Skip to main content

KontoCSV Claude Connector Privacy Notice

Version 1.0 · effective 6 October 2026

This notice applies to the KontoCSV remote MCP connector used with Claude. It supplements the full KontoCSV Privacy Policy. The German privacy policy is available as Datenschutzerklärung.

1. Controller and scope

Controller: Tom Abraham, Riemekestraße 118, 33102 Paderborn, Germany. Contact: support@kontocsv.de.

This notice covers data processed by KontoCSV when a user connects the KontoCSV connector to Claude and invokes KontoCSV tools. Anthropic separately processes the user's Claude account, conversation, and host-side data under Anthropic's own terms and privacy policy.

2. Claude data boundary

The public KontoCSV Claude connector does not query or extract Claude memory, chat history, conversation summaries, or files uploaded to Claude.

When a document is needed, the connector creates a short-lived KontoCSV browser-upload link. The user chooses the file on the KontoCSV page and uploads it directly from the browser to KontoCSV private storage. The connector then works only with the resulting KontoCSV source reference.

3. Categories of data processed

  • Account and authorization data: KontoCSV account identifier, account email where associated with the KontoCSV account, OAuth authorization metadata, and security/session information needed for the connection.
  • Directly uploaded financial documents: bank, card, or payment statement PDFs and transaction CSVs selected by the user on the KontoCSV browser-upload page, including the financial data contained in those files.
  • Conversion data: requested accounting format, inspection results, conversion status, generated export, and existing KontoCSV credit balance or reservations required for a requested conversion.
  • Technical data: timestamps, request identifiers, network/device metadata required for security and operation, and limited technical error metadata.

4. Purposes

  • Authenticate and authorize the connected KontoCSV account.
  • Create and validate short-lived direct browser uploads.
  • Inspect financial documents and identify supported exports.
  • Prepare and, after explicit user confirmation, execute an accounting conversion using credits already available in the KontoCSV account.
  • Return job status and a time-limited export download link.
  • Protect service security, diagnose failures, and provide support.

The Claude connector does not sell KontoCSV credits, initiate checkout, or collect payment-card details. KontoCSV does not sell personal data or use connector data for advertising.

5. Recipients and service providers

Data is disclosed only as needed for the requested connector function. Categories of recipients may include:

  • Anthropic / Claude: receives the authorized MCP tool results needed to present the requested workflow.
  • Supabase: authentication, database/job data, and private object storage in KontoCSV's configured EU region.
  • Vercel: web, OAuth, browser-upload, and MCP interface hosting.
  • Render: KontoCSV backend and document-processing jobs in Frankfurt.
  • Google Cloud Storage and Vertex AI / Gemini:temporary document processing and AI-assisted extraction in the configured Frankfurt region.
  • Technical security providers: limited technical error metadata may be processed by services such as Sentry; uploaded financial document contents are not sent to error-monitoring services.

Additional provider and transfer information is maintained in the full Privacy Policy.

6. Retention

DataRetention
Uploaded files, document chunks, intermediate formats, conversion files, and conversion jobsAutomatically deleted no later than 7 days after upload or creation; processing copies may be removed earlier.
Server and security logs30 days
KontoCSV account/session dataWhile needed for the account or session, subject to mandatory legal retention.

7. User controls

  • The connector can be disconnected in Claude to stop future calls.
  • A browser-upload link expires automatically and can be abandoned without starting a conversion.
  • KontoCSV account holders can export their account data and delete their account in the KontoCSV dashboard.
  • Users may request access, rectification, erasure, restriction, portability, or objection via support@kontocsv.de.
  • Inspection and preparation do not spend credits. A conversion that uses existing credits requires explicit user confirmation.

8. Security and legal basis

Data is transmitted over encrypted connections and processed only for the purposes described above. Account and conversion processing principally relies on Art. 6(1)(b) GDPR. Security and service-stability processing may rely on Art. 6(1)(f) GDPR. Additional safeguards are described in the full KontoCSV Privacy Policy.