: where we are the processor

An important distinction that most agency privacy policies skip. There are two different relationships here, with different obligations.

When we are the controller

For our own website visitors, enquirers and subscribers, we decide why and how data is used. Everything above applies, and we are accountable for it.

When we are the processor

During an engagement we work inside your analytics, Search Console, CMS and CRM. The personal data in those systems belongs to you and your customers. You are the controller. We act only on your documented instructions, and the data processing terms in our engagement agreement govern that work.

  • We use your data only for your campaign. Never to build products, train models, or benchmark other clients.
  • We do not aggregate client data. Your figures do not appear in an anonymized industry report without your written agreement.
  • Access is least-privilege and named. Specific people on our team, never a shared login, with the narrowest permission that lets us work.
  • We will sign your DPA rather than insisting on ours, and we will complete your security questionnaire.
  • Deletion on request. At the end of an engagement we return or delete what we hold and confirm it in writing.

Security

We are a small team, so our security is built on discipline and good defaults rather than a large program. Being straight about that is more useful than implying a certification we do not hold.

  • Encryption in transit across the site and all form submissions.
  • Multi-factor authentication on every account that holds client data or credentials.
  • A password manager for all shared credentials. Nothing lives in a spreadsheet or a chat message.
  • Least-privilege access to client systems, granted to named individuals and revoked at offboarding.
  • Reputable providers for hosting, email and analytics, each under a data processing agreement.
  • Breach notification. If a breach affects your data we will tell you within 72 hours of becoming aware, with what we know and what we are doing.
What we do not claim

We are not SOC 2 or ISO 27001 certified. If your procurement process requires either, say so early and we will tell you honestly whether we can meet it rather than working around the question.

Children, changes and contact

Children. This site is aimed at businesses and is not directed at anyone under 18. We do not knowingly collect data from children. If you believe a child has given us information, tell us and we will delete it.

Changes. When we update this policy we change the date at the top. For anything material, such as a new purpose for your data or a new category of recipient, we will tell subscribers and active clients by email rather than quietly editing the page.

Contact. Privacy questions, access requests and complaints go to hello@authoritymagnet.com. Postal address available on request. We aim to reply within one working day and are required to resolve formal requests within 30.

FAQ

Privacy questions

What procurement and legal teams ask most.

Ask a privacy question
What personal data does Authority Magnet collect?
Three categories. From website visitors: IP address, browser and device information, pages viewed and referring source, collected through analytics. From people who contact us: the name, work email, company and message you submit through the application form or by email. From clients during an engagement: business contact details, and access to systems such as analytics, Search Console and your CRM.
Do you use cookies?
We use a small number of first-party analytics cookies to understand which pages are read and where visitors arrive from. We do not use advertising or retargeting cookies, and we do not sell or share data with ad networks. Where required by law, analytics that set cookies run only after you consent through the banner.
Do you sell personal information?
No. We have never sold personal information and we do not share it for cross-context behavioral advertising, as those terms are defined under California law. There is nothing to opt out of because the practice does not happen here.
How long do you keep my data?
Enquiries that do not become clients are deleted after 24 months. Client records are kept for the engagement plus seven years, because tax law requires it. Newsletter data is kept until you unsubscribe. Analytics data is retained for 14 months. Anything else, you can ask us to delete sooner.
Where is my data stored, and does it leave my country?
Our website and forms run on infrastructure in the United States and the European Union. Our team works from India, so your data is accessed from there. If you are in the UK or EEA, that is an international transfer, and we rely on the UK and EU Standard Contractual Clauses to make it lawful.
What are my rights over my data?
Depending on where you live, you can ask for a copy of what we hold, correct it, delete it, restrict or object to how we use it, or receive it in a portable format. You can also withdraw consent at any time. Email us and we will respond within 30 days. We will not charge you or treat you differently for asking.
Who controls the data inside my own analytics and CRM?
You do. When we work inside your systems during an engagement, you are the controller and we act as your processor, following your instructions. Our engagement agreement includes the data processing terms that govern that relationship, and we do not use your customer data for anything except your campaign.
Do you use AI tools on my data?
We use AI for research, drafting and monitoring, and we say so plainly. Confidential client material is not entered into consumer AI tools that train on inputs. If your internal policy restricts AI processing of your data, tell us at kickoff and we will work within it.
How do I complain?
Email us first and we will try to resolve it. If you are not satisfied, you can complain to your data protection authority: the Information Commissioner's Office in the UK, your national supervisory authority in the EEA, the Office of the Privacy Commissioner in Canada, or the Data Protection Board in India.

Need the paperwork?

DPA, standard contractual clauses, security questionnaire. Ask and we will send them before you commit to anything.

We sign your DPA · We complete your security questionnaire · Reply within 24h