Effective 20 August 2026
Privacy Policy
This policy explains what data Sidcom processes across everything we operate — our MCP integrations, including the Claude, ChatGPT, and Microsoft Copilot Fortnox Connectors, the Sidcom account portal, and this website — and how we handle it.
1. Who we are and what this policy covers
Sidcom AB ("Sidcom", "we") is a Swedish company. This is our single privacy policy, and it covers everything we operate: the MCP integration servers at sidcom.app and its integration subdomains, the Sidcom account portal at business.sidcom.ai, the products sold through them, and this website. You can reach us at hello@sidcom.ai.
2. Our role under GDPR
Responsibility is split by category. For business data in transit — invoices, customer records, vouchers, files, and anything else that passes through while a tool call executes — you are the controller and we act as your processor. That data is processed in real time on your instruction and never stored. A data processing agreement (DPA) covering this processing is available on request; contact hello@sidcom.ai.
For authentication tokens, account information, activity records, payment records, and technical data, we are the controller, since this is our own customer relationship and we decide the purposes of that processing.
3. What we process
Authentication tokens. For OAuth-based integrations we store the access and refresh tokens issued by the provider. For credential-based integrations the credentials you enter are sent straight to the provider in exchange for an access token; we do not store the credentials themselves, only the resulting token.
MCP session tokens issued to your AI client (such as Claude, ChatGPT, or Microsoft Copilot) so it can call an integration on your behalf.
Account information, where a product is sold with a Sidcom account: your email address, your name if you give one, your organisation and its billing details, who belongs to it and in what role, and which AI clients are connected.
Activity records — an account activity log covering events such as an organisation being created, a member joining or being removed, and a company being linked or unlinked — so you can see what happened in your own organisation.
Business data in transit: whatever your AI client requests through an integration. It is not persisted, not logged in identifiable form, and not shared.
Payment information. For paid subscriptions bought directly from us, we bill you by card or by invoice. Where you pay by card, our payment provider processes your card details and we never see or store card numbers. Where you pay by invoice, we keep the billing details needed to issue and follow up the invoice. Either way we keep the subscription's status, seat count, and invoice history. Where a product is sold through a marketplace instead, such as the Fortnox Marketplace, that marketplace handles payment under its own terms.
Technical data: IP addresses and standard request metadata captured by our hosting infrastructure for security, abuse prevention, and reliability. Operational logs hold metadata only — timestamps, tool names, response codes — never request or response contents.
4. Why we process it
We process this data to authenticate you to the providers you connect and to your AI client, to execute the API calls you authorise, to determine what your organisation is entitled to use and to bill for it, to prevent abuse and keep the service available, and to send you essential messages about your account or security.
5. Your business data
The service is transit infrastructure. Business data flowing through an API call is not persisted by the service; it is delivered to the connected provider and not retained as a copy or backup. Content can reach the service in three ways: through your AI client, as a file we fetch on your behalf from a URL you designate, or as a direct upload to a one-time upload address created by your session. In all three cases the content is forwarded to the provider immediately and not stored. Uploaded files may be inspected programmatically, in memory, to detect format issues we know cause problems downstream and warn you about them; the content is not retained for this.
6. Upload links and filenames
Direct uploads use a single-use link that expires after ten minutes. The link contains an encrypted ticket that includes your session id and the name of the file, so treat upload links as secrets and do not share them. Filenames travel with the file to the connected provider; avoid putting personal data, such as personal identity numbers, in filenames.
7. Short-lived operational caches
To make retried write operations safe, the provider's response to a create or action call may be cached for up to 60 seconds before it expires automatically. Fingerprints of used upload links (a cryptographic hash, no content) are kept for up to 15 minutes to prevent reuse. These caches exist for reliability only, expire automatically, and are held in Cloudflare KV, our existing processor; no new subprocessor is involved.
8. Retention
Connector OAuth tokens are stored in Cloudflare KV and retained according to each provider's refresh cycle — typically up to 44 days for Fortnox. Credential-flow tokens are retained for up to 365 days, with automatic re-authentication on expiry.
Tokens belonging to a Sidcom account — where you have signed in and linked a company to your organisation — are encrypted before storage and kept in Cloudflare D1 for as long as the link exists. Removing the link, or leaving the organisation, deletes them.
Account information and activity records are stored in a managed Postgres database for as long as your organisation exists, and are removed when it is deleted. Operational logs are retained for 3 days. Business data passing through a tool call is not persisted at all.
You can delete stored tokens at any time by revoking access at the provider, by removing the link in the product, or by contacting us.
9. Subprocessors
We rely on the following processors to run the service, each contractually bound to handle data only on our instructions. Cloudflare provides hosting, token storage, DNS, and TLS. Supabase provides sign-in and the account database. Stripe provides card payment and subscription billing where you buy directly from us and pay by card.
Connected providers such as Fortnox, and AI clients such as Claude, ChatGPT, and Microsoft Copilot, are not our subprocessors. They act as independent controllers of the data you exchange with them, under their own privacy policies.
10. Where your data is stored
Account data — your organisation, its members, the activity log, and subscription records — is stored in the European Union, in Stockholm, Sweden. The database holding linked companies and their tokens is created with an EU jurisdiction, which pins where it runs and stores data to the European Union.
Connector session tokens are held in our hosting provider's global key-value store, which replicates to the edge locations serving your requests, and support access by our processors may occur outside the EEA. Where personal data leaves the EEA, transfers are governed by Standard Contractual Clauses or equivalent safeguards.
11. Security
All traffic is encrypted with TLS, provider tokens are encrypted before they are written to storage, and tokens are verified on every request. No system is perfect — report security issues to hello@sidcom.ai.
If a personal data breach affects your data, we will notify you without undue delay and include what you need for your own notification to the supervisory authority — in Sweden, IMY — within the 72-hour deadline under Article 33 GDPR.
12. Your rights
If you are in the EEA, the UK, or Switzerland, you may request access to, correction of, portability of, or deletion of your personal data, and you may ask us to restrict or object to processing. Contact hello@sidcom.ai to exercise these rights. You also have the right to lodge a complaint with your supervisory authority, which in Sweden is IMY.
13. Changes
We may update this policy as the service evolves. Material changes will be reflected by the effective date above.
14. Contact
Questions about privacy or your data: hello@sidcom.ai.