Data Processing Agreement
Last updated: August 2026
This DPA governs BusinessMCP’s processing of personal data on your behalf when you use our tracking script, support widget, and dashboard to collect end-visitor data. It supplements our Terms of Service and forms part of your agreement with us. Enterprise customers can request a countersigned copy from privacy@businessmcp.com.
Roles of the parties
With respect to end-visitor personal data processed through BusinessMCP, you (our customer) are the controller and BusinessMCP, Inc. is the processor. We process this data only to provide the service and only on your documented instructions, which include your configuration of the product.
Scope & nature of processing
We process pseudonymous web-analytics data (visitor ids, page paths, coarse geo, device type), CRM contact records you create or capture, and — where you enable them — company-enrichment and session-recording data. Processing consists of collection, storage, aggregation, and making this data available to you in the dashboard, API, and AI assistant.
Processor obligations
- Process personal data only on your documented instructions.
- Ensure personnel with access are bound by confidentiality.
- Implement appropriate technical and organizational security measures (see below).
- Assist you, so far as possible, with data-subject requests and with your DPIA and consultation duties.
- Delete or return personal data at the end of the service, subject to legal retention.
- Make available information needed to demonstrate compliance.
Security measures
We maintain workspace isolation via row-level security, an encrypted credential vault, TLS in transit, encryption at rest, and least-privilege access. Full detail is on our Security page, which is incorporated here by reference.
Sub-processors
We use the sub-processors listed in our Privacy Policy to deliver the service. We impose data-protection terms on each that are no less protective than this DPA, and we will give you reasonable notice of any intended addition or replacement so you may object.
Data-subject requests
If we receive a request from one of your end-visitors, we will refer them to you and, taking into account the nature of the processing, assist you in responding using appropriate technical and organizational measures.
Personal-data breaches
We will notify you without undue delay after becoming aware of a personal-data breach affecting your data, with the information you reasonably need to meet your own notification obligations.
Deletion & return
On termination, or on your request, we will delete or return the personal data we process on your behalf, except where retention is required by law. Pseudonymous, aggregated data that no longer identifies individuals may be retained.
International transfers
Where processing involves a transfer of personal data outside the EEA/UK, the parties rely on the applicable Standard Contractual Clauses, which are incorporated into this DPA by reference.