What happens to your data, written down
Every answer a security questionnaire asks for, published before you ask. Where the data lives, who can reach it, and what we do when something goes wrong.
The short version
Where data lives
Primary data is held in the UK. Sub-processors are pinned to UK or EEA regions wherever the service supports region pinning.
In transit and at rest
TLS 1.2 or better in transit. AES-256 at rest for the primary database and its backups.
Who can reach it
Role-based access control with a per-endpoint audit log, quarterly access reviews, and mandatory two-factor authentication for administrators.
What we do not do
We do not sell personal data, and we do not enrich it with third-party demographic feeds.
Incidents
Controllers are notified within 72 hours of us becoming aware of a personal-data breach, as UK GDPR Article 33 requires.
Deletion
On termination, customer data is hard-deleted within 30 days. Audit and ledger rows are anonymised rather than deleted, for fraud detection and financial record-keeping.
AI, and what it means for your content
Moksy uses large language models to draft plans from the answers you give. That processing is covered by the Data Processing Agreement, and the model provider is listed as a sub-processor with zero-day retention.
Two things worth stating plainly. First: an AI-drafted plan is a draft. It is fluent, which is exactly what makes an unchecked one risky — that is why expert review exists and why every recommendation shows its reasoning. Second: what you type into the Briefing is your content, we treat it as confidential, and we do not use it to train anybody’s model.
Who processes data on our behalf
What we do not claim
Being straight about the gaps is the point of a trust page.
- We are not ISO 27001 certified. When we are, this page will say so and carry the certificate.
- We are not Cyber Essentials certified yet either.
- Nothing on this page is a substitute for reading the DPA — it is a summary of it.