Data Processing Agreement

Frigo — a product of AMCO Trade & Finance AG
Bahnhofstrasse 23, 6300 Zug, Switzerland
CHE-108.622.594

Version 1.1 — Effective: 16.09.2026

Forms an integral part of the Frigo Terms & Conditions

I. Parties and Purpose

This Data Processing Agreement ("DPA") forms an integral part of the Frigo Terms & Conditions or other applicable agreement governing the use of Frigo (the "Main Agreement") and applies automatically, without separate signature, wherever:

AMCO Trade & Finance AG
Bahnhofstrasse 23
6300 Zug
Switzerland
CHE-108.622.594
("AMCO", "Processor")

processes personal data on behalf of a customer ("Customer", "Controller").

Contact for privacy and data protection matters:

privacy@frigo.online
+41 32 510 7810

This DPA is intended to satisfy the requirements of Article 28 of the EU General Data Protection Regulation ("GDPR"), the UK GDPR where applicable, and the Swiss Federal Act on Data Protection ("FADP").

This DPA applies only where AMCO processes personal data on behalf of Customer as a processor. Processing for which AMCO independently determines the purposes and means and acts as controller is governed by the Frigo Privacy Policy and applicable data protection law.

II. Scope and Instructions

AMCO processes personal data solely for the purpose of providing the Frigo Services, including:

  • user account management and authentication;

  • hosting and storage of platform data;

  • telemetry processing, storage, and dashboards;

  • alarms and notifications;

  • report generation;

  • device and connectivity management;

  • location-related functionality where enabled;

  • AI-assisted analysis where enabled;

  • customer support;

  • API and integration services;

  • maintenance and technical administration;

  • security, monitoring, and backups; and

  • other processing reasonably necessary to provide the Services under the Main Agreement.

AMCO shall process personal data only on documented instructions from Customer, including with regard to transfers of personal data to third countries or international organizations, unless required to do so by applicable law.

Where AMCO is required by law to process personal data other than according to Customer's documented instructions, AMCO shall inform Customer of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest.

The Main Agreement, this DPA, Customer's configuration and use of the Services, and other documented instructions agreed between the parties constitute Customer's documented instructions to AMCO.

AMCO shall immediately inform Customer if, in its opinion, an instruction infringes the GDPR, FADP, UK GDPR, or other applicable data protection law.
III. Data Subjects and Data Categories

Data subjects may include Customer’s employees, administrators, end users, contractors, site contacts, authorized platform users, and individuals associated with monitored assets or locations.

Personal data may include names, email addresses, phone numbers, usernames, job titles, company affiliation, user roles and permissions, login records, IP addresses, audit logs, location-related data where enabled, device assignments linked to users or sites, and notification contact details.

Frigo is designed for operational telemetry rather than sensitive personal data. Customer shall not upload special category data (Art. 9 GDPR) unless expressly agreed and lawfully permitted.

III. Data Subjects and Categories of Personal Data

Data subjects may include:

  • Customer's employees;

  • administrators;

  • authorized platform users;

  • contractors;

  • site contacts;

  • notification recipients;

  • end users; and

  • individuals associated with monitored assets, Devices, sites, or locations.

Personal data processed on behalf of Customer may include:

  • names;

  • email addresses;

  • telephone numbers;

  • usernames and account identifiers;

  • job titles;

  • company or organizational affiliation;

  • user roles and permissions;

  • authentication and login records;

  • IP addresses;

  • audit and security logs;

  • notification preferences and contact details;

  • device assignments associated with users, sites, or locations;

  • location-related data where enabled;

  • device, site, asset, or room identifiers that relate to identifiable individuals;

  • user-provided prompts or instructions submitted to AI-assisted functionality; and

  • telemetry or monitoring information where such information constitutes personal data because of its association with an identifiable individual.

Frigo is primarily designed for operational monitoring and telemetry rather than the processing of sensitive personal data.

Customer shall not use Frigo to process special categories of personal data within the meaning of Article 9 GDPR, or other particularly sensitive personal data, unless such processing is expressly supported by the Services, lawfully permitted, and, where necessary, separately agreed with AMCO.

IV. Duration

Processing continues for the duration of the Main Agreement and any applicable post-termination export period, followed by return or deletion in accordance with Section XI.

Individual processing activities may have shorter durations according to Customer configuration, the nature of the relevant data, and the functionality used.

