Molinia

Version 2026-08-07 · Effective August 7, 2026

Privacy Policy

This policy explains how Molinia B.V. collects, uses, stores, and protects your personal data, and describes your rights under the GDPR and applicable EU data protection law.

1. Data Controller

The data controller responsible for your personal data is:

Molinia B.V.

Registered in the Netherlands

Email: privacy@unpinned.nl

Imprint: /legal/imprint

Where Molinia processes personal data that your organisation uploads to the platform (i.e., the personal data of your own customers or employees), your organisation is the data controller and Molinia acts as data processor under the terms of ourData Processing Agreement. This Privacy Policy addresses Molinia's role as controller of the data it collects directly from users of the platform.

2. Personal Data We Collect

We collect personal data about you in the following categories:

2.1 Account and Identity Data

  • Full name and email address (provided at registration)
  • Company or organisation name
  • Job title or role (where provided)
  • Account credentials: password hash (bcrypt; plaintext password is never stored)
  • Two-factor authentication secrets (encrypted at rest)
  • Terms acceptance record: version and timestamp of Terms of Service acceptance

2.2 Usage and Audit Data

  • Actions taken within the platform (audit log entries): warehouse operations, data ingestion events, SQL queries executed, settings changes, invitations, and session activity
  • Query history: SQL statements you run and their execution metadata (duration, rows returned, compute cost)
  • Feature usage patterns (aggregated and non-aggregated)

2.3 Technical and Security Data

  • IP address and approximate geographic location (used for security monitoring)
  • Browser type and version (from User-Agent header)
  • Session identifiers and authentication tokens
  • Timestamps of login, logout, and other security-relevant events

2.4 Communications Data

  • Email correspondence with Molinia support or legal teams
  • Feedback submitted through the platform

We do not collect sensitive personal data (GDPR Article 9 categories) and do not knowingly collect personal data from persons under 18 years of age.

3. Purposes and Legal Bases for Processing

We process your personal data for the following purposes and rely on the following legal bases under GDPR Article 6:

PurposeLegal basis
Creating and managing your account; providing the platform serviceContract (Art. 6(1)(b))
Billing and invoicing; payment processingContract (Art. 6(1)(b))
Sending service notifications, security alerts, and transactional emailsContract (Art. 6(1)(b))
Security monitoring, fraud detection, and anomaly detectionLegitimate interests (Art. 6(1)(f))
Maintaining tamper-evident audit logs for platform integrityLegitimate interests (Art. 6(1)(f))
Compliance with legal obligations (e.g., tax records, law enforcement requests)Legal obligation (Art. 6(1)(c))
Improving and developing new platform features (using aggregated, anonymised data)Legitimate interests (Art. 6(1)(f))
Responding to support enquiries and resolving disputesLegitimate interests (Art. 6(1)(f))
Sending product updates and feature announcements to existing customersLegitimate interests (Art. 6(1)(f))

Where we rely on legitimate interests, we have assessed that these interests are not overridden by your rights and freedoms. You have the right to object to processing based on legitimate interests (see Section 7).

4. Subprocessors and Data Recipients

We do not sell, rent, or trade your personal data. We share personal data with third parties only as follows:

4.1 Subprocessors

We engage the following subprocessors to deliver the Service:

SubprocessorPurposeLocationTransfer mechanism
Leafcloud B.V.VPS / compute and storage infrastructure hostingAmsterdam, Netherlands (EU)EU — no transfer
Google LLC (Workspace)Transactional email delivery (SMTP relay)EU datacentresSCCs (Module 2, Decision 2021/914)

4.2 Legal Disclosure

We may disclose personal data to competent authorities, courts, or regulators where required by applicable law, a legally valid court order, or to protect our legal rights. We will notify you of such a disclosure to the extent permitted by law.

4.3 Business Transfers

In the event of a merger, acquisition, or sale of all or substantially all of our business or assets, personal data may be transferred to the successor entity, which will continue to be bound by this Privacy Policy or a materially equivalent one.

5. International Data Transfers

Molinia stores and processes personal data within the European Union (EU). Our primary infrastructure is hosted by Leafcloud B.V. in Amsterdam, which does not involve any transfer of data outside the EU/EEA.

For transactional email delivery we use Google LLC under Standard Contractual Clauses (SCCs) as adopted by the European Commission (Decision 2021/914, Module 2: controller-to-processor). A copy of the applicable SCCs is available upon written request to privacy@unpinned.nl.

