Legal
Privacy policy
What SIDES LABS does with personal data — and, just as deliberately, what it does not do.
1. Controller and contact
The controller for the processing described here is:
SimplyDelivery GmbHWilhelm-Kabus-Str. 70, Haus 34.3
10829 Berlin
Germany
[email protected]
The full statutory details are in the imprint.
No data protection officer has been appointed. We are below the threshold in §38 BDSG and none of the cases in Art. 37(1) GDPR applies. Requests about your data go to the address above and are handled by the management; if that changes, this section names the officer and this document gets a new version.
You may also complain to a supervisory authority. The one responsible for us is the Berliner Beauftragte für Datenschutz und Informationsfreiheit.
2. What we hold, and why
SIDES LABS is a platform for companies. What we hold is business contact data — but a named person at a company is still a natural person, so the GDPR applies to all of it unchanged.
| Category | What it is | Why we hold it |
|---|---|---|
| Partner user identity | name, business e-mail address, role, language preference | to give you an account and to address you in the right language |
| Authentication | password hash, session hashes, two-factor secret, backup codes | to sign you in and to keep somebody else from doing so |
| Company data | company name, address, VAT or tax identification number, legal form | to conclude and invoice the partner contract |
| Billing | subscription, invoices, billing contact | to charge for a paid tier and to meet retention obligations |
| Behaviour | login log, audit log, feature-request votes | to investigate abuse and to show who changed what |
| Public content | partner profile, app listings, blog posts, published reviews | because publishing it is the purpose of the marketplace |
| Newsletter | e-mail address, consent state, consent timestamp | to send the developer newsletter, and to prove you asked for it |
Visiting a public page needs none of this. You can read the marketplace, the blog, the changelog and the pricing without an account and without telling us who you are.
3. Lawful bases
- Contract (Art. 6(1)(b) GDPR) — registration, the account, the tier, billing, and publishing your partner profile and app listings. Publishing is not a favour we do you: it is what you signed up for.
- Legitimate interest (Art. 6(1)(f) GDPR) — security logging, abuse prevention and rate limiting. Our interest is in a platform that is not taken over; the data involved is the minimum that serves it.
- Consent (Art. 6(1)(a) GDPR) — the newsletter and marketing mail, each asked for separately and each revocable on its own. A single checkbox bundling them with the terms would not be a valid consent, so there is not one.
- Legal obligation (Art. 6(1)(c) GDPR) — keeping invoices for the period German commercial and tax law requires.
Every consent is stored as a record, not as a tick: what was consented to, which version of which document, when, and a hashed form of the address it came from. Withdrawing a consent does not delete that record — it marks it withdrawn, because proving that a consent existed when a mail was sent requires the history.
4. Who else sees it
Each of the following is a processor acting on our instructions under a data processing agreement. The list is complete for the services this platform actually uses today.
| Service | Receives | Processing location |
|---|---|---|
| Amazon Web Services | everything stored, as data at rest | EU region, encrypted with managed keys |
| MailJet | e-mail address, name, the content of the mail we send you | EU |
| Cloudflare R2 | the bytes of images you upload — logos, screenshots, gallery media | EU |
| Memcachier | no personal data: a hashed key and a counter, for rate limiting | EU |
Two calls that leave our servers and carry no identity
When you choose a password, we check whether it appears in known breach corpora. Only the first five characters of its SHA-1 hash are sent, and the service answers with every hash that begins with those five — so it never learns your password, your address, or which of the answers was yours. If the service is unreachable the registration proceeds; a breach check must not be able to lock you out.
Usage statistics for your apps are read from the SIDES platform. What travels there is an app identifier and a date; what comes back is a count. No SIDES customer's identity is involved in either direction.
Beyond that, we pass personal data to third parties only where we are legally obliged to.
5. What this site does not do
This is here because the absences are the part you cannot verify by reading a page, and they are deliberate design decisions rather than things we have not got round to.
- Nothing on this site is loaded from a third party. Fonts, images, icons, styles and scripts all come from our own servers. There is no content delivery network, no web font service, no embedded map and no embedded video. A request to a third party would disclose your IP address to them, and an IP address is personal data.
- There is no analytics, no tracking pixel and no advertising. We do not measure you across pages, we do not build a profile, and there is nothing here to opt out of.
- There is no consent banner, and that is a consequence of the two points above rather than an omission. We set nothing that needs consent.
- No automated decision-making in the sense of Art. 22 GDPR. A person at SIDES decides whether an app is published, and a rejection says why.
7. How long we keep it
| Data | Retained |
|---|---|
| Account data | for the life of the contract |
| Invoices and billing records | ten years, as German commercial and tax law requires |
| Security and audit logs | twelve months |
| Login logs | six months |
| Sessions | until they expire, then removed |
| Newsletter subscription | until you revoke it; the consent record outlives the revocation |
| Sent mail | ninety days after delivery finishes, then the address is removed and only the delivery record remains. Where a mail carried a single-use link, its content is erased the moment delivery finishes rather than ninety days later |
8. Your rights
You have the right to access your data (Art. 15), to have it corrected (Art. 16), to have it erased (Art. 17), to restrict processing (Art. 18), to receive it in a machine-readable form (Art. 20) and to object (Art. 21). Where processing rests on consent, you can withdraw it at any time, with effect for the future.
What erasure means here, stated plainly
Erasing a user account is carried out as anonymisation rather than as a row disappearing. The personal fields are overwritten; what remains is a record that an action happened, with no person attached to it. Two things make that necessary rather than convenient: an audit trail that can be emptied is not an audit trail, and marketplace history that a departing person can erase would rewrite what SIDES customers were shown. The result holds no personal data, which is why it can be kept.
Write to [email protected] to exercise any of these. We answer within the period Art. 12(3) GDPR allows.
9. How it is protected
- All traffic runs over TLS; plain HTTP is redirected.
- Passwords are stored as Argon2id hashes. Sessions, invitation tokens and password-reset tokens are stored as hashes too, never as the value that was issued — so a copy of the database does not contain a usable credential.
- Two-factor secrets and backup codes are encrypted at rest, as are the tax identifiers in a partner's company record.
- A partner sees only their own company's data. That is enforced on the server for every request, not by what the interface offers to show you.
- Logs carry identifiers for correlation and never passwords, tokens, session values or two-factor secrets.
10. Changes to this policy
This document carries a version, shown at the top. When it changes materially, the version changes with it, and any consent that rested on the previous version is asked for again rather than assumed to carry over. Your consent record stores the version that was in force when you gave it, so what you agreed to stays answerable after the document has moved on.

