Frostbridge logo FROSTBRIDGE
Legal Security Support
Back Home
Data Processing

Data Processing Addendum

The processor terms that apply when Frostbridge processes personal data on a customer's behalf.

Contents

1 Definitions2 Roles3 Processing instructions4 Customer responsibilities5 Confidentiality6 Security measures7 Subprocessors8 Data subject requests9 Personal Data Breach10 Assistance and audits11 Return and deletion12 International transfers13 U.S. state privacy laws14 AI and model useAnnex A - Processing detailsAnnex B - Transfer-mechanism details
Customer AgreementTerms of UseAUPPrivacy PolicySubprocessors

Frostbridge AI | Legal Terms

Data Processing Addendum

Effective Date: August 7, 2026

This Data Processing Addendum ("DPA") forms part of the Frostbridge Customer Agreement or other written agreement between Frostbridge AI, Inc., doing business as Frostbridge ("Frostbridge"), and the customer that has agreed to the Customer Agreement ("Customer"). This DPA applies when Frostbridge processes Personal Data on behalf of Customer as a processor, service provider, or equivalent role under applicable Data Protection Laws.

1 Definitions

"Customer Data" means data submitted to or made available to Frostbridge by or on behalf of Customer through the Services. "Personal Data" means Customer Data that relates to an identified or identifiable individual and is protected by Data Protection Laws. "Data Protection Laws" means applicable privacy, data protection, and data security laws, including, where applicable, GDPR, UK GDPR, Swiss FADP, and U.S. state privacy laws.

2 Roles

For Customer Data, Customer is the controller/business and Frostbridge is the processor/service provider, except where Frostbridge processes personal information as an independent controller for its own account administration, billing, security, analytics, and business operations as described in the Privacy Policy.

3 Processing instructions

Frostbridge will process Personal Data only to provide, secure, maintain, support, and improve the Services; to comply with Customer's documented instructions; as otherwise permitted by the Customer Agreement; and as required by law. Customer's documented instructions include the Customer Agreement, this DPA, the Subscription Record, Customer's configurations, integrations, settings, and use of the Services.

4 Customer responsibilities

Customer is responsible for determining the lawfulness of its use of the Services; providing notices and obtaining consents; maintaining required policies for employees, contractors, end users, and monitored individuals; ensuring it has rights to connect systems and deploy agents/extensions; and avoiding submission of data that is prohibited under the Customer Agreement or Acceptable Use Policy.

5 Confidentiality

Frostbridge will ensure that personnel authorized to process Personal Data are bound by appropriate confidentiality obligations.

6 Security measures

Frostbridge will implement and maintain reasonable technical and organizational measures designed to protect Personal Data against unauthorized or unlawful processing and accidental loss, destruction, or damage. Measures may include access controls, encryption in transit, encryption at rest where supported, logging, vulnerability management, personnel access restrictions, backup practices, incident response procedures, and vendor risk management. Specific measures may be described in the Frostbridge Security & Trust Center at /security.

7 Subprocessors

Customer authorizes Frostbridge to use subprocessors to provide the Services. Frostbridge will maintain a Subprocessor List at /legal/subprocessors and will impose data protection obligations on subprocessors that are materially consistent with this DPA. Frostbridge may update subprocessors from time to time.

Frostbridge will provide notice of new subprocessors by updating the Subprocessor List and, for customers that have requested advance notice, by sending notice to the email address provided by Customer for that purpose or to Customer's account or billing contact. Customer may request subprocessor notifications by emailing privacy@frostbridge.ai.

If required by applicable law or contract, Customer may object to a new subprocessor by sending written notice to privacy@frostbridge.ai within thirty (30) days after notice of the new subprocessor. Customer's objection must explain the reasonable data-protection grounds for the objection. The parties will work in good faith to resolve the objection. If the parties cannot resolve the objection, Frostbridge may, where commercially reasonable, avoid use of the objected-to subprocessor for Customer's Personal Data or permit Customer to terminate the affected Services and receive a pro rata refund of prepaid unused fees for the terminated portion. Frostbridge may use a subprocessor without advance notice where reasonably necessary to address security, availability, abuse, legal, or emergency operational needs, but will provide notice as soon as reasonably practicable.

8 Data subject requests

To the extent legally required and reasonably possible, Frostbridge will assist Customer in responding to requests from individuals to exercise privacy rights. If Frostbridge receives a request directly relating to Customer Data, Frostbridge may direct the requester to Customer.

9 Personal Data Breach

Frostbridge will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Data. Frostbridge will provide information reasonably available to assist Customer in meeting legal obligations, taking into account the nature of the Services and the information available to Frostbridge.

10 Assistance and audits

Taking into account the nature of processing and information available to Frostbridge, Frostbridge will provide reasonable assistance with Customer's compliance obligations relating to security, breach notification, data protection impact assessments, and regulator consultations. Customer may request reasonable information about Frostbridge's security and compliance program. On-site audits are not permitted unless required by Data Protection Laws and cannot be satisfied by documentation, reports, or third-party assessments.

