Last updated: 6 September 2026
The controller of the personal data processed through busmagus.com and the BusMagus mobile applications is Magus Group Albania, Linze, Nd. 30, H. 31, AP. 52, Dajti, 1040, Tirana, Republic of Albania (the "Controller", "we"). Our group companies in London, United Kingdom and Rome, Italy provide us with technology, finance and administrative services and may process data on our behalf under written agreements. Questions about this policy and requests concerning your data can be sent to support [@] busmagus [.] com or by post to the address above.
We process personal data in accordance with Albanian Law No. 124/2024 "On Personal Data Protection", which replaced Law No. 9887/2008 and aligns Albanian law with Regulation (EU) 2016/679 (the GDPR). Where you are resident in the European Union or the United Kingdom, the GDPR or the UK GDPR and the Data Protection Act 2018 apply to our processing of your data as well. The supervisory authority in Albania is the Commissioner for the Right to Information and Protection of Personal Data (Komisioneri për të Drejtën e Informimit dhe Mbrojtjen e të Dhënave Personale), Tirana.
Booking data. The names of the passengers, their dates of birth where a child or senior fare applies, the email address and phone number of the person booking, the journey, seats and add-ons chosen, the price paid and the payment method used. On international journeys, where the Operator or a border authority requires it, the type and number of an identity document and nationality.
Payment data. Payments are processed by the payment provider selected at checkout. We receive confirmation of the payment, the amount, the last four digits of a card and the card brand. We never receive or store full card numbers or security codes.
Account data. If you create an account: your name, email, phone number, password (stored only as a hash), saved passengers, preferences, favourite routes, price alerts and referral information.
Communications. Messages you send us through the contact form, by email, phone, WhatsApp or Telegram, and our replies.
Reviews. The rating and text you submit after a journey, linked to the booking it concerns.
Technical data. IP address, browser or device type, operating system, language, the pages visited and the time of the visit, error reports, and, in the apps, a device identifier used to deliver push notifications you have enabled.
Cookies and similar technologies, as described in our Cookie Policy.
To conclude and perform your booking, issue your ticket, tell you about changes to your journey and handle your requests: performance of a contract (Article 6(1)(b) GDPR and the corresponding provision of Law No. 124/2024). To share passenger details with the Operator: performance of the contract of carriage. To keep accounting records and answer lawful requests of public authorities: compliance with legal obligations, including tax and accounting law and, on international journeys, border and security law (Article 6(1)(c)). To keep the Platform secure, prevent fraud, monitor errors and understand how the Platform is used in aggregate: our legitimate interests (Article 6(1)(f)), balanced against yours. To send you our newsletter or marketing messages, and to place non-essential cookies: your consent (Article 6(1)(a)), which you can withdraw at any time. To send you a reminder about an unfinished reservation or an invitation to review a journey you have taken: our legitimate interest in completing and improving the service you asked for; you can object at any time.
The Operator performing your journey receives the passenger details needed to carry you and to check you in. Travel agencies and partner sites through which you booked see the bookings they made. Payment providers process your payment. Providers of email, SMS, WhatsApp and Telegram messaging deliver our messages to you. Hosting, content delivery, error monitoring and analytics providers process technical data on our behalf. Our group companies in the United Kingdom and Italy provide internal services. Public authorities receive data where the law requires it. Every provider acting on our behalf is bound by a data processing agreement and may use the data only on our instructions.
Some recipients are located in the European Union, the United Kingdom or other countries. Transfers to the EU and the UK rely on the adequacy those jurisdictions enjoy under Albanian law and on our group agreements. Transfers to other countries are made under standard contractual clauses or another safeguard recognised by law. You can ask us for details of the safeguards in place.
Booking and payment records are kept for at least five years after the end of the year of the journey, as Albanian tax and accounting law requires, then deleted or anonymised. Account data is kept while your account exists and deleted within 30 days of your request to close it, except what we must keep by law. Communications are kept for at least two years after the last exchange. Technical logs are kept for twelve months. Newsletter consent is kept until you withdraw it, together with proof of when and how it was given. Reviews remain published while the booking record exists, unless you ask us to remove yours.
You have the right to obtain a copy of the data we hold about you, to have inaccurate data corrected, to have your data erased where there is no longer a legal ground to keep it, to restrict processing in the circumstances provided by law, to receive the data you gave us in a portable format, to object to processing based on our legitimate interests, including direct marketing, and to withdraw a consent at any time without affecting processing already carried out. You are not subject to decisions based solely on automated processing that produce legal effects on you. To exercise a right, write to support [@] busmagus [.] com; we answer within one month. You may also lodge a complaint with the Commissioner for the Right to Information and Protection of Personal Data in Albania and, if you are resident in the EU or the UK, with the supervisory authority of your country.
The Platform is not directed at children. An account may be created only by a person aged 16 or over. Children travel as passengers on bookings made by an adult, and we process only the details the carriage requires.
Data travels over encrypted connections. Access to personal data is limited to staff and providers who need it, is logged, and is protected by strong authentication. Databases are backed up regularly, and backups are stored off-site in encrypted form. No system is perfectly secure; if a breach ever affects your data, we will inform you and the authority as the law requires.
We may update this policy as the Platform or the law changes. The date of the current version appears at the top, and material changes are announced on the Platform.
Bus Magus
Email: support [@] busmagus [.] com
Phone: +39 06 8587 0040