Política de privacidad del conector MCP de Clau
Vigente desde el 29 de septiembre de 2026
Esta política explica qué datos trata el conector MCP de Clau (https://mcp.clau.io/mcp) cuando un negocio conecta un asistente de inteligencia artificial, como Claude o ChatGPT, a su cuenta de Clau. Complementa la política de privacidad del usuario final de las aplicaciones de Clau y los Términos Generales de la Solución Clau.io.
1. Quiénes somos
El conector lo presta BE LOYAL, S.A. y/o sus afiliados, que operan bajo la marca CLAU.IO ("Clau", "nosotros"). Contacto: soporte@clau.io.
2. Qué es el conector y quién lo usa
El conector permite que un usuario autorizado de un negocio que usa Clau (el "Negocio") consulte y, si lo permite, modifique los datos de ese Negocio desde un asistente de IA. Lo usan dueños, administradores y empleados del Negocio con acceso al dashboard de Clau y el permiso API Keys. No está dirigido a consumidores ni a menores de edad.
Cada conexión corresponde a un solo Negocio. El usuario inicia sesión con su cuenta del dashboard, revisa el Negocio y elige los permisos en una pantalla de autorización de Clau. Solo entonces el asistente recibe acceso.
3. Datos que trata el conector
3.1 Datos del usuario que conecta
- Correo electrónico, identificador de usuario, negocio y rol del dashboard, usados para iniciar sesión, verificar permisos y registrar quién autorizó la conexión.
- Datos de la conexión: el asistente o cliente conectado, los permisos otorgados, las fechas de creación, último uso, vencimiento y revocación, y la API key asociada.
- Cookies de sesión estrictamente necesarias en la pantalla de inicio de sesión y autorización.
3.2 Datos del Negocio que el asistente puede consultar
Solo con los permisos que el usuario otorgó y dentro del techo de permisos de su rol en el dashboard:
- Datos del negocio: sucursales, ventas y compras (montos, fechas, forma de pago, sucursal), niveles, promociones, regalos, cupones, beneficios, campañas de correo y sus plantillas, segmentos y tareas automáticas.
- Datos de los clientes del Negocio: nombre, apellido, correo electrónico, teléfono, número y tipo de documento de identidad, fecha de nacimiento, género, ciudad, identificadores internos y externos, puntos y su historial, nivel, canjes, regalos y cupones asignados, compras, etiquetas y notas internas.
El conector no entrega datos de tarjetas ni de pagos, saldos de gift cards ni contraseñas, y no permite mover dinero.
3.3 Datos que envía el asistente
Clau recibe únicamente las solicitudes de herramientas que hace el asistente y sus parámetros: por ejemplo, el correo de un cliente a buscar, un rango de fechas o el texto de una nota. Clau no recibe ni guarda el resto de la conversación entre el usuario y el asistente.
4. Para qué usamos los datos
- Autenticar al usuario, verificar sus permisos y ejecutar las consultas y acciones que solicita el asistente en nombre del Negocio.
- Seguridad, prevención de abuso, límites de uso y auditoría de las operaciones que modifican datos.
- Soporte técnico y cumplimiento de obligaciones legales.
No vendemos datos personales, no los usamos con fines publicitarios y no los usamos para entrenar modelos de inteligencia artificial.
5. Roles y autorización del Negocio
El Negocio es el responsable de los datos de sus clientes; Clau los trata como encargado, por cuenta y según las instrucciones del Negocio. Al autorizar la conexión en la pantalla de Clau, el usuario, en nombre del Negocio, autoriza expresamente a Clau a entregar al asistente elegido los datos que este solicite dentro de los permisos otorgados. Esa autorización se registra con el usuario, la fecha y los permisos. El Negocio es responsable de contar con la base legal y de informar a sus clientes cuando corresponda.
6. Asistentes de IA de terceros
El asistente, por ejemplo Claude de Anthropic o ChatGPT de OpenAI, es un servicio de un tercero que el Negocio elige. Los datos que el asistente recibe de Clau se rigen por los términos y la política de privacidad de ese proveedor y por la configuración de la cuenta del usuario en ese servicio. Clau no controla cómo el proveedor del asistente almacena o usa las conversaciones.
7. Dónde se guardan los datos y cuánto tiempo
- Los datos se almacenan en servidores de Amazon Web Services en Estados Unidos.
- Cada operación que modifica datos queda en la auditoría del Negocio: fecha, herramienta, API key, dirección IP, un resumen de lo enviado con claves y datos de tarjeta ocultos, y el resultado.
- Los registros de conexiones y auditoría se conservan mientras el Negocio mantenga su cuenta en Clau, o el tiempo mayor que exija la ley.
- Las solicitudes de autorización pendientes y los códigos de un solo uso se borran solos en minutos.
8. Seguridad
- Todo el tráfico viaja cifrado con HTTPS.
- La autorización usa OAuth 2.1 con PKCE. Los tokens de acceso duran 1 hora; el token de renovación dura hasta 90 días y cambia en cada uso.
- Cada conexión tiene su propia API key, con permisos limitados y límites de uso por minuto.
- Revocar la key o la conexión corta el acceso en la siguiente solicitud del asistente; si se usa una API key fija por header, en menos de un minuto.
