Skip to main content
Home / Legal / MCP Server Terms
Legal · ES

MCP Server Terms

Version 1.2.0 · Last updated 17 August 2026

Version: 1.2.0 Last updated: 17 August 2026 Original language: Spanish. This English version is provided as a courtesy translation. In the event of any discrepancy, the Spanish version shall prevail in European Union jurisdictions and the English version shall prevail in English-speaking jurisdictions outside the EU.


1. Subject matter

These MCP Terms of Use (hereinafter, "MCP Terms") govern access to and use of the MCP server (Model Context Protocol) operated by PrecisionAI Marketing OÜ ("Entia", "ENTIA") under the trade name Entia, publicly accessible at:

  • Canonical endpoint: https://mcp.entia.systems/mcp/
  • Public discovery: https://entia.systems/.well-known/mcp.json
  • Public documentation: https://entia.systems/mcp-docs

These MCP Terms are a complementary and binding contractual document that integrates with the general Terms of Service and the API Terms. In the event of conflict, the more specific clauses applicable to the matter shall prevail, with these MCP Terms being prevalent in the specific regulation of the MCP server.

Access to the MCP server, connection of an MCP Client, invocation of any MCP tool or subscription to an MCP plan implies full acceptance of these MCP Terms.

2. Nature of the MCP service

2.1. Operational definition

The Model Context Protocol (MCP) is an open client-server communication protocol designed to allow AI systems, autonomous agents and language-model applications structured access to context resources, tools and prompts maintained by third-party servers, in accordance with the public specification of the protocol.

The ENTIA MCP server exposes, in accordance with the 2025-03-26 Streamable HTTP specification and associated JSON-RPC schemas, a delimited and versioned set of tools that allow MCP Clients to query ENTIA's knowledge base: the corpus of business entities, zonal socio-economic data, public commercial registry data, LEI data and VAT verifications.

2.2. Active tools

As of the publication of these Terms, the ENTIA MCP server exposes the following production tools:

Tool Function
entity_lookup Look up a business entity by name, CIF/NIF, EU VAT or LEI, with identity verification and trust score.
search_entities Parameterised search of verified entities across 10 countries by name, keyword, country or sector.
verify_vat Real-time validation of VAT identifiers against VIES (EU-27).
zone_profile Socio-economic profile of a Spanish postal code across 17 blocks: income, employment, demographics, business census, real estate, FTTH, poverty and tourism.
get_competitors Identification of real competitors for an entity in the same sector and geography.
get_showcase Curated set of example entities (IBEX 35 and European Union) for service discovery and evaluation.
get_full_dossier Aggregator: 90+ fields about an entity in a single call.
get_platform_stats Live platform metrics: entity count, countries, sources and published pages.
run_risk_audit AI-readiness and digital risk audit of a domain.
get_entia_home Retrieval of the complete Schema.org @graph (WebPage, Entity, Verification Report and Territorial Profile) for an entity's Entia Home page.
get_entity_home_projection Read of the entia.entity_home_projection.v1 snapshot for an Entia Home (claims, projection and policy), carrying the same truth as its public HTML/JSON-LD twin.
professional_lookup (Enterprise DPA required) Verification of professional registration across 24 Spanish health, legal and psychology verticals. Availability is conditional upon prior execution of the Enterprise DPA, in accordance with section 4.2.

The active tool list is the one published at /.well-known/mcp.json, which prevails over this enumeration.

ENTIA may add, modify, deprecate or discontinue tools in accordance with the Versioning Policy established in section 12 of the API Terms and section 12 of these MCP Terms.

2.2 bis. Tools retired from the public surface

Exercising the right reserved in section 2.2 in fine and in section 12(d) of these MCP Terms, ENTIA has retired the following tools from the public surface of the MCP server. Retirement affects the invocation path available to the MCP Client, not necessarily the underlying capability:

Retired tool Retirement date Where the capability remains
borme_lookup 15 June 2026 Corroborated BORME commercial acts continue to be served through entity_lookup and get_full_dossier. The retirement follows the VERIFIED-ONLY policy: registry acts are served only where the entity's identity is corroborated by an independent source, so that uncorroborated data is not presented as if it were corroborated.
lookup_by_domain 23 July 2026 No equivalent on the public MCP surface as at the date of this version.
ai_ready_profile 17 August 2026 Remains accessible through the REST API at /api/v1/v3/ai_ready_profile for tiers holding access rights, in accordance with the API Terms.

None of these retirements alters the rights and obligations of the parties established in these MCP Terms, nor the scope of the data licence granted. An MCP Client that had integrated a retired tool must rely on the current list published at /.well-known/mcp.json.

2.3. Resources exposed

In addition to tools, the MCP server may expose resources (consultable context data) and prompts (prompt templates that the MCP Client may invoke), in accordance with the protocol specification. Available resources and prompts are documented at https://entia.systems/mcp-docs.

2.4. Scope of Outputs

The MCP server returns data compiled, structured, canonicalised and enriched by ENTIA in accordance with the Data Licensing Framework. MCP Outputs are accompanied, where applicable, by the source_chain field describing the data's provenance: origin → transformation → publication.

3. Specific definitions

For the purposes of these MCP Terms, in addition to the definitions in the general Terms of Service:

Term Definition
Model Context Protocol (MCP) Open client-server protocol for integrating context and tools into AI systems, in accordance with the public specification in force.
MCP Client Software, agent, language model, orchestration framework or application that connects to the ENTIA MCP server using the Model Context Protocol.
MCP Server The server operated by ENTIA accessible at mcp.entia.systems/mcp/.
Tool Function exposed by the MCP server that the MCP Client may invoke via JSON-RPC.
Tool Call Atomic invocation of a tool.
Resource Context resource exposed by the MCP server.
Prompt Prompt template exposed by the MCP server.
Agent / Autonomous System AI system or software acting autonomously or semi-autonomously over MCP Outputs, with or without direct human supervision.
Orchestration Framework System coordinating multiple MCP Clients, models and tools (LangChain, LangGraph, OpenAI Agents SDK, Anthropic Claude Agent SDK, Vercel AI SDK, equivalents).
LLM Upstream Large Language Model that invokes MCP tools on behalf of a human end-user or an agent.
Sampling Mechanism by which the MCP server may request the MCP Client to generate text using its upstream LLM for specific tasks.
Source-chain Chain of provenance of a data point (origin → transformation → publication).
Tier locked State in which a given commercial MCP plan does not accept new subscriptions temporarily by operational decision of ENTIA (private GA).

4. Regulatory framework and AI Act alignment

4.1. Regulation (EU) 2024/1689 — AI Act

ENTIA operates the MCP server designed to align with Regulation (EU) 2024/1689 (the "AI Act") in accordance with its phased application. These MCP Terms incorporate the following alignments:

AI Act provision Application to the MCP server
Article 5 — Prohibited practices The MCP server does not operate, nor enable the operation of, prohibited practices. ENTIA expressly prohibits the MCP Client from using the Outputs for purposes classified as prohibited practices.
Article 6 + Annex III — High-risk systems The Outputs of the MCP server do not constitute high-risk systems per se. Where an MCP Client incorporates Outputs into a downstream system that is high-risk, the obligations of the Regulation fall upon that MCP Client in its capacity as provider or deployer of the downstream system.
Article 13 — Transparency to deployers ENTIA provides sufficient information on capabilities and limitations of the service in the public documentation and in the AI Transparency Statement.
Article 14 — Human oversight ENTIA requires the MCP Client to implement human-in-the-loop safeguards when Outputs feed decisions producing significant legal effects on natural persons.
Article 50 — Specific transparency obligations Where an MCP Client exposes ENTIA Outputs to a human end-user, it must ensure that the user is informed of the algorithmic nature of the response when applicable.
Articles 51 et seq. — GPAI ENTIA is a downstream consumer of GPAI models, not a provider. GPAI obligations do not fall upon ENTIA.

4.2. GDPR

These MCP Terms apply consistently with the Privacy Policy and, where applicable, with the DPA signed between ENTIA and the Enterprise client. Use of the MCP server involving processing of personal data on behalf of a client is subject to the applicable DPA.

Where the MCP Client processes personal data through the MCP server (for example, in tool arguments as per section 7.3.c), the Data Processing Agreement (DPA) under Article 28 of the GDPR is incorporated by reference and accepted at checkout, regardless of tier.

