1. Data controller
The data controller is Bonsai Srls, Via Francesco Ferrucci 100, 59100 Prato (PO), Italy (VAT IT02533060972). For privacy requests (access, deletion, objection, or connector disconnection support), email info@bonsaigrowth.it.
2. Scope
This notice covers only the Bonsai MCP Connector used with Claude: a remote MCP server over HTTPS, authenticated with OAuth 2.0. It does not replace Bonsai's general product privacy notices. It applies when you connect the connector from Claude, complete OAuth ("I am a company" or "I am an agency"), and invoke connector tools (about 70 platform and Amazon-analytics tools that already exist in the Bonsai workspace). This is a B2B service, not directed at children under 18.
3. Data we collect
We process only what is needed to authenticate you, run tools, and keep the service secure and auditable. We do not collect Claude chat transcripts, Claude memory, conversation history, files you upload to Claude, or any conversation data beyond what a tool needs to run.
3.1 Identity and authentication
- MCP user identifier (OAuth "TOKEN A" subject);
- Email / login on the Bonsai workspace or Hub-Agency — during broker login only; passwords are not stored on the MCP server;
- Subject type (company / agency / platform staff);
- Hub-Agency organization and allowed tenants (agency path);
- Active tenant code / id;
- OAuth access and refresh tokens — stored in a protected secret store, never written to audit logs.
The MCP server does not store workspace passwords and does not access tenant databases.
3.2 Tool arguments and results
When Claude calls a tool, we process: tool name, arguments (filters such as dates, marketplace, pagination, and platform tenant identifiers), outcome (success / error), non-secret error code and message, duration, correlation id, and results returned to Claude (KPIs, time series, product/SKU tables and metadata already stored in your Bonsai tenant).
Results come from the Bonsai product. The connector does not call Amazon SP-API and is not a third-party Amazon API wrapper. The only write tool sets the active tenant on the agency path (switch_tenant). It does not write Vendor, Ads, or Seller data.
3.3 Technical data
Infrastructure and authentication may process IP address, user-agent, timestamps, URL, HTTP status, and request identifiers for security and diagnostics. These system logs follow ordinary server/WAF retention and are not used for commercial profiling.
3.4 What we do not process through the connector
- passwords after login (not persisted on MCP);
- access tokens, refresh tokens,
Authorizationheaders, cookies, or secrets in audit logs; - Claude chats, memory, conversation summaries, or user files in Claude;
- personal health data, money transfers, ads, sponsored content.
4. Purposes and legal bases (GDPR)
- Performance of a contract (Art. 6(1)(b)): connecting Claude to Bonsai, authenticating you (OAuth), and running the tools you request;
- Legitimate interests (Art. 6(1)(f)): tool-invocation audit, security, abuse prevention, support;
- Legal obligation (Art. 6(1)(c)).
The connector accesses workspace data only after you authorize OAuth in Claude and complete Bonsai login. We do not carry out automated decision-making with legal or similarly significant effects (Art. 22 GDPR).
5. Use and storage
We use the data to authenticate Claude to the MCP server and maintain the OAuth session, resolve tenant context and permissions, call Bonsai first-party APIs, return only the tool output to Claude, and keep an audit trail (who called which tool, on which tenant, with which filters, with which result).
Where data lives: mcp-bonsai (central MCP server); customer Core (workspace — business data stays in the tenant); Hub-Agency (agency path only).
Bonsai does not sell this data and does not use connector data to train foundation models.
6. Third parties and sharing
- Anthropic / Claude: the MCP client you chose. Processing governed by Anthropic's terms and privacy policy. Bonsai does not control Claude.
- Customer Bonsai Core: source of KPIs and tables.
- Hub-Agency (only if you choose "I am an agency").
- Hosting / infrastructure providers: as processors under contract.
- Hub-Dev (Bonsai ops): not on the chat path; limited ops access under internal policy.
We do not share connector data with Amazon for MCP operation.
7. Retention
- OAuth tokens and MCP session context → until disconnect, expiry, rotation, or revocation.
- Tool-invocation audit logs (
mcp_tool_audit_logs) → 90 days, then automatic deletion. - Hub-Agency proxy audit logs (
proxy_audit_logs) → 90 days. - Infrastructure technical logs → ordinary security / diagnostics windows.
- Business data in the customer Core → follows the workspace contract.
8. International transfers
The MCP server and Bonsai systems are operated by Bonsai and its infrastructure providers. Using Claude means tool arguments and results are sent to Anthropic, which may process data outside the European Economic Area. See Anthropic's privacy policy.
9. Security
- HTTPS and OAuth 2.0 with PKCE;
- separate tokens (Claude→MCP vs MCP→workspace);
- secrets and tokens excluded from audit logs;
- no SQL or tenant-database access from MCP;
- domain tenant not freely chosen by Claude (allowlist / session context);
- analytics tools read-only, except switching the active agency tenant;
- invocation audit for operational traceability.
Personal-data breaches are handled under GDPR Arts. 33–34.
10. Your rights
Subject to applicable law, you may request access, rectification, erasure, restriction, objection, data portability, and you may disconnect the connector at any time.
- Disconnect the connector in Claude (Customize → Connectors).
- Revoke Bonsai access (logout, OAuth token revocation, agency membership removal).
- Email info@bonsaigrowth.it for access to or deletion of audit logs still within the retention window.
You may lodge a complaint with the Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome, Italy — or with your local EEA authority.
11. Children
The connector is a professional service for Bonsai account holders. It is not directed at anyone under 18.
12. Changes
We may update this notice. The date at the top is the current version. For material changes we will provide reasonable notice where required.
13. Directory acknowledgements (summary)
- Collection: OAuth identity, tenant context, tool arguments, tool results needed to fulfil the call, technical and audit logs. No Claude conversation harvesting, no Claude memory queries, no workspace passwords on MCP.
- Use and storage: run tools, enforce tenant allowlist and permissions, audit, security. Encrypted secret store for tokens. No tenant DB access from MCP.
- Third parties: Anthropic/Claude, customer Core, Hub-Agency (agency path), hosting processors. Not Amazon SP-API from the MCP server.
- Retention: 90 days for MCP and Hub-Agency audit logs; tokens until disconnect/revocation/expiry.
- Contact: info@bonsaigrowth.it.