Records of Processing Activities
GDPR Article 30 Records of Processing Activities for Frontal Labs, Inc.
Last updated 2026年6月11日
Table of Contents
- 1. CONTROLLER PROCESSING
- 1.1 Account Registration and Management
- 1.2 Billing and Payments
- 1.3 Customer Support
- 1.4 Marketing and Communications
- 1.5 Website and Service Analytics
- 1.6 Security Monitoring and Abuse Prevention
- 2. PROCESSOR PROCESSING
- 2.1 Customer Data Processing (All Services)
- 3. DATA SUBJECT RIGHTS PROCEDURES
- 4. CROSS-BORDER TRANSFER MECHANISMS
- 5. REVIEW AND UPDATES
- 6. CONTACT
This document constitutes the Records of Processing Activities (ROPA) maintained by Frontal Labs, Inc. ("Frontal") pursuant to Article 30 of the EU General Data Protection Regulation (GDPR) and Article 30 of the UK GDPR. This ROPA covers Frontal's processing of Personal Data as both a Controller (for its own business operations) and as a Processor (on behalf of Customers). This document is reviewed and updated at least annually.
1. CONTROLLER PROCESSING
1.1 Account Registration and Management
| Field | Detail |
|---|---|
| Processing Activity | Account creation, management, authentication, and maintenance |
| Purpose | To create and manage user Accounts, authenticate users, and provide Account-related services |
| Legal Basis | Performance of a contract (Terms of Service); Legitimate interest (account security) |
| Categories of Data Subjects | Customer employees, contractors, and agents (Authorized Users) |
| Categories of Personal Data | Name, email address, username, password (hashed), company name, account settings, IP address |
| Recipients | Cloud infrastructure providers (AWS, GCP, Azure, Vercel); Authentication providers (Google, GitHub, Apple); Subprocessors as listed |
| Retention Period | Duration of Account plus 90 days |
| Security Measures | AES-256 encryption at rest; TLS 1.2+ in transit; MFA; RBAC; access logging |
| Transfers Outside EU/UK | United States (In process; DPF certification pending, with SCCs in place with subprocessors) |
1.2 Billing and Payments
| Field | Detail |
|---|---|
| Processing Activity | Processing payments, invoicing, financial record-keeping |
| Purpose | To bill for Services, process payments, maintain financial records, and comply with tax obligations |
| Legal Basis | Performance of a contract; Legal obligation (tax law) |
| Categories of Data Subjects | Customer billing contacts, payment account holders |
| Categories of Personal Data | Name, email, billing address, payment method metadata, transaction history, tax ID (where applicable) |
| Recipients | Payment processor (Stripe); Accounting provider (Xero); Invoicing provider (Invopop) |
| Retention Period | 7 years from transaction date (tax and financial regulatory requirement) |
| Security Measures | Payment card data tokenized (not stored by Frontal); AES-256 encryption; TLS 1.2+; access controls |
| Transfers Outside EU/UK | United States (DPF; SCCs) |
1.3 Customer Support
| Field | Detail |
|---|---|
| Processing Activity | Customer support, technical assistance, troubleshooting |
| Purpose | To provide support, respond to inquiries, resolve technical issues, and maintain support records |
| Legal Basis | Performance of a contract; Legitimate interest (service improvement, quality assurance) |
| Categories of Data Subjects | Customer employees, contractors, agents (support requestors) |
| Categories of Personal Data | Name, email, Account identifier, support ticket content, chat transcripts, communication metadata |
| Recipients | Support platform (Intercom); Communication tools (Slack, Google Workspace); Incident management (PagerDuty, Incident.io) |
| Retention Period | 3 years after ticket closure |
| Security Measures | AES-256 encryption; TLS 1.2+; access controls; audit logging |
| Transfers Outside EU/UK | United States (DPF; SCCs); EEA (for EU-based support where applicable) |
1.4 Marketing and Communications
| Field | Detail |
|---|---|
| Processing Activity | Marketing communications, newsletters, promotional offers, surveys |
| Purpose | To send marketing and promotional content, solicit feedback, and manage communication preferences |
| Legal Basis | Consent (where required); Legitimate interest (business-to-business communications) |
| Categories of Data Subjects | Prospective customers, current Customer contacts, newsletter subscribers |
| Categories of Personal Data | Name, email address, company name, communication preferences, engagement data (opens, clicks) |
| Recipients | Email delivery provider (Resend); CRM (Attio); Analytics (PostHog, Google Analytics) |
| Retention Period | 2 years after last communication; opt-out preferences retained indefinitely |
| Security Measures | AES-256 encryption; TLS 1.2+; access controls |
| Transfers Outside EU/UK | United States (DPF; SCCs) |
1.5 Website and Service Analytics
| Field | Detail |
|---|---|
| Processing Activity | Collection and analysis of usage data, performance monitoring, error reporting |
| Purpose | To understand how the Site and Services are used, improve performance and functionality, detect and repair errors |
| Legal Basis | Consent (analytics cookies); Legitimate interest (service improvement, security) |
| Categories of Data Subjects | Site visitors, Service users |
| Categories of Personal Data | IP address, browser type and version, device type, operating system, pages visited, features used, session duration, timestamps, referring URLs, crash reports |
