Moonlit MCP Data Processing Agreement
Last updated 2 August 2026.
The terms under which Moonlit Legal Technologies B.V. processes personal data on behalf of customers in connection with the Moonlit MCP Server.
How this DPA applies
This Data Processing Agreement (the "DPA") is published by Moonlit Legal Technologies B.V., registered at Westeinde 14, 1017 ZP Amsterdam, the Netherlands, KvK number 93559291 (the "Processor" or "Moonlit"). It is incorporated by reference into the Moonlit MCP Server Terms of Service. By accepting those Terms, the customer using the MCP Service (the "Controller" or the "Customer", the party defined as the Subscriber in those Terms) accepts this DPA. Together, Moonlit and the Customer are the "Parties" and each a "Party".
This DPA takes effect, as between Moonlit and a given Customer, on the date the Customer first accepts the Terms or otherwise begins using the MCP Service after the Last updated date shown above. No separate signature is required. Enterprise Customers who require a counter-signed instrument may email privacy@moonlit.ai.
This DPA governs the Processing of Personal Data by Moonlit as Processor on behalf of the Customer as Controller in connection with the Moonlit MCP Server.
Recitals
(A) The Parties have entered into a Moonlit MCP Subscription or another order form (the "Principal Agreement") under which Moonlit provides the Customer with access to the Moonlit Data Layer through the MCP Service.
(B) In the course of providing the MCP Service, Moonlit may Process Personal Data on behalf of the Customer within the meaning of the GDPR.
(C) The Parties wish to set out their respective rights and obligations in relation to such Processing in compliance with Regulation (EU) 2016/679 (the "GDPR"), the Dutch GDPR Implementation Act, and any other applicable Data Protection Laws.
(D) This DPA forms an integral part of the Principal Agreement. In the event of a conflict between this DPA and the Principal Agreement on matters of data protection, this DPA shall prevail.
Clause 1. Definitions
In this DPA, unless the context requires otherwise:
1. "Authentication Credentials" means the Moonlit platform account credentials with which an Authorised User signs in to the MCP Server through the OAuth 2.1 authorisation code flow with PKCE, and any MCP key created by the Customer's organisation in the Moonlit platform for pooled and deployed services.
2. "Data Protection Laws" means the GDPR, the Dutch GDPR Implementation Act (UAVG), the ePrivacy Directive 2002/58/EC, and any other applicable EU or Member State law relating to the processing of Personal Data.
3. "Data Subject" means an identified or identifiable natural person to whom Personal Data relates.
4. "Moonlit Data Layer" or "Data Layer" means Moonlit's database of publicly available European legal and regulatory sources (such as court decisions, legislation, official publications, and regulatory materials), together with the metadata and classifications Moonlit generates from those sources, that Moonlit makes accessible through the MCP Service. The Moonlit Data Layer is also accessible through the Moonlit Data API, which is governed by a separate Data License Agreement and is outside the scope of this DPA.
5. "MCP Service" or "Service" means the Moonlit MCP Server and the read-only tools it exposes: keyword search, hybrid search (with and without reranking), reference search, document retrieval, article-level retrieval, filter and taxonomy lookups, CELEX conversion, account status reporting, and any successive or replacement tools.
6. "Personal Data" means any information relating to an identified or identifiable natural person, as defined in Article 4(1) of the GDPR.
7. "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Personal Data, as defined in Article 4(12) of the GDPR.
8. "Processing" means any operation or set of operations performed on Personal Data, as defined in Article 4(2) of the GDPR. "Process" and "Processed" shall be construed accordingly.
9. "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses approved by the European Commission pursuant to Article 46(2)(c) of the GDPR, as amended or replaced from time to time.
10. "Sub-processor" means any third party engaged by Moonlit to Process Personal Data on behalf of the Customer in connection with the MCP Service.
11. "Supervisory Authority" means an independent public authority established by an EU Member State pursuant to Article 51 of the GDPR.
Capitalised terms not defined in this DPA have the meanings given to them in the Principal Agreement or the GDPR.
Clause 2. Scope and Purpose of Processing
2.1 Subject Matter and Duration
This DPA applies to the Processing of Personal Data by Moonlit on behalf of the Customer in connection with the MCP Service. The Processing will continue for the duration of the Principal Agreement, unless earlier terminated in accordance with this DPA or the Principal Agreement.
