Legal

Data Processing Agreement

Our UK GDPR Article 28 terms.

Last updated: 15 September 2026

This Data Processing Agreement forms part of the Terms of Service between you and LiftMCP Ltd, company number 17177294, registered at 71–75 Shelton Street, Covent Garden, London WC2H 9JQ. It applies wherever LiftMCP processes personal data on your behalf, and it is governed by the UK GDPR and the Data Protection Act 2018.

1. Roles

Service Personal Data is personal data we process on your behalf, as described in clause 2. You are the controller and we are the processor. This DPA governs it.

Account Data is the personal data we process as a controller to run and bill your account: your team's names, email addresses, credentials and billing details. Our Privacy Policy governs it, not this DPA. We are registered with the ICO for it (ICO:00013889271).

If you are yourself a processor acting for another controller, we act as your sub-processor and you confirm you have that controller's authority to appoint us.

2. The processing

Subject matterProviding the LiftMCP service: relaying requests from AI agents to the endpoints you nominate and returning the responses, scanning and monitoring the Properties you configure, running the test-agent feature when you invoke it, and the operational telemetry those produce.
DurationThe term of the Terms of Service, plus the wind-down in clause 9.
Nature and purposeTransmitting requests and responses, held in memory for the duration of a call and not written to disk or to our database. Retrieving and assessing your Property for scanning and monitoring. Sending data to an AI provider for the test-agent feature when you invoke it. Storing configuration and telemetry.
Types of personal dataRelayed traffic: whatever your endpoints return and calling agents send. You determine this entirely; we do not specify or inspect it. Scanning: personal data in the public content of your Property. Telemetry: a truncated client IP prefix, session identifier, user agent, a reference to the hashed API key, the tool called, status and timings. Configuration: domains, endpoint URLs and tool definitions.
Categories of data subjectDetermined by you: your customers, visitors to your Property, people named in your published content, and the operators of calling agents.
Special category dataYou must not use the service for data within Article 9 or Article 10 unless we agree it in writing beforehand.

We do not store the content of requests or responses. Client IP addresses are truncated before storage to a /24 prefix for IPv4 or /48 for IPv6, and API keys are stored only as SHA-256 hashes. We do not claim the remaining telemetry is anonymous: it is pseudonymised, it is Service Personal Data, and this DPA covers it.

3. Our obligations

We will:

If we think an instruction of yours infringes data protection law, we will tell you immediately.

4. Security

Our measures are described on our security page, and we will provide the description in force at the date of your contract on request. In summary: TLS 1.2+ in transit and AES-256 at rest; tenant isolation enforced in the data access layer and verified by automated cross-tenant tests that fail the build, with database row-level security as a second layer; a least-privilege database role per service and no service holding administrative database rights; multi-factor authentication on administrative accounts; databases not publicly reachable, behind a web application firewall; encrypted automated backups on a rolling 14 day cycle; centralised service logging with 90 day retention, automated vulnerability scanning and alerting; and Cyber Essentials certification (IASME), renewed annually, currently valid to 29 April 2027.

5. Sub-processors

You give general written authorisation for those below. We will give at least 30 days' notice before adding or replacing one, by email and by updating this page, and you may object on reasonable data protection grounds; if we cannot resolve the objection you may terminate the affected service without penalty.

Each is engaged under a written contract imposing obligations no less protective than this DPA. Where a sub-processor fails to meet them, we remain fully liable to you for its performance.

Sub-processorPurposeLocation
Amazon Web ServicesHosting, database, email deliveryUnited Kingdom (eu-west-2)
SentryApplication error monitoringEuropean Union
AnthropicTest-agent feature onlyUnited States
OpenAITest-agent feature onlyUnited States
IntercomSupport conversations, if you send us Service Personal Data through oneEU and United States
GoogleWorkspace email, if you send us Service Personal Data by emailEU and United States

Stripe (payments), Termly (consent) and Google (sign-in) process Account Data only. They are our suppliers rather than sub-processors under this DPA, and are described in our Privacy Policy.

The test-agent feature is off until you enable it, and each run is a separate instruction to send the relevant data to the AI provider. We use Anthropic and OpenAI under commercial API terms that exclude training on API inputs and outputs, and we enable no optional retention or human review. Both retain inputs and outputs briefly for their own abuse monitoring under their own terms, acting as independent controllers for that retention, which our deletion and audit rights cannot reach. It is the only case where Capability content is stored by anyone other than you. If that is unacceptable, do not enable the feature, or tell us and we will disable it on your account.

