Frayme Data Processing Agreement

Last updated: 17 September 2026

This Data Processing Agreement ("DPA") forms part of the Agreement as defined in the Frayme Terms of Service (the "Agreement") between Frayme Ltd (company number 17360941, registered office 15 Carraway Street, Reading, England, RG1 3GB) ("Frayme") and the Customer, and applies automatically wherever Data Protection Laws apply to personal data contained in Customer Content ("Customer Personal Data"). No signature is required for this DPA to bind the parties. For Customer's records, a copy of this DPA signed on behalf of Frayme, with Customer's legal name and workspace inserted, is available on request from support@frayme.ai; a signed copy does not vary these terms, and Frayme does not accept alternative or amended data protection terms except under a separately negotiated written agreement.

How this DPA applies to you

Frayme has customers in the United Kingdom, the European Economic Area and the United States. This is one document for all of them. Which parts apply to a given customer depends on which law applies to that customer's data, not on where the customer is located.

PartClausesApplies
Part A: Core terms1 to 9To every customer, wherever Data Protection Laws apply
Part B: UK, EU and Swiss transfers10Only where UK, EU/EEA or Swiss data protection law applies
Part C: Breach, liability and general11 to 12To every customer
Part D: United States13Only where a US State Privacy Law applies
AnnexesA, B, CTo every customer; Annexes A to C also serve as the annexes to any incorporated Standard Contractual Clauses

A customer may be covered by more than one Part at the same time, for example a US business with European end users. Where that happens, each Part applies to the data it governs.

Order of precedence. In case of conflict, this DPA prevails over the rest of the Agreement for data protection matters. Within this DPA, any Standard Contractual Clauses entered into under clause 10 prevail over the rest of this DPA, and clause 13 prevails over clauses 1 to 12 in respect of personal data governed by US State Privacy Laws.


Part A: Core terms

This Part applies to every customer, wherever Data Protection Laws apply to personal data in Customer Content.

1. Definitions

1.1 "Data Protection Laws" means, as applicable: the UK GDPR and the Data Protection Act 2018; Regulation (EU) 2016/679 (the "EU GDPR"); the Swiss Federal Act on Data Protection; the US State Privacy Laws; and other applicable laws relating to privacy or the processing of personal data, in each case as amended.

1.2 "Controller", "processor", "data subject", "personal data", "personal data breach" and "processing" have the meanings given in Data Protection Laws. Where clause 13 applies, the corresponding terms used in US State Privacy Laws (including "business", "service provider", "consumer" and "personal information") carry the meanings given in those laws, and a reference in this DPA to a controller, a processor, a data subject or personal data is read accordingly.

1.3 "Sub-processor" means a third party engaged by Frayme to process Customer Personal Data.

1.4 "EEA" means the member states of the European Union together with Norway, Iceland and Liechtenstein.

1.5 "Restricted Transfer" means a transfer of Customer Personal Data to a country outside the UK or the EEA (as applicable) that is not covered by adequacy regulations under the UK GDPR or an adequacy decision under the EU GDPR and, where Swiss law applies, a transfer of Customer Personal Data out of Switzerland to a country that the Swiss Federal Council has not recognised as providing adequate protection.

1.6 "US State Privacy Laws" means the comprehensive consumer privacy laws of the states of the United States, as amended and including their implementing regulations: the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020 (the "CCPA"); the Virginia Consumer Data Protection Act; the Colorado Privacy Act; the Connecticut Data Privacy Act; the Utah Consumer Privacy Act; the Texas Data Privacy and Security Act; the Oregon Consumer Privacy Act; the Montana Consumer Data Privacy Act; the Delaware Personal Data Privacy Act; the Iowa Consumer Data Protection Act; the Nebraska Data Privacy Act; the New Hampshire data privacy act; the New Jersey Data Privacy Act; the Tennessee Information Protection Act; the Minnesota Consumer Data Privacy Act; the Maryland Online Data Privacy Act; the Indiana Consumer Data Protection Act; the Kentucky Consumer Data Protection Act; the Rhode Island Data Transparency and Privacy Protection Act; and any other law of a US state, of general application, governing the processing of personal data of that state's residents, including any such law that takes effect after the date of this DPA.

1.7 "Request Content" means, for a single request to the Service, the prompt, the DATA block, every model output generated for that request and the interface specification returned to Customer. Where Request Content contains personal data, it is Customer Personal Data.

