MCP CONNECTOR SHINE - TERMS OF SERVICE

These Terms of Use take effect on 2026-10-05.

Preamble

These Terms of Service (the "Terms") govern access to and use of the Shine MCP Connector (the "Service"), which allows the Subscriber to connect the invoicing and accounting features provided by Shine to a language model (LLM) or artificial intelligence agent of their choice (the "AI Agent").

These Terms complete, without replacing, the Terms of Service of the Shine application (the "Terms of Service") to which the Subscriber is already a party.

In the event of any contradiction, the Terms of Service shall prevail.

Activating the Service constitutes full and unconditional acceptance of these Terms.

Article 1 - Definitions

In these Terms, capitalised terms have the meaning given to them below:

  • "Shine" means the Shine Group entity with which the Subscriber has entered into its Subscription, as identified in Section 1.1 of the Terms of Service according to the Subscriber's country. For the purposes of the Service, Shine France, a simplified joint-stock company with a sole shareholder registered with the Paris Trade and Companies Register under number 828 701 557, whose registered office is at 122 rue Amelot, 75011 Paris, acts as the publisher of the Service, and Shine Denmark ApS acts, where applicable, as the Registered Agent for the electronic invoicing (e-invoicing/e-reporting) features accessible via the MCP Connector.
  • "Subscriber" means the Subscriber within the meaning of the Terms of Service, or any duly authorised person acting on its behalf, who has activated the Service.
  • "Terms of Service" means the Terms of Service of the Shine application, which govern the Subscriber's Subscription to the invoicing and accounting services, and supplement these Terms.
  • "MCP Connector" means the Model Context Protocol technical interface developed by Shine, allowing an AI Agent to access, within the Access Scope defined by the Subscriber, data and features relating to the invoicing and accounting Services.
  • "AI Agent" / "LLM" means the language model, agent or artificial intelligence system chosen, configured and operated by the Subscriber under its sole responsibility, which the Subscriber connects to the Service. Shine is neither the publisher, the provider, nor the operator of the AI Agent.
  • "LLM Provider" means the third party publishing or operating the AI Agent (for example: Anthropic, OpenAI, Mistral, or any other). The LLM Provider is a processor of the Subscriber, not of Shine.
  • "Access Scope" / "Permissions" means the set of authorisations (scopes) defined by the Subscriber, determining the data that can be viewed and, where applicable, the Operations that can be carried out by the AI Agent via the MCP Connector.
  • "Read Operation" means any consultation, aggregation or export of data from the invoicing and accounting Services, with no effect on such data.
  • "Write Operation" means any action whereby the AI Agent reads the necessary data and then prepares or edits, at the Subscriber's request, a draft relating to the invoicing Services (in particular a draft invoice or a proposed accounting categorisation). Such a draft has no effect until it has been validated by the Subscriber personally, from the Shine interface, under the conditions set out in Article 2.2 of these Terms.
  • "Invoicing Data" means data relating to the Subscriber and to the invoicing and accounting Services, including data entered or generated as part of those Services (in particular invoices, customers, suppliers, accounting entries).
  • "Third-Party Data" means personal data or data covered by a duty of confidentiality relating to persons other than the Subscriber, that may be accessible via the Service (in particular payment beneficiaries, employees appearing on a payslip, or customers or suppliers being invoiced).
  • "Request" means any request submitted to the MCP Connector by the AI Agent.

Article 2 - Description and architecture of the Service

2.1 The MCP Connector is a technical tool allowing the Subscriber to open, under its own control and at its own request, an access channel between the invoicing and accounting Services and the AI Agent it has chosen.

2.2 Shine's role. Shine provides and secures the MCP Connector and makes available, within the Access Scope defined by the Subscriber, Invoicing Data as well as features, including, where applicable, the ability for the AI Agent to read the necessary data and to prepare or edit, at the Subscriber's request, drafts of a Write Operation (in particular a draft invoice or a proposed accounting categorisation). Such a draft has no effect vis-à-vis third parties until it has been expressly validated by the Subscriber personally, from the Shine interface, in accordance with the arrangements specific to the Operation concerned.

Shine exercises no control over the Subscriber's AI Agent, nor over the instructions given by the Subscriber or the AI Agent, nor over the processing carried out by the LLM, nor over the content of the drafts or other outputs produced by the AI Agent, nor over the decisions the Subscriber makes in light of such outputs. The behaviour of an AI Agent is inherently non-deterministic and may produce erroneous, incomplete, unpredictable or inappropriate results. It is for the Subscriber to review such content before any validation.

2.3 Data transmission. The Subscriber acknowledges and accepts that, by the nature of the Service, Invoicing Data and, where applicable, Third-Party Data technically transit through Shine's infrastructure to the AI Agent, solely at the Subscriber's request and under its control, within the limits of the Access Scope it has defined.

2.4 Configurable Access Scope. The Subscriber determines, upon activating the Service, the Access Scope applicable to Read Operations and, where applicable, to the preparation and editing of drafts under a Write Operation. The Subscriber may revoke this access at any time by deactivating the MCP Connector. Any change to the Access Scope is made by disconnecting and then reactivating the Service, at which point the Subscriber redefines the Permissions granted to the AI Agent.

