FreNiMiGuard

Data Processing Addendum

Last updated: October 5, 2026

This Data Processing Addendum ("DPA") is part of the FreNiMiGuard Terms of Service, or of any other agreement under which FreNiMi LLC ("FreNiMi") provides FreNiMiGuard to a customer (the "Agreement"). It applies automatically when a customer accepts the Agreement; no signature is needed. Customers who want a countersigned copy can ask at info@frenimi.com.

1. Definitions

2. Roles

The customer is the controller of Customer Personal Data, or a processor acting for its own controller. FreNiMi is the customer's processor and, under the CCPA and similar laws, its service provider. Annex 1 describes the processing.

3. Processing only on instructions

FreNiMi processes Customer Personal Data only to provide the service under the Agreement and on the customer's documented instructions. The Agreement, this DPA, and the settings and requests the customer's administrators make in the service are the customer's instructions. FreNiMi will tell the customer if it believes an instruction breaks Data Protection Laws, unless the law forbids that.

The customer is responsible for having a lawful basis for the processing and for giving any notices its users and staff need. The service is not designed for special categories of personal data, such as health information about individuals, and the customer should not put such data into free-text fields.

4. People with access

FreNiMi gives access to Customer Personal Data only to staff and contractors who need it to run or support the service. Each is bound by a duty of confidentiality and uses multi-factor authentication.

5. Security

FreNiMi maintains the technical and organizational measures in Annex 2. FreNiMi may improve them over time but will not reduce the overall level of protection they give.

6. Subprocessors

The customer authorizes FreNiMi to use the Subprocessors listed in Annex 3. FreNiMi binds each Subprocessor to data protection terms at least as protective as this DPA and remains responsible for its work.

FreNiMi will email the customer's administrators at least 30 days before adding or replacing a Subprocessor. If the customer objects on reasonable data protection grounds and the parties can't resolve the objection, the customer may end the Agreement for the affected service and receive a refund of any prepaid amount for the time after it ends.

7. Help with requests and assessments

The service lets administrators find, export, correct and delete Customer Personal Data. Where they can't do something themselves, FreNiMi will help the customer respond to requests from data subjects. If FreNiMi receives such a request directly, it will pass it to the customer and not answer it, unless the law requires otherwise. FreNiMi will also give reasonable information the customer needs for a data protection impact assessment or a consultation with a regulator about the service.

8. Personal data breaches

FreNiMi will notify the customer without undue delay, and no later than 72 hours after confirming a personal data breach affecting Customer Personal Data. The notice will describe, as far as then known, what happened, the data and people affected, the likely consequences, and what FreNiMi has done and will do about it. FreNiMi will add information as it learns more and will take reasonable steps to contain the breach. Notifying the customer is not an admission of fault.

9. Return and deletion

While the Agreement is in place, administrators can export Customer Personal Data from the service. When the customer closes its account or the Agreement ends, FreNiMi deletes Customer Personal Data from the live service within 30 days, and it leaves FreNiMi's backups within a further 35 days. FreNiMi may keep a copy only where the law requires, and then only for that purpose and with the protections of this DPA.

10. Information and audits

FreNiMi will make available the information reasonably needed to show that it meets this DPA, including answering one reasonable security questionnaire a year. If that isn't enough to meet a requirement of Data Protection Laws or of a regulator, the customer, or an independent auditor bound by confidentiality, may audit FreNiMi's processing of Customer Personal Data with at least 30 days' notice, during business hours, at the customer's expense, and no more than once a year unless a regulator requires more or a breach has occurred.

11. International transfers

FreNiMi stores and processes Customer Personal Data in the United States. Where Data Protection Laws restrict transferring personal data from the European Economic Area, the United Kingdom or Switzerland to FreNiMi:

If these clauses conflict with the rest of this DPA, the clauses win.

12. US state privacy laws

Where the CCPA or a similar US state law applies, FreNiMi will not sell or share Customer Personal Data; will not keep, use or disclose it outside the direct business relationship with the customer or for any purpose other than providing the service; will not combine it with personal data from other sources except as those laws allow; and will give it the protection those laws require. FreNiMi will tell the customer if it can no longer meet these obligations, and the customer may then take reasonable steps to stop and fix unauthorized use.

13. General

Each party's liability under this DPA is subject to the limits in the Agreement, except where Data Protection Laws or the clauses in section 11 don't allow it. If this DPA conflicts with the rest of the Agreement on data protection, this DPA wins. FreNiMi may update this DPA to reflect changes in law or in the service, without reducing the protection it gives, and will tell customers of significant changes at least 30 days in advance.

Annex 1: Details of the processing

PartiesData exporter: the customer, as identified in its FreNiMiGuard account. Data importer: FreNiMi LLC, 1655 S Blue Island Ave, Suite 4050, Chicago, IL 60608, USA, info@frenimi.com.
PurposeProviding FreNiMiGuard: tracking the customer's assets and software, matching them against known vulnerabilities, managing remediation and evidence, sending the alerts and reports the customer sets up, running the optional agent and its approved actions, and supporting the customer.
Nature of processingCollecting, storing, organizing, matching, displaying, exporting, transmitting and deleting.
Data subjectsThe customer's users of the service; staff named as owners or users of the customer's devices; and people the customer mentions in tasks, incidents and notes.
Personal dataNames and usernames, work email addresses, roles; device names (which can contain a person's name), IP addresses, installed software and update status; owner, department and location fields; audit trail entries; any personal data in free-text notes the customer writes.
Special categoriesNone intended. See section 3.
FrequencyContinuous, for as long as the service is provided.
Duration and retentionThe term of the Agreement, then deletion as described in section 9.
Competent supervisory authorityThe authority competent for the data exporter under Clause 13 of the Standard Contractual Clauses.

Annex 2: Security measures

Keeping customers apart

Encryption

Access control

The agent

Records and monitoring

Resilience and maintenance

Annex 3: Subprocessors

SubprocessorPurposeDataLocation
DigitalOcean, LLCHosting the serviceAll Customer Personal Data, stored on FreNiMi's serversUnited States
Resend, Inc.Delivering emailRecipients' email addresses and message content: sign-in codes, alerts and reportsUnited States
Stripe, Inc.Payments and subscriptionsBilling contact details of the customer's administrators; no workspace dataUnited States