Frontal ya está disponible.Leer el anuncio
Legal/Legal

Data Processing Agreement

Agreement governing Frontal's processing of Personal Data on behalf of Customers, including Standard Contractual Clauses.

Last updated 11 de junio de 2026

This Data Processing Agreement ("DPA") forms part of the Frontal Labs, Inc. ("Frontal," "we," "us," or "our") Terms of Service or other written agreement between Frontal and the Customer ("you") governing your use of the Services (the "Principal Agreement"). This DPA applies when Frontal processes Personal Data on your behalf as a data processor or service provider.

1. DEFINITIONS

1.1 "Applicable Data Protection Law" means all data protection and privacy laws applicable to the Processing of Personal Data under the Principal Agreement, including where applicable: (a) the EU General Data Protection Regulation 2016/679 ("GDPR"); (b) the UK General Data Protection Regulation as defined in the Data Protection Act 2018 ("UK GDPR"); (c) the Swiss Federal Act on Data Protection ("FADP"); (d) the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020 ("CCPA"); and (e) other applicable data protection laws.

1.2 "Controller," "Processor," "Data Subject," "Personal Data," "Personal Data Breach," and "Processing" have the meanings given in the GDPR.

1.3 "Customer Personal Data" means Personal Data within Customer Data that Frontal Processes on behalf of the Customer as a Processor or service provider.

1.4 "Standard Contractual Clauses" or "SCCs" means the European Commission's Standard Contractual Clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 (Commission Implementing Decision (EU) 2021/914 of 4 June 2021), Module Two (Controller-to-Processor), as amended or replaced from time to time.

1.5 "UK International Data Transfer Agreement" or "UK IDTA" means the International Data Transfer Agreement issued by the UK Information Commissioner's Office, as amended or replaced from time to time.

1.6 "Subprocessor" means any third-party Processor engaged by Frontal to Process Customer Personal Data on behalf of the Customer.

1.7 "Security Measures" means the technical and organizational security measures described in our Data Protection Policy, Data Encryption Policy, and Data Classification Policy, as updated from time to time.

1.8 Capitalized terms used but not defined in this DPA have the meanings given in the Terms of Service.

2. ROLES AND SCOPE

2.1 Roles. For purposes of Applicable Data Protection Law, the Customer is the Controller and Frontal is the Processor of Customer Personal Data, except where: (a) the Customer acts as a Processor of Customer Personal Data, in which case Frontal is a sub-Processor; or (b) Applicable Data Protection Law uses different terminology (e.g., "business" and "service provider" under the CCPA), in which case the equivalent roles apply.

2.2 Subject Matter and Duration. The subject matter and duration of the Processing, the nature and purpose of the Processing, the types of Customer Personal Data, and the categories of Data Subjects are set forth in Annex 1 to this DPA.

2.3 Customer Instructions. Frontal will Process Customer Personal Data only in accordance with the Customer's documented instructions: (a) as set forth in the Principal Agreement and this DPA; (b) as necessary to provide the Services, including to prevent or address technical problems; and (c) as otherwise instructed in writing by the Customer and acknowledged by Frontal. Frontal will inform the Customer if, in Frontal's opinion, an instruction infringes Applicable Data Protection Law.

2.4 Legal Disclosure. Frontal may disclose Customer Personal Data if required by applicable law, provided that Frontal: (a) gives the Customer prior notice, unless prohibited by law; (b) discloses only the minimum information required; and (c) uses commercially reasonable efforts to obtain confidential treatment for the disclosed information, at the Customer's expense if the legal process is directed at the Customer.

3. SUBPROCESSORS

3.1 General Authorization. The Customer provides general written authorization for Frontal to engage Subprocessors to Process Customer Personal Data, subject to the terms of this Section 3. The current list of Subprocessors is maintained in our Subprocessors List.

3.2 Subprocessor Obligations. Frontal will: (a) impose data protection obligations on each Subprocessor that are no less protective than those in this DPA, including obligations of confidentiality; (b) remain liable to the Customer for the Subprocessor's performance of its data protection obligations; and (c) conduct appropriate due diligence on Subprocessors.

3.3 New Subprocessors. Frontal will notify the Customer of additions or replacements of Subprocessors that Process Customer Personal Data. Notice will be provided:

  • through updates to the Subprocessors List on the Site;
  • by email to the email address associated with your Account, at least 30 days before a new Subprocessor begins Processing Customer Personal Data, for material changes; and
  • through the Services interface or status page.

3.4 Objection Right. The Customer may object to a new Subprocessor on reasonable data protection grounds within 30 days of Frontal's notice by sending a written objection to dpo@frontal.dev. Frontal will: (a) work in good faith with the Customer to address the objection; (b) if the objection cannot be resolved, use commercially reasonable efforts to provide the affected Services without the Subprocessor; and (c) if that is not commercially feasible, allow the Customer to terminate the affected Services without penalty upon 30 days' written notice and receive a pro-rata refund of prepaid unused Fees.

