Compliance by design. Auditable by default.

Moozy is built for organisations that answer to a regulator, an auditor or the public. Consent, access control, human oversight and a complete record are part of how every customer journey runs, not features added afterwards.

Audit trail · one customer

  1. SMSConsent to be contacted recorded
  2. WhatsAppIdentity check passed
  3. SystemApplication scored 72 of 100, two reasons, held for review
  4. ReviewerApproved by a credit officer
  5. PayP120.00 confirmed by payment provider

Recorded stepA person decided

Illustrative record.

Governance that runs with the journey

When a message, a form, an identity check and a payment live in separate tools, the evidence does too. Reconstructing what happened to one customer becomes a project.

On Moozy those steps are one journey on one platform, so they produce one record. The same rules apply on WhatsApp, SMS, USSD and web. The same roles decide who can see what. The same log shows what the system did and what a person did.

  • Complete audit trail, exportable for review
  • Consent tracked per customer and per channel
  • Role-based access to customer information
  • Advisory scoring that shows its reasons
  • Human handover and escalation on every channel
  • Data processor under Botswana’s Data Protection Act, 2024, with a published compliance note

A complete audit trail

Every event is logged with its time, its channel and its actor, whether that actor is the customer, the platform or a member of your team. The trail can be exported for an auditor or an investigation.

What happenedWhat the record holds
ConversationsMessages sent and received, the channel, delivery outcome, and any handover to a person.
ConsentOpt-in and opt-out, when it was given and on which channel.
Forms and documentsAnswers as submitted, validation results, and the documents or media collected.
Identity checksWhich checks ran, the result returned by the verification provider, and who reviewed a referral.
Scores and flagsThe score, its band, the inputs and reasons behind it, and the person who made the decision.
PaymentsRequests, customer approvals, provider confirmations, failures, retries and mandate changes.
Actions by your teamWho replied, who took over a conversation and who approved, and when.

Role-based access

Roles decide who can see customer information, who can act on it and who can export it. Sensitive items such as identity documents are limited to the roles that need them.

Example roleWhat it is for
AgentTakes over conversations and replies to customers. Sees the conversation, not the identity documents.
ReviewerDecides referred cases. Sees the documents, check results, score and reasons for the cases assigned to them.
AnalystWorks with reports and exports, without access to individual documents.
AdministratorManages users, roles, journeys and connections.

Example roles. Yours are agreed and configured during setup.

Automation you can explain. People who decide.

Moozy automates the routine. It does not take consequential decisions away from your team.

AI replies can be imperfect, so chatbots answer from your approved information and hand over when a question is out of scope or sensitive.

Scoring is advisory

A score informs a person. It never approves, rejects, prices or underwrites, and it never triggers a payout.

Reasons, not just numbers

Each score comes with its band, the reasons behind it and any flags, so a reviewer can agree or disagree with it.

Held for review

Anything flagged waits for a person. Failed identity checks and exceptions are routed the same way.

Escalation on every channel

Customers can ask for a person, rules escalate reserved topics and exhausted payment retries, and your team can take over a conversation at any point. The agent receives the whole history.

Signals raised as evidence

Conversations can be watched for fraud, scam and compliance signals, which are raised to a person with the evidence.

Data Protection Act, 2024: compliance by design

Your organisation is the data controller and decides what is collected and why. Moozy is the data processor under Botswana’s Data Protection Act, 2024 (Act No. 18 of 2024), handling that information only on your instructions and under a written agreement. Our compliance note sets out how, section by section.

Where data lives

Platform servers in Germany, databases in South Africa and Germany, and the AI model in the Netherlands: each a country with an adequacy decision, so every transfer is permitted under s. 75. Mobile money and identity checks run through partners in Botswana.

Tenant isolation

Every record, export and setting is scoped to one business at the application, service and database level. Nothing one business sees can reach another.

Encryption

Data is encrypted in transit on every link. Encryption at rest is available as a deployment option.

No model training

Customer data never trains a model. Personal details can be masked before a message reaches the AI model, if you choose.

Consent and retention

Consent is recorded in the conversation and withdrawal stops the uses that depended on it. Retention periods are set by you as controller, and expired records pass through a two-stage recycle bin. Data deletion requests

Breach notification

Moozy notifies the affected business without delay with what happened, which records were involved and what has been done, as s. 63 requires.

Card details stay out

Card payments run through a hosted checkout into your own merchant account, so card details never reach Moozy.

Questions from risk, compliance and IT

Is Moozy certified to ISO 27001, SOC 2 or PCI DSS?

No certifications are claimed on this website. We answer due-diligence questionnaires directly during procurement.

Where is customer data hosted?

Platform servers run in Germany, databases in South Africa and Germany, and the AI model in the Netherlands, each a country with an adequacy decision under section 75 of Botswana’s Data Protection Act, 2024. Mobile money and identity checks run through partners in Botswana. If you operate in another market with its own residency rules, raise it during scoping.

Is customer data used to train AI models?

No. The AI model is processed only inside the EU and customer data never trains a model. Personal details can also be masked before a message reaches the model, if you choose.

Do you sign a data processing agreement?

Yes. Moozy processes under a written agreement with each business, as sections 55 and 58 of the Act require, and our sub-processors are bound on the same terms. The compliance note and the agreement are available on request.

Is data encrypted?

Data is encrypted in transit. Encryption at rest is available as a deployment option and is agreed during setup.

Can we export the audit trail?

Yes. The audit trail of conversations, consents, payments, automated actions and team actions can be exported for review.

Can the platform make a decision about a customer on its own?

Not a consequential one. Scoring is advisory and carries its reasons. A person approves, rejects or prices, and anything flagged is held for review.

Does using Moozy make us compliant?

No platform can do that for you. Moozy provides the controls and the evidence. Your obligations are decided by your regulator and your own policies, and we configure journeys to fit them.

Where these controls apply

Send us your due-diligence questions

Bring your risk, compliance and IT teams to the demo. We will walk through the controls against one of your own journeys.