Data Processing Agreement

Frigo — a product of AMCO Trade & Finance AG, Bahnhofstrasse 23, 6300 Zug, Switzerland
Version 1.0 — Effective: 10.08.2026 — Forms an integral part of the Frigo Terms & Conditions

I. Parties and Purpose

This Data Processing Agreement ("DPA") forms an integral part of the Frigo Terms & Conditions or other applicable agreement governing the use of Frigo (the "Main Agreement") and applies automatically, without separate signature, wherever AMCO Trade & Finance AG, Bahnhofstrasse 23, 6300 Zug, Switzerland, CHE-108.622.594 ("AMCO", "Processor") processes personal data on behalf of a customer ("Customer", "Controller").

AMCO Trade & Finance AG
privacy@frigo.online
+41.32.510.7810

This DPA is intended to satisfy the requirements of Art. 28 of the EU General Data Protection Regulation (GDPR), the UK GDPR (where applicable), and the Swiss Federal Act on Data Protection (FADP).

II. Scope and Instructions

AMCO processes personal data solely for the purpose of providing Frigo services, including user account management, authentication, hosting of platform data, telemetry storage and dashboards, alerts and notifications, report generation, customer support, API services, and maintenance, security, and backups.

AMCO shall process personal data only on documented instructions from Customer, including with regard to transfers to third countries, unless required to do so by law to which AMCO is subject; in that case, AMCO shall inform Customer of that legal requirement before processing, unless the law prohibits such information on important grounds of public interest.

AMCO shall immediately inform Customer if, in its opinion, an instruction infringes the GDPR, the FADP, or other applicable data protection provisions.

III. Data Subjects and Data Categories

Data subjects may include Customer’s employees, administrators, end users, contractors, site contacts, authorized platform users, and individuals associated with monitored assets or locations.

Personal data may include names, email addresses, phone numbers, usernames, job titles, company affiliation, user roles and permissions, login records, IP addresses, audit logs, location-related data where enabled, device assignments linked to users or sites, and notification contact details.

Frigo is designed for operational telemetry rather than sensitive personal data. Customer shall not upload special category data (Art. 9 GDPR) unless expressly agreed and lawfully permitted.

IV. Duration

Processing continues for the duration of the Main Agreement and any agreed post-termination export period, followed by deletion in accordance with Section 11.

V. Customer Responsibilities

Customer is responsible for: ensuring a lawful basis for processing; providing required notices to data subjects (including its own employees and site personnel, Arts. 13/14 GDPR); obtaining consents and, where applicable, completing employee-representation procedures for location tracking; determining retention settings; configuring access rights; the accuracy of uploaded data; and issuing lawful instructions to AMCO.

VI. Confidentiality

AMCO shall ensure that persons authorized to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

VII. Security (Art. 32 GDPR)

AMCO implements and maintains appropriate technical and organizational measures proportionate to the risk, as described in Annex 2, including encrypted communications (TLS), access controls and role permissions, authentication controls, logging and monitoring, secure hosting environments, backup and recovery procedures, patching and maintenance, least-privilege principles, and incident response procedures.

VIII. Subprocessors

Customer grants AMCO general authorization to engage subprocessors for the provision of Frigo services. The subprocessors engaged at the date of this DPA are listed in Annex 3.

AMCO Shall:

  • inform Customer of any intended addition or replacement of subprocessors at least 30 days in advance (email or notice via the platform or the published subprocessor list is sufficient)

  • give Customer the opportunity to object on reasonable data protection grounds within that period; if the objection cannot be resolved, Customer may terminate the affected services with effect from the date the change takes effect

  • impose on each subprocessor, by way of contract, data protection obligations no less protective than those in this DPA

  • remain fully liable to Customer for the performance of each subprocessor’s obligations

IX. Data Subject Rights and Assistance

Taking into account the nature of the processing, AMCO shall assist Customer by appropriate technical and organizational measures, insofar as possible, in fulfilling Customer’s obligation to respond to data subject requests (Arts. 12–23 GDPR). If a data subject contacts AMCO directly, AMCO will refer the request to Customer without undue delay.

AMCO shall further assist Customer in ensuring compliance with the obligations pursuant to Arts. 32–36 GDPR (security, breach notification, data protection impact assessments, and prior consultation), taking into account the nature of processing and the information available to AMCO.

AMCO may charge reasonable fees for extensive or extraordinary assistance not included in standard services, provided the assistance itself is not withheld.

X. Personal Data Breach Notification

AMCO shall notify Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer personal data.

The notification shall, to the extent available, describe: the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. Information may be provided in phases as it becomes available. AMCO shall document breaches and reasonably cooperate with Customer’s own notification obligations.

