This policy explains what personal data we collect when you visit moodree.com or use the Moodree software, why we collect it, and the rights you have under the EU General Data Protection Regulation (GDPR).
The controller of your personal data is Data Foundation s.r.o., Příčná 1892/4, Nové Město, 110 00 Prague 1, Czech Republic, company ID (IČO) 30033543, VAT CZ30033543, registered in the Commercial Register kept by the Municipal Court in Prague, file C 455322.
We have not appointed a Data Protection Officer, as we are not required to under Article 37 GDPR.
| Data | Purpose | Legal basis |
|---|---|---|
| Name, email, company (when you contact us or book a call) | Replying to you and preparing an offer | Pre-contractual steps, Art. 6(1)(b) |
| Email, phone number and company name (when you ask for beta access) | Contacting you about a place in the beta | Consent, Art. 6(1)(a) |
| Account and billing details | Providing the software and invoicing | Contract, Art. 6(1)(b); legal obligation, Art. 6(1)(c) |
| Payment details, handled by Stripe | Taking subscription payments | Contract, Art. 6(1)(b) |
| IP address, browser, pages viewed, clicks | Measuring and improving the site | Consent, Art. 6(1)(a) |
| Server logs | Security and abuse prevention | Legitimate interest, Art. 6(1)(f) |
We do not collect special categories of data (Art. 9 GDPR), we do not sell personal data, and we do not use it for advertising or profiling.
Analytics cookies are set only after you accept them. Until then, Google Analytics runs in consent-denied mode and stores nothing on your device.
| Cookie | Purpose | Basis | Lifetime |
|---|---|---|---|
cookie_consent (local storage) | Remembers your choice | Essential, no consent needed | Until you clear site data |
_ga, _ga_* | Google Analytics 4: visits and traffic sources | Consent | Up to 24 months |
To withdraw consent, clear cookies and site data for moodree.com in your browser; the banner will appear again. Withdrawal does not affect processing carried out beforehand.
We share data only with providers acting on our instructions under Article 28 GDPR:
| Provider | Purpose | Location |
|---|---|---|
| Analytics and cloud infrastructure | EU, with transfers to the USA | |
| Stripe | Payment processing. Card details go directly to Stripe. We never receive or store them. | EU/USA |
| Anthropic | AI processing that generates warehouse models (see below) | USA |
| Calendly | Call scheduling | USA |
| Airtable | Storing beta access requests | USA |
| Netlify | Serving this website | USA |
| Railway | Hosting the Moodree application | EU (Amsterdam) |
We may also disclose data where legally required.
The software uses the Anthropic API (Claude) to turn your requirements and database structure into warehouse architecture, models and documentation.
Under Anthropic's Commercial Terms: your inputs and outputs are not used to train their models, they are deleted within 30 days (barring a legal hold or a trust-and-safety flag), and a Data Processing Addendum with Standard Contractual Clauses applies automatically.
Several providers process data in the United States. For those transfers we rely on the safeguards in Chapter V GDPR:
Email us for a copy of the safeguards we rely on.
Beta access requests: until the beta closes, or until you withdraw consent. Enquiries: for as long as we are in contact or there is a realistic prospect of working together, reviewed periodically. Contract and billing records: for the term, then 10 years for tax and limitation purposes. Analytics: up to 14 months. Server logs: for the period our hosting providers retain them, and used only for security and troubleshooting. After that, data is deleted or irreversibly anonymised.
You have the right to access your data (Art. 15), have it corrected (16) or erased (17), restrict (18) or object to (21) processing, receive it in a portable format (20), and withdraw consent at any time (7(3)). We do not carry out automated decision-making under Art. 22.
Write to tom@moodree.com and we will respond within one month. You may also complain to a supervisory authority. Ours is the Czech Data Protection Authority (Úřad pro ochranu osobních údajů), Pplk. Sochora 27, 170 00 Prague 7, uoou.gov.cz.
The software builds and maintains a warehouse that runs in your own Google Cloud project. You remain the controller of everything in it; we act only as a processor on your documented instructions, set out in the written agreement we sign with you before any build. That agreement, not this policy, governs sub-processors, security, breach notification and deletion of the data in your warehouse.
We use encryption in transit and at rest, least-privilege access control and multi-factor authentication on administrative accounts. If a breach is likely to risk your rights, we notify the supervisory authority within 72 hours and you without undue delay where the risk is high.
We may update this policy, and material changes are announced here before taking effect. Questions: tom@moodree.com.