← Back to home

Data Processing Addendum

Version 1.0 — August 13, 2026

This Data Processing Addendum (“DPA”) forms part of the MCPFeedback Terms of Service and applies automatically whenever MCPFeedback processes personal data on a customer’s behalf. It takes effect on the date the customer accepts the Terms; no signature is required. If your procurement process needs a countersigned copy, email support@mcpfeedback.com and we will return this document executed.

1. Parties and roles

This DPA is between the entity that has entered into the Terms (“Customer”) and MCPFeedback (“Processor”).

With respect to personal data collected through the MCPFeedback widget and mobile SDKs from Customer’s end users (“Customer Personal Data”), Customer is the controller and MCPFeedback is the processor. MCPFeedback remains an independent controller for the limited account, authentication, billing and service-operations data described in our Privacy Policy; that data is outside the scope of this DPA.

“Data Protection Laws” means the EU General Data Protection Regulation 2016/679 (GDPR), the UK GDPR and Data Protection Act 2018, the Swiss FADP, and the California Consumer Privacy Act as amended (CCPA/CPRA), each to the extent applicable. For CCPA purposes MCPFeedback is a “service provider”: it does not sell or share Customer Personal Data and does not retain, use or disclose it for any purpose other than performing the Services.

2. Subject matter, duration, nature and purpose

Subject matter. Provision of the MCPFeedback feedback-collection platform: the embeddable web widget, the iOS, Android and Flutter SDKs, the management dashboard, the support portal, outbound webhooks and integrations, and the MCP server through which Customer-authorised AI agents read and act on feedback.

Duration. For the term of the Terms, plus the deletion window described in section 9.

Nature of processing. Collection via the widget and SDKs, transmission, storage, structured organisation, display in the dashboard, transformation (for example converting a screen recording to an animated GIF), disclosure to destinations Customer configures, and erasure.

Purpose. Solely to provide, secure, maintain and support the Services for Customer, and to comply with Customer’s documented instructions. Customer’s instructions are given through the Terms, this DPA, and Customer’s configuration of the Services.

3. Categories of data subjects

  • End users of Customer’s websites and mobile applications who submit feedback, whose sessions are replayed, or whose devices generate crash reports.
  • Customer’s personnel who are named or visible in feedback content, screenshots, recordings or support-portal conversations.
  • Any other individual whose personal data appears in content captured by the widget or SDKs.

4. Categories of personal data

  • Contact data: the email address supplied by the reporter, and any name or identifier the Customer’s integration passes through.
  • Feedback content: titles, descriptions, severity, comments and support-portal messages written by the reporter or by Customer’s team.
  • Screenshots and annotations: images of the page or screen at the time of the report, including whatever personal data was visible on it, plus reporter drawings and notes.
  • Screen recordings and session replays: recordings converted to animated GIFs; for mobile, sequences of frame screenshots with timestamps and screen names, interaction events (taps with coordinates, scrolls, navigations, input events) and network event metadata (method, URL, status, duration), captured under the privacy tier Customer selects.
  • Crash, ANR and hang diagnostics: exception classes and messages, stack traces, thread dumps, app version, fingerprints, and surrounding network logs which may include headers and truncated request and response bodies.
  • Technical and device data: page and referrer URLs, user agent, viewport and screen dimensions, platform, OS and device model, IP address as processed transiently for delivery, security and rate limiting.
  • Captured client errors: JavaScript console errors and unhandled exceptions with messages and stack traces.

Customer must not use the Services to intentionally collect special categories of personal data (Article 9 GDPR), payment card data, government identifiers, or data subject to HIPAA, PCI-DSS or similar regimes. Where such data may incidentally appear on screen, Customer is responsible for configuring an appropriate privacy tier and masking before capture.

5. Customer obligations

Customer warrants that it has a valid lawful basis for the collection and for instructing MCPFeedback to process Customer Personal Data; that it provides its end users with the notice required by Data Protection Laws, including notice of screenshot, screen-recording, session-replay and crash-report capture; that it obtains consent where consent is the applicable basis; and that its instructions will not cause MCPFeedback to breach Data Protection Laws.

6. Processor obligations

MCPFeedback shall:

  • process Customer Personal Data only on Customer’s documented instructions, including as to international transfers, unless required otherwise by law — in which case MCPFeedback will inform Customer before processing unless that law prohibits it;
  • ensure that personnel authorised to process Customer Personal Data are bound by confidentiality obligations and access it only on a need-to-know basis;
  • implement and maintain the technical and organisational measures summarised in section 10 and on our security page;
  • taking into account the nature of processing, assist Customer with responding to data-subject requests by providing the export, search and deletion functions in the Services, and by reasonable additional support where those functions are insufficient;
  • assist Customer with data protection impact assessments and prior consultations under Articles 32 to 36 GDPR, to the extent the information is available to MCPFeedback;
  • notify Customer without undue delay, and in any event within 72 hours of becoming aware, of any personal data breach affecting Customer Personal Data, together with the information reasonably available about its nature, likely consequences and remediation;
  • make available the information necessary to demonstrate compliance with this DPA and allow for audits as described in section 8.

