Last updated 27 August 2026
This notice applies to Kontor (v1, the Customers module) and, in a separate section, the public moskus.ai website and its contact form. Moskus AI AS is the controller. A separate notice covers the Kontor Post connection between ChatGPT and Kontor.
1. Controller
The controller is Moskus AI AS, which operates Kontor at moskus.ai.
Contact for personal data: personvern@moskus.ai (not a data-protection-officer address; Kontor has not appointed a DPO under art. 37).
Security issues and vulnerabilities: sikkerhet@moskus.ai (a different mailbox, so a subject-access request with a one-month deadline does not sit in the same pile).
2. Who this notice covers
Kontor is an office system for our own staff. V1 (the Customers module) stores information about customer businesses and about contact persons at those businesses — not about private individuals as customers, and not a national identity number (fødselsnummer).
If you are a contact person at a business we do customer or project work for, you are on record. If you are employed as a user of Kontor, you are on record as an account.
3. What we process, and why
We do not store a national identity number. We do not store special categories (art. 9). We do not send email to the customer’s contact persons. We do not create invoices. We have no product analytics and no session recording.
- Customer business: name, address, optional organisation number, website, where the business sits in a simple sales pipeline, how invoices should be received, and a general note. The organisation number is optional; when present it is nine digits.
- Contact person: name, email, phone, and an optional physical address. The contact person belongs to one customer and is not moved.
- Touchpoint: type (email, phone, in person), direction, planned and completed times, an optional follow-up date, and free text about what is planned or what happened. Free text must not contain unnecessary, sensitive, or special-category data.
- Project (only when the customer is won): name, status, dates, description, technical information, and a technical contact at the customer.
- Staff as users: name, email, password hash, two-factor setup, session, and security-audit events (who did what — field names, not field values).
4. Lawful basis
The legitimate interest is being able to do the work the customer business has asked for, with a named person at the customer. This is ordinary business contact data, with no profiling and no marketing from Kontor.
- Legitimate interest (art. 6(1)(f)) for contact persons in a business customer relationship.
- Contract (art. 6(1)(b)) where the contact person is a party to the customer relationship.
- For staff: contract (art. 6(1)(b)) for the account, and legitimate interest (art. 6(1)(f)) for security audit, logs, and error tracking.
5. Who processes the data for us
Host: Laravel Cloud (Postgres in Frankfurt). Secrets: Doppler. Account mail to staff: Resend. DNS/proxy: Cloudflare. Error tracking: Laravel Nightwatch, with the user as an opaque id, without the request body and without the query string.
Resend stores content, logs, and account in the United States; eu-west-1 only controls where mail is sent from. The transfer basis is standard contractual clauses and the EU–U.S. Data Privacy Framework.
A full list of role, what they process, where, transfer basis, and DPA is in the processor overview.
AI tools used to build Kontor are possible processors if someone pastes personal data into a session. Real customer records must not be pasted there.
6. How long we keep the data
- Archived customer or contact person: 24 months, then the whole graph is deleted (touchpoints and projects follow the customer).
- Deactivated user: anonymised after 12 months; the row remains so the audit trail still points at an actor.
- Audit events: 24 months, then name and reason are cleared; the row is never deleted.
- A deleted row may sit up to 30 days in the platform recovery window.
- Sessions and reset links: as the framework sets them; deactivation deletes sessions and open links.
- Kontor stores no accounting records. The bookkeeping act’s retention duty applies to the accounting system, not to Kontor. Erasure requests are honoured in full.
7. Your rights
You may ask for access, rectification, erasure, restriction, and data portability, and you may object to processing that rests on legitimate interest. Write to personvern@moskus.ai. We confirm identity before we reply.
You may complain to Datatilsynet (the Norwegian Data Protection Authority).
8. Automated decisions
None. Kontor does not profile, score, or take automated decisions that have legal effect or a similar impact.
9. Sources when the data does not come from you
Contact-person data usually comes from the staff member who registers the customer, or from you when you give it in a conversation with us. We do not import the old customer system.
The moskus.ai website and contact form
This section applies only to the public moskus.ai website and its contact form — not to the Customers module in Kontor.
When you submit the contact form, we process name, email, message and optional organisation only to answer and follow up your enquiry. We do not send newsletters, and we do not sell or share the details.
The submission is delivered through our form service (a Supabase function) and stored in our systems until the enquiry has been handled. We retain the details no longer than necessary. Please do not send sensitive information through the form.
The form may use Cloudflare Turnstile to tell people and bots apart. Turnstile is provided by Cloudflare and processes limited technical data under Cloudflare’s own privacy policy.
You may ask for access, rectification or erasure by writing to personvern@moskus.ai. You may complain to Datatilsynet.