Care MCP
Who it's forMCPAPIPricing
Sign in

Explore

Who it's forMCPAPIPricing

Service

PersonalProfessionalsOrganisations

Support

FAQContactLearn

Data processing agreement

In force since 2026-09-27.

This data processing agreement is between the organisation that holds an organisation account on Care MCP (the "controller") and Portfoliobox Stockholm AB, org. no. 556894-4382, VAT no. SE556894438201, Rånövägen 30, 168 39 Bromma, Sweden, caremcp@portfoliobox.net (the "processor"). It is part of the organisation terms and takes effect when they do; no signature is needed. An organisation that wants a signed copy writes to caremcp@portfoliobox.net and gets this text, signed.

Words used here have their meaning in the General Data Protection Regulation (EU) 2016/679 (the "GDPR"). Where this agreement and the organisation terms differ on personal data, this agreement applies.

1. What is processed

The processor processes personal data about the controller's clients for the controller, as described in Annex 1, only to provide the service under the organisation terms.

2. Instructions

The processor processes the personal data only on the controller's documented instructions. The organisation terms, this agreement and the controller's calls to the API are the instructions. The processor tells the controller at once if it believes an instruction breaks the GDPR or other data protection law, and it may then decline to follow it. If law of the EU or a member state requires the processor to process the data otherwise, it tells the controller first, unless that law forbids it.

The controller is responsible for having a legal basis for the processing, including the clients' explicit consent to the processing of health data, and for the lawfulness of its instructions.

3. Confidentiality

The processor ensures that everyone it authorises to process the personal data, its staff and the professionals, is bound by confidentiality by contract or by law, and processes the data only as this agreement allows.

4. Security

The processor takes the technical and organisational measures in Annex 2, which give a level of security appropriate to the risk under article 32 of the GDPR. It may improve them, but it does not lower the overall level of protection.

5. Sub-processors

The controller gives the processor general authorisation to use sub-processors. The sub-processors in use are listed in Annex 3 and on our sub-processors page. The processor tells the controller by email at least 30 days before it adds or replaces a sub-processor. The controller may object on reasonable grounds related to data protection within that time; if the parties cannot resolve the objection, the controller may end the organisation terms before the change takes effect and unused credit is refunded.

The processor binds each sub-processor by written contract to data protection obligations that are no less protective than these, and remains responsible to the controller for the sub-processor's performance.

The professionals who write the documents are individuals the processor contracts or employs. Each is bound by a written agreement with confidentiality and data protection obligations matching these, reads a brief without the client's identity, and may use it only to write the document ordered.

6. Transfers outside the EU

The processor stores the personal data in the European Union. It transfers personal data to a country outside the European Economic Area only under the safeguards in chapter V of the GDPR, such as an adequacy decision or the European Commission's Standard Contractual Clauses.

7. Assistance

Taking into account the nature of the processing, the processor helps the controller by appropriate technical and organisational measures to answer requests from clients exercising their rights. The API lets the controller read, correct and remove a client and the client's orders itself. The processor passes on at once any request it receives directly from the controller's client and does not answer it unless the controller asks it to.

The processor also helps the controller, with the information available to it, to meet its obligations on security, on notifying a personal data breach, on data protection impact assessments and on prior consultation with a supervisory authority. Help beyond what this agreement describes may be charged at reasonable cost.

8. Personal data breaches

The processor tells the controller of a personal data breach affecting the controller's data without undue delay and no later than 48 hours after becoming aware of it. The notice describes, as far as then known, the nature of the breach, the categories and approximate number of clients and records concerned, the likely consequences, the measures taken or proposed, and a contact. The processor adds what it learns later, and takes reasonable steps to contain the breach and limit its effects.

9. Deletion and return

When the controller removes a client through the API, the processor erases that client's briefs, drafts and documents and the data identifying the client within 30 days, keeping only what Annex 1 says is kept.

When the organisation terms end, the processor erases the personal data it processes for the controller within 30 days. Before that, the controller may export its clients' orders through the API. The processor keeps only what the law requires it to keep, such as bookkeeping records, and processes that only for that purpose.

