Blog
Kontakt os

Data Processing Agreement - Consile MCP

 

1. Background and Purpose

1.1 This Data Processing Agreement (“DPA”) is entered into between the Customer (as defined in the Terms of Service for Consile MCP, “the Terms”) as the data controller and Consile ApS, CVR No. 45643360, Under Hvidtjørnen 47, 7500 Holstebro (“Consile”), as the data processor.

1.2 The DPA constitutes an annex to the Terms and sets forth the rights and obligations that apply when Consile processes personal data on behalf of the Customer as part of the provision of Consile MCP (“the Service”). The DPA complies with the requirements of Article 28(3) of Regulation (EU) 2016/679 (“the General Data Protection Regulation”).

1.3 The DPA is accepted electronically together with the Terms and Conditions on Consile’s portal and remains in effect for as long as Consile processes personal data on behalf of the Customer.

1.4 In the event of any conflict between the DPA and the Terms, the DPA shall take precedence with respect to the processing of personal data on behalf of the Customer.

1.5 The subject matter, duration, nature, and purpose of the processing, as well as the type of personal data and the categories of data subjects, are set forth in Appendix A. Approved sub-processors are listed in Appendix B. The instructions, including the technical and organizational security measures, are set forth in Appendix C.

 

2. Rights and Obligations of the Data Controller

2.1 The Customer is responsible for ensuring that the processing of personal data complies with the General Data Protection Regulation, the Data Protection Act, and other applicable law, including that there is a valid legal basis for the processing of personal data processed through the Service.

2.2 The Customer is responsible for the content of the instructions provided, see Section 3, including for the Tool calls executed through the Customer’s connections, see Sections 5 and 6 of the Terms.

2.3 The Customer is responsible for assessing whether the Connected Systems that the Customer connects contain special categories of personal data (Article 9), information on criminal convictions (Article 10), or other information requiring special measures, and, if so, for refraining from connecting such systems or for entering into a separate agreement with Consile regarding this matter.

 

3. The Data Processor Acts in Accordance with Instructions

3.1 Consile shall process personal data solely in accordance with documented instructions from the Customer, unless processing is required under EU law or Danish law; in which case Consile shall notify the Customer of this legal requirement prior to processing, unless such notification is prohibited in the interest of important public interests.

3.2 The Customer’s documented instructions consist of: (a) the Terms and this DPA, (b) the Customer’s configuration of the Service in the portal, including which Connectors the Customer has purchased and connected, which AI clients the Customer has authorized, and which add-ons the Customer has activated, as well as (c) the individual Tool calls that the Service receives from the Customer’s authorized AI clients - each Tool call is considered an instruction from the Customer to retrieve or write the relevant information in the Connected System and to transmit the result to the AI client that issued the call.

3.3 Consile shall immediately notify the Customer if, in Consile’s opinion, an instruction violates the General Data Protection Regulation or other applicable data protection laws.

 

4. Confidentiality

4.1 Consile ensures that only authorized persons have access to the personal data processed on behalf of the Customer, that access is limited to what is necessary (need-to-know), and that the individuals in question have committed to confidentiality or are subject to an appropriate statutory duty of confidentiality.

4.2 At the Customer’s request, Consile may demonstrate that the individuals in question are subject to the aforementioned duty of confidentiality.

 

5. Security of Processing

5.1 Consile shall implement the technical and organizational measures set forth in Appendix C, and, in addition, such measures as required under Article 32 of the General Data Protection Regulation, taking into account the state of the art, the costs, and the nature, scope, context, and purposes of the processing, as well as the risks to data subjects.

5.2 The parties agree that the Service’s architecture—where business data from Connected Systems is, as a rule, merely transmitted and not stored by Consile—constitutes in itself a significant element of data minimization and risk mitigation.

 

6. Use of Sub-Processors

6.1 The Customer hereby grants Consile general authorization to use sub-processors. The sub-processors approved at the time of entering into the DPA are listed in Appendix B.

6.2 Consile shall notify the Customer of any planned addition or replacement of subprocessors with at least 30 days’ notice via the portal or email. The Customer may object to the change before the notice period expires. If the parties cannot reach a resolution, the Customer may terminate the subscription for the affected Connector(s) effective at the end of the current billing period; this constitutes the Customer’s sole remedy in connection with the change.

6.3 Consile shall, by written contract, impose on each subprocessor the same data protection obligations as those set forth in this DPA and shall remain fully liable to the Customer for the subprocessor’s compliance therewith.

6.4 A copy of Consile’s agreements with subprocessors (excluding commercial terms) will be provided upon the Customer’s request.

 

7. Transfer to Third Countries

7.1 The processing of personal data on behalf of the Customer generally takes place within the EU/EEA (AWS, region eu-central-1, Frankfurt), see Appendix B.

