Data Processing Addendum
Last updated: October 5, 2026
This Data Processing Addendum ("DPA") is part of the FreNiMiGuard Terms of Service, or of any other agreement under which FreNiMi LLC ("FreNiMi") provides FreNiMiGuard to a customer (the "Agreement"). It applies automatically when a customer accepts the Agreement; no signature is needed. Customers who want a countersigned copy can ask at info@frenimi.com.
1. Definitions
- Customer Personal Data means personal data in the data the customer or its users put into FreNiMiGuard, which FreNiMi processes on the customer's behalf.
- Data Protection Laws means the laws that apply to that processing, including, where relevant, the EU General Data Protection Regulation ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and US state privacy laws such as the California Consumer Privacy Act ("CCPA").
- Subprocessor means a company FreNiMi engages that processes Customer Personal Data.
- Other terms such as "controller", "processor", "data subject", "personal data breach" and "service provider" have the meanings given in Data Protection Laws.
2. Roles
The customer is the controller of Customer Personal Data, or a processor acting for its own controller. FreNiMi is the customer's processor and, under the CCPA and similar laws, its service provider. Annex 1 describes the processing.
3. Processing only on instructions
FreNiMi processes Customer Personal Data only to provide the service under the Agreement and on the customer's documented instructions. The Agreement, this DPA, and the settings and requests the customer's administrators make in the service are the customer's instructions. FreNiMi will tell the customer if it believes an instruction breaks Data Protection Laws, unless the law forbids that.
The customer is responsible for having a lawful basis for the processing and for giving any notices its users and staff need. The service is not designed for special categories of personal data, such as health information about individuals, and the customer should not put such data into free-text fields.
4. People with access
FreNiMi gives access to Customer Personal Data only to staff and contractors who need it to run or support the service. Each is bound by a duty of confidentiality and uses multi-factor authentication.
5. Security
FreNiMi maintains the technical and organizational measures in Annex 2. FreNiMi may improve them over time but will not reduce the overall level of protection they give.
6. Subprocessors
The customer authorizes FreNiMi to use the Subprocessors listed in Annex 3. FreNiMi binds each Subprocessor to data protection terms at least as protective as this DPA and remains responsible for its work.
FreNiMi will email the customer's administrators at least 30 days before adding or replacing a Subprocessor. If the customer objects on reasonable data protection grounds and the parties can't resolve the objection, the customer may end the Agreement for the affected service and receive a refund of any prepaid amount for the time after it ends.
7. Help with requests and assessments
The service lets administrators find, export, correct and delete Customer Personal Data. Where they can't do something themselves, FreNiMi will help the customer respond to requests from data subjects. If FreNiMi receives such a request directly, it will pass it to the customer and not answer it, unless the law requires otherwise. FreNiMi will also give reasonable information the customer needs for a data protection impact assessment or a consultation with a regulator about the service.
8. Personal data breaches
FreNiMi will notify the customer without undue delay, and no later than 72 hours after confirming a personal data breach affecting Customer Personal Data. The notice will describe, as far as then known, what happened, the data and people affected, the likely consequences, and what FreNiMi has done and will do about it. FreNiMi will add information as it learns more and will take reasonable steps to contain the breach. Notifying the customer is not an admission of fault.
9. Return and deletion
While the Agreement is in place, administrators can export Customer Personal Data from the service. When the customer closes its account or the Agreement ends, FreNiMi deletes Customer Personal Data from the live service within 30 days, and it leaves FreNiMi's backups within a further 35 days. FreNiMi may keep a copy only where the law requires, and then only for that purpose and with the protections of this DPA.
10. Information and audits
FreNiMi will make available the information reasonably needed to show that it meets this DPA, including answering one reasonable security questionnaire a year. If that isn't enough to meet a requirement of Data Protection Laws or of a regulator, the customer, or an independent auditor bound by confidentiality, may audit FreNiMi's processing of Customer Personal Data with at least 30 days' notice, during business hours, at the customer's expense, and no more than once a year unless a regulator requires more or a breach has occurred.
11. International transfers
FreNiMi stores and processes Customer Personal Data in the United States. Where Data Protection Laws restrict transferring personal data from the European Economic Area, the United Kingdom or Switzerland to FreNiMi:
- the EU Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 apply and are incorporated by reference, using Module Two (controller to processor) or Module Three (processor to processor) as fits the customer's role. The customer is the data exporter and FreNiMi the data importer. Clause 7 (docking) applies. Under Clause 9, option 2 applies with the notice period in section 6 of this DPA. The optional wording in Clause 11 does not apply. Under Clauses 17 and 18, the clauses are governed by Irish law and disputes go to the courts of Ireland. Annexes 1 to 3 of this DPA complete the clauses' annexes;
- for transfers from the United Kingdom, the International Data Transfer Addendum issued by the UK Information Commissioner applies, completed with the information in this DPA, and either party may end it as the Addendum allows;
- for transfers from Switzerland, the clauses apply with references to the GDPR read as references to the Swiss Federal Act on Data Protection, and the Swiss Federal Data Protection and Information Commissioner as the competent authority.