1.8 "Sub-processor List" means the list published at frayme.ai/sub-processors.

2. Roles and scope

2.1 For Customer Personal Data, Customer is the controller and Frayme is the processor. Where clause 13 applies, Customer is the "business" or "controller" and Frayme is the "service provider" or "processor", as those terms are used in the applicable US State Privacy Law. Where Customer is itself a processor acting for its own controllers, Customer warrants that its instructions to Frayme are authorised by the relevant controller, and Frayme acts as sub-processor.

2.2 This DPA covers the processing described in Annex A: the receipt and processing of Request Content to compose, validate and return interface specifications; the storage of Request Content in Frayme's database for up to 60 days from the request, for the purposes stated in Annex A; and the deletion of that content, and the anonymisation of what remains of the record, at the end of that period.

2.3 Frayme's processing of account, billing and usage data as a controller is described in the Privacy Policy and is outside the scope of this DPA. The same applies to the anonymised material described in clause 3.4, from the point at which it has been anonymised.

3. Customer instructions

3.1 Frayme will process Customer Personal Data only on Customer's documented instructions, including regarding international transfers and including the instruction in clause 3.4, unless required otherwise by law to which Frayme is subject. In that case Frayme will inform Customer before processing, unless the law prohibits it. The Agreement, this DPA and Customer's use of the Service's APIs and settings constitute the complete documented instructions. Frayme does not train, fine-tune or improve machine-learning models on Customer Content, on Outputs or on any other Customer Personal Data, and Customer's instructions do not permit it to do so. The only exception is the anonymisation instruction in clause 3.4, which operates on Request Content to produce material that is no longer personal data.

3.2 Frayme will inform Customer if, in its opinion, an instruction infringes Data Protection Laws. Frayme is not obliged to monitor Customer's compliance.

3.3 Frayme may update Annex A to reflect new or changed features of the Service, by notice given under clause 22.1 of the Terms, provided the update does not materially expand the categories of personal data processed or the purposes of processing. A material expansion requires Customer's agreement.

3.4 Anonymisation instruction. Customer instructs Frayme, and Frayme is permitted, to create anonymised material from generations that failed validation, by removing from the relevant Request Content all personal data and all information identifying Customer or any individual, so that the resulting material can no longer be linked to Customer or to any individual by Frayme or by any other person using means reasonably likely to be used. Customer may withdraw this instruction at any time, for all future requests, by written notice to support@frayme.ai, without charge and without affecting any other part of the Service; Frayme will confirm the change within 5 working days. Frayme may use that anonymised material to improve and train its models. This instruction is narrow and does not permit Frayme to use prompts, DATA blocks, model outputs or returned interface specifications, in their original or any identifiable form, for training or model improvement. Frayme will not attempt to reverse the anonymisation or to re-identify the material. Once anonymised, the material is no longer Customer Personal Data and clause 2.3 applies to it.

3.5 Roles for anonymisation. Frayme performs the anonymisation step in clause 3.4 on Customer's instruction and, to the extent that step is also carried out for Frayme's own purpose of improving its models, as a controller in its own right, relying on its legitimate interests in improving and securing the Service, for which it has carried out and records a legitimate interests assessment available on request. Frayme will not carry out that step where Customer has withdrawn the instruction, and will delete rather than anonymise any material that cannot be anonymised to the standard in clause 8.3(b) and (c) with confidence. Frayme's controller-side processing under this clause is described in the Privacy Policy.

4. Customer obligations

Customer is responsible for: the lawfulness of Customer Personal Data and of its instructions; establishing a lawful basis and providing any required notices to data subjects and consumers; and not submitting prohibited data. Prohibited data means the categories prohibited by clause 8.3 of the Terms, namely special categories of personal data (including health, biometric or genetic data), personal data relating to criminal convictions or offences, full payment card numbers or financial account credentials, government-issued identification numbers, and the personal data of children (for this purpose, anyone under 16), together with any other category of sensitive personal data or sensitive personal information defined in an applicable Data Protection Law, unless separately agreed with Frayme in writing.

5. Frayme's obligations

Frayme will:

(a) ensure persons authorised to process Customer Personal Data are bound by confidentiality obligations;

(b) implement and maintain the technical and organisational measures described in Annex B, appropriate to the risk, including as required by Article 32 UK/EU GDPR and by the reasonable-security requirements of US State Privacy Laws, and not materially reduce the overall protection they provide during the term;

(c) assist Customer, taking into account the nature of the processing, by appropriate technical and organisational measures, in responding to data subject and consumer requests (clause 7) and in Customer's obligations relating to the security of processing, personal data breach notification, data protection impact assessments, transfer risk assessments and prior consultation (Articles 32 to 36 UK/EU GDPR), and data protection assessments required by US State Privacy Laws, with Frayme entitled to charge reasonable costs for assistance that is manifestly excessive;

(d) make available the information reasonably necessary to demonstrate compliance with Article 28 UK/EU GDPR and with the equivalent processor or service provider obligations of US State Privacy Laws, and allow audits and assessments as set out in clause 9; and

(e) delete or return Customer Personal Data as set out in clause 8.

6. Sub-processors

6.1 Customer gives Frayme general written authorisation to engage Sub-processors. The current Sub-processor List (including each Sub-processor's purpose, the data it receives, its region and the applicable transfer safeguard) is published at [frayme.ai/sub-processors](https://frayme.ai/sub-processors) and reproduced in Annex C. Where the Sub-processor List and Annex C differ, the Sub-processor List is the authoritative version.

6.2 At least 30 days before a new or replacement Sub-processor begins processing Customer Personal Data, Frayme will (a) update the Sub-processor List, and (b) notify Customer by email, sent to the workspace owner and the billing contact recorded for Customer's account. Customer is responsible for keeping those addresses current; notice sent to the addresses then on record is effective notice under this clause. Customer may ask Frayme to copy additional addresses by writing to support@frayme.ai. If Customer objects on reasonable data-protection grounds within 30 days of the date the email notice is sent, the parties will discuss in good faith; if no resolution is found, Customer may terminate the affected Service and receive a pro-rata refund of prepaid Fees for the unused period. If Customer does not object within the notice period, the Sub-processor is deemed authorised. Where a Sub-processor must be replaced urgently for security or service-continuity reasons, Frayme may give shorter notice, will explain the reason, and Customer's objection right and remedy under this clause continue to apply; where Standard Contractual Clauses are in force under clause 10.3, the notice period for the purposes of Clause 9(a) of those Clauses is 30 days, and the urgent-replacement mechanism applies only to the extent consistent with those Clauses.

6.3 Frayme will engage each Sub-processor under a written contract imposing data protection obligations materially equivalent to those in this DPA, and remains liable to Customer for the Sub-processor's performance. On request, Frayme will provide a copy of the data protection terms agreed with a Sub-processor, redacted to protect commercially confidential information. Where a Sub-processor is engaged through another Sub-processor, as Anthropic is engaged through Vercel's AI Gateway, Frayme's contract is with that other Sub-processor, and the flow-down obligations in its terms apply to the onward engagement; Annex C states the chain for each such provider.

7. Data subject and consumer rights; third-party requests

7.1 Rights requests. Frayme will, taking into account the nature of the processing, assist Customer in fulfilling requests from data subjects and consumers to exercise their rights (including access, rectification or correction, erasure or deletion, restriction, portability, objection, opt-out and appeal) to the extent Customer cannot reasonably fulfil the request itself through the Service. If a data subject or consumer contacts Frayme directly about processing under this DPA, Frayme will promptly refer the request to Customer and will not respond substantively except as required by law.

In practice, Frayme holds Customer Personal Data for a short, fixed period: Request Content is stored for up to 60 days from the request and is then irreversibly deleted, as set out in clause 8 and Annex A. Within that period, Customer may ask Frayme to export, correct or delete the Request Content for identified requests, or all stored Request Content for a workspace, by writing to support@frayme.ai from the workspace owner's address; Frayme completes verified requests within 30 days. This is the practical means by which Frayme gives effect to access, rectification, erasure, restriction and portability requests, and to the equivalent consumer rights under US State Privacy Laws. From the dashboard, Customer can rotate and revoke API keys and cancel its Plan; deletion of Request Content, of a workspace or of an account is requested through support@frayme.ai.

7.2 Third-party and government requests. If Frayme receives a request or order from a court, regulator, law-enforcement body or other public authority for access to Customer Personal Data, Frayme will: (a) notify Customer promptly, unless legally prohibited, and if prohibited use reasonable efforts to obtain a waiver of the prohibition; (b) not disclose Customer Personal Data except to the extent legally compelled, and then only the minimum necessary; (c) where there are reasonable grounds to do so, challenge the request or order under available procedures; and (d) cooperate with Customer, at Customer's reasonable cost, in any legal response. Frayme keeps a record of such requests and, on request, provides Customer with aggregate information about them.

8. Retention, deletion and return

8.1 Routine retention and deletion. Request Content is stored in Frayme's database, in the European Union, for up to 60 days from the request, for the purposes stated in Annex A. At the end of that period the content is irreversibly deleted from the record. It is deleted from live systems at that point and leaves database backups as those backups roll over, within a further 7 days. What survives is non-identifying technical signal only: the failure category, the component and property names the validator flagged, timings, token counts, cost, which model answered and the validation result, with workspace, user, API-key and trace identifiers removed. The content itself is deleted rather than masked, and the surviving record is anonymised to the standard in clause 8.3(a) and (c). No separate confirmation is given for routine deletion; clause 9.1 governs evidence of Frayme's compliance.

8.2 Deletion and return on termination or request. On termination or expiry of the Agreement, on the end of the provision of services relating to processing, or on Customer's verified request at any time, Frayme will, at Customer's choice and direction: (a) return a copy of the Customer Personal Data it still holds (in practice, the Request Content stored for Customer's workspaces within the preceding 60 days) in a machine-readable export, where technically feasible; and/or (b) delete that Request Content, including copies held by Sub-processors to the extent Frayme is able to procure their deletion, and anonymise the remaining records for Customer's workspaces to the standard in clause 8.3(a) and (c). Frayme will complete this within 30 days of the request or of termination, and will confirm completion in writing on request. Request Content that has already reached the end of its 60-day period will already have been deleted under clause 8.1.

8.3 Anonymisation standards.

(a) Record anonymisation. When a stored record is anonymised at the end of the period in clause 8.1, Frayme removes every workspace, user, API-key and trace identifier and all residual Request Content, leaving only the non-identifying technical signal described in clause 8.1.

(b) Anonymisation of derived material. When Frayme creates the material described in clause 3.4, it removes every workspace, user, API-key and trace identifier and all personal data and all other information that identifies or could be used to identify Customer, any application Customer builds with the Service, or any individual, including within free-text prompts and DATA block contents.

(c) Common standard. In each case the result must be such that neither Frayme nor any other person can identify an individual from the material, directly or indirectly, by any means reasonably likely to be used. Until material has been anonymised to the applicable standard it remains Customer Personal Data and is processed under this DPA. Frayme will not attempt to re-identify anonymised material.

8.4 Limited exceptions. Frayme retains Customer Personal Data beyond the periods in clauses 8.1 and 8.2 only where and for as long as required by law or legitimately necessary for security and service integrity, in practice: (a) platform and security logs held by Frayme's hosting providers for a short period, typically 1 to 7 days on Frayme's current plans, unless exported for the investigation of a specific incident; (b) hashed API-key identifiers and abuse event records for approximately 12 months; (c) where Frayme is subject to a legal hold or a preservation obligation, the records covered by it, for as long as that obligation lasts; (d) where Frayme is investigating a suspected breach of the Acceptable Use Policy, has taken enforcement action under it, has referred a matter to law enforcement or a regulator, or is handling a complaint under the IP and Content Complaints Policy, the Request Content and records relevant to that matter, for as long as the matter and any resulting claim or proceeding reasonably requires (Customer instructs Frayme to retain that material for those purposes, and to the extent Frayme also retains it to establish, exercise or defend its own legal claims it does so as a controller relying on its legitimate interests, with the material remaining subject to the security measures in Annex B and to clause 8.3(a) and (c) on completion); and (e) Frayme may, on the same basis, restrict access to or delete a specific item of Request Content where it is required to do so by law or by a court order, or where the material is manifestly unlawful, and will notify Customer unless prohibited from doing so. Retained data remains protected under this DPA and is deleted when the requirement ends. Retention of Frayme's own account, workspace, usage and billing records, including the billing totals kept for approximately 6 years for invoicing and tax, is a controller-side matter described in the Privacy Policy and is outside the scope of this DPA.

9. Audits, assessments and compliance information

9.1 Information in the first instance. Frayme will make available, on request to support@frayme.ai, information reasonably necessary to demonstrate compliance with this DPA, including Annex B, summaries of testing, and third-party attestations or certifications as they become available. The parties agree these materials satisfy audit and assessment requests in the first instance. Frayme will respond to reasonable written security or due-diligence questionnaires, sent to support@frayme.ai, no more than once in any 12-month period, unless Data Protection Laws or a personal data breach require otherwise. Frayme maintains records of its compliance with this DPA for 3 years after this DPA ends.

9.2 Audit. Where the information provided under clause 9.1 is not reasonably sufficient to demonstrate Frayme's compliance, or where a supervisory authority or Data Protection Laws require an audit or inspection, Customer (or an independent auditor bound by confidentiality, not a Frayme competitor) may audit Frayme's compliance with this DPA: no more than once in any 12-month period, on at least 30 days' written notice, during business hours, without access to other customers' data, at Customer's cost, and subject to Frayme's reasonable security policies. Audits required by a supervisory authority are excepted from these limits.

9.3 Independent assessment. Where a US State Privacy Law entitles Customer to a reasonable assessment of Frayme's compliance, Frayme may satisfy that entitlement by arranging for a qualified and independent assessor to assess Frayme's policies and technical and organisational measures using an appropriate and accepted control standard or framework and an appropriate assessment procedure, and by providing a report of that assessment to Customer on request. Frayme will otherwise allow and cooperate with reasonable assessments by Customer or Customer's designated assessor on the terms in clause 9.2.

9.4 Saving. Nothing in this clause limits any right of Customer under Data Protection Laws, or under any incorporated Standard Contractual Clauses, that cannot lawfully be limited by agreement.


Part B: UK, EU and Swiss transfers

This Part applies only where UK, EU/EEA or Swiss data protection law applies to Customer Personal Data. It does not apply to personal data governed solely by US State Privacy Laws.

10. International transfers

10.1 Where processing happens. Account data, workspace data and stored Request Content rest in the European Union (Frankfurt). The application, the API and model inference run on United States providers, Vercel and Modal, under standard contractual clauses. Frayme's own model is served on Modal's global infrastructure, with requests routed through the United States; Frayme calls the model through Modal web endpoints, and Modal's security documentation states that for web endpoints request and response payloads are not stored and are proxied directly to the container, and that container logs are retained for one day on Frayme's current plan. The fallback model (Anthropic, reached through Vercel's AI Gateway) is also in the United States and is used only where the primary model's output fails validation. Frayme is established in the United Kingdom and its personnel access Customer Personal Data from the United Kingdom. Each provider, its region and its transfer safeguard are set out in Annex C, Table 1. The providers listed in Annex C, Table 2 handle account, billing, sign-in, email and operational-metadata for which Frayme is a controller; those transfers are described in the Privacy Policy and are outside the scope of this DPA.

10.2 For any Restricted Transfer, Frayme ensures a valid transfer mechanism is in place: an adequacy decision where available (including the EU-US Data Privacy Framework and UK Extension where the recipient is certified), or the EU Standard Contractual Clauses (Commission Decision (EU) 2021/914), supplemented for UK transfers by the ICO International Data Transfer Addendum, together with supplementary measures where appropriate. Frayme's transfers to the providers in Annex C, Table 1 are made under those mechanisms as stated in that table, with Frayme acting as data exporter.

10.3 Standard Contractual Clauses between Customer and Frayme. Because the United Kingdom is covered by an adequacy decision under the EU GDPR, is recognised by the Swiss Federal Council as providing adequate protection, and the EEA is covered by adequacy regulations under the UK GDPR, a transfer of Customer Personal Data from a Customer established in the UK, the EEA or Switzerland to Frayme in the United Kingdom is not a Restricted Transfer, and no Standard Contractual Clauses are required for it. This clause therefore bites only where adequacy does not cover the transfer, for example where an adequacy decision or regulation is repealed, suspended, annulled or otherwise ceases to apply, or where Customer is established in a country for which no such decision exists. Where a Restricted Transfer from Customer to Frayme would otherwise lack a mechanism, then from that point and without further action by the parties the EU SCCs (Module Two where Customer is a controller; Module Three where Customer is a processor) and, for transfers subject to the UK GDPR, the ICO Addendum, are incorporated into this DPA by reference and completed as follows:

(a) Customer is the data exporter and Frayme is the data importer;

(b) Annexes A, B and C of this DPA serve as Annexes I.B, II and III of the SCCs; for Annex I.A, the data exporter is the Customer entity named in its account, with the address, contact person and role as controller or processor recorded there, and the data importer is Frayme Ltd at the address in the opening paragraph of this DPA, contact support@frayme.ai, acting as processor or sub-processor, with the EU representative named in clause 12.4; and the competent supervisory authority for Annex I.C is that of the data exporter as determined under Clause 13 (for transfers subject to the UK GDPR, the Information Commissioner);

(c) the optional docking clause in Clause 7 applies;

(d) in Clause 9, Option 2 (general written authorisation) applies, with the 30-day notice period in clause 6.2 of this DPA;

(e) the optional language in Clause 11 does not apply;

(f) in Clause 17, Option 1 applies and the SCCs are governed by the law of Ireland (Clause 17 requires the law of an EU Member State that allows third-party beneficiary rights; this choice affects only the SCCs, and not this DPA or the Agreement, which remain governed by the law of England and Wales);

(g) under Clause 18(b), disputes under the SCCs are resolved by the courts of Ireland; and

(h) for the ICO Addendum, Table 4 is completed so that neither party may end the Addendum under its section 19; the parties will amend this DPA in good faith if the ICO issues a revised Approved Addendum; and the Addendum is governed by the law of England and Wales.

10.4 Swiss transfers. Where Swiss law governs a Restricted Transfer, the EU SCCs apply with references to the EU GDPR read as references to the Swiss Federal Act on Data Protection, references to the supervisory authority read as the Swiss Federal Data Protection and Information Commissioner, and "Member State" read to include Switzerland so that Swiss data subjects may enforce their rights there.

10.5 If a mechanism ceases to be valid. If an adequacy decision, certification framework or set of clauses relied on under this clause is invalidated, suspended, amended or replaced, Frayme will without undue delay implement an alternative lawful transfer mechanism or additional safeguards for the affected transfer, and the parties will execute any documents reasonably required to give effect to it. Where no lawful mechanism is available, Frayme will suspend the affected transfer, and Customer may terminate the affected Service and receive a pro-rata refund of prepaid Fees for the unused period.


Part C: Breach, liability and general

This Part applies to every customer.

11. Personal data breach

Frayme will notify Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data, by email to the workspace owner and the billing contact recorded for Customer's account. The notice will give the information then available and will be supplemented in phases as more becomes available: the nature of the breach, the categories and approximate volumes of data subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point. An initial notice need not be complete; the timing is set so that Customer can meet its own notification deadlines, including the 72-hour deadline under Article 33 UK/EU GDPR. Frayme will promptly take reasonable steps to contain, investigate and mitigate the breach, and will cooperate reasonably in Customer's notification obligations, including those under US state data breach notification laws, in a time and manner that enables Customer to meet them. Unsuccessful attempts, and activity that does not compromise the security of Customer Personal Data (such as pings, port scans or failed log-in attempts), are not personal data breaches for the purposes of this clause. Notification is not an admission of fault.

12. Liability and general

12.1 Each party's liability under this DPA (including under any incorporated SCCs, as between the parties and to the extent those Clauses permit) is subject to the exclusions and cap in clauses 21.1 to 21.4 of the Terms, treated as a single aggregate cap across the Agreement and this DPA. Nothing limits either party's liability to data subjects, consumers or supervisory or regulatory authorities where such limitation is not permitted.

12.2 This DPA starts when the Agreement starts and survives until Frayme has deleted or anonymised all Customer Personal Data. It is governed by the law of England and Wales, without prejudice to any mandatory governing-law requirements of incorporated SCCs and to the application of US State Privacy Laws under clause 13.

12.3 Claims against Frayme arising out of or relating to this DPA (including under incorporated SCCs, to the extent they permit) may be brought only by the Customer entity that is party to the Agreement, including on behalf of any affiliate that has acceded to the SCCs under the docking clause.