2.2 Nature and Purpose of Processing
Moonlit Processes Personal Data solely for the purpose of providing the MCP Service to the Customer, specifically:
- Receiving, processing, and responding to MCP Tool calls invoked by an Authorised User through an MCP-compatible client;
- Authenticating MCP sessions through Moonlit platform account sign-in via the OAuth 2.1 authorisation flow (with Dynamic Client Registration under RFC 7591 and PKCE under RFC 7636) or, for pooled and deployed services, through an MCP key created by the Customer's organisation, and issuing access and refresh tokens;
- Retrieving and returning legal documents (including metadata and full text) from the Moonlit Data Layer in response to such queries;
- Maintaining MCP access logs for security, abuse prevention, and usage reporting; and
- Processing hybrid and reranked search queries through the GenAI Sub-processor listed in Annex III to return conceptually relevant results.
2.3 Types of Personal Data
The Personal Data Processed under this DPA may include:
2.4 Categories of Data Subjects
Data Subjects whose Personal Data may be Processed include:
- Individuals referenced in legal documents within the Moonlit Data Layer (typically as publicly available information);
- Authorised Users who submit queries through the MCP Service, connecting to the MCP Server through Claude.ai, Claude Code, Claude Desktop, or another MCP-compatible client; and
- The Customer's employees or representatives with access to the MCP Service.
2.5 Nature of the Moonlit Data Layer
The Parties acknowledge that the Moonlit Data Layer consists exclusively of publicly available legal and regulatory sources. These sources are published by courts, legislatures, regulators, and other official bodies. They are typically anonymised or pseudonymised by the original publishers before ingestion by Moonlit. Any personal data present in the Moonlit Data Layer reflects the editorial decisions of the original publisher.
For the avoidance of doubt, Moonlit maintains the Moonlit Data Layer as an independent controller in its own right. Moonlit's independent controllership over the Moonlit Data Layer is separate from and does not affect its role as Processor with respect to the Processing activities described in Clauses 2.2 and 2.3 of this DPA (such as processing MCP Tool calls, maintaining account data, and generating usage logs). The Customer's retrieval of documents from the Moonlit Data Layer via the MCP Service constitutes access to data for which Moonlit is an independent controller. This DPA does not govern Moonlit's independent processing of the Moonlit Data Layer.
2.6 Obligations of the Controller
The Customer warrants that:
(a) it has and will maintain a valid legal basis under the GDPR for the Processing of Personal Data instructed under this DPA, including any Personal Data contained in MCP Tool calls submitted by or on behalf of the Customer;
(b) it has provided all necessary transparency and notices to Data Subjects in accordance with Articles 13 and 14 of the GDPR;
(c) it has the right to transfer or provide access to Personal Data to Moonlit for Processing under this DPA; and
(d) its documented instructions to Moonlit will at all times comply with Data Protection Laws; and
(e) it has an appropriate legal basis for any Processing, in connection with its use of the MCP Service, of special categories of personal data or data relating to criminal convictions and offences (Articles 9 and 10 of the GDPR) that the Moonlit Data Layer may contain as published in official legal sources.
The Customer shall be solely responsible for the lawfulness of its use of the MCP Service and for the instructions it provides to Moonlit.
Clause 3. Obligations of the Processor
3.1 Processing Instructions
Moonlit shall Process Personal Data only on documented instructions from the Customer, unless required to do so by EU or Member State law. In such a case, Moonlit shall inform the Customer of that legal requirement before Processing, unless that law prohibits such information on important grounds of public interest.
The Customer's documented instructions for Processing are set out in this DPA, the Principal Agreement, and any subsequent written instructions agreed by both Parties. If Moonlit considers that any instruction from the Customer infringes Data Protection Laws, Moonlit shall promptly inform the Customer.
3.2 Confidentiality
Moonlit shall ensure that all persons authorised to Process Personal Data on its behalf have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. Access to Personal Data is limited strictly to personnel with a legitimate business need.
3.3 Security of Processing
Moonlit shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of Processing, as well as the risk for the rights and freedoms of Data Subjects. These measures include:
- Encryption in transit using TLS 1.2 or higher for all MCP communications;
- Encryption at rest using AES-256 across all persistent storage systems;
- Role-based access control (RBAC) with access limited to authorised personnel;
- Multi-factor authentication (MFA) for all administrative access;
- Query content redaction in operational logs;
- Regular vulnerability scanning (at least quarterly) and annual penetration testing by an independent third party; and
- Secure development practices, including code review, change control, and environment segregation.
