Xakia Connector Privacy Brief
1. Who this applies to
MCP Connector (the "connector") and you choose to connect Xakia to an AI application, such as Claude, ChatGPT or Microsoft Copilot Studio, from within that AI application.
If you have not connected Xakia to an AI application, this page does not apply to you, and your use of Xakia remains governed by your agreement with Xakia, our Privacy Policy and our Data Processing Addendum.
2. What the connector can access
The connector lets an AI application that you authorise read information in Xakia on your behalf. It can read:
- matters, including their status, dates and team, and the parties, entities and contracts linked to them;
- contracts, including lifecycle dates, governing law and linked matters;
- documents: the folder structure and file list of a matter, and the extracted text of documents that have been processed for Xakia's document search;
- key dates and deadlines;
- contract playbooks, including your organisation's negotiating positions;
- custom log entries and their fields; and
- the Xakia locations you belong to.
It can also search Xakia and return summary details (such as type, number, name, status and dates) of items that appear in Xakia search, including tasks.
The connector is read-only. It cannot create, change or delete anything in Xakia. It returns only information you are already permitted to see in Xakia, under the same access rules as the Xakia web application.
3. Where the data goes
You choose which AI application to connect to Xakia, for example Claude (provided by Anthropic), ChatGPT (provided by OpenAI) or Microsoft Copilot Studio (provided by Microsoft). You use that AI application under your own agreement with its provider.
When your AI application asks the connector for information, Xakia retrieves it from the Xakia region that holds your data and sends it directly to that AI application, on your instruction. Xakia's processing of that information ends when we deliver the response to the AI application, except for the audit record described below.
From that point the information is handled under your agreement with the AI provider and the provider's own terms and privacy policy, including how long it is kept and whether it may be used to train models. The AI provider you choose is not a Xakia sub-processor in this role and is not listed on our Sub-processor Page. Xakia does not control, and is not responsible for, how the AI provider processes the information.
Xakia does not keep a copy of the information returned to your AI application. We keep only an audit record of each request, showing who made it, through which AI application, and which records were returned, identified by their IDs. It does not include the text of searches or the content of those records. It is kept for up to 12 months. "What Xakia records" below describes it in full.
4. What Xakia records
For security and audit purposes, Xakia records each request an AI application makes through the connector. Each record contains:
- which user made the request (their Xakia user ID);
- which AI application it came through, identified by its OAuth client ID (for example, `mcp-claude`);
- which Xakia location it concerned;
- which connector operation was used;
- identifiers and filters supplied with the request, such as a matter ID, a date range or a page number;
- the identifiers of the records returned, such as matter and document IDs;
- whether the request succeeded, and how long it took; and
- the date and time.
We do not record the text of search queries, or the names, descriptions or content of records returned to the AI application. For a search, we record only the length of the search text.
These records are part of Xakia's application logs, which are stored in Microsoft Azure Application Insights in the United States, for customers in every Xakia region. They hold identifiers only. Your matters, contracts, documents and other Xakia content are not copied into these logs and stay in your Xakia region.
The records are available for search for 6 months, then held in archive storage for a further 6 months, after which they are deleted.
5. Sign-in and tokens
The AI application connects using OAuth 2.0. You sign in to Xakia with your usual Xakia sign-in, including single sign-on and multi-factor authentication where your organisation uses them.
Before you connect, Xakia shows you a consent screen describing the access the AI application is requesting. For Claude, this screen is shown every time you connect. For other AI applications, it is shown the first time you connect each one.
Xakia then issues the AI application an access token, which is valid for 20 minutes, and a refresh token, which lets it stay connected without you signing in again. The refresh token expires after 15 days without use and, in any case, 30 days after you signed in. After that you must sign in again.
Tokens can be used only with the connector, not with any other Xakia service. They contain your Xakia user ID, your role, the Xakia locations you belong to and your role in each, the AI application's OAuth client ID, and the permitted access scope. They do not contain your name, your email address, or any matter or document information.
6. Administrator and user controls
The connector is off by default for every Xakia location. A Xakia administrator must switch on "MCP Enabled" for a location before anyone can use the connector there, and can choose whether all users or only location administrators may connect. The connector is available on the Xakia All-In plan.
An administrator can switch the connector off, or restrict it to administrators, at any time. The change applies to new requests within about a minute.
You can disconnect at any time by removing the Xakia MCP Connector in your AI application. Removing you from a location, or deactivating your Xakia account, also ends your access through the connector.
7. Privacy contact and data requests
For questions about the Xakia MCP Connector and your data, or to make a request about personal information we hold, contact legal@xakiatech.com.
We can tell your organisation which of its users accessed which Xakia records through the connector, through which AI application, and when, for the retention period described above.
Information that has been sent to your AI application is held by the AI provider. Requests about that information should be made to the provider under its own privacy terms.
8. Connector terms clause
**AI applications you choose.** You, the Subscriber, choose the AI application you connect to Xakia through the Xakia MCP Connector (the "connector"), for example Claude (Anthropic), ChatGPT (OpenAI) or Microsoft Copilot Studio (Microsoft), and you engage its provider under your own agreement with that provider. When that AI application makes a request through the connector, Xakia sends the requested information, including Subscriber Personal Data, to it on your instructions under clause 2.1 of the DPA.
The provider of that AI application is engaged by you, not by Xakia or its Affiliates. In that role it is not a Sub-processor as defined in the DPA, it is not listed on the Sub-processor Page, and clause 6 of the DPA, including Xakia's liability for its Sub-processors under clause 6.1, does not apply to it.
Xakia's Processing of Subscriber Personal Data for a connector request ends when Xakia delivers the response to the AI application, except for the audit record described in the Xakia MCP Connector privacy information, which Xakia keeps as described there.
This clause does not affect any provider that Xakia or its Affiliates engage separately as a Sub-processor, which remains listed on the Sub-processor Page.