Ontop MCP Server Terms of Use β€” Pilot Release

September 23, 2026

Ontop MCP Server Terms of Use β€” Pilot Release
‍

Effective Date: September 23, 2026

‍

These Terms of Use govern your access to and use of the Ontop Model Context Protocol (MCP) Server, which allows you to connect a third-party Artificial Intelligence (AI) environment to your Ontop account. Please read these Terms carefully, as they establish the data protection, security, and liability boundaries between your use of external AI providers and the Ontop platform.

‍

Pilot release. The MCP Server is currently made available as a pilot. These Terms describe the MCP Server as it operates today. Several controls that form part of Ontop's longer-term design; including OAuth authorization, automatic Access Key expiry, self-service access to connection logs, and administrator-controlled suppression of worker identifiers, are in development and are not available in the Pilot. Section 9 lists them. Ontop expects to add capabilities during and after the Pilot. Each material change will be reflected in an updated version of these Terms and notified under Section 20. The Client should not rely on any capability that is not expressly described in these Terms as currently available.Β 

‍

1. Acceptance

By generating an Access Key for, connecting to, or otherwise accessing or using the Ontop MCP Server (the "MCP Server"), you agree to be bound by these Terms of Use (the "Terms"). If you access the MCP Server on behalf of a company or other legal entity (the "Client"), you confirm that you are authorized to bind that entity to these Terms.

‍

These Terms are supplemental to, and do not replace, any master subscription agreement, Client Terms and Conditions, Privacy Policy, order form, data processing agreement, or equivalent agreement between the Client and Ontop Holdings Inc. or any of its affiliates ("Ontop", "we", "us") governing the Client's use of the Ontop platform (the "Main Agreement").

‍

Order of precedence. In the event of a conflict:

‍

  • (a) on data protection and privacy matters, the data processing agreement between the parties prevails;
  • (b) on all other matters, the Main Agreement prevails, except that these Terms prevail to the extent they address subject matter specific to the MCP Server and not addressed in the Main Agreement; and
  • (c) nothing in these Terms reduces, waives, or displaces any right, warranty, service commitment, liability cap, indemnity, or remedy available to the Client under the Main Agreement.

‍

The Client acknowledges that the MCP Server is a pilot offering, that its capabilities are limited to those described in these Terms, and that these Terms will be updated as those capabilities change.Β 

‍

Capitalized terms not defined here have the meaning given in the Main Agreement.

‍

If you do not agree to these Terms, do not access or use the MCP Server.

2. Definitions

  • "Access Key" β€” a secret credential (API key) generated by the Client through the Ontop platform that authenticates requests to the MCP Server and determines which Client account the request may read.
  • "Account Data" β€” the Client's own data made available for reading through the MCP Server, including balances, balance history, headcount and contract status, invoices, and worker payment information, as further described in Section 11.
  • "AI Environment" β€” the third-party software interface, application, or service that the Client connects to the MCP Server and through which the Client submits questions and receives responses. This includes, without limitation: (i) an Ontop connector or app made available through a third-party AI directory or marketplace (for example, the Claude Connectors Directory or the ChatGPT app directory); (ii) the MCP Server added manually as a custom connector using its server URL and an Access Key ; and (iii) any other MCP-compatible AI assistant, agent, or client (for example, Claude, ChatGPT, Perplexity, or Cursor).
  • "AI Provider" β€” the third party that operates an AI Environment.
  • "Authorized User" β€” an individual permitted by the Client to access the MCP Server on the Client's behalf, in each case holding an Ontop account whose role permits access to the relevant Account Data. Only Authorized Users holding the Administrator role (or another role to which the Client's administrator has expressly granted the relevant permission) may enable the MCP Server or generate or revoke an Access Key.
  • "Eligible AI Environment" β€” an AI Environment that, at all times while connected, satisfies each of the conditions in Section 8.2.
  • "Output" β€” any content, answer, summary, or analysis generated by an AI Environment as a result of processing Account Data retrieved through the MCP Server.
  • "Pilot" β€” the current pilot release of the MCP Server, the capabilities of which are those described in these Terms and in Section 9.Β 
  • "Security Incident" β€” a confirmed unauthorized access to, acquisition of, loss of, or disclosure of Account Data occurring within systems operated or controlled by Ontop.
  • "Worker Data" β€” personal data relating to the Client's workers, contractors, or their personnel that forms part of Account Data.

