ID Side

Privacy policy

Last updated: 31 August 2026

ID Side sells the machinery that proves a person's choices were honoured. A policy that was vague about our own handling of data would undo that argument, so this one is specific — including about where it stops.

Two roles, and the difference decides who you write to

Where we decide — controller

For the people who deal with ID Side directly: someone reading this site, an operator signing in to a customer's dashboard, an employee of a customer organization opening their transparency page, someone writing to us through the contact form, someone holding an ID Side account for their own preferences. We choose what is collected and why, so we are the controller within the meaning of Article 4(7) GDPR.

Where a customer decides — processor

For what a customer's own users generate through the SDK — a pseudonym, a recorded answer, a signed token, a ledger entry — that customer decides. We act on their instructions and for no purpose of our own: we do not use it to build a profile, to train a model, or to sell anything. We are their processor within the meaning of Article 4(8) GDPR.

One consequence, because customers ask it first: the prompts and responses your users exchange with an AI provider never reach us. The SDK sends a hash of the request. A hash is what we authorize against, what we sign, and what we write to the ledger — we could not read a prompt if we were ordered to.

What we hold, and why

Reading this site

One session cookie, described in the legal notice. No measurement of any kind, so nothing about this visit is recorded beyond the server logs our infrastructure keeps.

A dashboard or console account

An email address, a password digest, sign-in timestamps, and which organization the account belongs to. Access by ID Side staff to a named customer is recorded with a mandatory reason, in a table the database will not let anyone rewrite.

Writing to us

The address you give and the message you send. Nothing more — we do not ask your name, because answering you does not require one.

An ID Side account for your own preferences

An email address and the preferences you set. You can read everything we hold about you, download it, or delete the account from your own account page: no request to us, no waiting for an answer.

An employee of a customer organization

Your employer decided what applies to you, and we hold that decision plus counts of your activity. What your employer sees about you is exactly what your own transparency page shows you — one list, read by both screens, so they cannot disagree. The content of what you write is not among it.

What a customer entrusts to us

A pseudonym derived from the identifier the customer's application supplied, the answer recorded against it, the parameters the SDK forced on the provider call, and an entry in an append-only, hash-chained ledger. Plus the token that proves the call was authorized: it carries a request hash, a single-use nonce, a one-hour lifetime, the source of the decision and the legal basis. Never the request.

The pseudonym is computed per application, under a secret belonging to that application, and it does not invert. The same person using two customers' products is two unrelated pseudonyms, and neither can be turned back into an identifier. That is the point: a profile spanning customers cannot be assembled, including by us, including on request.

Legal bases

How long

The one thing we will not delete

The ledger is an append-only hash chain, and the database refuses a deletion from it — not by convention, by a trigger. That refusal is the product. A customer's proof that they honoured someone's choice is worth nothing if the party being audited can quietly remove an entry, and that has to include removing one because we were asked to.

So an erasure request does not remove ledger entries or signed tokens. It removes the identity: your address, your account, and the link between you and each pseudonym. What remains is chained, verifiable, and no longer attached to anything we hold that names you. Your answers to each application become the rule again, exactly as though no account had ever been linked.

Where it sits

In France, on European infrastructure, with the signing keys held in a key management service in the European Union which cannot export them. We do not transfer personal data outside the European Union.

Where the SDK runs, it is your infrastructure calling an AI provider under your own contract with that provider. Those calls and any transfer they involve are yours, not ours: we see a hash and never the content.

Your rights

Access (Article 15), rectification (Article 16), erasure (Article 17), restriction (Article 18), portability (Article 20), objection (Article 21), and not being subject to a decision based solely on automated processing (Article 22). Where consent is the basis, you can withdraw it at any time, and withdrawing it is as easy as giving it.

For an ID Side account, access and erasure are buttons on your own account page rather than a request to us. The export states in the file itself what it declines to include and why; the erasure asks you to retype your address and then runs, with no cooling-off period, because a delay would make deletion a promise rather than an act.

Anything else: dpo@idside.eu. If your data reached us through a company's product, that company is the controller and the request belongs with them — tell us and we will pass it on, but they decide, not us.

Complaints

You can complain to the CNIL — Commission nationale de l'informatique et des libertés, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France — or to the supervisory authority of the EU country where you live or work.

Legal notice