Data Processing Agreement
Last updated: 5 September 2026
This DPA governs BusinessMCP’s processing of personal data on your behalf when you use our tracking script, support widget, and dashboard to collect end-visitor data. It supplements our Terms of Service and forms part of your agreement with us. Enterprise customers can request a countersigned copy from privacy@businessmcp.com.
Roles of the parties
With respect to end-visitor personal data processed through BusinessMCP, you (our customer) are the controller and BusinessMCP, Inc. is the processor. We process this data only to provide the service and only on your documented instructions, which include your configuration of the product.
Scope & nature of processing
We process pseudonymous web-analytics data (visitor ids, page paths, coarse geo, device type), CRM contact records you create or capture, and — where you enable them — company-enrichment and session-recording data. Processing consists of collection, storage, aggregation, and making this data available to you in the dashboard, API, and AI assistant.
Processor obligations
- Process personal data only on your documented instructions.
- Ensure personnel with access are bound by confidentiality.
- Implement appropriate technical and organizational security measures (see below).
- Assist you, so far as possible, with data-subject requests and with your DPIA and consultation duties.
- Delete or return personal data at the end of the service, subject to legal retention.
- Make available information needed to demonstrate compliance.
Security measures
We maintain workspace isolation via row-level security, an encrypted credential vault, TLS in transit, encryption at rest, and least-privilege access. Full detail is on our Security page, which is incorporated here by reference.
Company identification & cross-site learning
Where you enable visitor identification, we determine the company likely behind an anonymous business visit and enrich company records. This is a company-level operation that involves no device access, no cookie, and no reading of any identifier from the visitor’s device. We process company data plus a truncated IP address only — the IP is truncated at ingestion (to a /24 for IPv4, /48 for IPv6), the email local-part is never stored, and IP addresses are held separately from analytics events. The lawful basis is your and our legitimate interest (GDPR Art. 6(1)(f)) in B2B account identification, balanced against the limited, company-scoped nature of the processing.
To improve accuracy, truncated IP↔company-domain confirmations observed across the sites that run our script may be aggregated into a shared, company-level model (the same legitimate-interest mechanism operated by comparable B2B identification providers). We act as processor for each customer, this cross-site improvement is covered by this DPA, the data is EU-hosted, and an opt-out is available (disable visitor enrichment in Settings, or contact privacy@businessmcp.com).
Confirmation signals. Three sensors feed that model, each recording only a truncated IP (/24 for IPv4, /48 for IPv6) paired with a company domain: (1) a form submission or verified signup with a corporate email; (2) a click on a link in an outreach email your workspace sent, captured on our redirect; (3) the originating mail-server IP in the Received / X-Originating-IP headers of a reply to that outreach.
Before a click or reply is counted we exclude link scanners and mail-security gateways (fetches within seconds of delivery, fan-out across many links, known wrapper hosts, automated user agents) and any address our own graph classes as hosting, VPN or relay. These signals only ever confirm a company; they are never used to identify a person.
Person-level identification (resolving a named individual) is a separate, stricter feature that is device-based, US-only under notice-and-opt-out, off in the EU/UK absent consent, and disabled whenever a Global Privacy Control signal is present — see our Privacy Policy.
Sub-processors
You authorise the sub-processors in the register at businessmcp.com/privacy#sub-processors. The register states each vendor’s purpose, the data it sees, its location and whether it only processes data when you connect or enable it. We impose data-protection terms on each that are no less protective than this DPA and remain liable for their performance.
Notice and objection. We email workspace owners at least 30 daysbefore a new sub-processor starts processing data for every workspace, and update the register’s Last updated date. You may object within that period on reasonable data-protection grounds by writing to privacy@businessmcp.com. If we cannot offer a workable alternative, you may terminate the affected service without penalty. Vendors marked only if you connect it are engaged by your own configuration and need no notice.
Data-subject requests
If we receive a request from one of your end-visitors, we will refer them to you and, taking into account the nature of the processing, assist you in responding using appropriate technical and organizational measures.
Personal-data breaches
We will notify you without undue delay after becoming aware of a personal-data breach affecting your data, with the information you reasonably need to meet your own notification obligations.
Deletion & return
On termination, or on your request, we will delete or return the personal data we process on your behalf, except where retention is required by law. Pseudonymous, aggregated data that no longer identifies individuals may be retained.
International transfers
Where processing involves a transfer of personal data outside the EEA/UK, the parties rely on the applicable Standard Contractual Clauses, which are incorporated into this DPA by reference.