Effective from 4 October 2026. This policy explains how Magus Group Albania processes personal data on magusgroup.al and on the group’s platforms: Magus ID, Magus Hub (with its client portal), Magus Pay and Magus Social, our tool for publishing on social networks. It follows Albanian Law no. 124/2024 “On personal data protection” and, for cookies, Article 158 of Law no. 54/2024 “On electronic communications in the Republic of Albania”. For people in the European Union we apply the same principles, in line with Regulation (EU) 2016/679 (GDPR).
In short
- We do not sell or rent personal data, and we do not use it for advertising or profiling.
- Our servers are in the European Union (netcup, Germany).
- Through social networks we only manage the group’s own pages and accounts: we do not read private messages and do not collect followers’ data.
- You can ask us to delete your data at any time: see Data deletion. We act within 30 days.
1. Who we are
- Magus Group Albania shpk, NIPT L92228018L
- Linzë, Nd. 30, H. 31, Ap. 52, Dajti, 1040, Tirana, Albania
- Email: per@magusgroup.al · Phone: +355 45 30 13 88
Magus Group Albania was formed in 2024 by the merger of Albmania Group (on the market since 2011) and autobus.al shpk (founded in 2019). We are the controller of the data described here. For any question or request about your data, write to us with the subject “Personal data”.
This policy covers magusgroup.al and the platforms named above. The group’s brand websites, such as autobus.al and busmagus.com, have their own privacy policies, which apply when you use their services (see the brands).
2. What data we process, why, and for how long
magusgroup.al: contact form and visits
Contact form. Your name, email and message, the language and page you wrote from, and, if you give them, your phone number and company. To protect the form from abuse we also keep your IP address and browser. Purpose: to answer you. Legal basis: steps you ask for before a possible contract (Article 7(1)(b) of Law 124/2024) or our legitimate interest in answering you (Article 7(1)(dh)). Retention: deleted automatically after 24 months, unless the law requires us to keep them or they relate to a contract with you. Data deletion requests sent through the form in Data deletion follow the same rules.
Job applications. When you apply on the careers page: name, email, phone, message and CV. Used only for recruitment, on the basis of the steps you ask for before an employment contract and your consent. Deleted automatically after 12 months (the careers page shows the exact period), sooner if you ask.
Visits. The server records the IP address, date and time, the page requested and the browser, to keep the site secure (legitimate interest), for no more than 30 days. Technical errors are reported to Sentry, with data stored in the European Union and without what you type into forms (up to 90 days).
Cookies. Necessary cookies only; analytics only if you accept them. The details are in the Cookie policy. Videos in articles are loaded from youtube-nocookie.com or Vimeo; their providers receive your IP address when you play a video.
Magus ID (id.magusgroup.al)
Magus ID is the shared sign-in for all our platforms. Accounts are created only by invitation, for our staff and for customers’ contact persons.
- Data: name, email, language, password (stored only as a one-way hash), the date and IP address of the last sign-in; for two-step verification, the authenticator app key and recovery codes (encrypted), or, if you choose them, codes by email or Telegram (Telegram chat ID and username); active sessions (IP address, browser, last activity); devices you marked as trusted; the activity log (sign-ins, failed attempts, access to applications, security changes); the applications you have access to and your role in them.
- Purpose: to identify you, protect your account and give you access to the platforms. You can see your sessions, devices and activity in your account.
- Legal basis: the contract or relationship under which the account was created (Article 7(1)(b)) and our legitimate interest in security (Article 7(1)(dh)).
- Retention: while the account exists; sessions end after 2 hours without activity; trusted devices expire after 30 days; the activity log is kept for 24 months.
Magus Hub and the client portal (hub.magusgroup.al)
Magus Hub is where we manage our business customers: services and licences, invoices, payments and support.
- Data: customer company details (name, legal name, NIPT, address, billing email, phone); contact persons (name, email, phone, role) who sign in to the portal with one-time codes by email or Telegram; licences, domains and technical data of the installations we support (website address, servers, regular status checks); invoices, payments and bank transfer details (payer, account); support tickets and the emails exchanged; access details for services we manage on the customer’s behalf, stored encrypted; a log of the emails sent and of actions in the system.
- Purpose: to provide the services agreed with the customer, invoice and collect payments, give support and meet legal obligations.
