GDPR compliance
Last updated: August 2026
BusinessMCP is designed to be GDPR-compliant out of the box. We collect the minimum, keep visitors pseudonymous, never sell data or train models on it, and give you the paperwork — a Data Processing Agreement and a transparent sub-processor list — to stay compliant when you use us.
Cookieless by design
Our analytics set no cookies and use no cross-site tracking. A single pseudonymous id lives in the visitor’s own browser storage — see the Cookie Policy. That removes the cookie-banner friction while keeping you compliant.
Never sold or shared — with a GPC opt-out
Our first-party analytics is cookieless and pseudonymous — never sold, and never shared with advertisers — so it measures a site’s own audience under legitimate interest. For the optional ad-platform integrations a customer can turn on (server-side conversion measurement or audience matching), we honor a Global Privacy Control signal as a valid Do Not Sell or Share opt-out where US state laws recognize it, excluding those visitors from the transfer. A consent-gate mode is available for sites that want explicit opt-in.
Data minimization & pseudonymization
Sessions are keyed by a one-way, daily-rotating hash that cannot be reversed to a person or linked across days. IP addresses are used transiently for geo and bot detection and then discarded; they are only retained when you explicitly enable company enrichment on a paid plan, and discarded again once the company is resolved.
A processor you can paper
For end-visitor data you remain the controller and we act as your processor under a Data Processing Agreement that covers sub-processor notice, security, breach notification, deletion on termination, and Standard Contractual Clauses for international transfers. Enterprise customers can request a countersigned copy.
Data-subject requests within 30 days
Access, rectification, erasure, portability, restriction, objection, and consent withdrawal are all supported. Email privacy@businessmcp.com and we respond within 30 days. Full detail is in the Privacy Policy.
No data sales, no model training
We never sell your data and never train AI models on it. Your workspace content is used only to run the work you ask for, secured with workspace isolation and an encrypted vault — see Security.