7. Subprocessors

Customer grants MCPFeedback general written authorisation to engage subprocessors. The current list is published at mcpfeedback.com/subprocessors.

MCPFeedback will update that page at least 30 days before a new subprocessor begins processing Customer Personal Data, and will notify Customer by email where Customer has subscribed to subprocessor notices (email support@mcpfeedback.com to subscribe). Customer may object on reasonable data-protection grounds within that 30-day window; if the objection cannot be resolved, Customer may terminate the affected Services and receive a pro-rata refund of prepaid fees.

MCPFeedback imposes data protection obligations on each subprocessor that are no less protective than those in this DPA, and remains fully liable to Customer for its subprocessors’ performance.

8. Audits and information rights

On written request, and no more than once per twelve-month period (unless required by a supervisory authority or following a personal data breach), MCPFeedback will provide a written description of its technical and organisational measures, answer a reasonable security questionnaire, and share available third-party attestations from its infrastructure subprocessors. Where that is not sufficient to satisfy Customer’s audit obligations under Article 28(3)(h) GDPR, the parties will agree the scope, timing and cost of a remote audit conducted under confidentiality and without disrupting the Services or exposing other customers’ data.

9. International transfers

MCPFeedback and several of its subprocessors process data in the United States. Where Customer Personal Data originating in the EEA, the United Kingdom or Switzerland is transferred to a country without an adequacy decision, the transfer is governed by the European Commission Standard Contractual Clauses of 4 June 2021 (Decision (EU) 2021/914), which are incorporated into this DPA by reference, with Module Two (controller to processor) applying between Customer and MCPFeedback and Module Three where Customer is itself a processor. Customer is the data exporter and MCPFeedback the data importer.

For the purposes of the Clauses: the optional docking clause applies; Clause 9 option 2 (general written authorisation, 30 days’ notice) applies; Clause 11 does not include the optional independent dispute-resolution body; Clause 17 selects the law of Ireland; Clause 18(b) selects the courts of Ireland; Annexes I, II and III are populated by sections 1 to 4, 10 and 7 of this DPA together with the published subprocessor list.

UK transfers are governed by the International Data Transfer Addendum to the Clauses issued by the UK Information Commissioner (version B1.0), and Swiss transfers by the Clauses as adapted by the Swiss Federal Data Protection and Information Commissioner.

10. Security measures

Taking into account the state of the art, the costs of implementation, and the nature, scope and risk of the processing, MCPFeedback maintains at least the following measures:

  • encryption of Customer Personal Data in transit (TLS) and at rest on managed database and object storage;
  • tenant isolation enforced in the database by PostgreSQL row-level security policies on all customer tables, plus role-based access control within each organization;
  • API keys stored only as SHA-256 hashes; OAuth 2.1 with PKCE for MCP client authorisation; HMAC-SHA256 signatures on outbound webhooks; origin validation of widget requests against the site’s registered domain;
  • rate limiting and abuse controls on public ingest endpoints; audit logging of privileged actions; least-privilege administrative access;
  • managed, encrypted backups with point-in-time recovery on the production database;
  • a documented process for detecting, assessing and reporting personal data breaches.

A fuller narrative is published on our security page.

11. Return and deletion on termination

Throughout the term, Customer may export its feedback data and delete individual records, sites, projects or its entire organization from the dashboard. Deletion removes the database records and the associated files from object storage.

On termination or expiry of the Terms, MCPFeedback will, at Customer’s election, return Customer Personal Data in a machine-readable format or delete it. Absent an election, MCPFeedback deletes Customer Personal Data from production systems within 30 days of termination. Residual copies in encrypted backups are removed as those backups age out on their normal rotation and remain protected by this DPA until then. MCPFeedback may retain data where required by law, for the statutory period only.

12. Liability, precedence and changes

Each party’s liability under this DPA is subject to the limitations and exclusions in the Terms. If there is a conflict, the Standard Contractual Clauses prevail over this DPA, and this DPA prevails over the Terms and the Privacy Policy, in each case only as to the processing of Customer Personal Data.

MCPFeedback may update this DPA to reflect changes in law, guidance or the Services, provided the update does not materially reduce the protections afforded to Customer Personal Data. Material updates are announced at least 30 days in advance by email or dashboard notice.

13. Contact

Data protection enquiries, signed-copy requests, subprocessor-notice subscriptions and breach notifications: support@mcpfeedback.com.

Questions about this addendum? Contact us at support@mcpfeedback.com