PRIVACY POLICY — Senzing MCP Server Effective Date: June 3, 2026 | Version 3.1 | Last Updated: June 3, 2026
This server is provided AS-IS (without modification or guarantee) with no warranty of merchantability, fitness for any purpose, accuracy, completeness, or reliability. By using this server, you acknowledge and accept these terms, and use it at your sole risk. Nothing in this disclaimer limits Senzing's obligations or your rights under applicable data protection law, including the UK GDPR and EU GDPR.
WHAT IS LOGGED: All tool calls and parameters are logged for operational monitoring and service improvement. This includes tool names, query text, language selections, workflow actions, response metadata (duration, success/failure status), and timestamps. Separately, if you request an MCP Server software license, we collect and log your full name, work email address, the referral-source value you provide, and the IP address from which the request is submitted (together, "License Request Data"). License Request Data is processed both within the MCP Server environment and by our customer relationship management provider, HubSpot, Inc., acting as our processor; see "License Request Processing" below. Logs are not shared with third parties except our authorized processors (including HubSpot) or as required by law. Senzing processes this data on the basis of its legitimate interests in maintaining the security, reliability, and improvement of the MCP Server (Article 6(1)(f) GDPR / UK GDPR).
WHAT IS NOT COLLECTED: This server does not collect, store, or transmit your source data files, any personally identifiable information (PII) submitted as a tool input, or the License Request Data described above beyond the retention periods stated in "License Request Processing", credentials, conversation context (meaning full prompt history, user identifiers, or session metadata), or authentication tokens. Data mapping and linting processes, as well as analysis scripts, execute entirely client-side in your environment and do not transmit any data to Senzing servers.
LICENSE REQUEST PROCESSING: When you request an MCP Server software license (typically by directing a large language model client or other MCP-compatible client to invoke the Senzing MCP Server license request tool, which prompts you to provide the information described below and relays it to us), we collect your full name, work email address, the referral-source value you provide, and the IP address from which the request is submitted ("License Request Data"). Note that if you submit your license request through a third-party large language model or other client (for example, Anthropic Claude, OpenAI ChatGPT, or a similar service), that third party will process the information you provide before transmitting it to Senzing, in accordance with its own privacy policy; Senzing is not the controller of any processing that occurs within that third-party client. License Request Data is transmitted to and stored in HubSpot, which acts as our processor, and is also logged within the MCP Server. We process License Request Data for the following purposes: (i) to evaluate and respond to your license request and, where the eligibility criteria are met, to issue a license key to you and to send you transactional communications about that license, including eval support information (e.g., how to reach us if you encounter problems) and expiration reminders (Article 6(1)(b) GDPR / UK GDPR – processing necessary in order to take steps at your request prior to entering into a contract and, where applicable, to perform that contract); and (ii) to verify that the request comes from a business email address and is not a duplicate of a prior request, in order to manage license distribution and protect against misuse, including requests from commercial competitors (Article 6(1)(f) GDPR / UK GDPR – legitimate interests). Eligibility (i.e., that you have not previously requested a license and that you have submitted what we identify as a business or work email address rather than a personal or free-webmail address) is determined by automated rules in HubSpot; if your request does not meet these criteria, no license key will be issued. This processing does not produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 GDPR. If you would like to contest the outcome or request human review, contact privacy@senzing.com. License Request Data is retained on a two-tier basis. The MCP Server environment purges all License Request Data (full name, email address, referral-source value, and IP address) within thirty (30) days of receipt. Separately, our processor HubSpot retains the email address associated with each license request on an ongoing basis for two purposes: (a) to honor any opt-out or communications-preference choices you make, so that we do not contact you in a manner you have declined, and (b) to identify duplicate license requests under the eligibility criteria described above. Other License Request Data held by HubSpot (full name and referral-source value) is deleted within thirty (30) days of receipt unless retained on the basis of a separate lawful purpose. If you exercise your right to erasure under Article 17 GDPR / UK GDPR, we will erase your License Request Data; however, we may retain a minimal suppression record (your email address and the fact of your erasure or opt-out request) for the limited purpose of ensuring we do not contact you again or re-issue a license in error, consistent with Article 17(3) GDPR / UK GDPR.
DO NOT SEND: Avoid sending PII, credentials, or sensitive data in any tool input (this restriction does not apply to information you knowingly submit in connection with an MCP Server license request, which is governed by the "License Request Processing" section below). As a best practice, treat all interactions as logged. If sensitive data is inadvertently submitted, contact support@senzing.com immediately.
POLICY UPDATES: Senzing reserves the right to update this Privacy Policy at any time. If you do not agree to material changes, you should discontinue use of the server. For data subjects under GDPR or UK GDPR, your statutory rights under applicable data protection law are not affected by this policy or any updates to it.
GOVERNING LAW: This Privacy Policy is governed by the laws of the state of Delaware, USA. Any disputes arising under this policy shall be subject to the exclusive jurisdiction of the courts located in Delaware, USA. Notwithstanding the foregoing, nothing in this policy limits the rights of data subjects under applicable data protection law. If you are located in the European Economic Area or the United Kingdom, EU GDPR and/or UK GDPR apply to the processing of your personal data by Senzing, regardless of governing law. Senzing processes personal data originating from the EEA or UK in compliance with applicable data protection legislation.
DATA CONTROLLER: Senzing, Inc., PO Box 19576, Las Vegas, NV 89132, USA, is the data controller responsible for personal data processed in connection with this server. For data protection queries, contact: privacy@senzing.com (or the address above marked "Data Protection").
YOUR DATA PROTECTION RIGHTS (EU / UK USERS): Under GDPR and UK GDPR, you have the right to: (1) access your personal data (Art. 15); (2) rectify inaccurate data (Art. 16); (3) erasure of your data (Art. 17); (4) restrict processing (Art. 18); (5) object to processing (Art. 21); and (6) data portability (Art. 20). To exercise any of these rights, contact privacy@senzing.com. We will respond within one calendar month as required by Article 12 GDPR. You also have the right to lodge a complaint with your local supervisory authority — UK users may contact the Information Commissioner's Office (ICO) at ico.org.uk; EU users should contact their national data protection authority.
INTERNATIONAL DATA TRANSFERS: Senzing is based in the United States. If you access the MCP Server or submit a license request from the European Economic Area (EEA) or United Kingdom, your operational log data and License Request Data may be transferred to and processed in the United States (including by HubSpot, Inc. as our processor). Where such transfers occur, Senzing relies on Standard Contractual Clauses (SCCs) / UK International Data Transfer Agreement (IDTA) as the transfer mechanism to ensure your data receives an adequate level of protection. Copies of the applicable transfer mechanism are available on request from privacy@senzing.com.
CONTACT: For questions or concerns, email support@senzing.com. We aim to respond to all inquiries within two (2) business days. For urgent matters, please include "URGENT – Privacy" in the subject line.
← Back to home