BusinessMCP

Privacy Policy

Last updated: 5 September 2026

BusinessMCP is built privacy-first: our analytics are cookieless, pseudonymize visitors by design, and are never sold or shared with advertisers — with a Global Privacy Control opt-out for the optional ad-platform integrations a customer can enable. This policy explains what we process, why, and the rights you have under the GDPR and similar laws. See also our Cookie Policy, Data Processing Agreement, and Security overview.

Who we are (data controller)

BusinessMCP, Inc. (“BusinessMCP”, “we”) is the data controller for the account and marketing data described below. For privacy questions or to exercise your rights, contact our privacy team at privacy@businessmcp.com or use the request form.

Two roles: controller and processor

For your BusinessMCP account (your email, billing, workspace content) we act as the controller. For the end-visitor analytics your workspace collects through our tracking script and support widget, you are the controller and we act as your processor, handling that data only on your instructions under our Data Processing Agreement. You are responsible for having a lawful basis and appropriate notice/consent for the visitors you track.

What we collect

  • Account & billing: your email, workspace name, team membership, and subscription status. Payment card details are handled by Stripe and never stored on our servers.
  • Workspace content: notes, playbooks, connections metadata, CRM contacts, and the messages you exchange with the AI assistant.
  • Usage: agent runs, token counts, and cost — used for metering and abuse prevention.
  • First-party analytics (pseudonymous):a random visitor id stored in the browser’s localStorage, a daily-rotating session hash that is one-way and re-identifiable only within a single UTC day (it cannot be reversed into a person or linked across days), page paths, coarse geo (country/region/city derived from IP then discarded), and device/browser type.
  • IP addresses are not storedwith analytics events. IP is used transiently for geo and bot detection and then dropped. It is only retained when a workspace on a paid plan explicitly turns on company enrichment, and even then it is discarded after the company is resolved (“enrich then discard”).
  • Visitor identification (business context): for paid workspaces that enable it, we identify the companybehind an anonymous business visitor from the network the visit originates on (in-house, no third party), and can surface a “likely person” from the workspace’s own contact records using page context — this uses company data only and no device access. Person-level identification(resolving an individual’s name and work email) is stricter: device/hashed-email matching runs only for US visitors under notice-and-opt-out, or elsewhere only where the visitor has given consent, is never performed for visitors in the EU/EEA/UK/Switzerland without consent, is disabled whenever a Global Privacy Control (GPC) signal is present, and every attempt is logged. A separate first-party mechanism recognizes a returning contact the workspace already knows (matching against its own records) — no third-party data is involved.

Legal bases (GDPR Art. 6)

  • Contract: to provide the service you signed up for — running your command center, storing your workspace, and billing you.
  • Legitimate interests: operating cookieless, pseudonymous product analytics, securing the platform, and preventing abuse — balanced against your rights. This analytics is first-party and is not sold or shared for advertising (see Do Not Sell or Share below).
  • Legitimate interests (company identification): identifying the company behind an anonymous business visit is a B2B, company-level operation carried out under Art. 6(1)(f) with no device access and no cookie: we process company data plus a truncated IP only (/24 · /48), never store the email local-part, and keep IP addresses separate from analytics events. It runs in every region on this basis; it is not person-level identification and can be turned off. Full detail is in our DPAand the “Do Not Sell or Share” section below.
  • Consent: for marketing email you can withdraw at any time. Where your end-visitors require consent for tracking, obtaining it is your responsibility as their controller.

AI processing

Workspace content is used solely to operate your command center: the assistant reads your business context, playbooks, thread history and the tool results it pulls (analytics, CRM contacts, connected data) to do the work you ask for. We do not train models on your data and we do not sell data to third parties.

The included AI tier is served by OpenCode Zen(opencode.ai, United States). Every workspace that has not connected its own model key runs on it. What is sent per run: the prompt, the compacted thread, your business description and goals, workspace memory, and the results of the tools the assistant calls — which can include contact names and emails from your CRM. Processing happens in the US under OpenCode Zen’s own policy; we do not make promises on a provider’s behalf beyond what its policy states.

Bring your own key:if you connect Anthropic, OpenAI, Google, Groq, DeepSeek, xAI, Mistral, OpenRouter, MiniMax or a custom endpoint, runs go to that provider on your key and under your contract with them instead — nothing reaches the included tier. The full list, with each provider’s location, is in the sub-processor table.