3. The MCP Server

The MCP Server lets an Authorized User connect an AI Environment of their choice to the Client's Ontop account and ask questions about the Client's own Account Data in natural language. Key characteristics of the MCP Server in the Pilot :

‍

  • Read-only. The MCP Server exposes a fixed set of read-only tools. It cannot move money, initiate or modify payments, create or edit contracts, or make any other change to the Client's account or to any Ontop system. There is no tool that performs a write action. All tools currently exposed are read tools. Any future write tool will be exposed as a separate, individually identifiable tool, distinctly identified from read tools.Β 
  • Scoped to the Client's own account. Each request is authenticated by the Access Key, and the account read is determined solely by that key β€” never by the content of the question. An Authorized User can only reach the Client's own account through the MCP Server. The MCP Server grants access only to data that the Ontop user account associated with that Access Key can already access manually in the standard Ontop platform interface. Connecting via the MCP Server does not bypass any pre-existing role-based access control restriction.Β 
  • Fixed queries. The MCP Server executes pre-defined queries. The AI Environment does not author database queries and cannot request arbitrary data beyond what the defined tools return.
  • Response minimization. Each tool returns only the fields defined for that tool, as listed in Section 11.4. Tool responses do not include diagnostic data, telemetry, or internal identifiers beyond what is necessary for the tool's stated purpose.
  • Attribution and logging. Each request to the MCP Server is logged and attributed to the Access Key used. Section 6 describes how these logs are maintained and retained.
  • Rate limits. Access is subject to rate limits applied by Ontop. Ontop may apply, adjust, or enforce rate limits to protect the availability and integrity of the MCP Server and of Client data.
  • Data sources and freshness. Responses are drawn from live operational data and from warehoused data that may lag by up to approximately one hour. Ontop does not warrant that any figure is real-time.
  • Authentication. Access is by Access Key only. OAuth authorization is not available in the Pilot; see Section 9.Β 

‍

Ontop does not operate or control the Client's AI Environment and has no access to the Output generated within it. The Client is solely responsible for the selection, configuration, and use of its AI Environment and for any Output.

‍

The characteristics described in this Section 3 are commitments by Ontop as to the design of the MCP Server, and are not subject to the disclaimer in Section 14.

4. Eligibility and Enablement

The MCP Server is available only to Clients with an active Ontop account in good standing, and only where enabled by the Client's administrator. Access is provided for the Client's internal business use in connection with its own Ontop account.

‍

Access control in the Pilot. The Client's administrator may revoke any Access Key at any time from the Ontop platform. Revoking an Access Key immediately ends all access that uses that key. Access control in the Pilot operates at the level of the Access Key: because a key may be placed by an Authorized User into any AI Environment, Ontop cannot block an individual Authorized User's use of a key that has not been revoked. The Client is responsible for issuing Access Keys only to Authorized Users it intends to permit, and for revoking a key when that permission ends.Β 

‍

Ontop may make the MCP Server available free of charge and may change, limit, or withdraw it at any time in accordance with these Terms and the Main Agreement. After the Pilot, except where a change is required to address a security, legal, or regulatory risk, Ontop will give the Client at least thirty (30) days' prior notice before withdrawing the MCP Server or removing a tool on which the Client's use materially depends.

Pilot terms. During the Pilot: (a) the MCP Server is provided free of charge; (b) Ontop may add, change, or remove tools and features on reasonable notice, which may be given through the Ontop platform; and (c) Ontop may invite the Client to share feedback on its use of the MCP Server, which the Client may decline. Ontop may introduce fees for the MCP Server after the Pilot by giving the Client at least thirty (30) days' prior notice, and fees will apply only if the Client continues to use the MCP Server after that notice period.

‍

No service level. The MCP Server is provided without a service level commitment and is not covered by any availability, uptime, or support commitment in the Main Agreement unless the parties expressly agree otherwise in writing.

