View policy contents
Purpose and Roles
This page summarizes how Moil Enterprise Inc. processes personal data on behalf of business customers (for example, employers who process applicant data through the Services). For most such processing, the customer is the "controller" and Moil acts as a "processor". A signed DPA is available on request.
Scope and Instructions
We process customer personal data only to provide the Services and according to the customer's documented instructions, the Terms and Conditions, and applicable law.
Confidentiality and Security
Personnel authorized to process personal data are bound by confidentiality, and we maintain technical and organizational measures appropriate to the risk, including encryption in transit and access controls.
Subprocessors
We engage the subprocessors listed on our Subprocessors page to help deliver the Services, under contracts that impose data-protection obligations. We remain responsible for their performance. We will give the customer notice before adding or replacing a subprocessor that processes customer personal data, and the customer may object on reasonable data-protection grounds; if we cannot accommodate the objection, the customer may terminate the affected Services.
4a. AI Providers and Model Training
Some subprocessors are AI providers, and content the customer submits may be sent to them to generate a response. We instruct those providers not to use customer content to train their models, to the extent each provider's API terms allow. We do not control their internal practices and make no representation beyond that instruction. Two AI providers we use are headquartered in China and one is part of the ByteDance group; the Subprocessors page identifies each by name and headquarters. A customer that requires processing limited to United States-headquartered providers should contact us before submitting data.
Data Subject Requests
We assist the customer, taking into account the nature of processing, in responding to requests from individuals to exercise their rights under applicable privacy laws.
Personal Data Breaches
We will notify the customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting customer personal data, and provide the information reasonably needed for the customer to meet its own notification obligations. Where Moil is itself required to notify individuals under state breach-notification law, we do so within the period that law allows.
Return and Deletion
On termination, and at the customer's choice, we will delete or return customer personal data, except where retention is required by law.
International Transfers
Moil's infrastructure processes data in the United States. Where personal data originating in the European Economic Area or the United Kingdom is transferred, we rely on the Standard Contractual Clauses or another lawful transfer mechanism. Separately, some AI subprocessors are headquartered outside the United States, including in China; that is disclosed by name on the Subprocessors page rather than left to a general clause, because a customer cannot assess a transfer it has not been told about.
8a. California: Service Provider Terms
For personal information the customer discloses to us that is subject to the California Consumer Privacy Act as amended, Moil Enterprise Inc. acts as a "service provider". We are prohibited from, and will not: sell or share that personal information; retain, use, or disclose it for any purpose other than performing the Services specified in the agreement, or as otherwise permitted by the CCPA; retain, use, or disclose it outside the direct business relationship with the customer; or combine it with personal information received from another source, except as the CCPA permits. We will notify the customer if we determine we can no longer meet these obligations, and the customer may take reasonable steps to stop and remediate unauthorized use.
Audits
On reasonable request and subject to confidentiality, we will make available information necessary to demonstrate compliance with these obligations.
Requesting a Signed DPA
To execute a DPA, email cs@moilapp.com.