Skip to content

Data and privacy

Personal data is never reachable through the MCP server or the API. This covers people, names, contact data, IPI name numbers and member numbers.

Access is enforced by a dedicated role, not by filtering in the application. Every token is restricted to api_operator, a role whose permissions cover only the society catalogue and the reference vocabularies it needs. The role has no permission on any table that holds personal data. A query for a person fails at the database.

Two more layers sit on top:

  • The API maps every response through fixed field lists. A field that is not named in the response schema is never returned.
  • Neither service logs request or response bodies.

Data is hosted in the EU.