LEGAL

Sub-processors

The current sub-processors Moonlit engages to deliver the MCP Service. Updated when sub-processors change, with notice to customers under the DPA Clause 3.4(c).

Infrastructure sub-processors

Sub-processorServiceLocationPurpose
Microsoft AzureCloud infrastructure and managed services (Azure API Management, Azure-hosted compute and storage, ElasticSearch hosting, hosting of the MCP Server at https://mcp.moonlit.ai/and Moonlit's own OAuth 2.1 authorisation server).EU regions onlyMCP Server infrastructure: compute, storage, APIM gateway, OAuth authorisation server, operational logs, telemetry.

Authentication is performed by Moonlit's own OAuth 2.1 authorisation server, hosted on Microsoft Azure in the EU. No third-party identity provider is engaged for MCP authentication. Authorised User authentication is bound to an Azure API Management subscription key issued by Moonlit and exchanged for a Bearer token through the OAuth handshake.

Microsoft Azure includes Azure-hosted managed services. Azure OpenAI Service, which has distinct data-handling terms, is listed separately under GenAI sub-processors.

GenAI sub-processors

Applicable to the hybrid_search_reranked MCP Tool. The MCP Server invokes Google Vertex AI for the query embedding step used in hybrid search and the reranking step inside that tool. No other GenAI sub-processor is invoked by the MCP Service today.

ProviderRegionData retentionTraining use
Google Vertex AIeurope-west4, Netherlands (EU)Zero-data-retention posture. No retention beyond transient processing.Not used for training.

The Vertex AI sub-processor is accessed via an enterprise API with a Data Processing Agreement in place. No customer identifiers are included in data sent to Vertex AI.

Anthropic as MCP client

Inside Claude or any other MCP-compatible client, Anthropic processes your prompts and Moonlit's tool responses under its own privacy policy. Anthropic is not a Moonlit sub-processor in the GDPR Article 28 sense; it is the client your tool calls originate from.

Changes

Moonlit notifies subscribers of changes to this list with at least thirty (30) days' advance notice via the email address on the account, in line with DPA Clause 3.4(c). Subscribers may object to a new sub-processor as set out in that clause.

Email privacy@moonlit.ai with sub-processor questions.