The data controller for the personal data described in this policy is [Company Legal Name], [Registered Address].
For any question about this policy or your data, contact our privacy team at privacy@mcpbundler.com.
We collect only the data each feature needs to function, and use it only for the purpose it was collected for - the GDPR principle of purpose limitation (doelbinding). We do not repurpose data collected for one feature to serve an unrelated one.
Stored credentials and other sensitive fields are encrypted at rest using AES-256-GCM before they ever reach disk. Data in transit is encrypted with TLS. Encryption keys are managed separately from the data they protect.
See our Security page for more detail on how these protections are implemented.
We keep account and billing data for as long as your account is active, and for the period afterwards required by EU tax and accounting law. Usage metrics are retained for 13 months on a rolling basis, then deleted.
We use a small number of sub-processors to run the service, each bound by a data processing agreement, and our infrastructure is hosted within the EU:
We use only strictly necessary cookies to keep you signed in and to remember your session. We do not use advertising or cross-site tracking cookies, and we do not sell or share your data with third parties for advertising.
If you believe we have not handled your data lawfully, you have the right to lodge a complaint with your national data protection authority. If you are unsure which authority applies to you, the European Data Protection Board maintains a directory of national authorities.
We will update the "last updated" date above whenever we make a material change to this policy, and where required by law, notify account holders directly.
Under the GDPR, you have the right to: