Version 1.0 — August 13, 2026
This Data Processing Addendum (“DPA”) forms part of the MCPFeedback Terms of Service and applies automatically whenever MCPFeedback processes personal data on a customer’s behalf. It takes effect on the date the customer accepts the Terms; no signature is required. If your procurement process needs a countersigned copy, email support@mcpfeedback.com and we will return this document executed.
This DPA is between the entity that has entered into the Terms (“Customer”) and MCPFeedback (“Processor”).
With respect to personal data collected through the MCPFeedback widget and mobile SDKs from Customer’s end users (“Customer Personal Data”), Customer is the controller and MCPFeedback is the processor. MCPFeedback remains an independent controller for the limited account, authentication, billing and service-operations data described in our Privacy Policy; that data is outside the scope of this DPA.
“Data Protection Laws” means the EU General Data Protection Regulation 2016/679 (GDPR), the UK GDPR and Data Protection Act 2018, the Swiss FADP, and the California Consumer Privacy Act as amended (CCPA/CPRA), each to the extent applicable. For CCPA purposes MCPFeedback is a “service provider”: it does not sell or share Customer Personal Data and does not retain, use or disclose it for any purpose other than performing the Services.
Subject matter. Provision of the MCPFeedback feedback-collection platform: the embeddable web widget, the iOS, Android and Flutter SDKs, the management dashboard, the support portal, outbound webhooks and integrations, and the MCP server through which Customer-authorised AI agents read and act on feedback.
Duration. For the term of the Terms, plus the deletion window described in section 9.
Nature of processing. Collection via the widget and SDKs, transmission, storage, structured organisation, display in the dashboard, transformation (for example converting a screen recording to an animated GIF), disclosure to destinations Customer configures, and erasure.
Purpose. Solely to provide, secure, maintain and support the Services for Customer, and to comply with Customer’s documented instructions. Customer’s instructions are given through the Terms, this DPA, and Customer’s configuration of the Services.
Customer must not use the Services to intentionally collect special categories of personal data (Article 9 GDPR), payment card data, government identifiers, or data subject to HIPAA, PCI-DSS or similar regimes. Where such data may incidentally appear on screen, Customer is responsible for configuring an appropriate privacy tier and masking before capture.
Customer warrants that it has a valid lawful basis for the collection and for instructing MCPFeedback to process Customer Personal Data; that it provides its end users with the notice required by Data Protection Laws, including notice of screenshot, screen-recording, session-replay and crash-report capture; that it obtains consent where consent is the applicable basis; and that its instructions will not cause MCPFeedback to breach Data Protection Laws.
MCPFeedback shall:
Customer grants MCPFeedback general written authorisation to engage subprocessors. The current list is published at mcpfeedback.com/subprocessors.
MCPFeedback will update that page at least 30 days before a new subprocessor begins processing Customer Personal Data, and will notify Customer by email where Customer has subscribed to subprocessor notices (email support@mcpfeedback.com to subscribe). Customer may object on reasonable data-protection grounds within that 30-day window; if the objection cannot be resolved, Customer may terminate the affected Services and receive a pro-rata refund of prepaid fees.
MCPFeedback imposes data protection obligations on each subprocessor that are no less protective than those in this DPA, and remains fully liable to Customer for its subprocessors’ performance.
On written request, and no more than once per twelve-month period (unless required by a supervisory authority or following a personal data breach), MCPFeedback will provide a written description of its technical and organisational measures, answer a reasonable security questionnaire, and share available third-party attestations from its infrastructure subprocessors. Where that is not sufficient to satisfy Customer’s audit obligations under Article 28(3)(h) GDPR, the parties will agree the scope, timing and cost of a remote audit conducted under confidentiality and without disrupting the Services or exposing other customers’ data.
MCPFeedback and several of its subprocessors process data in the United States. Where Customer Personal Data originating in the EEA, the United Kingdom or Switzerland is transferred to a country without an adequacy decision, the transfer is governed by the European Commission Standard Contractual Clauses of 4 June 2021 (Decision (EU) 2021/914), which are incorporated into this DPA by reference, with Module Two (controller to processor) applying between Customer and MCPFeedback and Module Three where Customer is itself a processor. Customer is the data exporter and MCPFeedback the data importer.
For the purposes of the Clauses: the optional docking clause applies; Clause 9 option 2 (general written authorisation, 30 days’ notice) applies; Clause 11 does not include the optional independent dispute-resolution body; Clause 17 selects the law of Ireland; Clause 18(b) selects the courts of Ireland; Annexes I, II and III are populated by sections 1 to 4, 10 and 7 of this DPA together with the published subprocessor list.
UK transfers are governed by the International Data Transfer Addendum to the Clauses issued by the UK Information Commissioner (version B1.0), and Swiss transfers by the Clauses as adapted by the Swiss Federal Data Protection and Information Commissioner.
Taking into account the state of the art, the costs of implementation, and the nature, scope and risk of the processing, MCPFeedback maintains at least the following measures:
A fuller narrative is published on our security page.
Throughout the term, Customer may export its feedback data and delete individual records, sites, projects or its entire organization from the dashboard. Deletion removes the database records and the associated files from object storage.
On termination or expiry of the Terms, MCPFeedback will, at Customer’s election, return Customer Personal Data in a machine-readable format or delete it. Absent an election, MCPFeedback deletes Customer Personal Data from production systems within 30 days of termination. Residual copies in encrypted backups are removed as those backups age out on their normal rotation and remain protected by this DPA until then. MCPFeedback may retain data where required by law, for the statutory period only.
Each party’s liability under this DPA is subject to the limitations and exclusions in the Terms. If there is a conflict, the Standard Contractual Clauses prevail over this DPA, and this DPA prevails over the Terms and the Privacy Policy, in each case only as to the processing of Customer Personal Data.
MCPFeedback may update this DPA to reflect changes in law, guidance or the Services, provided the update does not materially reduce the protections afforded to Customer Personal Data. Material updates are announced at least 30 days in advance by email or dashboard notice.
Data protection enquiries, signed-copy requests, subprocessor-notice subscriptions and breach notifications: support@mcpfeedback.com.
Questions about this addendum? Contact us at support@mcpfeedback.com