Version 2026-08-07 · Effective August 7, 2026
Data Processing Agreement
This Data Processing Agreement ("DPA") is entered into between Molinia B.V.("Processor") and the Customer accepting the Terms of Service ("Controller"). It forms part of the Terms of Service and is incorporated by reference. It governs Molinia's processing of personal data on behalf of the Controller in accordance with GDPR Article 28.
1. Definitions
Capitalised terms used but not defined in this DPA have the meanings given in the Terms of Service. The following additional definitions apply:
- "Controller" means the Customer entity that determines the purposes and means of processing personal data.
- "Processor" means Molinia B.V., acting on the documented instructions of the Controller.
- "Data Subject" means any identified or identifiable natural person whose personal data is processed under this DPA.
- "Personal Data" has the meaning given in GDPR Article 4(1): any information relating to an identified or identifiable natural person.
- "Processing" has the meaning given in GDPR Article 4(2), and includes any operation performed on personal data such as collection, storage, retrieval, use, disclosure, or erasure.
- "GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016.
- "Sub-processor" means any third-party processor engaged by Molinia to process personal data on behalf of the Controller.
- "Security Incident" means any breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data processed under this DPA.
2. Subject Matter and Details of Processing
2.1 Subject matter
The subject matter of this DPA is Molinia's processing of personal data contained within data sets uploaded, ingested, or otherwise provided by the Controller to the Molinia platform for the purpose of providing the contracted data warehousing, ingestion, transformation, and analytics services.
2.2 Nature and purpose of processing
Molinia processes personal data to: (a) ingest and store data sets provided by the Controller; (b) execute SQL transformations and analytical queries on those data sets as instructed by the Controller's users; (c) enable controlled data sharing with authorised third parties as configured by the Controller; and (d) support backup, recovery, and data lifecycle management operations. Molinia will not process personal data for any purpose other than to provide the Service, unless required by applicable law.
2.3 Types of personal data
The types of personal data processed depend entirely on the data sets uploaded by the Controller. They may include, without limitation: names, email addresses, contact details, transaction records, behavioural data, or any other personal data included in the Controller's data sets. Molinia does not determine or limit the types of personal data the Controller uploads.
2.4 Categories of data subjects
Data subjects may include the Controller's customers, employees, contractors, partners, or other individuals whose personal data appears in the data sets uploaded to the platform.
2.5 Duration of processing
Processing continues for the duration of the Controller's subscription and for the data deletion period following termination set out in the Terms of Service (30 days post-closure, unless a legal hold is in place).
3. Processor Obligations
Molinia, as Processor, agrees that it shall:
3.1 Instructions
Process personal data only on documented instructions from the Controller, as set out in the Terms of Service and as communicated through the Controller's use of the platform, unless required to do so by applicable law (in which case Molinia will inform the Controller of that legal requirement before processing, to the extent permitted by law).
3.2 Confidentiality
Ensure that all persons authorised to process personal data are subject to binding obligations of confidentiality and have received appropriate data protection training.
3.3 Security
Implement and maintain the technical and organisational security measures set out in Section 5 (Annex II — Security Measures) of this DPA. These measures shall ensure a level of security appropriate to the risk, taking into account the state of the art, costs, and nature of the data processed.
3.4 Sub-processor engagement
Not engage sub-processors without prior specific or general written authorisation of the Controller. General authorisation is provided via the sub-processor list in Section 4. Molinia will inform the Controller of any intended changes at least 14 days in advance; the Controller may object in writing within that period.
3.5 Data subject rights
Assist the Controller in fulfilling its obligations to respond to data subject rights requests under GDPR Chapter III (access, rectification, erasure, restriction, portability, objection), taking into account the nature of the processing and the information available to Molinia. The Controller is responsible for managing the relationship with its data subjects.
3.6 Security and compliance assistance
Assist the Controller in ensuring compliance with GDPR Articles 32–36 (security obligations, breach notification, DPIAs, prior consultation), taking into account the nature of processing and information available to Molinia.
3.7 Deletion or return of data
At the Controller's choice and within 30 days of the end of the service period, delete or return all personal data to the Controller in machine-readable format, and delete existing copies, unless retention is required by applicable law. Molinia will certify deletion in writing upon request.
3.8 Audit and information
Make available all information necessary to demonstrate compliance with this DPA and allow for audits conducted by the Controller or a mandated auditor, on reasonable advance notice (at least 30 days), subject to reasonable confidentiality obligations. Molinia may provide ISO 27001 or equivalent third-party audit reports in lieu of a direct audit where appropriate.
4. Sub-processors
The Controller grants general written authorisation for Molinia to engage the following sub-processors. Molinia will inform the Controller of any intended changes (additions or replacements) at least 14 days before the change takes effect.
| Sub-processor | Purpose | Location | Transfer mechanism |
|---|---|---|---|
| Leafcloud B.V. | Compute, storage, and VPS infrastructure | Amsterdam, Netherlands (EU) | EU — no transfer outside EEA |
| Google LLC (Google Workspace) | Transactional email relay (system notifications) | EU datacentres | SCCs Module 2 (Decision 2021/914) |
Molinia will impose data protection obligations on all sub-processors at least equivalent to those in this DPA by way of a written contract (GDPR Article 28(4)). Molinia remains fully responsible to the Controller for the performance of sub-processors' obligations.
