Enerdatics Leap is a Model Context Protocol (MCP) server that exposes curated, read-only tools over Enerdatics' renewable-energy datasets — M&A deals, projects, financings, PPAs, company profiles, league tables and related market data. A separate 3-question trial chat widget lets prospective users try Leap from a web page.
In plain language: when you use the MCP server, your own AI assistant (such as Claude) calls our tools and we receive only the structured query parameters — not your conversation. When you use the trial widget, we collect your work email to grant access and we log the questions you submit, and your question text is sent to our LLM sub-processor (Anthropic) to generate an answer. This policy explains what we collect on each surface, how it is used and stored, who it is shared with, how long it is kept, and the rights you have. Read it alongside our Terms & Conditions.
Data we collect
We collect the minimum needed to authenticate users, operate the service, enforce tenant isolation, generate trial answers and maintain an audit trail. The exact items depend on whether you use the MCP server, the trial widget, or both.
Trial chat widget
- Work email — used to grant trial access and identify your trial.
- OTP / verification code — a short-lived code emailed to confirm you control that address.
- IP address & registration metadata — captured for security, abuse-prevention and rate limiting.
- The questions / prompts you submit — these are logged by us and sent to our LLM sub-processor to generate answers.
- Usage analytics — how the widget is used (e.g. number of questions, errors).
- Cookies / local storage — Cloudflare Turnstile (bot-protection) and a
localStoragetrial token that tracks your 3-question allowance.
MCP server — account & access data
- Customer record — organisation identifier, plan tier, entitlements, and an
ai_desk_enabledflag. - Credential material — for issued access tokens we store only a SHA-256 hash of the token, never the token itself. OAuth identity is handled by our identity provider (see Sub-processors).
MCP server — tool-call (audit) data
For each tools/call we record:
- The authenticated customer and credential identifiers.
- The tool name and structured parameters, with known free-text fields stripped.
- Response size, duration, and success/error status.
tools/list and initialize calls are not audited.
Feedback data
If a user invokes the submit_feedback tool, the free-text content they provide is stored and may be forwarded to an internal Enerdatics notification channel.
Operational data
- Rate-limit counters keyed to the server-derived credential.
- Standard application logs, with sensitive keys redacted (authorization, cookie, any
*_token, password,api_key,client_secret).
What we do not collect: On the MCP server we do not receive your conversation — your natural-language prompt is processed by your own AI assistant, and only the resulting structured tool parameters reach Leap. We do not request or store payment-card data. Note that the trial widget is different: there, the questions you type are logged and sent to our LLM sub-processor to produce an answer (see Sub-processors and Retention).
How we use data & lawful basis
- Verify identity and grant trial access; authenticate and authorise each request, deriving customer identity server-side (never from request input) to keep tenants isolated.
- Operate and protect the service — generate trial answers, rate limiting, error handling, and abuse prevention.
- Maintain accountability through the audit log.
- Improve the service using submitted feedback and aggregate usage patterns.
The table below maps each data item to its purpose and, under the EU/UK GDPR, our lawful basis.
| Data item | Purpose | Lawful basis (GDPR) |
|---|---|---|
| Work email | Verify identity & grant trial | Consent |
| OTP / verification code | Confirm email ownership | Consent; legitimate interest (security) |
| IP & registration metadata | Security, abuse prevention, rate limiting | Legitimate interest |
| Questions / prompts (logged) | Generate answers; operate, secure & improve the service | Legitimate interest (and consent where applicable) |
| Usage analytics | Measure & improve the service | Legitimate interest / consent |
| Cookies / local storage | Bot-protection (Turnstile) & trial session | Strictly necessary; analytics on consent |
| MCP credential hash & audit log | Authenticate API calls; accountability | Contract / legitimate interest |
| Feedback content | Improve the service | Consent / legitimate interest |
We do not sell personal data, and we do not use your data to train our own machine-learning models. Our LLM sub-processor (Anthropic) acts as a processor and, under its commercial terms, does not train its models on inputs or outputs.
Storage & security
Tool logic runs as a Cloudflare Worker. Control-plane data — customers, credentials, audit rows, rate-limit counters, and feedback — is stored in Cloudflare D1. All database access uses parameterised queries.
The underlying datasets (Quickbase; the distributed-generation dataset in Postgres via Cloudflare Hyperdrive) are systems of record queried read-only. No tool mutates source data.
All traffic is encrypted in transit over HTTPS via the Cloudflare edge. Production secrets are held in the Cloudflare wrangler secret store and are never committed to source control.
Hosting / data region: TODO: e.g. Cloudflare global edge; D1 primary region
See the accompanying Security overview for authentication, multi-tenancy, and logging details.