V. Customer Responsibilities

Customer, as Controller, is responsible for:

  • ensuring a lawful basis for the processing;

  • providing required privacy information to data subjects, including notices required under Articles 13 and 14 GDPR;

  • obtaining consent where consent is required;

  • complying with employment, workplace, employee-representation, or similar requirements where location or employee-related monitoring is used;

  • determining whether a data protection impact assessment is required;

  • determining appropriate retention requirements and settings;

  • configuring user access rights and permissions;

  • ensuring the accuracy and lawfulness of personal data provided to Frigo;

  • ensuring that Customer's use of AI-assisted functionality does not unnecessarily disclose personal data;

  • ensuring that Customer has the necessary rights to provide personal data to AMCO for processing; and

  • issuing lawful documented instructions to AMCO.

Customer shall not instruct AMCO to process personal data in violation of applicable data protection law.

VI. Confidentiality

AMCO shall ensure that persons authorized to process Customer Personal Data have committed themselves to confidentiality or are subject to an appropriate statutory obligation of confidentiality.

Access to Customer Personal Data shall be limited to personnel and authorized service providers who require such access for the performance of their duties.

The confidentiality obligation shall continue after the relevant person's authorization to process personal data ends.

VII. Security

AMCO shall implement and maintain appropriate technical and organizational measures proportionate to the risks presented by the processing, as further described in Annex 2.

These measures include, as appropriate:

  • encrypted communications;

  • authentication and access controls;

  • role-based permissions;

  • least-privilege administration;

  • logging and monitoring;

  • secure hosting environments;

  • backup and recovery procedures;

  • vulnerability management, patching, and maintenance;

  • logical separation of customer data;

  • personnel access restrictions; and

  • incident detection and response procedures.

AMCO may update its technical and organizational measures as technology and risks evolve, provided that such updates do not materially reduce the overall level of protection provided for Customer Personal Data.

VIII. Subprocessors

Customer grants AMCO general authorization to engage subprocessors for the provision of the Frigo Services.

The categories and principal subprocessors engaged at the date of this DPA are described in Annex 3.

AMCO shall:

  • ensure that each subprocessor is engaged under written terms imposing data protection obligations appropriate to the processing and meeting applicable Article 28 GDPR requirements;

  • remain responsible to Customer for the performance of its subprocessors' data protection obligations to the extent required by applicable law;

  • maintain information concerning the subprocessors used for the Services; and

  • inform Customer of intended additions or replacements of subprocessors at least 30 days in advance where the new subprocessor will process Customer Personal Data.

Notification may be provided by email, through the Frigo platform, or through a published subprocessor list or other notification mechanism made available to Customer.

Customer may object to a new subprocessor during the notification period on reasonable grounds relating specifically to data protection.

The parties shall work in good faith to resolve a reasonable objection. Where an objection cannot reasonably be resolved, Customer may terminate the affected Services with effect from the date on which the relevant subprocessor begins processing Customer Personal Data.

A service provider that is being evaluated or tested by AMCO but does not process production Customer Personal Data is not considered an active subprocessor for purposes of this Section.

IX. Data Subject Rights and Assistance

Taking into account the nature of the processing, AMCO shall assist Customer by appropriate technical and organizational measures, insofar as reasonably possible, in fulfilling Customer's obligations to respond to requests from data subjects exercising their rights under applicable data protection law.

If a data subject contacts AMCO directly concerning Customer Personal Data processed solely on behalf of Customer, AMCO shall, unless legally prohibited, refer the request to Customer or otherwise inform Customer without undue delay.

AMCO shall not independently respond to such a request except on Customer's documented instructions or where required by applicable law.

Taking into account the nature of processing and the information available to AMCO, AMCO shall also reasonably assist Customer with compliance obligations relating to:

  • security of processing;

  • personal data breach notification;

  • data protection impact assessments; and

  • prior consultation with supervisory authorities,

including Articles 32–36 GDPR where applicable.

AMCO may charge reasonable fees for extensive or extraordinary assistance beyond the standard Services where permitted by applicable law, provided that legally required assistance is not withheld.

X. Personal Data Breach Notification

AMCO shall notify Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data.

To the extent information is available, the notification shall describe:

  • the nature of the personal data breach;

  • the categories and approximate number of affected data subjects;

  • the categories and approximate number of affected personal data records;

  • the likely consequences of the breach;

  • measures taken or proposed to address the breach and mitigate possible adverse effects; and

  • an appropriate contact point for further information.

Where complete information is not immediately available, AMCO may provide information in phases without undue further delay.

AMCO shall document relevant personal data breaches and reasonably cooperate with Customer in meeting Customer's notification and documentation obligations.

Notification of a personal data breach shall not constitute an acknowledgement of fault or liability by AMCO.

XI. Return and Deletion of Data

Upon termination or expiry of the Main Agreement, AMCO shall, at Customer's choice and subject to the functionality of the Services, return Customer Personal Data and/or delete it, unless applicable law requires continued storage.

Unless Customer instructs otherwise, Customer may export available Customer data for 30 days following termination.

