Privacy Policy

Frigo — a product of AMCO Trade & Finance AG
Bahnhofstrasse 23, 6300 Zug, Switzerland
CHE-108.622.594

Version 1.1 — Effective: 16.09.2026

I. Introduction and Controller

This Privacy Policy explains how personal data is collected, used, disclosed, stored, and protected in connection with Frigo, a monitoring platform for critical spaces consisting of software, connected devices, mobile applications, and related services ("Frigo" or the "Services").

Frigo is operated by:

AMCO Trade & Finance AG
Bahnhofstrasse 23
6300 Zug
Switzerland
CHE-108.622.594

privacy@frigo.online
https://frigo.online

Depending on the circumstances, AMCO may process personal data as a data controller or as a data processor on behalf of a customer, as explained below.

This Privacy Policy applies to users of the Frigo website, platform, mobile applications, and related Services.

II. Scope and Data Protection Roles

Frigo is available to both business customers and individual consumers.

Where AMCO Acts as Controller

AMCO generally acts as the controller for personal data processed for its own purposes, including:

  • individual customer account and subscription information;

  • business customer account administration and commercial contacts;

  • billing and payment administration;

  • customer support communications;

  • website and application security;

  • authentication and account management;

  • service administration;

  • legal and regulatory compliance; and

  • communications concerning the Services.

Where an individual subscribes directly to Frigo as a Consumer, AMCO generally acts as controller for the personal data required to establish, administer, and provide that individual's Frigo account and subscription.

Where AMCO Acts as Controller

Where a business, organization, healthcare provider, laboratory, retailer, facility operator, or other customer uses Frigo to process personal data relating to its employees, contractors, customers, patients, users, or other individuals, that customer generally determines the purposes and means of such processing and acts as controller.

In those circumstances, AMCO generally acts as processor on behalf of the customer and processes the relevant personal data according to the customer's instructions and the applicable Frigo Data Processing Agreement ("DPA").

Individuals whose personal data is processed by one of our organizational customers should generally direct privacy requests relating to that processing to the relevant customer as controller.

III. Personal Data We Collect

Depending on how Frigo is used, we may process the following categories of personal data.

Account and Identity Data

This may include:

  • name;

  • email address;

  • telephone number, where provided;

  • user ID and account identifiers;

  • organization or company;

  • role and permissions;

  • preferred language;

  • authentication and account status information.

Billing and Subscription Data

This may include:

  • billing name and address;

  • country of residence or establishment;

  • company information;

  • VAT identification number, where applicable;

  • subscription plan;

  • subscription status;

  • billing currency;

  • transaction and invoice information;

  • payment status;

  • evaluation period information;

  • reference or promotional codes; and

  • payment provider identifiers.

Payment card details are processed by our authorized payment provider and are not intended to be stored directly by AMCO.

Device, Site and Monitoring Data

Depending on the Services and Devices used, Frigo may process:

  • device identifiers;

  • sensor identifiers and serial numbers;

  • gateway identifiers;

  • customer, site, asset, room, or location associations;

  • temperature;

  • humidity;

  • battery level;

  • signal quality;

  • connectivity information;

  • timestamps;

  • alarm and event data;

  • device status;

  • diagnostic information; and

  • other telemetry generated by supported Devices.

Sensor measurements such as temperature or humidity do not necessarily constitute personal data by themselves. They may, however, become personal data where they are associated with an identifiable individual, account, household, site, or other information relating to a natural person.

Location Data

Certain Frigo Devices or features may support location-related functionality.

Depending on the Device and enabled functionality, this may include:

  • GPS-derived location;

  • approximate network-based location;

  • Wi-Fi scan information used for location resolution;

  • gateway or network-derived location;

  • movement information; and

  • location timestamps.

Location functionality is processed only where required for the relevant Device or feature.

Technical and Usage Data

We may process:

  • IP address;

  • browser type;

  • operating system;

  • application version;

  • device type;

  • login timestamps;

  • session information;

  • application events;

  • error and diagnostic logs;

  • security events; and

  • other technical information necessary to operate and protect the Services.

