Legal

Privacy Policy

Effective 4 July 2026Document v1.0

This policy explains what personal data Molnex Ltd. collects when you visit molnex.io or use the Molnex platform and its applications, why we collect it, and the choices you have.

The short version: your content is yours, we collect the minimum we need to run the service, we never sell personal data, and when you connect external storage we access it only on your instruction.

01Who we are

Molnex Ltd. (“Molnex”, “we”, “us”), registered in Sofia, Bulgaria, builds AI infrastructure and a multi-tenant content platform for agencies, studios, and VFX teams. For personal data connected to your account and to visits to this website, Molnex is the data controller. For content your organization stores or links inside a platform workspace, your organization is the controller and Molnex processes it on your organization’s behalf.

Questions about this policy or your data: [email protected].

02Scope

This policy covers the molnex.io website, the Molnex platform (workspaces, user and permission management, billing), and Molnex applications such as the Digital Asset Manager (DAM). Individual applications may publish supplementary notices where their data handling differs; those notices extend, and never contradict, this policy.

03Data we collect

Website visits. Standard technical data when you browse molnex.io: IP address, browser and device information, pages viewed, and referrers — collected through server logs and the analytics described below.

Account and identity data. Name, email address, authentication identifiers (including from single sign-on providers you choose), multi-factor enrolment status, workspace membership, and role assignments.

Workspace content and metadata. Assets, files, custom fields, folders, projects, tags, share links, and the metadata the platform keeps about them (names, sizes, types, checksums, timestamps, and who created or changed them).

Connected-storage credentials. When a workspace connects an external storage provider we store the minimum credential required to act on its behalf: an OAuth refresh token (Dropbox, Google Drive, Microsoft OneDrive/SharePoint) or access keys you enter (S3-compatible storage). These are encrypted at rest and never exposed to browsers or other users.

Billing data. Plan selections and invoicing details. Card payments are handled by our payment processor; Molnex does not store card numbers.

Support and correspondence. Messages you send to our support or sales addresses.

04How we use data

  • To provide, operate, and secure the website and platform.
  • To render your content — for example generating thumbnails and converted downloads of files you store or link.
  • To enforce workspace permissions resolved from the roles your administrators assign.
  • To bill for the plans and components your workspace selects.
  • To respond to support and sales enquiries.
  • To understand, in aggregate, how the website is used so we can improve it.
  • To meet legal obligations and to detect, prevent, or investigate abuse and security incidents.

We do not sell personal data, and we do not use your content or data from connected storage providers for advertising or to train machine-learning models.

05Cookies & analytics

The platform uses strictly necessary cookies for authentication and session security. The marketing website uses Google Analytics to measure visits in aggregate; the data it collects (device, approximate location, pages viewed) is governed by Google’s privacy policy. You can opt out with the Google Analytics opt-out add-on or by blocking analytics cookies in your browser. We do not use advertising or cross-site tracking cookies. The full list of cookies, their purposes, and lifetimes is in our Cookie Policy; analytics cookies are set only after you consent through the cookie banner.

06Connected storage providers

Platform applications can connect to storage your organization controls — S3-compatible object storage, Dropbox, Google Drive, and Microsoft OneDrive/SharePoint. These connections follow a data-minimization principle:

  • Your files stay in your storage. For linked providers we store only metadata (file name, identifier, size, type). File contents are fetched from the provider on demand and are not copied into Molnex storage.
  • Derived artifacts only. To keep libraries fast we may cache small derived artifacts (thumbnails, converted renders) generated from linked files. Originals are never retained, and cached derivatives are deleted when a file is unlinked or removed.
  • Access on your instruction only.We call a provider’s API only in response to actions taken in your workspace — browsing a folder you opened, linking files you selected, or serving a file you requested. There is no background scanning of your storage.
  • Revocable at any time.Removing a connection deletes the stored credential; you can also revoke Molnex’s access from the provider’s own security settings.

07Google API Services disclosure

Molnex’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google Drive data is used only to provide the storage-linking features visible in the product: browsing folders you open, linking files you select, and displaying or downloading those files inside your workspace. It is not used for advertising, is not sold, and is not read by humans except with your explicit consent for support, for security purposes, or where required by law.

08Security

  • All traffic is encrypted in transit with TLS.
  • Storage credentials and OAuth tokens are encrypted at rest; decryption keys are held only by the backend services that need them.
  • Access inside a workspace is governed by role-based permissions enforced on every request at the API gateway and again in each service.
  • Accounts support multi-factor authentication, and workspaces can require it for their members.
  • Public share links are unlisted, capability-scoped URLs that can be expired or revoked by their creator at any time.

No system is perfectly secure. If we learn of a breach affecting your personal data we will notify you and the relevant authorities as required by law.

09Data retention & deletion

Workspace content is retained while the workspace is active. When content is deleted, its stored bytes and cached derivatives are removed from Molnex-managed storage; unlinking a connected file removes our metadata and cached derivatives while leaving the original untouched in your storage.

When a workspace or account is terminated, associated data is deleted or irreversibly anonymized within 90 days, except where a longer period is required by law (for example invoicing records). Server logs are retained for up to 12 months for security purposes.

10Sharing & subprocessors

We share personal data only with:

  • Service providers (subprocessors) that host infrastructure, provide analytics, or process payments on our behalf, bound by data processing agreements.
  • Storage providers you connect— by connecting them you instruct us to exchange data with them on your behalf, under that provider’s own terms and privacy policy.
  • Authorities, where disclosure is required by applicable law or a valid legal process.

A current list of subprocessors is available on request at [email protected].

11International transfers

Molnex is established in the European Union. Where personal data is transferred outside the European Economic Area, we rely on appropriate safeguards such as adequacy decisions or the European Commission’s Standard Contractual Clauses.

12Your rights

Under the GDPR and comparable laws you have the right to access, correct, export, restrict, object to the processing of, and delete your personal data, and to lodge a complaint with a supervisory authority (in Bulgaria, the Commission for Personal Data Protection). Workspace members should direct content-related requests to their workspace administrator, who controls that data; account-related requests sent to [email protected] are answered within 30 days.

13Children

The website and platform are intended for business use and are not directed at children under 16. We do not knowingly collect personal data from children; if you believe a child has provided us data, contact us and we will delete it.

14Changes to this policy

We may update this policy as the service evolves. Material changes will be announced on this page, in the product, or by email before they take effect, and the effective date above will be updated.

15Contact

Molnex Ltd., Sofia, Bulgaria. Privacy questions, data requests, and complaints: [email protected]. General legal notices: [email protected].