LEGAL · GDPR
Mosaqo and the GDPR
The General Data Protection Regulation gives people in the European Economic Area and the United Kingdom rights over their personal data, and places duties on whoever handles it. This page states which of those duties are Mosaqo’s, which are your workspace’s, and how to exercise a right. Effective August 31, 2026.
QUICK OVERVIEW
What this changes in practice
01
Controller, processor and your workspace
Mosaqo is operated by Andrii Petlovanyi, an individual entrepreneur registered in Ukraine, reachable at hello@mosaqo.app. Ukraine sits outside the European Economic Area; the GDPR applies here because Mosaqo offers its services to people inside it. Which role it takes under the GDPR depends on the data, and that distinction decides who a request should go to.
For your own account — sign-in identity, billing contact, support messages, security session records — Mosaqo is the controller and answers requests directly.
For what a workspace puts into its codes and collects through them — form responses, scan events, uploaded assets — the workspace is the controller and Mosaqo is its processor, acting on documented instructions. If you scanned somebody’s QR code and want your data removed, the business that published the code decides. Mosaqo will pass the request on to that workspace and help it answer.
02
Lawful bases for processing
Every use of personal data needs a lawful basis under Article 6. Mosaqo relies on four of them, and never on legitimate interests where consent is what the law actually requires.
- Performance of a contract — creating your account, storing workspace content, serving redirects and producing the analytics a workspace has enabled.
- Legitimate interests — keeping the service secure, preventing abuse of unauthenticated endpoints, and the operational logs needed to run it.
- Consent — the newsletter and anything else you opt into. You can withdraw it at any time, and withdrawing it does not make earlier processing unlawful.
- Legal obligation — records that tax, accounting or law-enforcement rules require Mosaqo to keep.
03
Your rights under the GDPR
These rights are yours whether or not you pay for Mosaqo, and exercising one costs nothing.
- Access — a copy of the personal data held about you, and what it is used for.
- Rectification — correction of anything inaccurate or incomplete.
- Erasure — deletion of your data where no overriding reason to keep it applies.
- Restriction — a pause on processing while a dispute about accuracy or grounds is settled.
- Portability — your data in a structured, machine-readable format, or sent to another provider.
- Objection — an end to processing that rests on legitimate interests.
- Withdrawal of consent — for anything you opted into, without giving a reason.
04
Automated decisions and profiling
Mosaqo makes no decision about you by automated means that produces a legal or similarly significant effect, so the Article 22 right does not arise. Scan analytics counts events and groups them by time, broad region and device category. It is not built to identify a person, and it is not used to score, rank or profile one.
05
Making a request
Write to hello@mosaqo.app with the subject “GDPR request” and say which right you are exercising. Mosaqo may ask you to prove control of the account or mailbox in question — not to obstruct the request, but because handing personal data to the wrong person is itself a breach.
You will have an answer within one month, as Article 12 requires. An unusually complex request may take up to two further months, in which case you will be told why inside the first month.
06
Data processing agreement
Where your workspace is the controller and Mosaqo the processor, Article 28 requires a written agreement between you. Mosaqo provides one on request: email hello@mosaqo.app with the subject “DPA” and the legal name of the entity that will sign it.
07
Processors, transfers and retention
Mosaqo uses a small set of providers to run the product: application and database hosting, transactional email, object storage for uploaded assets, and the sign-in providers you choose to use. Each is bound by a processing agreement and handles data only to deliver its part of the service. None receives personal data for its own purposes, and Mosaqo neither sells personal data nor uses it for advertising.
Some of those providers operate outside the European Economic Area. Where they do, the transfer rests on an adequacy decision of the European Commission or on the Commission’s standard contractual clauses.
Scan events are deleted when the workspace retention period expires, 90 days by default. Account and workspace data is kept while the account exists and removed when it is closed, except where a legal obligation requires a copy to be held longer.
08
Security, breaches and complaints
Data is encrypted in transit, access to production systems is limited to the people who operate them, and secrets are stored apart from application data.
If a breach occurs that is likely to put your rights at risk, Mosaqo notifies the competent supervisory authority within 72 hours of becoming aware of it, and tells affected people directly where the risk to them is high.
If you are not satisfied with how a request was handled, you can complain to the data protection authority of the country you live or work in. You do not have to come to Mosaqo first, though it is usually faster.
NEXT STEP