Frends Data Processing Agreement

Version 2.0 - 22.09.2026

APPLICABILITY

This Data Protection Agreement shall apply immediately to any Customer that enters into an Agreement on or after the publication date stated above. For Customers that entered into an Agreement before the publication date, this Data Protection Agreement shall take effect thirty (30) days after Frends provides notice of its publication. Until such effective date, the previous version of the Data Protection Agreement shall continue to apply to those Customers. 

This Data Protection Agreement does not apply to Customers having entered into a separate written data protection agreement with Frends. 

1. BACKGROUND AND PURPOSE

1. This Data Processing Agreement (“DPA”) forms an integral part of the agreement entered into by Frends Technology Oy (“Frends”) and the customer identified in the Agreement (“Customer”), which governs the provision of the Platform and related services (“Services”) by Frends to Customer and Customer’s use thereof (“Platform Agreement”). Where the Parties have also entered into a Professional Services Agreement, this DPA shall form an integral part of such Professional Services Agreement only to the extent that (i) Customer acts as a Data Controller in respect of the relevant Personal Data, and (ii) the Parties have identified in the Professional Services Agreement that Frends acts as a Data Processor processing Personal Data on behalf of Customer in connection with the provision of the professional services (“Professional Services”). Together, the Platform Agreement and, where applicable, the Professional Services Agreement, are referred to herein as the “Agreement”.

2. In connection with the provision of the Services, and where applicable, Professional Services, under the Agreement, Customer acts as the Data Controller of Personal Data and Frends acts as the Data Processor of such Personal Data. The details of the processing, including the categories of Data Subjects, categories of Personal Data, purposes of processing, and applicable technical and organizational security measures, are set out in Schedule 1 and Schedule 2 of this DPA.

3. The Parties acknowledge that competent supervisory authorities, courts, or other regulatory bodies may issue guidance, recommendations, decisions, or requirements relating to the interpretation or application of the GDPR or other applicable Data Protection Legislation after the Effective Date of this DPA. The Parties shall cooperate in good faith and, where reasonably necessary to ensure compliance with applicable Data Protection Legislation, amend this DPA accordingly.

4. In the event of any conflict or inconsistency between the provisions of this DPA and the Agreement, the provisions of this DPA shall prevail with respect to the processing of Personal Data and any other matters specifically governed by this DPA. In case of discrepancy relating to this DPA between the Platform Agreement and the Professional Services Agreement, the Platform Agreement prevails.

2. DEFINITIONS

Any capitalized terms not defined in this DPA shall have the meaning given to them in the applicable Data Protection Legislation, the Platform Agreement, or, where relevant, the Professional Services Agreement.

Authorized Individual(s) means the person processing Personal Data on behalf of and under the control of Frends pursuant to the Agreement and this DPA;

Data Protection Legislation means the national data protection legislation applicable to processing under this DPA and the GDPR;

GDPR means the General Data Protection Regulation of the European Union (2016/679/EU);

Personal Data means any information relating to an identified or identifiable natural person, from which the person can be identified, directly or indirectly;

Personal Data Breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored or otherwise processed.

Sub-processor means any third party appointed by Frends to process Personal Data on behalf of Customer in connection with the Services and Professional Services. Sub-processors may include global cloud, hosting, infrastructure, software, analytics, communication, and support service providers that process Personal Data as part of the delivery of the Services and Professional Services and that may make available their own standard data processing terms and data protection commitments in addition to the requirements set out in this DPA.

3. CUSTOMER OBLIGATIONS

1. Customer shall ensure it has the right to provide Personal Data to Frends. Customer is responsible for the lawfulness, accuracy, and completeness of the processing instructions given to Frends under this DPA, and shall promptly notify Frends of any material change to those instructions. Changes to the instructions, including any related cost impact, shall be agreed separately in writing.

2. Customer is responsible for the Personal Data provided to Frends, including its lawfulness and accuracy. Frends does not monitor or verify the content, quality, or timeliness of such data.

3. Customer shall ensure that: (a) the purpose and legal grounds for processing comply with the Data Protection Legislation; (b) the Personal Data was collected lawfully; (c) Customer has the right to transfer the Personal Data to Frends, and (d) special categories of Personal Data (Art. 9/10 GDPR) are not included unless agreed with Frends in writing in advance.