Article 3 - Access, authentication and management of permissions

3.1 Access to the Service requires an active Subscription to the Shine invoicing Services. Activation of the MCP Connector is initiated from the interface of the AI Agent chosen by the Subscriber, by means of an OAuth authorisation protocol. It only becomes effective once the Subscriber has authenticated with Shine and approved, on the authorization screen presented by Shine, the Access Scope granted to the AI Agent. This approval constitutes acceptance of these Terms within the meaning of the Preamble.

3.2 Credentials and access keys. The Subscriber is solely responsible for the confidentiality of the credentials, tokens and keys, or the OAuth authorisation, allowing the AI Agent to access the Service. Any Request made using these elements is deemed to originate from the Subscriber. The Subscriber shall not share these elements with any unauthorised third party.

3.3 Revocation. The Subscriber may interrupt the AI Agent's access at any time. Shine provides a mechanism for the immediate revocation of Permissions.

Article 4 - Nature of the Service and the Subscriber's responsibility for its use of AI

4.1 The Service is a management and consultation support tool. It does not constitute advice of any kind (accounting, tax, legal or financial), a personalised recommendation, or an approval by Shine of the actions carried out via the AI Agent.

4.2 The Subscriber has sole control over the AI Agent it connects: its choice, configuration, settings, level of autonomy, the instructions it gives it and the control measures it puts in place. The Subscriber bears full responsibility for the consequences of the AI Agent's actions and outputs passing through the Service.

4.3 The Subscriber acknowledges having been informed of the fallible and non-deterministic nature of generative AI systems and undertakes to verify, before any legal or financial effect, the relevance and accuracy of the actions proposed or triggered by the AI Agent.

Article 5 - Subscriber's obligations

5.1 Professional status warranty. The Subscriber warrants that it meets the eligibility conditions for the Services set out in Sections 1.4 and 3.7 of the Terms of Service.

5.2 Security. The Subscriber takes all reasonable measures to preserve the security of its access. The Subscriber acknowledges that connecting an autonomous AI Agent to the invoicing and accounting Services constitutes a particular risk, requiring enhanced precautionary measures.

5.3 Prudent configuration of the AI Agent. The Subscriber undertakes not to grant the AI Agent a level of autonomy disproportionate to the risks involved. Allowing an AI Agent to trigger Write Operations with significant legal effect (in particular the issuance of an invoice) without adequate supervision or control measures constitutes a breach of the Subscriber's security obligations.

5.4 Third-Party Data, confidentiality and intellectual property. The Subscriber warrants that it holds all the rights and legal bases necessary to make Third-Party Data accessible to the AI Agent, and to have it processed by the LLM Provider. It is solely responsible for complying with its own obligations towards such third parties (notice, legal basis, trade secrets, intellectual property, any duty of confidentiality it owes).

5.5 Prohibited uses. The following are in particular prohibited: any unlawful use or use contrary to public policy; any circumvention of security measures or Request limits; any attempt at unauthorised access; the introduction of malicious code; use of the Service for money laundering, terrorist financing, fraud, or circumvention of Shine's anti-money-laundering and counter-terrorist-financing (AML/CFT) obligations; and resale or unauthorised sharing of access.

5.6 Subscriber's regulatory compliance. The Subscriber is solely responsible for complying, in its use of the AI Agent, with the obligations incumbent on it under applicable regulations, in particular Regulation (EU) 2024/1689 (the AI Act), in its capacity as a deployer, within the meaning of Article 3(4) of that regulation, of an artificial intelligence system that it uses under its own authority in the course of its professional activity. It is for the Subscriber, in particular, to determine whether such use falls within the enhanced obligations applicable to deployers of high-risk AI systems within the meaning of Annex III of that regulation.

Article 6 - Protection of personal data

6.1 Qualification of roles. The parties qualify their respective roles as follows, depending on the nature of the data concerned:

  • (a) for data relating to the identification of the Subscriber and its Subscription (account/subscription data within the meaning of Section 11.1 of the Terms of Service), Shine is the data controller;
  • (b) for data entered by the Subscriber in the course of its use of the invoicing and accounting Services (Section 11.2 of the Terms of Service and the attached Data Processing Agreement), Shine acts as processor on behalf of the Subscriber for making such data available via the MCP Connector, on the Subscriber's documented instructions constituted by activation of the Service and configuration of the Access Scope;
  • (c) the Subscriber is an independent data controller for all processing it carries out by means of the AI Agent, from the point the data is transmitted by the MCP Connector;
  • (d) the LLM Provider acts as processor on behalf of the Subscriber, and it is for the Subscriber to put in place an appropriate processing agreement with it.

6.2 No joint controllership. Each party is responsible for its own processing under the roles qualified in Article 6.1.

6.3 Impact assessment. Shine carries out its own data protection impact assessment for the processing for which it is controller. The Subscriber carries out its own assessment for the processing for which it is responsible, in particular with regard to its use of the AI Agent.

