Effective 28 September 2026
Privacy Policy
This policy explains what data Sidcom processes across everything we operate — our MCP integrations, including the Claude, ChatGPT, and Microsoft Copilot Fortnox Connectors and Fortnox AI Connector: Multi-Company, the account areas built into our products, and this website — and how we handle it.
1. Who we are and what this policy covers
Sidcom AB ("Sidcom", "we") is a Swedish company. This is our single privacy policy, and it covers everything we operate: the MCP integration servers and product portals on sidcom.app and sidcom.ai subdomains, such as fortnox.sidcom.app and fortnox.sidcom.ai, the products sold through them, and this website. You can reach us at hello@sidcom.ai.
2. Our role under GDPR
Responsibility is split by category. For business data in transit — invoices, customer records, vouchers, files, and anything else that passes through while a tool call executes — you are the controller and we act as your processor. That data is processed in real time on your instruction and never stored.
The same applies to the access tokens and connection credentials by which the service reaches your account at a connected provider. They exist only to carry out the operations you authorise, you set their scope through the provider's own sign-in flow, you can revoke them at any time, and we may not use them for anything else. You are the controller and we are your processor for them too.
Both are governed by our Data Processing Agreement, published in full. It takes effect without a signature when you accept our terms, so there is nothing to request and nothing to sign.
For account information, activity records, payment records, and technical data, we are the controller, since this is our own customer relationship and we decide the purposes of that processing.
3. What we process
Authentication tokens. For OAuth-based integrations we store the access and refresh tokens issued by the provider. For credential-based integrations the credentials you enter are sent straight to the provider in exchange for an access token; we do not store the credentials themselves, only the resulting token. We process these as your processor, not for our own purposes — see section 2.
MCP session tokens issued to your AI client (such as Claude, ChatGPT, or Microsoft Copilot) so it can call an integration on your behalf.
Account information, where a product is sold with a Sidcom account: your email address, your name if you give one, your organisation and its billing details, who belongs to it and in what role, and which AI clients are connected.
Activity records — an account activity log covering events such as an organisation being created, a member joining or being removed, and a company being linked or unlinked — so you can see what happened in your own organisation.
Business data in transit: whatever your AI client requests through an integration. It is not persisted, not logged in identifiable form, and not shared.
Payment information. For paid subscriptions bought directly from us, we bill you by card or by invoice. Where you pay by card, our payment provider processes your card details and we never see or store card numbers. Where you pay by invoice, we keep the billing details needed to issue and follow up the invoice. Either way we keep the subscription's status, seat count, and invoice history. Where a product is sold through a marketplace instead, such as the Fortnox Marketplace, that marketplace handles payment under its own terms.
Technical data: IP addresses and standard request metadata captured by our hosting infrastructure for security, abuse prevention, and reliability. Operational logs hold metadata only — timestamps, tool names, response codes — never request or response contents.
Website analytics and marketing data, only for the purposes you accept on sidcom.ai: the pages you visit, the site you came from, campaign parameters and advertising click identifiers such as gclid and fbclid, a pseudonymous visitor id kept in a cookie, and, once you sign in to a product, your account id and email address. Without the relevant acceptance, advertising identifiers and a persistent analytics identity are not collected. The contact and booking forms report only that a message was sent, never its contents or your details.
Visit counting without cookies: if you do not accept cookies your visit is still counted, but no cookie is set and no visitor id is kept in your browser. The only thing stored is a technical marker recording that this browser is not tracked. It holds nothing about you, and it is what keeps the tracking switched off. PostHog instead forms a visitor id by hashing your IP address, your browser's identifier and a random value that changes every day and is deleted when that day ends. This identifier lasts one day and is not stored in your browser. We use it for daily visit counts, not to connect your visits across days. These cookieless events are not passed on to Meta or Google. These counts can include a page path, the referring site's domain, and recognised campaign sources and media, but not advertising click identifiers, URL queries or fragments, form contents, or contact details. We also record whether analytics and marketing consent is unknown, granted or denied, and changes to that choice, so these counts can be interpreted correctly.
4. Why we process it
We process this data to authenticate you to the providers you connect and to your AI client, to execute the API calls you authorise, to determine what your organisation is entitled to use and to bill for it, to prevent abuse and keep the service available, and to send you essential messages about your account or security.
