// LEGAL_COMPLIANCE

Data Processing Agreement & Sub-processors

GDPR compliance documentation for enterprise and regulated-industry customers evaluating MakeYourMCP.

DPA Status

A formal Data Processing Agreement is available for enterprise customers on request. Email connect@makeyourmcp.com with your company name and jurisdiction to receive a PDF DPA for review and countersignature.

What Data MakeYourMCP Processes

MakeYourMCP is a gateway and policy layer — it does not store your business data. The data types processed depend on your deployment configuration:

  • Audit log entries: Agent ID, user role, tool name, policy decision, timestamp, and redacted context fields. PII in context is automatically masked before storage.
  • Credential references: Encrypted references to credentials stored in the HSM vault. Raw credentials are never stored in log or database fields.
  • Early access form data: Name, email, company, and use case descriptions submitted via the early access request form. Processed only for onboarding communication.

Data Residency

Enterprise customers can deploy the MakeYourMCP gateway inside their own AWS VPC or Azure VNet, keeping all transaction data within their compliance boundary. In this configuration, audit logs and credential references never leave your perimeter.

Sub-processor List

The following third parties process data on behalf of MakeYourMCP. This list is updated when sub-processors are added or removed. Last updated: July 2026.

Sub-processorCountryPurposeData Processed
Vercel Inc.United StatesApplication hosting and edge deliveryLog data, request metadata
Microsoft AzureUnited States / EUCloud infrastructure (VPC-mode deployments)Encrypted audit logs, encrypted credentials
FormSubmit.coUnited StatesForm submission routing (early access requests)Name, email, company (from early access form)
Plausible AnalyticsEuropean UnionPrivacy-preserving web analyticsAnonymised page views, no personal data

Your Rights Under GDPR

If you are a data subject covered by GDPR, you have the right to access, correct, port, and request deletion of personal data we hold about you. Submit requests to connect@makeyourmcp.com. We respond to all data subject requests within 30 days.

Data Retention

  • Early access form submissions: retained for 24 months or until deletion is requested.
  • Audit logs: plan-dependent (7 days / 30 days / unlimited — contact us for enterprise retention details).
  • Web analytics: anonymised, no retention limit (no personal data stored).

Request a DPA

To request a countersigned DPA for your organisation, email connect@makeyourmcp.com with:

  • Your legal entity name and registered country
  • The name and title of the signing authority
  • Any jurisdiction-specific annexes required (e.g. Standard Contractual Clauses for EU-US transfers)
Get Early Access
Get Early Access