Skip to content

PRIVACY & DATA

Privacy Policy

How MoClarus handles personal information when you use our website or contact us.

Last updated

This Privacy Policy explains how MoClarus handles personal data on the public website, when you contact us, and when you use a MoClarusCRM account.

Who is responsible for your personal data

MoClarus is the data controller for the personal data described in this policy.

MoClarus
Gnejsvägen 6
746 41 Bålsta
Sweden
Swedish company registration no.: 19790613-6473
Email: info@moclarus.com

Public website data

When you view the public website, the hosting environment may process technical data needed to deliver and protect it. This can include an IP address, browser or device information, requested pages, date and time, and server or security log information.

Normal public page views do not set cookies and do not use localStorage, sessionStorage, IndexedDB or service workers. The public pages do not load advertising pixels, session replay, fingerprinting scripts or an active third party analytics service.

Contact form and email

When you use the Contact Us form, we receive the name, company, email address and message you provide. A telephone number is optional. The form emails the message to MoClarus and is not configured to save form submissions in the WordPress database.

To reduce automated submissions, the form uses a short term rate limit. It keeps a keyed, one way value derived from the visitor’s IP address, with a count and start time, for no more than ten minutes. The rate limiter does not store the raw IP address. Form values are not sent to analytics.

Enquiries may remain in the receiving mailbox and related mail systems while they are needed to answer the enquiry, maintain relevant business records or meet legal obligations.

MoClarusCRM account data

If you create a MoClarusCRM account, we process the information needed to register, verify and secure it. This can include your name, email address, username, password hash, verification and password reset records, MFA status, language, profile settings, subscription or trial information, and security events.

The CRM also processes the information you choose to enter or share, such as contacts, relationship details, appointments, tasks, reminders, notes and chat participation data. You are responsible for only entering or sharing information that you have a lawful right to use.

Why we process personal data

We use enquiry data to reply to you and take steps you request before a possible contract. We use CRM account and service data to provide the account and requested functions. These activities may rely on Article 6(1)(b) GDPR.

We process necessary technical, security and audit information under our legitimate interests in providing, maintaining and protecting the website and CRM, under Article 6(1)(f) GDPR. Where records must be kept to meet a legal obligation, Article 6(1)(c) GDPR may apply. We do not use contact form information for marketing unless a separate lawful basis applies.

CRM security measures and limits

CRM passwords are hashed. MFA secrets are encrypted. Personal Chat message content is encrypted in the browser before it reaches the server. When an encrypted CRM backup is configured, its contents are protected with AES-256-GCM.

These controls do not mean that every CRM field is application-encrypted. In the active PostgreSQL setup, ordinary CRM fields and application logs are readable by the application and rely on database, host, access and operational controls for protection. Signed session cookies are not encrypted. They contain the minimum session state used by the application, rather than your name, email address or role.

No online service can guarantee absolute security. Data may also exist in device memory while in use, user-created exports, external backups, device snapshots or systems outside MoClarusCRM’s control.

CRM cookies and browser storage

The CRM uses a necessary signed session cookie for login, session security and CSRF protection. It is HttpOnly, uses SameSite=Lax and is marked Secure in the production PostgreSQL environment. Its current session state includes a user ID, a credential validation value and necessary session metadata.

Personal Chat uses an IndexedDB database in the browser for identity keys, prekeys, conversation security state and locally available message copies. When an account is permanently deleted, the current browser attempts to delete that user’s chat database and related chat storage. If the browser blocks this cleanup, the user is told to clear the site’s local data manually. This cannot clear another device remotely.

Audit and security logs

The CRM records audit events needed to investigate changes and security issues. A request IP address may be attached to an audit event for a short security period. The default technical policy removes the IP field after 30 days while retaining the audit event. The operator can configure this period to match its documented security purpose.

Application logs are used for operation and fault finding. SQL parameters are hidden from database error logs, and normal application logging is designed not to record passwords, tokens, request bodies or Personal Chat plaintext.

Account deletion

Deleting a CRM account removes the active account and records owned by that account. In a multi-user installation, shared records needed by other participants may remain, with the deleted user’s direct identifiers removed where possible. Invitation email copies are removed when they are no longer needed. Audit records may remain in anonymised form, and limited privacy request metadata may remain as a compliance record after its free-text personal content is removed.