After the applicable export period, AMCO shall delete Customer Personal Data from active production systems in accordance with its standard deletion procedures, unless continued storage is required by applicable law.

Residual copies contained in backups may remain until overwritten or deleted in accordance with AMCO's normal backup lifecycle. During that period, backup data shall remain protected and shall not be used for ordinary processing except where necessary for restoration, security, disaster recovery, or compliance with applicable law.

Where Customer Personal Data must be retained under applicable law, AMCO shall continue to protect that data and shall process it only for the purpose requiring its retention.

Upon reasonable request, AMCO shall provide confirmation concerning completion of deletion.

XII. Audits and Information Rights

AMCO shall make available to Customer information reasonably necessary to demonstrate compliance with its obligations under Article 28 GDPR and equivalent applicable data protection requirements.

AMCO shall allow for and contribute to reasonable audits, including inspections, conducted by Customer or an independent auditor mandated by Customer.

Unless otherwise required by a competent supervisory authority or applicable law, audits shall:

  • be notified at least 30 days in advance;

  • occur no more than once in any 12-month period;

  • take place during normal business hours;

  • be reasonable and proportionate in scope;

  • avoid unnecessary disruption to AMCO's operations;

  • not compromise the security, confidentiality, or rights of other customers or third parties;

  • be subject to appropriate confidentiality obligations; and

  • be conducted at Customer's cost.

AMCO may satisfy audit or information requests in the first instance by providing available third-party certifications, security documentation, audit reports, completed security questionnaires, or other appropriate evidence.

Nothing in this Section restricts audit rights that cannot lawfully be limited.

XIII. Data Hosting and International Transfers

The core Frigo platform infrastructure and primary Customer Personal Data are hosted within the European Union, currently in Frankfurt, Germany.

AMCO may engage subprocessors established outside Germany, the EEA, Switzerland, or the United Kingdom where necessary to provide specific Services.

Where Customer Personal Data subject to GDPR is transferred to a country that does not benefit from an applicable adequacy decision, AMCO shall ensure that an appropriate transfer mechanism is in place.

Where required, the European Commission Standard Contractual Clauses adopted under Commission Implementing Decision (EU) 2021/914 are incorporated or otherwise implemented between the relevant parties.

The applicable SCC module shall be determined according to the roles of the parties in the relevant transfer, including:

  • Module 2 (Controller to Processor) where Customer as Controller transfers personal data directly to AMCO as Processor; and

  • Module 3 (Processor to Processor) where AMCO, acting as Processor on behalf of Customer, transfers Customer Personal Data to a subprocessor.

Where Swiss data protection law applies, the relevant safeguards shall be interpreted and supplemented as necessary to satisfy the FADP and applicable guidance of the Swiss Federal Data Protection and Information Commissioner ("FDPIC").

Where UK GDPR applies, an appropriate UK transfer mechanism, including the UK International Data Transfer Addendum where applicable, shall be used.

AMCO shall implement supplementary safeguards where reasonably required following an assessment of the relevant transfer.

XIV. Liability

Liability under this DPA is subject to the limitations and exclusions contained in the Main Agreement, except to the extent liability cannot lawfully be excluded or limited under applicable data protection law.

Nothing in this DPA limits either party's obligations toward data subjects or competent supervisory authorities where such obligations cannot lawfully be limited by contract.

XV. Order of Precedence, Governing Law and Contact

In the event of a conflict between this DPA and the Main Agreement concerning the processing of personal data, this DPA prevails.

Where applicable Standard Contractual Clauses conflict with this DPA, the Standard Contractual Clauses prevail to the extent of the conflict.

This DPA is governed by the law governing the Main Agreement or, if no governing law is specified there, substantive Swiss law, subject to any mandatory provisions applicable to international data transfers.

Contact for privacy and data protection matters:

AMCO Trade & Finance AG
Bahnhofstrasse 23
6300 Zug
Switzerland

privacy@frigo.online
frigo.online
+41 32 510 7810

Annex 1 - Processing Summary

Subject matter:
Provision of the Frigo IoT monitoring platform and related Services.

Nature of processing:
Collection, receipt, hosting, storage, organization, transmission, retrieval, display, reporting, alerting, analysis, AI-assisted analysis where enabled, location processing where enabled, support, backup, and deletion.

Purposes:
Operational monitoring, analytics, alarms and notifications, reporting, device and connectivity management, customer administration, support, security, maintenance, and provision of related Frigo functionality.

Duration:
The term of the Main Agreement plus any applicable export, backup, legal retention, and deletion periods described in this DPA.

Categories of data subjects:
As described in Section III.

Categories of personal data:
As described in Section III.

Special categories of personal data:
Not intended to be processed as part of the standard Frigo Services unless expressly agreed and lawfully permitted.