Before engaging any new subprocessor that involves a transfer of personal data outside the EU/EEA, we ensure that appropriate safeguards under GDPR Chapter V are in place.

6. Data Retention

We retain personal data only for as long as necessary for the purposes for which it was collected, or as required by applicable law:

Data categoryRetention period
Account data (name, email, company)Duration of subscription + 30 days post-closure
Audit log entriesMinimum 365 days (for security and compliance)
Query history and session data90 days rolling
Billing records and invoices7 years (Dutch tax and accounting law)
Security and access logs (IP, timestamps)90 days rolling
Free-tier workspace dataPurged after 30 days of inactivity
Support correspondence3 years from last interaction

Following the applicable retention period, personal data is securely deleted or irreversibly anonymised. You may request early deletion subject to the exceptions described in Section 7.

7. Your Rights Under the GDPR

As a data subject under the GDPR, you have the following rights. To exercise any of these rights, contact us atprivacy@unpinned.nl. We will respond within one month, or within three months where the request is complex or numerous (with notice of the extension).

Right of access (Art. 15)

You have the right to obtain confirmation of whether we process your personal data and, if so, to receive a copy of that data along with information about how it is processed.

Right to rectification (Art. 16)

You have the right to have inaccurate personal data corrected. You can update most account details directly in your account settings.

Right to erasure / "right to be forgotten" (Art. 17)

You may request deletion of your personal data where it is no longer necessary, where you withdraw consent (where processing is based on consent), or where you object and there is no overriding legitimate interest. Some data may be retained where required by law (e.g., billing records) or for security purposes.

Right to restriction of processing (Art. 18)

You may request that we restrict processing of your personal data in certain circumstances, such as while a dispute about accuracy or lawfulness is resolved.

Right to data portability (Art. 20)

Where processing is based on contract or consent and carried out by automated means, you have the right to receive your personal data in a structured, commonly-used, machine-readable format. The Service provides data export functionality for your Customer Data.

Right to object (Art. 21)

You may object at any time to processing based on our legitimate interests (including direct marketing). We will cease such processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.

Right to withdraw consent

Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.

Right to lodge a complaint (Art. 77)

You have the right to lodge a complaint with the Dutch supervisory authority, the Autoriteit Persoonsgegevens (AP), atwww.autoriteitpersoonsgegevens.nl, if you believe we have not complied with applicable data protection law. We encourage you to contact us first so we can address your concern.

Identity verification: to protect your data, we may need to verify your identity before fulfilling a request. We will not use your data for purposes other than verification.

8. Cookies and Similar Technologies

The Molinia platform uses only strictly necessary cookies required for authentication and session management. These cookies:

  • Are session-scoped or short-lived (authentication tokens and CSRF tokens)
  • Are set only upon login and deleted upon logout
  • Do not track you across third-party websites
  • Do not contain any personally identifiable information beyond a session identifier

We do not use advertising cookies, analytics tracking pixels, third-party marketing scripts, or any other non-essential cookies. No consent banner is required for essential cookies under ePrivacy Directive Article 5(3), but we disclose their use here for full transparency.

The public marketing site at www.molinia.eu does not set any cookies. Analytics on the marketing site, if any, use privacy-preserving, cookieless techniques only.

9. Security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration, or destruction. These measures include:

  • Encryption of data in transit using TLS 1.2 or higher
  • Encryption of sensitive data at rest (passwords are hashed using bcrypt; 2FA secrets are encrypted using AES-256)
  • Role-based access controls within the platform enforcing least-privilege access
  • Tamper-evident audit logging with hash-chaining
  • Brute-force protection on authentication endpoints
  • Regular automated backups with tested restore procedures
  • Multi-tenant data isolation preventing cross-customer data access

In the event of a personal data breach that is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay in accordance with GDPR Article 34. We will also notify the Autoriteit Persoonsgegevens within 72 hours where required.

To report a suspected security vulnerability, contactsecurity@unpinned.nl.

10. Changes to This Policy

We may update this Privacy Policy from time to time. The version number and effective date at the top of this page will reflect any changes. Material changes will be communicated to you by email or via a notice within the platform at least 30 days before taking effect.

Your continued use of the Service after the effective date of an updated Privacy Policy constitutes your acceptance of the changes. If you do not accept the updated policy, you must stop using the Service.

11. Contact and DPO

For all privacy-related enquiries, requests, or complaints, contact our privacy team:

Email: privacy@unpinned.nl

Postal address: see imprint

We aim to respond to all privacy requests within 5 business days to acknowledge receipt and within 30 days for substantive responses.