7.2 To the extent that an approved subprocessor processes personal data in a third country, Consile ensures a valid basis for transfer in accordance with Chapter V of the General Data Protection Regulation (GDPR), see Appendix B (e.g., the EU-U.S. Data Privacy Framework or the European Commission’s Standard Contractual Clauses (SCCs)).

7.3 It should be noted that the Customer’s own disclosure of information to the Customer’s AI client (e.g., Anthropic or OpenAI) takes place in accordance with the Customer’s instructions, see Section 3.2(c), and pursuant to the Customer’s own contractual relationship with the AI provider; the Customer’s AI provider is not a subprocessor for Consile.

 

8. Assistance to the Data Controller

8.1 Consile shall assist—taking into account the nature of the processing and the information available to Consile - the Customer in fulfilling the Customer’s obligations under Articles 32–36 of the General Data Protection Regulation (GDPR) and in responding to requests to exercise the rights of data subjects (Chapter III).

8.2 The Service includes self-service features that support this assistance: exporting account data in a machine-readable format, as well as deleting accounts and connections, see Appendix C, Section C.3.

8.3 Since Consile does not store business data from Connected Systems, see Section 5.2, requests from data subjects for access to, rectification of, or erasure of information in Connected Systems must be directed to and fulfilled within those systems, which is the responsibility of the Customer.

8.4 Assistance under this section shall be provided without separate compensation, unless such assistance exceeds what can reasonably be expected; in such cases, Consile may demand payment based on time spent at Consile’s hourly rate in effect at any given time, subject to prior notice.

 

9. Notification of Personal Data Breaches

9.1 Consile shall notify the Customer without undue delay after becoming aware of a personal data breach involving personal data processed on the Customer’s behalf. Consile shall endeavor to provide notification within 48 hours.

9.2 The notification shall—to the extent that the information is available—include the details specified in Article 33(3) of the General Data Protection Regulation, so that the Customer can fulfill any obligation to report the breach to the Danish Data Protection Agency (within the 72-hour deadline) and any obligation to inform the data subjects.

9.3 It is the Customer’s responsibility to file any necessary reports with the Danish Data Protection Agency and to notify the data subjects.

 

10. Deletion and Return of Data

10.1 Upon termination of the Service—or of an individual subscription—Consile will delete the personal data processed on the Customer’s behalf in connection therewith, unless EU law or Danish law requires continued retention. Since the Service does not store business data from Connected Systems, the deletion in practice includes: stored Access Credentials (deleted and revoked from the Connected System, where the system supports this), any optionally stored derived data, as well as account and connection data, see Appendix C, Section C.3.

10.2 Access Credentials for a Connector are deleted immediately when the Customer disconnects and upon request for account deletion. Other account deletions are carried out after a [14]-day cooling-off period.

10.3 The following are retained after deletion based on a documented legal basis: (a) deletion receipts (documentation that deletion has been completed, Article 5(2)), (b) audit trails for up to 400 days from the event (accountability and security documentation), and (c) information subject to accounting requirements at Consile’s payment provider. This information is not processed for any other purposes.

 

11. Audit and Supervision

11.1 Upon request, Consile shall make available to the Customer all information necessary to demonstrate compliance with Article 28 and this DPA, including descriptions of security measures, deletion receipts, and relevant statements or certifications from sub-processors (e.g., AWS’s ISO 27001/SOC 2 documentation).

11.2 The Customer may—either directly or through an independent third party that is not a competitor of Consile—conduct audits, including inspections, at Consile. Supervision must be announced at least 30 days in advance, may be conducted no more than once a year (unless a specific breach warrants otherwise), must not unnecessarily disrupt operations, and shall be conducted at the Customer’s expense.

11.3 Supervision of sub-processors that are major cloud providers is conducted by reviewing the provider’s audit reports and certifications.

 

12. Entry into Force and Termination

12.1 The DPA enters into force upon the Customer’s acceptance and remains in effect for as long as Consile processes personal data on the Customer’s behalf.

12.2 The DPA cannot be terminated separately as long as the Terms and Conditions remain in effect.

12.3 Consile’s liability under the DPA is governed by Section 15 of the Terms [, including the increased liability limit in Section 15.4].

 

Appendix A – Information on the Processing

A.1 Purpose of the processing: Provision of the Service: facilitating Tool calls between the Customer’s authorized AI clients and the Customer’s Connected Systems, storing the Customer’s Access Credentials, and—solely upon the Customer’s express opt-in—storing specifically defined derived data.

