PRIVACY POLICY

EDITO-PDF® MCP CONNECTOR

Jugaad S.r.l. – Via Luigi Reverberi 30A, 42027, Montecchio Emilia (RE) PEC: jugaad@legalmail.it | E-mail: contatto@edito-pdf.com Legal representative: Dr. Giacomo Verdi

Art. 1 – Data Controller

The Data Controller is Jugaad S.r.l., with registered office at Via Generale Luigi Reverberi 30/A, 42027 Montecchio Emilia (RE), VAT No. 02905570350, SDI SUBM70N, in the person of its legal representative Dr. Giacomo Verdi (hereinafter also “the Controller” or “the Provider”). For communications regarding this privacy policy: support@edito-pdf.com | Tel. 0522-1607520.

Art. 2 – Scope of Application

This Privacy Policy applies exclusively to the Edito-Pdf MCP Connector (hereinafter “the Connector”), which enables AI assistants such as Claude (Anthropic) to interact with pseudonymized documents generated by the Omissis module within the EDITO® platform, via the Model Context Protocol (MCP). This privacy policy does not cover the Edito-Pdf web application (app.edito-pdf.com) or other platform services, which are governed by their own privacy policy available at https://www.edito-pdf.com/en/edito-privacy/.

Art. 3 – Data Processed

3.1 Authentication data OAuth 2.0 tokens (access token, refresh token), API keys (stored as irreversible SHA-256 hashes), and the internal user identifier associated with the Edito-Pdf account. 3.2 Pseudonymized document content The Connector retrieves exclusively the text of documents already pseudonymized by the Omissis module of the Edito-Pdf platform. All personally identifiable information (PII) is replaced with opaque labels (e.g., [[PERS_1]], [[LOC_2]]) before reaching the Connector or any AI model. The Connector never accesses or transmits the original non-pseudonymized text through the MCP protocol. 3.3 Entity dictionaries (server-side only) The mapping between pseudonymous labels and real values is stored in the Edito-Pdf platform database. It is accessed server-side exclusively when the user explicitly requests de-pseudonymization. Real values are never returned in tool responses or exposed to the AI assistant. 3.4 Email address The email address associated with the user’s Edito-Pdf account is used exclusively to deliver de-pseudonymized documents upon the user’s explicit request. 3.5 Technical logs The Connector records authentication events and errors for security and debugging purposes. Logs may include: timestamps, user ID, client ID, IP address, user-agent, and error codes. Logs do not contain document content, entity values, or API keys in plain text.

Art. 4 – Purpose and Legal Basis (GDPR Art. 6)

Purpose Legal basis
Authentication and authorization to access user documents Performance of contract (Art. 6(1)(b))
Retrieval and presentation of pseudonymized document content Performance of contract (Art. 6(1)(b))
De-pseudonymization and delivery of documents via email Explicit user request / Performance of contract (Art. 6(1)(b))
Security logging and fraud prevention Legitimate interest (Art. 6(1)(f))

Art. 5 – Data Recipients and Transfers

5.1 Infrastructure Google Cloud Platform (region: europe-west1, Belgium) — Cloud Functions, Firestore, Cloud Storage. SMTP relay for email delivery. 5.2 AI assistant providers The pseudonymized text of documents is transmitted to the AI assistant (e.g., Claude by Anthropic) through the MCP protocol. Since documents are pseudonymized before reaching the AI provider, no real personal data is shared with it. 5.3 No other third parties The Connector does not share data with advertisers, analytics providers, data brokers, or any other third parties. 5.4 International transfers All data processing takes place within the EU/EEA (Google Cloud europe-west1). Pseudonymized text transmitted to AI providers may be processed outside the EEA according to their respective data processing agreements. Since the text is pseudonymized, no directly identifiable personal data leaves the EEA.

Art. 6 – Data Retention

  • OAuth access tokens: expire 1 hour after generation.
  • OAuth refresh tokens: valid until revoked by the user or automatic rotation.
  • API key hashes: retained until the key is revoked by the user.
  • Security logs: retained for a maximum of 90 days.
  • Document content: not retained by the Connector — retrieved on request from the Edito-Pdf platform and never cached.
  • De-pseudonymized output: generated in memory, attached to email, and immediately deleted. Not retained on any server.

Art. 7 – Data Subject Rights

Pursuant to Regulation (EU) 2016/679, the data subject has the right to:
  • Access their personal data (Art. 15)
  • Rectify inaccurate data (Art. 16)
  • Erase their data — “right to be forgotten” (Art. 17)
  • Restrict processing (Art. 18)
  • Data portability (Art. 20)
  • Object to processing (Art. 21)
  • Withdraw consent at any time (Art. 7(3))
To exercise these rights, the data subject may contact the Controller at: support@edito-pdf.com. The data subject also has the right to lodge a complaint with the Italian Data Protection Authority: https://www.garanteprivacy.it.

Art. 8 – Security Measures

  • All communications take place over encrypted HTTPS/TLS channels.
  • API keys are stored as irreversible SHA-256 hashes.
  • OAuth 2.0 authentication with PKCE (S256) — no client secret for public clients.
  • Privacy by design pseudonymization: real personal data never transits through the MCP protocol or reaches AI providers.
  • De-pseudonymized documents are delivered exclusively via email to the account holder; never exposed in chat or API responses.
  • Access control: users can only access documents in their own Drives or in Drives explicitly shared with them.

Art. 9 – Cookies and Tracking

The Connector does not use cookies, tracking pixels, or any client-side analytics systems. It operates as a server-to-server protocol without a browser interface (except for the one-time OAuth authorization page).

Art. 10 – Children’s Privacy

The Connector is not intended for individuals under 16 years of age. We do not knowingly collect data from minors.

Art. 11 – Changes to this Privacy Policy

The Controller reserves the right to update this Privacy Policy to reflect changes to its practices or applicable regulations. Substantial changes will be communicated through the Edito-Pdf platform or via email. The “Last updated” date at the top indicates the most recent revision.

Art. 12 – Applicable Law and Jurisdiction

This privacy policy is governed exclusively by Italian law and Regulation (EU) 2016/679. For any dispute, the Court of Reggio Emilia has jurisdiction.
Jugaad S.r.l. – Via Luigi Reverberi 30A, 42027, Montecchio Emilia (RE) VAT No.: 02905570350 | Tel: 0522-1607520 E-mail: support@edito-pdf.com | Website: www.edito-pdf.com