Data Processing Agreement
Last updated: 26 April 2026
This Data Processing Agreement ("DPA") forms part of the WP MCP Terms of Service and applies to the extent that WP MCP processes personal data on behalf of a Customer that is subject to the GDPR or UK GDPR.
1. Definitions
- Controller: the Customer who determines the purposes and means of processing.
- Processor: WP MCP, which processes personal data on behalf of the Controller.
- Personal Data: any information relating to an identified or identifiable natural person transmitted through the Service.
2. Scope of Processing
WP MCP processes personal data solely to provide the Service as described in the Privacy Policy. Processing occurs within the EEA (Google Cloud europe-west1) unless the Customer configures otherwise.
3. Obligations of WP MCP (Processor)
- Process personal data only on documented instructions from the Controller.
- Ensure persons authorised to process personal data are bound by confidentiality.
- Implement appropriate technical and organisational security measures (Article 32 GDPR).
- Notify the Controller without undue delay of any personal data breach.
- Assist the Controller in fulfilling data subject rights requests.
- Delete or return all personal data upon termination of the Service.
4. Sub-processors
WP MCP uses the following sub-processors:
- Google Cloud Platform (EU) — hosting and database.
- Resend Inc. (US) — transactional email (SCCs applied).
We will notify Customers of any changes to sub-processors with at least 10 days' notice.
5. International Transfers
For transfers outside the EEA/UK (e.g. Resend in the US), WP MCP relies on Standard Contractual Clauses (SCCs) approved by the European Commission.
6. Security Measures
- TLS 1.2+ for all data in transit.
- AES-256 (Fernet) encryption for stored WordPress credentials.
- bcrypt password hashing.
- Access controls and audit logging.
7. Duration
This DPA is effective for the duration of the Customer's use of the Service and terminates automatically upon account deletion.
8. Contact
Data Protection queries: privacy@wpmcp.io