This Data Processing Addendum ("DPA") forms part of the agreement between sidething Ltd ("sidething", "we", "our", or "us") and the customer who uses the Service ("Customer", "you", "your") (the "Agreement"). It sets out how sidething processes personal data on your behalf, and in particular how it handles the data read from the tools you connect for the optional intelligence features.
sidething Ltd is registered in England and Wales (Company Number 16834072) with its registered office at 14/2E Docklands Business Centre, 10-16 Tiller Road, Canary Wharf, London, E14 8PX, United Kingdom.
If any term of this DPA conflicts with the main Agreement on the subject of personal data processing, this DPA governs.
1.1. For personal data that relates to your own end users and contacts, which you or your connected tools supply, you are the controller and sidething is the processor. You decide why and how that data is processed, and sidething processes it only to provide the Service and only on your instructions.
1.2. For personal data about you and the people you authorise to use your account, such as your account and billing details, sidething is the controller. That processing is described in our Privacy Policy at sidething.com/privacy, not in this DPA.
1.3. This DPA applies whenever sidething processes personal data as your processor.
2.1. "Personal data", "processing", "controller", "processor", "sub-processor" and "data subject" carry the meanings given to them in UK GDPR.
2.2. "UK GDPR" means the retained EU General Data Protection Regulation as it forms part of the law of England and Wales, read together with the Data Protection Act 2018.
2.3. "Service" means the sidething website, app and related services, including the optional intelligence features described in Section 18 of our Privacy Policy.
2.4. "Connected tools" means the external services you choose to link to sidething, such as Stripe, your own database, Gmail and Google Calendar.
2.5. "Sub-processor" means a third party that sidething engages to process personal data on your behalf.
3.1. Subject matter. sidething processes personal data to provide the Service to you, including reading data from your connected tools to produce metrics, a daily brief, signals and suggested actions.
3.2. Duration. sidething processes the data for as long as your account is active, then deletes it as set out in Section 7.
3.3. Nature and purpose. Reading, storing, computing on, and showing back to you the data needed to run the Service. sidething does not sell the data, does not share it with advertisers, and does not use it to train models.
3.4. Types of personal data. Depending on which tools you connect, this can include: identifiers and contact details of your end users and business contacts (email addresses, names where you provide them, and account identifiers); email and calendar metadata (the address of a person you are corresponding with, a subject line, a thread identifier, meeting attendees and times); and business metrics computed from the above.
3.5. Categories of data subjects. Your own end users and customers; your business contacts, meaning the people you email and meet; and the members of your team you authorise to use your account.
3.6. Your instructions. sidething processes the data only on your documented instructions, which include this DPA, the settings you choose in the Service, and the connectors you switch on. sidething will tell you if it believes an instruction breaches data protection law, and may decline it.
3.7. Read-only connections. The connections to your tools are built to read only. sidething does not write to, modify or delete anything in your connected tools.
3.8. Minimising what we keep. Where the Service only needs to count a population and never to name it, sidething stores a one-way hash of the identifier rather than the plaintext. For example, the count of your end users who have gone quiet is computed from hashed identifiers, so no plaintext end-user email address is stored for that purpose.
4.1. sidething ensures that the people authorised to process the data are bound by confidentiality and reach it only as their work on the Service requires.
5.1. You authorise sidething to engage the sub-processors below to run the Service. Each processes only the data its role needs, and under terms consistent with UK GDPR.
| Sub-processor | What it processes | Why |
|---|---|---|
| Supabase | Database records, authentication, file storage and realtime messaging | Stores and serves the data behind your account and the Service |
| Netlify | Website and app content delivery | Hosts and serves the sidething website and app |
| Cloudflare | Network request metadata, such as IP address and request headers | Protects the website and app from bots and automated abuse |
| Anthropic | The text sent for the narration and extraction steps of the AI-assisted and intelligence features | Turns your data into a written brief, signals and suggested actions |
| OpenAI | The text sent for the AI-assisted and intelligence steps routed to its models | An additional AI provider for the same written output |
| Perplexity | The text sent for the research and web-lookup steps of the intelligence features | An additional AI provider used for research and web lookups |
| Composio | OAuth authorisation and API calls for the OAuth-based connectors | Connects Gmail, Google Calendar and similar tools so the Service can read from them |
| Stripe | Your billing and payment details | Processes your subscription payments |
| RevenueCat | Your in-app purchase and subscription entitlements on mobile | Manages subscription status for the iOS and Android apps |
| Resend | Your account email address and message content | Delivers transactional email such as briefs and account notices |
| Flodesk | Your email address, only if you opt in | Delivers the newsletter you chose to receive |
| Endorsely | Referral and sign-up attribution data | Cookieless referral attribution, to credit the referrer who sent a new customer |
5.2. Notice of changes. sidething keeps this list current. Before adding or replacing a sub-processor that processes personal data on your behalf, sidething gives at least 30 days' notice, by email or in-app notice, so you have time to object. If you object on reasonable data protection grounds and sidething cannot offer a workaround, you may end the affected part of the Service.
5.3. sidething stays responsible to you for a sub-processor's processing, and binds each one to data protection terms at least as protective as this DPA.
6.1. sidething uses technical and organisational measures to protect the data, including:
6.2. What sealing does and does not mean today. Sealing keeps the content out of every ordinary read path, so the database, the dashboard, the SQL editor and the admin panel show scrambled text. In this version the master key that protects the per-user keys is held as a secret on the systems sidething operates, so a member of staff with the right access could still reach the content. They could not do so through any ordinary read path, and not without taking an action that leaves a trail, such as changing the code, which is recorded in the deploy history, or granting themselves access, which is recorded in the logs. sidething does not claim in this version that staff are unable to read sealed content. A later version moves the master key to an external key manager that records every change to who may use it.
6.3. sidething notifies you without undue delay after it becomes aware of a personal data breach affecting the data it processes for you, and gives you the information you need to meet your own reporting duties.
7.1. sidething processes the data for as long as your account is active.
7.2. When you close your account, or when you ask sidething to delete the data it processes for you, sidething removes it from the live system. Encrypted backups may persist for up to 30 days before being permanently erased.
7.3. On request, sidething returns a copy of the data it holds for you before deletion, in a commonly used format.
7.4. sidething keeps data beyond account closure only where the law requires it, for example payment records retained to meet financial reporting duties.
8.1. If a data subject contacts sidething directly about data sidething processes for you, sidething passes the request to you and does not answer it itself, unless you have asked it to.
8.2. Taking account of the nature of the processing, sidething helps you respond to data subject requests and meet your own obligations on security, breach notification and data protection impact assessments.
9.1. Some sub-processors may process data outside the UK or the European Economic Area. Where they do, sidething relies on adequacy decisions, Standard Contractual Clauses, or equivalent safeguards in line with UK GDPR.
10.1. On reasonable request, sidething gives you the information you need to show that it meets this DPA, and allows an audit, including an inspection, carried out by you or an auditor you appoint, on reasonable notice and no more than once a year, unless a regulator or a breach requires otherwise.
10.2. For any question about this DPA, a sub-processor, or the data sidething processes for you, contact support@sidething.com.
11.1. This DPA is governed by the laws of England and Wales, and any dispute arising from it will be handled by the English courts.