MCP Connector Privacy Policy

Agentibus OÜ · Vendus platform

Last updated: 26 September 2026

Controller:

Agentibus OÜ (registry code 17226791)

Harju maakond, Tallinn, Kesklinna linnaosa, Järvevana tee 9, 11314, Estonia

Email: [email protected]

Phone: +372 5648 4014 · +39 392 676 2590

1. Scope

This policy explains how Agentibus OÜ ("Agentibus", "we", "us") processes personal data when you use the Agentibus MCP connector (the "Connector"), built on the Vendus platform,: the remote Model Context Protocol server at https://vendus-mcp-directory.fly.dev/mcp that lets an AI assistant, such as Muse, Claude or ChatGPT, work inside your Vendus workspace. How the Connector works is described in the Connector documentation.

It complements the Vendus Privacy Policy (in Italian) and the Data Processing Agreement, which continue to apply to everything this policy does not cover.

2. Roles

  • Agentibus as controller for the data of the person who connects: their Vendus account, the authorization they grant, the OAuth tokens and the audit log of their calls.
  • Agentibus as processor for the lead data that the Connector reads or changes: contacts, conversations, drafts and related data of the business's leads. We process it on behalf of the business that owns the workspace, under Article 28 GDPR and the DPA. The business is the controller.
  • The AI assistant provider (for example Meta for Muse, Anthropic for Claude, OpenAI for ChatGPT) receives the tool results you request. It is not our sub-processor: it processes those results under its own terms and privacy policy, in the relationship between you and that provider.

3. Data the Connector processes

CategoryDataSource
Account and authorizationEmail of your Vendus login, the workspace you choose, the scopes you grant, the time of consentYou, on the consent page at app.vendus.ai
Client registrationName of the AI assistant application and its redirect addressesThe AI assistant, when it registers as an OAuth client
OAuth tokensAuthorization codes, access tokens and refresh tokens, stored only as hashes, with expiry and last-used timeGenerated by Vendus
Audit logTime, workspace, user email, application id, token id, HTTP method and API route called, reason for any refusal, IP addressGenerated by Vendus on every call
Workspace data reached through toolsLeads (name, phone number or social handle, email), conversation content, reply and email drafts, agent settings and prompts, knowledge base documents, reminders, metricsYour Vendus workspace, read or changed at your request
Tool callsTool name and arguments sent by the assistant, and the results returnedThe AI assistant, on your instructions

We receive only what your assistant sends in a tool call. We do not receive the rest of your conversation with the assistant.

The Connector server itself holds no credentials and stores nothing. It forwards your OAuth access token and the tool call to the Vendus API over TLS and returns the result. The audit log records which API route was called, not the content of requests or results. Workspace data stays in the Vendus database, where it already is. The Connector does not create another copy of it.

4. Purposes and legal bases

PurposeLegal basisGDPR
Authenticating you, and enforcing the workspace binding, scopes and rate limitPerformance of the contract for the Vendus service, which includes the ConnectorArt. 6(1)(b)
Carrying out the tool calls you request on your workspace dataProcessing on behalf of your business, on its documented instructionsArt. 28
Audit log, security and prevention of abuseLegitimate interest in keeping the service and its customers secureArt. 6(1)(f)

We do not sell personal data, and we do not use data processed through the Connector for advertising or third-party marketing.

5. Sub-processors and recipients

The Connector relies on sub-processors that are already on our Sub-processors list:

  • Fly.io, Inc.: application hosting, including the Connector endpoint.
  • Supabase, Inc.: the Vendus database (PostgreSQL) in the EU (Frankfurt), where tokens, the audit log and workspace data are stored.
  • Tools that run an agent (test_agent) or add knowledge (add_knowledge_url, add_knowledge_text) use the same providers Vendus uses for those functions: Anthropic, PBC (AI model) and Voyage AI, Inc. (document embeddings).
  • Tools that send messages deliver them through the channels already set up for the workspace, for example Meta Platforms, Inc. for the WhatsApp Business API.

Tool results are delivered to the AI assistant you use, as described in section 2. We share no other data with the assistant provider.

6. International transfers

The Vendus database is hosted in the EU. The Connector endpoint runs on Fly.io infrastructure, which may relay requests through regions outside the European Economic Area. Nothing is stored there. Transfers to sub-processors in the United States are covered by Standard Contractual Clauses and data processing agreements, as shown on the Sub-processors page.

The AI assistant provider you choose may process tool results outside the European Economic Area under its own terms.

7. Retention

DataRetention
Authorization codesValid for 10 minutes, single use
Access tokensValid for 1 hour
Refresh tokensValid for 30 days, or until you revoke the connection
Audit log12 months, like the other security logs described in the Vendus Privacy Policy
Tool calls on the Connector serverNot stored
Workspace and lead dataUnchanged by the Connector: kept according to the business's instructions and the DPA, and deleted or returned within 30 days of a written request after the contract ends

8. Security

  • OAuth 2.1 authorization code flow with PKCE (S256). No API keys are accepted on the Connector endpoint.
  • Each token is bound to one workspace and to the granted scopes. Workspace, scope and rate limit (120 requests per minute per connection) are checked on every request.
  • Tokens are stored only as hashes. All traffic uses TLS.
  • Every call, including refused calls, is recorded in the audit log.
  • Connections can be revoked at any time, and the Connector can be turned off for a whole workspace.
  • The other technical and organisational measures are described on the Security page.

9. Your controls

  • You choose whether to approve access on the consent page, and for which workspace.
  • You can revoke a connection at any time in the Vendus dashboard, under Settings > API Keys, in the list of MCP connections. Its refresh and access tokens stop working immediately.
  • The workspace owner can ask us to turn the Connector off for the whole workspace by writing to [email protected].

10. Your rights

Under the GDPR you have the right to access, rectify and erase your personal data, to restrict or object to its processing, and to data portability. To exercise these rights, write to [email protected]. We reply within 30 days, as required by Article 12(3) GDPR.

If you are a lead of a business that uses Vendus, that business is the controller of your data. You can contact it directly, or write to us and we will help the business handle your request.

You also have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, [email protected]) or with the supervisory authority of your country of residence.

11. Personal data breaches

If a personal data breach affects data handled through the Connector, we notify the affected business customers without undue delay and within 48 hours of reasonably confirming it, as set out in our DPA and Security page. Where we are the controller, we notify the supervisory authority as required by Article 33 GDPR.

12. Children

The Connector is a tool for businesses. It is not intended for people under 16, and we do not knowingly process their data through it.

13. Changes to this policy

We may update this policy. The current version is always published on this page with its date. We will inform dashboard users of material changes by email or in the Vendus dashboard.

14. Contact

For any question about this policy or about your data: [email protected], or by post to Agentibus OÜ, Järvevana tee 9, 11314 Tallinn, Estonia.