Version 3.1 · Last updated: 12 January 2026 · Effective: 1 February 2026
Data controller: Sideout Journal S.r.l., Via Marconi 27, 40122 Bologna, Italy. P.IVA IT03974220378.
Data Protection contact: privacy@sideoutjournal.example.
We are established in Italy and our lead supervisory authority is the Garante per la protezione dei dati personali (Italian Data Protection Authority).
| Purpose | Legal basis (GDPR) |
|---|---|
| Provide subscription service | Contract |
| Send the weekly newsletter you signed up for | Consent |
| Send you renewal reminders, billing notices, service updates | Contract, legitimate interests |
| Site security, fraud detection, rate limiting | Legitimate interests |
| Aggregate analytics to improve editorial and site | Legitimate interests (privacy-preserving, no individual profiling) |
| Tax records, invoicing, accounting | Legal obligation |
| Journalism (source contact, research) | Public interest / journalistic activity |
We do not sell personal data and do not share it for cross-context behavioral advertising. We use the following processors:
Each processor is bound by a written Data Processing Agreement and uses your data only to provide the specific service.
Our data is primarily hosted in the EU (Germany). Where a processor transfers data outside the EEA — for example, Stripe and Cloudflare may process transactional metadata via the US — we rely on the 2021 Standard Contractual Clauses and, where the processor holds it, the EU-US Data Privacy Framework certification. We conduct transfer impact assessments for each such flow.
Technical and organizational measures include: HTTPS with TLS 1.2+ for all traffic; Argon2id password hashing; role-based access with least-privilege; hardware-key MFA for staff systems; encrypted backups; monthly access reviews; and documented incident-response and breach-notification procedures (Art. 33/34 GDPR).
If you are in the EEA, UK, or Switzerland, you have the rights to access, rectify, erase, restrict, port, and object to processing of your personal data, and to withdraw consent. To exercise them, email privacy@sideoutjournal.example. We reply within 30 days (extendable to 60 for complex requests). Identity verification may be required.
You may also lodge a complaint with your local supervisory authority. In Italy: Garante per la protezione dei dati personali.
The Site is not directed to children under 16 and we do not knowingly collect their personal data. Where Italian law sets a higher digital-consent age (currently 14), that higher age applies.
Residents of California, Colorado, Connecticut, Utah, and Virginia have rights to know, access, correct, delete, port, and opt out of sale/sharing/targeted advertising. We do not sell personal data and do not process personal data for targeted advertising. Requests: privacy@sideoutjournal.example.
Some of our processing is conducted for journalistic purposes and is subject to the exemptions in Art. 85 GDPR, Article 137 of the Italian Data Protection Code, and the code of ethics for journalism. Where these exemptions apply, certain data-subject rights may be modified or restricted to the extent necessary to reconcile the right to the protection of personal data with the freedom of expression and information.
Material changes will be notified to registered users by email at least 30 days before taking effect. The "Last updated" date shows the current version.
Sideout Journal S.r.l.
Attn: Privacy
Via Marconi 27
40122 Bologna, Italy
privacy@sideoutjournal.example