Legal

Privacy Policy

Effective 3 September 2026 · Applies to syde.to and app.syde.to

This Privacy Policy explains how Syde Ltd(“Syde”, “we”, “us”) collects, uses, and shares your personal data when you use the Syde platform.

By creating an account or continuing to use Syde, you acknowledge that you’ve read and understood this policy.

Section 1

Who we are and how to contact us

Syde Ltd is the data controller responsible for your personal data when you use the Syde platform.

Syde Ltd — Privacy Team

11 St Nicholas Street, Suite 201, Weymouth, Dorset, DT4 8AA

Company number: 17231998

Email: privacy@syde.to

If you’re a member of a Network on Syde, the organisation running that Network (the “Network Owner”) is also an independent data controller for the data you share with them directly — check their own privacy notice for how they handle it.

Where we act as a data processor for a Network Owner, we process your data only in line with their instructions and the data processing terms in our Terms of Service.

Section 2

What personal data we collect

We collect the following categories of personal data:

CategoryExamplesHow collected
Account dataName, email address, password (hashed), profile photo, role, date of birthProvided by you on registration
Payment dataSubscription tier, billing history, last four digits of card. Full card details are held by Stripe and never stored by us.Generated when you subscribe or pay
Network & usage dataNetworks joined or managed, posts, events, documents, messages, feature interactionsGenerated as you use the platform
Technical dataIP address, browser type, device type, pages visited, session timestampsCollected automatically via server logs and strictly-necessary cookies
AI interaction dataPrompts and input you submit to AI-assisted features; the resulting outputProvided by you when using an AI feature (see Section 6)
CommunicationsMessages sent to our support team, enquiry formsProvided by you

We collect date of birth to confirm you meet our minimum age requirement (see Section 11). We don’t knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, please contact us at privacy@syde.toand we’ll delete it promptly.

Section 3

Why we process your data and our lawful basis

PurposeLawful basis (UK GDPR)
Creating and maintaining your accountContract (Art. 6(1)(b)) — necessary to provide the service
Processing subscription and purchase paymentsContract (Art. 6(1)(b))
Enabling Network features (posts, events, messaging)Contract (Art. 6(1)(b))
Sending transactional emails (receipts, account notices)Contract (Art. 6(1)(b))
Preventing fraud and keeping the platform secureLegitimate interests (Art. 6(1)(f)) — protecting the platform and its users
Understanding platform usage to improve the productLegitimate interests (Art. 6(1)(f))
Complying with legal obligations (e.g. tax records)Legal obligation (Art. 6(1)(c))
Marketing communications, if you opt inConsent (Art. 6(1)(a))
Section 4

How long we keep your data

Data typeRetention periodReason
Account dataDuration of your account, plus a short window after a deletion request to complete itTo provide the service, and as a safety margin for account recovery
Payment records7 years from the transaction dateHMRC tax and accounting obligations
Usage and activity logsKept only as long as needed for security monitoring and fraud prevention, then deleted or anonymisedSecurity
Support correspondenceUp to 3 yearsResolving disputes and improving support
AI interaction dataUp to 30 days, then deletedSee Section 6
Backup copiesUp to 90 days after deletion from live systemsDisaster recovery

When we no longer need your data, we delete or anonymise it.

Section 5

Who we share your data with

We don’t sell your personal data. We share it only in the following circumstances:

Payment processing — Stripe
We use Stripe, Inc. to process payments. Stripe is an independent data controller for the data it collects to do this. Stripe’s privacy policy is at stripe.com/gb/privacy.
Network Owners
When you join a Network, its Network Owner can see the profile and activity data you share within that Network. Network Owners are independent data controllers for that data — check their own privacy notice before joining.
AI feature providers
If you use an AI-assisted feature, your input may be processed by our AI provider to generate a response. The specific provider currently in use, and the international transfers this involves, are published at syde.to/legal/sub-processors — see also Section 6.
Other service providers
We use a small number of carefully selected providers to run the platform — for email delivery, encrypted backups, and optional integrations (calendar/video-call connections, SMS/WhatsApp messaging, GIF search) that only apply if a Network admin chooses to enable them. The full, current list is published at syde.to/legal/sub-processors.
Legal and regulatory requirements
We may disclose personal data where required by law or court order, or to protect the rights, property, or safety of Syde, our users, or others.
Business transfers
If Syde is involved in a merger, acquisition, or sale of assets, personal data may transfer to the new entity. We’ll notify you by email or a prominent platform notice first.
Section 6

AI-assisted features

Syde includes optional, clearly-labelled AI-assisted features to help with things like drafting an event or Network description. When you use them:

  • Your input (prompts, text, queries) may be sent to our AI provider to generate a response. See syde.to/legal/sub-processors for the specific provider currently configured — this may change from time to time, and that page always reflects the current one.
  • We retain AI input and output for up to 30 days, so you can review recent AI interactions, then delete it from our systems.
  • Our AI provider may retain data for a different period under their own policy — check the link on the sub-processors page for the provider in use.
  • Please don’t submit special category data (e.g. health information) or sensitive information about other people to an AI feature.