A.2 Nature of the processing: Forwarding (retrieval and—for certain Connectors—writing) of data in the Customer’s Connected Systems pursuant to instructions in the form of Tool calls; encryption and storage of Access Credentials; temporary processing in working memory during the transmission. Business data from Connected Systems is not stored by Consile unless the Customer has explicitly opted in.

A.3 Types of personal data: Depends on which Connected Systems the Customer connects. Typically: general personal data in business systems, e.g., names, contact information, customer numbers, order, invoice, and payment history, supplier information, marketing and advertising data, and content data. Furthermore, the Customer’s Access Credentials (OAuth tokens/API keys) for the Connected Systems. The Service is not intended to process special categories of personal data (Article 9) or information regarding criminal convictions (Article 10), cf. Section 2.3 of the DPA.

A.4 Categories of data subjects: The Customer’s customers, leads, suppliers, employees, end users, and other individuals whose information is included in the Connected Systems, as well as the Customer’s own users (with respect to Access Credentials and connection data).

A.5 Duration: For as long as the relevant subscription remains in effect; see, however, Section 10 of the DPA regarding erasure.

 

Appendix B – Approved Sub-Processors

Sub-processor Service Location of Processing Basis for Transfer
Amazon Web Services EMEA SARL (“AWS”) Hosting, database, key management (KMS), and operation of the Service EU – eu-central-1 region (Frankfurt, Germany) Processing in the EU/EEA [; any limited support access from third countries is governed by AWS’s Data Processing Addendum with SCCs]
Stytch, Inc. Login and identity service for the Customer’s users (authentication of users and AI clients to the Service) United States EU-U.S. Data Privacy Framework [/ SCC—verify Stytch’s current certification status]

Note: Consile’s payment processing (Stripe) and customer relationship management (HubSpot) providers process only information for which Consile is the sole data controller (account, payment, and support information) and are therefore not subprocessors under this DPA. The processing is described in Consile’s Privacy Policy.

 

Appendix C - Instructions

 

C.1 Processing

Consile may only process personal data on behalf of the Customer as described in Appendix A and Section 3.2 of the DPA, i.e. (a) forward Tool calls from the Customer’s authorized AI clients to the Customer’s Connected Systems and return the result to the calling AI client, (b) store and use the Customer’s Access Credentials for this purpose, and (c) upon explicit opt-in, store the derived data covered by such opt-in.

C.2 Technical and Organizational Security Measures (TOMs)

Consile maintains, at a minimum, the following measures:

Encryption and Key Management

  • Access Credentials are stored encrypted at rest using AES-256-GCM (envelope encryption) with one data encryption key per customer, generated and encapsulated by AWS KMS; the key can cryptographically be used only for that customer’s data.
  • All data in transit is encrypted (TLS), including database connections.
  • Application secrets are stored in AWS Secrets Manager and loaded at startup; they are not included in the source code.

Access Control and Isolation

  • Customer identity is derived solely from the verified access token—never from the client’s input.
  • Subscription and access control are enforced on every single Tool call before credentials are loaded.
  • A Tool call can access only the relevant customer’s own credentials; this isolation has been verified through automated testing.
  • The access token that the customer’s AI client uses with the Service is never forwarded to Connected Systems.

Data Minimization and Retention

  • Business data from Connected Systems is processed in real time and is not stored (unless explicitly selected, see C.1(c)).
  • Access credentials are deleted immediately upon disconnecting a Connector; for OAuth-based connections, the token is simultaneously revoked from the provider (RFC 7009), where supported.
  • Detailed usage events are disabled by default and, if enabled, are retained for a maximum of 90 days; aggregated usage statistics (number of calls per day) are retained for billing and fair-use purposes.

Logging and Traceability

  • Logs are automatically redacted for tokens, keys, and other secrets before being written; access credentials are never logged.
  • Security and management events are recorded in an audit log, which is retained for up to 400 days.
  • Completed deletions are documented with a deletion receipt.

Organizational

  • Access for Consile staff is limited to what is necessary and subject to a confidentiality obligation, cf. Section 4 of the DPA.
  • Changes to the Service undergo automated testing that includes isolation and access control requirements prior to deployment.

C.3 Support and Self-Service

  • Export: The Customer may export their account data (master data, subscriptions, connection status, consents, and acceptances) in JSON via the portal or API. The export never contains confidential information.
  • Deletion: The Customer may request deletion of their account; login credentials are deleted immediately, and other account data is deleted after the [14]-day cancellation period. Deletion also includes the deletion of the customer’s organization from Stytch and anonymization by the payment provider (subject to accounting requirements).

C.4 Retention Periods Upon Termination

See Section 10 of the DPA: all data is deleted upon termination, except for deletion receipts, audit logs (maximum 400 days), and information subject to accounting requirements.

 

Version: [1.2] June 1, 2026.