This Data Processing Agreement ("DPA") forms part of the agreement between you (the "Customer," "Controller," or "you") and PopMCP (the "Processor," "we," "us," or "our") and governs the processing of personal data that PopMCP carries out on your behalf when providing the Service. It is intended to reflect the requirements of Article 28 of the EU General Data Protection Regulation ("GDPR") and equivalent data-protection laws.
Please note: this DPA should be reviewed by qualified legal counsel before it is executed, and the security, transfer, and liability terms confirmed against your own contractual requirements. For a countersigned copy, or to supply your own DPA, contact legal@popmcp.com.
1. Parties and Roles
In respect of personal data processed through the Service, you act as the controller and PopMCP acts as the processor. You determine the purposes and means of the processing, and PopMCP processes personal data only on your behalf and in accordance with this DPA.
Where PopMCP processes personal data contained in, or exchanged with, the third-party provider accounts you connect, PopMCP does so as your processor and only on your documented instructions. Your creation of a connection, your configuration of it, and the tool operations you or your authorized AI clients invoke constitute your documented instructions for that processing.
PopMCP is operated by PopMCP, established in Australia. For matters relating to this DPA, PopMCP can be reached at privacy@popmcp.com.
2. Subject Matter and Duration of Processing
The subject matter of the processing is the provision of the Service, namely operating a control plane that connects MCP-compatible clients to the provider accounts you connect and routing authorized requests between them.
The processing continues for the duration of the agreement between you and PopMCP and for any additional period during which PopMCP is required or permitted to retain personal data under the Terms and Conditions, this DPA, or applicable law. On expiry or termination, the return and deletion provisions of this DPA apply.
3. Nature and Purpose of Processing
PopMCP processes personal data for the purpose of providing, securing, maintaining, and supporting the Service. The nature of the processing includes collecting, storing, encrypting, transmitting, routing, logging, and deleting personal data as required to operate hosted MCP endpoints and related features.
- authenticating users and managing agencies, organizations, members, roles, and permissions;
- storing connection metadata and encrypting provider credentials so authorized requests can be routed to connected providers;
- recording usage events for analytics, rate limiting, reliability, security, and billing;
- processing subscriptions, invoices, and refunds through our payment subprocessor;
- responding to support requests and sending operational communications.
4. Types of Personal Data and Categories of Data Subjects
Types of personal data
- identity and account data, such as name, email address, avatar, and authentication identifiers;
- tenant and membership data, such as organization membership, role, and invitation status;
- connection and configuration data, including encrypted provider credentials and access settings;
- usage and technical data, such as tool names, outcomes, latency, client name and version, hashed network addresses, and timestamps;
- billing data, such as plan, subscription status, and payment metadata (no full card numbers are stored by PopMCP);
- any personal data contained in the connected provider accounts that is processed when you or your AI clients invoke tool operations, the scope of which is determined by you.
Categories of data subjects
- your authorized users, administrators, and team members;
- your customers, contacts, and other individuals whose personal data appears in the provider accounts you connect;
- any other individuals whose personal data you choose to process through the Service.
5. Obligations of the Processor
PopMCP will process personal data only on your documented instructions, including with regard to international transfers, unless required to do otherwise by applicable law, in which case PopMCP will inform you of that legal requirement before processing unless the law prohibits it on important grounds of public interest. PopMCP will inform you if, in its opinion, an instruction infringes applicable data-protection law.
PopMCP ensures that persons authorized to process personal data are bound by appropriate obligations of confidentiality. PopMCP does not sell personal data and does not use provider credentials to access your provider accounts other than to perform the Service functions you request.
Security of processing (Article 32)
PopMCP implements appropriate technical and organizational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing. These measures include:
- encryption of provider credentials at rest using
AES-256-GCMbefore storage, and encryption of data in transit using industry-standard transport security (TLS); - storage of personal access token secrets only as cryptographic hashes, never in plaintext, with a non-secret prefix retained for identification;
- authentication, tenant isolation, and role-based access controls (RBAC) that scope access to the relevant agency and organization;
- per-token rate limiting, secret redaction in structured logs, and audit logging of usage and operational events;
- monitoring designed to detect, investigate, and respond to security incidents.