Third-party sub-processors
We share data only with the service providers required to run Leap. Each provider's privacy policy is linked below.
| Sub-processor | Purpose | Data involved |
|---|---|---|
| Anthropic, PBC | LLM inference — generates trial-widget answers (policy) | Question text you submit, plus anything included in the prompt |
| Cloudflare, Inc. | Hosting (Workers), control-plane DB (D1), CDN and Turnstile bot-protection (policy) | All control-plane & audit data; IP; Turnstile token |
| WorkOS, Inc. | Authentication / OAuth 2.x identity for the MCP server (policy) | Authentication identifiers |
| Resend (Plus Five Five, Inc.) | Transactional email / OTP delivery (policy) | Work email, OTP code |
| HubSpot, Inc. if sales path in scope | CRM for trial follow-up (policy) | Work email & contact details |
| Quickbase, Inc. | Renewable-energy system-of-record (read-only queries) (policy) | Query parameters only |
| Google LLC | Internal feedback notifications via Chat webhook, only if enabled (policy) | submit_feedback content |
| Upstash / Render as applicable | Rate-limiting / supporting infrastructure | Operational metadata |
About the LLM provider. For the trial widget, the text of your question is sent to Anthropic to generate an answer. Under its Commercial Terms, Anthropic acts as a processor and does not train its models on inputs or outputs. Anthropic's standard API retention is approximately 7 days unless Zero-Data-Retention applies confirm figure for the model Leap uses.
Clarify: whether raw connector/deal data — vs. only the natural-language question text — is passed to the model.
When you connect your own AI assistant to the MCP server (e.g. Anthropic's Claude), that assistant is chosen and controlled by you or your organisation, and that provider's own privacy terms govern how your prompts are handled on that surface.
TODO: confirm this list matches the live deployment and DPA, and add any others (e.g. error/monitoring providers).
International data transfers
Your data may be processed outside India, including in the United States (for example via Anthropic and our cloud infrastructure). We rely on specific legal mechanisms rather than a generic "we transfer internationally" statement:
- EU/UK → India. India does not currently hold an EU adequacy decision, so transfers of EU/UK personal data to India rely on the EU Standard Contractual Clauses (SCCs) together with a Transfer Impact Assessment.
- EU/UK → US (prompt flow to Anthropic). This transfer relies on its own mechanism — Anthropic's DPA/SCCs or the EU-US Data Privacy Framework as applicable.
You can request a copy of the relevant safeguards by contacting privacy@enerdatics.com.
Data retention
We keep each type of data only as long as needed for the purpose it was collected, then delete or anonymise it.
- OTP / verification code — ephemeral; expires within minutes of being issued.
- Work email (trial) — retained for TODO: e.g. 24 months, then deleted or anonymised.
- Question logs (trial widget) — retained for TODO: e.g. 12 months, then deleted or aggregated.
- Question text held by Anthropic — approximately 7 days under standard API retention unless Zero-Data-Retention applies confirm.
- MCP credentials — retained until revoked or the customer relationship ends.
- Audit logs — retained for TODO: e.g. 12 months for security and accountability, then deleted or aggregated.
- Feedback — retained for TODO: retention period, then deleted.
On account termination, control-plane data is deleted or anonymised within TODO: e.g. 30 days, subject to legal retention obligations.
Your rights & choices
Depending on where you are, you have rights over your personal data under the EU/UK GDPR and/or India's Digital Personal Data Protection Act (DPDP). To exercise any of them, email privacy@enerdatics.com. Withdrawing consent is as easy as giving it.
Under the GDPR
- Access, rectification, erasure, restriction, portability, and objection.
- Withdraw consent at any time (without affecting prior processing).
- Lodge a complaint with your supervisory authority.
We aim to respond within one month, extendable for complex requests as the GDPR permits.
Under the DPDP Act
- Access a summary of your personal data and processing (s.11).
- Correction and erasure (s.12).
- Grievance redressal (s.13).
- Nominate another person to exercise your rights (s.14).
- Withdraw consent (s.6).
- Complain to the Data Protection Board of India.
Grievances are addressed within 90 days, as DPDP requires.
Customer administrators can also request credential revocation or account deletion at any time.
Automated & AI processing
Answers in the trial widget are generated by a large language model (Anthropic). Model output can be inaccurate, incomplete or out of date and is provided "as is" — please verify any answer before relying on it for a decision.
We do not use this AI processing to make solely-automated decisions that produce legal or similarly significant effects about you.
Security, breaches & age
We protect data with encryption in transit (HTTPS/TLS), parameterised database queries, redacted application logs, secrets held in a managed secret store, and least-privilege access. No security measure is perfect, but we work to keep your data safe.
If a personal-data breach occurs, we will notify the relevant authorities and affected individuals where and as required by law (including the GDPR's notification timelines and the DPDP Act's reporting to the Data Protection Board and affected persons).
Age. The trial is a business-to-business service offered to work-email holders. It is not directed to, or intended for, anyone under 18, and we do not knowingly collect children's personal data.
Changes to this policy
We may update this policy as the service evolves. Material changes will be reflected in the "Last updated" date at the top of this page, summarised in the "What changed" note, and communicated to customers where appropriate.
Contact
For any question or request about this policy or your data, use the details below.
Under India's DPDP Act, grievances are addressed within 90 days. To exercise your data rights or withdraw consent, email the Grievance Officer above; withdrawing consent is as easy as giving it. See also our Terms & Conditions.
Provider: Enerdatics Services Private Limited., 8th floor, Tower 3B, Thanisandra Main Rd, RK Hegde Nagar, Bengaluru, Karnataka 560064, India. Published at https://www.enerdatics.com/privacy-policy