5. Authentication and Security

In the Pilot, the MCP Server supports one authentication method: an Access Key (an API key generated in the Ontop platform). OAuth authorization is not available; see Section 9.Β 

5.1 Access KeysΒ 

  • One-time display. The full secret value of an Access Key is displayed only once, at creation. Ontop stores only a hashed representation and cannot retrieve, reveal, or restore a key value. If a key value is lost, the Client must revoke it and create a new one.
  • Safeguarding. The Client is responsible for keeping Access Keys confidential. Access Keys must be placed in the AI Environment's authentication field and must never be embedded in a URL, shared publicly, or disclosed to any party who is not an Authorized User.
  • Rotation. Access Keys do not expire automatically in the Pilot and remain valid until revoked by the Client. Ontop does not send expiry or renewal reminders. The Client is responsible for rotating Access Keys β€” Ontop recommends at least every ninety (90) days, and immediately whenever an Authorized User with knowledge of a key leaves the Client's organization or changes role β€” and for revoking any key that is no longer required. Automatic expiry and advance expiry notices are planned; see Section 9.Β 
  • Revocation. The Client may revoke any Access Key at any time. Revoking one key does not affect the others.
  • Compromise. The Client must promptly revoke any Access Key it believes may be compromised and notify Ontop without undue delay, and in no event later than twenty-four (24) hours after discovery of the suspected compromise, at cybersecurity@getontop.com

5.2 Client obligationsΒ 

  • Multi-factor authentication. Where Ontop makes multi-factor authentication available, the Client must enable multi-factor authentication on every Ontop account used to enable the MCP Server or to generate or hold an Access Key.
  • Responsibility for activity. The Client is responsible for all access to and use of the MCP Server carried out through its Access Key, except to the extent such access or use results from Ontop's breach of these Terms, negligence, or willful misconduct.Β 
  • Credential hygiene. The Client must not share an Access Key with any party who is not an Authorized User, and must promptly revoke, and notify Ontop of, any Access Key it believes may be compromised, within the period set out in Section 5.1.Β 

5.3 Ontop's security commitmentsΒ 

Ontop will:

  • (a) maintain technical and organizational security measures for the MCP Server consistent with those it applies to the Ontop platform generally, with the Main Agreement and any applicable data processing agreement, and with applicable law;
  • (b) encrypt Account Data in transit between the MCP Server and the AI Environment using industry-standard transport encryption, and store Access Key values only in hashed form;
  • (c) maintain logging of requests to the MCP Server sufficient to reconstruct which Access Key accessed which tool and when;
  • (d) notify the Client without undue delay after becoming aware of a Security Incident affecting the Client's Account Data, and provide information reasonably necessary for the Client to meet its own notification obligations; and
  • (e) maintain a monitored contact address for receiving security vulnerability reports concerning the MCP Server at cybersecurity@getontop.com.

6. Logging, Audit, and Regulated Clients

6.1 Access logs

Ontop logs each request to the MCP Server, including the timestamp, the tool invoked, the Access Key to which it is attributed, and the response status. These logs are maintained by Ontop for the purposes set out in Section 11.3. Self-service access to MCP Server logs from the Ontop platform is not available in the Pilot; see Section 9.Β 

‍

6.2 RetentionΒ 

Ontop retains MCP Server access logs for the longer of twelve (12) months and any period required by applicable law or regulation, including recordkeeping obligations applicable to Ontop as a registered money services business. Logs are used only for the purposes set out in Section 11.3 and are never used to train any artificial intelligence model.

‍

6.3 Regulated clients

Ontop recognizes that clients that are, or that serve, regulated financial institutions may be subject to third-party and ICT risk management requirements. On reasonable request, Ontop will provide information reasonably necessary to support the Client's due diligence and ongoing monitoring of the MCP Server, including any security certifications Ontop then holds and a description of the MCP Server's architecture and data flows. During the Pilot, a Client that is subject to Regulation (EU) 2022/2554 (DORA), the interagency third-party risk management expectations applicable to US banking organizations, or comparable requirements must contact Ontop before enabling the MCP Server. Any supplemental terms will apply only if agreed in a written addendum to the Main Agreement.

7. Permitted Use and Restrictions

Permitted use. The Client may use the MCP Server solely to read its own Account Data through an Eligible AI Environment for the Client's internal business purposes.

