Legal
Data Processing Agreement
This Data Processing Agreement (“DPA”) forms part of the Terms of Service and applies whenever MCP Guard processes personal data on your behalf.
Last updated ·
1. Parties, scope and precedence
This DPA is between you, the customer (“Customer”), and Laya Studio, Avenue Dumas 7, 1206 Genève, operating MCP Guard (“MCP Guard”). It applies to personal data contained in content the Customer (or its end users) sends to the Service for checking (“Customer Personal Data”), which MCP Guard processes as processor (Auftragsbearbeiter under the Swiss nFADP) for the Customer as controller. It is concluded when the Customer accepts the Terms; a countersigned copy is available on request from support@mcp-guard.ai. If this DPA conflicts with the Terms, this DPA prevails for data protection matters; if the Standard Contractual Clauses apply, they prevail over both.
Account, billing and usage-metadata data, for which MCP Guard is controller, is governed by the Privacy Policy, not this DPA.
2. Details of the processing
- Subject matter and nature: hosted inference: receiving request content (proposed agent actions and their context), running our guard model on it, and returning a verdict and scores.
- Purpose: providing the Service to the Customer under the Terms.
- Duration: for each request, only as long as needed to return the verdict; the DPA lasts as long as the Terms.
- Categories of data subjects: determined by the Customer; typically the Customer’s end users, customers, employees or other persons named in the actions, tool arguments, messages or context sent.
- Categories of personal data: determined by the Customer; any personal data contained in actions, tool arguments, messages and context (for example names, email addresses, account ids or amounts), which may include special categories if the Customer chooses to send them.
- Retention: request content is not stored. Request metadata (which contains neither content nor verdicts) is kept 30 days.
3. Customer instructions and responsibilities
MCP Guard processes Customer Personal Data only on the Customer’s documented instructions, which are these Terms and DPA and the Customer’s API calls and settings, unless Union, Member State or Swiss law requires otherwise; in that case MCP Guard informs the Customer first unless the law prohibits it. MCP Guard informs the Customer if it believes an instruction infringes data protection law. The Customer is responsible for the lawfulness of the data it sends, for having a legal basis, and for informing data subjects.
4. Confidentiality and security
MCP Guard ensures that anyone authorised to process Customer Personal Data is bound by confidentiality, and implements appropriate technical and organisational measures under Art. 32 GDPR and Art. 8 nFADP, in particular:
- No persistence of request content: processed in memory only, never written to a database, log or training set.
- TLS encryption on every connection; GPU servers not reachable from the public internet and accepting requests only from the gateway, authenticated with a shared secret.
- API keys stored only as SHA-256 hashes; tenant isolation derived from the key; database row-level security; privileged operations server-side only.
- Least-privilege access to production systems, with secrets held in the hosting provider’s secret store.
- Inference on GPU servers we operate in Switzerland; no third-party inference provider receives request content.
MCP Guard may update these measures provided the overall level of protection is not reduced.
5. Assistance
Taking into account the nature of the processing, MCP Guard assists the Customer with responding to data subject requests, with security, breach notification, data protection impact assessments and prior consultations (Art. 32–36 GDPR; Art. 22–24 nFADP). Because request content is not stored, MCP Guard will generally hold no Customer Personal Data to which such a request could apply.
6. Subprocessors
The Customer gives general authorisation for MCP Guard to engage the subprocessors listed on the Subprocessors page. MCP Guard will notify the Customer by email and on that page at least 30 days before adding or replacing a subprocessor that receives Customer Personal Data. The Customer may object on reasonable data protection grounds within that period; if the parties cannot resolve the objection, the Customer may terminate the affected Service and receive a refund of unused prepaid credits. This applies in particular to any failover inference provider, which will not receive Customer Personal Data before that notice period has passed. MCP Guard imposes data protection obligations on each subprocessor equivalent in substance to this DPA and remains responsible to the Customer for its subprocessors’ performance.
7. International transfers
Customer Personal Data is processed in Switzerland and, in transit, on Cloudflare’s global network, which may include data centres outside Switzerland and the EU/EEA. Where Customer Personal Data is transferred to a country without an adequacy decision recognised under the GDPR or the nFADP, the transfer is based on the recipient’s certification under the EU-U.S. or Swiss-U.S. Data Privacy Framework or on the European Commission’s Standard Contractual Clauses (Module 2 or 3 as applicable), with the adaptations required by the FDPIC for transfers subject to Swiss law, which are incorporated by reference where required.
8. Personal data breaches
MCP Guard notifies the Customer without undue delay, and where feasible within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data, with the information reasonably available to help the Customer meet its own notification duties, and takes reasonable steps to contain it.
9. Deletion and return
Request content is deleted from memory as soon as each verdict is returned, so nothing remains to be returned or deleted at the end of the Service. Any Customer Personal Data that nonetheless exists is deleted on termination unless law requires storage.
10. Information and audits
MCP Guard makes available the information reasonably necessary to demonstrate compliance with this DPA and Art. 28 GDPR, primarily through written answers and documentation. Where that is insufficient, the Customer (or an auditor bound by confidentiality) may audit once per year on at least 30 days’ written notice, during business hours, at the Customer’s cost and without access to other customers’ data or to subprocessors’ facilities beyond their own audit reports. MCP Guard holds no formal certification (such as ISO 27001) today.
11. Liability and term
Liability under this DPA is subject to the limitations in the Terms, except where the law or the Standard Contractual Clauses do not allow it. This DPA ends when the Terms end; obligations about deletion and confidentiality survive. Swiss law and the jurisdiction in the Terms apply, except where the Standard Contractual Clauses require otherwise.