Crisol MCP
How it works Sources Security Pricing Contact
Log in Get started
← Annex I to the Terms of Service

Data Processing Agreement

Annex to the Crisol MCP Terms of Service (Art. 28 GDPR)



0. Parties

  • The Data Controller: the natural or legal person who registers for Crisol MCP and connects their own accounts of digital marketing tools (hereinafter, "the Client" or "the Controller").
  • The Data Processor: Sara Fernández Velasco, with NIF 47528322H and address at Calle Carmen Burgos, n.º 96, 18100 Armilla, Granada (Spain), sole trader (self-employed individual, autónoma), owner of the Crisol MCP platform (hereinafter, "the Processor").

This Agreement is deemed automatically accepted upon acceptance of the Crisol MCP Terms of Service, without the need for a separate signature, in accordance with Art. 28(9) GDPR (which allows electronic form).

Communication channel between the Parties. The communications provided for in this Agreement (security breach notifications, prior notice of changes to sub-processors, audit requests and requests for assistance) are addressed to the Processor through privacidad@crisolmcp.com, and to the Controller at the email address associated with its account on the Platform.

1. Subject matter

The Processor, within the framework of providing the Crisol MCP Service, accesses, reads and temporarily caches the personal data contained in the digital marketing tool and online store accounts that the Controller voluntarily connects to the Platform (Google Search Console, Google Analytics 4, Google Ads, Google Merchant Center, Meta Ads, Bing Webmaster Tools, and WooCommerce or PrestaShop stores), for the sole purpose of making them available, through the MCP protocol (Model Context Protocol), to the artificial intelligence assistant that the Controller decides to use to query and analyze them.

The processing is carried out at all times in read-only mode. Only two operations write outside that boundary, both executed by the Controller themselves from the panel and neither of them on the personal data covered by this Agreement: the crawl notification through IndexNow, disabled by default, which does not involve the processing of personal data but rather the notification of URLs to search engines; and the registration and deregistration of the Processor's developer project in Google Merchant Center (registerGcp / unregisterGcp), a step that Google requires in order to read performance data and that does not alter product listings, prices or commercial configuration.

The connectable sources available vary according to the plan contracted by the Controller; the composition of each plan in force at any given time is the one published on the Service's plans page.

This Agreement governs exclusively the processing of the data referred to in this section. The processing of the data of the Controller's own account in Crisol MCP (email, name, internal account identifier) is governed by the Privacy Policy, in which the Processor acts as controller of that processing, not as processor.

2. Duration

This Agreement remains in force for as long as the Service provision relationship between the parties lasts, and until the full performance of the data deletion or return obligations described in Clause 9.

3. Nature of the processing

Collection of data through the official APIs of each connected platform; temporary storage in a local cache (SQLite database); querying and reading through MCP tools at the request of the AI assistant used by the Controller; periodic synchronization of the cached data.

4. Categories of data subjects

  • Users and visitors of the Controller's websites and applications, whose behavioral data is collected by Google Search Console and Google Analytics 4.
  • Persons reached by the Controller's advertising campaigns on Google Ads and Meta Ads, exclusively through aggregated performance reports (insights), never through individual contact lists.
  • Buyers of the Controller's online store (WooCommerce or PrestaShop), exclusively through a pseudonymous identifier assigned by the store itself, never through their identifying data (name, email, phone, address, etc.).

Important clarification: Crisol MCP is read-only across all payment channels. None of its tools (ads_*, meta_*) makes calls to the Customer Match APIs of Google Ads (CustomerMatchUserListService, UserDataService, OfflineUserDataJobService) or to those of Meta Custom Audiences (/customaudiences, POST /audiences). Consequently, no data of the Controller's end clients (email lists, phone numbers or other contact identifiers) passes through the Platform.

