LegalMCP Connector

MCP Connector Terms

Additional terms that apply specifically when you connect a third-party AI assistant to your Compass data through the GrowByData MCP Connector.

Effective 29 July 2026 Last updated 29 July 2026

What this document does — and doesn't — cover

This document supplements, and doesn't replace, the Master Service Agreement (MSA) and the terms established in your Statement of Work (SOW). It covers only what's specific to connecting the MCP Connector.

It does not establish terms for account eligibility, fees and payment, data ownership and export, intellectual property, or general liability and indemnification — those are governed by the MSA and your SOW. Where anything here conflicts with the MSA or your SOW, the MSA and SOW control.

1Purpose and scope

These terms apply when you authorize a third-party AI assistant to access your Compass data through the GrowByData Model Context Protocol server (the "MCP Connector"). By authorizing that connection, you agree to the terms below in addition to the Master Service Agreement (MSA) and the terms established in your Statement of Work (SOW).

For a full description of what data the MCP Connector requests and how it's handled, see the Privacy section of the MCP documentation and the GrowByData Privacy Policy.

2Definitions

Account
A tenant workspace in Compass containing the data, reports, and users provisioned for a customer.
MCP Connector
The GrowByData Model Context Protocol server that lets a third-party AI assistant query your Compass data on your behalf, after you authorize it.
Output
Reports, charts, metrics, exports, and AI-generated summaries or answers produced through the MCP Connector.

3Authorizing the connector

Before any authorization is issued, we show you a consent screen naming the application, the destination it will be redirected to, and what the resulting token permits. Authorization happens only when you accept it.

We record each consent decision — what you were shown, when, and from what IP address — as proof of your authorization, and retain that record while the grant is live and for a reasonable period afterward for audit purposes.

4Scope of access

  • Access granted to an assistant is currently read-only and limited to the Accounts your own login is authorized for. Cross-Account queries aren't supported. If we introduce tools capable of modifying data, that access will require its own explicit scope and consent screen — it will not be granted automatically under an existing authorization.
  • Tokens are short-lived; refresh tokens rotate on use and expire if unused.
  • You will not attempt to bypass authentication, tenancy isolation, or rate limiting, or use the MCP Connector to systematically extract data beyond documented rate limits, except under a security testing engagement we've authorized in writing.

5AI output and accuracy

Parts of the Service generate summaries, narratives, and answers using large language models over your data, retrieved through the MCP Connector. These are probabilistic systems.

AI Output may be incomplete, out of date, or wrong. It's provided for informational purposes as decision support, not as professional, legal, financial, or compliance advice. Verify against the underlying report data before relying on it for a material decision.

Search results, marketplace listings, and AI-assistant answers we measure are collected from third-party sources that change constantly and may themselves be inaccurate, personalized, or geographically variable. We aim for accurate and representative measurement but don't warrant that any metric is complete, error-free, or reproducible.

We do not use your prompts, tool inputs, or Output to train our own or any third party's foundation models.

6Your responsibilities

  • You're responsible for the assistant you connect and for what it does with your data once delivered. The assistant's own terms and privacy policy govern its handling of that data — it's a third-party service, not something GrowByData controls.
  • Only authorize an application you started the sign-in from yourself and trust. Don't paste an authorization URL supplied by someone else.
  • You're responsible for keeping any tokens issued to your AI assistant secure, and for telling us promptly at clientsuccess@growbydata.com if you suspect a leaked token or unauthorized access.

7Revoking access

You can revoke a connection at any time from your Compass account settings or by removing the connector in the assistant. Revocation invalidates the refresh token immediately.

8Third-party AI assistants

The MCP Connector interoperates with third-party AI assistants that we don't control. Their availability, terms, and behavior may change without notice, which can affect the Output you receive. We're not responsible for the third-party assistant itself, and your use of it is governed by its own terms.

9Changes to these terms

We may update these terms. The "Last updated" date at the top reflects the current version. For material changes we'll give notice — in the application, by email, or by asking you to re-consent the next time you authorize a connection — before they take effect. Continuing to use the MCP Connector after the effective date means you accept the updated terms; if you don't, revoke the connection and contact us.

10Governing law and disputes

Governing law, jurisdiction, and dispute resolution for the MCP Connector are as set out in the Master Service Agreement (MSA) and the terms established in your Statement of Work (SOW). This document doesn't independently establish governing law or dispute-resolution terms.

11Contact

Postal address — GrowByData, 4 Militia Drive, Suite 27, Lexington, MA 02421, USA

i For anything not covered here — accounts, fees, data ownership and export, intellectual property, general liability — refer to the Master Service Agreement (MSA) and the terms established in your Statement of Work (SOW), or contact Client Success.