‍

The Client shall not:

‍

  • (a) attempt to access, read, or infer any data that does not belong to the Client, or to bypass, probe, or interfere with the account-scoping, authentication, or security controls of the MCP Server;

‍

  • (b) use the MCP Server for any unlawful, fraudulent, harmful, or abusive purpose, or in a manner that would cause Ontop to breach any anti-money-laundering, sanctions, payments, or employment law applicable to it;

‍

  • (c) overload, disrupt, or interfere with the MCP Server or Ontop's infrastructure, circumvent or attempt to circumvent any rate limit, or transmit any malicious code;

‍

  • (d) engage in prompt injection, jailbreaking, or adversarial prompting directed at the MCP Server;

‍

  • (e) scrape or bulk-extract Account Data beyond ordinary interactive use, or permit any AI Environment to cache, index, or bulk-extract Account Data for the purpose of competitive data tracking or the training or fine-tuning of any model;

‍

  • (f) reverse engineer, decompile, or attempt to derive the structure, source, or non-public logic of the MCP Server, except to the extent this restriction is prohibited by applicable law;

‍

  • (g) use the MCP Server, Account Data, or Output to build, train, or improve any product or service that competes with Ontop, or to develop a competing model or tool;

‍

  • (h) resell, sublicense, or otherwise make the MCP Server available to any third party who is not an Authorized User, or allow any third party to access the MCP Server through the Client's Access Keys;

‍

  • (i) use the MCP Server in any way that infringes the rights of Ontop or any third party;

‍

  • (j) connect, or keep connected, any AI Environment that is not an Eligible AI Environment;

‍

  • (k) use the MCP Server or any Output as the sole or determinative basis for a decision that produces legal effects concerning, or similarly significantly affects, an individual, including any decision on the engagement, renewal, suspension, or termination of a contractor or worker, or on their payment terms, without meaningful human review by a person with the authority and competence to change the decision; or

‍

  • (l) use the MCP Server to conduct automated monitoring, scoring, or profiling of individual workers or contractors, or to infer any special category of personal data about them.

8. Third-Party AI Environments

8.1 General

The AI Environment is a third-party system that the Client selects, enables, configures, and controls at its own discretion and risk (for example, Claude, ChatGPT, Perplexity, or another MCP-compatible client). The Client acknowledges that:

‍

  • Data leaves Ontop's boundary. When an Authorized User submits a question, the AI Environment calls the MCP Server on the Client's instruction, and the requested Account Data is returned to the AI Environment. From that point, the Account Data is processed by the AI Provider under the Client's own arrangements with that AI Provider and outside Ontop's control. Ontop remains responsible for the security of Account Data within systems operated or controlled by Ontop. Ontop is not responsible for, and has no ability to control, the processing, storage, retention, security, or onward disclosure of Account Data within the AI Environment or the AI Provider's infrastructure, and Ontop has no liability for any data breach, leakage, or misuse occurring there.
  • Irreversibility. Disconnecting an AI Environment or revoking an Access Key stops further access to Account Data. It does not delete, recall, or render inaccessible any Account Data that the AI Environment has already retrieved.
  • The Client's arrangements govern. The Client is responsible for its relationship and agreement with each AI Provider, including any terms relating to model training, data retention, confidentiality, and security. Ontop does not verify and makes no representation regarding those terms. As between Ontop and the Client, the Client is responsible for determining and documenting the role of each AI Provider under applicable data protection law, and for putting in place any authorization, contract, or transfer mechanism that role requires. No AI Provider is a sub-processor of Ontop.

8.2 Eligible AI Environments

Given the sensitivity of payroll and financial Account Data, the Client may connect only an Eligible AI Environment. An AI Environment is an Eligible AI Environment only if, at all times while connected, it is governed by written terms between the Client and the AI Provider that:

‍

  • (a) are enterprise, business, commercial, or equivalent terms, and not a consumer, free-tier, trial, personal, or unpaid plan;
  • (b) prohibit the AI Provider from using the Client's inputs and outputs to train or fine-tune generalized models;
  • (c) provide for defined and limited retention of the Client's inputs and outputs, and for deletion on termination;
  • (d) impose confidentiality obligations and security measures appropriate to payroll and financial data; and
  • (e) provide the Client with administrative controls over the AI Provider's workspace, including the ability to manage members and revoke access.

‍

The Client represents and warrants that each AI Environment it connects meets these conditions, and undertakes to disconnect promptly any AI Environment that ceases to meet them. Ontop may request written confirmation, and may revoke the relevant Access Key where the Client does not provide it within a reasonable period.