5. Categories of personal data

Source Type of data
Google Search Console Queries and search terms, visited URLs, aggregated ranking data
Google Analytics 4 Device/session identifiers, browsing behavior, approximate location derived from IP
Google Ads / Meta Ads Aggregated campaign performance data, costs, keywords and conversion identifiers at the report level, without individual contact lists
Google Merchant Center Product catalog data; generally non-personal, unless the feed includes identifying data of individual sellers
Bing Webmaster Tools Data equivalent to that of Search Console, referring to the Bing search engine
Online store (WooCommerce / PrestaShop) Catalog data (product, SKU, prices, sales) and order data (identifiers, dates, status, quantities, amounts net of taxes), associated with a pseudonymous buyer identifier. No identifying buyer data (name, email, phone, address, NIF, IP or advertising tracking identifiers) is processed, as it is discarded at the moment of reading before any storage.

The Processor does not intentionally process special categories of data (Art. 9 GDPR). If the Controller were to introduce this type of data through the connected platforms, it would be under their exclusive responsibility as data controller.

6. Obligations of the Processor

In accordance with Article 28(3) GDPR, the Processor:

a) Will process the personal data only following documented instructions from the Controller (understood to mean the normal use and configuration that the Controller establishes on the Platform), unless required to do so by Union or Member State law; in that case, it will inform the Controller of that legal requirement before processing, unless the law prohibits it.

b) Will ensure that the persons authorized to process the personal data have committed to respecting confidentiality or are under a confidentiality obligation of a contractual or legal nature.

c) Will adopt the security measures required by Article 32 GDPR, described in Clause 7 of this Agreement.

d) Will respect the conditions established in Clause 8 for engaging other data processors (sub-processors).

e) Will assist the Controller, through appropriate technical and organizational measures, in fulfilling its obligation to respond to requests for the exercise of data subjects' rights (access, rectification, erasure, objection, restriction, portability).

f) Will help the Controller ensure compliance with the obligations established in Articles 32 to 36 GDPR (security of processing, breach notification, impact assessments, prior consultations with the supervisory authority), taking into account the nature of the processing and the information available to the Processor.

g) At the Controller's choice, will delete or return all personal data once the Service provision ends, and will delete existing copies, unless Union or Member State law requires their retention.

h) Will make available to the Controller the information necessary to demonstrate compliance with the obligations established in this article, in accordance with the audit mechanism described in Clause 10.

7. Security measures

The Processor applies, among others, the following technical and organizational measures:

  • Encryption at rest of all third-party credentials using a Fernet token (AES-128-CBC + HMAC-SHA256 authentication), with a master key stored outside the database.
  • Strict data isolation between Controllers: one Controller's data is never accessible to another. Each Controller has its own analytics cache file, which it does not share with any other Controller.
  • Unencrypted analytics cache: unlike credentials, each Controller's local cache file is not encrypted at rest. It contains no credentials or identifying buyer data; it may contain the pseudonymous identifier described in Clause 5. It resides in the infrastructure of the sub-processor indicated in Clause 8, is isolated per Controller and is automatically purged in accordance with the periods declared in the Privacy Policy.
  • Minimization boundary in the reading of online stores: the system extracts a closed, predefined set of fields and discards the rest of the order at the moment of reading, before any storage, so that the buyer's identifying data is not copied, transmitted or stored.
  • Role-based access control (administrator / user). The administrator can delete a Controller's data but cannot decrypt or read their credentials.
  • Audit logging of the relevant actions performed on the connected credentials and tools.
  • Encrypted communications via HTTPS across the entire Service.
  • The artificial intelligence assistant integrated into the panel never accesses credentials or the data covered by this Agreement; it only receives metadata about the Controller's account: which sources it has connected, its contracted plan and the panel screen it is on.

8. Sub-processors

The Controller generally authorizes the Processor to engage the following sub-processors for the provision of the Service:

Sub-processor Function Location
OVH SAS Hosting infrastructure (VPS); storage of the encrypted database and of the automatic backups (7-day retention, managed by OVH's own backup system) Gravelines, France (EU)

OVH is the sole sub-processor of this Agreement: no additional provider is used for backups or for any other function related to the data covered by this Agreement.

The Processor will inform the Controller with a minimum of 15 calendar days prior notice of any planned change in the addition or replacement of sub-processors, giving the Controller the opportunity to object for reasonable data-protection reasons. The Processor will impose on any sub-processor the same data-protection obligations as those established in this Agreement.

