Legal documents

Privacy Policy

This Privacy Policy explains how Werkdata OÜ (“Werkdata”, “we”) collects and processes personal data when you use the OrgMCP platform (the “Service”). This policy is designed to comply with Regulation (EU) 2016/679 (the “GDPR”) and the equivalent United Kingdom regime (the “UK GDPR”).

Effective
23 July 2026
Version
v2.0
Last updated
23 July 2026
Operator
Werkdata OÜ · Tallinn, Estonia
Need the signed PDF? Email legal@orgmcp.io.

1. Data controller

Werkdata OÜ, with registered office in Tallinn, Estonia, is the data controller for personal data of:

  • Visitors to orgmcp.io and our marketing pages.
  • Workspace owners and invited members during account creation, sign-in and billing — including individuals whose name and email address we receive as part of an invitation before they accept it.
  • Anyone who contacts us by email or via the in-product help widget.

For Customer Data uploaded into or indexed by a Workspace, Werkdata acts as a data processor on behalf of the Workspace owner (the controller). The terms of that processing are governed by the Data Processing Addendum.

You can reach us at privacy@orgmcp.io for any privacy-related request.

2. Categories of personal data

We process the following categories of personal data:

  • Account data — name, email, profile picture (from WorkOS AuthKit during sign-up).
  • Billing data — company name, billing address, VAT number, last-four of payment card (handled by Stripe; we never touch full card data).
  • Usage data — per-tenant counters of MCP tool invocations and knowledge-source ingest jobs, used for billing and rate-limiting.
  • Audit logs — timestamped record of security-relevant events (logins, invites, role changes, connector edits, deletion requests). Retention varies by plan; see Section 6 below.
  • Connector tokens — per-tenant or per-user OAuth access/refresh tokens for third-party services. Stored as AWS-KMS-encrypted SecureStrings; never logged.
  • Contract performance (GDPR Art. 6(1)(b)) — to provide the Service you signed up for and to operate billing.
  • Legitimate interest (GDPR Art. 6(1)(f)) — operational security (audit logs, rate-limiting, abuse and fraud prevention) and to keep the Service running reliably. A balancing test is documented internally and available on request.
  • Consent (GDPR Art. 6(1)(a)) — only where we ask for it explicitly (for example, before enabling any non-essential cookies in the future). All of our current cookies are strictly necessary; see the Cookie Policy.
  • Legal obligation (GDPR Art. 6(1)(c)) — accounting and tax records, and responses to lawful law-enforcement requests.

4. Sub-processors and independent controllers

We rely on a short list of sub-processors to deliver the Service. The authoritative list with regions and transfer mechanisms lives at /legal/sub-processors and is updated whenever it changes. Today these are:

  • Amazon Web Services (eu-central-1, Frankfurt) — RDS Postgres, OpenSearch Serverless, S3, ECS, KMS, SES, and AWS Bedrock for retrieval embeddings.
  • WorkOS — authentication, SSO and SCIM.
  • Stripe — billing and payment processing.
  • Sentry (eu.sentry.io) — error reporting; request bodies are scrubbed.

Independent controllers (Customer connectors). When you connect an external SaaS source — GitHub, Google Drive, Slack, Linear, Notion, Atlassian (Jira, Confluence, Bitbucket), GitLab, Sentry, Figma, Vercel, Airtable, Dropbox, Trello — those vendors act as independent controllers with respect to the data they hold. OrgMCP holds the OAuth tokens your administrator granted and reads through their APIs; we do not have a sub-processor relationship with those vendors and they are governed by your own contracts with them.

5. International transfers

All Customer Data is stored in AWS eu-central-1(Frankfurt) by default. A small amount of operational metadata may be processed by sub-processors outside the EEA (notably WorkOS and Stripe's US infrastructure). For those transfers we rely on:

  • The EU-US Data Privacy Framework where the recipient is certified and the certification covers the relevant data category;
  • The Standard Contractual Clauses approved by EU Commission Decision 2021/914 (Module 2 controller → processor, or Module 3 processor → sub-processor), with supplementary technical and organisational measures (encryption in transit, encryption at rest, strict key management and no plaintext processing in non-EEA regions); and
  • For UK data subjects, the UK International Data Transfer Addendum to the SCCs (in the form approved by the UK Information Commissioner's Office).