Connected mailboxes, files, repositories and databases

When you connect Gmail, Google Drive, Slack or GitHub, we read only what the connection authorises. Content from those sources is stored in your workspace knowledge base tagged as untrusted, meaning the assistant treats it as data, never as instructions.

Connected databases.If you connect your own PostgreSQL, MySQL, BigQuery or Snowflake, the credential is held in our encrypted vault and the connection is read-only. Two different things happen to what we read. The database’s shape— table and column names and types — is refreshed into your knowledge base every six hours; no sample rows are ever stored there. Query results are not stored by us at all: they are passed to whichever AI model your workspace is configured to use, in order to answer the question that was asked, and they appear in that conversation. Queries are logged (truncated) against the run that made them. You decide what the connection can reach by scoping the database role you create for it, and you can disconnect it at any time from Connections, which deletes the stored credential.

Gmail inbox sweep.With a connected mailbox, we check for new inbound mail every 15 minutes. Automated and bulk mail is filtered out. A reply from a known contact is logged on that contact’s timeline; a first email from a genuinely new human sender creates a CRM contact for that person (name, email, the message) and an assisted reply draft that you review before anything is sent.

Those senders are third parties whose data you, the workspace owner, are the controller of. Where GDPR applies you carry the Art. 14 duty to inform them (typically satisfied by your own privacy notice and the reply you send). Disconnect the mailbox at any time from Connections; stored contacts stay until you delete them.

Lead quality checks

To keep form spam out of your CRM and out of automated outreach, we score the domainof a newly captured lead email. We look up the domain’s registration age through RDAP (IANA bootstrap, rdap.org and the TLD registry) and its MX and A records through Google Public DNS (dns.google). Only the bare domain is sent — never the address, the person’s name, or their IP.

Verdicts are cached per domain for 180 days and shared across workspaces, so a domain is looked up once. A poor verdict flags the contact and keeps it out of automated outreach; it never deletes data, and a workspace owner can override it. We deliberately do not consult IP or country reputation lists for this purpose.

Secrets and credentials

API keys and tokens you store in the vault are encrypted at rest, are never returned to the browser after saving, and are only decrypted server-side at the moment an integration call is made on your behalf.

Retention

How long each kind of data is kept. Shorter on request where the law allows.

DataKept forNotes
Raw analytics eventsUp to 13 monthsPseudonymous visitor id, page path, coarse geo, device type. No IP address. Expire automatically in the event store.
Sessions, daily rollups and visitor profilesLife of the accountAggregate and pseudonymous, no IP. Kept so lifetime journeys and year-over-year reports survive the raw window.
Session replays and heatmaps7 days (Growth), 30 days (Scale), kept while the account is open (Business and Enterprise)Off entirely on Free and Starter. Only recorded where a site enables it, and after consent on consent-gated sites.
Visitor IP addressesDiscarded after company resolutionUsed transiently for geo and bot detection. Retained only while a paid workspace with company identification enabled resolves the company, unless that workspace explicitly opts in to keep it.
Domain reputation (lead quality)180 daysKeyed by email DOMAIN only (registration age, MX and A-record presence). Shared across workspaces; contains no address, name or IP.
Email send and event logs400 daysDelivery, open, click and bounce events plus a per-recipient send ledger. Lifecycle one-time markers are kept so a nudge is never sent twice.
Hiring assessment telemetry30 daysTiming, focus and paste signals from the careers assessment, pseudonymised by HMAC. Scores stay with the application.
Job applications6 monthsName, email, links and written answers. Deleted earlier on request.
Account, workspace content and vault secretsUntil you delete the workspace or accountThreads, notes, CRM contacts, connections and encrypted credentials are removed on deletion, subject to legal retention.

Sub-processors

The vendors below process data to run the service. Core rows apply to every workspace; optional rows only see data when a workspace connects or enables that vendor. Each is bound by a data-protection agreement no less protective than our DPA.

Last updated: 2026-09-07 · 18 core, 43 only when a workspace connects or enables them.