‍

Supported AI Environments. MCP is an open protocol, and the MCP Server does not technically restrict which AI Environment may connect using a valid Access Key. Compliance with this Section 8.2 is therefore a contractual obligation of the Client, on which Ontop relies. Ontop may publish a list of AI Environments it has tested, but does not verify, approve, or block any AI Environment. Where the Client connects an AI Environment that is not an Eligible AI Environment, Ontop's remedies are those set out in Section 19, including revocation of the relevant Access Key.Β 

8.3 Authorization to transmit

The Client authorizes Ontop to return Account Data to the AI Environment activated by the Client's Access Key, and represents that it has all rights and authority necessary to grant that authorization, including in respect of Worker Data.

8.4 Connection methods and directory listings

The MCP Server may be connected in different ways, and the following apply regardless of method:

‍

  • Same authentication and scoping. Whether the Client connects through an Ontop listing in a third-party AI directory, adds the MCP Server manually as a custom connector, or uses any other MCP-compatible client, the account-scoping described in Section 3 applies identically regardless of how the MCP Server is connected. The connection method does not expand the data the Client can reach.
  • Directory and marketplace terms. Where the Client connects through a third-party AI directory or marketplace, the Client's use within that environment is also governed by that operator's own terms, policies, permissions, and consent screens. Those are agreements between the Client and the operator; Ontop is not a party to them and is not responsible for them.
  • Permission screens. In the Pilot, access is granted by the Client placing an Access Key into its chosen AI Environment; Ontop does not present a consent screen. Any permission, consent, or data-sharing screen shown by the AI Provider or directory operator (including its description of the app or connector) is presented and controlled by that operator, not by Ontop, and reflects that operator's practices.Β 
  • Official listings only. Only Ontop may publish or authorize an official Ontop connector, app, or directory listing for the MCP Server. The Client shall not publish, distribute, operate, or hold out any unofficial connector, proxy, relay, or middleware that provides access to the MCP Server, and shall not represent any connector as endorsed, certified, or provided by Ontop unless Ontop has expressly authorized it in writing.
  • Directory verification is not an Ontop assurance. Where a directory operator marks the Ontop connector as verified, reviewed, or similar, that designation reflects the operator's own process. It is not a security audit of the MCP Server and is not a representation by Ontop.
  • Account type. The obligation in this Section 8 to ensure that each connected AI Environment is an Eligible AI Environment applies to every connection method, including connection through a directory listing or a manually added custom connector.

9. Pilot Scope and Planned CapabilitiesΒ 

9.1 Read-only scope

The MCP Server is read-only, as described in Section 3. Nothing in these Terms grants the Client any right to write, modify, or transactional capability that is not expressly offered. Ontop does not intend to expose any tool that initiates, authorizes, or modifies the movement of funds.

9.2 Capabilities not available in the PilotΒ 

The following are part of Ontop's design for the MCP Server but are not available in the Pilot. The Client must not rely on any of them:

‍

  • (a) OAuth authorization. Access in the Pilot is by Access Key only. Ontop intends to add OAuth authorization, under which the Authorized User is redirected to Ontop's login to authenticate and consent, access tokens are short-lived, refresh tokens are rotated on use, authorizations are reviewable and revocable from the Ontop platform, and periodic reconfirmation may be required.Β 
  • (b) Automatic Access Key expiry and expiry notices. Access Keys do not expire automatically and Ontop does not send expiry reminders. Rotation is the Client's responsibility under Section 5.1.Β 
  • (c) Self-service access to MCP Server logs. Ontop maintains the logs described in Section 6, but the Client cannot retrieve them from the Ontop platform.Β 
  • (d) Administrator-controlled suppression of worker identifiers. Ontop does not offer a setting that removes worker names, email addresses, or countries from tool responses. See Section 11.5.Β 
  • (e) Write tools. No tool performs a write action.

‍

The following is not planned, and the Client should not assume it: technical restriction of AI Environments. MCP is an open protocol and the MCP Server does not restrict which AI Environment may connect with a valid Access Key. See Section 8.2.Β 

9.3 How capabilities change

No capability listed in Section 9.2 may be relied on until these Terms state that it is available. Ontop may introduce additional capabilities, including tools that perform write actions. Before any write capability becomes available to the Client:

‍

  • (a) these Terms will be updated and the Client given notice in accordance with Section 20;
  • (b) the capability will be off by default and will require affirmative enablement by the Client's administrator;
  • (c) write tools will be exposed as separate tools, distinctly identified from read tools; and
  • (d) Ontop will apply step-up confirmation controls to any high-risk action, requiring an Authorized User to confirm the action outside the AI Environment before it is executed, with confirmation requests expiring if not approved within a defined period.