4. Customer shall promptly notify Frends of any data subject or authority request or complaint relating to the processed Personal Data.

4. FRENDS OBLIGATIONS

1. Frends shall process Personal Data only in accordance with the Data Protection Legislation and Customer's written instructions, unless Frends is required to do otherwise by law. If such a legal requirement applies, Frends shall inform Customer before processing, unless the law prohibits notification. Frends shall promptly inform Customer if, in Frends' reasonable opinion, an instruction given by Customer infringes the Data Protection Legislation. For the avoidance of doubt, Frends does not actively monitor or review Customer's instructions for compliance with the Data Protection Legislation, and Customer remains solely responsible and liable for ensuring that its instructions comply with the Data Protection Legislation.

2. Taking into account the nature of the processing, Frends shall assist Customer, using technical and organisational measures chosen by Frends, in fulfilling Customer's obligation to respond to data subject requests under Chapter III of the GDPR, including the rights to: (a) access; (b) rectification and erasure; (c) restriction of processing; (d) data portability; and (e) object to processing — in each case only to the extent the data subject holds that right under the GDPR.

3. If either Party receives a data subject rights request that requires action from the other Party, it shall notify the other Party without delay with sufficient information the other Party reasonably needs to fulfil the request.

4. Taking into account the nature of the processing and the information available to it, Frends shall assist Customer in complying with Articles 32–36 GDPR, including: (a) implementing appropriate technical and organizational security measures; (b) notifying the supervisory authority and data subjects of Personal Data Breaches; (c) participating in a data protection impact assessment where required under Article 35 GDPR; and (d) participating in prior consultation with the supervisory authority where required under Article 36 GDPR.

5. Frends shall provide reasonable assistance under Section 4.4 above at no additional charge, provided the request is not excessive, repetitive, or disproportionate to the nature of the processing. Where assistance requires material effort beyond this — for example, extensive investigation, custom-reporting, forensic analysis or custom or non-standard reporting — Frends shall notify Customer in advance with a good-faith estimate of the work and cost involved and shall proceed only upon Customer's written approval. Any such additional assistance shall be charged on a time-and-materials basis at Frends' then-current price list rates. Frends shall not charge Customer for assistance required as a result of Frends' own breach of this DPA or the Data Protection Legislation.

5. INFORMATION SECURITY

1. Each Party shall implement technical and organisational measures consistent with industry practice to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Such measures may include, for example:

(a) pseudonymisation and encryption of Personal Data;

(b) the ability to ensure ongoing confidentiality, integrity, availability, and resilience of processing systems and services;

(c) the ability to restore availability and access to Personal Data in a timely manner following a physical or technical incident; and

(d) a process for regularly testing, assessing, and evaluating the effectiveness of technical and organisational measures.

2. The measures above are illustrative. The specific measures Frends shall implement in processing Personal Data are set out in Schedule 1 and Schedule 2, and the Parties shall agree in writing on any material change to those measures.

3. Customer is responsible for the security of the equipment, networks, and IT environment under its own control, including any systems used to access or transmit Personal Data to Frends. To the extent not otherwise agreed in the Platform Agreement with respect to Frends Back-Ups, the Customer shall be solely responsible for backing up Personal Data and for periodically verifying that such backups are functional and can be successfully restored.

4. Frends shall ensure that Authorized Individuals processing Personal Data are bound by confidentiality obligations, whether contractual or statutory, and shall implement measures to ensure such individuals process Personal Data only in accordance with the security procedures set out in Schedule 2 and on a need-to-know basis.

6. SUB-PROCESSORS

1. Frends is entitled to engage Sub-processors, including its Affiliates, in providing the Services and Professional Services, and processing Personal Data. As of the date of this DPA, Frends' authorized Sub-processors are listed at https://frends.com/legal/sub-processors. Frends shall remain responsible for ensuring that its Sub-processors process Personal Data in accordance with the Data Protection Legislation and on terms materially equivalent to those set out in this DPA. Notwithstanding anything to the contrary in the Agreement or this DPA, the processing of Personal Data conducted by an unaffiliated Sub-processor shall always occur solely and exclusively subject to the data processing terms and conditions issued by that Sub-processor.