NamePurposeDataLocationOptionalDPA
SupabasePrimary database, authentication, file storage (session replays, snapshots) and the encrypted credential vault.
  • Account and billing data
  • Workspace content and CRM contacts
  • Pseudonymous analytics sessions
  • Encrypted secrets
EUCore servicePrivacy / DPA
VercelApplication hosting, serverless functions and the global edge network that receives tracking beacons.
  • All request data in transit
  • Transient IP address (geo and bot detection)
  • Server logs
US (global edge)Core servicePrivacy / DPA
Sentry (Functional Software, Inc.)Application error monitoring. Receives a stack trace and request context when a server or browser error occurs.
  • Error stack traces
  • Request URL, method and headers
  • Transient IP address
  • User agent
USCore servicePrivacy / DPA
ipapi.isIP-classification benchmark. A nightly job scores the addresses our own IP graph resolved against this vendor to measure coverage; its verdict never drives a customer-visible reveal.
  • Visitor IP address
EUCore servicePrivacy / DPA
TinybirdRaw analytics event store (the firehose our rollups are computed from).
  • Pseudonymous visitor id
  • Page paths
  • Coarse geo
  • Device and browser type
EU (London)Core servicePrivacy / DPA
StripeSubscription billing and payments. Card details never touch our servers.
  • Account email
  • Billing details
  • Payment card (held by Stripe only)
USCore servicePrivacy / DPA
ResendTransactional and notification email; sending and inbound-reply capture for customer email domains.
  • Recipient email and name
  • Message content
  • Delivery, open and click events
USCore servicePrivacy / DPA
CloudflareDNS and proxy for businessmcp.com, and the Turnstile bot check on our public forms.
  • Client IP address
  • Browser signals used for the bot challenge
US (global edge)Core servicePrivacy / DPA
OpenCode ZenThe included AI tier. Serves every workspace that has not connected its own LLM key.
  • Assistant prompts and thread history
  • Business context and workspace memory
  • Tool results incl. CRM contacts and analytics the assistant reads
USCore servicePrivacy / DPA
TavilyLive web research for the assistant and sales research (queries only, never workspace records).
  • Search queries the assistant composes
  • Company and prospect names being researched
USCore servicePrivacy / DPA
Google Public DNSLead-quality screening: MX and A-record lookups on the DOMAIN of a submitted lead email, and DNS checks for domain setup cards.
  • Email domain only (never the address, IP or name)
USCore servicePrivacy / DPA
RDAP registries (IANA bootstrap, rdap.org, TLD registries)Lead-quality screening: domain registration age for the DOMAIN of a submitted lead email.
  • Email domain only (never the address, IP or name)
Varies by registryCore servicePrivacy / DPA
SerperGoogle search results used to find a prospect or contact LinkedIn profile URL.
  • Prospect name, title and company (as a search query)
USCore servicePrivacy / DPA
Hunter.ioEmail deliverability verification before an outreach email is sent.
  • Prospect email address
EU (France)Core servicePrivacy / DPA
ApifyManaged scraping of public social profiles and posts for handle-tracked accounts, and Google Maps business listings for prospect discovery.
  • Public social handles and profile URLs
  • Public posts and comments
  • Public business listings
EU (Czech Republic)Core servicePrivacy / DPA
DataForSEOAI-visibility probes (asking answer engines about your category) and keyword or SERP data.
  • Tracked questions
  • Brand and competitor names
  • Domains being ranked
USCore servicePrivacy / DPA
MicrolinkWebsite screenshot and metadata fetch used to generate a brand kit during onboarding.
  • The public website URL you enter
EU (Spain)Core servicePrivacy / DPA
DataFastSecond-opinion analytics on businessmcp.com itself. Never loaded on customer websites.
  • Pseudonymous visits to our own marketing site
  • Our own conversion goals
EU (France)Core servicePrivacy / DPA
TypeformForm submissions delivered to BusinessMCP by webhook when a workspace connects its Typeform account.
  • Respondent email, name and answers
  • Hidden-field visitor id
US / EU (per the account)Only if you connect itPrivacy / DPA
TallyForm submissions delivered to BusinessMCP by webhook when a workspace connects its Tally account.
  • Respondent email, name and answers
  • Hidden-field visitor id
EUOnly if you connect itPrivacy / DPA
CalendlyMeeting bookings and cancellations delivered by webhook, plus upcoming-meeting reads through the customer-supplied API token.
  • Invitee email, name and time zone
  • Meeting time and join link
  • Booking questions and answers
USOnly if you connect itPrivacy / DPA
Cal.comMeeting bookings, reschedules and cancellations delivered by webhook when a workspace connects Cal.com.
  • Attendee email, name and time zone
  • Meeting time and join link
  • Booking responses
US / EU (per the account; self-hostable)Only if you connect itPrivacy / DPA
ShopifyOrder and refund events delivered by webhook, plus order/product/customer reads through the customer-supplied Admin API token.
  • Buyer email, name and phone
  • Order amount, currency and line items
  • Cart attribute visitor id
US / CanadaOnly if you connect itPrivacy / DPA