| Recipients | Analytics providers (PostHog, Google Analytics, Vercel Analytics); Error monitoring (Sentry); Observability (Datadog, Grafana, Axiom) |
| Retention Period | API logs: 30 days (standard) / 24 months (Enterprise); Analytics (individual): 13 months; Analytics (aggregated): 24 months |
| Security Measures | AES-256 encryption; TLS 1.2+; access controls; IP anonymization where configured |
| Transfers Outside EU/UK | United States (DPF; SCCs); EEA (as configured) |
1.6 Security Monitoring and Abuse Prevention
| Field | Detail |
|---|---|
| Processing Activity | Security event monitoring, fraud detection, abuse prevention, access auditing |
| Purpose | To detect, prevent, and respond to security incidents, fraud, abuse, and violations of Terms of Service |
| Legal Basis | Legitimate interest (security, fraud prevention); Legal obligation |
| Categories of Data Subjects | Service users, attackers, fraud actors |
| Categories of Personal Data | IP address, access timestamps, authentication events, authorization decisions, security event data, abuse indicators |
| Recipients | Security tooling providers (Snyk, Semgrep, Trivy, Gitleaks, SonarQube); SIEM/logging infrastructure |
| Retention Period | Security event logs: 12 months; Abuse/fraud data: up to 12 months after Account termination |
| Security Measures | AES-256 encryption; TLS 1.2+; strict access controls; tamper-proof logging |
| Transfers Outside EU/UK | United States (DPF; SCCs) |
2. PROCESSOR PROCESSING
2.1 Customer Data Processing (All Services)
| Field | Detail |
|---|---|
| Processing Activity | Processing of Customer Data submitted to the Services, including prompts, inputs, files, databases, configurations, models, datasets, and outputs |
| Purpose | To provide the Services in accordance with the Principal Agreement and Customer's documented instructions |
| Legal Basis | Performance of a contract (Terms of Service + DPA); Processor acts on Controller's documented instructions |
| Categories of Data Subjects | As determined by Customer (Controller). May include Customer's employees, contractors, agents, end users, and any individuals whose Personal Data is included in Customer Data |
| Categories of Personal Data | As determined by Customer. May include any category of Personal Data included in Customer Data submitted to the Services |
| Recipients | Cloud infrastructure providers (AWS, GCP, Azure, Vercel, Cloudflare); Database providers (Neon, MongoDB, PlanetScale, Timescale, Neo4j, Qdrant, Upstash); AI model providers (Anthropic, OpenAI, Google, Microsoft, Mistral, ElevenLabs); All subprocessors as listed in the Subprocessors List |
| Retention Period | Duration of Account plus 30 days; Backup data expires per retention schedule (7-35 days) |
| Security Measures | Full technical and organizational measures as described in Data Protection Policy, Data Encryption Policy, and Data Classification Policy |
| Transfers Outside EU/UK | United States (In process; DPF certification pending, with SCCs Module 2/3 in place); EEA (as configured by Customer data residency settings); Global (per Customer configuration) |
| Subprocessor Authorizations | General written authorization (DPA Section 3.1); 30-day advance notice of new subprocessors; 30-day objection period |
3. DATA SUBJECT RIGHTS PROCEDURES
| Right | Procedure | Response Timeframe |
|---|---|---|
| Access (Art. 15) | Submit request to privacy@frontal.dev or via Account settings; identity verification required | Within 1 month (extendable by 2 months) |
| Rectification (Art. 16) | Submit request to privacy@frontal.dev or update via Account settings | Within 1 month |
| Erasure (Art. 17) | Submit request to privacy@frontal.dev; subject to legal preservation exceptions | Within 1 month |
| Restriction (Art. 18) | Submit request to privacy@frontal.dev; restriction applied pending verification | Within 1 month |
| Portability (Art. 20) | Submit request to privacy@frontal.dev; data provided in structured machine-readable format (JSON, CSV) | Within 1 month |
| Objection (Art. 21) | Submit request to privacy@frontal.dev; processing ceased unless compelling legitimate grounds override | Within 1 month |
| Consent Withdrawal (Art. 7(3)) | Via cookie settings, unsubscribe links, or Account settings | Immediate effect |
| Complaints | Contact privacy@frontal.dev or CNPD (Portuguese DPA): Av. Dom Carlos I, 134, 1200-651 Lisboa, Portugal | Per statutory timeframes |
4. CROSS-BORDER TRANSFER MECHANISMS
| Mechanism | Status | Applies To |
|---|---|---|
| EU-U.S. Data Privacy Framework (DPF) | Certified (or in process) | EU→US transfers |
| UK Extension to EU-U.S. DPF | Certified (or in process) | UK→US transfers |
| Swiss-U.S. Data Privacy Framework | Certified (or in process) | Switzerland→US transfers |
| EU SCCs (Module 2: C2P) | Incorporated into DPA | EEA→third country transfers where Customer is Controller |
| EU SCCs (Module 3: P2P) | Incorporated into DPA | EEA→third country transfers where Customer is Processor |
| UK International Data Transfer Agreement (IDTA) | Incorporated into DPA | UK→third country transfers |
| Adequacy Decisions | Relied upon where applicable | Transfers to countries with EU/UK adequacy decisions |
5. REVIEW AND UPDATES
This ROPA is reviewed at least annually and updated as processing activities change. The Data Protection Officer (dpo@frontal.dev) is responsible for maintaining this document.
6. CONTACT
Frontal Labs, Inc. Attn: Data Protection Officer 131 Continental Drive, STE 305 Newark, DE 19713 United States of America Email: dpo@frontal.dev