Magni

Privacy Policy

Last updated: 9 September 2026

Magni Solutions ehf. builds Magni, a platform for managing industrial assets — vessels, factories and the components inside them. This policy explains what personal data we handle, why we handle it, who we share it with and what you can ask us to do about it.

It covers our website at magni-app.is and the Magni application at serviceportal.is.

1. Who we are

Magni Solutions ehf. (“Magni”, “we”, “us”), registration number 690426-1370, Gjáhella 4, 221 Hafnarfjörður, Iceland.

For anything in this policy, including requests about your own data, write to [email protected].

2. The two roles we play

Data protection law distinguishes the party that decides why and how data is processed (the controller) from the party that processes it on someone else's instructions (the processor). Magni is both, depending on the data.

We are the controller for visitors to our website, for the accounts people hold in the Magni application, and for the technical records we keep to run and secure the service.

We are a processor for the operational content our customers put into Magni — their assets, components, work orders, service reports, contacts and technicians. The customer organisation decides what goes in and why, and we handle it on their behalf and on their instructions.

If you work for one of our customers and want to exercise your rights over that operational content, ask your own organisation first. They control it. We will help them respond.

3. What we collect

On the website (magni-app.is), we ask before collecting analytics. If you accept, we collect how the site is used: pages viewed, which navigation, call-to-action and feature elements are clicked, approximate location derived from your IP address, and basic device and browser information. This is handled by PostHog on servers in the European Union. Whether you accept or not, we collect reports of errors the site runs into in your browser, because a site that fails on your first visit is a site we have not delivered. Those reports reach us without your IP address, though an approximate location derived from it travels with them, and nothing is stored on your device for them.

In the application (serviceportal.is), we collect the following.

Your name and email address are necessary to hold a Magni account. Without them we cannot give you access.

Free-text fields are not meant for special categories of personal data — health, trade union membership, and the other categories Article 9 of the GDPR lists. We never ask for them, and we ask our customers not to record them in Magni.

4. If your details are in Magni because someone else added them

Not everyone whose details are in Magni has a Magni account. A customer may record you as a contact or a technician, or share a work order with you by email. In that case we did not get your details from you — we got them from the organisation that entered them, and that organisation decides what is held and why.

What we hold about you in that situation is your name and, depending on what was entered, your email address, telephone number, work location, and any notes the organisation wrote about you in connection with their equipment.

You have the same rights over that data as anyone else — see section 13. Because the organisation controls it rather than us, we will pass your request to them. If you do not know which organisation holds your details, tell us and we will find out for you.

5. Signing in with Google

You can sign in to Magni with a Google account. If you do, Google tells our authentication provider PropelAuth your name, your email address, whether that address is verified, and your Google account identifier. We store your name and email address. We never receive your Google password.

We request only the basic sign-in scopes. We do not ask for access to your Gmail, Drive, Calendar, Contacts or any other Google service.

Magni's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google account data solely to create your Magni account and sign you in. We do not use it for advertising, we do not sell it, we do not build profiles from it, and we do not transfer it to anyone other than the providers listed in section 8.

You can withdraw Magni's access to your Google account at any time at myaccount.google.com/permissions. Doing so stops you signing in with Google; it does not by itself delete your Magni account.

6. Why we process it, and on what legal basis

Our customers are organisations, and our agreement is with them rather than with you personally. For that reason we rely on legitimate interests for the processing described here, rather than on a contract with you.

PurposeLegal basis
Providing Magni to the organisation you work for, and giving you access to itOur legitimate interest in delivering the service our customer has asked us for
Signing you in and keeping accounts secureOur legitimate interest in the security of the service
Keeping a record of who changed whatOur legitimate interest in accountability, traceability and resolving disputes about what happened
Diagnosing errors and measuring performanceOur legitimate interest in a service that works. Nothing is stored on your device for this, and the reports reach us without your IP address, though an approximate location derived from it travels with them
Understanding how our website and application are usedYour consent
Recording application sessions, to see how the application behaves in useYour consent
Producing a draft service report when you ask for oneOur legitimate interest in providing the feature you asked for
Answering enquiries you send usOur legitimate interest in responding to you

Where the basis is our legitimate interest, we have weighed that interest against your rights and freedoms, and you can object to any of it — see section 13. Where the basis is your consent, nothing runs until you give it: we ask on your first visit, and you can withdraw it at any time as easily as you gave it — on the website through the link in the footer, and in the application on the privacy page under Settings, or from this policy if you are not signed in. Withdrawing deletes the identifier that was stored on your device.

7. Cookies and similar technologies

Some storage on your device is strictly necessary to deliver the service you asked for, and some is not. This is what is set today.