Moonlit is ISO/IEC 27001:2022 certified (Certificate No. 202506-107, AssuranceLab Pty Ltd, issued 30 June 2025, valid until 30 June 2028). The certification covers the development, operation, and support of the software-as-a-service platform for European legal research. The certificate is published at trust.moonlit.ai; further audit documentation is available as set out in Clause 3.8.
Moonlit's security measures are summarised in Annex II.
3.4 Sub-processors
(a) General authorisation. The Customer provides general written authorisation for Moonlit to engage Sub-processors for the provision of the MCP Service, subject to the conditions in this Clause 3.4.
(b) Current Sub-processors. Moonlit's current Sub-processors are listed in Annex III.
(c) Notification and objection. Moonlit shall inform the Customer of any intended addition or replacement of Sub-processors at least thirty (30) days in advance. The Customer may object to the engagement of a new Sub-processor on reasonable grounds relating to data protection within fourteen (14) days of receiving notice. If the Customer objects, the Parties shall negotiate in good faith to find a commercially reasonable solution. If no solution is found within thirty (30) days, either Party may terminate the Principal Agreement with respect to the affected MCP Service without penalty. Moonlit provides such notification by updating the publicly accessible list of Sub-processors at Sub-processorsand by email to the Customer's designated contact.
(d) Sub-processor agreements. Moonlit shall enter into a written agreement with each Sub-processor that imposes data protection obligations equivalent to those set out in this DPA. Moonlit remains fully liable to the Customer for the performance of each Sub-processor's obligations.
3.5 Assistance with Data Subject Rights
Taking into account the nature of the Processing, Moonlit shall assist the Customer by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Customer's obligation to respond to requests from Data Subjects exercising their rights under Chapter III of the GDPR (including access, rectification, erasure, restriction, portability, and objection).
If Moonlit receives a Data Subject request directly, it shall promptly forward the request to the Customer without responding to it, unless required by law.
3.6 Assistance with Compliance Obligations
Moonlit shall assist the Customer in ensuring compliance with its obligations under Articles 32 to 36 of the GDPR, taking into account the nature of Processing and the information available to Moonlit. This includes assistance with security of Processing, Personal Data Breach notification, data protection impact assessments, and prior consultation with Supervisory Authorities where required.
3.7 Personal Data Breach Notification
Moonlit shall notify the Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Personal Data Processed under this DPA. The notification shall include, to the extent available:
- a description of the nature of the breach, including the categories and approximate number of Data Subjects and records affected;
- the name and contact details of the relevant contact point;
- a description of the likely consequences; and
- a description of the measures taken or proposed to address the breach.
Moonlit shall cooperate with the Customer and take reasonable steps as directed by the Customer to investigate, mitigate, and remediate the breach. Moonlit shall not notify any third party of a Personal Data Breach without the Customer's prior written consent, except where Moonlit is itself under a legal obligation to notify a Supervisory Authority or another party, including in its own capacity as controller of account and telemetry data.
3.8 Demonstrating Compliance and Audits
Moonlit shall make available to the Customer the information necessary to demonstrate compliance with this DPA and with Article 28 of the GDPR.
Moonlit demonstrates compliance through:
- its ISO/IEC 27001:2022 certificate, published at trust.moonlit.ai;
- under an enterprise agreement and a non-disclosure agreement, the most recent ISO audit report and penetration test summary (full penetration test reports are available under NDA on request); and
- written responses to a reasonable audit questionnaire from the Customer, at most once per calendar year, provided within thirty (30) days of receipt.
Where a Supervisory Authority exercises its powers with respect to the Customer's use of the MCP Service, Moonlit shall cooperate with that authority and with the Customer. Assistance beyond the items above may be charged in accordance with Clause 3.10.
3.9 Records of Processing Activities
Moonlit shall maintain a record of processing activities carried out on behalf of the Customer in accordance with Article 30(2) of the GDPR. Moonlit shall make such records available to the Customer or the competent Supervisory Authority upon request.
3.10 Costs of Assistance
To the extent that Moonlit's assistance under Clauses 3.5, 3.6, 3.7, and 3.8 requires effort beyond what is reasonably necessary for the standard provision of the MCP Service, Moonlit may charge the Customer for such assistance at Moonlit's then-current professional services rates, provided that Moonlit informs the Customer of the expected costs in advance.
Clause 4. Data Handling Specifics for the MCP Service
4.1 MCP Query Content
Not stored by Moonlit. Moonlit does not store the content of MCP Tool-call payloads in its own systems. Where operational logging or telemetry could otherwise capture query content, Moonlit applies explicit redaction so that the content is masked.