Frequency of processing:
Continuous or as initiated by Customer, users, Devices, integrations, or configured platform functions

Annex 2 - Technical and Organizational Measures

AMCO maintains technical and organizational measures appropriate to the nature, scope, context, and purposes of processing and the risks to individuals.

These measures include, as applicable:

Transport encryption:
TLS-protected communications for web, application, and API traffic and secured MQTT communications for Device telemetry.

Access control:
Role-based permissions, least-privilege administration, individual user accounts, controlled administrative access, and revocation of access when no longer required.

Authentication:
Authentication controls, password policies, securely hashed credential storage, and restricted administrative access.

Logging and monitoring:
Audit logging of relevant platform and administrative activity together with infrastructure, application, and security monitoring.

Hosting:
Core Frigo platform infrastructure and primary Customer Personal Data hosted in EU data centers, currently in Frankfurt, Germany, using professional infrastructure and cloud service providers.

Data separation:
Logical separation of customer data through tenant and authorization controls.

Availability and resilience:
Backup and recovery procedures and infrastructure-level resilience appropriate to the Services.

Maintenance and vulnerability management:
Regular software maintenance, security updates, patching, dependency management, and vulnerability remediation procedures.

Incident response:
Procedures for detection, investigation, escalation, containment, remediation, and documentation of security incidents.

Personnel:
Confidentiality obligations and access limited according to role and operational need.

Backups:
Controlled backup and recovery procedures, with backup data protected against unauthorized access and removed according to the applicable backup lifecycle.

Data minimization:
Processing limited, where reasonably practicable, to information necessary to provide and operate the relevant Frigo functionality.

AMCO may update these measures to reflect changes in technology, security risks, or the Services, provided that the overall level of protection is not materially reduced.

Annex 3 - Subprocessors

AMCO uses third-party subprocessors where necessary to provide Frigo. The precise providers involved may depend on the functionality, Device type, connectivity arrangement, geographic region, and Customer configuration.

Current principal subprocessors that may process Customer Personal Data include:


Render Services, Inc. — United States

Service: Cloud application and backend infrastructure.

Processing: Hosting and processing of Frigo backend services and associated application data.

Primary Frigo processing location: Frankfurt, Germany.

Transfer safeguards: Appropriate contractual transfer safeguards, including Standard Contractual Clauses where required.

THINGSBOARD, Inc. — United States

Service: ThingsBoard Cloud IoT platform.

Processing: IoT Device management, telemetry, alarms, dashboards, customer/site associations, platform configuration, and related IoT data.

Primary Frigo processing location: Frankfurt, Germany.

Transfer safeguards: Appropriate contractual transfer safeguards, including Standard Contractual Clauses where required.

HiveMQ GmbH — Germany

Service: MQTT and IoT messaging infrastructure.

Processing: Transmission and handling of Device telemetry and associated Device/network identifiers.

Processing region used by Frigo: Frankfurt, Germany / European Union.

OpenAI Ireland Ltd. — Ireland

Service: AI-assisted analysis used by Frigo AI.

Processing: Processing of information submitted to enabled AI-assisted Frigo functionality, which may include telemetry, alarms, Device or site context, operational information, and user-provided prompts where such information constitutes Customer Personal Data.

Transfer safeguards: OpenAI's applicable data-processing terms and appropriate safeguards for onward transfers, including Standard Contractual Clauses or applicable adequacy mechanisms where required.

AMCO seeks to minimize Customer Personal Data transmitted to AI services and does not intentionally submit payment card information or other information unnecessary for the requested analysis.

Stripe Payments Europe, Limited — Ireland

Service: Payment processing, billing, subscription management, and related financial services.

Processing: Customer, billing, transaction, subscription, and payment-related information.

Stripe may act as a processor or independent controller depending on the relevant processing activity.

Combain Mobile AB — Sweden

Service: Geolocation and positioning services, where enabled.

Processing: Network, Wi-Fi scan, Device, or related technical information necessary to resolve or determine Device location.

Combain is relevant only where location functionality using its services is enabled.

Hutchison Drei Austria GmbH — Austria

Service: LoRaWAN connectivity and network services for supported Frigo deployments, including associated network infrastructure provided through Drei.

Processing: Device and gateway identifiers, network and connectivity metadata, and related technical information required to provide LoRaWAN connectivity.

Other technical providers, including email delivery, mobile push-notification, security, support, or connectivity providers, may process limited Customer Personal Data where necessary to provide the relevant functionality.

AMCO maintains information regarding active subprocessors and will notify Customer of material additions or replacements involving Customer Personal Data in accordance with Section VIII.

Providers undergoing technical evaluation or testing that do not process production Customer Personal Data are not considered active subprocessors under this Annex.