10. Accuracy, No Advice, and AI Risk

  • No warranty of accuracy. Account Data returned by the MCP Server and any Output derived from it may be inaccurate, incomplete, outdated, or misinterpreted by the AI Environment. Warehoused figures may lag by up to approximately one hour.
  • AI-specific risk. AI Environments may generate inaccurate, fabricated, or misleading Output ("hallucinations"), including incorrect figures or conclusions, even when the underlying Account Data is accurate.
  • Manipulation risk. Output may also be influenced by content the AI Environment processes from other sources, including other connected tools, documents, or web content, by means outside Ontop's control. The Client should treat Output as an aid to analysis and not as an instruction.
  • Not advice. The MCP Server and any Output do not constitute financial, accounting, tax, legal, payroll, or compliance advice, and are not a substitute for the Client's own professional judgment.
  • Client responsibility. The Client is solely responsible for evaluating and verifying Account Data and Output before relying on it, and for any decision it makes based on it. The Client should confirm figures in the Ontop platform of record before acting on any financial or payroll matter. The Client must not use Output as the sole basis for initiating a payment, filing a tax or regulatory return, or making a statutory report.

‍

11. Data and Privacy

11.1 Governing instruments

Ontop's processing of personal data in connection with the Client's account and use of the MCP Server is governed by the Main Agreement, any applicable data processing agreement, and Ontop's Privacy Policy at https://www.getontop.com/policy/privacy-policy.Β 

11.2 Roles

Where Ontop processes personal data on the Client's behalf in connection with the MCP Server, Ontop acts as a processor acting on the Client's documented instructions, and the Client acts as the controller. The Client's act of connecting an AI Environment and submitting a question constitutes a documented instruction to Ontop to disclose the responsive Account Data to that AI Environment.

11.3 Logging

Ontop logs requests to the MCP Server (the tools invoked and their parameters, not the questions typed by Authorized Users or the Output) for security, abuse-prevention, and compliance purposes, and to operate, support, and improve the MCP Server, including through aggregated usage analytics. Such logs will be retained in accordance with Section 6.2, and will under no circumstances be used by Ontop to train any artificial intelligence model. Ontop does not access or review Output generated within the Client's AI Environment. Once Account Data is transmitted to the AI Environment on the Client's instruction, its further processing is governed by the Client's arrangements with the relevant AI Provider, as described in Section 8.

11.4 Categories of data the MCP Server can access

When an Authorized User asks a question, the MCP Server reads and returns categories of the Client's own Account Data, which are then transmitted to, and become accessible within, the AI Environment the Client has connected. These categories are:

‍

  • the Client's account balance and its movement history (top-ups, withdrawals, and payments), including any free-text descriptions an operator may have entered on a transaction;
  • aggregate headcount figures (counts of contracts by status, with no individual records);
  • contract information, including personal data of the Client's workers and contractors β€” such as name (or legal-entity name where the worker invoices as a company), email, role, country, team, contract type, start and end dates, remuneration amount, currency and payment frequency, and whether each party has signed;
  • invoices that Ontop issues to the Client for membership and service fees; and
  • worker payment invoices, including the worker's name and country of residence, the amounts invoiced and paid, and the related payment dates.

‍

This list reflects the tool responses in the Pilot and will be updated if the tool set changes.Β 

11.5 Third-party personal data

Some of this data β€” in particular worker and contractor names, emails, countries, roles, remuneration, and payment details β€” is personal data of individuals who are not the person granting consent. By connecting an AI Environment and asking questions that return this data, the Client causes such third-party personal data to be transmitted to the AI Provider. The Client, acting as the data controller, is responsible for ensuring it has a lawful basis and appropriate arrangements in place to do so, including:

‍

  • (a) providing any privacy notice or information required to the affected workers and contractors, and informing them that their personal data may be transmitted to and processed within a third-party AI environment;
  • (b) obtaining any authorization or consent required under applicable law, including where required under Ley 1581 de 2012 (Colombia);
  • (c) legitimizing any international transfer of that personal data to the AI Provider, including under Articles 44 to 49 of the GDPR or Article 26 of Ley 1581 de 2012 as applicable;
  • (d) responding to requests from those individuals to exercise their rights, with Ontop providing reasonable assistance in accordance with the data processing agreement; and
  • (e) conducting any impact assessment required in respect of its use of an AI Environment.

