Parties, duration and instructions
The customer is controller and Moselstudio ApS, Danish company no. 46617762, is processor. Processing lasts for the subscription and agreed wind-down period.
Kundeservice AI processes personal data only on documented instructions in this DPA, the order and customer configuration. Unlawful instructions are suspended and raised with the customer.
Nature, purpose and data categories
The purpose is to provide the selected support channels, integrations, AI assistance, human control, secure operations and support. Audio and voice cloning are not processed in Kundeservice AI without a separate documented voice instruction and consent through AI Kald.
- Contact, account, CRM, order and support data.
- Conversations, messages, attachments, transcripts and approved knowledge sources.
- Operational, security, usage, invoice and audit data.
Confidentiality and security
Access follows need-to-know. Measures are reviewed against risk and recorded in the operational and security documentation.
- Role-based access and tenant isolation.
- Encryption in transit and encrypted storage with approved suppliers.
- Signed webhooks, rate limits, file quarantine, audit logs, backup, restore and rollback exercises.
Subprocessors and transfers
The customer grants general written authorisation for subprocessors listed in the current public register and order. The register states name, purpose, location and transfer mechanism.
Material changes are notified so the customer can object on reasonable grounds. Transfers outside the EEA require a valid Chapter V mechanism and the necessary transfer assessment.
Data-subject rights and assistance
Kundeservice AI provides export, correction, restriction and deletion workflows and reasonably assists with access requests, DPIAs, regulator contact and evidence. The customer makes the legal decision and verifies the data subject.
Breaches and incidents
Moselstudio notifies the customer without undue delay after becoming aware of a personal-data breach and provides available information about nature, scope, impact and mitigation. The customer decides on regulator and data-subject notification.
Retention, backups and termination
Retention is set per workspace. The default transcript retention is 90 days unless the customer documents another necessary period; legal holds are time-bound and audited.
On termination, customer data is returned or deleted as instructed and required by law. Deletions are logged so restored data is deleted again. Encrypted backups expire under the documented backup retention.
Audit, responsibility and approval
Moselstudio supplies reasonable compliance evidence and supports audits without exposing other customers or security controls. The customer must approve the DPA, subprocessors, purposes, legal bases and retention before processing personal data.
This document is not certification or a guarantee of 100% GDPR compliance. Final compliance depends on customer use and written legal approval. Contact privacy@kundeserviceai.dk.