Communications and Support Data

When you contact us, we may process:

  • your contact information;

  • correspondence;

  • support requests;

  • troubleshooting information;

  • attachments you provide; and

  • records relating to the resolution of your request.

IV. How We Collect Personal Data

We collect personal data:

  • directly from you when you create an account, subscribe, contact us, or configure the Services;

  • from an organization that creates or manages an account for you;

  • automatically through the Frigo platform, applications, Devices, and associated infrastructure;

  • from connected sensors, gateways, and network services;

  • from payment and billing providers;

  • from integrations authorized by Customer; and

  • from service providers involved in delivering the Services.

V. Purposes of Processing

We process personal data as necessary to:

  • create and manage accounts;

  • authenticate users;

  • provide the Frigo platform and mobile applications;

  • provision and manage Devices;

  • receive, process, store, and display monitoring data;

  • generate alarms and notifications;

  • provide reporting and analytics;

  • provide AI-assisted analyses and summaries where enabled;

  • manage subscriptions and evaluation periods;

  • process payments and invoices;

  • calculate applicable taxes;

  • provide customer support;

  • diagnose technical problems;

  • maintain security and prevent abuse;

  • improve the reliability and functionality of Frigo;

  • communicate operational or contractual information;

  • comply with legal, tax, accounting, and regulatory obligations; and

  • establish, exercise, or defend legal claims.

Where AMCO acts as processor, the purposes of processing are determined by the relevant Customer as controller.

VI. Legal Bases for Processing

Where the EU General Data Protection Regulation ("GDPR") or similar legal requirements apply and AMCO acts as controller, we rely on one or more of the following legal bases:

Performance of a Contract

We process data necessary to enter into or perform a contract with you, including account creation, provision of the Services, subscription administration, billing, and customer support.

Legitimate Interests

We may process personal data where necessary for our legitimate interests or those of a third party, provided those interests are not overridden by your rights and interests.

These interests may include:

  • operating and improving Frigo;

  • maintaining service and network security;

  • preventing fraud and misuse;

  • diagnosing technical issues;

  • maintaining appropriate business records; and

  • protecting our legal rights.

Legal Obligations

We process information where necessary to comply with applicable legal, tax, accounting, regulatory, or law-enforcement obligations.

Consent

Where processing requires consent under applicable law, we will request consent before carrying out that processing. Consent may be withdrawn at any time, without affecting processing carried out lawfully before withdrawal.

Where AMCO acts as processor, the relevant Customer is responsible for determining the appropriate legal basis for the processing.

VII. Device Monitoring, Alarms and Notifications

Frigo processes telemetry received from connected Devices in order to provide monitoring functionality.

Depending on Customer configuration, Frigo may automatically evaluate telemetry against configured thresholds and generate:

  • temperature alarms;

  • humidity alarms;

  • battery alarms;

  • device inactivity or activity notifications;

  • connectivity events;

  • location or movement events;

  • mousetrap or other supported device events; and

  • other configured operational notifications.

Notifications may be delivered through the Frigo platform, email, push notifications, or other enabled channels.

Recipients and notification preferences may be configured by Customer or authorized users.

These automated monitoring functions are designed to assist operational monitoring and do not ordinarily constitute solely automated decision-making producing legal or similarly significant effects on individuals within the meaning of Article 22 GDPR.

VIII. Artificial Intelligence and Automated Analysis

Frigo may provide AI-assisted functionality that analyzes information available within the platform to produce summaries, explanations, recommendations, or other analytical outputs ("Frigo AI").

AMCO currently uses services provided by OpenAI to support certain Frigo AI functionality.

Only information necessary to perform the requested or enabled AI functionality should be transmitted to the AI service provider. Depending on the feature and context, this may include sensor readings, alarm information, device information, operational context, and user-provided prompts or instructions.

AMCO seeks to minimize the transmission of personal data to AI services and does not intentionally submit payment card details or other information that is unnecessary for the requested analysis.

AI-generated outputs may be inaccurate or incomplete and are intended to assist users rather than replace professional judgment.

Frigo AI does not ordinarily make solely automated decisions that produce legal effects or similarly significantly affect individuals within the meaning of Article 22 GDPR.