XI. Return and Deletion of Data

Upon termination of the Main Agreement, at Customer’s choice, AMCO shall return all personal data processed on Customer’s behalf (in a common, machine-readable format) and/or delete it, unless storage is required by law.

Unless Customer instructs otherwise, Customer may export its data for 30 days after termination; thereafter AMCO deletes the personal data within [30 days], and backup copies are purged on rotating schedules within [90 days]. Upon request, AMCO shall confirm deletion in writing.

XII. Audits and Information Rights

AMCO shall make available to Customer all information reasonably necessary to demonstrate compliance with the obligations laid down in Art. 28 GDPR, and shall allow for and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer.

Unless required otherwise by a supervisory authority or applicable law, audits shall: be announced at least 30 days in advance; occur at most once per 12 months; take place during business hours; be reasonable in scope; not compromise the security or confidentiality of other customers; be subject to confidentiality obligations; and be at Customer’s cost. AMCO may satisfy audit requests in the first instance by providing current third-party certifications, audit reports, or completed security questionnaires.

XIII. International Transfers

AMCO processes Frigo production data on EU infrastructure (see Annex 3). Where personal data is transferred to a country outside Switzerland, the EEA, or the UK that does not provide an adequate level of protection, the parties agree that the EU Standard Contractual Clauses (Module 2: Controller to Processor) as adopted by the European Commission are incorporated into this DPA by reference, completed with the details in the Annexes, together with the Swiss addendum recognized by the FDPIC (competent authority: FDPIC; references to the GDPR understood as references to the FADP where Swiss law applies) and, where UK GDPR applies, the UK International Data Transfer Addendum.

XIV. Liability

Liability under this DPA is subject to the limitations and exclusions set out in the Main Agreement, except to the extent liability cannot be limited under applicable data protection law.

XV. Order of Precedence, Law, Contact

In case of conflict between this DPA and the Main Agreement regarding the processing of personal data, this DPA prevails. This DPA is governed by the law governing the Main Agreement, or, if none is specified, by substantive Swiss law.

Contact for privacy and data protection matters: AMCO Trade & Finance AG, Bahnhofstrasse 23, 6300 Zug, Switzerland — privacy@frigo.onlinehttps://frigo.online.

Annex 1 - Processing Summary

  • Subject matter: provision of Frigo IoT monitoring platform services.

  • Nature of processing: hosting, storage, transmission, organization, retrieval, reporting, alerting, automated analysis, deletion.

  • Purpose: monitoring, analytics, customer administration, support, and related services.

  • Duration: term of the Main Agreement plus the export and deletion periods in Section 11.

  • Data subjects and data categories: as described in Section 3.

  • Frequency: continuous.

Annex 2 - Technical and Organizational Measures

  • Transport encryption: TLS for web, API, and app traffic; secured MQTT for device telemetry.

  • Access control: role-based permissions, least-privilege administration, personal accounts, revocation on offboarding.

  • Authentication: password policies and hashed credential storage; [multi-factor authentication for administrative access — confirm].

  • Logging and monitoring: audit logs of platform and administrative activity; system monitoring and alerting.

  • Hosting: EU data centers (Frankfurt, Germany) operated by professional infrastructure providers with physical security controls.

  • Availability: backup and recovery procedures; redundancy at infrastructure level.

  • Maintenance: regular patching and vulnerability management.

  • Incident response: defined procedures for detection, escalation, and remediation of security incidents.

  • Personnel: confidentiality commitments; access limited to personnel who need it.

  • Data separation: logical separation of customer data by tenant.

Annex 3 - Subprocessors

Current subprocessors engaged for the processing of Customer personal data:

  • [Hosting provider legal name and country of establishment — TO CONFIRM (Render Inc., USA? ThingsBoard Inc., USA? self-hosted?)] — platform hosting and backend — processing location: Frankfurt, Germany — [transfer mechanism if US-controlled: SCCs / EU–US Data Privacy Framework]

  • HiveMQ GmbH (Germany) — MQTT telemetry transport — Frankfurt, Germany

  • Stripe Payments Europe, Limited (Ireland; group companies in the USA) — payment processing and billing — transfer mechanism: SCCs / EU–US Data Privacy Framework

  • Combain Mobile AB (Sweden) — geolocation and positioning services, where enabled

  • Hutchison Drei Austria GmbH (Austria) — cellular connectivity (network metadata)

  • ThingPark Wireless / Actility SA (France) — LoRaWAN network services (network metadata)

  • [Email/support tooling provider(s) — name if customer personal data is processed there]

  • AI analysis provider (Frigo AI) — to be confirmed; required here only if personal data (e.g. user names, or site/asset names with personal references within prompts or reports) is processed by an external provider; include legal entity, country, and transfer mechanism

The current subprocessor list is also published at [https://frigo.online/subprocessors] and updated in accordance with Section 8.