6.4 Third-Party Data. The Subscriber acknowledges that the invoicing and accounting Services may contain Third-Party Data and that it is responsible for ensuring the lawfulness of its transmission to the AI Agent. Shine cannot be held liable for the processing of Third-Party Data carried out by or for the Subscriber via the AI Agent.

6.5 The processing for which Shine is the data controller is described in the Privacy Policy. The processing for which Shine acts as processor is governed by the Data Processing Agreement referenced in the Terms of Service. These documents form an integral part of these Terms as regards their respective scope.

Article 7 - Confidentiality

7.1 Confidentiality of invoicing data. For data relating to the invoicing and accounting Services, the confidentiality of such data is ensured in accordance with article 6 (Confidentiality) of the Data Processing Agreement referenced in the Terms of Service.

7.2 Activation of the Service does not relieve the Subscriber of its own obligations with regard to Third-Party Data. The Subscriber shall indemnify Shine against any third-party claim in this respect.

Article 8 - Intellectual property

8.1 The MCP Connector, its code, interfaces and documentation are protected under the conditions set out in Section 6 of the Terms of Service. The database underlying the MCP Connector further benefits from the specific protection of database producers' sui generis rights.

8.2 Shine grants the Subscriber a personal, non-exclusive, non-transferable and revocable licence to use the Service, for the duration of the contractual relationship and within the limits of these Terms.

8.3 Prohibitions. The Subscriber shall not, in particular: disassemble, decompile, decrypt, extract, reuse, copy or, more generally, reproduce, represent, distribute or otherwise use the MCP Connector, in whole or in part, without Shine's authorisation; extract or reuse a qualitatively or quantitatively substantial part of the database; or use the Service to train, fine-tune or evaluate any AI model other than as part of the authorised use.

8.4 The Subscriber retains the rights to its own content and data. No ownership right is transferred to Shine over such content or data.

Article 9 - Security, operational resilience and incidents

9.1 Shine implements appropriate technical and organisational security measures, as part of its information and communication technology risk management framework.

9.2 The Subscriber shall promptly notify Shine of any compromise, abnormal use or incident affecting the Service or its access.

9.3 Shine may suspend the AI Agent's access on a precautionary basis in the event of detected abnormal behaviour (unusual Request volume, atypical operation pattern, indications of fraud or compromise), for as long as necessary to carry out the required checks, without such suspension giving rise to any liability on its part.

Article 10 - Liability

Shine's liability under the Service, including its limits and exclusions, is governed by Section 8 of the Terms of Service.

Article 11 - Subscriber's warranty

The Subscriber shall indemnify Shine against any third-party claim, action or judgment (in particular from persons concerned by Third-Party Data, beneficiaries, employees or customers of the Subscriber) resulting from its use of the Service, the configuration of its AI Agent, or a breach of its obligations under these Terms, applicable laws or third-party rights.

Article 12 - Availability, evolution and duration

12.1 Shine endeavours to ensure the availability of the Service without guaranteeing it. Interruptions may occur for maintenance, updates or incidents.

12.2 Shine may develop, restrict or discontinue the Service, subject to reasonable notice except in cases of urgency or legal obligation.

12.3 The Service is provided for the duration of the contractual relationship. The Subscriber may deactivate the MCP Connector at any time.

Article 13 - Suspension and termination

13.1 Shine may suspend or terminate access to the Service, with immediate effect, in the event of a breach of these Terms, fraudulent or abusive use, a security risk, or grounds relating to its legal obligations, for reasons consistent with those set out in Sections 3.6, 5.7 and 5.8 of the Terms of Service. 

13.2 Termination of the Service does not terminate the Subscriber's Subscription to the invoicing and accounting Services, which is governed by the Terms of Service.

Article 14 - Amendment of these Terms

Shine may amend these Terms, in particular to reflect developments in the Service or in applicable regulation, by updating them on its website or by notifying the Subscriber. If the amendments have a significant impact on the Subscriber's rights or obligations, Shine will inform the Subscriber beforehand and specifically. The Subscriber may then deactivate the MCP Connector before the amendments take effect. Continued use of the Service after that date constitutes acceptance.

Article 15 - Governing law and jurisdiction

These Terms are governed by, and any dispute shall be subject to the jurisdiction applicable to, the same Shine Group entity with which the Subscriber has entered into its Subscription for the Shine invoicing Services, as identified in Section 1.1 of the Terms of Service. The governing law and competent courts accordingly vary depending on the contracting entity set out in that table.

Article 16 - Miscellaneous

16.1 Severability. The invalidity of one clause does not affect the others.

16.2 No waiver. Failure to exercise a right does not constitute a waiver of that right.

16.3 Assignment. Assignment of these Terms follows the assignment regime applicable under Section 13 of the Terms of Service, of which these Terms constitute an ancillary part.

16.4 Entire agreement. These Terms, the Privacy Policy and the Terms of Service constitute the entire agreement between the parties on their subject matter.