2. Where Customer submits any support request to Frends, Customer shall not include Personal Data in the support ticket unless agreed with Frends in advance. Where such inclusion has been agreed, Frends acts as a processor of that Personal Data, and the relevant ticketing and workflow infrastructure providers are classified as Sub-processors, in accordance with the Sub-processor terms of this DPA and as further described at https://frends.com/legal/sub-processors . For clarity, if a support ticket contains only the sender's contact information (such as name and email address) necessary to respond to the ticket, and no other Personal Data, such ticket may be submitted without Frends’ prior consent. In such cases, Frends acts as an independent Data Controller with respect to such contact information, and the relevant ticketing system service providers are not considered Sub-processors.

3. Frends shall notify Customer before engaging a new Sub-processor or replacing an existing one. Customer may object to such a change on reasonable data protection grounds by notifying Frends in writing without undue delay, and in any event within thirty (30) days of receiving Frends' notice. If Customer objects and the Parties are unable to resolve the objection, each Party may terminate the Agreement upon thirty (30) days' written notice.

7. INTERNATIONAL TRANSFERS

Frends is committed to protecting Customer's Personal Data and processes Personal Data primarily within the EU or EEA. Any processing of Personal Data outside the EU or EEA, including the Sub-processors involved and the applicable transfer mechanism under the Data Protection Legislation, is described at https://frends.com/legal/sub-processors, as may be updated by Frends from time to time. By entering into this Agreement, Customer accepts the use of the transfer mechanism(s) described at that page, as so updated. Such processing is also subject to security measures consistent with Frends' own ISO 27001-certified information security standards. Frends shall not otherwise transfer Personal Data outside the EU or EEA unless (a) Customer has separately agreed to such transfer in writing, or (b) Customer has selected a product, feature, or configuration that, for technical reasons, requires Frends to host or process Personal Data outside the EU or EEA.

8. PERSONAL DATA BREACHES

1. Each Party shall notify the other Party without undue delay after becoming aware of a Personal Data Breach affecting the Personal Data processed under this Agreement.

2. When notifying Frends of a Personal Data Breach, Customer shall provide all information reasonably necessary to assist Frends in investigating, containing, and remediating the breach.

3. When notifying Customer of a Personal Data Breach, Frends shall, to the extent the information is available to Frends, provide:

(a) a description of the nature of the breach, including, where possible, the categories and approximate number of Data Subjects and Personal Data records concerned;

(b) the contact details of Frends' Chief Information Security Officer or another contact point for further information;

(c) a description of the likely consequences of the Personal Data Breach; and

(d) a description of the measures Frends has taken or proposes to take to address the Personal Data Breach, including measures to mitigate its possible adverse effects.

4. Where the information above is not available at the time of notification, Frends shall provide it in phases without undue further delay as it becomes available.

9. RIGHT TO AUDIT

1. During the term of this DPA, Customer, or an independent third-party auditor appointed by Customer (who may not be a competitor of Frends), may audit Frends' compliance with its obligations under this DPA. The audit shall be conducted remotely and shall be limited to Frends' relevant records and systems used in the processing of Customer's Personal Data.

2. Customer may conduct such an audit no more than once per calendar year, unless a further audit is required following a Personal Data Breach or by a competent supervisory authority. Customer shall provide Frends with at least thirty (30) days' prior written notice, together with a detailed audit plan describing the proposed scope, duration, and start date. Frends may raise reasonable concerns or questions regarding the proposed plan, which Customer shall address in good faith before the audit proceeds.

3. Frends shall reasonably cooperate with the audit and provide the auditor with information reasonably necessary to demonstrate Frends' compliance with its obligations under this DPA, including by way of documentation, screen-sharing, video calls, or remote access to relevant systems, as reasonably determined by Frends. The audit shall not unreasonably interfere with Frends' business operations or the provision of the Services or Professional Services, and the auditor shall not be given access to information belonging to Frends' other customers or partners. Where the auditor is not Customer itself, the auditor shall enter into a confidentiality agreement with Frends before the audit begins. No competitor of Frends, as reasonably determined by Frends, may conduct an audit of Frends.

4. Where Frends holds a current, relevant third-party certification or audit report (such as an ISO 27001 certificate) covering the systems or processing in scope, Frends may satisfy its obligations under this Section 9 by providing that certification or report to Customer, unless Customer can demonstrate a reasonable basis for requiring a further audit.

