Privacy Policy

Frigo — a product of AMCO Trade & Finance AG, Bahnhofstrasse 23, 6300 Zug, Switzerland
Version 1.0 — Effective: 10.08.2026

I. Introduction and Data Controller

AMCO Trade & Finance AG ("AMCO", "we", "our", or "us") respects your privacy and protects personal data in accordance with applicable data protection laws, including the EU General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection (FADP).

The controller for personal data processed under this Privacy Policy is:

AMCO Trade & Finance AG
Bahnhofstrasse 23, 6300 Zug, Switzerland
Commercial Register of the Canton of Zug, CHE-108.622.594

privacy@frigo.online
+41.32.510.7810
https://frigo.online

We have not appointed a data protection officer, as we are not legally required to do so. Our privacy team can be reached at privacy@frigo.online.

Representative in the EU (Art. 27 GDPR): AMCO IoT GmbH, Kirchstraße 7a, 6971 Hard, Austria — privacy@frigo.online.

This Privacy Policy explains how we process personal data when you use Frigo, our monitoring platform for critical spaces, including the Frigo web portal, mobile applications, APIs, connected IoT devices, sensors and gateways, reports, alerts, dashboards, subscription and billing services, our website, and customer support.

II. Scope and Roles (B2B Notice)

Frigo is a business-to-business platform. This Privacy Policy applies to website visitors, registered users, customer administrators, mobile app users, support contacts, and individuals interacting with connected devices.

Where a customer organization uses Frigo to manage its own users, sites, assets, or operations, the customer acts as data controller for that data and AMCO acts as data processor on the customer’s behalf. That processing is governed by the Frigo Data Processing Agreement (DPA), which forms part of our Terms & Conditions.

If you use Frigo through your employer or another organization, that organization is responsible for informing you about its own processing of your data and for ensuring a lawful basis for it, including — where location tracking of vehicles, assets, or personnel is enabled — any employee-representation or works-council requirements that apply to it.

III. Categories of Data We Process

Account and identity data: name, company name, email address, phone number, billing contact details, job title, user role and permissions, account preferences.

Authentication and access data: login timestamps, password hashes, authentication logs, failed login attempts, session identifiers, IP addresses, browser and device information.

Device, sensor and telemetry data: temperature, humidity and other environmental values, battery levels, device identifiers, signal strength, alarm states, timestamps, connectivity status, firmware versions, gateway diagnostics, sensor metadata. Telemetry is operational data; it relates to individuals only where linked to them (e.g. device assignments).

Geolocation data (where enabled): GPS coordinates, device location history, gateway location, mapped addresses, network-based positioning. Positioning may use the third-party provider Combain.

Reports and documents: compliance reports, historical telemetry reports, alarm summaries, PDF exports.

Billing data: company billing name, billing address, VAT/tax IDs, subscription details, invoices, payment status. Payment card data is processed by our payment provider and is not stored by AMCO.

Communications data: support requests, emails, meeting notes, service communications.

Website usage data: IP address, browser type, pages visited, timestamps, referral source, cookie identifiers.

IV. Purposes and Legal Bases

Where the GDPR applies, we process personal data on the following legal bases:

  • Contract performance (Art. 6(1)(b) GDPR): providing the Frigo platform, device monitoring and alerting, dashboards, reports, account administration, billing and subscription management, onboarding, and support.

  • Legitimate interests (Art. 6(1)(f) GDPR): service security, fraud prevention, audit trails, improving reliability and performance, and business communications with customer contacts. You may object to processing based on legitimate interests at any time (see Section 10).

  • Legal obligation (Art. 6(1)(c) GDPR): accounting, tax, and statutory retention duties.

  • Consent (Art. 6(1)(a) GDPR): where required, marketing communications. Consent can be withdrawn at any time with effect for the future.

Where the FADP applies, we process personal data in accordance with its principles of lawfulness, proportionality, and purpose limitation.

V. Service Providers and Recipients

We use carefully selected service providers to operate Frigo. All providers are bound by appropriate contractual and security safeguards. Our current providers include:

  • Hosting / backend infrastructure: [hosting provider legal name — to be confirmed (Render? ThingsBoard Cloud? self-hosted?)], hosted in Frankfurt, Germany.