4.3. Source-chain clause

ENTIA expressly incorporates into the body of these MCP Terms the following declaration of nature:

"MCP outputs are informational infrastructure signals and must not be treated as sole authoritative sources for high-risk automated decisions."

Any internal reference to this declaration in other documents of the ENTIA Legal Stack shall be interpreted as binding upon MCP Clients.

5. Restrictions for high-risk automated decisions

5.1. Specific prohibition

It is strictly prohibited to use MCP Outputs as the sole source of information for automated decisions producing significant legal effects on natural persons, within the meaning of Article 22 GDPR and Annex III of the AI Act, in any of the following areas:

a) Granting, denial, modification or withdrawal of credit or solvency assessment. b) Underwriting, modification or cancellation of insurance and actuarial pricing. c) AML/CFT (anti-money laundering / counter-terrorism financing) as the sole decision signal, without prejudice to the use of the service as a complement to KYC/CDD programmes of the regulated client. d) Selection, evaluation, promotion, sanction, dismissal or any significant employment decision concerning natural persons. e) Administrative decisions on the granting of benefits, social benefits, pensions, subsidies or economic rights. f) Law enforcement decisions and public-security management. g) Migratory, border, asylum or visa decisions. h) Judicial decisions concerning natural persons, including reoffending-risk assessments. i) Decisions on access to critical infrastructure affecting the integrity or safety of natural persons.

5.2. Human-oversight safeguard

In all cases where an MCP Client integrates ENTIA Outputs into systems producing significant legal effects on natural persons, the MCP Client must ensure:

a) Human-in-the-loop: significant human review before the final decision. b) Traceability: documentation of the ENTIA Outputs used, their version, their source_chain and the weight attributed in the decision. c) Right of review: the affected person's ability to request human review of the decision, in accordance with Article 22(3) GDPR where applicable. d) Internal documentation: record of MCP server use cases in accordance with the logic of the applicable MSA.

5.3. Carve-out: AML/CFT as a complement

Without prejudice to the prohibition in section 5.1.c, the MCP Client may use MCP Outputs (in particular, the available verified-identity tools, such as verify_vat or entity_lookup with sanctions dimension when available) as a complementary signal within the MCP Client's own KYC/CDD programme, provided that such programme complies with applicable legislation, incorporates other sources and maintains human oversight over material decisions.

6. Attribution and source-chain

6.1. Attribution obligation

When an MCP Client publishes, exposes or redistributes MCP Outputs to human end-users or third parties, it must include a reasonable attribution to ENTIA in accordance with the Data Licensing Framework. The minimum recommended attribution for machine-to-machine consumption is provided via source-chain in the MCP response itself:

{
  "isBasedOn": {
    "@type": "Dataset",
    "name": "ENTIA Verified Entities",
    "url": "https://entia.systems",
    "publisher": {
      "@type": "Organization",
      "name": "PrecisionAI Marketing OÜ",
      "url": "https://entia.systems"
    }
  }
}

6.2. Source-chain disclosure

The MCP Client is required to preserve the source_chain field when delivering it to its end-user or to another downstream system. Deliberate removal of the source_chain for the purpose of concealing the ENTIA provenance constitutes an infringement of the Data Licensing Framework and the Acceptable Use Policy (Category F — Trademark / Brand Abuse).

6.3. Exceptions

  • For purely internal consumption by the MCP Client (debugging, testing, quality evaluation), attribution is not required.
  • In specific Enterprise contracts, ENTIA may agree to exceptions to the attribution obligation under express clause.

7. MCP Client obligations

In addition to the general obligations of the Terms of Service and the API Terms, the MCP Client undertakes to:

7.1. Honest identification

a) Send an honest User-Agent in MCP requests, clearly identifying the client, the orchestration framework and, where applicable, the upstream model operating the session. b) Not impersonate identities of verified bots, ENTIA employees or other MCP Clients. c) When operating through a recognised commercial orchestration framework (LangChain, OpenAI Agents SDK, Anthropic Claude Agent SDK, Vercel AI SDK, etc.), include reasonable information enabling identification.