5. Each Party shall bear its own costs in connection with an audit. Frends shall provide reasonable assistance in connection with an audit at no additional charge. Where such assistance would require material effort beyond what is reasonable — for example, an audit exceeding the agreed scope, requiring extensive documentation review, or requiring dedicated personnel over an extended period — Frends shall notify Customer in advance with a good-faith estimate of the work and cost involved, and shall proceed only upon Customer's written approval. Any such additional assistance shall be charged on a time-and-materials basis at Frends' then-current price list rates. Where an audit is triggered by a confirmed Personal Data Breach caused by Frends, Frends shall bear its own costs regardless of the effort involved.

10. LIMITATION OF LIABILITY UNDER THIS DPA

1. Each Party's liability arising out of or in connection with this DPA shall be subject to, and shall not exceed, the applicable limitation of liability set out below:

(a) Where liability relates to Personal Data processed in connection with the Platform under the Platform Agreement, the Platform Agreement's limitation of liability shall apply.

(b) Liability shall be subject to the Professional Services Agreement's limitation of liability only where it arises directly from the performance of Professional Services (including Customer's provision of Personal Data in connection therewith). Professional Services merely being performed concurrently with Customer's use of the Platform is not sufficient to attribute liability to the Professional Services Agreement.

(c) Where liability cannot be clearly and specifically attributed to Professional Services under (b), the Platform Agreement's limitation of liability shall apply by default. It shall instead be attributed to the Professional Services Agreement only to the extent the Party invoking that cap affirmatively establishes the liability arose directly from Professional Services.

(d) The two limitations of liability shall not be combined into a single, aggregate cap; each applies separately as determined under (a)–(c).

2. This DPA does not itself create a separate or additional limitation of liability; it operates by reference to the limitation(s) of liability in the Platform Agreement and/or Professional Services Agreement, as applicable.

11. TERM AND TERMINATION

1. This DPA shall become effective in parallel with the Agreement and shall continue in force until the termination of the Agreement or as long as Frends processes Personal Data on behalf of the Customer.

2. If not instructed otherwise in writing by the Customer and unless legally required to keep the Personal Data (including possible Personal Data stored in the Platform and Frends Back-Ups), Frends shall delete and destroy such Personal Data the latest within ninety (90) days of the termination of the Agreement or after the maximum data retention period permitted by the relevant technology. Frends will keep the Personal Data stored in the Platform and in the Frends Back-Ups available for download by the Customer during the termination period and thereafter if and as reasonably requested by Customer in writing.

3. Where Customer requests that Frends return Personal Data to Customer or to a third party, and such request is extensive in scope, nature, or effort required (for example, requiring non-standard export formats, data extraction beyond Frends' standard tooling, or processing significant volumes of data), Customer shall reimburse Frends for the reasonable additional costs and expenses incurred by Frends in fulfilling such request, beyond what is provided as part of Frends' standard data return or export functionality.

12. INCORPORATION OF GENERAL PROVISIONS

The governing law, dispute resolution, and any other general or miscellaneous provisions set out in the Agreement (including, without limitation, provisions relating to notices, assignment, severability, and entire agreement) shall apply to this DPA as though fully set out herein, save to the extent expressly varied by this DPA. Where the Platform Agreement and the Professional Services Agreement differ on any such provision, the precedence rule in Section 1.4 of this DPA shall apply.

 

SCHEDULE 1 – DESCRIPTION OF THE PERSONAL DATA AND DATA SECURITY PROCEDURES

The Parties may amend or update this Schedule in writing, where necessary.

1. SUBJECT MATTER AND DURATION OF PROCESSING

The subject matter of the processing is the Personal Data submitted, stored, or otherwise made available by Customer in connection with Customer's use of the Frends Platform and/or receipt of Professional Services. Processing shall continue for the duration of the Agreement, and thereafter only to the extent required to comply with Frends' data retention, deletion, or return obligations under the Agreement and this DPA.

2. NATURE AND PURPOSE OF THE PROCESSING

Frends shall process Personal Data solely for the purpose of providing the Frends Platform and related Professional Services as stipulated in the Agreement, including the underlying technical operation, maintenance, support, and security of the Frends Platform.

