BusinessMCP

GDPR compliance

Last updated: 5 September 2026

BusinessMCP is designed to be GDPR-compliant out of the box. We collect the minimum, keep visitors pseudonymous, never sell data or train models on it, and give you the paperwork — a Data Processing Agreement and a transparent sub-processor list — to stay compliant when you use us.

Cookieless by design

Our analytics set no cookies and use no cross-site tracking. A single pseudonymous id lives in the visitor’s own browser storage — see the Cookie Policy. That removes the cookie-banner friction while keeping you compliant.

Never sold or shared — with a GPC opt-out

Our first-party analytics is cookieless and pseudonymous — never sold, and never shared with advertisers — so it measures a site’s own audience under legitimate interest. For the optional ad-platform integrations a customer can turn on (server-side conversion measurement or audience matching), we honor a Global Privacy Control signal as a valid Do Not Sell or Share opt-out where US state laws recognize it, excluding those visitors from the transfer. Two consent-gate modes are available for sites that want explicit opt-in: gate all tracking, or a split mode that keeps basic analytics running under legitimate interest while session recordings and visitor identification wait for consent — the posture we run on businessmcp.com itself for EU/UK visitors.

Data minimization & pseudonymization

Sessions are keyed by a one-way, daily-rotating hash that cannot be reversed to a person or linked across days. IP addresses are used transiently for geo and bot detection and then discarded; they are only retained when you explicitly enable company enrichment on a paid plan, and discarded again once the company is resolved.

A processor you can paper

For end-visitor data you remain the controller and we act as your processor under a Data Processing Agreement that covers sub-processor notice, security, breach notification, deletion on termination, and Standard Contractual Clauses for international transfers. Enterprise customers can request a countersigned copy.

Data-subject requests within 30 days

Access, rectification, erasure, portability, restriction, objection, and consent withdrawal are all supported. Use the form below or email privacy@businessmcp.com. We respond within 30 days, after confirming you are the person the data concerns. Full detail is in the Privacy Policy.

If your request is about data one of our customers collected on their own website, we will pass it to them (they are the controller) and help them answer.

We answer within 30 days. Workspace owners can export or delete a contact from the CRM without this form.

No data sales, no model training

We never sell your data and never train AI models on it. Your workspace content is used only to run the work you ask for, secured with workspace isolation and an encrypted vault — see Security.