7.2. Respect for technical limits

a) Respect the rate limits and quotas of the contracted tier in accordance with the API Terms. b) Implement exponential backoff in response to 429 Too Many Requests or 503 Service Unavailable responses. c) Not coordinate across multiple accounts to exceed individual limits. d) Not use multiple API Keys of the same client to distribute load in violation of the 3 keys/email limit.

7.3. Logging and telemetry

a) ENTIA records each Tool Call with metadata sufficient for billing, security and compliance. b) The MCP Client accepts the logging and telemetry described in the Privacy Policy and the API Terms. c) In productive environments, the MCP Client must not send sensitive personal data in tool arguments unless strictly necessary for the query.

7.4. Information to end-users

When a human end-user interacts with a system operating MCP Outputs, the MCP Client must ensure the transparency required by Article 50 of the AI Act and equivalent rules of each applicable jurisdiction.

7.5. Cooperation in case of abuse

When ENTIA detects indications of abuse by an MCP Client, the MCP Client undertakes to:

a) Attend to abuse reports addressed to abuse@entia.systems within reasonable time. b) Provisionally suspend the detected behaviour while it is investigated. c) Cooperate in good faith with the investigation and, where appropriate, with competent authorities.

8. Commercial MCP tiers and access policies

8.1. Catalogue

As of publication, the commercial MCP tiers are those described in the API Terms (section 4) and in the public documentation at entia.systems/mcp-setup and entia.systems/mcp-docs.

8.2. Private GA policy

Certain MCP tiers may be temporarily in "tier locked" or "private GA" state by operational decision of ENTIA. In this state:

a) The tier does not accept new subscriptions through public checkout. b) Requests are queued in the waitlist through the POST /api/v1/mcp/waitlist endpoint. c) ENTIA evaluates the incorporation of new clients to locked tiers on a case-by-case basis based on operational maturity, specific commercial agreements and deployment strategy.

As of this version, the BUILD, INTEGRATE, OPERATE and SCALE tiers may be partially or fully locked; the SIGNAL tier remains open to public checkout, and the TRACE and ENTERPRISE tiers are managed under their specific regime.

8.3. Checkout endpoint

MCP checkout is managed through:

  • POST /api/v1/mcp/checkout — opens a Stripe payment session; returns 503 with error: "tier_locked" when the requested tier is in private GA.
  • GET /api/v1/mcp/checkout?tier=<X> — redirects 303 to /mcp-setup?tier=<X>#waitlist when the requested tier is in private GA.
  • POST /api/v1/mcp/waitlist — registration on the persistent waitlist.

ENTIA notifies fv@entia.systems of each waitlist registration to maintain visibility of commercial demand.

9. MCP discovery

ENTIA maintains a public MCP discovery endpoint at https://entia.systems/.well-known/mcp.json, in accordance with the emerging convention of the MCP ecosystem. This endpoint exposes MCP server metadata, list of tools, capabilities and links to documentation.

ENTIA also participates in public MCP server directories where appropriate (Smithery, Anthropic Connectors Directory or other equivalents), with the scope described in the public documentation.

10. Specific restrictions for autonomous systems

10.1. Operation without human oversight

When an MCP Client operates as an autonomous system without direct human oversight (multi-agent loops, scheduled jobs, batch enrichment pipelines), it must additionally comply with:

a) Per-session rate cap: the MCP Client shall implement an internal cap that prevents unforeseen quota consumption. b) Persistent logging: the MCP Client shall maintain auditable logs of each Tool Call, retaining them for at least 12 months. c) Human traceability: the MCP Client must maintain an operational human point of contact (technical lead, DPO or equivalent) accessible for incidents and reports. d) No infinite recursion: the MCP Client must implement circuit breakers that detect recursive invocation loops and stop them automatically.

10.2. Specific prohibition

The operation of autonomous systems that:

a) Make material decisions about third-party users without traceability or oversight. b) Generate cascading Outputs exceeding the scope of the contracted tier. c) Carry out mass enrichment of the corpus in violation of the Data Licensing Framework.

is prohibited.