WooCommerce (Automattic)Order and refund events delivered by webhook from the customer-hosted WooCommerce store.
  • Buyer email, name, phone and company
  • Order amount, currency and line items
  • Order meta visitor id
Customer-hosted (the store itself); Automattic USOnly if you connect itPrivacy / DPA
PaddleMerchant-of-record billing events (payments, subscriptions, refunds) delivered by webhook when a workspace connects its Paddle account.
  • Buyer email and name where the seller passes it
  • Vendor customer and subscription ids
  • Amount, currency, plan and billing status
UK / EUOnly if you connect itPrivacy / DPA
Lemon SqueezyMerchant-of-record billing events (orders, subscriptions, refunds) delivered by webhook when a workspace connects its Lemon Squeezy store.
  • Buyer email and name
  • Vendor customer, order and subscription ids
  • Amount, currency, plan and billing status
USOnly if you connect itPrivacy / DPA
ChargebeeSubscription-billing events (payments, plan changes, cancellations, refunds) delivered by webhook when a workspace connects its Chargebee site.
  • Customer email, name, company and phone
  • Vendor customer, subscription and invoice ids
  • Amount, currency, plan and billing status
US / EU (per the site)Only if you connect itPrivacy / DPA
ElevenLabsNarration audio for our public Academy course (script text only, no customer data). Also available as an optional workspace text-to-speech connector.
  • Course narration scripts
  • Text a workspace chooses to voice (optional connector only)
USOnly if you connect itPrivacy / DPA
AnthropicAI inference when you connect your own Anthropic key (replaces the included tier).
  • Assistant prompts, thread history, business context and tool results
USOnly if you connect itPrivacy / DPA
OpenAIAI inference and embeddings when you connect your own OpenAI key; grounded AI-visibility probes on your key.
  • Assistant prompts, thread history, business context and tool results
  • Knowledge chunks for embedding
USOnly if you connect itPrivacy / DPA
Snowflake (your own account)Running the read-only SQL you or the assistant ask for against a Snowflake account you connect. We hold a token you issue; the account, the data and the grants are yours.
  • SQL statements
  • The rows your query returns
Your Snowflake regionOnly if you connect itPrivacy / DPA
Google (Gemini API and connected Google services)Gemini inference on your own key; Calendar, Gmail, Drive, Search Console, Google Analytics 4, Google Ads, YouTube and BigQuery when you connect them. The Analytics connection is read-only and imports your own historical traffic reports; the BigQuery connection is read-only and runs the queries you ask for.
  • Assistant prompts and tool results (Gemini)
  • Calendar free/busy and events
  • Mailbox and Drive content you connect
  • Search, analytics and ads reports
USOnly if you connect itPrivacy / DPA
GroqAI inference when you connect your own Groq key.
  • Assistant prompts, thread history, business context and tool results
USOnly if you connect itPrivacy / DPA
DeepSeekAI inference when you connect your own DeepSeek key.
  • Assistant prompts, thread history, business context and tool results
ChinaOnly if you connect itPrivacy / DPA
xAIAI inference when you connect your own xAI (Grok) key.
  • Assistant prompts, thread history, business context and tool results
USOnly if you connect itPrivacy / DPA
Mistral AIAI inference when you connect your own Mistral key.
  • Assistant prompts, thread history, business context and tool results
EU (France)Only if you connect itPrivacy / DPA
OpenRouterAI inference routed to the model you pick when you connect your own OpenRouter key.
  • Assistant prompts, thread history, business context and tool results
USOnly if you connect itPrivacy / DPA
MiniMaxCheap-tier completions (compaction, compression, drafts) when you connect your own MiniMax key.
  • Thread summaries
  • Oversized tool results being compressed
  • Draft text
SingaporeOnly if you connect itPrivacy / DPA
BigDBMPerson-level visitor identification (hashed-email graph). Only when you enable person-level reveal, and only where the geo gate allows it.
  • Hashed email of a visitor
  • Truncated IP
USOnly if you connect itPrivacy / DPA
LeadPipePerson-level visitor identification from IP. Only when you enable person-level reveal, and only where the geo gate allows it.
  • Visitor IP address
  • Page context
USOnly if you connect itPrivacy / DPA
RB2BPerson-level visitor identification from IP. Only when you enable person-level reveal, and only where the geo gate allows it.
  • Visitor IP address
  • Page context
USOnly if you connect itPrivacy / DPA
VersiumPerson-level visitor identification (hashed-email graph). Only when you enable person-level reveal, and only where the geo gate allows it.
  • Hashed email of a visitor
USOnly if you connect itPrivacy / DPA
UnipileLinkedIn, X and WhatsApp messaging for sales automation when you connect an account through Unipile.
  • Prospect profile URLs
  • Message content
  • Reply content
EU (France)Only if you connect itPrivacy / DPA
Instantly.aiAlternative cold-email sending when you connect your own Instantly account.
  • Prospect email and name
  • Message content
  • Reply events
USOnly if you connect itPrivacy / DPA
