Legal

MCP Additional Terms.

Version 2026-08-27 · Last updated: 27 August 2026

These MCP Additional Terms version 2026-08-27 cover this site, the local connector, the synthetic sandbox and the closed read-only live MCP service at mcp.stchl.eu. For live account access they supplement, and do not replace, the SatchelPay terms and conditions and the customer's signed pilot addendum. Real data must not flow until those documents and the required written approvals are in force.

1. Operator and regulatory status

The Satchel MCP interface is operated by Satchelpay UAB, reg. No. 304628112, of Upės St. 21-1, LT-08128 Vilnius, Lithuania. Satchelpay UAB is authorised by the Bank of Lithuania as an electronic money institution (licence No. 28). Client funds in the regulated e-money service are safeguarded in accordance with applicable requirements. Electronic money is not a deposit and is not covered by the Lithuanian deposit guarantee scheme.

2. Three client modes

  • Local or customer-hosted. The customer operates or chooses the MCP client. A customer-selected AI is not automatically a Satchel ICT provider. The customer remains responsible for that client and its AI-provider agreement.
  • Hosted external client. Data is sent only to an exact allowlisted domain after the recipient, account-information-service and international-transfer dispositions are recorded and approved.
  • Satchel-managed provider. Satchel may use a provider it selects, contracts, manages or operationally depends on only after contract ownership, DPA, transfer, subprocessor and DORA-register evidence is confirmed.

The consent screen identifies the client's verified name, legal entity, exact destination and mode. For any external client or assistant, review its linked external client terms and privacy notice too; those govern what the recipient does after it receives data.

3. Corporate authority, SCA and permissions

Only a representative authorised by the customer may connect company account data. The representative confirms that authority, authenticates with Client Office and completes the applicable strong customer authentication (SCA) challenge. If Client Office does not present a challenge, live use requires a recorded, approved SCA disposition or exemption reference. Satchel records the accepted Terms/Privacy versions, client identity, company, scopes, data categories, destination and SCA result.

Permissions are granular: accounts, balances, cards and transactions are separate scopes. Transaction narratives and counterparties require a separate optional scope and are off by default. Account and card identifiers are masked in tool output. The hosted remote service exposes read tools only; it does not register a payment tool.

4. Responsibility split

Satchel is responsible for its MCP interface, authorization controls, minimisation, audit trail and secure transfer to the exact destination shown at consent. The customer is responsible for choosing and administering a customer-controlled client, ensuring its users have corporate authority, and reviewing assistant output. The external client or AI provider is responsible under its own terms and privacy notice for its service, prompts, conversation history, retention, model use and onward sharing. Nothing here makes Satchel responsible for an independently customer-selected assistant.

5. Silent-party and confidential data

Transaction data may identify payers, payees, employees, directors or other people who did not operate the assistant. The customer must ensure it has authority and a lawful basis to disclose those silent-party data, provide required notices, restrict access to authorised users and avoid requesting optional narratives unless needed. MCP access does not bypass KYC, AML, sanctions, account limits or other regulated controls.

6. Output limits

Tool output can be delayed, incomplete or transformed by the receiving assistant. A financial summary analyses up to 200 most recent transactions. Merchant grouping and recurring-payment detection are heuristic and, when the optional narrative scope is absent, are not computed. Verify the underlying transactions in an authoritative Satchel channel before acting. Output is informational only and is not financial advice.

7. Connected apps, revocation and termination

Review connected clients, their scopes and last use at /connections. "Revoke now" terminates the active subject-client grant, including its access and refresh tokens. Revocation stops new reads from Satchel but cannot delete copies already stored in an external assistant; use that provider's deletion controls as well. Satchel may suspend a client, narrow scopes or engage the kill switch for security, legal or operational reasons.

8. Sandbox and waitlist

Sandbox accounts, balances, cards, transactions and counterparties are synthetic. They represent no real funds or people. A sandbox transfer changes only in-memory sample data. Joining the waitlist is not an account application and creates no entitlement. Any live access requires the applicable agreement, identification, verification and due diligence; supporting documents may be requested. Access also remains subject to Satchel's onboarding decision.

9. Acceptable use

Do not seek data outside your authority, disclose credentials, evade security or compliance controls, load-test without permission, present sandbox data as real, or use output as an authoritative statement without verification. We may refuse or suspend use where necessary to protect customers, the service or legal compliance.

10. Availability and liability

The sandbox is a preview and may reset or change. The live pilot may be interrupted, rate-limited or withdrawn. To the extent permitted by law, no uninterrupted or error-free operation is promised. Nothing in these terms excludes liability, customer rights, safeguarding obligations, regulatory duties or remedies that cannot be excluded under mandatory law. Any additional liability allocation for live use belongs in the main agreement and signed pilot addendum.

11. Changes, governing law and contact

The version above is the acceptance marker. Material changes will be notified where required and require a new acceptance where appropriate. To the extent permitted by mandatory law, Lithuanian law applies without limiting non-waivable rights or forums. Service questions: support@satchel.eu. Privacy: dpo@satchel.eu.