Legal
Privacy Policy
Last updated: July 2026
1. Scope
This Privacy Policy explains how MCP Data (“we”, “us”) handles information in two distinct contexts: (a) data collected through this website — the contact form, cookies, and newsletter sign-ups — and (b) official public data delivered through the API/MCP endpoints of the Service.
By using this website or the Service, you accept the practices described here. If you disagree, please do not use the website or the Service.
2. MCP Data does not collect, store, or sell personal data through the API
The Service enriches data that our clients already hold about their own end users, using context derived from official public sources (geographic, territorial, and identity/company registries). MCP Data does not build or maintain its own database of end-user personal data, and does not commercialize personal data as a product.
Each query made to an MCP endpoint is processed to return the requested official-source data; MCP Data does not retain query inputs beyond what is strictly necessary for billing, abuse prevention, and service reliability (e.g., credit consumption logs, rate-limit counters).
3. Origin of the data returned by the Service
All information returned by the Service originates from official public sources — the same registries that governments, financial institutions, and regulators consult in each country.
Data is organized and stored in segmented, non-interconnected data sets per source and per country. This separation is a deliberate design choice that limits cross-linking of records and helps protect the integrity of the underlying information.
| Country | Applicable data protection framework |
|---|---|
| 🇦🇷 Argentina | Ley 25.326 de Protección de Datos Personales |
| 🇲🇽 Mexico | LFPDPPP |
| 🇨🇴 Colombia | Ley 1581 de Habeas Data |
| 🇪🇨 Ecuador | LOPDP — Ley Orgánica de Protección de Datos |
| 🇵🇪 Peru / 🇨🇱 Chile | Applicable national frameworks (rollout in progress) |
4. Data collected on the website
When you use the contact form, we collect the fields you submit: name, email, organization, service of interest, and message. When you request free-tier credits, we collect your corporate email address. This information is used to:
- Respond to your inquiry and provide the requested information.
- Provision and manage your account and credit balance.
- Send service-related communications (updates, billing notices, security notices).
- With your consent, send product news and marketing communications.
- Improve the website and the Service based on aggregated usage analysis.
5. Consent
By voluntarily submitting your data through the website, having been informed of the purpose of processing, the identity of the data controller, and your rights of access, rectification, and deletion, you give express consent for MCP Data to process your data as described in this Policy.
6. International data transfer
To operate the Service, data may be processed by infrastructure and sub-processors located outside your country of residence (see Section 9). In all cases we take measures intended to ensure an adequate level of protection and to safeguard your rights as a data subject.
7. Your rights
You may withdraw consent to be contacted at any time, and exercise your rights of access, rectification, and — where applicable — deletion of your personal information, free of charge, upon verification of your identity.
To exercise these rights, email contact@mcpdata.io indicating the request and the data concerned. We aim to respond within a reasonable time frame in line with the applicable framework listed in Section 3.
If you are not satisfied with our response, you may contact the data protection authority competent in your jurisdiction (in Argentina, the Agencia de Acceso a la Información Pública).
8. Data retention
Website-related personal data is retained only for as long as necessary to fulfill the purposes described in Section 4, or until you request its deletion.
9. Confidentiality & security of information
We keep the information in our systems confidential, except where disclosure is required by law. We have implemented technical and organizational measures appropriate to the risk, including hosting the Service on infrastructure provided by DigitalOcean and Cloudflare, both independently certified under SOC 2 Type II, ISO/IEC 27001, and PCI DSS. Public compliance reports for each provider are linked in the footer of this site.
If a security incident is detected that poses a significant risk to data subjects, we will notify the competent data protection authority without undue delay, together with the corrective measures adopted.
10. Cookies
This website uses cookies to support navigation and improve the user experience. Continued use of the site implies acceptance of this use.
11. Governing law
This Policy is governed by the data protection laws of Argentina, including Ley 25.326. Any dispute will be submitted to the competent courts of Buenos Aires, Argentina.
12. Contact
Questions about this Policy or requests to exercise your rights can be sent to contact@mcpdata.io.