MCP bit24
EN ES
Back to landing
🔒 Data protection

Privacy Policy

Personal data processing in the MCP-Bit24 service

Last updated: June 24, 2026

This Privacy Policy describes how BIT24, SL ("Bit24") processes personal data within the MCP-Bit24 service (the "Service"). Bit24 is committed to the protection of personal data in accordance with Regulation (EU) 2016/679 (GDPR), the Andorran data protection regulations and other applicable legislation.

1. Data Controller

  • Identity: BIT24, SL.
  • Registered address: Carrer de les Escoles, 21, Bloc D, Local D1, Edifici l'Era del Vermell, AD600 Sant Julià de Lòria, Principality of Andorra.
  • Privacy contact / Data Protection Officer: hola@bit24.es.

2. Two distinct roles

It is important to distinguish two scenarios:

  • Data of Service customers/users (registration, billing, support): Bit24 acts as Data Controller.
  • Data contained in the customer's Bitrix24 CRM, which the Service accesses to provide its functionality: Bit24 acts as Data Processor, and the customer is the Controller. These processing activities are governed by the corresponding Data Processing Agreement.

3. Data we process

3.1. As Controller (Service customers)

  • Identification and contact data: name, email, phone, company.
  • Account data: credentials, linked Bitrix24 portal, configuration.
  • Billing data: managed through the payment provider (Stripe).
  • Usage and support data: technical logs, incidents, communications.

3.2. As Processor (customer's CRM data)

The Service accesses the data that the customer has in their Bitrix24 portal and that is necessary to resolve each request: identification and contact data of the customer's contacts, and commercial management data (deals, activities, tasks). Bit24 processes this data solely following the customer's instructions.

4. Purposes and legal basis

  • Provide the contracted Service — basis: contract performance.
  • Manage billing and collection — basis: contract performance and legal obligation.
  • Handle queries and support — basis: contract performance / legitimate interest.
  • Comply with legal obligations — basis: legal obligation.
  • Send communications about the Service — basis: legitimate interest or consent, as applicable.

5. Use of artificial intelligence

The Service uses third-party artificial intelligence models (such as Anthropic/Claude, OpenAI/ChatGPT and Google/Gemini) to process user requests. When the user requests an operation, the CRM data strictly necessary to fulfil it is transmitted to the corresponding AI model. Bit24 uses enterprise plans from these providers that, contractually, do not use transmitted data to train their models. The Service assists the user and does not make automated decisions with legal effects without human intervention.

6. Recipients and processors

To provide the Service, Bit24 uses providers that may process data on behalf of Bit24 (sub-processors), including:

  • Infrastructure provider: Hetzner Online GmbH (data centre in Germany, EU).
  • AI model providers: Anthropic, OpenAI, Google.
  • Payment provider: Stripe.
  • External connectors activated by the customer (for example, messaging or grant services), where applicable.

Bit24 enters into the corresponding processing agreements with these providers.

7. International transfers

Some providers (AI models) are located in the United States. In those cases, transfers are covered by valid mechanisms under the GDPR, such as the EU-U.S. Data Privacy Framework and/or the European Commission's Standard Contractual Clauses. Additionally, Bit24 is domiciled in Andorra, a country that has an Adequacy Decision from the European Commission, so transfers to Andorra are recognized as safe.

8. Data retention

As Controller, Bit24 retains data for the duration of the relationship and, subsequently, for the applicable legal retention periods (e.g., tax and accounting obligations). As Processor, upon termination of the Service, Bit24 will return or delete CRM data in accordance with the customer's instructions, unless legally required to retain it.

9. Data subject rights

Data subjects may exercise their rights of access, rectification, erasure, objection, restriction of processing and portability by contacting hola@bit24.es. When Bit24 acts as Processor, it will forward any request received to the Controller (the customer). Data subjects also have the right to lodge a complaint with the competent supervisory authority.

10. Security

Bit24 applies technical and organizational measures to protect data, including:

  • Encryption of communications (TLS).
  • OAuth-based authentication.
  • Role-based access control.
  • Data isolation per customer portal.
  • Hosting in ISO 27001 certified data centre in the EU.
  • Backups.

11. Changes to this policy

Bit24 may update this Privacy Policy. Changes will be published at https://mcp.bit24.com indicating the last update date.

12. Contact

For any matter regarding this Policy or data processing, please contact hola@bit24.es.

BIT24, SL · Registered in the Principality of Andorra

A product by bit24.com · mcp@bit24.com

Landing Privacy Policy EULA