NL · EN

Back to Context Engineer MCP

Data Processing Agreement (DPA)

Last updated: 24 July 2026

This data processing agreement (the "DPA") forms part of the Terms & Conditions and applies where Context Engineer (Dutch Chamber of Commerce 99945274, the Netherlands; the "Processor") processes personal data on your behalf when providing Context Engineer MCP (the "Service") to you as a business customer (the "Controller"), within the meaning of Article 28 GDPR. If you use the Service as a company or organization that is the controller of the connected data, you enter into this DPA with us. Need a signed copy? E-mail joris@context-engineer.nl.

1. Roles and definitions

You are the controller of the personal data in the services you connect (for example your GA4 property, Google Ads account or Craft site). Context Engineer is the processor and processes that data solely to provide the Service. Terms such as personal data, processing, data subject and sub-processor have the meaning given in the GDPR. The nature, purpose and categories of processing are set out in Annex 1.

2. Subject matter and duration

The subject matter is relaying requests between your AI client and your connected services, plus managing your account and billing (see Annex 1). This DPA applies for as long as the Service is provided to you and for as long as we process personal data on your behalf thereafter. Provisions that by their nature survive (such as confidentiality and liability) remain in force after it ends.

3. Processing only on instructions

We process your personal data only on your documented instructions. Those instructions consist of this DPA, the Terms, your configuration of the Service and the requests your AI client sends on your behalf, and they also apply to transfers of personal data to a third country or international organization. We may depart from them only where processing is required by European Union or Dutch law to which we are subject; in that case we inform you of that legal requirement before processing, unless that law prohibits this on important grounds of public interest. We do not process your data for our own purposes. In particular, we do not use the content that flows through the Service to train, develop or improve AI models or our service, and we do not sell or share that content. If we believe an instruction breaches the GDPR or other data protection law, we will inform you.

4. Confidentiality

Persons authorized under our control to access your personal data (currently the operator only) are bound by confidentiality and process the data only on instructions.

5. Security

We implement appropriate technical and organizational measures (Article 32 GDPR) to protect your data, taking into account the state of the art and the risks. These measures are described in Annex 2. In short: connection credentials are stored encrypted (AES-256-GCM), traffic runs over TLS, everything runs on EU servers, and the content of requests and responses is not stored.

6. Sub-processors

You give general authorization for the sub-processors listed in Annex 3. We impose equivalent data protection obligations on each sub-processor by contract and remain liable to you for their acts. If we intend to add or replace a sub-processor, we announce it at least 30 days in advance on this page and by e-mail to the address we have on file. You may object on reasonable, data-protection-related grounds; if we cannot resolve the objection, you may terminate the affected connection.

7. Data subject rights

We assist you, with appropriate technical and organizational measures, in responding to data subject requests (access, rectification, erasure, objection, restriction, portability). Because we do not store the content of your connected services, such requests mainly concern account and usage data at our end. If we receive a data subject request or a supervisory authority inquiry concerning your data, we forward it to you without undue delay and do not respond ourselves without your authorization.

8. Personal data breaches

If we become aware of a personal data breach affecting your data, we notify you without undue delay and in any event within 72 hours of becoming aware. The notification includes, where available, the nature of the breach, the categories and approximate number of affected data subjects and records, the likely consequences and the measures taken or proposed. We support you in meeting your own notification duties to the supervisory authority and data subjects.

9. DPIA and prior consultation support

Taking into account the nature of processing and the information available to us, we reasonably assist you with data protection impact assessments (DPIAs) and, where needed, prior consultation of the supervisory authority.

10. Return and deletion

On termination of the Service, or earlier at your request, we delete or return the personal data we process on your behalf (your connection credentials and related data), at your choice, except where EU or Dutch law requires retention (for example invoices for 7 years). On request we confirm deletion in writing.

11. Audits and demonstrating compliance

We make available the information needed to demonstrate compliance with Article 28 GDPR. You, or an independent auditor bound by confidentiality who is not a competitor of ours, may audit compliance once per year with at least 30 days' notice; we may also satisfy this through up-to-date documentation or certifications. Each party bears its own costs, unless the audit reveals a material non-compliance, in which case we reimburse the reasonable audit costs.

12. Transfers outside the EU/EEA

The Service and database run in the EU; database backups are stored encrypted in Cloudflare R2 with a Western Europe data location. Where a sub-processor is a US (parent) company or processes data outside the EEA (transactional e-mail via Resend, Inc.; backup storage with Cloudflare, Inc.), it does so under standard contractual clauses (SCCs) or another appropriate transfer mechanism. Transfer of your Google data depends on your own Google configuration and is covered by Google's SCCs. See also our Privacy Policy.

13. Liability and governing law

Liability under this DPA is governed by the Terms & Conditions, provided that nothing limits liability that cannot be limited under the GDPR. This DPA is governed by Dutch law; disputes are submitted to the competent court in the Netherlands. In case of conflict between this DPA and the Terms, this DPA prevails as far as the processing of personal data is concerned.

14. Changes

We may update this DPA as the Service or our sub-processors evolve; the "Last updated" date above reflects the latest version, and material changes will be announced on this page or by e-mail.

Annex 1: Details of processing

Annex 2: Technical and organizational measures

Context Engineer is a small operation; the measures are proportionate to the risk and are updated as the Service evolves.

Annex 3: Sub-processors

For clarity: Mollie B.V. (the Netherlands) processes payments as an independent controller under its own legal obligations and privacy policy, and is therefore not a sub-processor. Google is not our sub-processor but your own connected data source that you authorize; and your AI client (for example Anthropic's Claude) is your tool, not our sub-processor. They process your data under your own arrangements with those parties.

Back to Context Engineer MCP