Privacy policy
We collect very little, we do not sell any of it, and you can ask us to delete it at any time. The detail below exists because the law requires specifics and because procurement teams need to see them.
What this policy says
We collect very little, we do not sell any of it, and you can ask us to delete it at any time. Analytics tells us which pages are read. The application form tells us who wants to work with us. That is close to the whole picture.
The detail below exists because privacy law requires specifics, and because procurement teams need to see them. If you only want the summary, you have already read it.
Who we are
Authority Magnet is a SaaS SEO agency operating from Jamshedpur, Jharkhand, India, serving clients principally in the United States, the United Kingdom and Canada. For the personal data described in this policy, Authority Magnet is the data controller.
For anything relating to privacy, including access and deletion requests, contact hello@authoritymagnet.com. Requests are handled by Mohammad Qaiser, who is responsible for data protection here.
This policy covers authoritymagnet.com and any forms or emails connected to it. It does not cover PRWiz, which operates its own policy at prwiz.com, or any third-party site we link to.
What we collect, and how
Three groups of people, three different sets of data. Nothing is bought from data brokers or scraped.
| Who | What we collect | How we get it |
|---|---|---|
| Website visitors | IP address, browser and device type, pages viewed, referring source, approximate city-level location | Analytics, when you consent to it |
| Applicants and enquirers | Name, work email, company, website, and whatever you write in the message | You type it into the application form or email us |
| Newsletter subscribers | Email address, and whether you opened or clicked | You subscribe on the blog |
| Clients | Business contact details, billing details, and access to your analytics, Search Console, CMS and CRM | You provide it during onboarding |
| Anyone emailing us | The content of the correspondence | You send it |
No advertising identifiers, no cross-site tracking pixels, no fingerprinting, no purchased contact lists, and no special category data such as health, religion or political opinion. We have no reason to want any of it.
Why we use it, and our legal basis
If you are in the UK or EEA, the law requires us to name a lawful basis for each use. Here they are.
- To reply to your enquiry. Basis: taking steps at your request before entering a contract. Without your email we cannot answer you.
- To deliver an engagement. Basis: performance of a contract. This covers billing, reporting and everything we do for a client.
- To understand how the site is used. Basis: consent, given through the cookie banner where required. Decline it and the site works exactly the same.
- To send the newsletter. Basis: consent. One click unsubscribes, and the link is in every email.
- To keep records and meet tax obligations. Basis: legal obligation under Indian accounting and tax law.
- To secure the site and prevent abuse. Basis: legitimate interest in keeping the service working and spam out of our inbox.
We do not use automated decision-making or profiling that produces legal or similarly significant effects. No algorithm decides whether we take you on as a client; a person reads every application.
Cookies and analytics
We run analytics to see which pages get read and which do not. That is genuinely the extent of the ambition.
- Essential cookies keep the site working and record your cookie choice. These cannot be switched off and do not identify you.
- Analytics cookies measure page views, referral sources and rough location. Where consent is required, these load only after you agree.
- No advertising or retargeting cookies. We do not run ads and we do not build audiences for anyone else.
- You can change your mind at any time through the cookie settings link in the footer, or by clearing cookies in your browser.
- We honor Global Privacy Control. If your browser sends a GPC signal, we treat it as an opt-out of non-essential tracking.
No content is gated behind consent, nothing is degraded, and you will not be asked again on every page. We would rather have accurate analytics from people who agreed than complete analytics from people who were worn down.
International transfers
This one matters more for us than for most agencies, so it gets its own section rather than a footnote.
Our team works from India. Our infrastructure sits in the United States and the European Union. Most of our clients are in the United States, the United Kingdom and Canada. That means personal data routinely crosses borders, including being accessed from India.
- For UK and EEA data, India has no adequacy decision, so transfers rely on the EU Standard Contractual Clauses and the UK International Data Transfer Addendum. We sign these with clients who need them, and we have them in place with our own providers.
- We run a transfer risk assessment and apply the safeguards described under security below, including encryption in transit and least-privilege access.