‍

Ontop does not currently offer a setting that suppresses worker identifiers from tool responses. In the Pilot, the controls available to the Client are the credential, access, and use restrictions in these Terms, together with the arrangements the Client puts in place with its AI Provider. See Section 9.Β 

11.6 What the MCP Server does not exposeΒ 

Other than information the Client's users may have entered in free-text transaction descriptions (see Section 11.4), the MCP Server does not return signed documents or their contents, bank-account, card, or wallet numbers, tax or national identifiers, postal addresses, phone numbers, or dates of birth, and does not access any special categories of personal data (such as health, biometric, racial or ethnic origin, trade-union membership, or similar data). It cannot reach data belonging to any account other than the Client's own.

12. Intellectual Property

Ontop retains all intellectual property rights in the MCP Server, including its tools, interfaces, query definitions, schemas, and documentation. The Client is granted a limited, non-exclusive, non-transferable, revocable right to use the MCP Server solely as permitted in these Terms. All rights not expressly granted are reserved.

‍

The Client retains all rights in its Account Data. As between Ontop and the Client, Output is the Client's, subject to the Client's arrangements with the AI Provider; Ontop makes no claim to it and assumes no responsibility for it. If the Client provides feedback or suggestions regarding the MCP Server, it grants Ontop a perpetual, irrevocable, royalty-free license to use that feedback without obligation.

13. Confidentiality

Non-public information about the MCP Server, including its features, tool definitions, and documentation, is Ontop's confidential information. The Client shall protect it with at least reasonable care and shall not use or disclose it except as necessary to use the MCP Server under these Terms. This obligation does not apply to information that is or becomes public other than through the Client's breach, is independently developed, or is lawfully received from another source without restriction.

‍

Account Data is the Client's confidential information and is subject to Ontop's confidentiality obligations under the Main Agreement. Nothing in these Terms reduces those obligations.

14. Disclaimers

Except as expressly stated in Sections 3, 5.3, 6, and 11.3, THE MCP SERVER AND ALL ACCOUNT DATA MADE AVAILABLE THROUGH IT ARE PROVIDED "AS IS" AND "AS AVAILABLE", WITHOUT WARRANTY OF ANY KIND. TO THE FULLEST EXTENT PERMITTED BY LAW, ONTOP DISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, ACCURACY, COMPLETENESS, AND NON-INFRINGEMENT. ONTOP DOES NOT WARRANT THAT THE MCP SERVER WILL BE UNINTERRUPTED, SECURE, OR ERROR-FREE, OR THAT OUTPUT WILL BE ACCURATE OR FREE FROM ERRORS OR HALLUCINATIONS. NOTHING IN THIS SECTION LIMITS ANY WARRANTY GIVEN BY ONTOP UNDER THE MAIN AGREEMENT.

15. Limitation of Liability

TO THE FULLEST EXTENT PERMITTED BY LAW, ONTOP SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, OR FOR ANY LOSS OF PROFITS, DATA, BUSINESS, OR GOODWILL, ARISING OUT OF OR RELATING TO THE MCP SERVER, INCLUDING ANY RELIANCE ON ACCOUNT DATA OR OUTPUT, ANY INACCURACY OR HALLUCINATION, OR ANY ACT OR OMISSION OF AN AI PROVIDER.

‍

Ontop's total aggregate liability arising out of or relating to the MCP Server and these Terms is subject to, and counts against, the limitation of liability set out in the Main Agreement. These Terms do not create a separate or lower cap.

‍

For the avoidance of doubt, and without limiting the preceding paragraph, Ontop is not liable for any data breach, unauthorized access, or misuse of Account Data occurring within the AI Environment or the AI Provider's infrastructure after the Account Data has been transmitted to the AI Environment on the Client's instruction.

‍

Nothing in these Terms limits or excludes liability for fraud or fraudulent misrepresentation, for death or personal injury caused by negligence, for a party's gross negligence or willful misconduct, or any other liability that cannot be limited or excluded under applicable law.

16. Indemnification

The Client shall defend, indemnify, and hold harmless Ontop and its affiliates and their respective officers, employees, and agents from and against any third-party claims, losses, damages, costs, and expenses (including reasonable legal fees) arising from: (a) the Client's use of the MCP Server in breach of these Terms; (b) the Client's selection, configuration, or use of any AI Environment, including any data breach, privacy violation, or unauthorized processing of personal data occurring within such AI Environment; or (c) the Client's violation of applicable law; in each case except to the extent the claim arises from Ontop's breach of these Terms, negligence, or willful misconduct.

