Legal

Privacy policy

What SIDES LABS does with personal data — and, just as deliberately, what it does not do.

Version
1.0
In force since
Document
Privacy policy

1. Controller and contact

The controller for the processing described here is:

SimplyDelivery GmbH
Wilhelm-Kabus-Str. 70, Haus 34.3
10829 Berlin
Germany
[email protected]

The full statutory details are in the imprint.

No data protection officer has been appointed. We are below the threshold in §38 BDSG and none of the cases in Art. 37(1) GDPR applies. Requests about your data go to the address above and are handled by the management; if that changes, this section names the officer and this document gets a new version.

You may also complain to a supervisory authority. The one responsible for us is the Berliner Beauftragte für Datenschutz und Informationsfreiheit.

2. What we hold, and why

SIDES LABS is a platform for companies. What we hold is business contact data — but a named person at a company is still a natural person, so the GDPR applies to all of it unchanged.

Categories of personal data, and the purpose each serves
Category What it is Why we hold it
Partner user identity name, business e-mail address, role, language preference to give you an account and to address you in the right language
Authentication password hash, session hashes, two-factor secret, backup codes to sign you in and to keep somebody else from doing so
Company data company name, address, VAT or tax identification number, legal form to conclude and invoice the partner contract
Billing subscription, invoices, billing contact to charge for a paid tier and to meet retention obligations
Behaviour login log, audit log, feature-request votes to investigate abuse and to show who changed what
Public content partner profile, app listings, blog posts, published reviews because publishing it is the purpose of the marketplace
Newsletter e-mail address, consent state, consent timestamp to send the developer newsletter, and to prove you asked for it

Visiting a public page needs none of this. You can read the marketplace, the blog, the changelog and the pricing without an account and without telling us who you are.

3. Lawful bases

  • Contract (Art. 6(1)(b) GDPR) — registration, the account, the tier, billing, and publishing your partner profile and app listings. Publishing is not a favour we do you: it is what you signed up for.
  • Legitimate interest (Art. 6(1)(f) GDPR) — security logging, abuse prevention and rate limiting. Our interest is in a platform that is not taken over; the data involved is the minimum that serves it.
  • Consent (Art. 6(1)(a) GDPR) — the newsletter and marketing mail, each asked for separately and each revocable on its own. A single checkbox bundling them with the terms would not be a valid consent, so there is not one.
  • Legal obligation (Art. 6(1)(c) GDPR) — keeping invoices for the period German commercial and tax law requires.

Every consent is stored as a record, not as a tick: what was consented to, which version of which document, when, and a hashed form of the address it came from. Withdrawing a consent does not delete that record — it marks it withdrawn, because proving that a consent existed when a mail was sent requires the history.

4. Who else sees it

Each of the following is a processor acting on our instructions under a data processing agreement. The list is complete for the services this platform actually uses today.

Processors, what each receives, and where it processes
Service Receives Processing location
Amazon Web Services everything stored, as data at rest EU region, encrypted with managed keys
MailJet e-mail address, name, the content of the mail we send you EU
Cloudflare R2 the bytes of images you upload — logos, screenshots, gallery media EU
Memcachier no personal data: a hashed key and a counter, for rate limiting EU

Two calls that leave our servers and carry no identity

When you choose a password, we check whether it appears in known breach corpora. Only the first five characters of its SHA-1 hash are sent, and the service answers with every hash that begins with those five — so it never learns your password, your address, or which of the answers was yours. If the service is unreachable the registration proceeds; a breach check must not be able to lock you out.

Usage statistics for your apps are read from the SIDES platform. What travels there is an app identifier and a date; what comes back is a count. No SIDES customer's identity is involved in either direction.

Beyond that, we pass personal data to third parties only where we are legally obliged to.

5. What this site does not do

This is here because the absences are the part you cannot verify by reading a page, and they are deliberate design decisions rather than things we have not got round to.

  • Nothing on this site is loaded from a third party. Fonts, images, icons, styles and scripts all come from our own servers. There is no content delivery network, no web font service, no embedded map and no embedded video. A request to a third party would disclose your IP address to them, and an IP address is personal data.
  • There is no analytics, no tracking pixel and no advertising. We do not measure you across pages, we do not build a profile, and there is nothing here to opt out of.
  • There is no consent banner, and that is a consequence of the two points above rather than an omission. We set nothing that needs consent.
  • No automated decision-making in the sense of Art. 22 GDPR. A person at SIDES decides whether an app is published, and a rejection says why.

6. Cookies and local storage

One cookie, set only after you sign in: the refresh token. It is marked HttpOnly, Secure and SameSite=Strict, it is scoped to the single endpoint that renews a session, it is replaced every time it is used, and signing out revokes it. It is strictly necessary to keep you signed in across a page reload, so it needs no consent — and it is set only for somebody who has chosen to sign in.

Your browser also keeps three preferences locally: the theme you chose, the language you chose, and — once you are signed in to the partner portal — whether its sidebar is collapsed. They stay in your browser, they are never sent to us, and clearing your site data removes them.

7. How long we keep it

Retention periods by category
Data Retained
Account data for the life of the contract
Invoices and billing records ten years, as German commercial and tax law requires
Security and audit logs twelve months
Login logs six months
Sessions until they expire, then removed
Newsletter subscription until you revoke it; the consent record outlives the revocation
Sent mail ninety days after delivery finishes, then the address is removed and only the delivery record remains. Where a mail carried a single-use link, its content is erased the moment delivery finishes rather than ninety days later

8. Your rights

You have the right to access your data (Art. 15), to have it corrected (Art. 16), to have it erased (Art. 17), to restrict processing (Art. 18), to receive it in a machine-readable form (Art. 20) and to object (Art. 21). Where processing rests on consent, you can withdraw it at any time, with effect for the future.

What erasure means here, stated plainly

Erasing a user account is carried out as anonymisation rather than as a row disappearing. The personal fields are overwritten; what remains is a record that an action happened, with no person attached to it. Two things make that necessary rather than convenient: an audit trail that can be emptied is not an audit trail, and marketplace history that a departing person can erase would rewrite what SIDES customers were shown. The result holds no personal data, which is why it can be kept.

Write to [email protected] to exercise any of these. We answer within the period Art. 12(3) GDPR allows.

9. How it is protected

  • All traffic runs over TLS; plain HTTP is redirected.
  • Passwords are stored as Argon2id hashes. Sessions, invitation tokens and password-reset tokens are stored as hashes too, never as the value that was issued — so a copy of the database does not contain a usable credential.
  • Two-factor secrets and backup codes are encrypted at rest, as are the tax identifiers in a partner's company record.
  • A partner sees only their own company's data. That is enforced on the server for every request, not by what the interface offers to show you.
  • Logs carry identifiers for correlation and never passwords, tokens, session values or two-factor secrets.

10. Changes to this policy

This document carries a version, shown at the top. When it changes materially, the version changes with it, and any consent that rested on the previous version is asked for again rather than assumed to carry over. Your consent record stores the version that was in force when you gave it, so what you agreed to stays answerable after the document has moved on.