- For Canadian clients, we tell you plainly that data is processed outside Canada and is therefore subject to the laws of the countries involved, as PIPEDA expects.
- You can ask for the paperwork. If your legal team wants the executed clauses before signing, ask and we will send them.
How long we keep things
We delete on a schedule rather than hoarding by default. You can always ask us to delete sooner.
| Data | Kept for | Why |
|---|---|---|
| Enquiries that do not become clients | 24 months | People often return after a year. After two, it is clutter. |
| Client records and correspondence | Engagement plus 7 years | Indian tax and accounting law |
| Invoices and financial records | 7 years | Statutory requirement |
| Newsletter subscribers | Until you unsubscribe | Consent lasts until withdrawn |
| Analytics data | 14 months | Enough for year-on-year comparison, no more |
| Access credentials to your systems | Revoked at offboarding | Confirmed to you in writing |
| Backups | Up to 90 days | Deleted data may persist in backups until they cycle out |
Your rights
Which rights you have depends on where you live, but our practice is to honor all of them for everyone rather than checking your address first.
Email hello@authoritymagnet.com with what you want. We respond within 30 days, free of charge. We may ask you to confirm your identity, but only enough to be sure we are not handing your data to someone else. If you are unhappy with our answer, you can complain to your data protection authority: the ICO in the UK, your national authority in the EEA, the OPC in Canada, or the Data Protection Board in India.
Client data: where we are the processor
An important distinction that most agency privacy policies skip. There are two different relationships here, with different obligations.
When we are the controller
For our own website visitors, enquirers and subscribers, we decide why and how data is used. Everything above applies, and we are accountable for it.
When we are the processor
During an engagement we work inside your analytics, Search Console, CMS and CRM. The personal data in those systems belongs to you and your customers. You are the controller. We act only on your documented instructions, and the data processing terms in our engagement agreement govern that work.
- We use your data only for your campaign. Never to build products, train models, or benchmark other clients.
- We do not aggregate client data. Your figures do not appear in an anonymized industry report without your written agreement.
- Access is least-privilege and named. Specific people on our team, never a shared login, with the narrowest permission that lets us work.
- We will sign your DPA rather than insisting on ours, and we will complete your security questionnaire.
- Deletion on request. At the end of an engagement we return or delete what we hold and confirm it in writing.
Security
We are a small team, so our security is built on discipline and good defaults rather than a large program. Being straight about that is more useful than implying a certification we do not hold.
- Encryption in transit across the site and all form submissions.
- Multi-factor authentication on every account that holds client data or credentials.
- A password manager for all shared credentials. Nothing lives in a spreadsheet or a chat message.
- Least-privilege access to client systems, granted to named individuals and revoked at offboarding.
- Reputable providers for hosting, email and analytics, each under a data processing agreement.
- Breach notification. If a breach affects your data we will tell you within 72 hours of becoming aware, with what we know and what we are doing.
We are not SOC 2 or ISO 27001 certified. If your procurement process requires either, say so early and we will tell you honestly whether we can meet it rather than working around the question.
Children, changes and contact
Children. This site is aimed at businesses and is not directed at anyone under 18. We do not knowingly collect data from children. If you believe a child has given us information, tell us and we will delete it.
Changes. When we update this policy we change the date at the top. For anything material, such as a new purpose for your data or a new category of recipient, we will tell subscribers and active clients by email rather than quietly editing the page.
Contact. Privacy questions, access requests and complaints go to hello@authoritymagnet.com. Postal address available on request. We aim to reply within one working day and are required to resolve formal requests within 30.
What personal data does Authority Magnet collect?
Do you use cookies?
Do you sell personal information?
How long do you keep my data?
Where is my data stored, and does it leave my country?
What are my rights over my data?
Who controls the data inside my own analytics and CRM?
Do you use AI tools on my data?
How do I complain?
Need the paperwork?
DPA, standard contractual clauses, security questionnaire. Ask and we will send them before you commit to anything.
We sign your DPA · We complete your security questionnaire · Reply within 24h