  • MQTT messaging: HiveMQ, Frankfurt, Germany — secure telemetry and device messaging.

  • Payment processing: Stripe — subscription billing, payment processing, and invoicing, under its own privacy and security obligations.

  • Geolocation: Combain (Sweden) — location lookup and positioning services where enabled.

  • Connectivity: Hutchison Drei Austria and ThingPark Wireless — network metadata necessary for device communication.

  • Support and communications: email, support, and collaboration tools reasonably required for operations.

  • AI analysis (Frigo AI): AI/LLM provider — to be confirmed (external provider incl. legal entity, hosting location, and transfer mechanism, or note self-hosted) — generation of automated sensor analyses, where enabled.

A current list of subprocessors used for customer data is maintained in Annex 3 of the Frigo DPA. We may disclose personal data where required by law or to protect our legal rights.
We do not sell personal data.

VI. International Data Transfers

Frigo production data is hosted on EU infrastructure. Where personal data is transferred outside Switzerland, the EEA, or the UK (for example to providers with group companies in the United States), we implement appropriate safeguards such as adequacy decisions, the EU Standard Contractual Clauses (SCCs) with the Swiss addendum recognized by the FDPIC, and supplementary contractual and technical measures. You may request further information about the safeguards used via privacy@frigo.online.

VII. Data Retention

We retain personal data only as long as necessary for the purposes described in this Policy:

  • account data: for the duration of the contract and up to [12 months] thereafter

  • billing and accounting records: 10 years (statutory retention, Switzerland/Austria)

  • telemetry and reports: according to the customer contract and configured retention settings

  • security and access logs: up to [12 months]

  • backups: deleted on rotating schedules within [90 days]

  • support communications: up to [24 months] after the request is closed

When no longer required, data is deleted or anonymized.

VIII. Security

We implement appropriate technical and organizational measures, including encrypted communications (TLS), access controls and role permissions, secure authentication, monitoring and logging, backups, infrastructure hardening, vulnerability management, and least-privilege principles. No system can guarantee absolute security, but we continuously work to protect data.

IX. Cookies, Website and Mobile Apps

Our website uses only technically necessary cookies, for example for security and basic site functionality. We do not use analytics, tracking, or marketing cookies on our website; accordingly, no cookie consent banner is required or displayed.

The Frigo platform uses session cookies required for login and secure operation, and processes operational usage data as described in Section 4. No third-party analytics or advertising technologies are embedded in the platform.

Our mobile applications process limited device-related data necessary for operation, such as app version, device model, operating system version, crash diagnostics, and push notification tokens. Permissions requested by the app depend on the features you enable.

X. Your Rights

Depending on applicable law, you have the right to: access your personal data; correct inaccurate data; request deletion; restrict processing; object to processing based on legitimate interests, including direct marketing; data portability; and withdraw consent at any time where processing is based on consent.

To exercise your rights, contact privacy@frigo.online. We may need to verify your identity before responding.

You also have the right to lodge a complaint with a supervisory authority. In Switzerland, this is the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern. If you are in the EU/EEA, you may contact the supervisory authority of your habitual residence or place of work.

If your data is processed by AMCO on behalf of your employer or another organization (see Section 2), that organization is the controller and your request may be forwarded to it.

XI. Automated Decision-Making

Frigo automatically triggers alerts and notifications based on configured thresholds, device states, inactivity rules, or geofencing logic. These automations are operational in nature. We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you within the meaning of Art. 22 GDPR.

Frigo may also generate AI-assisted analyses, summaries, and recommendations based on sensor telemetry ("Frigo AI"); these outputs relate to monitored assets and environments, are informational, and are identified as AI-generated in the platform. They are not used to make decisions with legal or similarly significant effects on individuals.

XII. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. The current version is always published at https://frigo.online. Material changes will be communicated appropriately, for example by email or in-app notice.

XIII. Contact

AMCO Trade & Finance AG
Bahnhofstrasse 23, 6300 Zug, Switzerland
privacy@frigo.online
https://frigo.online