Hybrid and reranked search queries routed through the GenAI Sub-processor are processed transiently and are not retained, as set out in Annex III.
4.2 MCP Usage Metrics
Moonlit stores aggregated usage counts (number of MCP Tool invocations per tool name; latency distributions) for usage reporting. Individual query text is not retained.
4.3 Document Content Returned to the Customer
Documents retrieved through the MCP Service are not retained by Moonlit beyond the operational cache used to serve responses. The Moonlit Data Layer consists of publicly available legal sources. Documents are returned to the Customer via the MCP Service as-is. Moonlit does not modify the personal data content of legal sources. If residual personal data in the Moonlit Data Layer is identified due to a publisher error, notice can be given to privacy@moonlit.ai; Moonlit will assess the notice within seventy-two (72) hours and anonymise or remove the data where required.
4.4 Data Hosting and Residency
The MCP Server (https://mcp.moonlit.ai/mcp), its database, and its operational logs are hosted in Microsoft Azure, EU regions (currently West Europe, Netherlands). Moonlit does not route MCP Tool calls or their responses outside the EU; the search Sub-processors executing those calls operate in the EU regions listed in Annex III. Authentication data of Authorised Users is processed by Clerk, Inc. as set out in Clause 5.
4.5 GenAI Processing
Hybrid and reranked search queries are routed through the GenAI Sub-processor listed in Annex III for transient processing. The following safeguards apply:
- Queries are sent to the GenAI provider from a single Moonlit account. No Customer identifiers (names, email addresses, account IDs) are included in the data sent to the provider.
- The GenAI provider does not use the queries or their outputs for model training.
- GenAI processing takes place in the EU region listed in Annex III.
The GenAI Sub-processors and their data handling posture are described in Annex III.
Clause 5. International Data Transfers
Query, retrieval, and GenAI processing under the MCP Service takes place within the European Economic Area (EEA), in the EU regions set out in Annex III.
One search Sub-processor, turbopuffer Inc., is headquartered in Canada; the data it processes for Moonlit is stored and processed in AWS eu-central-1 (Frankfurt). The EU Standard Contractual Clauses (Commission Implementing Decision 2021/914, Modules 2 and 3) are incorporated in its data processing addendum as the Article 46 safeguard for any transfer connected with that engagement.
Authentication data of Authorised Users (account identifiers, sign-in credentials, session tokens) is processed by Clerk, Inc. in the United States. This transfer is made under the EU-U.S. Data Privacy Framework, for which the European Commission has issued an adequacy decision pursuant to Article 45 GDPR; Clerk, Inc. is certified under the EU-U.S. Data Privacy Framework, including the UK Extension, and the Swiss-U.S. Data Privacy Framework.
For any other transfer outside the EEA that becomes necessary in the future (for example, due to the engagement of a new Sub-processor), Moonlit shall ensure that adequate safeguards are in place in accordance with Chapter V of the GDPR, including the use of Standard Contractual Clauses where required. Moonlit shall notify the Customer and provide the Customer with the opportunity to object in accordance with Clause 3.4(c).
Clause 6. Deletion or Return of Personal Data
Upon termination or expiry of the Principal Agreement, or upon the Customer's written request, Moonlit shall, at the Customer's choice:
- delete all Personal Data in Moonlit's possession or control that was Processed on behalf of the Customer; or
- return such Personal Data to the Customer in a commonly used, machine-readable format.
Moonlit shall complete deletion or return within thirty (30) days of termination or request, and shall provide written confirmation of deletion upon the Customer's request. Where the Customer has requested a data export under §16.5 of the MCP Terms, deletion follows completion of that export. Security and operational logs are carved out from this timeline: they are retained for security purposes only and deleted in accordance with the retention schedules in Annex II.
Moonlit may retain Personal Data to the extent required by EU or Member State law, provided that Moonlit informs the Customer, continues to protect the data, and Processes it solely for the legally required purpose.
For clarity: because Moonlit does not store MCP query content or document bodies returned to the Customer beyond operational caching, deletion obligations relate to MCP account data and, at the end of the Annex II retention periods, MCP usage logs. The Moonlit Data Layer itself is publicly available data maintained by Moonlit independently of any Customer relationship and is not subject to deletion upon termination.
Clause 7. Liability
Each Party shall be liable for damage caused by its Processing of Personal Data in violation of the GDPR or this DPA, in accordance with Articles 82 and 83 of the GDPR.
Unless otherwise agreed in the Principal Agreement, any limitations of liability in the Principal Agreement shall also apply to this DPA, provided that neither Party's liability for breaches of Data Protection Laws shall be excluded or limited to the extent that such exclusion or limitation is not permitted by applicable law.