4. SECURITY

4.1 Security Measures. Frontal will implement and maintain Security Measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. The Security Measures are subject to technical progress and development. Frontal may update the Security Measures provided that such updates do not materially reduce the overall level of protection.

4.2 Personnel. Frontal ensures that persons authorized to Process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

4.3 Audits. Frontal makes available to the Customer information reasonably necessary to demonstrate compliance with this DPA. The audit rights of the Customer are set forth in Section 8.

5. DATA BREACH NOTIFICATION

5.1 Frontal will notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data.

5.2 The notification will include: (a) the nature of the breach, including the categories and approximate number of Data Subjects and records concerned; (b) the name and contact details of Frontal's Data Protection Officer or other contact point; (c) the likely consequences of the breach; and (d) the measures taken or proposed to address the breach and mitigate adverse effects.

5.3 Frontal will cooperate with the Customer and provide reasonable assistance to enable the Customer to comply with its breach notification obligations under Applicable Data Protection Law.

6. DATA SUBJECT REQUESTS

6.1 Frontal will, taking into account the nature of the Processing, assist the Customer by implementing appropriate technical and organizational measures to respond to Data Subject requests under Applicable Data Protection Law, insofar as this is possible.

6.2 If Frontal receives a Data Subject request relating to Customer Personal Data, Frontal will advise the Data Subject to submit the request to the Customer and will notify the Customer, unless prohibited by law. Frontal will not respond to the request directly except at the Customer's documented instruction.

7. DATA PROTECTION IMPACT ASSESSMENTS

Frontal will provide the Customer with reasonable cooperation and information as needed for the Customer to conduct data protection impact assessments and prior consultations with supervisory authorities, taking into account the nature of the Processing and the information available to Frontal.

8. AUDITS AND COMPLIANCE

8.1 Upon the Customer's written request and no more than once per 12-month period (unless a supervisory authority requires more frequent audits or an audit follows a Personal Data Breach), Frontal will provide: (a) a summary of its most recent third-party security audit or certification (e.g., SOC 2 Type II report, ISO 27001 certificate); and (b) responses to a written security questionnaire.

8.2 If the information provided under Section 8.1 is insufficient to demonstrate compliance, the Customer may request a remote or virtual audit no more than once per 12-month period, subject to: (a) at least 30 days' advance written notice; (b) the audit being conducted during regular business hours; (c) the scope being limited to Frontal's Processing of Customer Personal Data; (d) the Customer and its representatives executing a non-disclosure agreement; (e) the audit not unreasonably disrupting Frontal's business operations; and (f) the Customer bearing the costs of the third-party auditor and its own expenses, provided that Frontal shall absorb its reasonable internal costs of making personnel available, consistent with its obligation to contribute to audits under applicable data protection law. Frontal is a fully remote company with no physical office facilities; audits under this Section are conducted via videoconference, document review, and system walkthrough. Any third-party auditor must be mutually agreed upon and must not be a competitor of Frontal.

8.3 Audit findings will be shared with Frontal and treated as Confidential Information. Frontal will address material findings within a commercially reasonable timeframe.

9. RETURN AND DELETION

9.1 Upon termination of the Principal Agreement, Frontal will delete all Customer Personal Data in accordance with the Data Retention Policy and Data Disposal Policy.

9.2 At the Customer's request made before termination, Frontal will make Customer Personal Data available for export in a standard format.

9.3 Frontal may retain Customer Personal Data to the extent required by applicable law, provided that such data remains subject to the confidentiality and security obligations of this DPA.

10. INTERNATIONAL DATA TRANSFERS

10.1 Data Privacy Framework

Frontal is pursuing certification under the EU-U.S. Data Privacy Framework (EU-U.S. DPF), the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as administered by the U.S. Department of Commerce. Until DPF certification is confirmed, lawful transfers of Personal Data from the EEA, UK, and Switzerland to the United States are governed by the SCCs and UK IDTA as set forth in Section 10.2 of this DPA.

10.2 Standard Contractual Clauses

Where the DPF does not apply or is not a valid transfer mechanism, the SCCs and, where applicable, the UK IDTA, are incorporated into this DPA by this reference and apply as follows:

(a) The SCCs apply to transfers of Customer Personal Data from the EEA to a country outside the EEA not subject to an adequacy decision. The applicable module is determined by the Customer's role: Module Two (Controller-to-Processor) applies where the Customer is a Controller; Module Three (Processor-to-Processor) applies where the Customer is a Processor and Frontal is a sub-Processor.

(b) The UK IDTA applies to transfers of Customer Personal Data from the United Kingdom to a country outside the UK not subject to an adequacy regulation.