Where the nature of AI processing materially changes, this Privacy Policy may be updated accordingly.

IX. Payments

Frigo uses third-party payment service providers to process payments and manage recurring subscriptions.

We currently use Stripe for payment processing.

When Customer provides payment information, payment card and related financial information is generally submitted directly to the payment provider. AMCO receives information necessary to administer the transaction and subscription, such as:

  • customer and payment-provider identifiers;

  • payment status;

  • subscription status;

  • transaction amount;

  • currency;

  • invoice information; and

  • limited payment method information where provided by the payment provider.

AMCO does not intend to store full payment card numbers or card security codes.

The payment provider processes certain personal data as an independent controller or processor according to the circumstances and its own applicable privacy terms.

X. Service Providers and Subprocessors

We use trusted third-party service providers to operate and deliver Frigo.

Depending on the Services used, these may include:

  • cloud hosting and infrastructure providers;

  • database and storage providers;

  • IoT platform providers;

  • MQTT and messaging infrastructure providers;

  • LoRaWAN network and connectivity providers;

  • payment processors;

  • email delivery providers;

  • push-notification providers;

  • authentication and security providers;

  • AI service providers;

  • customer-support providers;

  • analytics and diagnostic providers; and

  • location service providers where location functionality is enabled.

These providers may process personal data only to the extent necessary for their respective services and are subject to applicable contractual, confidentiality, security, and data-protection obligations.

The providers used may vary according to geography, Device type, connectivity technology, customer configuration, or technical requirements.

Where AMCO acts as processor on behalf of a Customer, subprocessors are governed by the applicable DPA and AMCO's applicable subprocessor arrangements.

We therefore do not identify every infrastructure or connectivity provider in this Privacy Policy. Where required, further information concerning subprocessors is made available separately or upon request.

XI. Data Hosting and International Transfers

The core Frigo platform infrastructure and primary customer data are hosted within the European Union, currently in Frankfurt, Germany.

AMCO uses service providers that may process certain personal data outside Germany, including in Switzerland, other countries within the European Economic Area ("EEA"), and, where necessary for specific services, other countries.

Switzerland is recognized by the European Commission as providing an adequate level of protection for personal data.

Where personal data subject to GDPR is transferred to a country that has not been recognized as providing an adequate level of protection, AMCO uses an appropriate transfer mechanism where required, such as:

  • European Commission Standard Contractual Clauses ("SCCs");

  • applicable adequacy decisions;

  • contractual safeguards; or

  • another legally recognized transfer mechanism.

Where necessary, supplementary technical or organizational safeguards may also be applied.

XII. Data Retention

We retain personal data only for as long as reasonably necessary for the purposes for which it was collected, including provision of the Services and compliance with legal, accounting, tax, security, and contractual obligations.

Retention periods depend on the type of information and the context in which it is processed.

In general:

  • account and subscription information is retained for the duration of the customer relationship and thereafter as necessary for legal, contractual, tax, or accounting purposes;

  • billing, invoice, and transaction records are retained for the period required by applicable tax, accounting, and commercial law;

  • telemetry and monitoring data is retained according to the applicable Frigo plan, Customer configuration, contractual requirements, and legitimate operational needs;

  • security and technical logs are retained for periods reasonably necessary for security, troubleshooting, audit, and abuse prevention;

  • support communications are retained as reasonably necessary to provide support, maintain service history, and establish or defend legal claims; and

  • backup copies may remain temporarily after deletion until they are overwritten according to our backup lifecycle.

Where AMCO acts as processor, retention may additionally be determined by the Customer's instructions and the applicable DPA.

Personal data may be retained longer where required by law, necessary to resolve disputes, or necessary to establish, exercise, or defend legal claims.

XIII. Security

AMCO uses appropriate technical and organizational measures designed to protect personal data against unauthorized access, disclosure, alteration, loss, or destruction.

Measures may include, as appropriate:

  • encryption in transit;

  • encryption or other protection at rest;

  • authentication and access controls;

  • role-based permissions;

  • logging and monitoring;

  • infrastructure security;

  • backups;

  • vulnerability and security management;

  • access restrictions for personnel and service providers; and

  • incident response procedures.

