Privacy Notice for MoL Wallet AIS Evaluation

Last updated: 4 September 2026

1. Who is responsible for the data

Roaming Minds is the data controller for the processing described in this notice.

Roaming Minds
CVR: 46376692
C/O Mathias Henrik Ottosen
Lysbrovænget 2
8600 Silkeborg
Denmark

Data protection contact: mathias_ottosen@roamingmindshouse.com

2. Scope of this notice

This notice applies only to the MoL Wallet AIS Evaluation. The evaluation is an internal, founder-operated test of read-only access to a single Lunar Business account owned by Roaming Minds. It is not a public service, is not available to third-party users, and cannot initiate payments.

The application uses Enable Banking’s account information service to retrieve data from Lunar after the account holder has authorised access.

3. Personal data processed

Depending on what Lunar makes available through its open-banking interface, the evaluation may process:

  • account identifiers and account details, including account name, type, currency and account-holder information;
  • account balances;
  • transaction data, including amounts, dates, status, descriptions, references and counterparty information;
  • consent and session information needed to establish and maintain the connection; and
  • limited technical logs, such as timestamps, request status, error information and non-secret technical identifiers.

The evaluation does not request payment-initiation access.

4. Where the data comes from

The data comes from Lunar Bank A/S and is transmitted through Enable Banking Oy after the founder, acting for Roaming Minds and as the account holder, completes the bank’s authorisation process.

5. Purposes and legal basis

Roaming Minds processes the data to:

  • evaluate whether a restricted account-information connection works reliably with the designated business account;
  • determine which account, balance and transaction fields are available;
  • test read-only reconciliation and financial-control mechanisms; and
  • identify technical, security and data-quality limitations before any later operational decision.

The legal basis is Article 6(1)(f) of the General Data Protection Regulation: Roaming Minds’ legitimate interest in evaluating and securing its own business financial infrastructure. Because the evaluation concerns an account owned and operated by Roaming Minds and has no external users, Roaming Minds considers the processing limited and proportionate.

The open-banking authorisation given through Lunar and Enable Banking permits account access. It is separate from the GDPR legal basis described above and can be ended through the available consent-management mechanisms.

6. Storage and retention

During the present evaluation, raw bank responses are processed only for the active test and are not intentionally retained after the test completes. Roaming Minds may retain sanitised technical results that do not contain transaction descriptions, counterparty details, account numbers or balances. These results may include counts, timestamps, statuses, expiry information and error outcomes.

Sanitised technical evaluation records are retained until the evaluation is concluded and for no longer than 12 months afterwards, unless a longer period is required to establish, exercise or defend a legal claim.

This notice must be reviewed and updated before the application begins persistently storing bank data, supplies data to an operational MoL service, or is made available to any other user.

7. Recipients and service providers

Account data passes from Lunar through Enable Banking to Roaming Minds. Lunar and Enable Banking provide the banking and connectivity services under their own applicable terms and privacy information.

Roaming Minds does not sell the data, disclose it to third-party users, or use it for advertising. During this evaluation, raw account data is not sent to the pre-launch MoL server or an autonomous entity runtime.

8. Processing location and travel

Lunar is established in Denmark and Enable Banking is established in Finland. Roaming Minds does not intentionally disclose evaluation data to recipients outside the European Economic Area.

The founder may operate the evaluation from founder-controlled equipment while travelling, including outside the European Economic Area. This remains access by the same controller. Raw bank responses are not intentionally retained on that equipment after the active test. If the evaluation later introduces persistent processing outside the European Economic Area or an external recipient there, Roaming Minds will assess the required safeguards and update this notice before that processing begins.

9. Security and access

Access is restricted to the founder. The application is configured for account-information access only, with no payment initiation. Credentials and private keys are kept separately from public application information, and raw responses are not intentionally written to evaluation records.

10. Your rights

Subject to the conditions and limits in data-protection law, you may request access to your personal data, correction, erasure, restriction of processing, data portability, or object to processing based on legitimate interests. You may contact Roaming Minds using the data-protection email above.

You may also complain to the Danish Data Protection Agency (Datatilsynet): How to complain

11. Automated decisions

The evaluation does not make decisions about individuals through automated processing and does not perform profiling.

12. Changes

Roaming Minds will update this notice if the purpose, data flow, users, storage practice or operational status of the application changes materially.