Privacy Policy
Hyperus OEE MCP · Last updated: September 25, 2026
This policy explains how Hyperus handles data when you connect an AI assistant (such as Claude, ChatGPT or Cursor) to Hyperus OEE through the MCP server at https://mcp.hyperus.com.br. It complements the Hyperus OEE terms and privacy policy already accepted by your company.
1. Summary
- The server is read-only: it queries data and never changes it.
- You can only access the data you already see in the Hyperus OEE dashboard.
- Hyperus does not sell data and does not use it to train AI models.
- Query results are delivered to the AI client you chose to connect.
2. Data we process
Account and sign-in data
- Email and password entered on the sign-in screen. The password is verified and is not stored by the MCP server.
- Verification code (MFA), when required by your company.
- IP address and browser (user agent) at sign-in, recorded the same way as in the dashboard, for security and login alerts.
Connection data
- Name and redirect URIs of the AI client, provided by the client at registration.
- User and company identifiers, connected client and authorized scope.
- Access and refresh tokens, stored only as SHA-256 hashes.
Plant operational data
Machines, OEE, stops, production, production orders, products, maintenance, SPC, operator performance and telemetry, according to the questions asked to the assistant and the user's permissions. This data already exists in Hyperus OEE. The MCP server only reads it.
Technical logs
For each query we log: tool called, user, company and client identifiers, duration and response size. Response content is not logged. Authorization headers and cookies are redacted.
3. Purposes
- Authenticate the user and enforce the permissions set by the company.
- Answer the queries made by the AI assistant.
- Protect the service: usage limits, abuse detection and incident investigation.
- Operate, monitor and improve the performance of the service.
Processing is based on the performance of the contract with your company and on the legitimate interest of keeping the service secure, under the Brazilian General Data Protection Law (LGPD, Law No. 13,709/2018) and other applicable laws.
4. Sharing
- The AI client you connected: receives the query results. From then on, the data is subject to that provider's privacy policy (Microsoft, Anthropic, OpenAI, Cursor, etc.). Review it before connecting.
- Infrastructure providers: hosting, database and storage used by Hyperus OEE, under contract and bound by confidentiality.
- Authorities: when required by law or court order.
We do not sell or rent data, and we do not use it for advertising or to train AI models.
5. Retention
| Data | Period |
|---|---|
| Pending sign-in request | 10 minutes |
| OAuth authorization code | 2 minutes |
| Access token | 1 hour |
| Refresh token / connection | 30 days since last use, capped by the company's maximum session time, or until revoked |
| AI client registration | 180 days since last use |
| Query result cache | At most 10 minutes |
| Technical logs | As long as needed for security and operations |
Plant operational data follows the retention terms of the Hyperus OEE contract with your company.
6. Security
- HTTPS-only communication.
- OAuth 2.1 with PKCE, company MFA and refresh token rotation.
- Tokens stored only as hashes.
- Permissions re-evaluated every minute; revocations take effect immediately.
- Sensitive fields (such as operator PINs) are never exposed.
7. Your rights and control
- End the connection at any time in the session list of the Hyperus OEE dashboard or by removing the connector in the AI client.
- Request confirmation, access, correction, anonymization or deletion of personal data, and other rights under applicable law.
Because the data belongs to your company's account, some requests may be forwarded to the account administrator.
8. Children
The service is intended for professional use and is not directed to anyone under 18.
9. Changes
We may update this policy. The date at the top shows the latest version. Material changes will be communicated through Hyperus OEE channels.
10. Contact
Privacy questions or requests: suporte@hyperus.com.br.
Mail: Hyperus Technology LTDA, Rua Nova Jerusalém, 246, Sala 3, Terras de São José, São João da Boa Vista, SP, CEP 13874-816, Brasil.