No electronic system can guarantee absolute security. Customers are also responsible for protecting account credentials and appropriately managing authorized users..

XIV. Cookies and Similar Technologies

The Frigo website and applications may use cookies, local storage, tokens, and similar technologies that are necessary for authentication, security, preferences, session management, and operation of the Services.

Where non-essential analytics, advertising, or similar technologies requiring consent are used, we will request consent where required by applicable law.

Users may be able to manage certain preferences through their browser, device, application, or available consent controls.

XV. Mobile Applications and Push Notifications

Frigo mobile applications may process information necessary to provide application functionality, including authentication information, Device and monitoring information, notification preferences, and technical information about the application and device.

Where enabled, Frigo may use platform notification services provided by mobile operating-system providers to deliver push notifications.

Push notification settings may be controlled through Frigo where available and through the user's mobile operating-system settings.

Mobile operating-system and app-store providers may process certain information independently under their own privacy policies.

XVI. Location Services

Certain Devices and Frigo features may use location information for asset tracking, approximate positioning, movement detection, or related monitoring functionality.

Depending on the relevant Device or feature, location may be determined using GPS, Wi-Fi network information, connectivity infrastructure, or third-party location-resolution services.

Where a third-party location service is used, information necessary to determine a location may be transmitted to that provider.

Location functionality is used only where supported and enabled for the relevant Device, plan, or configuration.

Users and Customers are responsible for ensuring that their use of location functionality complies with applicable law, including requirements relating to employees or other individuals whose location may be identifiable.

XVII. Data Sharing and Disclosure

We may disclose personal data:

  • to service providers necessary to operate Frigo;

  • to payment processors;

  • to connectivity and infrastructure providers;

  • to professional advisers where necessary;

  • to authorities where required by law;

  • where necessary to establish, exercise, or defend legal claims;

  • in connection with a merger, acquisition, restructuring, financing, or sale of all or part of our business; or

  • where you have authorized the disclosure.

We do not sell personal data.

We do not share personal data with third parties for their own independent advertising purposes unless explicitly disclosed and legally permitted.

XVIII. Privacy Rights

Depending on applicable law and the circumstances of processing, individuals may have rights including:

  • access to personal data;

  • correction of inaccurate data;

  • deletion;

  • restriction of processing;

  • objection to certain processing;

  • data portability;

  • withdrawal of consent where processing is based on consent; and

  • rights relating to certain automated decision-making.

Requests concerning processing for which AMCO acts as controller may be submitted to: privacy@frigo.online

We may need to verify identity before fulfilling a request.

Where AMCO processes personal data solely on behalf of an organizational Customer, requests should generally be directed to that Customer as controller. AMCO will assist Customers with such requests as required by applicable law and the DPA.

XIX. Complaints

If you have concerns about how we process personal data, please contact us first at privacy@frigo.online.

Where applicable, you also have the right to lodge a complaint with a competent data-protection supervisory authority.

For matters concerning AMCO as a Swiss company, the relevant Swiss authority is the Federal Data Protection and Information Commissioner ("FDPIC").Individuals in the EEA may also have the right to contact the supervisory authority in the country of their habitual residence, place of work, or place of the alleged infringement.

XX. Children's Privacy

Frigo is not directed at children and is not intended for use by children to create or manage their own Frigo subscriptions or accounts.

We do not knowingly seek to collect personal data directly from children for independent use of the Services.

Where an organizational Customer processes information relating to minors using Frigo, that Customer is responsible for ensuring that the processing has an appropriate legal basis and complies with applicable law.

XXI. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes in law, our Services, technologies, service providers, or data-processing practices.

Where changes materially affect how personal data is processed, we will provide appropriate notice where required by applicable law.

The current version and effective date will be published on the Frigo website.

XXII. Contact

For questions about this Privacy Policy or AMCO's processing of personal data, contact:

AMCO Trade & Finance AG
Bahnhofstrasse 23
6300 Zug
Switzerland

privacy@frigo.online
https://frigo.online