What happens to your data, written down

Every answer a security questionnaire asks for, published before you ask. Where the data lives, who can reach it, and what we do when something goes wrong.

The short version

Where data lives

Primary data is held in the UK. Sub-processors are pinned to UK or EEA regions wherever the service supports region pinning.

In transit and at rest

TLS 1.2 or better in transit. AES-256 at rest for the primary database and its backups.

Who can reach it

Role-based access control with a per-endpoint audit log, quarterly access reviews, and mandatory two-factor authentication for administrators.

What we do not do

We do not sell personal data, and we do not enrich it with third-party demographic feeds.

Incidents

Controllers are notified within 72 hours of us becoming aware of a personal-data breach, as UK GDPR Article 33 requires.

Deletion

On termination, customer data is hard-deleted within 30 days. Audit and ledger rows are anonymised rather than deleted, for fraud detection and financial record-keeping.

AI, and what it means for your content

Moksy uses large language models to draft plans from the answers you give. That processing is covered by the Data Processing Agreement, and the model provider is listed as a sub-processor with zero-day retention.

Two things worth stating plainly. First: an AI-drafted plan is a draft. It is fluent, which is exactly what makes an unchecked one risky — that is why expert review exists and why every recommendation shows its reasoning. Second: what you type into the Briefing is your content, we treat it as confidential, and we do not use it to train anybody’s model.

Who processes data on our behalf

What we do not claim

Being straight about the gaps is the point of a trust page.

Security questionnaires and diligence

Send the questionnaire. We would rather answer it once, properly, than trade emails for three weeks.

Read the detail

The DPA carries the full processing terms, the sub-processor list and the security schedule.