6. International transfers

Service Personal Data is stored in AWS eu-west-2 (London) and our infrastructure is in the United Kingdom. It leaves the UK only as follows.

To our sub-processors. We rely, in order: on UK adequacy regulations where they exist; on the UK Extension to the EU-US Data Privacy Framework where the specific receiving entity is certified and the transfer is within that certification; otherwise on the ICO's International Data Transfer Agreement, or the EU Standard Contractual Clauses as modified by the UK Addendum. In each case we apply the data protection test UK law requires. We keep a record of which applies to each recipient entity and will provide it on request.

To the endpoints you nominate and the agents that call them. The service works by sending data to the endpoint you specify and returning the response to the caller. We select neither. Your endpoint requires an API key issued per Property, so the callers are those you have issued a key to, and the disclosure is on your instruction. You are responsible for its lawfulness and for any transfer mechanism it needs.

If you are established outside the UK in a country without adequacy regulations, we will complete and enter into an International Data Transfer Agreement, or the EU Standard Contractual Clauses with the UK Addendum, before processing begins.

7. Data subject rights

Because we do not store Capability content, a request about it is answered from your systems. If one reaches us concerning Service Personal Data, we will tell you promptly and will not respond substantively unless you instruct us or the law requires it.

Requests about Account Data go through our Privacy Policy. You may also complain to us directly about that processing, and we will acknowledge within 30 days.

8. Personal data breaches

We will tell you without undue delay after becoming aware of a breach affecting Service Personal Data, describing its nature, the categories and approximate number of records affected, the likely consequences and the measures taken or proposed, so far as we know them at the time. We will follow up as more emerges rather than delay the first notification, and will help you assess and make any notification required under Article 33 or Article 34.

A breach at a sub-processor is treated as a breach at us.

9. Deletion and return

At the end of the service, or on your written request, we will at your choice delete or return Service Personal Data and delete existing copies, unless UK law requires us to keep it. This concerns your configuration, your scanning results and your telemetry, since payload content is never stored. We complete it within 30 days, require the same of our sub-processors, and will confirm in writing if you ask.

Two mechanical exceptions: residual telemetry in our centralised service logs is overwritten on the rolling 90 day cycle in clause 4, having been removed within 30 days from our database and from everything we show you; and backups are overwritten on a rolling 14 day cycle, are never restored into live systems after a deletion, and have the deletion reapplied if restored for any other reason.

10. Information and audits

We will make available all the information necessary to demonstrate compliance with Article 28, and will allow for and contribute to audits, including inspections, by you or an auditor you mandate. We will offer our certifications and documentation first, which may answer the question; that is an offer, not a precondition. Audits are on reasonable notice, no more than annually unless a breach or regulator requires otherwise, and subject to confidentiality and reasonable security requirements.

11. Your obligations

You will have a lawful basis for what you instruct and give data subjects the information they are due; be entitled to disclose through a Capability whatever your endpoint returns; keep each Property's API key secret, treating anyone holding it as able to call your Capabilities; and satisfy yourself that a valid transfer mechanism exists where a Capability may return personal data to an agent outside the UK, or restrict access so it cannot.

12. Liability, precedence and changes

Liability under this DPA is subject to the limits in the Terms of Service. Where this DPA conflicts with those terms on personal data, this DPA prevails. Nothing here limits any liability or right that cannot lawfully be limited, including the rights of data subjects and the powers of the Information Commissioner.

You are bound by the version in force when you accepted the Terms of Service, plus any later version you accept or change we notify that does not materially reduce your rights. Earlier versions are available on request.

13. Where Article 28 is met

RequirementClause
28(3) particulars2
28(3)(a) documented instructions, and notice of an infringing instruction3
28(3)(b) confidentiality3
28(3)(c) security under Article 323, 4
28(2), 28(3)(d) and 28(4) sub-processors5
28(3)(e) data subject rights3, 7
28(3)(f) Articles 32 to 363, 8
28(3)(g) deletion or return at your choice9
28(3)(h) information and audits10

14. Contact

Data protection enquiries: privacy@liftmcp.com
Security and breach reports: security@liftmcp.com

LiftMCP Ltd, 71–75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom. Company number 17177294. ICO registration ICO:00013889271.

You have the right to complain to the Information Commissioner's Office at ico.org.uk.