Effective 17 August 2026
Privacy Policy
This policy explains what data Sidcom processes when you use our MCP integrations, including the Claude, ChatGPT, and Microsoft Copilot Fortnox Connectors, and how we handle it.
1. Who we are
Sidcom AB ("Sidcom", "we") is the controller for the personal data described here. You can reach us at hello@sidcom.ai.
2. What we process
To run the service we process: OAuth and credential-based access tokens for your connected providers; MCP session tokens issued to your AI client (such as Claude, ChatGPT, or Microsoft Copilot); and standard technical data such as IP addresses captured by our hosting infrastructure. Your business data (invoices, customer details, files you upload or direct us to fetch, and so on) passes through during an API call but is not stored by the service.
3. Why we process it
We process this data to authenticate you, to execute the API calls you authorise, to prevent abuse, and to send you essential messages about your account or security.
4. Your business data
The service is transit infrastructure. Business data flowing through an API call is not persisted by the service; it is delivered to Fortnox and not retained as a copy or backup. Content can reach the service in three ways: through your AI client, as a file we fetch on your behalf from a URL you designate, or as a direct upload to a one-time upload address created by your session. In all three cases the content is forwarded to Fortnox immediately and not stored. Uploaded files may be inspected programmatically, in memory, to detect format issues we know cause problems downstream and warn you about them; the content is not retained for this.
5. Upload links and filenames
Direct uploads use a single-use link that expires after ten minutes. The link contains an encrypted ticket that includes your session id and the name of the file, so treat upload links as secrets and do not share them. Filenames travel with the file to Fortnox; avoid putting personal data, such as personal identity numbers, in filenames.
6. Short-lived operational caches
To make retried write operations safe, the provider's response to a create or action call may be cached for up to 60 seconds before it expires automatically. Fingerprints of used upload links (a cryptographic hash, no content) are kept for up to 15 minutes to prevent reuse. These caches exist for reliability only, expire automatically, and are held in Cloudflare KV, our existing processor; no new subprocessor is involved.
7. Retention
OAuth tokens are stored in Cloudflare KV and retained according to each provider's refresh cycle — typically up to 44 days for Fortnox. Credential-flow tokens are retained for up to 365 days, with automatic re-authentication on expiry.
8. Subprocessors
We use Cloudflare as a processor for hosting, storage, DNS, and TLS. Connected providers such as Fortnox, and AI clients such as Claude, ChatGPT, and Microsoft Copilot, act as independent controllers under their own privacy policies.
9. Security and transfers
All traffic is encrypted with TLS, and tokens are verified on each request. Where personal data is transferred internationally, we rely on Standard Contractual Clauses where applicable.
10. Your rights
If you are in the EEA, the UK, or Switzerland, you may request access to, correction of, portability of, or deletion of your personal data, and you may ask us to restrict processing. Contact hello@sidcom.ai to exercise these rights.
11. Changes
We may update this policy as the service evolves. Material changes will be reflected by the effective date above.
12. Contact
Questions about privacy or your data: hello@sidcom.ai.