- Legal basis: the contract with the customer (Article 7(1)(b)), our legal obligations on accounting and tax (Article 7(1)(c)), and our legitimate interest in managing the relationship with the customer’s staff (Article 7(1)(dh)).
- Retention: while the business relationship lasts and up to 5 years after it ends; invoices and accounting records for 10 years, as required by Albanian accounting and tax law; status checks of installations 90 days; the log of sent emails about 13 months; the action log 12 months.
Magus Pay (pay.magusgroup.al)
Magus Pay processes card payments for the group’s websites through Raiffeisen Bank’s RaiAccept service.
- Data: the order (amount, what is being paid, and the names of the travellers or customers it concerns), the payer’s details (name, email, phone, company, address, country, IP address), the result of the payment and the transaction reference returned by the bank.
- Card details: you enter them on the bank’s secure payment page. We never receive or store the full card number or the security code (CVV). Our technical logs remove any card data and keys.
- Purpose and legal basis: to carry out the payment (contract, Article 7(1)(b)), to meet accounting obligations (Article 7(1)(c)) and to prevent fraud (legitimate interest).
- Retention: orders and payments for 10 years (accounting law); technical logs of payments up to 400 days.
The bank processes the card data as an independent controller under its own privacy policy. The site you buy from (for example autobus.al) is responsible for the booking itself.
Website administration and AI tools
Our staff sign in to the magusgroup.al admin through Magus ID; their actions are logged and kept for 12 months. The admin has AI tools that translate texts, suggest titles and descriptions and describe images: they receive only the content written for publication (texts and images of the site), never contact messages, job applications or visitors’ data. More in section 4.
3. Social media accounts (Magus Social / Postiz)
Magus Social (social.magusgroup.al) is our own installation of the open-source tool Postiz, on our servers in the European Union. It is an internal tool: public registration is closed and only Magus Group Albania staff use it, to prepare, schedule and publish the posts of the group’s brands and to see basic statistics of those posts. The accounts connected are the group’s brand pages and channels and, where a staff member chooses, their own professional profile (for example on LinkedIn), always by their own authorisation.
Which networks and what we access through them
When an account is connected, the network asks the person connecting it to approve the permissions below. We use them only for these purposes:
- Facebook (Meta): the list of Pages you manage and their name, ID and picture; publishing posts, photos and videos on our Pages; reading and answering comments on our Pages’ posts; Page and post statistics.
- Instagram (Meta): the ID, username and picture of the professional account; publishing posts, reels and stories; reading and answering comments on our posts; account and post statistics.
- Threads (Meta): the ID, username and picture of the profile; publishing posts; managing replies to our posts; statistics.
- LinkedIn: the name, ID and picture of the person connecting; publishing as that person or as company pages they administer; reading the posts and statistics of those pages.
- X: the ID, name, username and picture of the account; publishing posts; statistics of our posts.
- TikTok: the basic profile (ID, name, username, picture) and its public counts (followers, likes); the list of our videos; uploading and publishing videos; statistics.
- Pinterest: account details; reading and creating boards and pins; statistics.
- YouTube (Google): the name, email and picture of the Google account connecting and the channel’s details; uploading and managing videos and playlists on our channel; reading channel and video data and YouTube Analytics statistics.
- Reddit: the username; publishing posts and choosing their flair in communities.
- Mastodon: the profile; publishing posts and media.
- Discord and Slack: our bot added to our own servers and workspaces; the list of channels (and, in Slack, the names of workspace members, used to mention them); posting messages in the channels we choose.
- Dribbble: the public profile; uploading shots.
- Medium: the profile (ID, name, picture) of the account whose integration token we entered; publishing articles.
Staff can also sign in to Magus Social with GitHub: GitHub then gives us their username, name and email. GitHub is not used to publish.
What we store and where
- For each connected account: its ID on the network, name, username, profile picture (a copy) and the access keys (OAuth tokens) the network gives us, with their expiry.
- The posts we prepare and publish, their media files, the publication date and link, and any publication errors.
- Internal notes our team writes on posts.
- When we look up an account to mention it in a post: the public name, username and picture the network returns.
- Statistics are not stored in our database: they are fetched from the network when someone opens them and kept in memory for at most one hour.
All this stays on our servers in the European Union. The access keys are used only by Magus Social to act on the account, and only staff with access to Magus Social can use it.
What we do not do
- We do not sell, rent or share data obtained from the networks with anyone, except the AI provider described in section 4, and only for the text being written.
