Privacy Policy
Last updated: 9 September 2026
Magni Solutions ehf. builds Magni, a platform for managing industrial assets — vessels, factories and the components inside them. This policy explains what personal data we handle, why we handle it, who we share it with and what you can ask us to do about it.
It covers our website at magni-app.is and the Magni application at serviceportal.is.
1. Who we are
Magni Solutions ehf. (“Magni”, “we”, “us”), registration number 690426-1370, Gjáhella 4, 221 Hafnarfjörður, Iceland.
For anything in this policy, including requests about your own data, write to [email protected].
2. The two roles we play
Data protection law distinguishes the party that decides why and how data is processed (the controller) from the party that processes it on someone else's instructions (the processor). Magni is both, depending on the data.
We are the controller for visitors to our website, for the accounts people hold in the Magni application, and for the technical records we keep to run and secure the service.
We are a processor for the operational content our customers put into Magni — their assets, components, work orders, service reports, contacts and technicians. The customer organisation decides what goes in and why, and we handle it on their behalf and on their instructions.
If you work for one of our customers and want to exercise your rights over that operational content, ask your own organisation first. They control it. We will help them respond.
3. What we collect
On the website (magni-app.is), we ask before collecting analytics. If you accept, we collect how the site is used: pages viewed, which navigation, call-to-action and feature elements are clicked, approximate location derived from your IP address, and basic device and browser information. This is handled by PostHog on servers in the European Union. Whether you accept or not, we collect reports of errors the site runs into in your browser, because a site that fails on your first visit is a site we have not delivered. Those reports reach us without your IP address, though an approximate location derived from it travels with them, and nothing is stored on your device for them.
In the application (serviceportal.is), we collect the following.
- Account data — your user identifier, name and email address. Our authentication provider PropelAuth holds the account itself; we copy the identifier, name and email into our own database so the application can show who did what, and we record when you were last seen signing in.
- Content you and your organisation enter — assets, components, work orders, service reports, maintenance schedules, documents, photographs and point-cloud scans. Free-text fields and uploaded files may contain personal data whenever someone puts it there.
- Contacts and technicians — names, email addresses, telephone numbers and free-text notes that your organisation chooses to record.
- Work-order sharing — when a work order is shared with someone outside your organisation, we process that recipient's first name, last name and email address.
- Activity and audit records — for every change made through the application we record who made it, when, the values that were submitted and the result. We also store your notification settings, what you have subscribed to and what you have marked as a favourite.
- Product telemetry — error reports, performance measurements and recordings of application sessions, handled by PostHog on servers in the European Union. Recordings and usage analytics run only if you accept them; error reports and performance measurements run either way, and reach us without your IP address, though an approximate location derived from it travels with them. Recordings mask every piece of text on screen and everything typed into a field, and they capture nothing of the requests the application makes. They are tied to a randomly generated identifier rather than to your account.
- Map usage — when a page shows a map, your browser requests map tiles from Mapbox, which necessarily reveals your IP address and the area you are looking at to Mapbox.
- AI-assisted drafting — when you ask Magni to draft a service report, the relevant work order, component and project content is sent to Anthropic so a draft can be generated. Anything personal in that content goes with it.
Your name and email address are necessary to hold a Magni account. Without them we cannot give you access.
Free-text fields are not meant for special categories of personal data — health, trade union membership, and the other categories Article 9 of the GDPR lists. We never ask for them, and we ask our customers not to record them in Magni.
4. If your details are in Magni because someone else added them
Not everyone whose details are in Magni has a Magni account. A customer may record you as a contact or a technician, or share a work order with you by email. In that case we did not get your details from you — we got them from the organisation that entered them, and that organisation decides what is held and why.
What we hold about you in that situation is your name and, depending on what was entered, your email address, telephone number, work location, and any notes the organisation wrote about you in connection with their equipment.
You have the same rights over that data as anyone else — see section 13. Because the organisation controls it rather than us, we will pass your request to them. If you do not know which organisation holds your details, tell us and we will find out for you.
5. Signing in with Google
You can sign in to Magni with a Google account. If you do, Google tells our authentication provider PropelAuth your name, your email address, whether that address is verified, and your Google account identifier. We store your name and email address. We never receive your Google password.
We request only the basic sign-in scopes. We do not ask for access to your Gmail, Drive, Calendar, Contacts or any other Google service.
Magni's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use Google account data solely to create your Magni account and sign you in. We do not use it for advertising, we do not sell it, we do not build profiles from it, and we do not transfer it to anyone other than the providers listed in section 8.
You can withdraw Magni's access to your Google account at any time at myaccount.google.com/permissions. Doing so stops you signing in with Google; it does not by itself delete your Magni account.
