Search Results :

×

miniOrange Privacy Policy for Joomla MCP Server

This policy outlines how our Secure MCP Server collects, stores, processes, and protects your authorized data connections between your AI assistant and your Joomla environment.

Last updated: Aug 27, 2026

As a security company, miniOrange is committed to providing secure and resilient solutions to our customers. We design and maintain our products and services with a focus on security, privacy, and the requirements of the marketplaces and platforms where our solutions are available.

This Privacy Policy explains how Xecurify Inc. ("Xecurify", "miniOrange", "we", "our", or "us") collects, processes, uses, stores, and discloses information in connection with the miniOrange MCP Server for Joomla ("Service"). It also explains your rights and choices regarding the processing of your Personal Data.

This Policy applies specifically to the miniOrange MCP Server for Joomla.


1. Overview

The miniOrange MCP Server for Joomla enables Joomla websites to connect with MCP-compatible AI assistants and applications.

Depending on the configuration and permissions established by the Joomla administrator, a connected AI client may retrieve Joomla site information or perform permitted operations through the MCP Server.

The Service provides an MCP endpoint through which authorized AI clients can communicate with the Joomla website. Access to Joomla resources and operations is governed by the permissions, authentication mechanisms, and configurations established by the Joomla administrator.

The Joomla administrator remains responsible for determining which data, tools, resources, and operations are made available to connected AI clients.

2. Information We Process

The information processed through the Service depends on how the MCP Server is configured and which tools, resources, and permissions are enabled by the Joomla administrator.

2.1 Joomla Site and Connection Data

To establish and maintain communication between the MCP client and Joomla website, the Service may process information such as:

• Joomla website URL or MCP endpoint URL.

• Connection or configuration identifiers.

• Authentication and authorization information.

• MCP client information.

• Connection status.

• Connection creation and last-used timestamps.

• Configuration settings related to enabled MCP tools.

Authentication credentials or tokens, where applicable, are used to authorize requests to the Joomla resources and operations permitted by the Joomla administrator.

2.2 Joomla Data Processed Through MCP

When an authorized user submits a request through a connected AI client, the MCP Server may process Joomla information necessary to fulfill that request.

Depending on the tools and permissions enabled by the Joomla administrator, this information may include:

• Joomla articles and other website content.

• Categories and tags.

• Joomla user information.

• User groups and access permissions.

• Site configuration information.

• Content and resources made available through configured MCP tools.

• Information returned from Joomla APIs or administrative operations.

• Other Joomla resources explicitly made available through the MCP Server.

Some of this information may contain Personal Data, including information associated with Joomla users, administrators, website visitors, or other individuals.

The scope of information accessible through the MCP Server is determined by the permissions and tools configured by the Joomla administrator.

2.3 MCP Tool Requests and Responses

When a connected AI client invokes an MCP tool, the Service processes the information necessary to execute the requested operation.

This may include:

• The MCP tool being requested.

• Parameters provided with the request.

• Joomla data required to fulfill the request.

• Results returned by Joomla.

• Technical information required to process the operation.

The Service processes this information for the purpose of completing the MCP operation requested by the user.

miniOrange does not require access to the user's complete AI assistant conversation history. However, information from an AI conversation may be included in an MCP request where the connected AI platform determines that such information is necessary to invoke a particular tool.

2.4 Authentication and Authorization Data

The Service may process authentication and authorization information required to validate MCP requests.

Depending on the selected configuration, this may include:

• Access tokens.

• OAuth authorization information.

• Token identifiers.

• Authorization state.

• Joomla user or permission information.

• Other credentials required to authenticate and authorize MCP requests.

Access is restricted according to the permissions and configuration established by the Joomla administrator.

Joomla administrators should configure the MCP integration using the minimum permissions necessary for the intended use.

2.5 Operational and Security Data

We may process limited technical information required to operate, secure, troubleshoot, and protect the Service.

This may include:

• Request timestamps.

• Connection identifiers.

• Request status or outcome.

• Error and diagnostic information.

• IP addresses.

• MCP client or device information where technically necessary.

• Security and abuse-prevention information.

Operational information may be used for security monitoring, debugging, rate limiting, fraud prevention, abuse prevention, and maintaining the reliability of the Service.

Authentication secrets should not be intentionally recorded in application logs in plaintext.

2.6 Support and Contact Information

If you contact miniOrange for technical support, product inquiries, demonstrations, licensing, or other assistance, we may process information you voluntarily provide, including:

• Name.

• Business email address.

• Phone number.

• Organization name.

• Technical configuration information.

• Support correspondence.

• Diagnostic information you choose to share.

Support information is used to provide the requested assistance and for related legitimate business purposes.

3. How We Use Information

We may process information described in this Policy to:

• Establish and maintain authorized connections between Joomla and MCP-compatible AI clients.

• Authenticate and authorize MCP requests.

• Retrieve Joomla information requested through MCP tools.

• Perform Joomla operations explicitly permitted by the Joomla administrator.

• Return requested information or operation results to the connected AI client.

• Maintain, secure, troubleshoot, and improve the reliability of the Service.

• Prevent unauthorized access, abuse, fraud, and security threats.

• Provide technical and customer support.

• Comply with applicable legal and regulatory obligations.

miniOrange does not sell Personal Data processed through the Joomla MCP Server.
miniOrange does not use Joomla customer, user, or website data processed through the MCP Server for targeted advertising.
miniOrange does not use Joomla website data processed through the MCP Server to train general-purpose AI models.

4. Access Control and Customer Responsibility

The Joomla administrator controls which Joomla resources and operations the MCP Server can access.

Access to Joomla information and operations may be controlled through Joomla's user, group, and permission mechanisms and through the MCP tools configured by the administrator.

Depending on the configuration, an MCP connection may be granted read-only capabilities or may be permitted to perform additional authorized operations.

Joomla administrators are responsible for:

• Configuring appropriate permissions for the MCP Server.

• Following the principle of least privilege when granting access.

• Ensuring that users connecting AI clients are authorized to access the relevant Joomla information.

• Reviewing and approving the MCP tools made available to AI clients.

• Revoking credentials or access when they are no longer required.

• Reviewing the privacy and security practices of AI platforms they choose to connect.

• Complying with applicable privacy and data-protection requirements relating to information stored within their Joomla environment.

• Customer should carefully review the tools and permissions enabled for their MCP Server before connecting an AI client to their Joomla website.

5. Sharing and Recipients

Information processed through the miniOrange MCP Server for Joomla may be exchanged with the following parties where necessary to provide the Service.

5.1 Joomla Website

MCP requests are sent to the Joomla website associated with the configured MCP endpoint.

Joomla processes these requests according to its configuration, permissions, authentication mechanisms, and access-control settings.

5.2 Connected AI Platform

Information requested through MCP may be returned to the AI client or platform selected by the customer, such as ChatGPT, Claude, Cursor, GitHub Copilot, or another MCP-compatible application.

Once information is transmitted to a third-party AI platform, that platform's handling of the information is governed by its own privacy policy, terms of service, data controls, and contractual arrangements with the customer.

Customers should review the privacy and security practices of any AI platform before allowing it to access information from their Joomla environment.

5.3 Infrastructure and Service Providers

Where miniOrange uses third-party infrastructure or service providers to deliver, secure, maintain, or support the Service, those providers may process limited information on our behalf and only for the purposes for which they have been engaged.

We require applicable service providers to protect information in accordance with contractual, security, and confidentiality requirements.

A current list of applicable sub-processors may be available upon request at joomlasupport@xecurify.com.

5.4 Legal and Security Requirements

We may disclose information where reasonably necessary to:

• Comply with applicable law, regulation, legal process, or governmental request.

• Protect the security or integrity of the Service.

• Investigate fraud, misuse, or security incidents.

• Protect the rights, property, or safety of miniOrange, our customers, or others.

6. Data Retention

We retain Personal Data only for as long as reasonably necessary to provide the Service, fulfill the purposes described in this Policy, comply with legal obligations, resolve disputes, enforce agreements, and maintain security.