We maintain a Transfer Impact Assessment for each non-EEA sub-processor and provide a copy on written request to privacy@orgmcp.io.

6. Retention

Personal data is retained for the lifetime of your account. After account deletion: a 30-day soft-delete window for recovery, then permanent purge. Audit logs follow the per-plan retention table below. Billing records are kept for 7 years to satisfy Estonian tax law (Raamatupidamise seadus § 12).

Audit-log retention by plan tier. Source of truth: docs/ARCH-security-compliance.md.
Plan tierRetentionNotes
Free90 days
Team1 year
Business1 year
EnterpriseUnlimitedOptional Kinesis stream to the customer SIEM

7. Your rights

Under the GDPR and UK GDPR you have the rights of access, rectification, erasure, restriction, portability, and objection, plus the right not to be subject to automated decisions producing legal or similarly significant effects (we do not make such decisions about you). Workspace owners can exercise the data-portability and erasure rights self-serve:

  • Export your workspace data via GET /api/t/<slug>/export (GDPR Art. 15 / 20).
  • Schedule workspace deletion (after sign-in) at Settings → Danger zone (GDPR Art. 17). The 30-day soft-delete window can be cancelled by the owner up until purge.

Other rights — or a complaint to the supervisory authority (in Estonia: Andmekaitse Inspektsioon (Estonian Data Protection Inspectorate)) — can be raised via privacy@orgmcp.io. We aim to respond within 30 days and will extend by up to two further months only where strictly necessary.

8. Security

Encryption in transit (TLS 1.2+), encryption at rest (RDS storage and S3 SSE-KMS), per- tenant AWS Secrets Manager entries with KMS key separation, AWS WAFv2 with managed rule sets and per-IP rate limiting in front of the ALB, mandatory tenant + audience filters on every retrieval query, automated encrypted RDS backups with point-in-time recovery (14-day retention), and on-call alerting with PII-scrubbed Sentry error reports. We plan to commission independent third-party penetration testing and to pursue SOC 2 attestation; neither is complete yet, and we will update this page (and trust.orgmcp.io) when they are.

9. Data Protection Officer

Werkdata has not designated a statutory Data Protection Officer under GDPR Art. 37 (our processing does not, on its face, meet the size or special-category thresholds that compel designation). We have nonetheless nominated a privacy contact who handles all data- subject requests and supervisory-authority correspondence: privacy@orgmcp.io. We will re-assess the designation requirement as our processing grows and will update this section if we appoint a DPO.

10. UK GDPR representative

We process limited amounts of personal data of individuals located in the United Kingdom (for example, UK customers signing up). Where the UK GDPR requires us to designate a UK representative under Article 27, that representative's details are available on written request to privacy@orgmcp.io. UK data subjects can in the meantime raise any GDPR-style rights request directly to that same address.

11. Estonian Personal Data Protection Act

Estonian national data-protection law (Isikuandmete kaitse seadus, “IKS ”) applies to our processing alongside the GDPR. The competent supervisory authority is the Estonian Data Protection Inspectorate (aki.ee). The IKS does not derogate from the data-subject rights set out in Section 7 above.

12. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be announced with at least 30 days' advance notice (in-app banner plus email to the Workspace owner). The current version, effective date and changelog are always visible at the top and bottom of this page.

13. Contact

Privacy questions: privacy@orgmcp.io. Legal: legal@orgmcp.io.

Changelog

  • v2.012 May 2026Aligned audit-log retention with the engineering source of truth (Free 90 days / Team 1 year / Business 1 year / Enterprise unlimited). Re-classified GitHub and Google as independent controllers, not sub-processors. Added a Schrems II-aware international-transfers section, a DPO statement, a UK Art. 27 representative note, and a reference to the Estonian IKS. Removed the unused “marketing emails” legal basis.
  • v1.01 April 2026Initial publication.