5. Technical and Organisational Security Measures
Molinia implements and maintains the following technical and organisational measures (TOMs) to protect personal data processed under this DPA. These measures reflect the current state of implementation and will be updated as the product evolves.
5.1 Encryption
- All data in transit is encrypted using TLS 1.2 or higher
- Passwords are hashed using bcrypt (adaptive, salted)
- Two-factor authentication secrets are encrypted using AES-256
- Database backups are encrypted at rest
5.2 Access controls
- Role-based access control (RBAC): Owner, Admin, and Member roles with least-privilege enforcement
- Multi-factor authentication (TOTP/FIDO2) available and enforceable at organisation level
- API keys scoped and revocable per user
- Session management with revocable tokens and automatic expiry
- Brute-force and rate-limit controls on authentication endpoints
5.3 Multi-tenant isolation
- Physical isolation of customer warehouses at the storage layer
- Row-level security policies enforced at the database layer
- Strict organisation-scoping on all API endpoints
5.4 Audit logging and integrity
- Tamper-evident audit log with SHA-256 hash chaining
- All security-relevant events logged with timestamps and actor identity
- Audit logs retained for a minimum of 365 days
5.5 Availability and resilience
- Automated daily backups with tested restore procedures
- Point-in-time recovery capability
- Monitoring and alerting for service degradation
5.6 Organisational measures
- Security awareness training for all staff with access to production systems
- Principle of least privilege for internal access to customer data
- Documented incident response and breach notification procedures
- Regular security review of code changes via code review processes
6. Security Incident Notification
In the event of a Security Incident affecting personal data processed under this DPA, Molinia will:
- Notify the Controller without undue delay and in any event within72 hours of becoming aware of the incident, to the extent reasonably practicable;
- Provide the Controller with the following information as it becomes available: (a) description of the nature of the incident, categories and approximate number of data subjects and records affected; (b) name and contact details of the data protection contact; (c) likely consequences of the incident; (d) measures taken or proposed to address the incident;
- Cooperate with the Controller's investigation and take all reasonable steps to contain and remediate the incident; and
- Not make any public disclosure regarding a Security Incident without the Controller's prior written consent (except where required by law).
The Controller is responsible for any notification obligations it may have to supervisory authorities and affected data subjects. Molinia's notification of a Security Incident does not constitute an acknowledgement of fault or liability.
Security incidents should be reported to Molinia atsecurity@unpinned.nl.
7. International Data Transfers
Personal data processed under this DPA is stored and processed within the EU. Our primary infrastructure (Leafcloud B.V.) is located in Amsterdam, the Netherlands, and does not involve any transfer outside the EU/EEA.
Transfers to sub-processors outside the EU/EEA are governed by Standard Contractual Clauses (SCCs) adopted by the European Commission (Decision 2021/914). The applicable SCC modules are specified in the sub-processor table in Section 4.
If the Controller requires a copy of applicable SCCs or transfer impact assessments, these are available upon written request todpa@unpinned.nl.
8. Audit Rights
The Controller has the right to audit Molinia's compliance with this DPA. Molinia will provide the following, at the Controller's choice:
- Documentation review: Access to relevant policies, procedures, and certifications upon reasonable request and under NDA;
- Third-party audit reports: Molinia may satisfy an audit request by providing a recent ISO 27001, SOC 2 Type II, or equivalent report prepared by an independent auditor; or
- On-site or remote audit: Subject to at least 30 days' written notice, mutually agreed scope, and reasonable confidentiality obligations. The Controller bears the costs of any on-site audit unless the audit reveals a material breach of this DPA.
Audits must not unreasonably disrupt Molinia's business operations. The frequency of audits is limited to once per 12-month period unless a Security Incident has occurred.
9. Term and Termination
This DPA is effective from the date the Controller accepts the Terms of Service and remains in force for the duration of the Terms of Service.
Upon termination or expiry of the Terms of Service, Molinia will, at the Controller's election: (a) return all personal data to the Controller in machine-readable format; or (b) securely delete all personal data — in either case within 30 days of the termination date, except where retention is required by applicable law. Molinia will provide written confirmation of deletion upon request.
Sections 5 (Security Measures), 6 (Incident Notification), and 8 (Audit Rights) survive termination to the extent necessary.
10. Liability
Each party's liability under this DPA is subject to the limitations and exclusions set out in the Terms of Service. Nothing in this DPA shall limit either party's liability for wilful misconduct or gross negligence, or for breach of obligations arising directly from GDPR Article 82 (liability for damages suffered by data subjects), which shall be governed by applicable law.
11. Governing Law
This DPA is governed by and construed in accordance with the laws of the Netherlands. Any disputes arising under this DPA shall be subject to the exclusive jurisdiction of the competent courts of Amsterdam, the Netherlands, consistent with the governing law provision in the Terms of Service.
12. Contact
For all DPA-related enquiries, contact:
Email: dpa@unpinned.nl
Postal address: see imprint