Joomla information processed as part of an MCP request is intended to be processed only as necessary to fulfill the requested operation unless retention is required for a separately disclosed operational, support, security, or legal purpose.

Authentication and connection information, where retained by miniOrange-managed components, is retained only for as long as necessary to maintain the applicable connection or meet legitimate security, contractual, or legal requirements.

Operational and security logs may be retained for a limited period where necessary for security monitoring, troubleshooting, abuse prevention, compliance, or service reliability.

When information is no longer required, it is deleted, anonymized, or otherwise handled in accordance with applicable retention requirements.

7. Data Processed by Connected AI Platforms

The miniOrange MCP Server for Joomla may be connected to third-party AI clients or platforms.

When an AI client sends an MCP request, information required to perform that request may be transmitted between the AI platform, the MCP Server, and the Joomla website.

miniOrange does not control how an independent third-party AI platform processes information after it is provided to that platform.

Customers should review the applicable AI platform's:

• Privacy policy.

• Terms of service.

• Enterprise or business data-processing terms.

• Data-retention settings.

• Model-training controls.

• Administrator and security controls.

before allowing that platform to access Joomla information.

8. Data Protection Roles

Joomla website owners and organizations generally determine why their Joomla data is processed, which users may access it, and which resources and operations are made available to MCP clients.

Where miniOrange processes Personal Data solely on a customer's behalf to provide the Service, the respective roles of miniOrange and the customer will depend on the particular deployment, contractual relationship, and applicable data-protection law.

Customers remain responsible for:

• Establishing an appropriate legal basis for processing Personal Data contained within their Joomla environment.

• Providing appropriate privacy notices to individuals where required.

• Obtaining any required permissions or consents.

• Configuring appropriate access controls.

• Ensuring that connected AI platforms are suitable for the data being processed.

9. Security

miniOrange implements reasonable technical and organizational measures designed to protect information processed through the Service against unauthorized access, alteration, disclosure, or destruction.

These measures may include:

• Encryption of data in transit using Transport Layer Security (TLS).

• Secure handling of authentication and authorization information.

• Access controls based on the principle of least privilege.

• Authentication and authorization controls.

• Security monitoring and logging.

• Measures designed to prevent unauthorized access, abuse, and security threats.

miniOrange's broader security practices include encryption and access controls designed to protect customer information.

The security of information within the customer's Joomla environment also depends on the customer's Joomla configuration, hosting environment, access controls, enabled extensions, credentials, and security practices.

10. International Data Transfers

The Service may be operated and supported from locations outside the country in which you access or use the Service.

If you access the Service from outside the United States, your information may be transferred to and processed in the United States or other locations where miniOrange or its service providers operate.

Where required by applicable law, miniOrange relies on appropriate mechanisms for international data transfers, such as Standard Contractual Clauses.

11. Children's Privacy

The Service is not directed to children under 13, and we do not knowingly collect Personal Data from children under 13 through the Service.

If you believe that a child has provided Personal Data to us, please contact us. We will take appropriate steps to investigate and delete the information where required.

12. Your Rights and Choices

Depending on applicable law, you may have rights relating to your Personal Data, including the right to:

• Access your Personal Data.

• Correct inaccurate or incomplete Personal Data.

• Request deletion of Personal Data.

• Request information about how your Personal Data is processed.

• Object to or restrict certain processing.

• Exercise other rights available under applicable privacy and data-protection laws.

You may also manage or revoke access to the MCP Server through your Joomla configuration and connected AI client.

To exercise applicable rights or request additional information, please contact us using the details provided below.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes to the Service, our practices, applicable laws, or other requirements.

Material changes will be posted on this page with an updated "Last updated" date.

Your continued use of the Service after an updated Privacy Policy is posted constitutes acceptance of the revised Policy, where permitted by applicable law.

Contact Us

If you would like to contact us with questions or concerns about our privacy policies and practices, you may contact us via any of the following methods:

Email: info@xecurify.com

Phone: +1 978 658 9387

Form: Contact Us / Visit miniOrange

Hello there!

Need Help? We are right here!

support