// LEGAL_COMPLIANCE
Data Processing Agreement & Sub-processors
GDPR compliance documentation for enterprise and regulated-industry customers evaluating MakeYourMCP.
DPA Status
A formal Data Processing Agreement is available for enterprise customers on request. Email connect@makeyourmcp.com with your company name and jurisdiction to receive a PDF DPA for review and countersignature.
What Data MakeYourMCP Processes
MakeYourMCP is a gateway and policy layer — it does not store your business data. The data types processed depend on your deployment configuration:
- Audit log entries: Agent ID, user role, tool name, policy decision, timestamp, and redacted context fields. PII in context is automatically masked before storage.
- Credential references: Encrypted references to credentials stored in the HSM vault. Raw credentials are never stored in log or database fields.
- Early access form data: Name, email, company, and use case descriptions submitted via the early access request form. Processed only for onboarding communication.
Data Residency
Enterprise customers can deploy the MakeYourMCP gateway inside their own AWS VPC or Azure VNet, keeping all transaction data within their compliance boundary. In this configuration, audit logs and credential references never leave your perimeter.
Sub-processor List
The following third parties process data on behalf of MakeYourMCP. This list is updated when sub-processors are added or removed. Last updated: July 2026.
| Sub-processor | Country | Purpose | Data Processed |
|---|---|---|---|
| Vercel Inc. | United States | Application hosting and edge delivery | Log data, request metadata |
| Microsoft Azure | United States / EU | Cloud infrastructure (VPC-mode deployments) | Encrypted audit logs, encrypted credentials |
| FormSubmit.co | United States | Form submission routing (early access requests) | Name, email, company (from early access form) |
| Plausible Analytics | European Union | Privacy-preserving web analytics | Anonymised page views, no personal data |
Your Rights Under GDPR
If you are a data subject covered by GDPR, you have the right to access, correct, port, and request deletion of personal data we hold about you. Submit requests to connect@makeyourmcp.com. We respond to all data subject requests within 30 days.
Data Retention
- Early access form submissions: retained for 24 months or until deletion is requested.
- Audit logs: plan-dependent (7 days / 30 days / unlimited — contact us for enterprise retention details).
- Web analytics: anonymised, no retention limit (no personal data stored).
Request a DPA
To request a countersigned DPA for your organisation, email connect@makeyourmcp.com with:
- Your legal entity name and registered country
- The name and title of the signing authority
- Any jurisdiction-specific annexes required (e.g. Standard Contractual Clauses for EU-US transfers)