Legal

Privacy Policy

Effective Date: May 25, 2026
Last Updated: May 25, 2026

Apotrope ("Apotrope," "we," "us," or "our") provides an enterprise Model Context Protocol (MCP) server that enables organizations to build, deploy, and govern AI agents that interact with their internal tools and data. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our website, services, and platform (collectively, the "Services").

This policy applies to information we process as a controllerof personal data relating to our website visitors, prospective customers, and individual users of our Services. When we process customer data on behalf of an organization that uses our Services (our "Customer"), we act as a processor, and the Customer's privacy policy and our Data Processing Agreement ("DPA") govern that processing.

1. Information We Collect

1.1 Information You Provide

  • Account & waitlist information: work email address, name, job title, company name, and any information you submit through forms on our website (e.g., waitlist signup, demo requests, contact forms).
  • Customer account data: information provided by administrators when configuring the Services, including user identities, role assignments, organizational structure, integration credentials, and policy configurations.
  • Communications: messages, support tickets, and feedback you send to us.
  • Billing information: for paid customers, billing contact details and payment information processed by our payment processor.

1.2 Information Collected Automatically

  • Usage data: logs of API calls, agent invocations, integration requests, permission checks, latency metrics, error events, and feature usage.
  • Device & technical data: IP address, browser type and version, operating system, device identifiers, referring URLs, and timestamps.
  • Cookies and similar technologies: session cookies, authentication tokens, and analytics identifiers. See Section 8 for details.
  • Audit logs: records of administrative actions, access events, and policy decisions made within the Services. These are retained to support customer compliance obligations (SOC 2, GDPR, etc.).

1.3 Information from Third Parties

  • Identity providers: when you sign in through SAML SSO or SCIM provisioning (e.g., Okta, Google Workspace, Azure AD), we receive the identity attributes your provider sends, such as email, name, and group memberships.
  • Integrated tools: when an administrator connects third-party tools (Notion, Google Drive, Slack, GitHub, Salesforce, etc.), we receive OAuth tokens and the data those tools return in response to authorized agent requests. We do not retain the content of integration responses beyond what is required for the request lifecycle and any audit logs the Customer has configured.
  • Business sources: publicly available business information used for sales outreach and account verification.

1.4 Information We Do Not Want

We do not knowingly seek special categories of personal data (health, biometric, religious, etc.) or information about children under 16. Please do not submit such information through the Services unless required by your enterprise use case and contemplated by your agreement with us.

2. How We Use Information

We use the information described above to:

  • Provide, operate, secure, and improve the Services;
  • Authenticate users and enforce access policies;
  • Process and route agent requests through the MCP server;
  • Maintain audit logs and support customer compliance requirements;
  • Monitor performance, debug errors, and detect abuse or security incidents;
  • Communicate with you about your account, the Services, security advisories, and product updates;
  • Respond to inquiries, demo requests, and waitlist applications;
  • Process payments and manage billing;
  • Conduct analytics to understand product usage and improve features;
  • Comply with legal obligations and enforce our terms.

Legal Bases (GDPR / UK GDPR)

Where the GDPR or UK GDPR applies, we rely on the following legal bases:

  • Performance of a contract with you or your employer;
  • Legitimate interests in operating, securing, and improving our Services (balanced against your rights);
  • Consent, where required (e.g., certain cookies, marketing communications);
  • Compliance with legal obligations (e.g., tax, accounting, lawful requests).

3. How We Share Information

We share information only as described below. We do not sell personal data.

  • Sub-processors: we engage vetted vendors to host infrastructure, process payments, send transactional email, monitor performance, and provide customer support. A current list of sub-processors is available at [INSERT URL] and is incorporated into our DPA.
  • Within Customer organizations:administrators and authorized users within a Customer's tenant can see usage, audit, and configuration data scoped to their organization.
  • Integrated tools:when an authorized agent makes a request, we transmit the request to the third-party tool the Customer has connected. That tool's privacy policy governs its own processing.
  • Legal and safety: we may disclose information when required by law, subpoena, or court order, or where we believe disclosure is necessary to protect rights, safety, or property.
  • Corporate transactions: in the event of a merger, acquisition, financing, or sale of assets, information may be transferred subject to customary confidentiality protections and notice where legally required.
  • With your direction: when you instruct us to share information (e.g., enabling an integration or inviting a collaborator).

4. International Data Transfers

We are based in the United States and may process data in the U.S. and other countries where we or our sub-processors operate. For Customers requiring EU data residency, we offer regional deployments (see "EU residency" in our product documentation).

When personal data is transferred from the EEA, UK, or Switzerland to a country that has not received an adequacy decision, we rely on Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, or other lawful transfer mechanisms, supplemented by technical and organizational measures appropriate to the risk.

5. Data Retention

We retain personal data for as long as needed to provide the Services and for the following additional purposes:

  • Account data: for the duration of the customer relationship plus a reasonable wind-down period.
  • Audit logs and security records: for the period required by Customer configuration, our SOC 2 obligations, and applicable law (typically [INSERT RETENTION PERIOD, e.g., 12 months] unless extended by Customer).
  • Backups: retained on a rolling basis and overwritten according to our backup schedule.
  • Billing and tax records: retained for the period required by applicable law.
  • Marketing data: retained until you opt out or it is no longer relevant.

When personal data is no longer needed, we delete or anonymize it.

6. Security

We maintain a security program designed to protect personal data, including:

  • Encryption: AES-256 encryption at rest and TLS 1.2+ in transit; end-to-end encryption for supported request paths.
  • Access controls: role-based access, SAML SSO, SCIM provisioning, and least-privilege principles for our personnel.
  • Zero-trust architecture: no implicit trust between services; every request is authenticated and authorized.
  • Monitoring: continuous logging, anomaly detection, and security incident response procedures.
  • Compliance: SOC 2 Type II audited controls and GDPR-aligned processing practices.

No system is perfectly secure. If we become aware of a security incident affecting your personal data, we will notify you and applicable regulators as required by law.

7. Your Rights

Depending on your location, you may have the following rights with respect to your personal data:

  • Access a copy of the personal data we hold about you;
  • Correct inaccurate or incomplete data;
  • Delete personal data, subject to legal retention requirements;
  • Restrict or object to certain processing;
  • Receive your data in a portable format;
  • Withdraw consent where processing is based on consent;
  • Lodge a complaint with a data protection authority.

California residentshave rights under the CCPA/CPRA, including the right to know, delete, correct, and opt out of "sharing" for cross-context behavioral advertising. We do not sell personal information.

8. Cookies and Tracking

We use a limited set of cookies and similar technologies for authentication, session management, security, and analytics. You can control cookies through your browser settings. Where required by law, we present a cookie banner allowing you to manage non-essential cookies.

We honor Global Privacy Control (GPC) signals as an opt-out preference signal where applicable.

9. Children's Privacy

The Services are not directed to children under 16, and we do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.

10. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or through the Services and update the "Last Updated" date above. Continued use of the Services after the effective date constitutes acceptance of the revised policy.