9. Return and deletion of data

Upon the end of the Service provision (through the Controller's closure or termination of the contractual relationship), the Processor will delete the personal data covered by this Agreement in accordance with the periods established in the Privacy Policy: complete deletion within a maximum of 14 days from the end of access, with deletion from the production database within a maximum of 48 hours from that same end of access and purge of the encrypted backups within a maximum of 7 days (according to OVH's backup retention system). If the Controller exercises its right to erasure in accordance with Article 17 GDPR, the same periods are counted from the receipt of its request. This deletion will be carried out unless there is a legal obligation requiring the retention of some specific data, in which case only that data will be retained for the legally required period.

10. Security breach notification

The Processor will notify the Controller without undue delay and, in any case, within a maximum period of 48 hours from becoming aware of a security breach affecting the personal data processed on behalf of the Controller, providing the necessary information (nature of the breach, categories and approximate volume of data and affected data subjects, measures adopted) so that the Controller can fulfill its own obligation to notify the supervisory authority within the 72-hour period provided for in Article 33 GDPR.

11. Audit and compliance verification

At the reasonable request of the Controller, with a minimum of 30 calendar days prior notice and a maximum of one request per year except for justified cause (such as a security breach), the Processor will provide documentation demonstrating compliance with the obligations of this Agreement (description of the security measures, evidence of the encryption applied, current list of sub-processors). The Processor is not obligated to allow on-site audits or direct access to its systems. If the Controller needs justified additional information, the parties will agree in good faith on the most appropriate procedure to provide it.

12. International transfers

The Processor will not transfer the personal data covered by this Agreement outside the European Economic Area, unless one of the safeguards provided for in Chapter V of the GDPR applies (such as Standard Contractual Clauses or an adequacy decision, e.g., the EU-US Data Privacy Framework), of which it will inform the Controller in advance.

As long as the sole sub-processor declared in this Agreement (OVH) processes the data within the European Union, no international transfer of the marketing data covered by this Agreement takes place.

Clarifying note: the artificial intelligence assistant integrated into the panel relies on inference providers that may be located outside the European Union. Such providers do not process the data covered by this Agreement (that is, they do not access the personal data of the data subjects contained in the sources that the Controller connects), but only metadata about the Controller's own account (which sources it has connected, its contracted plan and the panel screen it is on). The processing of that metadata is not governed by this Agreement, but by the Privacy Policy, in which the Processor acts as controller of that processing and where these providers are declared as its own processors. For that reason, and not because of the specific nature of the metadata transmitted, such providers do not appear as sub-processors in this document.

13. Liability

Each party will be liable for the damages arising from the breach of the obligations that the GDPR imposes directly on data processors or on data controllers, respectively, in accordance with Article 82 GDPR. This clause governs exclusively the internal allocation of liability between the Parties and does not limit, modify or exclude the right of any data subject to claim directly against the Processor, the Controller, or both jointly and severally, in accordance with Article 82(4) GDPR.

14. Governing law and jurisdiction

This Agreement is governed by Spanish law and, in matters not provided for herein, by Regulation (EU) 2016/679 (GDPR) and Organic Law 3/2018 (LOPDGDD, Spain's Organic Law on Data Protection). For any dispute, the parties submit to the Courts and Tribunals of Granada.


This is a courtesy translation of the Spanish original. In the event of any discrepancy, the Spanish version published at https://crisolmcp.com/legal/dpa prevails.

Last updated: July 25, 2026

Crisol MCP SEO · ANALYTICS
Legal notice Cookie policy Privacy policy Terms and conditions Cookie preferences
Read-only on your accounts · Encrypted at rest · Built for AI agents

COOKIES

At Crisol MCP we use our own cookies, needed for the site to work, and Google Analytics cookies to understand how the site is browsed and improve it. The analytics ones collect a pseudonymous identifier for your browser, the pages you visit, your approximate location and your device's characteristics. We do not use them for advertising or to build advertising profiles, and they are not installed if you do not accept them.

See the full cookie policy →

CONFIGURE YOUR COOKIES

The technical ones are needed for the site to work; the analytics ones are optional and help us improve it.

Needed for the site to load and work. They do not require consent and cannot be switched off.

See the full cookie policy →