Privacy Policy
ForInvest MCP Server — effective date: 2025-01-01 · last updated: 2025-05-09
This Privacy Policy explains how ForInvest Yazılım ve Teknoloji Hizmetleri A.Ş. ("ForInvest", "we", "us") collects, uses, shares, and retains information when you connect to the ForInvest MCP Server through ChatGPT or any other MCP-compatible AI client.
1. Data We Collect
1.1 Authentication Data
To access the MCP server you authenticate with your Foreks account credentials through an OAuth 2.0 + PKCE flow. We receive and process your username, a short-lived OAuth authorization code, and a Foreks bearer access token. Passwords are transmitted directly to the Foreks Pass authentication service and are never stored by the MCP server.
1.2 Tool Input Data
When you or your AI assistant invokes an MCP tool, the server receives the parameters you supply. All 60 tools are read-only; they accept only the minimum inputs needed to query financial data (symbol codes, date ranges, numeric parameters, filter criteria).
1.3 Session Metadata
Each MCP session generates a random UUID session identifier stored in server memory for up to 30 minutes. This identifier is used solely to route subsequent requests within the same session.
1.4 Server Logs
Our server logs record timestamp, tool name invoked, HTTP status code, and response time. Logs do not contain tool input parameters, bearer tokens, or user-identifiable content.
2. Purposes of Processing
- Authenticate your identity and authorize access to financial data (contract performance)
- Execute tool requests and return financial market data (contract performance)
- Maintain session state for the duration of a conversation (contract performance)
- Monitor service health, diagnose errors, and improve reliability (legitimate interest)
- Comply with applicable laws and regulatory obligations (legal obligation)
We do not use your data for advertising, profiling, or sale to third parties.
3. Data Recipients
Your data is shared only as strictly necessary to deliver the service:
- OpenAI / ChatGPT: Financial data returned by tool calls
- Foreks Pass: Username, password (during login only)
- Foreks Cloud APIs: Bearer token, symbol codes, date ranges
- Foreks PubSub WebSocket: Bearer token, symbol codes
- AWS Bedrock (eu-central-1): Query text for NLU agent tools only
4. Data Retention
- OAuth authorization codes: 10 minutes (single-use)
- Bearer access tokens (in-memory): 1 hour or until session ends
- MCP session identifiers: 30 minutes of inactivity, then auto-deleted
- Server logs: 30 days, then automatically purged
- Tool input parameters: Not persisted — processed in memory only
5. Your Rights and Controls
- Access — request a copy of the personal data we hold about you
- Rectification — ask us to correct inaccurate data
- Erasure — request deletion of your data
- Restriction — ask us to limit processing
- Portability — receive your data in a structured format
- Objection — object to processing based on legitimate interest
- Withdraw consent — disconnect the MCP integration at any time
Turkish residents also have rights under KVKK (Law No. 6698) — see our KVKK Aydınlatma Metni.
To exercise any right, contact us at privacy@forinvest.com. We will respond within 30 days.
6. Security
- All data in transit is encrypted with TLS 1.2 or higher
- OAuth 2.0 with PKCE (S256) — authorization codes cannot be intercepted and replayed
- Bearer tokens are never logged or persisted to disk
- Session identifiers are random UUIDs with no predictable pattern
- HTTP security headers enforced via Helmet.js
7. Contact
- Data Controller: ForInvest Yazılım ve Teknoloji Hizmetleri A.Ş.
- Privacy inquiries: privacy@forinvest.com
- General contact: info@forinvest.com
- Website: www.forinvest.com