Data Processing Addendum (DPA)
Effective Date: January 1, 2024
Last Updated: January 1, 2024
1. Scope and Parties
This DPA forms part of the Terms of Service between FrejFund ("Processor") and the customer ("Controller"). It applies to the processing of personal data by FrejFund on behalf of the customer in connection with the Services.
2. Roles and Instructions
The customer is the Controller and determines the purposes and means of processing. FrejFund acts as Processor and shall process personal data only on documented instructions from the Controller, including with regard to transfers to third countries.
3. Nature and Purpose of Processing
FrejFund processes uploaded documents, user inputs, and related metadata to provide AI-powered analysis, investor matching, and related Services.
4. Data Types and Data Subjects
Personal data may include contact details, business profile data, communications, and optionally financial or investment-related information concerning customer personnel, representatives, founders, or other data subjects.
5. Security Measures
- Encryption in transit and at rest where available
- Access controls and authentication
- Logging and monitoring of access
- Regular security reviews
6. Subprocessors
FrejFund uses subprocessors to deliver the Services, including cloud hosting and AI providers. Current subprocessors include: cloud infrastructure (e.g., AWS), email delivery, analytics (opt-in), and AI API providers (e.g., OpenAI). A current list is available upon request and may be updated from time to time.
7. International Transfers
Transfers outside the EEA/UK use appropriate safeguards, including Standard Contractual Clauses where applicable.
8. Data Subject Rights
FrejFund will assist the Controller by appropriate technical and organizational measures to fulfill obligations to respond to requests to exercise data subject rights.
9. Confidentiality
FrejFund ensures that persons authorized to process personal data have committed to confidentiality or are under an appropriate statutory obligation of confidentiality.
10. Deletion or Return
Upon termination of the Services, FrejFund will delete or return all personal data to the Controller, unless storage is required by law.
11. Audits
FrejFund will make available information necessary to demonstrate compliance with this DPA and allow for audits or inspections by the Controller or an auditor mandated by the Controller, subject to reasonable notice and confidentiality.
12. Contact
For DPA-related inquiries, contact privacy@frejfund.com.
