Molinia

Version 2026-08-24 · Effective August 24, 2026

Privacy Policy

This policy explains how Unpinned B.V., trading as Molinia, collects, uses, stores, and protects your personal data, and describes your rights under the GDPR and applicable EU data protection law.

1. Data Controller

The data controller responsible for your personal data is:

Unpinned B.V. (trading as Molinia)

Amsterdamsestraatweg 325C, 3551 CJ Utrecht, Netherlands

KvK: 72410930

Email: privacy@molinia.eu

Imprint: /legal/imprint

Where Molinia processes personal data that your organisation uploads to the platform (i.e., the personal data of your own customers or employees), your organisation is the data controller and Molinia acts as data processor under the terms of ourData Processing Agreement. This Privacy Policy addresses Molinia's role as controller of the data it collects directly from users of the platform.

2. Personal Data We Collect

We collect personal data about you in the following categories:

2.1 Account and Identity Data

  • Full name and email address (provided at registration)
  • Company or organisation name
  • Job title or role (where provided)
  • Account credentials: password hash (bcrypt; plaintext password is never stored)
  • Two-factor authentication secrets (encrypted at rest)
  • Terms acceptance record: version and timestamp of Terms of Service acceptance

2.2 Usage and Audit Data

  • Actions taken within the platform (audit log entries): warehouse operations, data ingestion events, SQL queries executed, settings changes, invitations, and session activity
  • Query history: SQL statements you run and their execution metadata (duration, rows returned, compute cost)
  • Feature usage patterns (aggregated and non-aggregated)

2.3 Technical and Security Data

  • IP address and approximate geographic location (used for security monitoring)
  • Browser type and version (from User-Agent header)
  • Session identifiers and authentication tokens
  • Timestamps of login, logout, and other security-relevant events

2.4 Communications Data

  • Email correspondence with Molinia support or legal teams
  • Feedback submitted through the platform

2.5 Website Analytics Data (public marketing site only)

When you visit the public marketing site at molinia.eu, we collect aggregate usage measurements through Plausible Analytics. This is limited to:

  • The page visited and the referring URL
  • Browser, operating system, and device type
  • Country, derived from the IP address
  • A count of clicks on the "Create free account" call to action

No cookies, no cross-site identifiers, and no persistent visitor identifier are used, and IP addresses are not stored. These measurements are aggregate and cannot be linked to an individual or to a Molinia account. This applies to the marketing site only — the Molinia platform itself carries no analytics or tracking scripts.

We do not collect sensitive personal data (GDPR Article 9 categories) and do not knowingly collect personal data from persons under 18 years of age.

3. Purposes and Legal Bases for Processing

We process your personal data for the following purposes and rely on the following legal bases under GDPR Article 6:

PurposeLegal basis
Creating and managing your account; providing the platform serviceContract (Art. 6(1)(b))
Billing and invoicing; payment processingContract (Art. 6(1)(b))
Sending service notifications, security alerts, and transactional emailsContract (Art. 6(1)(b))
Security monitoring, fraud detection, and anomaly detectionLegitimate interests (Art. 6(1)(f))
Maintaining tamper-evident audit logs for platform integrityLegitimate interests (Art. 6(1)(f))
Compliance with legal obligations (e.g., tax records, law enforcement requests)Legal obligation (Art. 6(1)(c))
Improving and developing new platform features (using aggregated, anonymised data)Legitimate interests (Art. 6(1)(f))
Responding to support enquiries and resolving disputesLegitimate interests (Art. 6(1)(f))
Sending product updates and feature announcements to existing customersLegitimate interests (Art. 6(1)(f))
Measuring aggregate usage of the public marketing site (cookieless analytics)Legitimate interests (Art. 6(1)(f))

Where we rely on legitimate interests, we have assessed that these interests are not overridden by your rights and freedoms. You have the right to object to processing based on legitimate interests (see Section 7).

4. Subprocessors and Data Recipients

We do not sell, rent, or trade your personal data. We share personal data with third parties only as follows:

4.1 Subprocessors

We engage the following subprocessors to deliver the Service:

SubprocessorPurposeLocationTransfer mechanism
Leafcloud B.V.VPS / compute and storage infrastructure hostingAmsterdam, Netherlands (EU)EU — no transfer
Google LLC (Workspace)Transactional email delivery (SMTP relay)EU datacentresSCCs (Module 2, Decision 2021/914)
Plausible Insights OÜCookieless analytics for the public marketing site; no access to platform or customer dataEstonia (EU); data stored in the EUEU — no transfer

4.2 Legal Disclosure

We may disclose personal data to competent authorities, courts, or regulators where required by applicable law, a legally valid court order, or to protect our legal rights. We will notify you of such a disclosure to the extent permitted by law.

4.3 Business Transfers

In the event of a merger, acquisition, or sale of all or substantially all of our business or assets, personal data may be transferred to the successor entity, which will continue to be bound by this Privacy Policy or a materially equivalent one.

5. International Data Transfers

Molinia stores and processes personal data within the European Union (EU). Our primary infrastructure is hosted by Leafcloud B.V. in Amsterdam, which does not involve any transfer of data outside the EU/EEA.