AI features are always optional — you can use the rest of Syde without them.

Section 7

Network Owners and data control

Network Owners are independent data controllers in their own right for their members’ personal data. This means:

  • Each Network Owner is responsible for having a lawful basis to process their members’ data;
  • Network Owners should give their members their own privacy notice;
  • If you have questions about how a Network Owner uses your data, contact them directly.

Where Syde processes member data on a Network Owner’s behalf (for example, storing membership records or sending communications for them), Syde acts as a data processor. The data processing terms in our Terms of Service, Section 6.5, form the written agreement required under UK GDPR Article 28 between us.

Syde remains the data controller for any data we process about Network Owners themselves — account data, billing records, and platform usage logs.

Section 8

International data transfers

Syde is based in the UK. Some of our service providers — including Stripe and our AI provider, both listed at syde.to/legal/sub-processors — may process personal data outside the UK, mainly in the United States.

Where we transfer personal data outside the UK, we put appropriate safeguards in place, such as:

  • Transfer to a country covered by a UK adequacy decision; or
  • The UK International Data Transfer Addendum or Standard Contractual Clauses approved by the ICO; or
  • Another legally recognised transfer mechanism.

You can ask for details of the specific safeguard used for any particular transfer by emailing privacy@syde.to.

Section 9

Cookies

Syde doesn’t use any analytics, marketing, or advertising cookies. Every cookie we set is strictly necessary to run the product — keeping you signed in, remembering your light/dark preference, and supporting a feature you’ve explicitly used (such as an embedded single-network view, or resuming an action you started before verifying your email). None of these track you across other sites, and none require your consent under UK cookie law (PECR) because they’re all strictly necessary.

Because of that, the cookie notice you see on first visiting Syde is a simple acknowledgement rather than an accept/reject choice — there’s nothing non-essential to opt in or out of. If that ever changes, we’ll update this section and the notice first.

Section 10

Your data protection rights

Under UK data protection law, you have the following rights over your personal data:

Right to be informed

To know how and why we use your personal data — this policy is how we tell you.

Right of access

To get a copy of the personal data we hold about you.

Right to rectification

To have inaccurate data corrected, or incomplete data completed.

Right to erasure

To ask us to delete your personal data where there's no good reason to keep it.

Right to restrict processing

To ask us to pause processing your data in certain circumstances.

Right to data portability

To get your data in a structured, machine-readable format and take it elsewhere.

Right to object

To object to processing based on legitimate interests or direct marketing.

Rights re: automated decisions

Not to be subject to solely automated decisions with significant legal or similar effects. We don't currently make any.

To exercise any of these rights, go to Profile → Preferences and submit a data export or deletion request, or email privacy@syde.to. We review and respond to requests within one calendar month, and don’t charge a fee for a standard request.

If you’re unhappy with our response, you can complain to the UK Information Commissioner’s Office (ICO) at ico.org.uk or on 0303 123 1113.

Section 11

Children and minors

Syde is intended for people aged 16 and over — this is our minimum age for creating an account, whether as a member or a Network Owner. We collect date of birth at registration to check this.

If you’re a parent or guardian and believe your child has created an account despite this, please contact us at privacy@syde.to and we’ll look into it promptly, and delete the account and its personal data where appropriate.

Section 12

Security

We use appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or damage, including:

  • Encryption of data in transit (TLS) and at rest;
  • Access controls limiting which staff can access personal data;
  • Regular review of our security practices;
  • Secure, third-party payment processing via Stripe — we never store full card numbers.

No system is ever completely secure. You’re responsible for keeping your account credentials confidential and for any activity under your account. If you suspect unauthorised access, contact us straight away at privacy@syde.to.

Section 13

Changes to this policy

We may update this Privacy Policy from time to time. When we make a material change, we’ll notify you by email and by showing a notice on the platform, at least 14 days before it takes effect.

The date at the top of this page shows when it was last revised. Continuing to use Syde after a change takes effect means you accept the update.

Section 14

Contact us

Questions about this policy or how we handle your data? Get in touch:

Syde Ltd — Privacy Team

11 St Nicholas Street, Suite 201, Weymouth, Dorset, DT4 8AA

Company number: 17231998

Email: privacy@syde.to

Information Commissioner’s Office (ICO)

Website: ico.org.uk

Helpline: 0303 123 1113

Terms of serviceSub-processorsBack to app