The Customer shall indemnify and hold Moonlit harmless from and against any claims, damages, losses, costs, and expenses (including reasonable legal fees) arising out of or relating to: (a) the Customer's breach of this DPA or applicable Data Protection Laws; (b) any Processing carried out in accordance with the Customer's documented instructions; or (c) the Customer's failure to fulfil its obligations as Controller under the GDPR. This indemnification is without prejudice to the liability provisions of the GDPR.
Clause 8. Term and Termination
This DPA takes effect when the Customer accepts the MCP Terms of Service or otherwise begins using the MCP Service, and shall remain in effect for the duration of the Principal Agreement.
The Customer may terminate this DPA (and the Principal Agreement) with immediate effect by written notice if Moonlit materially breaches this DPA and fails to cure the breach within thirty (30) days of receiving written notice, or if a Supervisory Authority orders the Customer to cease using Moonlit's services.
Moonlit may suspend or terminate the MCP Service (and this DPA) with immediate effect by written notice if the Customer materially breaches this DPA and fails to cure the breach within thirty (30) days of receiving written notice, or if Moonlit reasonably determines that it can no longer process Personal Data in compliance with Data Protection Laws due to the Customer's instructions or conduct.
Clauses 3.2 (Confidentiality), 4 (Data Handling Specifics), 6 (Deletion or Return), 7 (Liability), and 10 (Governing Law) shall survive termination.
Clause 9. General Provisions
9.1 Amendments
This DPA may only be amended by written agreement signed by both Parties, except that Moonlit may update Annex III (Sub-processors) in accordance with the notification and objection procedure in Clause 3.4(c).
9.2 Severability
If any provision of this DPA is held to be invalid or unenforceable, the remaining provisions shall remain in full force and effect.
9.3 Entire Agreement
This DPA, together with the Principal Agreement and its Annexes, constitutes the entire agreement between the Parties regarding the Processing of Personal Data in connection with the MCP Service.
Clause 10. Governing Law and Jurisdiction
This DPA shall be governed by and construed in accordance with the laws of the Netherlands. Any dispute arising in connection with this DPA that cannot be resolved amicably shall be submitted to the exclusive jurisdiction of the competent courts in Amsterdam, the Netherlands.
Clause 11. Contact
For questions about this DPA or Moonlit's data protection practices, please contact:
Moonlit Legal Technologies B.V.
Westeinde 14, 1017 ZP Amsterdam, the Netherlands
Email: privacy@moonlit.ai
KvK: 93559291. VAT: NL866449437B01.
Annex I: Details of Processing
This Annex describes the Processing carried out by Moonlit under this DPA, as required by Article 28(3) of the GDPR.
Annex II: Technical and Organisational Security Measures
This Annex describes the security measures Moonlit implements to protect Personal Data Processed under this DPA. These measures are consistent with Moonlit's ISO/IEC 27001:2022 certification and its Information Security Addendum.
Annex III: Sub-processors
This Annex lists Moonlit's current Sub-processors engaged for the provision of the MCP Service. The operative public list is maintained at Sub-processors; Moonlit will notify the Customer of changes in accordance with Clause 3.4(c) of this DPA.
Infrastructure Sub-processors
https://mcp.moonlit.ai/mcp.clerk.moonlit.ai): authentication of Authorised Users, account identifiers, sign-in credentials, session tokens. Certified under the EU-U.S. Data Privacy Framework, including the UK Extension, and the Swiss-U.S. Data Privacy Framework, as set out in Clause 5.Authorised Users sign in with their Moonlit platform account through the OAuth 2.1 authorisation code flow with PKCE. The authorisation server runs at clerk.moonlit.ai and is operated using Clerk as the underlying identity service. Organisations can additionally authenticate pooled and deployed services with MCP keys, presented as Bearer tokens in the Authorization header.
GenAI Sub-processors
Applicable to the hybrid_search and hybrid_search_reranked MCP Tools. The MCP Server invokes Google Vertex AI for the query embedding step used in both, and for the reranking step inside hybrid_search_reranked. No other GenAI sub-processor is invoked by the MCP Service today.
hybrid_search_reranked. Zero-data-retention posture: no retention beyond transient processing, and the data is never used for training. Accessed via an enterprise API with a data processing agreement in place; no Customer identifiers are included in data sent to Vertex AI.Enterprise Customers who require a counter-signed copy of this DPA may email privacy@moonlit.ai.