If these clauses conflict with the rest of this DPA, the clauses win.
12. US state privacy laws
Where the CCPA or a similar US state law applies, FreNiMi will not sell or share Customer Personal Data; will not keep, use or disclose it outside the direct business relationship with the customer or for any purpose other than providing the service; will not combine it with personal data from other sources except as those laws allow; and will give it the protection those laws require. FreNiMi will tell the customer if it can no longer meet these obligations, and the customer may then take reasonable steps to stop and fix unauthorized use.
13. General
Each party's liability under this DPA is subject to the limits in the Agreement, except where Data Protection Laws or the clauses in section 11 don't allow it. If this DPA conflicts with the rest of the Agreement on data protection, this DPA wins. FreNiMi may update this DPA to reflect changes in law or in the service, without reducing the protection it gives, and will tell customers of significant changes at least 30 days in advance.
Annex 1: Details of the processing
| Parties | Data exporter: the customer, as identified in its FreNiMiGuard account. Data importer: FreNiMi LLC, 1655 S Blue Island Ave, Suite 4050, Chicago, IL 60608, USA, info@frenimi.com. |
|---|---|
| Purpose | Providing FreNiMiGuard: tracking the customer's assets and software, matching them against known vulnerabilities, managing remediation and evidence, sending the alerts and reports the customer sets up, running the optional agent and its approved actions, and supporting the customer. |
| Nature of processing | Collecting, storing, organizing, matching, displaying, exporting, transmitting and deleting. |
| Data subjects | The customer's users of the service; staff named as owners or users of the customer's devices; and people the customer mentions in tasks, incidents and notes. |
| Personal data | Names and usernames, work email addresses, roles; device names (which can contain a person's name), IP addresses, installed software and update status; owner, department and location fields; audit trail entries; any personal data in free-text notes the customer writes. |
| Special categories | None intended. See section 3. |
| Frequency | Continuous, for as long as the service is provided. |
| Duration and retention | The term of the Agreement, then deletion as described in section 9. |
| Competent supervisory authority | The authority competent for the data exporter under Clause 13 of the Standard Contractual Clauses. |
Annex 2: Security measures
Keeping customers apart
- Every request is tied to one organization. The application limits every database query to that organization, and PostgreSQL row-level security enforces the same rule a second time, so a mistake in one layer does not expose another customer's data. Automated tests check every API operation for this.
Encryption
- All connections to the service, from browsers and from agents, use TLS.
- Passwords are stored only as salted scrypt hashes. Sign-in codes, device tokens, agent tokens and API keys are stored only as hashes.
- Integration credentials and each organization's agent signing key are encrypted in the database with authenticated encryption, using a key kept outside the database.
Access control
- Roles (administrator, analyst, auditor) limit what each user can do. API keys are limited to read-only or analyst access.
- Multi-factor authentication, emailed sign-in codes and SAML single sign-on are available to every customer. Sign-in and signup attempts are rate limited.
- FreNiMi staff access production systems only when needed, with multi-factor authentication.
The agent
- Remote actions are off until a customer administrator enables them, run only on machines installed with actions allowed, and by default need a second administrator's approval.
- Each action is signed with the organization's own key and checked by the agent before it runs, so an agent will not run an action signed for another organization.
Records and monitoring
- Every change in a workspace is recorded in its audit trail with who made it and when.
- Server logs are kept for up to 30 days for security investigation.
Resilience and maintenance
- Backups are taken daily, kept for 35 days, and restores are tested.
- FreNiMi applies security updates to its servers regularly and scans its code and dependencies for known vulnerabilities before release.
- FreNiMi follows a written process for responding to security incidents, including notifying customers as section 8 requires.
Annex 3: Subprocessors
| Subprocessor | Purpose | Data | Location |
|---|---|---|---|
| DigitalOcean, LLC | Hosting the service | All Customer Personal Data, stored on FreNiMi's servers | United States |
| Resend, Inc. | Delivering email | Recipients' email addresses and message content: sign-in codes, alerts and reports | United States |
| Stripe, Inc. | Payments and subscriptions | Billing contact details of the customer's administrators; no workspace data | United States |
