GDPR Compliance
Last updated: June 6, 2026
1. Our Commitment to GDPR
Bridgeside is committed to ensuring that our processing of personal data complies with the General Data Protection Regulation (EU) 2016/679 ("GDPR"). This page outlines our GDPR compliance measures and your rights as a data subject.
2. Data Controller
Bridgeside is the data controller for personal data processed through our platform. If you have questions about how we handle your data, contact our Data Protection Officer at dpo@bridgeside.dev.
3. Legal Basis for Processing
We process personal data on the following legal bases under GDPR:
- Contractual Necessity (Art. 6(1)(b)): Processing necessary to provide our Services under our Terms of Service.
- Legitimate Interests (Art. 6(1)(f)): Processing for security, fraud prevention, service improvement, and business operations.
- Consent (Art. 6(1)(a)): Processing based on your explicit consent, which you may withdraw at any time.
- Legal Obligation (Art. 6(1)(c)): Processing required to comply with applicable laws.
4. Your Rights Under GDPR
As a data subject located in the European Economic Area (EEA), you have the following rights:
- Right to Access (Art. 15): Obtain confirmation of whether we process your data and receive a copy.
- Right to Rectification (Art. 16): Request correction of inaccurate or incomplete data.
- Right to Erasure (Art. 17): Request deletion of your personal data in certain circumstances.
- Right to Restrict Processing (Art. 18): Request limitation of processing in specific situations.
- Right to Data Portability (Art. 20): Receive your data in a structured, machine-readable format.
- Right to Object (Art. 21): Object to processing based on legitimate interests or direct marketing.
- Right to Withdraw Consent: Withdraw consent at any time without affecting lawful processing before withdrawal.
5. Data Processing Agreements
When we engage subprocessors to process personal data on our behalf, we enter into Data Processing Agreements (DPAs) that comply with Article 28 GDPR. Our key subprocessors include:
- Amazon Web Services (cloud infrastructure)
- Auth0 (authentication services)
6. International Data Transfers
We process data primarily in the EU (eu-west-1 region). Where data is transferred outside the EEA, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission.
7. Data Breach Notification
In the event of a personal data breach, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, where feasible. If the breach is likely to result in high risk to your rights, we will also communicate directly to affected users.
8. Data Protection Impact Assessment
We conduct Data Protection Impact Assessments (DPIAs) for processing operations that are likely to result in high risk to individuals, including large-scale processing of sensitive data and systematic monitoring.
9. Retention Periods
We retain personal data only as long as necessary for the purposes for which it was collected:
- Account data: Retained for the duration of your account plus 90 days
- Usage logs: Retained for 12 months for security and debugging
- Payment records: Retained for 7 years for tax and accounting purposes
- Sandbox session data: Retained according to your organization's retention policy
10. Contact and Complaints
To exercise your GDPR rights or raise concerns, contact us at dpo@bridgeside.dev. You also have the right to lodge a complaint with your local supervisory authority.