Privacy Policy

How moned processes personal information and the choices available to people who use the service.

Version
2026-08-14.1
Effective
Updated

Controller and contact

Moned UG, Schedestraße 7, 20251 Hamburg, Germany, is the controller for the moned public website and marketplace services described here.

Privacy questions and rights requests can be sent to privacy@moned.ai or submitted through the governed privacy request form. moned does not claim a Data Protection Officer unless one is formally appointed.

Information moned processes

Account and profile information; expert application and review evidence; versioned expert attestations and booking acknowledgements; service, availability, booking, payment, communication, review, and support records when those features are used; AI-search and conversational-discovery wording, bounded structured criteria, typed results, and derived continuity state; consented participant microphone-audio segments, speaker-labelled transcripts, and summaries when enabled; browser consent records; security and operational records. Camera video and screen sharing are not recorded for session transcripts or summaries.

Attestation records contain safe references, the accepted copy and legal versions, scope classification, a server-generated snapshot hash, locale, and time. moned does not collect IP addresses or user-agent strings for these acknowledgements by default.

For enabled tax workflows, moned may process legal and trading names, tax residence, establishments, performance locations, billing and business status, tax and business identifiers, registrations, evidence, forms, confirmations, expiry dates, transaction tax decisions, documents, settlement, withholding, seller-reporting, exposure, reconciliation, approval, correction, and audit records.

Professional review evidence is private. Government identity documents are not collected by default for expert review. Conversational discovery asks for the kind of help needed, not payment details or sensitive personal case facts.

Purposes and lawful bases

moned processes account, profile, discovery, support, and enabled service information where necessary to take requested pre-contract steps or perform a contract. Safety, fraud prevention, platform security, service reliability, proportionate dispute evidence, and product improvement rely on moned's legitimate interests where those interests are not overridden by a person's rights. Required tax, accounting, reporting, and lawful-authority responses rely on applicable legal obligations.

Optional analytics, microphone capture, transcription, and similar optional processing rely on consent where stated. Consent can be withdrawn for future processing without affecting processing that was lawful before withdrawal. A more specific notice shown at collection controls if it identifies a different purpose or basis.

Sources of information

moned receives information directly from users and representatives; from interactions with experts, support, enabled bookings, communications, and transactions; from connected services a user authorizes; and from service providers that return delivery, security, verification, or payment status. moned may also use public professional registers and public profile information to review an expert's stated professional scope. If information was obtained indirectly, a rights response can identify the relevant source category unless an applicable exception prevents disclosure.

AI-assisted processing

moned may send bounded search, recent conversational context, compact public marketplace facts, or session inputs to configured cloud AI providers for discovery interpretation and wording, consented transcription, or session summaries. moned's backend controls expert facts, availability, prices, and every permitted operation; rich cards and selectors are application-owned. Recognizable payment credentials and first-person sensitive-category disclosures are rejected before assistant persistence or provider use, but users should still enter only a general help need. See the AI Policy.

Current matching, routing, support, and enforcement tools assist human or user-directed decisions. moned does not use these tools to make a solely automated decision that produces legal or similarly significant effects. If that changes, the applicable notice must describe the logic, significance, expected consequences, and available human-review rights before activation.

Service providers and international transfers

Current provider categories include cloud hosting and AI processing, authentication, payment processing, video communication, email delivery, storage, malware scanning where configured, and error monitoring where enabled. Stripe, Google services, LiveKit, and Sentry are used only by the relevant product surfaces and configuration.

Some providers or support operations may process information outside the country where it was collected. Where EU or UK transfer rules apply and an adequacy decision is unavailable, moned uses an approved transfer mechanism such as the European Commission's Standard Contractual Clauses, together with supplementary safeguards where required. People may request information about the applicable safeguard through the privacy contact.

Google does not use moned's prompts to train or fine-tune models without permission. Google approved moned's project-level exception from prompt logging for abuse monitoring. This approval concerns the provider's abuse-monitoring prompt logging. It does not change moned's own retention rules or processing required to operate and secure the service.

Google Calendar and Limited Use

moned uses Google Calendar data only to check availability, prevent booking conflicts, and create, reschedule, or cancel moned session events on the calendar a user connects. moned keeps imported events as private busy-time blocks and does not use their titles, descriptions, attendees, locations, conference links, or other event content.

