Privacy policy
Effective 29 September 2026
Eurekall is a free remote MCP server run as a personal project by the owner of borisano.com (“we”). It has no user accounts, sets no cookies and uses no analytics or advertising. This page describes everything it processes. Questions and requests: eurekall@borisano.com.
What a tool call processes
To answer, Eurekall uses the arguments of the tool you call and passes only what each public source needs:
-
VAT tools: the VAT numbers you ask about and, if you give one, your own
VAT number (
requester_vat) are sent to the European Commission's VIES service. VIES answers with the registered name and address, which may be a person's name and address when the number belongs to a sole trader. - Holiday tools: the country and year are sent to Nager.Date.
- Exchange-rate tools: only a date range is sent to the European Central Bank; amounts and currencies stay with us.
What we store, and for how long
| Data | Why | Kept for |
|---|---|---|
| VAT cache: country, VAT number, valid/invalid, the name and address VIES returned, time of the check | Fewer calls to VIES; a “last known” answer when VIES is down | Deleted automatically 30 days after the check (an hourly job). Database backups (Cloudflare D1 point-in-time recovery) may hold a deleted row for up to 7 more days. |
| Rate-limit counters, keyed by a keyed hash (HMAC-SHA256) of your IP address; IPv6 addresses are shortened to their /64 network first | Fair use: 30 units per minute and 1,000 per day per client | Deleted 24–25 hours after your last call |
| Public holidays and ECB exchange rates | Caching of public reference data (no personal data) | Refreshed regularly |
| Operational logs: tool name, outcome, duration, country, error codes, and at most a masked VAT number (country and last 3 characters) | Running and debugging the service | 3 days (Cloudflare Workers Logs) |
| Emails you send to the support address | Answering you | As long as needed to handle your request |
We never store or log your IP address, your own VAT number (requester_vat),
VIES consultation numbers, or the arguments of your calls. Names and addresses from VIES
appear only in the VAT cache above, never in logs.
Service providers
- Cloudflare, Inc. hosts Eurekall (Workers, D1 database, Durable Objects, logs) and forwards support email (Email Routing). Like any web host, Cloudflare processes the IP address and headers of each request to deliver it; see the Cloudflare privacy policy.
- The public sources queried on your behalf, under their own terms: the European Commission (VIES), the European Central Bank and Nager.Date.
We do not sell or share data with anyone else.
Legal basis and your rights
We process this data on the basis of our legitimate interest in providing a working, abuse-resistant public service (Article 6(1)(f) GDPR). VAT registration data comes from a public EU register. You may ask for access to, correction or deletion of data about you, or object to its processing, by writing to eurekall@borisano.com; we will reply within one month. You may also complain to your data protection authority.
Changes
If our data practices change, we update this page and its effective date before the change takes effect.