(c) For purposes of the SCCs:

  • Clause 7 (Docking Clause) applies.
  • Clause 9 (Use of Sub-Processors): Option 2 (General Written Authorization) applies. The time period for notice is as set forth in Section 3.3 of this DPA.
  • Clause 11 (Redress): The optional language does not apply.
  • Clause 17 (Governing Law): Option 1 applies. The governing law is Ireland for EEA transfers.
  • Clause 18 (Choice of Forum and Jurisdiction): The courts of Ireland for EEA transfers; the courts of England and Wales for UK transfers.

(d) Annexes I, II, and III of the SCCs are completed as follows:

  • Annex I: The information set forth in Annex 1 to this DPA.
  • Annex II: The Security Measures described in this DPA and the policies referenced herein.
  • Annex III: The Subprocessors List.

(e) The parties agree that the SCCs are governed by the law of Ireland (for EEA transfers) and the law of England and Wales (for UK transfers).

10.3 Conflict

In the event of a conflict between the terms of this DPA and the SCCs or UK IDTA, the SCCs or UK IDTA prevail with respect to the transfer of Personal Data to which they apply.

11. CCPA SERVICE PROVIDER TERMS

Where the CCPA applies, Frontal acts as a "service provider" and will: (a) not sell or share Customer Personal Data; (b) not retain, use, or disclose Customer Personal Data for any purpose other than providing the Services or as otherwise permitted by the CCPA; (c) not combine Customer Personal Data with data obtained from other sources except as permitted by the CCPA; and (d) comply with all applicable CCPA obligations. Frontal certifies that it understands and will comply with these restrictions.

12. LIMITATION OF LIABILITY

12.1 Each party's liability arising out of or relating to this DPA, whether in contract, tort, or otherwise, is subject to the limitations and exclusions of liability in the Principal Agreement, provided that such limitations shall not apply to: (a) a party's obligations under this DPA that arise from or relate to breach of Applicable Data Protection Law; (b) statutory liability under Articles 28, 82, and related provisions of the GDPR or equivalent provisions of other Applicable Data Protection Law; or (c) a party's indemnification obligations under this DPA.

12.2 Notwithstanding Section 12.1, neither party limits its liability for Data Subject claims where liability is mandatory under Applicable Data Protection Law.

13. CONFLICT

In the event of a conflict between the Principal Agreement and this DPA regarding the Processing of Customer Personal Data, this DPA prevails.

14. CONTACT

Frontal Data Protection Officer: Email: dpo@frontal.dev Mail: Frontal Labs, Inc., Attn: Data Protection Officer, 131 Continental Drive, STE 305, Newark, DE 19713, United States of America

EU Representative: As set forth in our EU Representative Notice.


ANNEX 1: DETAILS OF PROCESSING

A. LIST OF PARTIES

Data Exporter (Customer): The Customer as identified in the Principal Agreement.

Data Importer (Frontal): Frontal Labs, Inc., 131 Continental Drive, STE 305, Newark, DE 19713, United States of America. Contact: dpo@frontal.dev.

B. DESCRIPTION OF TRANSFER

Categories of Data Subjects whose Personal Data is transferred:

  • Customer's Authorized Users (employees, contractors, agents).
  • Customer's end users (if Customer uses the Services to process end-user data).
  • Any individuals whose Personal Data is included in Customer Data submitted to the Services.

Categories of Personal Data transferred:

  • Account registration and profile information (name, email, username).
  • Authentication credentials (hashed passwords, API Keys, tokens).
  • Billing and payment information (billing address, payment method metadata, transaction history).
  • Communications and support data (support tickets, chat logs, emails).
  • Usage data (IP addresses, access logs, feature usage, session data).
  • Any Personal Data included by the Customer in Customer Data (prompts, completions, uploaded files, databases, configurations, datasets).

Sensitive data transferred (if applicable):

  • Authentication credentials (subject to enhanced security measures).
  • Special categories of Personal Data under GDPR Article 9 are not intended to be processed unless the Customer explicitly agrees in writing and implements appropriate safeguards.

Frequency of the transfer:

  • Continuous, as necessary to provide the Services.

Nature of the Processing:

  • Collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction, as necessary to provide the Services described in the Principal Agreement.

Purpose(s) of the data transfer and further Processing:

  • To provide, maintain, improve, and secure the Services in accordance with the Principal Agreement and the Customer's documented instructions.

Period for which Personal Data will be retained:

C. COMPETENT SUPERVISORY AUTHORITY

The competent supervisory authority for the SCCs shall be determined in accordance with Clause 13 of the SCCs. Where the governing law of the SCCs is that of Ireland, the competent supervisory authority is the Irish Data Protection Commission (An Coimisiun um Chosaint Sonrai). Where the data exporter is established in a different Member State, the competent supervisory authority shall be that of the data exporter's establishment.

For transfers from the UK: The UK Information Commissioner's Office.

For transfers from Switzerland: The Swiss Federal Data Protection and Information Commissioner.

De forma predeterminada medimos el tráfico del sitio sin cookies. Si aceptas, recordaremos tu visita entre sesiones, lo que hace más precisa nuestra analítica.