MCP Connector Privacy Policy
Agentibus OÜ · Vendus platform
Last updated: 26 September 2026
Controller:
Agentibus OÜ (registry code 17226791)
Harju maakond, Tallinn, Kesklinna linnaosa, Järvevana tee 9, 11314, Estonia
Email: [email protected]
Phone: +372 5648 4014 · +39 392 676 2590
1. Scope
This policy explains how Agentibus OÜ ("Agentibus", "we", "us") processes personal data when you use the Agentibus MCP connector (the "Connector"), built on the Vendus platform,: the remote Model Context Protocol server at https://vendus-mcp-directory.fly.dev/mcp that lets an AI assistant, such as Muse, Claude or ChatGPT, work inside your Vendus workspace. How the Connector works is described in the Connector documentation.
It complements the Vendus Privacy Policy (in Italian) and the Data Processing Agreement, which continue to apply to everything this policy does not cover.
2. Roles
- Agentibus as controller for the data of the person who connects: their Vendus account, the authorization they grant, the OAuth tokens and the audit log of their calls.
- Agentibus as processor for the lead data that the Connector reads or changes: contacts, conversations, drafts and related data of the business's leads. We process it on behalf of the business that owns the workspace, under Article 28 GDPR and the DPA. The business is the controller.
- The AI assistant provider (for example Meta for Muse, Anthropic for Claude, OpenAI for ChatGPT) receives the tool results you request. It is not our sub-processor: it processes those results under its own terms and privacy policy, in the relationship between you and that provider.
3. Data the Connector processes
| Category | Data | Source |
|---|---|---|
| Account and authorization | Email of your Vendus login, the workspace you choose, the scopes you grant, the time of consent | You, on the consent page at app.vendus.ai |
| Client registration | Name of the AI assistant application and its redirect addresses | The AI assistant, when it registers as an OAuth client |
| OAuth tokens | Authorization codes, access tokens and refresh tokens, stored only as hashes, with expiry and last-used time | Generated by Vendus |
| Audit log | Time, workspace, user email, application id, token id, HTTP method and API route called, reason for any refusal, IP address | Generated by Vendus on every call |
| Workspace data reached through tools | Leads (name, phone number or social handle, email), conversation content, reply and email drafts, agent settings and prompts, knowledge base documents, reminders, metrics | Your Vendus workspace, read or changed at your request |
| Tool calls | Tool name and arguments sent by the assistant, and the results returned | The AI assistant, on your instructions |
We receive only what your assistant sends in a tool call. We do not receive the rest of your conversation with the assistant.
The Connector server itself holds no credentials and stores nothing. It forwards your OAuth access token and the tool call to the Vendus API over TLS and returns the result. The audit log records which API route was called, not the content of requests or results. Workspace data stays in the Vendus database, where it already is. The Connector does not create another copy of it.
4. Purposes and legal bases
| Purpose | Legal basis | GDPR |
|---|---|---|
| Authenticating you, and enforcing the workspace binding, scopes and rate limit | Performance of the contract for the Vendus service, which includes the Connector | Art. 6(1)(b) |
| Carrying out the tool calls you request on your workspace data | Processing on behalf of your business, on its documented instructions | Art. 28 |
| Audit log, security and prevention of abuse | Legitimate interest in keeping the service and its customers secure | Art. 6(1)(f) |
We do not sell personal data, and we do not use data processed through the Connector for advertising or third-party marketing.
5. Sub-processors and recipients
The Connector relies on sub-processors that are already on our Sub-processors list:
- Fly.io, Inc.: application hosting, including the Connector endpoint.
- Supabase, Inc.: the Vendus database (PostgreSQL) in the EU (Frankfurt), where tokens, the audit log and workspace data are stored.
- Tools that run an agent (
test_agent) or add knowledge (add_knowledge_url,add_knowledge_text) use the same providers Vendus uses for those functions: Anthropic, PBC (AI model) and Voyage AI, Inc. (document embeddings). - Tools that send messages deliver them through the channels already set up for the workspace, for example Meta Platforms, Inc. for the WhatsApp Business API.
Tool results are delivered to the AI assistant you use, as described in section 2. We share no other data with the assistant provider.
6. International transfers
The Vendus database is hosted in the EU. The Connector endpoint runs on Fly.io infrastructure, which may relay requests through regions outside the European Economic Area. Nothing is stored there. Transfers to sub-processors in the United States are covered by Standard Contractual Clauses and data processing agreements, as shown on the Sub-processors page.
The AI assistant provider you choose may process tool results outside the European Economic Area under its own terms.
7. Retention
| Data | Retention |
|---|---|
| Authorization codes | Valid for 10 minutes, single use |
| Access tokens | Valid for 1 hour |
| Refresh tokens | Valid for 30 days, or until you revoke the connection |
| Audit log | 12 months, like the other security logs described in the Vendus Privacy Policy |
| Tool calls on the Connector server | Not stored |
| Workspace and lead data | Unchanged by the Connector: kept according to the business's instructions and the DPA, and deleted or returned within 30 days of a written request after the contract ends |
8. Security
- OAuth 2.1 authorization code flow with PKCE (S256). No API keys are accepted on the Connector endpoint.
- Each token is bound to one workspace and to the granted scopes. Workspace, scope and rate limit (120 requests per minute per connection) are checked on every request.
- Tokens are stored only as hashes. All traffic uses TLS.
- Every call, including refused calls, is recorded in the audit log.
- Connections can be revoked at any time, and the Connector can be turned off for a whole workspace.
- The other technical and organisational measures are described on the Security page.
9. Your controls
- You choose whether to approve access on the consent page, and for which workspace.
- You can revoke a connection at any time in the Vendus dashboard, under Settings > API Keys, in the list of MCP connections. Its refresh and access tokens stop working immediately.
- The workspace owner can ask us to turn the Connector off for the whole workspace by writing to [email protected].
10. Your rights
Under the GDPR you have the right to access, rectify and erase your personal data, to restrict or object to its processing, and to data portability. To exercise these rights, write to [email protected]. We reply within 30 days, as required by Article 12(3) GDPR.
If you are a lead of a business that uses Vendus, that business is the controller of your data. You can contact it directly, or write to us and we will help the business handle your request.
You also have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, [email protected]) or with the supervisory authority of your country of residence.
11. Personal data breaches
If a personal data breach affects data handled through the Connector, we notify the affected business customers without undue delay and within 48 hours of reasonably confirming it, as set out in our DPA and Security page. Where we are the controller, we notify the supervisory authority as required by Article 33 GDPR.
12. Children
The Connector is a tool for businesses. It is not intended for people under 16, and we do not knowingly process their data through it.
13. Changes to this policy
We may update this policy. The current version is always published on this page with its date. We will inform dashboard users of material changes by email or in the Vendus dashboard.
14. Contact
For any question about this policy or about your data: [email protected], or by post to Agentibus OÜ, Järvevana tee 9, 11314 Tallinn, Estonia.
Related documents
- Vendus MCP connector documentation
- MCP connector Terms of Use
- MCP connector Privacy Policy
- Vendus Terms and Conditions (Italian, with an English version on the same page)
- Vendus Privacy Policy (Italian)
- Data Processing Agreement (Italian and English)
- Security measures (Italian)
- Sub-processors