Two purposes rest on your consent under Article 6(1)(a) GDPR, and you can withdraw it at any time. Analytics: understanding how the website and the products are used. Marketing attribution: telling Meta and Google which advertisement led to a company connection, first successful product use, trial, purchase or contact, so that we can measure and buy advertising. You can choose analytics without marketing. Our marketing attribution also requires analytics cookies to link visits with later conversions; this dependency is explained in the cookie choices. Everything else above rests on our contract with you, or on our legitimate interest in running a secure service.
Visit counting without cookies rests on our legitimate interest under Article 6(1)(f) GDPR in knowing how many people visit sidcom.ai and where they come from. No optional cookie or visitor identifier is kept in your equipment for these counts; the necessary marker records the privacy choice. You may object at any time.
5. Your business data
The service is transit infrastructure. Business data flowing through an API call is not persisted by the service; it is delivered to the connected provider and not retained as a copy or backup. Content can reach the service in three ways: through your AI client, as a file we fetch on your behalf from a URL you designate, or as a direct upload to a one-time upload address created by your session. In all three cases the content is forwarded to the provider immediately and not stored. Uploaded files may be inspected programmatically, in memory, to detect format issues we know cause problems downstream and warn you about them; the content is not retained for this.
6. Upload links and filenames
Direct uploads use a single-use link that expires after ten minutes. The link contains an encrypted ticket that includes your session id and the name of the file, so treat upload links as secrets and do not share them. Filenames travel with the file to the connected provider; avoid putting personal data, such as personal identity numbers, in filenames.
7. Short-lived operational caches
To make retried write operations safe, the provider's response to a create or action call may be cached for up to 60 seconds before it expires automatically. Fingerprints of used upload links (a cryptographic hash, no content) are kept for up to 15 minutes to prevent reuse. These caches exist for reliability only, expire automatically, and are held in Cloudflare KV, our existing processor; no new sub-processor is involved.
Where you have configured dashboards in the account portal, the computed panel values — aggregated figures derived from your data in the connected provider — are cached for between 15 minutes and 6 hours, so a dashboard can be shown without re-querying on every view.
8. Retention
Connector OAuth tokens are stored in Cloudflare KV and retained according to each provider's refresh cycle — typically up to 44 days for Fortnox. Credential-flow tokens are retained for up to 365 days, with automatic re-authentication on expiry.
Tokens belonging to a Sidcom account — where you have signed in and linked a company to your organisation — are encrypted before storage and kept in Cloudflare D1 for as long as the link exists. Removing the link, or leaving the organisation, deletes them.
Account information and activity records are stored in a managed Postgres database for as long as your organisation exists, and are removed when it is deleted. Operational logs are retained for 3 days. Business data passing through a tool call is not persisted at all.
When an organisation is deleted we remove its account records, its activity log and all its tokens. We keep only the contract and accounting record that Swedish law requires — your legal name and registration number, and the dates your subscription began and ended — for the period set by the Bookkeeping Act (bokföringslagen (1999:1078)), and we use it for nothing else. No tokens, no logs and no business data are kept on that basis.
You can delete stored tokens at any time by revoking access at the provider, by removing the link in the product, or by contacting us.
Analytics events are kept in PostHog for up to seven years. Your cookie choice is kept for one year, or until you change it, together with what we need to show that consent was given.
9. Sub-processors and other providers
Cloudflare, Inc. is our only sub-processor: the only provider that processes personal data on your behalf, on our instruction. What it does, the personal data it processes, where that processing takes place and the transfer mechanism relied on are published at sidcom.ai/subprocessors, which forms part of our Data Processing Agreement. We give at least 14 days' notice by email before adding or replacing a sub-processor, and you may object.
We also engage providers in processing where we are the controller rather than your processor. They are not sub-processors, the right to object does not apply to them, and we hold a written data processing agreement with each. They are:
Supabase Pte. Ltd. — sign-in, and the account database holding organisations, members, roles, email addresses and the activity log. Stored in the European Union, on AWS eu-north-1 in Stockholm. The contracting entity is incorporated in Singapore, and support and maintenance access may take place from outside the EEA, covered by Supabase's data processing agreement together with the European Commission's Standard Contractual Clauses, module 2.
Stripe Payments Europe, Limited — card payment and subscription billing, where you buy directly from us. Card numbers are handled by Stripe under PCI DSS and never pass through us. Ireland, with onward processing within the Stripe group, covered by Stripe's data processing agreement together with Standard Contractual Clauses, module 2, and the Data Privacy Framework certification of Stripe's U.S. entity.
Plus Five Five, Inc., trading as Resend — delivery of transactional email: sign-in links, invitations, account notifications and contact form submissions. United States, covered by Resend's data processing agreement together with Standard Contractual Clauses, module 2.