Calendar data is not sold, used for advertising, or used to train generalized AI models. Human access is limited to cases where a user gives explicit support consent, a security investigation requires access, or access is required by law.

moned's use and transfer of information received from Google Workspace APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.

Users can disconnect Google Calendar from Calendar connections. Disconnecting stops future synchronization and removes the associated connection data. Expired imported busy-time blocks are removed through moned's Calendar retention process.

Tax-data safeguards and sharing

Raw tax identifiers and identity payloads are encrypted using the private credential-vault path. Product surfaces display only masked values and non-sensitive verification status. Tax admins receive role-scoped access; payment operators receive only payout reason projections rather than raw tax identity. Sensitive changes and exports require MFA step-up and, where specified, a different proposer and approver.

moned may share the minimum required information with tax authorities, reporting authorities, payment processors, filing or validation providers, professional advisers, or other recipients where an approved workflow and legal basis apply. Stripe Tax is the selected initial transaction-tax calculator and the European Commission's VIES service is the selected EU VAT-ID source, but both remain inactive in disabled and shadow modes. Filing remains provider-neutral. Provider results are minimized and do not replace moned's retained decision and audit record.

Retention and deletion

Retention follows purpose and record type rather than one blanket period. Anonymous legacy AI-search records are eligible for seven-day cleanup. When conversational guidance is enabled, anonymous free-form turns are retained for up to 24 hours and their bounded structured conversation for up to seven days. For signed-in users, free-form conversation wording is retained for up to 30 days and bounded structured history, typed results, and summaries for up to 90 days. Raw consented discovery events are retained for up to 90 days and aggregate totals for up to 13 months. Browser consent records are candidates for deletion after approximately three years.

Consented raw session microphone audio is targeted for deletion promptly after successful transcription. If transcription or cleanup fails, it is retained only for recovery and targeted for deletion within seven days. Internal speaker-labelled transcripts have a 30-day target. Shared session summaries have a 365-day target unless erased earlier. Consent withdrawal stops further capture, cancels summary processing where possible, and creates a deletion candidate for captured raw audio.

Expert attestations and booking acknowledgements are versioned, append-only records retained with the relevant application, booking, dispute, and applicable statutory record. They are not used as substitutes for the underlying application or booking evidence.

Current support policy targets are two years for closed general and feature cases, 18 months for product bugs, three years for conduct, booking/payment, privacy, and appeal cases, and five years for coordinated security disclosures. These are retention candidates while destructive workers remain in observe mode. moned will describe these targets as enforced deletion periods only after a verified enforcement canary proves complete database, object-storage, and domain acknowledgements. Legal holds pause every deletion path. Invoices, booking and payment evidence, tax identity and decision records, seller-reporting snapshots, filings, corrections, and commercial correspondence follow applicable statutory recordkeeping and restriction periods.

Authenticated users can remove individual assistant conversations, clear assistant history, remove supported search history, and use account-deletion controls. Deletion does not remove records that moned must retain for tax, accounting, reporting, payment, fraud-prevention, dispute, or legal-hold purposes. Access is restricted after the ordinary product purpose ends.

Choices, rights, and complaints

Depending on location, people may have rights to access, correct, erase, restrict, object, withdraw consent, or receive portable data. Access and portability are different rights: access provides a copy and contextual information about processing, while portability covers eligible information supplied by or observed from the requester in a structured, commonly used, machine-readable format where the legal conditions apply.

For requests governed by EU law, moned responds without undue delay and normally within one calendar month of receipt. A complex request or multiple requests may permit an extension of up to two additional months; moned must communicate the extension and its reason before the original deadline. Identity or representative authority may need proportionate verification before disclosure or action. Government ID is not requested by default.

Submit a request through the privacy request form or email privacy@moned.ai. People also have the right to complain to a competent supervisory authority, including the Hamburg Commissioner for Data Protection and Freedom of Information where it is competent. Contacting moned first is optional and does not limit that right.

Security

moned uses access control, encryption, audit, private storage, and governed administrative patterns appropriate to the relevant system. No internet service can promise absolute security. Vulnerabilities should be reported to security@moned.ai or through the dedicated disclosure form.

Privacy Policy | moned