If the deleted account is the final account in an installation, the active CRM database and CRM-managed local uploads, backups and logs are cleared. Browser cleanup applies only to the current device. Exports, external backups, device snapshots, storage history and copies held outside the active service follow their own retention or deletion process.

How long we keep personal data

The public contact form rate-limit value expires after no more than ten minutes. CRM account and active service data are kept while the account and service need them, unless the user deletes the account or another documented retention rule applies. Audit events, necessary compliance records and backups may be kept longer where there is a defined security, operational or legal purpose.

Contact and enquiry emails are normally kept for 12 months after the last relevant contact. They may be kept longer if the enquiry becomes part of an active customer relationship, a legal obligation applies, or the information is needed for a dispute or legal claim.

Technical and security logs controlled by MoClarus are normally kept for 30 days. They may be kept longer when needed to investigate a security incident, abuse, fraud or an operational failure, or to meet a legal requirement. Raw IP addresses in CRM audit records are removed after 30 days by default.

Retention for active customer and contract records, accounting records, legal claims and external backups depends on the relevant business, legal or recovery purpose. Provider-level hosting and mail retention also depends on the applicable provider arrangement. MoClarus does not state a fixed period where it has not been verified.

Website guide and optional feedback

The website guide uses short, approved explanations of MoClarus. Your description is processed in your browser. It is not sent to MoClarus or an AI provider, saved on the server or used for training. You can clear it with “Clear my text”. The guide has no access to CRM accounts.

If you tick the optional box in the guide, we count the topic, the page, the language and any helpfulness feedback you choose to give. Only fixed categories and daily totals are saved in MoClarus’ WordPress database. We do not save the question, a visitor identifier or an individual browsing history. The totals cover the latest 90 days; older totals are removed by daily cleanup when the website runs. You can stop future counting by unticking the box. The choice is not saved in a cookie or browser storage.

To limit automated submissions, a keyed, one-way value derived from the connection’s IP address is kept with a count and start time for no more than ten minutes. The guide’s feedback limiter does not save the raw IP address. Normal hosting and security logs may still apply as described above.

Website analytics

The public website does not use general visitor analytics. The guide’s optional, limited feedback counts are described above. Page views, clicks, form activity and visitor identifiers are not sent to the MoClarus owner dashboard or an external analytics provider. The separate general analytics prototype is not active on this WordPress site.

Hosting, mail and other recipients

MoClarus uses Miss Hosting for production web hosting and moclarus.com email. The public contact form sends messages to info@moclarus.com. The current public website configuration does not identify a separate analytics or advertising provider that receives form data.

Personal data may be available to MoClarus and providers that need it to operate the relevant website, mail or CRM service. Miss Hosting may use suppliers or subprocessors and provides data-processing terms for hosted customer data. MoClarus is responsible for ensuring appropriate processor arrangements are in place. MoClarus does not sell personal data.

If an online MoClarusCRM installation uses another hosting or infrastructure provider, that provider must be assessed for the relevant service before personal data is processed there.

International transfers

The production website and moclarus.com email are hosted through Miss Hosting. The currently identified web and mail server infrastructure is in Sweden.

Miss Hosting states that it may use suppliers or partners and that personal data may in some cases be transferred outside the EU or EEA. Processing locations may also depend on the provider used for a particular CRM installation. Where a restricted international transfer applies, MoClarus and the relevant providers must use lawful safeguards appropriate to the transfer.

MoClarus does not state that all personal data remains in Sweden or within the EU or EEA.

Your data protection rights

Depending on the circumstances, you may have the right to request access to, correction of or deletion of your personal data, restriction of processing, data portability, or to object to processing based on legitimate interests. If processing is based on consent, you may withdraw it at any time without affecting earlier lawful processing.

To exercise a right, email info@moclarus.com. We may need to verify your identity, and legal exceptions may apply.

Complaints

You may lodge a complaint with the Swedish Authority for Privacy Protection, Integritetsskyddsmyndigheten (IMY). Information is available on the IMY website.

Updates to this policy

We may update this policy when our services, providers or legal obligations change. The latest version and update date will be published on this page.

A little help

Get the short version of this page, or find somewhere to start with MoClarus.

This is an automatic guide, not a person. Your text stays in your browser. It is not sent to MoClarus or an AI provider, or used for training. How your data is handled