Legal

MCP Privacy Notice.

Version 2026-08-27 · Last updated: 27 August 2026

Controller and scope

Satchelpay UAB, reg. No. 304628112, of Upės St. 21-1, LT-08128 Vilnius, Lithuania, is controller for the Satchel MCP site, waitlist, sandbox and live MCP authorization interface. Satchelpay UAB is an electronic money institution authorised by the Bank of Lithuania (licence No. 28). Client funds are safeguarded in accordance with applicable requirements; electronic money is not a deposit and is not covered by the Lithuanian deposit guarantee scheme. Contact the DPO at dpo@satchel.eu.

This notice covers the live MCP service at mcp.stchl.eu as well as the synthetic sandbox. It supplements the main SatchelPay Privacy Policy. The destination client or AI provider may be a separate controller or a processor under a documented arrangement; its linked Terms and Privacy notice apply after receipt.

Data categories

  • Waitlist and contact. Email, request type, time and any sandbox key.
  • Authorization. Account email, company, corporate-authority confirmation, verified client identity/domain/mode, exact scopes and data categories, notice versions, acceptance time and SCA result or approved disposition reference. The password is not persisted; its encoded value may be held in process for up to five minutes solely to complete an OTP challenge, then it is deleted.
  • Account-access data. Account names and masked identifiers, balances, card status and masked identifiers, transaction amounts/dates/status. Transaction narratives and counterparties are off by default and are processed only if the separate optional scope is granted.
  • Security and operations. Pseudonymized subject reference, client, action, scope, result, timestamps and denial reason. Audit output excludes tokens, sessions and account payloads.

Sandbox records are synthetic. They do not represent real customers, funds or counterparties.

Purposes and legal bases

  • Provide the requested read-only connection and regulated account service: performance of the applicable agreement and steps requested before it (GDPR art. 6(1)(b)).
  • Authenticate, apply SCA, meet financial-services, security, recordkeeping and regulatory duties: legal obligation (art. 6(1)(c)).
  • Prevent misuse, investigate incidents, operate a closed pilot and improve reliability: legitimate interests (art. 6(1)(f)), balanced against affected rights.
  • Administer the waitlist and requested follow-up: consent where collected (art. 6(1)(a)); withdrawal does not affect prior lawful processing.

OAuth authorization is your service instruction and permission boundary; it is not a claim that consent is the only GDPR legal basis. We do not use MCP data for advertising or solely automated decisions with legal or similarly significant effect.

Recipients and client modes

  • Local/customer-hosted. Data goes to a client controlled or selected by the customer. That customer-selected AI does not automatically become Satchel's ICT supplier; the customer and provider determine their own roles.
  • Hosted external. Data goes only to the exact domain shown at consent after recipient, AISP and transfer dispositions are approved.
  • Satchel-managed provider. Use is blocked until Satchel contract ownership, DPA, training/secondary-use settings, transfers, subprocessors and DORA register coverage are evidenced.

The authorization screen gives the recipient's verified entity, destination, external Terms and Privacy links and their accepted versions. Live activation is blocked until the required hosting and security-supplier arrangements are evidenced. We do not sell personal data.

Silent parties and counterparty data

Transaction records can identify a payer, payee, employee, director or other silent party who never used the assistant. Satchel minimises this risk by withholding narratives and counterparties by default and masking identifiers. The customer must have a lawful basis and authority, provide any required notice to those people and avoid enabling the optional narrative scope unless necessary. Satchel remains responsible for its own transparency and safeguards and provides this notice for onward communication.

Retention and deletion

  • Pending Legal and DPO approval, the current technical maximum for waitlist entries is 12 months. Entries older than that maximum are removed by the application on access; the approved schedule may be shorter or otherwise different. A relationship, an earlier deletion request or a legal requirement may also change how long an entry is kept.
  • Current OAuth defaults are: authorization code one minute, access token 30 minutes and rotating refresh token seven days. Expired or revoked records are purged; the account- access password is not persisted beyond the short OTP challenge described above.
  • A connected-app management session lasts 10 minutes. Use /connections to see scopes and last use or revoke now.
  • The current technical maximum for pseudonymized application audit events is 12 months. Those references remain personal data: rights requests are assessed against the approved schedule and applicable legal exceptions. Live use remains blocked until the DPIA and retention schedule confirm that period and any infrastructure-log period.

Revocation and Satchel-side erasure stop access and remove Satchel authorization records, but cannot delete copies already placed in an external assistant's conversation history. Use the external provider's deletion controls and rights channel as well.

International transfers

The exact destination is shown before authorization. A hosted client outside the EEA is blocked until its international transfer disposition is approved. Where personal data is transferred internationally, the approved arrangement must identify an adequacy decision or appropriate safeguards such as the European Commission's Standard Contractual Clauses, with a transfer assessment and supplementary measures where required. Contact the DPO for information about the applicable safeguard or a copy subject to lawful redactions.

Accuracy and assistant boundary

A financial summary uses up to 200 most recent transactions. Merchant and recurring- payment labels are heuristic, may be incomplete or wrong and are not computed without the optional narrative scope. Verify the underlying transactions. Output is informational only and is not financial advice. External assistants may transform or retain output under their own settings; Satchel does not promise their accuracy.

Your rights

Subject to GDPR conditions and exceptions, you may request access, portability, rectification, erasure, restriction, object to legitimate-interest processing and withdraw consent. You may also complain to Lithuania's State Data Protection Inspectorate (VDAI), vdai.lrv.lt. Email dpo@satchel.eu; we may verify identity before acting and will respond within applicable legal time limits.

Security, cookies and changes

Live OAuth records are encrypted at rest; token values are stored as hashes; authorization is PKCE-bound; and live destinations are exact-domain allowlisted. Successful live connections and allowed read-tool outcomes require persisted audit events. Resource-access denials are submitted to the audit sink on a best-effort basis and remain denied if it is unavailable. An operator kill switch stops reads. The site uses no non-essential analytics or marketing cookies by design. The connected-app page uses a 10-minute, HttpOnly, SameSite session cookie for authentication and CSRF protection.

The version above is stored with each live grant. Material changes are notified and re-accepted where required. Privacy: dpo@satchel.eu. Service support: support@satchel.eu.