‍

Procedure. The party seeking indemnification will give the indemnifying party prompt written notice of the claim, sole control of the defense and settlement (provided that no settlement imposing a non-indemnified obligation or an admission of liability may be made without the indemnified party's consent, not to be unreasonably withheld), and reasonable cooperation at the indemnifying party's expense. A delay in notice relieves the indemnifying party only to the extent it is prejudiced by the delay.

‍

Ontop's indemnities. Any indemnity given by Ontop under the Main Agreement, including in respect of third-party intellectual property claims, applies to the MCP Server as part of the Ontop platform.

17. Trademarks

The Client may make factual references to Ontop and the Ontop MCP Server when describing its use of them. The Client shall not use Ontop's name, logo, or trademarks in any way that implies endorsement, certification, or approval by Ontop without Ontop's prior written consent.

‍

18. Export Controls and Sanctions

The Client shall comply with all applicable export control and economic sanctions laws, including those administered by the U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC), and confirms that it is not located in, and is not a national or resident of, any jurisdiction subject to applicable comprehensive sanctions or embargoes. Use of the MCP Server from or in connection with such jurisdictions is prohibited.

‍

The Client shall not permit any Authorized User who is a sanctioned person, or who is located in a comprehensively sanctioned jurisdiction, to access the MCP Server, and shall not connect an AI Environment operated from such a jurisdiction. Ontop may block, suspend, or terminate access where it determines, acting reasonably, that continued access would present a sanctions risk.

19. Suspension, Termination, and Changes to the Service

Ontop may suspend or terminate access to the MCP Server at any time, with or without notice, including for breach of these Terms, suspected compromise of an Access Key, connection of an AI Environment that is not an Eligible AI Environment, risk to Ontop's systems or other clients, or any reasonable suspicion of a data privacy violation or unauthorized processing of personal data by the Client or its AI Provider. Where Ontop suspends access without prior notice, it will notify the Client promptly afterwards and, where the cause is capable of remedy, will restore access once the Client has remedied it.

‍

Access to the MCP Server terminates automatically if the Main Agreement terminates or expires. Ontop may modify or discontinue the MCP Server or any of its tools at any time, subject to Section 4.

‍

On termination or suspension, the Client must cease use of the MCP Server and revoke its Access Keys . Account Data already retrieved by an AI Environment is not recoverable by Ontop; the Client is responsible for its deletion under the Client's arrangements with the AI Provider.

‍

Sections 7, 10 through 18, and 20 through 22, and this Section, survive termination.Β 

20. Changes to These Terms

Ontop may update these Terms. The current version will be available at link. Where a change is material, Ontop will give the Client at least thirty (30) days' prior notice before it takes effect, except where a shorter period is required to address a legal, regulatory, or security requirement. If the Client does not accept a material change, its remedy is to stop using the MCP Server before the change takes effect. Continued use of the MCP Server after an update takes effect constitutes acceptance of the updated Terms.

21. Governing Law and Jurisdiction

These Terms are governed by the laws and subject to the exclusive jurisdiction of the courts as set forth in the Ontop Client General Terms and Conditions (available at https://www.getontop.com/policy/client-general-terms-and-conditions or the applicable customized master agreement executed between the Client and Ontop. Ontop may seek injunctive or equitable relief in any court of competent jurisdiction to protect its intellectual property or the security of its systems.

22. General

  • Entire agreement; precedence. These Terms, together with the Main Agreement and Ontop's Privacy Policy, constitute the entire agreement regarding the MCP Server, and are subject to the order of precedence in Section 1.
  • Assignment. The Client may not assign these Terms without Ontop's prior written consent.
  • Severability. If any provision is held invalid or unenforceable, it shall be modified to the minimum extent necessary and the remaining provisions shall continue in effect.
  • No waiver. Ontop's failure to enforce any provision is not a waiver of its right to do so.
  • No third-party beneficiaries. These Terms do not confer any right or remedy on any person other than the Client and Ontop.
  • Language. These Terms are made in English, which prevails over any translation.
  • Contact. Questions about these Terms: cybersecurity@getontop.com.Β 

‍

Table of contents
Landscape earth planet
Γ—Talk to an expert

Let's get you on board

Drop your details and a teammate from Ontop will reach out.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.