6. Why we process it, and on what legal basis
Our customers are organisations, and our agreement is with them rather than with you personally. For that reason we rely on legitimate interests for the processing described here, rather than on a contract with you.
| Purpose | Legal basis |
|---|---|
| Providing Magni to the organisation you work for, and giving you access to it | Our legitimate interest in delivering the service our customer has asked us for |
| Signing you in and keeping accounts secure | Our legitimate interest in the security of the service |
| Keeping a record of who changed what | Our legitimate interest in accountability, traceability and resolving disputes about what happened |
| Diagnosing errors and measuring performance | Our legitimate interest in a service that works. Nothing is stored on your device for this, and the reports reach us without your IP address, though an approximate location derived from it travels with them |
| Understanding how our website and application are used | Your consent |
| Recording application sessions, to see how the application behaves in use | Your consent |
| Producing a draft service report when you ask for one | Our legitimate interest in providing the feature you asked for |
| Answering enquiries you send us | Our legitimate interest in responding to you |
Where the basis is our legitimate interest, we have weighed that interest against your rights and freedoms, and you can object to any of it — see section 13. Where the basis is your consent, nothing runs until you give it: we ask on your first visit, and you can withdraw it at any time as easily as you gave it — on the website through the link in the footer, and in the application on the privacy page under Settings, or from this policy if you are not signed in. Withdrawing deletes the identifier that was stored on your device.
9. Transfers outside the EEA
Iceland is part of the European Economic Area. Uploaded files are stored in Amsterdam, and the analytics and telemetry PostHog holds for us are stored in Frankfurt — both inside the EEA.
Our application and our database run in London. Transfers to the United Kingdom are covered by the European Commission's adequacy decision for the United Kingdom, renewed on 19 December 2025 and running until 27 December 2031, so no additional safeguard is required.
PropelAuth, SendGrid, Mapbox and Anthropic process data in the United States. Each of those transfers relies on the mechanism that provider's data processing agreement provides for: the European Commission's Standard Contractual Clauses for PropelAuth, Mapbox and Anthropic, and certification under the EU–US Data Privacy Framework for SendGrid, whose agreement falls back on the Standard Contractual Clauses if that certification ends. DigitalOcean and PostHog are certified under the Framework as well: PostHog stores our analytics and telemetry in Frankfurt and processes it in the United States too, and DigitalOcean's United States operations can reach what it holds for us in London and Amsterdam. Every one of these agreements is published by the provider, and we will send you the one you ask about.
10. How long we keep it
The law lets us state either a fixed period or the criteria we use to work one out. We state criteria, because Magni does not currently delete personal data on a schedule.
| Data | What decides how long we keep it |
|---|---|
| Account records | While you have a Magni account. If your organisation stops using Magni, the record remains until the agreement ends or until it is removed on request |
| Content your organisation entered, including contacts and technicians | Your organisation decides. They can delete it in Magni themselves at any time, and we hold it while their agreement with us is in force |
| Records of who changed what | Kept alongside the content they describe, so that the history of a piece of equipment stays complete |
| Notification settings, subscriptions and favourites | While you have a Magni account |
| Alarm readings from connected equipment | A fixed number of the most recent readings for each feed, set by the customer. Older readings are deleted automatically as new ones arrive |
| Error reports, performance data and session recordings | The retention period configured in our PostHog project |
| Website analytics | The retention period configured in our PostHog project |
If you want personal data about you removed, ask us — see section 13 — and we will remove it, unless we are required to keep it, or unless it belongs to a customer whose records we hold on their behalf, in which case we will pass your request to them.
11. Automated decisions
We do not make decisions about you by automated means that produce legal effects or that affect you in a similarly significant way, and we do not profile you.
Magni can draft a service report for you using an AI model. That produces a draft for a person to read, change and approve. It does not decide anything about anyone.
12. How we protect it
Traffic between your browser and Magni is encrypted. Using the application requires an account, and each account sees only the organisations it belongs to — that boundary is applied on the server for every request rather than hidden in the browser. Changes made through the application are recorded.
No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify Persónuvernd, and you, as the law requires.
13. Your rights
Under the GDPR and the Icelandic Data Protection Act you can ask us to:
- tell you what personal data we hold about you, and give you a copy
- correct data that is wrong or incomplete
- delete data we no longer have grounds to keep
- restrict how we use it while a dispute about it is resolved
- give you, or another provider, a portable copy of data you gave us
- stop processing based on legitimate interests, where your situation outweighs those interests
- withdraw consent you gave, without affecting what we did before you withdrew it
Write to [email protected]. We will answer within one month, and tell you if we need longer. There is no charge unless a request is manifestly unfounded or excessive.
Where we hold the data on behalf of your employer or another organisation, we will forward your request to them rather than act on it ourselves, and tell you that we have done so.
If you are unhappy with how we handle it, you can complain to Persónuvernd, Laugavegur 166, 4th floor, 105 Reykjavík, [email protected], telephone 510 9600.
14. Children
Magni is a tool for businesses. It is not directed at children, and we do not knowingly collect data about them. If you believe a child's data has reached us, tell us and we will delete it.
15. Changes to this policy
We update this policy when what we do changes. The date at the top always reflects the current version. Where a change materially affects you, we will tell you through the application or by email rather than relying on you noticing the date.