1. Scope and controller
This Privacy Policy explains how Sidewatts, Inc. collects, uses, discloses, retains, and protects personal data when you use Sidewatts websites, accounts, identity services, research and documentation surfaces, APIs, organization resources, developer tools, communications, streams, recordings, and limited-access services.
Sidewatts is the controller of account, security, service, and operational data used for its own purposes. An organization may be the controller of material it submits or of activity it directs within organization-managed resources; in that case, Sidewatts may process that data on the organization's instructions.
2. Data we collect
We collect data you provide, data generated when you use the Services, data provided by organizations or connected applications, and data received from infrastructure and service providers.
- Identity and profile data, including name, legal name, account identifier, email addresses, organization memberships, roles, and preferences.
- Authentication and security data, including password state, passkey registration metadata, multi-factor configuration, recovery events, sessions, consent records, IP address, user agent, device and request signals, and security logs.
- Developer and organization data, including verified domains, client metadata, redirect URIs, scopes, secrets in protected form, administrative actions, and application activity.
- Material you submit, including messages, files, requests, technical records, support correspondence, and other content provided to a Service.
- Transaction and entitlement data, including purchases, access status, payment-provider references, and records required for accounting or fraud prevention. Sidewatts need not receive full payment-card details from its payment provider.
- Usage and diagnostic data, including pages and features used, requests, timestamps, errors, latency, referral data, cookies, local storage, and approximate location inferred from IP address.
3. Why we process data
Sidewatts processes personal data only where it has a purpose and a lawful basis. Depending on the context, the basis is performance of a contract, compliance with law, Sidewatts' legitimate interests, protection of vital interests, or consent.
- Provide accounts, authentication, recovery, authorization, organization access, developer tools, content, media, support, and requested Services.
- Secure systems; verify requests; detect fraud, abuse, intrusion, and policy violations; investigate incidents; and preserve service integrity.
- Operate, diagnose, measure, maintain, and improve the Services and understand whether features function as intended.
- Administer access, transactions, records, legal notices, and communications, and comply with tax, accounting, sanctions, regulatory, and lawful-process obligations.
- Establish, exercise, or defend legal claims and protect the rights and safety of Sidewatts, its users, and others.
5. Disclosure
Sidewatts discloses personal data only as necessary to operate the Services, follow your direction, administer an organization, complete an authorized connection, address security or legal demands, or complete a corporate transaction.
- Infrastructure and service providers that supply hosting, databases, delivery, email, security, monitoring, support, storage, analytics, and payment processing.
- Organizations and their administrators for membership, role, access, policy, application, and audit administration.
- Connected applications when you or your organization authorize scopes and consent to the connection.
- Professional advisers, auditors, insurers, courts, regulators, law-enforcement bodies, and other authorities where disclosure is lawful and necessary.
- A buyer, successor, affiliate, or transaction participant in a financing, reorganization, merger, sale, or transfer, subject to appropriate confidentiality and data-protection measures.
6. No sale of personal data
Sidewatts does not sell personal data. Sidewatts does not disclose account or OAuth data to a connected application unless a user, an authorized organization administrator, or an applicable configuration authorizes that disclosure.
7. International transfers
Sidewatts, its users, and its providers may operate in different countries. Where law requires safeguards for a transfer, Sidewatts will use an applicable mechanism such as an adequacy decision, standard contractual clauses, supplementary measures, or another legally recognized safeguard.
8. Retention
Sidewatts retains personal data only for as long as reasonably necessary for the purpose collected, including service delivery, account and organization continuity, security, fraud prevention, backup recovery, legal compliance, dispute resolution, and enforcement.
Periods differ by record. Short-lived flow, challenge, and session data ordinarily expires sooner than account, transaction, consent, security, audit, or legal records. Deletion from active systems may precede deletion from protected backups. Sidewatts may retain limited records after account deletion when law or a compelling security or legal need requires it.
9. Security
Sidewatts uses technical and organizational measures designed to protect personal data, including access controls, authentication safeguards, separation of duties, logging, monitoring, transport encryption, protected credentials, backups, and review appropriate to the risk.
No system is invulnerable. You must protect credentials, factors, devices, API tokens, and client secrets and report suspected compromise to security@sidewatts.com without delay.
10. Your rights
Depending on your location and the circumstances, you may have rights to access, correct, delete, restrict, object to processing, receive a portable copy, or withdraw consent. You may also have the right to complain to a competent data-protection authority. Withdrawal does not affect processing already lawfully performed.
You may exercise available controls through your Sidewatts account or contact privacy@sidewatts.com. Sidewatts may verify your identity, ask for information needed to locate the data, deny or limit a request where law permits, and refer organization-controlled requests to the relevant organization.
11. Automated decisions
Sidewatts does not use personal data to make decisions based solely on automated processing that produce legal or similarly significant effects, unless a specific Service discloses that processing and provides the protections required by law. Automated security systems may rate, delay, challenge, or block activity to protect accounts and infrastructure; consequential actions may be reviewed where appropriate.
12. Children
The Services are not directed to children below the age at which they may lawfully consent to data processing. If Sidewatts learns that it collected a child's personal data without required authorization, it will take appropriate steps to restrict or delete that data.
13. Changes
Sidewatts may revise this Policy when Services, practices, risks, or laws change. A revised Policy will identify its effective date. Material changes will be communicated where required by law, and renewed consent will be requested when the law requires it.
14. Contact
Privacy questions and rights requests may be sent to privacy@sidewatts.com. Legal notices may be sent to legal@sidewatts.com. Security reports may be sent to security@sidewatts.com.