LobPhysical letters as an outreach channel when you connect your own Lob account.
  • Recipient name and postal address
  • Letter content
USOnly if you connect itPrivacy / DPA
TwilioSMS as an outreach channel when you connect your own Twilio account.
  • Recipient phone number
  • Message content
USOnly if you connect itPrivacy / DPA
Microsoft (Graph)Microsoft 365 calendar free/busy and event creation for booking when you connect it.
  • Calendar free/busy
  • Meeting details incl. guest name and email
USOnly if you connect itPrivacy / DPA
Apple iCloud (CalDAV)iCloud calendar free/busy and event creation for booking when you connect it with an app-specific password.
  • Calendar free/busy
  • Meeting details incl. guest name and email
USOnly if you connect itPrivacy / DPA
HubSpotTwo-way CRM sync when you connect HubSpot (OAuth or a private-app token): contacts, deals, owners and pipelines are read into your BusinessMCP CRM every two hours, and — only if you switch on "Push to HubSpot" — our own enrichment is written back into a "businessmcp" property group on your contacts and companies. Your own HubSpot fields, including its lifecycle stage, are never overwritten and nothing is deleted.
  • Your HubSpot contacts (name, email, phone, company, title, owner, lifecycle stage)
  • Deals (name, stage, amount, close date, owner) and their contact associations
  • Owner emails (to match your team)
  • Sent back when push is on: the contact email as the match key, our lead / fit / intent scores, score band, churn risk, product-qualified flag and estimated lifetime value
  • Sent back when push is on: first-touch channel and UTM source/campaign, the self-reported "how did you hear about us" answer, our lifecycle stage, last seen time and last page viewed, and a link to the contact in BusinessMCP
  • Sent back when push is on: the identified company domain, industry and employee range, on the contact and on the matching HubSpot company
US / EU (your HubSpot data residency)Only if you connect itPrivacy / DPA
PipedriveCRM pull sync when you connect Pipedrive with your API token: persons, deals, stages and users are read into your BusinessMCP CRM every two hours. Nothing is written back.
  • Your Pipedrive persons (name, email, phone, organisation, owner)
  • Deals (title, stage, status, value, expected close, owner) and the person they belong to
  • User emails (to match your team)
EUOnly if you connect itPrivacy / DPA
SlackNotifications to a channel you choose, and optional read access to channels you pick for assistant context.
  • Notification text (lead, reply, meeting, alert)
  • Channel messages you opt in to ingest
USOnly if you connect itPrivacy / DPA
GitHubRepository reads, pull requests the assistant opens, and optional ingestion of your repo docs into the workspace knowledge base.
  • Repository content you authorise
  • Pull-request content
USOnly if you connect itPrivacy / DPA
Meta (Facebook, Instagram, Meta Ads)Page and Instagram stats, ad reporting, Custom Audiences and Conversions API when you connect them.
  • Ad and page reports
  • Hashed emails for audience matching
  • Server-side conversion events
USOnly if you connect itPrivacy / DPA
LinkedInCompany-page stats, ad audiences and Conversions API when you connect them.
  • Page and ad reports
  • Hashed emails for audience matching
  • Server-side conversion events
USOnly if you connect itPrivacy / DPA
TikTokAccount stats, Customer File audiences and the Events API when you connect them.
  • Account and post reports
  • Hashed emails for audience matching
  • Server-side conversion events
US / SingaporeOnly if you connect itPrivacy / DPA
X (Twitter)Account stats and comment replies when you connect an X account.
  • Public posts and engagement
  • Replies you send
USOnly if you connect itPrivacy / DPA
IntercomReceives the conversations a customer chooses to forward from their Intercom inbox (inbound webhook only; we call no Intercom API).
  • Conversation text
  • End-user name and email
  • Conversation ids and deep links
USOnly if you connect itPrivacy / DPA
CrispReceives the chat conversations a customer chooses to forward from their Crisp inbox (inbound webhook only; we call no Crisp API).
  • Conversation text
  • End-user nickname and email
  • Session ids and deep links
EU (France)Only if you connect itPrivacy / DPA
Mailchimp (Intuit)Reads campaign and audience lists on the customer API key, and receives the engagement webhooks the customer points at us (opens, clicks, unsubscribes, cleaned addresses).
  • Campaign and audience names
  • Recipient email address
  • Message engagement events
USOnly if you connect itPrivacy / DPA
KlaviyoReads campaign and list data on the customer API key, and receives the engagement webhooks the customer configures in their flows (opens, clicks, bounces, unsubscribes).
  • Campaign and list names
  • Recipient email address
  • Message engagement events
USOnly if you connect itPrivacy / DPA
BrevoReceives nothing from us — Brevo POSTS its own email engagement events (delivered, opened, clicked, bounced, spam, unsubscribed) to a per-workspace webhook URL the customer registers.
  • Recipient email address
  • Campaign name and subject
  • Message engagement events
EU (France)Only if you connect itPrivacy / DPA

