Privacy Policy
Last updated: 21 August 2026
This Privacy Policy explains how Moods AI B.V. ("Moods AI", "we", "us") collects, uses, stores, shares, and deletes personal data when people use our website, platform, and integrations.
Who Is Responsible for the Data?
Moods AI is the controller for data concerning its own website, customer contacts, user accounts, security, and service administration.
When a healthcare organization uses Moods AI to process data about its personnel, clients, suppliers, patients, or other contacts, that organization normally determines the purpose of the processing and remains the controller. Moods AI processes that data on the organization's instructions under the applicable service agreement and data processing agreement.
People whose data was supplied by a customer organization should normally contact that organization first. They may also contact Moods AI using the details below.
Data We Collect and Store
Depending on the services and integrations an organization enables, we may process the following categories of data.
Account and Service Data
- Names, business contact details, organization membership, roles, and permissions
- Authentication, session, and account-security information
- Subscription, invoicing, and payment-reference information
- Support requests and communications with Moods AI
Customer-Provided Service Data
- Organizational, operational, financial, workforce, referral, appointment, and reporting data entered into or supplied to Moods AI
- Documents, recordings, transcripts, and other content uploaded or generated through an enabled service
- Special-category personal data, including health-related data, only where an organization uses a contracted feature that requires it and has a lawful basis for doing so
Technical and Security Data
- IP address, browser and device information, timestamps, requested pages, and session information
- Application events, synchronization status, error codes, security events, and audit records
- Cookie and similar-technology data as described in our Cookie Policy
Exact Online Integration
When an authorized organization user connects Exact Online, the categories below may be collected from the selected Exact Online administration, depending on the organization's Exact licence, the connecting user's Exact permissions, the scopes approved by the organization, and the Moods AI modules it uses.
- Connection data: administration number and name, connection status, synchronization timestamps, encrypted OAuth access and refresh tokens, and security and audit events
- CRM and commercial data: accounts, business contacts and addresses, opportunities, quotations, sales orders, sales invoices, contracts, subscriptions, items, and prices
- Purchasing data: suppliers, purchase orders, purchase invoices, contracts, prices, payment conditions, and related entries
- Financial data: journals, general-ledger accounts and classifications, transaction lines, bank and cash entries, balances, financial periods, currencies, VAT information, receivables, payables, payments, returns, budgets, assets, depreciation data, cost centres, and cost units
- Project and operational data: projects, planning, time and cost transactions, billing information, items, and inventory information
- Workforce and payroll data: employees, employment relationships and contracts, departments, job information, schedules, leave and absence data, salary information, payroll components and transactions, tax-related employment data, and employee bank-account data where Exact HR or Payroll is used
- Administration data: administration details, approved business documents and workflow records, synchronization deletion events, and definitions needed to interpret customer-specific fields
The Exact Online connector uses read-only access. Moods AI does not create, change, or delete records in Exact Online. The connector is intended for relevant business, workforce, financial, and administrative information; it is not intended to import clinical records, treatment notes, or mailbox contents.
How We Collect Data
We collect data:
- Directly from users when they register, configure the service, submit a form, upload content, or contact us
- From customer organizations and their authorized users
- Automatically through normal use of the website and platform
- From connected services after an authorized user initiates and approves an integration
For Exact Online, an authorized user starts the connection in Moods AI and is redirected to Exact Online. Exact Online authenticates the user and requests authorization for the approved read scopes. After authorization, Moods AI exchanges the temporary authorization code for encrypted credentials, imports the available history through the Exact Online API, and performs scheduled synchronization. No Exact administration data is imported before authorization succeeds.
How We Use Data
We use personal and business data to:
- Provide, operate, secure, and support Moods AI
- Authenticate users and enforce organization roles and permissions
- Import, synchronize, validate, reconcile, and retain data from authorized integrations
- Provide historical reporting, dashboards, organizational analysis, and contracted operational features
- Monitor reliability, investigate incidents, prevent misuse, and maintain audit trails
- Process subscriptions and comply with contractual and legal obligations
- Respond to questions, rights requests, and support requests
- Improve the service using appropriately protected, minimized, or aggregated information
Exact Online data is not sold or used for third-party advertising. The historical import and structured synchronization do not send Exact business records to an AI model. If a future contracted analytics or AI feature processes derived Exact data, its purpose, safeguards, and applicable processors will be documented before that processing is enabled.
