MCP & AI Connector Usage Policy
v1.0 · Published 30 September 2026
When you authorise an MCP connection, enabled tools can return information from your Autom Mate environment to the MCP client you select. With a hosted AI service, that information becomes available to the service and may form part of its conversation context, history or records under your arrangement with that provider.
Publication date: 30 September 2026. Contractual provisions take effect in accordance with your applicable Agreement and DPA.
1. Scope and relationship to other terms
This policy explains the use of Autom Mate's authorised Model Context Protocol (MCP) connector and hosted gateway, including connections to ChatGPT, Claude and other compatible clients. It covers customer-enabled access to an Autom Mate environment. It does not authorise unrestricted access to that environment.
It supplements our Privacy Policy and, where applicable, your End User License Agreement (EULA), order and Data Processing Addendum (DPA). It does not replace the DPA, create an international transfer mechanism, reduce statutory rights or expand the processing permitted by your agreement. Applicable contractual precedence and amendment provisions continue to apply.
An AI service engaged by Autom Mate to deliver a separate built-in product feature must be assessed and disclosed under the arrangements for that feature. It is not treated as customer-selected merely because this policy describes customer-enabled connectors.
2. Connecting and authorising access
You initiate the connection and authenticate through the authorised sign-in flow using your Autom Mate account. Review the client identity, environment, requested permissions and this policy before authorising access. Do not enter Autom Mate passwords, API keys or other authentication secrets into an AI conversation.
Only connect accounts and environments you are authorised to use. If acting for an organisation or its customers, you must have the required authority and follow their approval procedures. Authentication verifies an account; it does not by itself establish authority to disclose all information that the account can access.
The connector applies the permissions of the connected Autom Mate user. Tool availability and scope also determine what the client can request. An enabled client may make tool calls while handling a request without you manually typing a separate instruction for each call. Authorise only the access appropriate for your intended use.
3. Information that may be returned
The information returned depends on the enabled tool, the request and the permissions of the connected user. This may include operational information about automations, runs and agents, together with the following personal information:
- Names and email addresses of users in the environment, with their assigned roles and account status.
- The name of the person who created or last updated an automation.
- The name of the person who initiated an automation run or owns a stored connection.
Information returned by a tool is disclosed to the connected client. For a hosted AI client, its provider can process the returned information under the terms and settings applicable to your account. A locally operated client has its own processing and storage arrangements.
The connector does not return stored credential values, passwords or API keys as tool results. Do not place secrets or unnecessary personal or confidential information in fields that are exposed through connector tools.
4. Your organisation's use of the connector
Select a client and account plan that your organisation has approved for the data involved. Assess the provider's terms, retention, model-training settings, access controls and processing locations before enabling the connection. Do not use a connection to bypass your organisation's security, confidentiality or data protection requirements.
Ensure that you have the appropriate authority and lawful basis for the information you make available, including information about employees, customers or other individuals. An MSP or service provider must also follow the instructions and authorisations of the relevant customer or controller.
Use the minimum permissions and information necessary for the task, and remove connections that are no longer needed. Do not request data or actions that you are not authorised to access or perform.
5. Tools that can perform actions
Some enabled tools can initiate automations or perform other supported actions, rather than only retrieve information. Review the intended action, affected environment and relevant permissions before authorising it. A general connection authorisation is not a substitute for any action-specific approval required by the product, client or your organisation.
AI-generated suggestions and summaries can be inaccurate. Review consequential decisions and actions using the underlying records and your organisation's approval process. Autom Mate remains responsible for the access controls and security obligations applicable to its service.
6. Autom Mate's hosted gateway
The hosted gateway at mcp.autommate.app operates in AWS eu-central-1 (Frankfurt). It maintains encrypted access tokens for the connection, an association with the relevant environment and request audit records identifying the environment, connection, requested operation, outcome and duration.
The MCP gateway handles tool request and response payloads in pass-through mode and does not store payload bodies as part of its connection or request audit records. Tokens, connection records and request audit metadata are retained separately. This description concerns the hosted MCP gateway; it does not describe retention by the underlying Autom Mate environment or the connected client or AI service.
Autom Mate processes customer personal data in accordance with the applicable DPA and instructions, including the relevant security, access-control and assistance obligations. Hosting location alone does not determine the location of processing or access by your selected client or its provider.
7. Retention and disconnection
To disconnect a client or revoke its access, use the relevant connection controls available in Autom Mate and your selected client, or contact [email protected] for assistance. Check any remaining authorisations in both services; removing an entry in one service does not by itself establish that access has been revoked in the other.
Disconnecting an MCP client is separate from deleting your Autom Mate account and all associated user accounts. It does not, by itself, delete information already returned to the client or remove its conversation history. Manage that information through the selected client or AI service's applicable retention and deletion controls.
Access tokens are used to authenticate authorised connections. Connection records associate those connections with an environment, and request audit metadata supports operation, security and troubleshooting. Retention and deletion of Customer Personal Data in those records remain subject to the applicable DPA and Customer's instructions.
Where the DPA applies, Section 7.2 requires Autom Mate to delete Customer Personal Data in its possession within 30 days after it receives Customer's request to delete the Customer account and all associated user accounts, or after Customer and all associated users delete their accounts. The data must be made available for Customer to download before deletion. Annex I, Section B.7 states the retention period as the duration of Customer's subscription plus 30 days. These existing requirements continue to apply to MCP processing; this policy does not extend them.
Customer may request deletion of Customer Personal Data in connection records under Section 2.6 of the DPA by contacting [email protected]. Any copy that Autom Mate is required by applicable law to retain remains subject to the applicable DPA. For personal information outside the DPA, Section 5 of the Privacy Policy sets out the applicable retention criteria and periods.
8. Selected AI services and provider roles
ChatGPT, Claude and other clients have their own service terms and data practices. The relevant provider entity, account plan and settings determine how it handles information received through the connector, including retention, model training, onward disclosure and support access. Autom Mate does not promise a particular provider configuration simply because that provider supports MCP.
A provider independently selected and contracted by a customer is not automatically a subprocessor appointed by Autom Mate. Where Autom Mate engages a provider to process customer personal data on its behalf, the applicable subprocessor obligations and disclosures apply. Roles are determined by the actual processing and contractual arrangements.
Customer selection does not remove Autom Mate's obligations for the part of the service and processing it performs. Responsibility and liability remain subject to the applicable agreements and mandatory law.
For the current terms and controls that apply to your chosen plan, consult your provider. The links below are provided for convenience; available controls and defaults can vary by account, plan and workspace. Turning off model training does not necessarily delete data or disable other processing permitted under the provider agreement.
For other compatible clients, review the corresponding provider documentation and your organisation’s approved settings.
9. Data locations and international transfers
Depending on your selected client, provider entity, plan and processing or support arrangements, connector data may be processed outside the country or region in which your Autom Mate environment is hosted.
An authorised connection and its recorded scope can document a customer instruction. It is not, by itself, the consent of every individual whose data is returned, a waiver of the DPA or a safeguard for international transfers.
Any applicable contractual and legal transfer requirements must be satisfied before the relevant processing occurs. Autom Mate and the customer must apply their respective obligations under the DPA and applicable law; the connection must not be used to bypass those requirements.
10. Questions, rights and policy updates
For privacy questions or assistance with data rights, contact [email protected]. For technical assistance with a connection, contact [email protected]. Your organisation's administrator should be your first contact for company-specific access permissions and approved AI clients.
We will identify this policy by version and publication date. Material changes will be handled under the applicable notice and contractual amendment requirements. Publication of this policy does not, by itself, accelerate an existing contract's effective date or replace a required subprocessor notice.
