MCP Connect

Privacy

Privacy policy

What MCP Connect processes when you connect company services to an approved AI assistant, and the choices you have.

Effective and last updated: 18 August 2026

Controller

schoene neue kinder GmbH
Candidplatz 11
81543 Munich
Germany

On this page

Scope and purpose Account data Connector data How content is handled Recipients and transfers Retention and deletion Security Legal basis and rights

01

Scope and purpose

MCP Connect is SNK's internal connection service. It lets authorized users retrieve information from connected company services and use the limited write actions that SNK has enabled.

We process data to sign users in, maintain provider connections, enforce access rules, complete requested actions, protect the service, investigate incidents, and meet provider privacy requirements. MCP Connect does not sell personal data, use it for advertising or model training, or make decisions with legal or similarly significant effects.

02

Account and service data

Identity
SNK account details, a stable internal person identifier, work email aliases, employment or directory status, and the provider identifiers needed to match the same person across services. Identity information can come from Personio and the connected provider directories.
Connections
Provider user and tenant references, approved scopes, connection status and timestamps, and encrypted OAuth grants. This includes the relevant Google Workspace domain, Atlassian site, HubSpot portal, team or workspace, and Tempo Jira-site binding.
Security and operations
Hashed session tokens, short-lived encrypted cursor state, consent state, request IDs, rate-limit counters, and minimal write receipts used to prevent duplicate actions.
Audit records
An internal principal ID, tool name, opaque resource reference, policy result, status class, timing, and aggregate result count where applicable. Audit records do not contain requested provider content.

03

Data available through each connector

The exact data depends on the action you request, the scopes you approve, your permissions in the source service, and SNK's access rules.

Connector Data MCP Connect may process
Google WorkspaceGmail messages, drafts and attachments; Drive files and folders; Calendar lists, availability, events, attendees and attachments.
AtlassianJira issues, comments, worklogs, attachments and users; Confluence spaces, pages, folders and attachments.
MiroUser and workspace references, board metadata, board content and board items.
FigmaCurrent-user details, file metadata, file content and rendered design nodes.
HubSpotOwner, company, contact and deal records.
TempoTeams, members, accounts, work attributes, resources, worklogs, plans, schedules and capacity.
SlackProfile and directory details, joined conversations, messages and files.

04

How provider content is handled

Provider content is fetched for the active request, filtered, returned to the approved AI assistant you selected, and then discarded by MCP Connect. It is not stored in the MCP Connect database, audit trail, or application logs.

This includes message and document bodies, calendar details, attachments, parsed text, images, search text, JQL and CQL, CRM content, board and design content, and time-planning details. OAuth tokens are never stored in plaintext, and upstream error bodies are not logged.

The site uses only cookies needed for sign-in, security, and short-lived provider authorization transactions. It has no analytics or advertising trackers.

05

Recipients and international transfers

MCP Connect exchanges data with Google Workspace, Atlassian, Miro, Figma, HubSpot, Tempo, and Slack when you use those connectors. Results go to the approved MCP client you selected, such as Claude or Codex. DigitalOcean hosts the application and managed PostgreSQL database in Frankfurt, Germany.

Some connected services may process data outside the European Economic Area. SNK relies on the contractual and organizational transfer safeguards that apply to those services. MCP Connect does not disclose data to data brokers or advertising networks.

06

Retention, disconnection, and deletion

  • OAuth authorization requests and codes expire within five minutes.
  • Browser dashboard sessions expire after 30 minutes idle and no later than eight hours. Search cursors expire within 15 minutes.
  • MCP access tokens expire within 15 minutes; refresh sessions expire within 30 days and can be revoked earlier.
  • Rate-limit counters are removed after two days. Content-free audit events are retained for up to 30 days.
  • Encrypted provider grants remain while access is active and are deleted on replacement, invalid authorization, disconnect, offboarding, or an applicable provider privacy action.
  • Employee identity records and mapping history are retained, deactivated, or restricted under SNK's employment, security, and accountability lifecycle.

Disconnecting removes the local provider grant and authorization state, then asks the provider to revoke access where its API supports that. Other connections remain active. Miro app installation is managed separately in Miro. Protected backups are cleared through the managed backup lifecycle.

For Atlassian privacy compliance, MCP Connect periodically reports the stored Atlassian account ID and the date it was obtained to Atlassian's Personal Data Reporting API. A closed or updated Atlassian account causes the affected grant to be removed.

07

Security

Provider grants are encrypted at rest and bound to the user and environment. MCP tokens are stored only as hashes. The service uses short-lived sessions, least-privilege scopes, current provider permission checks, SNK access policy, rate limits, duplicate-write protection, isolated document parsing, sanitized logs, and restricted database roles.

08

Legal basis and your rights

SNK processes this data where necessary to administer the employment or contractual relationship, to meet legal obligations, and for its legitimate interests in giving authorized staff secure access to company systems. Provider consent is the technical permission for API access; it is not the sole legal basis for processing.

Subject to applicable law, you may request access, correction, deletion, restriction, or portability, and you may object to processing. You can use SNK's established privacy process or write to the controller at the address shown on this page. You may also complain to the competent data-protection supervisory authority.

This notice supplements other SNK employee or contractual privacy notices.

09

Changes to this policy

We update this page when the service adds a connector or materially changes how it uses, shares, or retains data. The date at the top identifies the current version.

© schoene neue kinder GmbH
About Privacy Terms snk.de