Legal Bases
Depending on the context, processing is based on performance of a contract, compliance with legal obligations, legitimate interests in operating and securing the service, or consent where consent is the appropriate legal basis. Customer organizations are responsible for establishing a lawful basis for the data they instruct Moods AI to process.
Exact Online authorization is granted by an authorized user through Exact's OAuth flow and can be withdrawn as described below.
Sharing and Service Providers
We share data only where needed to provide and secure the service, follow a customer's documented instructions, or comply with law. Relevant recipients may include:
- Microsoft Azure: application hosting, database storage, key and secret management, and operational monitoring. The primary Moods AI production environment and Exact data store are hosted in Azure's France Central region.
- Sentry: limited application error and performance monitoring data, such as technical routes, error information, and user or organization identifiers where required for investigation. We do not intentionally include imported Exact business-record content in Sentry telemetry.
- Exact Online: authorization and API communication required to establish and maintain the integration.
- Other contracted providers used for specific enabled services, such as payment, email, communications, or approved AI functionality.
Processors are required to act under contractual safeguards and only for the purposes for which they were engaged. We do not sell personal data.
Where a provider processes data outside the European Economic Area, we use an applicable lawful transfer mechanism and appropriate contractual safeguards.
Data Retention and Deletion
We retain data only for as long as needed for the purposes described in this policy, the customer agreement, security and audit requirements, or applicable law.
- Account and customer-service data is retained while the account or customer relationship remains active and is then deleted or anonymized, unless continued retention is required by contract or law.
- Exact OAuth credentials are retained only while the connection remains authorized. Disconnecting Exact removes the stored access and refresh tokens and stops future synchronization.
- Imported Exact history is retained while the customer organization uses Moods AI. Disconnecting the integration does not automatically delete previously imported data, because the organization may need its historical reports or may reconnect later.
- An authorized organization representative can request deletion of the organization's imported Exact data at any time. After verifying the request and the requester's authority, we delete active copies without undue delay and normally within 30 days, unless an agreed or legal retention obligation applies.
- Ordinary technical telemetry is normally retained for no longer than 90 days. Security, compliance, and audit records may be retained longer where needed to investigate an incident or meet contractual or legal requirements.
- Data removed from active systems may remain in protected backups until those backups expire through the normal backup-rotation cycle. Backups are not used for ordinary processing and deleted data is not restored except where necessary for disaster recovery or legal obligations.
Withdrawing Authorization and Requesting Deletion
An authorized organization user can stop future Exact collection by selecting Disconnect in the Moods AI Exact Online integration settings. Authorization can also be revoked from Exact Online. Disconnecting removes the stored OAuth authorization and stops scheduled synchronization, but it does not by itself delete previously imported history.
To request deletion of imported Exact data or other personal data, email info@moodsai.ai. Include the organization name, your business contact details, and the administration or integration concerned. Do not include unnecessary sensitive data in the email. We may request additional information to verify identity and authority before acting on the request.
Where processing relies on consent, consent may be withdrawn at any time. Withdrawal does not affect processing that occurred lawfully before withdrawal.
Individual Rights
Subject to applicable law, individuals may have the right to:
- Access their personal data
- Correct inaccurate or incomplete data
- Request deletion or restriction of processing
- Object to certain processing
- Receive portable data where applicable
- Withdraw consent where processing is based on consent
- Lodge a complaint with the Dutch Data Protection Authority or another competent supervisory authority
Because Moods AI often acts as a processor, we may refer a request to the customer organization that controls the data and assist that organization in responding.
Security
We use technical and organizational safeguards designed to protect data against unauthorized access, loss, alteration, or disclosure. These include TLS in transit, application-level AES-256-GCM encryption for Exact OAuth tokens and imported raw or sensitive Exact fields, tenant isolation, role-based access controls, private database networking, Azure Key Vault, audit logging, automated testing, and vulnerability scanning.
No system can guarantee absolute security. We assess risks and update safeguards as the service changes.
Changes to This Policy
We may update this policy when our services, integrations, processors, or legal obligations change. The current version and its last-updated date are published on this page. Material changes will be communicated where required.
Contact Us
For privacy questions, withdrawal, or deletion requests, contact:
Moods AI B.V., Keizersgracht 391 A, 1016 EJ Amsterdam, The Netherlands
Email: info@moodsai.ai