Data hosting
All Mossy data — scan results, claim records, evidence files and audit trails — is stored on EU-based servers in Ireland. Data is never transferred outside the European Economic Area without appropriate safeguards.
GDPR compliance
Mossy is committed to GDPR compliance. All personal data is processed lawfully and transparently. We act as a data processor on behalf of our customers for sustainability communications data. For privacy or data security questions contact hello@mossy.green.
Data retention
- Scan content: 30 days for registered users, not stored for anonymous users
- Claim register and evidence files: stored for the lifetime of your account
- Audit trail: permanently stored — immutable by design
- Account data: deleted within 30 days of account closure
Security practices
- All data encrypted in transit and at rest
- Row-level security on every database table
- Private file storage with signed URL access only
- All data operations through authenticated server functions
- Regular security scanning — zero active vulnerabilities
- Application infrastructure SOC 2 Type II and ISO 27001 certified
Contact
For security concerns or privacy questions: hello@mossy.green
See our full Privacy Policy at mossy.green/privacy