- We do not use it for advertising, profiling, or to build audiences or lists of people.
- We do not read private messages and do not collect lists of followers or personal data of the people who follow our pages: we see only aggregate numbers and the comments on our own posts that the network shows.
- We do not use it for any purpose other than publishing and measuring the group’s own posts.
How long we keep it
- Access keys and account details: while the account is connected. When it is disconnected in Magus Social, or when you revoke access on the network, we delete the keys and the account’s details within 30 days.
- Posts, media and notes: while the account is connected, as a record of what we published; then deleted within 30 days of disconnection, unless you ask for earlier deletion.
- Statistics: not stored (memory cache for up to one hour).
- Encrypted backups: deleted data disappears from them when they rotate, within at most 12 months, and is never restored.
How to revoke access
You can remove Magus Social’s access to an account at any time, from the network itself (the names of the menus may change slightly between app versions):
- Facebook: Settings & privacy → Settings → Business integrations (for Pages) or Apps and websites.
- Instagram: Settings → Website permissions → Apps and websites (or through Accounts Center).
- Threads: through the Meta settings of the connected Instagram account (Apps and websites).
- LinkedIn: Me → Settings & Privacy → Data privacy → Other applications → Permitted services.
- X: Settings and privacy → Security and account access → Apps and sessions → Connected apps.
- TikTok: Settings and privacy → Security & permissions → Apps and services permissions.
- Pinterest: Settings → Security and logins → Apps.
- YouTube / Google: Third-party apps & services in your Google account.
- Reddit: User settings → Safety and privacy → Apps (or reddit.com/prefs/apps).
- Mastodon: Preferences → Account → Authorized apps, on your server.
- Discord: User settings → Authorized apps; the bot is removed from Server settings → Integrations.
- Slack: the workspace administrator removes the app from Manage apps.
- Dribbble: Account settings → Applications.
- Medium: Settings → Security and apps → Integration tokens (revoke the token).
- GitHub: Settings → Applications → Authorized OAuth apps.
Revoking access stops any further use. To also have the data we already hold deleted, follow the steps in Data deletion.
Google and YouTube
Magus Social uses the YouTube API Services. Magus Social’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. By connecting a YouTube channel you agree to be bound by the YouTube Terms of Service; Google processes data under the Google Privacy Policy. We use data from Google only to publish and measure our channel’s videos, never for advertising, and we do not let people read it except our staff who manage the channel or where the law requires it. We keep it in line with the YouTube API Services Developer Policies, including refreshing or deleting stored data as they require. You can revoke access at any time from your Google security settings.
The networks’ own rules
We use each network’s services under its developer terms: the Meta Platform Terms, the LinkedIn API Terms of Use, the X Developer Agreement and Policy, the TikTok Developer Terms, the Pinterest Developer Guidelines and the YouTube API Services Terms of Service. Each network is an independent controller of the data on its own platform, under its own privacy policy.
4. Artificial intelligence
- Magus Social: when a staff member asks for help writing a post (suggesting, improving or shortening text, or creating an image), the text or instruction is sent to OpenAI. It does not include access keys or followers’ data.
- magusgroup.al admin: translations, titles, descriptions and image descriptions are prepared with the provider chosen in the admin (for example Anthropic, OpenAI or Google). Only content written for publication is sent.
- Magus Hub: to summarise a support ticket and draft a reply, the ticket’s content may be sent to the AI provider chosen in Hub. A staff member always reviews the draft before anything is sent to the customer.
We use these providers through their business APIs: under their terms, data sent through the API is not used to train their models, and is kept by them only for a short time to prevent abuse (OpenAI: up to 30 days). AI is never used to make decisions about people.
5. Who receives the data
We share data only with:
- providers that work for us and process the data only on our instructions: netcup GmbH (servers, Germany); Cloudflare (storage of encrypted backups, EU jurisdiction) and, where configured, other storage for encrypted backups (Amazon S3, Google Drive, Microsoft OneDrive); our email provider; Sentry (error reports, EU data region); Telegram (only if you choose codes or notifications by Telegram); the AI providers in section 4;
- independent controllers: Raiffeisen Bank for card payments; the social networks for what is published on them; Google and Microsoft for website analytics, only if you accept those cookies;
- Magus Group Albania brands, when your request concerns them;
- public authorities, when the law requires it.