11 Return and deletion

Upon termination or expiration of the Services, Frostbridge will return or delete Customer Data in accordance with the Customer Agreement, product functionality, backup practices, and legal obligations. Backup copies may persist for a limited period and will be protected in accordance with this DPA.

12 International transfers

Where Customer's use of the Services involves a restricted transfer of Personal Data under applicable Data Protection Laws, the parties will use an appropriate transfer mechanism.

For transfers subject to GDPR, the parties incorporate by reference the European Commission's standard contractual clauses for international transfers adopted under Commission Implementing Decision (EU) 2021/914 ("EU SCCs"), as follows: Module Two applies where Customer acts as controller and Frostbridge acts as processor; Module Three applies where Customer acts as processor and Frostbridge acts as subprocessor. For purposes of the EU SCCs, Customer is the data exporter and Frostbridge is the data importer, unless the parties' roles under Data Protection Laws require otherwise.

For transfers subject to UK GDPR, the parties incorporate by reference the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner's Office ("UK Addendum"). The information required to complete the UK Addendum is supplied by this DPA, the Customer Agreement, the Subscription Record, Annex A, the Subprocessor List, and the security measures described in Section 6 and /security.

For transfers subject to Swiss FADP, the EU SCCs apply with modifications required by Swiss law, including that references to GDPR are interpreted to include the Swiss FADP where applicable, references to supervisory authority include the Swiss Federal Data Protection and Information Commissioner, and data subjects in Switzerland may enforce their rights under the EU SCCs.

Annex A below describes the processing details. Annex B below describes transfer-mechanism details. Annex C is the Subprocessor List at /legal/subprocessors. If a transfer mechanism is invalidated, replaced, or no longer sufficient under applicable law, the parties will work in good faith to implement a lawful replacement mechanism.

13 U.S. state privacy laws

To the extent applicable, Frostbridge will act as Customer's service provider/processor for Personal Data processed under the Services. Frostbridge will not sell Customer Data, share Customer Data for cross-context behavioral advertising, or retain, use, or disclose Customer Data outside the business purposes of providing the Services, except as permitted by applicable law and the Customer Agreement.

14 AI and model use

Unless otherwise stated in the Customer Agreement, Frostbridge may process Customer Data using automated systems and AI models to provide, secure, debug, maintain, and improve the Services. Frostbridge will not use Customer Data to train third-party foundation models except as expressly disclosed or agreed in writing.

Annex A - Processing details

Subject matter: Provision of Frostbridge's AI/security SaaS, monitoring, connectors, agents/extensions, APIs, alerts, workflows, reporting, and support.

Duration: The term of Customer's subscription plus any post-termination retention period.

Nature and purpose: Security monitoring, shadow AI detection, AI governance, telemetry analysis, alerting, investigation, reporting, support, account administration, debugging, abuse prevention, and service improvement.

Categories of data subjects: Customer personnel, contractors, administrators, end users, customer representatives, and other individuals whose information is made available through Customer-connected systems.

Categories of Personal Data: Account information, identifiers, device metadata, browser metadata, security events, access logs, cloud/SaaS/repository metadata, prompt/response content or metadata depending on configuration, communications metadata, IP addresses, audit logs, and support content.

Sensitive data: The Services are not designed for unrestricted processing of sensitive personal data unless expressly enabled and configured by Customer. Customer is responsible for limiting sensitive data submitted to the Services and for any required notices, consents, and legal bases.

Annex B - Transfer-mechanism details

Data exporter: Customer, as identified in the Subscription Record, account records, or applicable agreement.

Data importer: Frostbridge AI, Inc., a Delaware corporation with offices at 202 S Parker St, Tampa, FL 33606, USA.

Roles/modules: EU SCC Module Two for controller-to-processor transfers and Module Three for processor-to-subprocessor transfers, as applicable.

Frequency of transfers: Continuous or as initiated by Customer's use, configurations, integrations, agents, connectors, support requests, and subscription administration.

Purpose of transfers: The purposes described in Annex A and the Customer Agreement.

Categories of personal data and data subjects: As described in Annex A.

Subprocessors: Listed at /legal/subprocessors.

Technical and organizational measures: The measures described in Section 6, the Customer Agreement, and /security, including access controls, encryption in transit, encryption at rest where supported, logging, vulnerability management, incident response, personnel access restrictions, backup practices, and vendor risk management.

Competent supervisory authority: Determined in accordance with Clause 13 of the EU SCCs and applicable Data Protection Laws.

1 Definitions2 Roles3 Processing instructions4 Customer responsibilities5 Confidentiality6 Security measures7 Subprocessors8 Data subject requests9 Personal Data Breach10 Assistance and audits11 Return and deletion12 International transfers13 U.S. state privacy laws14 AI and model useAnnex A - Processing detailsAnnex B - Transfer-mechanism details
© 2026 Frostbridge AI, Inc. All rights reserved.
Customer AgreementTerms of UseAUPPrivacy PolicyDPASubprocessors Security Support privacy@frostbridge.ai