Privacy notice
Moira Connect Privacy Notice
This Notice explains how Moira Solutions B.V., trading as Moira Connect, processes personal data when it operates the public website, administers customer accounts, and provides the service. It is distinct from the Data Processing Addendum, which applies when Moira processes Customer Data on a customer's documented instructions.
1. Who is responsible for processing
Moira Solutions B.V. is the controller for public-site interactions, sales enquiries, account administration, billing, security, and Moira's own product operations. In these contexts, contact [email protected] with a privacy question or request.
For content and personal data that a Customer submits to or retrieves through a connected provider account, Customer generally determines the purpose and means of processing and Moira acts as processor under the Data Processing Addendum. The provider may also process data under its own terms and privacy notice.
2. Data categories
The categories depend on how you interact with Moira Connect and which product features a Customer enables. We do not require more data than is reasonably needed for the relevant purpose.
- Identity and account data, such as name, work email, organisation, role, authentication identifiers, and sign-in events.
- Commercial data, such as sales enquiries, subscription status, invoice references, tax information supplied for billing, and payment status. Payment-card data is handled by Stripe rather than stored in the Moira application.
- Technical and security data, such as IP address, device and browser information, request identifiers, audit events, API-key metadata, access logs, and configuration state.
- Customer Data and provider-account data processed only as required to provide the requested connection, event, webhook, support, and recovery workflows.
3. Sources of personal data
We receive data directly from you, from a Customer administrator, from an identity provider or authentication service, from a payment provider, from a connected provider account where authorised, and automatically from use of the public site or service.
4. Purposes and legal bases
We process personal data to provide and support the service, create and secure accounts, administer subscriptions, authenticate users, operate connections, investigate reliability and security events, comply with legal obligations, and communicate about requested services. The legal basis is typically performance of a contract, compliance with a legal obligation, or Moira's legitimate interests in operating a secure, reliable service.
Where consent is required—for example, for a non-essential storage or analytics technology that Moira later enables—we will identify the purpose, obtain a positive choice before activation, and provide a way to withdraw it. The current public site does not enable optional analytics or advertising storage.
5. Recipients and subprocessors
Access is limited to authorised Moira personnel and service providers with a need to know. The current service dependencies are listed on the Subprocessor page, including the purpose and typical data scope for each.
A Customer-selected provider platform is not made equivalent to a Moira-controlled service provider: it receives data only through the Customer's authorised connection and under that provider's own terms and privacy notice.
6. International transfers
Moira and its service providers may process data in countries outside the European Economic Area. Where a transfer mechanism is required, we use an adequacy decision, the applicable EU Standard Contractual Clauses, or another lawful safeguard and apply supplementary measures where appropriate.
7. Retention and deletion
We retain personal data for the period needed for the purpose collected, including the active service term, security investigation, legal, accounting, and dispute-resolution requirements. Retention varies by category and cannot always be reduced to a single time period.
Customer workspace deletion and erasure follow the service's documented controls, including the mandatory seven-day delay before irreversible erasure. We may keep limited information where required by law, necessary to prevent fraud or abuse, or needed to establish, exercise, or defend legal claims.
8. Security and automated decisions
We use technical and organisational measures designed for the risk of the processing, including access controls, scoped credentials, auditability, encryption controls, and operational monitoring appropriate to the service. No internet service can promise absolute security, and Customers remain responsible for their own account configuration and user management.
Moira does not make solely automated decisions that produce legal or similarly significant effects about individuals through the public site or standard account administration. Operational rules may flag a connection, usage condition, or security event for review.
9. Your rights and complaints
Depending on applicable law, you may request access, rectification, erasure, restriction, portability, or objection to processing, and may withdraw consent where processing relies on consent. To make a request, email [email protected] and tell us which relationship or workspace it concerns so we can verify and route it safely.
If Moira processes data as a processor, please direct the request first to the relevant Customer as controller; Moira will assist the Customer as required by the Data Processing Addendum. You may also complain to the supervisory authority that is competent for your habitual residence, workplace, or alleged infringement.
10. Changes to this Notice
We may update this Notice to reflect legal, technical, or operational changes. The version and publication date above identify the current notice. Where a change is material, we will use a reasonable additional notice method appropriate to the change and our relationship with you.