We email workspace owners at least 30 days before adding a new core sub-processor so you can object as described in the DPA. Any MCP server, ad platform or tool you connect yourself is your own choice and is not listed here.

International transfers

Our database and analytics event store are hosted in the EU. Where data is transferred outside the EEA/UK — hosting, email, billing and the included AI tier are in the US — we rely on Standard Contractual Clauses and our providers’ data-protection frameworks to ensure an equivalent level of protection.

Do Not Sell or Share / Global Privacy Control

We do not sellyour personal information. Our first-party analytics is cookieless and pseudonymous and is not “shared” for cross-context behavioral advertising, so it is not gated by a privacy signal.

Where a customer enables our optional ad-platform integrations — server-side conversion measurement or audience matching that transfers data to networks like Meta or Google — that can constitute a “sale” or “share” under US state privacy laws (California, Colorado, Connecticut and others). For residents of states that recognize it, we honor a Global Privacy Control (GPC) browser signal as a valid opt-out: visitors who send GPC are excluded from those ad-platform transfers. First-party analytics is unaffected. Do-Not-Track is not an agreed legal standard and we do not rely on it.

Person-level visitor identification (US visitors, opt-in customers only) may use a third-party identity provider (BigDBM, LeadPipe, RB2B or Versium). That provider acts as a third party under US state law, not a service provider, under a contract limiting it to identity resolution with audit rights. GPC is honored as an opt-out for this processing, and it is never run for EU/EEA/UK/Swiss visitors absent consent. We do not resell visitor-identity data.

Where a customer uses our optional Sales Automationfeature to conduct business-to-business outbound outreach, that customer is the controller of the prospect data and is responsible for having a lawful basis (in the EU/UK, typically legitimate interest for B2B prospecting) and for honoring opt-outs. Every message carries the sender’s identity and postal address, a one-click unsubscribe link and List-Unsubscribe headers; recipients who unsubscribe, existing customers, and GPC opt-outs are suppressed automatically. Prospect enrichment draws on lawfully-sourced public and licensed B2B data.

Your rights

Under the GDPR and similar laws you have the right to access, rectify, erase, port, restrict, and object to the processing of your personal data, and to withdraw consent at any time.

To exercise any of these, email privacy@businessmcp.com or use the request form. We respond within 30 days. We will first verify that you are the person the request concerns — usually by replying to the email address on record, or by asking for a detail only the account holder would know. Workspace owners can export or delete any contact directly from the CRM without contacting us.

If your request concerns end-visitor data held on behalf of one of our customers, we will refer you to that customer (the controller) or assist them in responding. You also have the right to lodge a complaint with your local supervisory authority.

Children

BusinessMCP is a business tool not directed to children, and we do not knowingly collect personal data from anyone under 16.

Changes & contact

We may update this policy; material changes will be announced by email. Questions? Email privacy@businessmcp.com.