Privacy policy
Last updated: 31 August 2026
ID Side sells the machinery that proves a person's choices were honoured. A policy that was vague about our own handling of data would undo that argument, so this one is specific — including about where it stops.
Two roles, and the difference decides who you write to
Where we decide — controller
For the people who deal with ID Side directly: someone reading this site, an operator signing in to a customer's dashboard, an employee of a customer organization opening their transparency page, someone writing to us through the contact form, someone holding an ID Side account for their own preferences. We choose what is collected and why, so we are the controller within the meaning of Article 4(7) GDPR.
Where a customer decides — processor
For what a customer's own users generate through the SDK — a pseudonym, a recorded answer, a signed token, a ledger entry — that customer decides. We act on their instructions and for no purpose of our own: we do not use it to build a profile, to train a model, or to sell anything. We are their processor within the meaning of Article 4(8) GDPR.
One consequence, because customers ask it first: the prompts and responses your users exchange with an AI provider never reach us. The SDK sends a hash of the request. A hash is what we authorize against, what we sign, and what we write to the ledger — we could not read a prompt if we were ordered to.
What we hold, and why
Reading this site
One session cookie, described in the legal notice. No measurement of any kind, so nothing about this visit is recorded beyond the server logs our infrastructure keeps.
A dashboard or console account
An email address, a password digest, sign-in timestamps, and which organization the account belongs to. Access by ID Side staff to a named customer is recorded with a mandatory reason, in a table the database will not let anyone rewrite.
Writing to us
The address you give and the message you send. Nothing more — we do not ask your name, because answering you does not require one.
An ID Side account for your own preferences
An email address and the preferences you set. You can read everything we hold about you, download it, or delete the account from your own account page: no request to us, no waiting for an answer.
An employee of a customer organization
Your employer decided what applies to you, and we hold that decision plus counts of your activity. What your employer sees about you is exactly what your own transparency page shows you — one list, read by both screens, so they cannot disagree. The content of what you write is not among it.
What a customer entrusts to us
A pseudonym derived from the identifier the customer's application supplied, the answer recorded against it, the parameters the SDK forced on the provider call, and an entry in an append-only, hash-chained ledger. Plus the token that proves the call was authorized: it carries a request hash, a single-use nonce, a one-hour lifetime, the source of the decision and the legal basis. Never the request.
The pseudonym is computed per application, under a secret belonging to that application, and it does not invert. The same person using two customers' products is two unrelated pseudonyms, and neither can be turned back into an identifier. That is the point: a profile spanning customers cannot be assembled, including by us, including on request.
Legal bases
- Performance of a contract, Article 6(1)(b): serving the dashboard, the API, and the accounts they depend on.
- Legitimate interest, Article 6(1)(f): keeping the service standing and honest — rate limits, audit records of staff access, fraud detection on call patterns — and answering someone who writes to us.
- Legal obligation, Article 6(1)(c): accounting and tax records.
- Where we act as a processor the basis is the customer's, not ours. Where their users are asked, the answer is theirs and the basis is consent. Where an organization sets a policy for the people working under it, the basis is legitimate interest or a contractual obligation — never consent, because an employee's answer to their employer is not freely given, and the product refuses to sign a proof claiming otherwise.
How long
- A sign-in link: fifteen minutes. An invitation: three days.
- A message sent through the contact form: twelve months.
- A dashboard, console or ID Side account: as long as the account exists.
- Counters recording how often a subject could not be named: four hundred days. They count calls, never people, and hold no pseudonym.
- The ledger and the signed tokens: kept. The next section is about that, because it is the one place where this policy says no.
The one thing we will not delete
The ledger is an append-only hash chain, and the database refuses a deletion from it — not by convention, by a trigger. That refusal is the product. A customer's proof that they honoured someone's choice is worth nothing if the party being audited can quietly remove an entry, and that has to include removing one because we were asked to.
So an erasure request does not remove ledger entries or signed tokens. It removes the identity: your address, your account, and the link between you and each pseudonym. What remains is chained, verifiable, and no longer attached to anything we hold that names you. Your answers to each application become the rule again, exactly as though no account had ever been linked.
Where it sits
In France, on European infrastructure, with the signing keys held in a key management service in the European Union which cannot export them. We do not transfer personal data outside the European Union.
Where the SDK runs, it is your infrastructure calling an AI provider under your own contract with that provider. Those calls and any transfer they involve are yours, not ours: we see a hash and never the content.
Your rights
Access (Article 15), rectification (Article 16), erasure (Article 17), restriction (Article 18), portability (Article 20), objection (Article 21), and not being subject to a decision based solely on automated processing (Article 22). Where consent is the basis, you can withdraw it at any time, and withdrawing it is as easy as giving it.
For an ID Side account, access and erasure are buttons on your own account page rather than a request to us. The export states in the file itself what it declines to include and why; the erasure asks you to retype your address and then runs, with no cooling-off period, because a delay would make deletion a promise rather than an act.
Anything else: dpo@idside.eu. If your data reached us through a company's product, that company is the controller and the request belongs with them — tell us and we will pass it on, but they decide, not us.
Complaints
You can complain to the CNIL — Commission nationale de l'informatique et des libertés, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France — or to the supervisory authority of the EU country where you live or work.