Data Processing Agreement (DPA)
Last updated: 24 July 2026
This data processing agreement (the "DPA") forms part of the Terms & Conditions and applies where Context Engineer (Dutch Chamber of Commerce 99945274, the Netherlands; the "Processor") processes personal data on your behalf when providing Context Engineer MCP (the "Service") to you as a business customer (the "Controller"), within the meaning of Article 28 GDPR. If you use the Service as a company or organization that is the controller of the connected data, you enter into this DPA with us. Need a signed copy? E-mail joris@context-engineer.nl.
1. Roles and definitions
You are the controller of the personal data in the services you connect (for example your GA4 property, Google Ads account or Craft site). Context Engineer is the processor and processes that data solely to provide the Service. Terms such as personal data, processing, data subject and sub-processor have the meaning given in the GDPR. The nature, purpose and categories of processing are set out in Annex 1.
2. Subject matter and duration
The subject matter is relaying requests between your AI client and your connected services, plus managing your account and billing (see Annex 1). This DPA applies for as long as the Service is provided to you and for as long as we process personal data on your behalf thereafter. Provisions that by their nature survive (such as confidentiality and liability) remain in force after it ends.
3. Processing only on instructions
We process your personal data only on your documented instructions. Those instructions consist of this DPA, the Terms, your configuration of the Service and the requests your AI client sends on your behalf, and they also apply to transfers of personal data to a third country or international organization. We may depart from them only where processing is required by European Union or Dutch law to which we are subject; in that case we inform you of that legal requirement before processing, unless that law prohibits this on important grounds of public interest. We do not process your data for our own purposes. In particular, we do not use the content that flows through the Service to train, develop or improve AI models or our service, and we do not sell or share that content. If we believe an instruction breaches the GDPR or other data protection law, we will inform you.
4. Confidentiality
Persons authorized under our control to access your personal data (currently the operator only) are bound by confidentiality and process the data only on instructions.
5. Security
We implement appropriate technical and organizational measures (Article 32 GDPR) to protect your data, taking into account the state of the art and the risks. These measures are described in Annex 2. In short: connection credentials are stored encrypted (AES-256-GCM), traffic runs over TLS, everything runs on EU servers, and the content of requests and responses is not stored.
6. Sub-processors
You give general authorization for the sub-processors listed in Annex 3. We impose equivalent data protection obligations on each sub-processor by contract and remain liable to you for their acts. If we intend to add or replace a sub-processor, we announce it at least 30 days in advance on this page and by e-mail to the address we have on file. You may object on reasonable, data-protection-related grounds; if we cannot resolve the objection, you may terminate the affected connection.
7. Data subject rights
We assist you, with appropriate technical and organizational measures, in responding to data subject requests (access, rectification, erasure, objection, restriction, portability). Because we do not store the content of your connected services, such requests mainly concern account and usage data at our end. If we receive a data subject request or a supervisory authority inquiry concerning your data, we forward it to you without undue delay and do not respond ourselves without your authorization.
8. Personal data breaches
If we become aware of a personal data breach affecting your data, we notify you without undue delay and in any event within 72 hours of becoming aware. The notification includes, where available, the nature of the breach, the categories and approximate number of affected data subjects and records, the likely consequences and the measures taken or proposed. We support you in meeting your own notification duties to the supervisory authority and data subjects.
9. DPIA and prior consultation support
Taking into account the nature of processing and the information available to us, we reasonably assist you with data protection impact assessments (DPIAs) and, where needed, prior consultation of the supervisory authority.
10. Return and deletion
On termination of the Service, or earlier at your request, we delete or return the personal data we process on your behalf (your connection credentials and related data), at your choice, except where EU or Dutch law requires retention (for example invoices for 7 years). On request we confirm deletion in writing.
11. Audits and demonstrating compliance
We make available the information needed to demonstrate compliance with Article 28 GDPR. You, or an independent auditor bound by confidentiality who is not a competitor of ours, may audit compliance once per year with at least 30 days' notice; we may also satisfy this through up-to-date documentation or certifications. Each party bears its own costs, unless the audit reveals a material non-compliance, in which case we reimburse the reasonable audit costs.
12. Transfers outside the EU/EEA
The Service and database run in the EU; database backups are stored encrypted in Cloudflare R2 with a Western Europe data location. Where a sub-processor is a US (parent) company or processes data outside the EEA (transactional e-mail via Resend, Inc.; backup storage with Cloudflare, Inc.), it does so under standard contractual clauses (SCCs) or another appropriate transfer mechanism. Transfer of your Google data depends on your own Google configuration and is covered by Google's SCCs. See also our Privacy Policy.
13. Liability and governing law
Liability under this DPA is governed by the Terms & Conditions, provided that nothing limits liability that cannot be limited under the GDPR. This DPA is governed by Dutch law; disputes are submitted to the competent court in the Netherlands. In case of conflict between this DPA and the Terms, this DPA prevails as far as the processing of personal data is concerned.
14. Changes
We may update this DPA as the Service or our sub-processors evolve; the "Last updated" date above reflects the latest version, and material changes will be announced on this page or by e-mail.
Annex 1: Details of processing
| Subject matter | Relaying requests between your AI client and your connected services, plus account management and billing. |
|---|---|
| Nature and purpose | Proxying API requests and responses on your behalf; managing your connection and subscription. |
| Duration | The term of the agreement, plus statutory retention periods. |
| Categories of data subjects | You and your staff or users, and data subjects whose personal data appears in the content of your connected services (for example website visitors in GA4 or contacts in your CMS), transiently only. |
| Types of personal data | Account data (name, e-mail, language, billing details such as company, address and VAT number, plus Mollie IDs); connection credentials (encrypted OAuth tokens or a Craft GraphQL token); usage metadata (tool names, counts, timestamps); and the transient content of requests and responses, processed in memory only and not stored. |
Annex 2: Technical and organizational measures
- Encryption at rest (AES-256-GCM) of connection credentials; TLS for traffic in transit.
- EU-only hosting (Hetzner, Germany); the database runs on the same EU infrastructure.
- The content of requests and responses is not stored; only aggregated usage counters are kept.
- No use of customer data to train models or to develop our service.
- Least-privilege access; a single operator, bound by confidentiality, over authenticated channels.
- Tokens scoped to the minimum; you control the scope (Craft) and can revoke access at any time (Google).
- Minimal logging; no request or response content is logged.
- Automated database backups of operational data to object storage with a Western Europe data location, encrypted at rest; plus a personal data breach response process.
- Secure development: dependency management and a mandatory production build before deployment.
Context Engineer is a small operation; the measures are proportionate to the risk and are updated as the Service evolves.
Annex 3: Sub-processors
| Sub-processor | Purpose | Location | Safeguard |
|---|---|---|---|
| Hetzner Online GmbH | EU hosting (servers and database) | Germany (EU) | Within the EU/EEA |
| Cloudflare, Inc. | Encrypted storage of database backups (R2) | Western Europe data location; US company | Standard contractual clauses (SCCs) |
| Resend, Inc. | Transactional e-mail delivery | United States | Standard contractual clauses (SCCs) |
For clarity: Mollie B.V. (the Netherlands) processes payments as an independent controller under its own legal obligations and privacy policy, and is therefore not a sub-processor. Google is not our sub-processor but your own connected data source that you authorize; and your AI client (for example Anthropic's Claude) is your tool, not our sub-processor. They process your data under your own arrangements with those parties.