Cal.com, Inc. — meeting booking on sidcom.ai: the name, email address and any note you enter when you book a meeting with us, and the time you pick. The calendar is embedded on the get started page and loads when you scroll to it, and Cal.com may set its own cookies inside it. United States, covered by Cal.com's data processing agreement together with Standard Contractual Clauses, module 2.
PostHog, Inc. — website and product analytics, processed on PostHog's EU cloud in Frankfurt, with a visitor id in a cookie once you have accepted cookies, and otherwise with the daily hash described in section 3. Where you have accepted marketing attribution, PostHog also forwards conversion events to Meta Platforms Ireland Ltd and Google Ireland Ltd on our instruction: an event name, a time, an advertising click identifier and, for signed-in users, a hashed email address for ad measurement, which they process under their own terms. This choice does not grant ad-personalization consent. For Meta, we and Meta are joint controllers for that transfer under Meta's Controller Addendum; Meta is responsible for the processing after receipt, and you can exercise your rights against either of us.
Connected providers such as Fortnox, and AI clients such as Claude, ChatGPT, and Microsoft Copilot, are not our sub-processors. They act as independent controllers of the data you exchange with them, under their own privacy policies.
10. Where your data is stored
Account data — your organisation, its members, the activity log, and subscription records — is stored in the European Union, in Stockholm, Sweden. The database holding linked companies and their tokens is created with an EU jurisdiction, which pins where it runs and stores data to the European Union.
Connector session tokens are held in our hosting provider's global key-value store, which replicates to the edge locations serving your requests, and support access by our processors may occur outside the EEA.
Where personal data leaves the EEA, transfers are governed by Standard Contractual Clauses or, where the recipient is certified, the EU-U.S. Data Privacy Framework. The mechanism relied on for our sub-processor is stated at sidcom.ai/subprocessors, and for every other provider in section 9 above.
11. Security
All traffic is encrypted with TLS, provider tokens are encrypted before they are written to storage, and tokens are verified on every request. No system is perfect — report security issues to hello@sidcom.ai.
If a personal data breach affects your data, we will notify you without undue delay and include what you need for your own notification to the supervisory authority — in Sweden, IMY — within the 72-hour deadline under Article 33 GDPR.
12. Your rights
If you are in the EEA, the UK, or Switzerland, you may request access to, correction of, portability of, or deletion of your personal data, and you may ask us to restrict or object to processing. Contact hello@sidcom.ai to exercise these rights. You also have the right to lodge a complaint with your supervisory authority, which in Sweden is IMY.
13. Cookies
Necessary cookies, which need no consent: sidcom_sess and sidcom_ticket keep you signed in to a product, sidcom_pkce protects the sign-in flow, sidcom_lang remembers your language, and sidcom_consent remembers your cookie choice for one year. If you have not accepted, a technical marker recording that this browser is not tracked is also kept; it holds nothing about you and exists so that the tracking stays off.
Analytics cookies, set only after you accept analytics: a cookie named ph_ followed by our project key, set by PostHog on .sidcom.ai for 365 days, holding a pseudonymous visitor id and session id. When marketing attribution is also enabled, that consented identity links a visit with a later product conversion. Advertising campaign details use the separate cookie below.
If you enable marketing attribution as well as analytics, sidcom_attribution stores the first consented campaign touch and latest paid campaign touch on .sidcom.ai for up to 30 days per touch. It holds campaign parameters, available advertising click and browser identifiers, the public landing-page path and the time it was observed. This carries consented attribution from the website to a Sidcom product on another .sidcom.ai subdomain. It contains no name, email address, full URL query or fragment, or additional visitor identifier. Returning directly does not extend an earlier touch's lifetime.
If you do not accept, no optional cookie is set and no visitor id is kept. The visit is still counted, using the daily hash in section 3, and it never reaches Meta or Google.
You can withdraw or change your choice at any time through the Cookies link in the footer of every page. Withdrawing removes the analytics and attribution cookies from your browser; later events are excluded from advertising exports. The visit is then counted without optional browser identifiers, as above. A change also notifies Sidcom products where this browser has an existing signed-in session, so the account's stored choice is updated. This notification contains only the purpose choices. A network or service failure can delay the account update; it does not delay your local browser choice. Data already delivered to a provider cannot be recalled by changing the cookie choice. Withdrawing is as easy as accepting.
14. Changes
We may update this policy as the service evolves. Material changes will be reflected by the effective date above.
15. Contact
Questions about privacy or your data: hello@sidcom.ai.