11. Notaría Digital invoked via MCP

Where the MCP server exposes access to the Notaría Digital service (qualified eIDAS time stamp via SK ID Solutions AS), the MCP Client undertakes to:

a) Limit invocation to SHA-256 hashes that the client legitimately wishes to time-stamp. b) Not use the service to time-stamp third-party content without authorisation. c) Retain the cryptographic token returned as evidence of certain date. d) Respect the specific conditions of the Trust Service Provider set out in the Subprocessors and in the service documentation.

12. Modifications to the MCP Terms

ENTIA may modify these MCP Terms to adapt to:

a) Changes in the public specification of the Model Context Protocol. b) Regulatory evolution (in particular, the progressive deployment of the AI Act). c) Emerging abuse vectors in the MCP ecosystem. d) Operational adjustments of the service (new tools, deprecation, tier changes).

Substantial modifications will be notified to active clients with at least 30 calendar days prior notice. Minor modifications will take effect upon publication at entia.systems/legal/mcp-terms.

13. Limitation of liability

TO THE FULLEST EXTENT PERMITTED BY APPLICABLE LAW AND WITHOUT PREJUDICE TO THE PROVISIONS OF THE GENERAL TERMS OF SERVICE AND THE API TERMS:

a) ENTIA SHALL NOT BE LIABLE FOR DECISIONS BY THE MCP CLIENT OR ITS END-USERS BASED ON MCP OUTPUTS, IN PARTICULAR IN HIGH-RISK AREAS UNDER ANNEX III OF THE AI ACT. b) ENTIA SHALL NOT BE LIABLE FOR INTEGRATION FAILURES OF THE MCP CLIENT OR FOR INTERACTIONS WITH THIRD-PARTY ORCHESTRATION FRAMEWORKS. c) ENTIA'S AGGREGATE LIABILITY FOR ANY CLAIM ARISING FROM USE OF THE MCP SERVER SHALL BE LIMITED IN ACCORDANCE WITH THE PROVISIONS OF THE GENERAL TERMS OF SERVICE AND, WHERE APPLICABLE, THE ENTERPRISE MSA.

The provisions of this clause do not affect mandatory consumer rights or damages caused by intent or gross negligence of the provider.

14. Governing law and jurisdiction

These MCP Terms are governed by the laws of the Republic of Estonia and, on a supplementary basis, by the laws of the European Union. Any dispute shall be submitted to the courts of Tallinn, without prejudice to mandatory consumer rights and the specific clauses provided for in the Enterprise MSA.

15. Cross-references

These MCP Terms must be read together with:

  • Legal Notice.
  • Privacy Policy.
  • Cookies Policy.
  • Terms of Service.
  • API Terms.
  • Data Licensing Framework (in particular, section 4.5 — License Train).
  • Database Rights Notice.
  • AI Consumption Policy.
  • Acceptable Use Policy (Category D — Harm to Third Parties).
  • AI Transparency Statement (classification of algorithmic components and human oversight).
  • DPA Template and Subprocessors List for Enterprise clients.

16. Contact

Matter Email
MCP technical support api@entia.systems
Commercial / Enterprise / MSA atc@entia.systems
MCP abuse reports abuse@entia.systems
Privacy and data subject rights dpo@entia.systems
Public documentation https://entia.systems/mcp-docs
Public discovery https://entia.systems/.well-known/mcp.json
Setup and checkout https://entia.systems/mcp-setup
Status page https://status.entia.systems

17. Version history

ENTIA maintains the change record of these MCP Terms in accordance with section 12. Versions prior to 1.2.0 were published without a structured change record; from 1.2.0 onwards every modification is recorded in this section.

Version Date Changes
1.2.0 17 August 2026 Section 2.2 updated to reflect the current public surface of the MCP server (12 tools). New section 2.2 bis documenting the retirement of borme_lookup, lookup_by_domain and ai_ready_profile and indicating where the capability remains. Addition of this version history. Non-substantial modification: it does not alter the rights or obligations of the parties, pricing, tiers, usage limits or the scope of the data licence.
1.1.0 23 July 2026 Consolidated version of the ENTIA legal stack. Published without a detailed change record.

PrecisionAI Marketing OÜ Sepapaja tn 4, 11415 Tallinn, Estonia VAT: EE102780516 — D-U-N-S: 565868914 Document updated on 17 August 2026 — Version 1.2.0

Contents
↑ Back to top