3. NATURE OF THE PROCESSING ACTIVITIES

Frends shall perform the following processing activities on the Personal Data, as necessary to fulfil the purpose described in Section 2 above:

  • Collection
  • Adaptation and alteration
  • Recording
  • Making data available (disclosure of data by, e.g., transmission or dissemination)
  • Organisation
  • Alignment or combination
  • Storage
  • Erasure and destruction

4. CATEGORIES OF DATA SUBJECTS

Frends shall process Personal Data relating to the following categories of Data Subjects, as applicable and without limitation:

  • Customer's employees, independent contractors, agents, advisors, and freelancers;
  • Customer's prospects, customers, business partners, and vendors, or their respective employees and contact persons;
  • Any other natural persons whose Personal Data is contained within Customer's integrations, workflows, or configurations processed through the Frends Platform.

5. CATEGORIES OF PERSONAL DATA

Frends shall process the following categories of Personal Data in relation to the Data Subjects identified in Section 4 above, as applicable and without limitation:

  • Identification data (e.g., first and last name)
  • Contact data (e.g., email address)
  • Technical/online identifiers (e.g., IP address)
  • Any other Personal Data that Customer elects to include within the data flows, integrations, or configurations processed through the Frends Platform in connection with the Agreement

Customer acknowledges and agrees that the specific categories and volume of Personal Data actually processed depend on the content and configuration of Customer's own integrations and use of the Frends Platform, and are determined by Customer, not by Frends.

6. SUB-PROCESSORS

A current list of Frends' authorized sub-processors, including the nature of the services provided by each and the country/location of processing, is maintained and made available at frends.com/legal/sub-processors.

7. APPLICABLE DATA SECURITY MEASURES

Frends shall implement and maintain the technical and organizational security measures set out in Schedule 2 in respect of its processing of Personal Data under the Agreement.

SCHEDULE 2 – FRENDS DATA SECURITY PROCEDURES

Frends has implemented, and shall maintain throughout the term of the Agreement, the following technical and organizational measures:

  1. Information Security Program. Frends maintains an information security program approved by its management, regularly reviewed and updated, and aligned with ISO 27001 certification requirements.
  2. Access Authentication. Access to Personal Data is restricted to Authorized Individuals who authenticate using credentials that uniquely identify them.
  3. Role-Based Access Control. Authorized Individuals' rights to access or modify Personal Data are restricted according to business role and legitimate business need.
  4. Access Review. Access and authorization rights of Authorized Individuals are reviewed on a regular basis, and are promptly withdrawn or modified upon termination of employment/engagement or change of role.
  5. Physical Security. Physical access to systems storing or processing Personal Data is appropriately secured and monitored.
  6. Encryption. Personal Data is encrypted both at rest and in transit, using industry-standard protocols and encryption algorithms.
  7. Secure Development. Frends has implemented and maintains secure coding and development standards that incorporate security and privacy considerations by design.
  8. Personnel Training. Frends personnel receive regular security and privacy training appropriate to their roles and responsibilities in relation to the treatment and protection of Personal Data.
  9. Network Segregation. Internal systems storing or processing Personal Data are segregated from public networks.
  10. Monitoring and Alerting. Frends has implemented monitoring and alerting capabilities across its systems to detect anomalous or unauthorized activity.
  11. Vulnerability Management. Frends regularly evaluates its systems for vulnerabilities and deploys security updates on a schedule based on risk and severity.
  12. Penetration Testing. Frends regularly tests the security of its systems, including an annual penetration test conducted by a qualified independent third party.
  13. Sub-processor Oversight. Frends evaluates the security and privacy practices of all authorized sub-processors prior to engagement and on an ongoing basis.
  14. Availability and Continuity. Frends deploys redundant services and maintains practices, including regular backups, designed to ensure continued availability of, and access to, Personal Data despite disruptions to its infrastructure.
  15. Incident Response. Frends maintains a documented incident response plan and commits to providing notification of a confirmed Personal Data Breach without undue delay, in accordance with the Agreement Data Protection Legislation.
  16. Data Subject Rights and Retention. Frends maintains systems and processes to support compliance with applicable data privacy requirements, including limited data retention periods and the handling of Data Subject requests.

Previous versions: