Roles and responsibilities
The customer normally acts as controller for customer and conversation data. Moselstudio ApS acts as processor under a separate DPA.
The controller determines purposes, lawful bases, access, integrations and retention periods.
Data and purposes
Data is used to provide support, retrieve context, run approved workflows, measure quality, secure operations and bill subscriptions and usage.
- Contact, company, order, subscription and CRM data.
- Enabled-channel conversations, agent actions and approved knowledge sources.
- Operational, security, usage, invoice and audit data.
Legal bases, suppliers and transfers
The customer documents its lawful basis. Svarværk processes on instructions and uses approved subprocessors only. The public list must state purpose, location and transfer mechanism.
Retention and rights
Retention is configured per workspace. Verified access, correction, deletion, restriction and export requests are handled in the privacy workflow; audited legal holds may temporarily prevent deletion.
AI transparency and learning
End users must be told when they interact with AI. Answers are linked to sources, policies, model version and decision trace.
Edits become bounded improvement proposals that are evaluated, approved and reversible. Personal data is not used for general model training without a separate basis and agreement.
Security and incidents
Incidents follow a documented response plan. Notification duties are assessed by the privacy owner and counsel.
- Role-based access and tenant isolation.
- Encrypted OAuth tokens, signed webhooks and replay protection.
- File quarantine, malware scanning, audit logs, retention and an AI kill switch.
Contact and complaints
Contact privacy@svarvaerk.dk. Data subjects may also contact the customer acting as controller and the relevant supervisory authority.