BusinessMCP

GDPR compliance

Last updated: 26 September 2026

BusinessMCP is designed to help you stay GDPR-compliant. We collect the minimum, keep visitors pseudonymous, never sell data or train models on it, and give you the paperwork — a Data Processing Agreement and a transparent sub-processor list — to stay compliant when you use us.

Cookieless by design — which is not the same as banner-free

Our tracking script sets no cookies and uses no cross-site tracking. It does keep one pseudonymous visitor id (mcph_vid) in the visitor’s own browser storage — see the Cookie Policy.

Be clear about what that means in the EU/EEA and UK: the ePrivacy rules (Art. 5(3) of the ePrivacy Directive, and PECR in the UK) cover anystoring of or access to information on a visitor’s device, including localStorage and sessionStorage, not only cookies. So a cookieless tracker does not by itself remove the need for consent. As the site owner you decide your posture, and the script offers three:

  • Default (no attribute): everything is collected with no consent gate — use it where you do not need prior consent, or where you manage consent yourself.
  • data-require-consent="true": nothing is sent and no visitor id is stored until you call mcph.consent('granted') — the most defensible choice for EU/UK visitors.
  • data-require-consent="split": basic page-view and goal analytics are sent with a session-only id (sessionStorage, cleared when the tab closes), while the persistent id, session recordings, heatmaps and visitor identification wait for consent. This narrows what happens before consent; it does not make pre-consent storage exempt.

Never sold or shared — with a GPC opt-out

Our first-party analytics is cookieless and pseudonymous — never sold, and never shared with advertisers — so it measures a site’s own audience under legitimate interest. For the optional ad-platform integrations a customer can turn on (server-side conversion measurement or audience matching), we honor a Global Privacy Control signal as a valid Do Not Sell or Share opt-out where US state laws recognize it, excluding those visitors from the transfer. Two consent-gate modes are available for sites that want explicit opt-in: gate all tracking, or a split mode that keeps basic analytics running under legitimate interest while session recordings and visitor identification wait for consent — the posture we run on businessmcp.com itself for EU/UK visitors.

Data minimization & pseudonymization

Sessions are keyed by a one-way, daily-rotating hash that cannot be reversed to a person or linked across days, and IP addresses are never stored with analytics events. IP addresses are used for company identification, and we say exactly how: on paid plans company identification is on by default and the full address is kept only until the company is resolved (an enrichment job runs every three hours), unless you choose to keep it; on every plan, Free included, the visitor’s /24 (IPv4) or /48 (IPv6) network prefix is kept for 30 days to maintain our shared IP-to-company graph. Turning company identification off stops both, and on a consent-gated snippet neither runs before consent. Retention for every store is in the Privacy Policy, and the graph is explained there too.

A processor you can paper

For end-visitor data you remain the controller and we act as your processor under a Data Processing Agreement that covers sub-processor notice, security, breach notification, deletion on termination, and Standard Contractual Clauses for international transfers. The one exception is disclosed in it: for the network prefixes that maintain our shared IP-to-company graph we are an independent controller, under our own legitimate interest. Enterprise customers can request a countersigned copy.

Data-subject requests within 30 days

Access, rectification, erasure, portability, restriction, objection, and consent withdrawal are all supported. Use the form below or email privacy@businessmcp.com. We respond within 30 days, after confirming you are the person the data concerns. Full detail is in the Privacy Policy.

If your request is about data one of our customers collected on their own website, we will pass it to them (they are the controller) and help them answer.

We answer within 30 days. Workspace owners can export or delete a contact from the CRM without this form.

No data sales, no model training

We never sell your data and never train AI models on it. Your workspace content is used only to run the work you ask for, secured with workspace isolation and an encrypted vault — see Security.