Last updated 16 July 2026
This notice applies to the custom GPT Kontor Post and its OAuth connection to the Post messaging service in Moskus Kontor.
Who is responsible for the data?
Moskus AI AS is the controller for the OAuth, access and security metadata we need to provide and secure the connection.
For messages and other workplace content in Kontor, the organisation through which you use Kontor is normally the controller. Moskus AI then processes the data on the organisation’s instructions as its processor.
Which data do we process?
We process only what is needed to authenticate you and perform the Post action you request.
- Your Kontor identity, including an internal user ID, person slug and name.
- Recipient or channel, organisation, message text, icon, sending mode and whether the request is a dry run.
- OAuth metadata such as client, scope, timestamps and technical statuses. Tokens and client secrets are stored only as one-way hashes in our database.
- Audit and error data needed for access control, abuse prevention, troubleshooting and documenting what the action did.
Purpose and legal basis
The data is used to confirm that you are an active Kontor user with Post access, resolve the correct target, perform or validate the action and return an auditable result.
Moskus AI relies on its legitimate interest in providing a secure, limited and auditable service for its own processing of access and security metadata. When we process workplace content for a Kontor customer, this forms part of our processor engagement for that customer.
What is shared with ChatGPT?
ChatGPT sees the text and target you provide in the conversation and receives the limited result returned by the action. Kontor Post never sends your Kontor password to ChatGPT.
OpenAI processes the ChatGPT conversation under its own terms and privacy rules. Moskus AI does not sell the data or use Post content for marketing or model training.
Retention and deletion
An access token lasts for up to one hour and a refresh token for up to 30 days. Moskus AI stores only hash values. Expired and revoked token records are removed when they are no longer needed for security and audit purposes.
A dry run validates the request without creating a message or approval proposal. Proposals and messages that are actually created follow the retention and deletion rules of the organisation using Kontor.
Service providers and security
Kontor uses service providers for database, hosting and network services, including Supabase, Vercel and Cloudflare. Access is limited and communications are encrypted in transit.
The OAuth connection never shares your Kontor password. Every Post action is tied to the signed-in identity, and approval is the default unless you explicitly choose direct sending.
Your choices and rights
You can disconnect Kontor Post in ChatGPT or contact us to have the OAuth access revoked. You may also request access, correction, deletion or restriction, or object to processing where applicable.
If your request concerns workplace content for which your organisation is the controller, we will help direct you to the appropriate contact. You may complain to the Norwegian Data Protection Authority if you believe your rights have not been respected.
Contact
Contact Moskus AI AS at johannes@moskus.ai. Use the subject “Privacy – Kontor Post” so we can route your request quickly.