6. Subprocessors
You provide PopMCP with a general authorization to engage subprocessors to help deliver the Service. PopMCP maintains a current list of its subprocessors, including each one's purpose, the personal data it processes, and where it operates, on our Subprocessors page at /legal/subprocessors.
PopMCP imposes on each subprocessor data-protection obligations that are, in substance, no less protective than those set out in this DPA, and remains responsible for the performance of its subprocessors' obligations. PopMCP will give you reasonable notice of any intended addition or replacement of a subprocessor so that you have an opportunity to object on reasonable, data-protection grounds before the change takes effect. To receive change notifications, contact privacy@popmcp.com.
The third-party providers you choose to connect are not PopMCP subprocessors; they are your own processors, selected and instructed by you, and are governed by their own terms and privacy policies.
7. Assistance with Data-Subject Requests
Taking into account the nature of the processing, PopMCP will assist you by appropriate technical and organizational measures, insofar as this is possible, in fulfilling your obligation to respond to requests to exercise data-subject rights, including rights of access, rectification, erasure, restriction, portability, and objection.
If PopMCP receives a request directly from a data subject relating to personal data processed on your behalf, PopMCP will, unless legally required to respond, refer the data subject to you or forward the request to you without undue delay.
8. Personal-Data Breach Notification
PopMCP will notify you without undue delay after becoming aware of a personal-data breach affecting personal data processed on your behalf. The notification will describe, to the extent known, the nature of the breach, the likely consequences, and the measures taken or proposed to address it, and will be supplemented with further information as it becomes available.
PopMCP will provide reasonable assistance to help you meet your own breach-notification and communication obligations to supervisory authorities and affected data subjects. Notification of a breach is not, and will not be construed as, an acknowledgement of fault or liability.
9. Return and Deletion of Personal Data
On termination of the Service, and at your choice, PopMCP will delete or return personal data processed on your behalf and delete existing copies, unless applicable law requires continued storage. Much of this can be actioned by you directly, for example by disconnecting connections, deleting tokens, or removing organizations and members.
Residual copies present in routine backups, and records retained for billing, security, fraud-prevention, or legal purposes, are deleted or de-identified in accordance with PopMCP's retention schedules and applicable law rather than immediately.
10. Audits and Information
PopMCP will make available to you information reasonably necessary to demonstrate compliance with its obligations under Article 28 of the GDPR and this DPA, and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate.
The parties will agree on the reasonable scope, timing, and confidentiality of any audit in advance. PopMCP may satisfy audit requests by providing existing documentation, security summaries, or third-party reports where these reasonably address your inquiry, and audits must not compromise the security or confidentiality of other customers' data.
11. International Data Transfers
PopMCP and its subprocessors may process personal data in countries other than the country in which you or your data subjects are located. Where personal data protected by the GDPR or comparable law is transferred to a country that has not received an adequacy decision, the parties will rely on an appropriate transfer mechanism, such as the applicable European Commission Standard Contractual Clauses (SCCs) or equivalent safeguards, together with any supplementary measures required.
To the extent the SCCs apply, they are incorporated into this DPA by reference and completed by the details of the parties, the processing, and the safeguards described here and confirmed by counsel before use.
12. Liability and Order of Precedence
Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Terms and Conditions, and any reference in those terms to a party's liability means the aggregate liability of that party under the Terms and Conditions and this DPA together.
In the event of a conflict between this DPA and the Terms and Conditions or the Privacy Policy in relation to the processing of personal data on your behalf, this DPA prevails to the extent of that conflict. This DPA is governed by the law and subject to the jurisdiction stated for the agreement, namely the laws of Australia, except where mandatory data-protection law provides otherwise.
13. Contact
Questions about this Data Processing Agreement may be sent to:
PopMCP