MCP Integration Data Disclosure
Effective 1 August 2026 · Version 1.0.0
This page explains, in plain language, exactly what the AccMCP integration does when you connect it to an AI assistant such as ChatGPT or Claude: what it can read, why, who else sees it, how long anything is kept, and how to switch it off.
It supplements our Privacy Policy and Terms of Service. Where this page and the Privacy Policy overlap, both apply.
Operator: Wilford Technology ("AccMCP", "we", "us")
MCP endpoint: https://mcp.accmcp.com/mcp
Contact: support@whats91.com
1. What the integration does
AccMCP exposes your Busy Accounting data to an AI assistant through the Model Context Protocol (MCP). Once connected, the assistant can call a fixed set of named tools — for example "list customers", "get sales register", "summarise receivables" — and use the results to answer your questions.
The assistant does not get a database connection, a query language, or general access to your systems. It can only call the specific tools we publish, and each tool returns a defined, bounded result. You can review the full catalogue on the MCP Tools page.
2. What data the tools can access
Depending on the tools you approve and the companies you grant, the integration can read:
- Master records — customers, suppliers, products and product groups, including the names, addresses, contact fields and tax registration details held in your Busy Accounting data.
- Transactions — sales, purchases, receipts, payments and related vouchers.
- Balances and ageing — receivables, payables, outstanding amounts and credit limits.
- Inventory — stock positions, movement and ageing.
- Derived analytics — trends, rankings, segmentation and comparisons computed from the above.
This is business accounting data. It routinely contains personal data about your customers, suppliers and staff — names, contact details and commercial terms. You are the controller of that data and we process it on your behalf.
3. Why the data is used
Solely to answer the request you or your assistant made. We do not use your accounting data for advertising, resale, profiling, or to train any AI model — ours or anyone else's.
4. What you approve, and what it grants
Access is granted through an OAuth 2.1 authorisation screen hosted by AccMCP. Nothing is shared until you complete it. On that screen you approve:
- the connection itself, for one named client;
- the companies the client may read — you grant them individually, not in bulk;
- the scopes the client requests.
api:mcp:managepermits a user to inspect, rename and revoke MCP connections.
Every subsequent request is re-checked against live server state. Access is the intersection of your active account and organisation membership, an active or trialing subscription, your current role and permissions, the connection's scopes, the specific company grants, and the selected financial year. Narrowing any one of these — removing a company, reducing a role, downgrading a plan, revoking a connection — takes effect immediately, not on a delayed cleanup job.
5. What the integration cannot do
These are enforced in the server, not merely promised:
- It cannot write. Accounting reads run inside database transactions opened
as
READ ONLY. The integration cannot create, edit or delete anything in your accounting data. - It cannot be told who you are by the client. Tools never accept a user, organisation, warehouse or grant identifier from the AI client. Company and financial-year arguments select among what you already granted; they cannot widen it.
- It cannot reach another tenant's data. Every query is scoped to your organisation, granted companies and financial year.
- It never asks for credentials in chat. Authorisation happens only on the AccMCP browser page. You should never paste a password, API token or recovery code into an AI assistant. We will never ask you to.
- It does not read your chat history. The integration receives only the tool arguments the assistant sends; it does not request or store your conversations, files or assistant memory.
6. Who else receives your data
This is the most important thing to understand before connecting.
Your AI assistant provider receives the tool results. When the assistant calls a tool, our response travels to that provider — OpenAI for ChatGPT, Anthropic for Claude, or whoever operates the client you chose — and is handled under their terms and privacy policy, not ours. We do not control how they retain, log or process it. Review your provider's terms before connecting a company containing sensitive data, and grant only the companies the assistant genuinely needs.
Beyond that, we share data only with service providers who help us operate the service — hosting and infrastructure, and email delivery for notifications. They act on our documented instructions and may not use the data for their own purposes. We may also disclose data where required by law or to establish or defend a legal claim.
We do not sell your data.
7. Where data is processed and stored
Your Busy Accounting data is synchronised into a warehouse we operate in order to serve tool requests quickly and consistently. Tool responses are generated from that warehouse rather than by querying your Busy installation live.
Our service providers may process data outside India. Where they do, we rely on contractual safeguards requiring a comparable standard of protection.
8. How long things are kept
| What | How long |
|---|---|
| Synchronised accounting data | For the life of your subscription, then deleted on the schedule in §9 |
| Asynchronous export jobs | 24 hours, then expired |
| Export download links | 10 minutes |
| Drill-down tokens | 15 minutes |
| Interactive analysis sessions | 15 minutes idle, 4 hours maximum |
| Operational and security logs | Up to 90 days |
Access tokens expire on their own schedule and can be revoked by you at any time. A revoked token family cannot be reused.
9. Disconnecting and deleting your data
To revoke access immediately, sign in to AccMCP and open Settings → MCP connections. Each connection shows its granted scopes and companies. Revoking takes effect at once — the next tool call from that client fails. Do this straight away if a device or client is lost or compromised. You should also remove the connector inside the AI assistant itself, which is governed by that provider's own controls.
Revoking a connection stops access but does not by itself erase the synchronised accounting data held in your AccMCP account.
To delete your data, email support@whats91.com from the address on your account, or contact us through the contact form. We will confirm your identity and authority over the organisation before acting. Deleting your AccMCP account removes the synchronised accounting data associated with it; we may retain limited records where law requires, as described in the Privacy Policy.
Deleting data in AccMCP does not delete anything already held by your AI assistant provider. Use that provider's own controls for their copy.
10. Limitations and your responsibilities
- Check the numbers before you rely on them. Tool output is generated from your data by an AI assistant and can be misread, truncated or misattributed by the assistant. It is not accounting, tax, audit or legal advice. Verify against your books before filing, paying or contracting on it.
- Grant the minimum. Connect only the companies the assistant needs.
- You are responsible for who you connect. Anyone who can use your assistant session may be able to invoke the tools you approved.
- Personal data is your responsibility as controller. If you grant a company whose records contain personal data, you are responsible for having a lawful basis to have that data processed by us and disclosed to your chosen AI provider.
- Availability is not guaranteed. Rate limits apply, and access stops if your subscription lapses.
11. Contact
Questions about this disclosure, or a data request:
Wilford Technology 131, C21 Mall, Ujjain, Madhya Pradesh, 456010, India support@whats91.com
To report a security vulnerability, follow our Responsible Disclosure policy.