6. Transfers outside Albania
Our servers are in the European Union. Some providers (for example OpenAI, Anthropic, Google, Sentry, Telegram, the social networks) are based in, or also process data in, the United States or other countries. We transfer data only to countries the Commissioner recognises as ensuring adequate protection (Article 40 of Law 124/2024) or under the safeguards of Article 41, such as standard contractual clauses; for people in the EU, under the EU–US Data Privacy Framework or the European Commission’s standard contractual clauses. You can ask for a copy of these safeguards at per@magusgroup.al.
7. Security
All our services use encrypted connections (HTTPS). Passwords are stored only as one-way hashes; two-step verification is required for staff; access keys and customers’ secrets are stored encrypted where our systems allow it, and on servers with restricted access in every case. Actions in our systems are logged. Backups are encrypted before they leave our servers and are tested regularly. Staff access only the data they need for their work.
8. Children
Our site and platforms are aimed at businesses and adults. We do not knowingly collect data from children under 16 (Article 8 of Law 124/2024). If you believe a child has sent us data, write to us and we will delete it.
9. Your rights
Under Articles 13–20 of Law 124/2024 (and, in the EU, Articles 15–22 of the GDPR) you have the right to:
- be informed about and access your data;
- have it corrected or erased (the “right to be forgotten”);
- restrict its processing;
- receive it in a structured, machine-readable format (portability);
- object to processing based on our legitimate interest;
- withdraw your consent at any time, without affecting the lawfulness of earlier processing;
- not be subject to automated decisions. We make no such decisions and do no profiling.
Write to us at per@magusgroup.al. We answer free of charge within 30 days; for complex requests this may be extended by up to 60 more days, and we tell you why. We may ask you to confirm your identity.
10. Data deletion
You can ask us at any time to delete the data we hold about you, on any of our services. These instructions also serve as the data deletion instructions for the apps we use on Facebook, Instagram, Threads, LinkedIn, X, TikTok, Pinterest, YouTube and the other networks.
Step 1: revoke our access (social accounts)
If you connected a social account to Magus Social, first remove our access on the network, as described in How to revoke access (for example, on Facebook: Settings & privacy → Settings → Business integrations; on Google: Third-party apps & services). From that moment we can no longer use the account.
Step 2: send us your request
Use the form below or write to per@magusgroup.al with the subject “Data deletion”. Tell us:
- which service it concerns (Magus ID account, Hub or the client portal, Magus Pay, Magus Social, the contact form) and, for a social account, the network and the name of the page or profile;
- the email address you use with us; if possible, write from that address, so we can confirm the request comes from you.
For a Magus ID account, deletion removes your access to every platform at the same time (Hub and the client portal, Magus Pay, Magus Social and the admin of this site). We close the account and end its sessions as soon as we have confirmed the request.
What we delete and what we keep
- We delete: the Magus ID account and its sessions, devices, two-step verification data and activity log; access to the client portal; contact messages and job applications; for a social account, its access keys, details, profile picture, and the posts, media and notes linked to it; any other data we hold about you that we no longer need.
- We keep only what the law requires: invoices, accounting records and payment records (10 years, Albanian accounting and tax law), and what we need to establish or defend a legal claim. This data is kept apart and used only for that purpose.
- The request itself: we keep your request and our reply, as proof that we handled it, for 24 months, like any other message.
- Backups: the data leaves our systems within 30 days; in encrypted backups it disappears when they rotate, within at most 12 months, and it is never restored.
Timeline and confirmation
- We confirm we have received your request, by email, usually within 2 working days.
- We complete the deletion within 30 days of receiving the request (for complex requests up to 60 more days, and we tell you why).
- We send you a confirmation by email with the reference number of your request and what was deleted or, for data we have to keep, the reason and for how long.
Questions about deletion: per@magusgroup.al · +355 45 30 13 88.
11. Complaints
If you believe your data is processed against the law, you have the right to complain to the Commissioner for the Right to Information and Personal Data Protection (Rr. “Abdi Toptani”, Nd. 5, 1001 Tirana · info@idp.al · idp.al) under Article 86 of Law 124/2024, and to go to court. In the EU you can also contact the data protection authority of your country. We would appreciate the chance to resolve it with you first.
12. Changes to this policy
When we change this policy, the new version is published on this page with the date of the update. For significant changes we also notify you on the site and, if you have an account, by email. See also our Terms of service and Cookie policy.
Last updated on 4 October 2026