WhatWherePurposeStrictly necessary
PropelAuth session cookiesserviceportal.isKeeping you signed inYes
hsp-trace-idserviceportal.isCorrelating a request with its diagnostic trace; expires after 60 secondsYes
Your cookie choicemagni-app.is and serviceportal.isRemembering whether you accepted or refused, so you are not asked againYes
PostHog website analytics identifiermagni-app.isRecognising a returning browser so visits are not double-counted; set only once you acceptNo
PostHog product telemetry identifierserviceportal.isUsage analytics and session recording; set only once you acceptNo

You can block or delete cookies in your browser settings. The ones that are not strictly necessary are set only if you accept them, and you can change your mind at any time — through the link in the website footer, or in the application on the privacy page under Settings — and from this policy either way. Blocking the strictly necessary ones will stop you signing in.

8. Who we share it with

We share personal data with the service providers we need in order to run Magni, and with nobody else except as described at the end of this section.

ProviderWhat they do for usWhere they process it
PropelAuthAuthentication, user accounts and organisation membershipUnited States
DigitalOceanApplication hosting and our database (London), and file storage (Amsterdam)United Kingdom and Netherlands
SendGridDelivering the email that invites someone to a shared work orderUnited States
PostHogWebsite analytics, error reporting, performance monitoring and session recordingEuropean Union and United States
MapboxRendering mapsUnited States
AnthropicGenerating draft service reports on requestUnited States

We may also disclose personal data where the law requires it, or to establish or defend legal claims.

We do not sell personal data, and we do not use it for advertising.

9. Transfers outside the EEA

Iceland is part of the European Economic Area. Uploaded files are stored in Amsterdam, and the analytics and telemetry PostHog holds for us are stored in Frankfurt — both inside the EEA.

Our application and our database run in London. Transfers to the United Kingdom are covered by the European Commission's adequacy decision for the United Kingdom, renewed on 19 December 2025 and running until 27 December 2031, so no additional safeguard is required.

PropelAuth, SendGrid, Mapbox and Anthropic process data in the United States. Each of those transfers relies on the mechanism that provider's data processing agreement provides for: the European Commission's Standard Contractual Clauses for PropelAuth, Mapbox and Anthropic, and certification under the EU–US Data Privacy Framework for SendGrid, whose agreement falls back on the Standard Contractual Clauses if that certification ends. DigitalOcean and PostHog are certified under the Framework as well: PostHog stores our analytics and telemetry in Frankfurt and processes it in the United States too, and DigitalOcean's United States operations can reach what it holds for us in London and Amsterdam. Every one of these agreements is published by the provider, and we will send you the one you ask about.

10. How long we keep it

The law lets us state either a fixed period or the criteria we use to work one out. We state criteria, because Magni does not currently delete personal data on a schedule.

DataWhat decides how long we keep it
Account recordsWhile you have a Magni account. If your organisation stops using Magni, the record remains until the agreement ends or until it is removed on request
Content your organisation entered, including contacts and techniciansYour organisation decides. They can delete it in Magni themselves at any time, and we hold it while their agreement with us is in force
Records of who changed whatKept alongside the content they describe, so that the history of a piece of equipment stays complete
Notification settings, subscriptions and favouritesWhile you have a Magni account
Alarm readings from connected equipmentA fixed number of the most recent readings for each feed, set by the customer. Older readings are deleted automatically as new ones arrive
Error reports, performance data and session recordingsThe retention period configured in our PostHog project
Website analyticsThe retention period configured in our PostHog project

If you want personal data about you removed, ask us — see section 13 — and we will remove it, unless we are required to keep it, or unless it belongs to a customer whose records we hold on their behalf, in which case we will pass your request to them.

11. Automated decisions

We do not make decisions about you by automated means that produce legal effects or that affect you in a similarly significant way, and we do not profile you.

Magni can draft a service report for you using an AI model. That produces a draft for a person to read, change and approve. It does not decide anything about anyone.

12. How we protect it

Traffic between your browser and Magni is encrypted. Using the application requires an account, and each account sees only the organisations it belongs to — that boundary is applied on the server for every request rather than hidden in the browser. Changes made through the application are recorded.

No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify Persónuvernd, and you, as the law requires.

13. Your rights

Under the GDPR and the Icelandic Data Protection Act you can ask us to:

Write to [email protected]. We will answer within one month, and tell you if we need longer. There is no charge unless a request is manifestly unfounded or excessive.

Where we hold the data on behalf of your employer or another organisation, we will forward your request to them rather than act on it ourselves, and tell you that we have done so.

If you are unhappy with how we handle it, you can complain to Persónuvernd, Laugavegur 166, 4th floor, 105 Reykjavík, [email protected], telephone 510 9600.

14. Children

Magni is a tool for businesses. It is not directed at children, and we do not knowingly collect data about them. If you believe a child's data has reached us, tell us and we will delete it.

15. Changes to this policy

We update this policy when what we do changes. The date at the top always reflects the current version. Where a change materially affects you, we will tell you through the application or by email rather than relying on you noticing the date.