10. Audits

The processor makes available to the controller the information needed to show that it meets article 28 of the GDPR and this agreement, and answers the controller's reasonable written questions. If that is not enough, the controller may, once a year and with 30 days' written notice, have an audit carried out by an independent auditor bound by confidentiality, during business hours and without disturbing the service or other customers' data. The controller bears the cost of an audit. An audit required by a supervisory authority is allowed at any time.

11. Liability

Each party's liability under this agreement is subject to the limits in the organisation terms, as far as article 82 of the GDPR allows. Each party is responsible to the other for fines and damages that arise from its own breach of the GDPR or of this agreement.

12. Term and law

This agreement lasts as long as the processor processes personal data for the controller. The law and the courts named in the organisation terms apply.

Annex 1: The processing

Subject matter and duration. The service under the organisation terms, for as long as they last, and the deletion afterwards.

Nature and purpose. Receiving the controller's clients and orders by API; checking each order against the service's rules on age, country and the health declaration; showing the brief, without the client's identity, to one approved professional; storing the document the professional writes and making it available as the service provides; billing.

Data subjects. The controller's clients: adults who have asked the controller for a written plan, evaluation or review.

Personal data. The controller's reference for the client, birth date, country and region, language; each order's brief: the period, goals, training and diet history, logs, body measurements and fitness status as the controller sends them; the document written.

Special categories. Health data in the brief: the health declaration, including pregnancy and eating disorders, and diagnoses, medications, conditions and lab values when the controller sends them.

Recipients. The professional who takes the order; the sub-processors in Annex 3.

Kept after deletion. Order records without the client's reference, brief or document, and the controller's own payment records, for seven years as Swedish bookkeeping law requires.

Annex 2: Technical and organisational measures

  1. Data is stored in the European Union, at our host in Amsterdam.
  2. Every connection to the service is encrypted with TLS.
  3. Briefs, drafts, screenings and documents are encrypted in the database with AES-256-GCM, under a key kept outside the database.
  4. A professional sees a brief with the client's age and language only, never the client's reference, name, email or account, and only after taking the order.
  5. The tools our staff operate the service with do not show briefs or documents.
  6. Passwords are stored as hashes; API keys are stored as hashes and can be revoked at once; sessions are held in cookies the browser cannot read from scripts and expire after 30 days.
  7. Webhooks to the controller are signed, so the controller can verify they come from us.
  8. Access to production systems is limited to named people who need it, with their own credentials.
  9. Every order passes the same rules in code before a professional sees it, and every document passes the same checks on its template and wording before it is delivered.
  10. Removing a client erases their briefs, drafts and documents; bookkeeping records are kept without them.
  11. Professionals are approved by us before they may take an order and are bound by confidentiality by contract.

Annex 3: Sub-processors

Sub-processorWhat it doesData it handlesWhere
Fly.io, Inc.Hosting of the service and its databaseEverything the service stores, briefs and documents sealedAmsterdam, the Netherlands. A US company: Standard Contractual Clauses
Mollie B.V.PaymentsThe amount, the payer's country and what the card or bank provides. Never a brief or a documentThe Netherlands
Plus Five Five, Inc. (Resend)Sending emailThe recipient's email and the message: receipts, notices that a document is ready, messages to us. Never a brief or a documentUnited States: Standard Contractual Clauses
Apple Inc. and Google LLCSign in with Apple and Google, each as its own controllerA stable account identifier and, when shared, an emailTheir own terms and safeguards

In addition, the professionals under section 5, individuals in the countries where they live, each bound by a written agreement with us.

Care MCP

Care MCP by Portfoliobox

Personal training and nutrition plans from certified professionals, ordered by your AI agent over MCP or our API.

For AI

  • llms.txt
  • sitemap.xml

Service

  • Personal
  • Professionals
  • Organisations
  • Pricing

Documentation

  • MCP
  • API
  • Learn
  • FAQ

Company

  • About
  • Contact
  • Security
Terms of servicePrivacy policyHealth data noticeOrganisation termsData processing agreementProfessional agreementSub-processors

Portfoliobox Stockholm AB, Rånövägen 30, 168 39 Bromma, Sweden. Org. no. 556894-4382, VAT no. SE556894438201. caremcp@portfoliobox.net.