Ninguna medida es infalible, pero aplicamos medidas técnicas y organizativas razonables para proteger los datos.
9. Tus opciones y derechos
- Revocar el acceso: en el dashboard, en Configuración → API Keys, o desconectando el conector desde el asistente.
- Clientes del Negocio: para acceder, corregir o eliminar sus datos, deben dirigirse al Negocio, que es el responsable; Clau lo asistirá.
- Usuarios del dashboard: pueden escribir a soporte@clau.io.
10. Cambios
Podemos actualizar esta política. Publicaremos la versión vigente en esta página con su fecha. Si un cambio es sustancial, lo avisaremos por medios razonables antes de que entre en vigor.
11. Contacto
BE LOYAL, S.A. (CLAU.IO), República de Panamá. soporte@clau.io · clau.io
Clau MCP Connector Privacy Policy
Effective September 29, 2026
This policy explains what data the Clau MCP connector (https://mcp.clau.io/mcp) processes when a business connects an artificial intelligence assistant, such as Claude or ChatGPT, to its Clau account. It supplements the end-user privacy policy of Clau apps and the Clau.io Solution General Terms. If the Spanish and English versions differ, the Spanish version prevails.
1. Who we are
The connector is provided by BE LOYAL, S.A. and/or its affiliates, doing business as CLAU.IO ("Clau", "we"). Contact: soporte@clau.io.
2. What the connector is and who uses it
The connector lets an authorized user of a business that uses Clau (the "Business") query and, if permitted, change that Business's data from an AI assistant. It is used by owners, managers and employees of the Business who have access to the Clau dashboard and the API Keys permission. It is not intended for consumers or minors.
Each connection belongs to a single Business. The user signs in with their dashboard account, reviews the Business and chooses the permissions on a Clau authorization screen. Only then does the assistant get access.
3. Data the connector processes
3.1 Data about the connecting user
- Email address, user ID, Business and dashboard role, used to sign in, check permissions and record who authorized the connection.
- Connection data: the connected assistant or client, the permissions granted, creation, last-use, expiry and revocation dates, and the associated API key.
- Strictly necessary session cookies on the sign-in and authorization screen.
3.2 Business data the assistant can access
Only with the permissions the user granted, and never beyond the permissions of their dashboard role:
- Business data: stores, sales and purchases (amounts, dates, payment method, store), tiers, promotions, rewards, coupons, benefits, email campaigns and templates, segments and automated tasks.
- Data about the Business's customers: first and last name, email address, phone number, identity document number and type, date of birth, gender, city, internal and external identifiers, points and points history, tier, redemptions, assigned rewards and coupons, purchases, tags and internal notes.
The connector does not provide card or payment data, gift card balances or passwords, and it cannot move money.
3.3 Data sent by the assistant
Clau only receives the tool requests the assistant makes and their parameters: for example, a customer email to look up, a date range or the text of a note. Clau does not receive or store the rest of the conversation between the user and the assistant.
4. How we use the data
- To authenticate the user, check their permissions and carry out the queries and actions the assistant requests on behalf of the Business.
- For security, abuse prevention, usage limits and auditing of operations that change data.
- For technical support and to meet legal obligations.
We do not sell personal data, we do not use it for advertising and we do not use it to train artificial intelligence models.
5. Roles and the Business's authorization
The Business is the controller of its customers' data; Clau processes that data as a processor, on behalf of and following the instructions of the Business. By authorizing the connection on the Clau screen, the user, on behalf of the Business, expressly authorizes Clau to provide the chosen assistant with the data it requests within the granted permissions. That authorization is recorded with the user, the date and the permissions. The Business is responsible for having a legal basis and for informing its customers where required.
6. Third-party AI assistants
The assistant, for example Anthropic's Claude or OpenAI's ChatGPT, is a third-party service chosen by the Business. Data the assistant receives from Clau is governed by that provider's terms and privacy policy and by the user's account settings in that service. Clau does not control how the assistant provider stores or uses conversations.
7. Where data is stored and for how long
- Data is stored on Amazon Web Services servers in the United States.
- Every operation that changes data is recorded in the Business's audit log: date, tool, API key, IP address, a summary of the input with secrets and card data masked, and the result.
- Connection and audit records are kept while the Business has an account with Clau, or longer if the law requires.
- Pending authorization requests and one-time codes are deleted automatically within minutes.
8. Security
- All traffic is encrypted with HTTPS.
- Authorization uses OAuth 2.1 with PKCE. Access tokens last 1 hour; the refresh token lasts up to 90 days and changes on every use.
- Each connection has its own API key, with limited permissions and per-minute usage limits.
- Revoking the key or the connection cuts off access on the assistant's next request; when a fixed API key is sent in a header, within one minute.
No measure is infallible, but we apply reasonable technical and organizational measures to protect data.
9. Your choices and rights
- Revoke access: in the dashboard under Settings → API Keys, or by disconnecting the connector in the assistant.
- The Business's customers: to access, correct or delete their data, they should contact the Business, which is the controller; Clau will assist it.
- Dashboard users: can write to soporte@clau.io.
10. Changes
We may update this policy. We will publish the current version on this page with its date. If a change is material, we will give reasonable notice before it takes effect.
11. Contact
BE LOYAL, S.A. (CLAU.IO), Republic of Panama. soporte@clau.io · clau.io