For transactional email delivery we use Google LLC under Standard Contractual Clauses (SCCs) as adopted by the European Commission (Decision 2021/914, Module 2: controller-to-processor). A copy of the applicable SCCs is available upon written request to privacy@molinia.eu.

Analytics for the public marketing site are provided by Plausible Insights OÜ (Estonia), which stores its data within the EU. This does not involve any transfer of personal data outside the EU/EEA.

Before engaging any new subprocessor that involves a transfer of personal data outside the EU/EEA, we ensure that appropriate safeguards under GDPR Chapter V are in place.

6. Data Retention

We retain personal data only for as long as necessary for the purposes for which it was collected, or as required by applicable law:

Data categoryRetention period
Account data (name, email, company)Duration of subscription + 30 days post-closure
Audit log entriesMinimum 365 days (for security and compliance)
Query history and session data90 days rolling
Billing records and invoices7 years (Dutch tax and accounting law)
Security and access logs (IP, timestamps)90 days rolling
Free-tier workspace dataPurged after 30 days of inactivity
Support correspondence3 years from last interaction

Following the applicable retention period, personal data is securely deleted or irreversibly anonymised. You may request early deletion subject to the exceptions described in Section 7.

7. Your Rights Under the GDPR

As a data subject under the GDPR, you have the following rights. To exercise any of these rights, contact us atprivacy@molinia.eu. We will respond within one month, or within three months where the request is complex or numerous (with notice of the extension).

Right of access (Art. 15)

You have the right to obtain confirmation of whether we process your personal data and, if so, to receive a copy of that data along with information about how it is processed.

Right to rectification (Art. 16)

You have the right to have inaccurate personal data corrected. You can update most account details directly in your account settings.

Right to erasure / "right to be forgotten" (Art. 17)

You may request deletion of your personal data where it is no longer necessary, where you withdraw consent (where processing is based on consent), or where you object and there is no overriding legitimate interest. Some data may be retained where required by law (e.g., billing records) or for security purposes.

Right to restriction of processing (Art. 18)

You may request that we restrict processing of your personal data in certain circumstances, such as while a dispute about accuracy or lawfulness is resolved.

Right to data portability (Art. 20)

Where processing is based on contract or consent and carried out by automated means, you have the right to receive your personal data in a structured, commonly-used, machine-readable format. The Service provides data export functionality for your Customer Data.

Right to object (Art. 21)

You may object at any time to processing based on our legitimate interests (including direct marketing). We will cease such processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.

Right to withdraw consent

Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.

Right to lodge a complaint (Art. 77)

You have the right to lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens (AP), atwww.autoriteitpersoonsgegevens.nl, if you believe we have not complied with applicable data protection law. We encourage you to contact us first so we can address your concern.

Identity verification: to protect your data, we may need to verify your identity before fulfilling a request. We will not use your data for purposes other than verification.

8. Cookies and Similar Technologies

The Molinia platform does not set any HTTP cookies. Authentication is handled entirely through JWT Bearer tokens, which are stored in browserlocalStorage and sent via the HTTP Authorization header — not as cookies. localStorage is not subject to the ePrivacy Directive cookie rules; no consent banner is required.

The public marketing site at molinia.eu does not set any cookies. Analytics on the marketing site use Plausible Analytics, operated by Plausible Insights OÜ (Estonia), a privacy-preserving, cookieless service that does not use cookies, cross-site identifiers, or any persistent tracking mechanism. Because no information is stored on or read from your device, no consent banner is required. What is collected is described in Section 2.5, and the subprocessor entry is in Section 4.1.

We do not use advertising cookies, analytics tracking pixels, third-party marketing scripts, or any other non-essential cookies or trackers on any part of the platform.

9. Security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration, or destruction. These measures include:

  • Encryption of data in transit using TLS 1.2 or higher
  • Encryption of sensitive data at rest (passwords are hashed using bcrypt; 2FA secrets are encrypted using AES-256)
  • Role-based access controls within the platform enforcing least-privilege access
  • Tamper-evident audit logging with hash-chaining
  • Brute-force protection on authentication endpoints
  • Regular automated backups with tested restore procedures
  • Multi-tenant data isolation preventing cross-customer data access

In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay in accordance with GDPR Article 34. We will also notify the Autoriteit Persoonsgegevens within 72 hours where required.

To report a suspected security vulnerability, contactsecurity@molinia.eu.

10. Changes to This Policy

We may update this Privacy Policy from time to time. The version number and effective date at the top of this page will reflect any changes. Material changes will be communicated to you by email or via a notice within the platform at least 30 days before taking effect.

Your continued use of the Service after the effective date of an updated Privacy Policy constitutes your acceptance of the changes. If you do not accept the updated policy, you must stop using the Service.

11. Contact and DPO

For all privacy-related enquiries, requests, or complaints, contact our privacy team:

Email: privacy@molinia.eu

Postal address: see imprint

We aim to respond to all privacy requests within 5 business days to acknowledge receipt and within 30 days for substantive responses.