12.4 Contacts. All matters under this DPA (including security and due-diligence questionnaires, breach notifications, deletion requests and sub-processor objections) go to support@frayme.ai. Frayme has not appointed a Data Protection Officer; one is not required for its processing, and privacy matters are handled at support@frayme.ai. Frayme's representative in the European Union under Article 27 EU GDPR is DPO Europe GmbH, Auguste-Viktoria-Allee 20A, 13403 Berlin, Germany (HRB 235801), representative@data-privacy-office.eu. Frayme has not appointed a separate United States representative; no US State Privacy Law requires one.


Part D: United States

13. US state privacy laws

This Part applies to the extent Frayme processes Customer Personal Data that is subject to a US State Privacy Law. Where it conflicts with Parts A, B or C, this Part prevails in respect of that data. Nothing in this Part requires either party to act under a law that does not apply to it, and each obligation applies only to the extent of the US State Privacy Law that imposes it.

13.1 Roles and permitted processing. Customer is the business or controller; Frayme is the service provider or processor. Frayme processes Customer Personal Data only on Customer's documented instructions under clause 3, and only for the limited and specified business purposes set out in Annex A and in the Agreement.

13.2 Contract particulars. As US State Privacy Laws require the parties' contract to set these out, the parties record that: Customer's processing instructions are as stated in clauses 3.1 and 3.4; the nature and purpose of processing, the types of personal data processed, the categories of data subjects and consumers, and the duration of processing are as stated in Annex A; and the parties' rights and obligations in respect of the processing are as stated in this DPA and the Agreement.

13.3 CCPA service provider commitments. Frayme:

(a) will not sell and will not share Customer Personal Data, as "sell" and "share" are defined in the CCPA, and will not use it for cross-context behavioural advertising or targeted advertising;

(b) will not retain, use or disclose Customer Personal Data for any purpose other than the business purposes specified in Annex A and the Agreement, including not for any commercial purpose other than those business purposes, and not outside the direct business relationship between Frayme and Customer;

(c) will not combine Customer Personal Data with personal information it receives from or on behalf of any other person, or collects from its own interaction with a consumer, except where the CCPA expressly permits a service provider to do so;

(d) will comply with the obligations applicable to it under the CCPA and other US State Privacy Laws, will provide the same level of privacy protection that those laws require of Customer, and will implement reasonable security procedures and practices appropriate to the nature of the personal information, in accordance with California Civil Code section 1798.81.5 (Annex B);

(e) will notify Customer promptly, and in any event without undue delay, if Frayme determines that it can no longer meet its obligations under the CCPA or any other applicable US State Privacy Law;

(f) grants Customer the right to take reasonable and appropriate steps (including the steps available under clause 9) to ensure that Frayme uses Customer Personal Data in a manner consistent with Customer's obligations under the CCPA, and, on notice, to stop and remediate any unauthorised use of Customer Personal Data (the materials made available under clause 9.1 satisfy the first of these in the first instance); and

(g) certifies that it understands the restrictions in this clause 13.3 and will comply with them.

13.4 Processor commitments under other US State Privacy Laws. In addition to clause 13.3, and in satisfaction of the processor contract requirements of the Virginia, Colorado, Connecticut and comparable statutes, Frayme will:

(a) ensure that each person processing Customer Personal Data is subject to a duty of confidentiality (clause 5(a));

(b) at Customer's direction, delete or return Customer Personal Data at the end of the provision of services, unless retention is required by law (clause 8);

(c) on Customer's reasonable request, make available to Customer all information necessary to demonstrate Frayme's compliance with its obligations (clause 9.1);

(d) allow and reasonably cooperate with assessments by Customer or Customer's designated assessor, or arrange for a qualified and independent assessor as provided in clause 9.3;

(e) engage each Sub-processor by written contract requiring the Sub-processor to meet Frayme's obligations in respect of Customer Personal Data (clause 6.3), and give Customer notice of, and an opportunity to object to, the engagement of a new Sub-processor (clause 6.2); and

(f) assist Customer in meeting its obligations relating to consumer rights requests, the security of processing, personal data breach notification, and data protection assessments (clauses 5(c), 7 and 11).

13.5 Consumer rights. Clause 7.1 governs Frayme's assistance with consumer requests, including requests to know, access, delete, correct, opt out and appeal. Frayme will not respond substantively to a consumer who contacts it directly, and will refer the request to Customer.

13.6 Sensitive personal information. Customer must not submit sensitive personal information or sensitive data, as defined in any applicable US State Privacy Law, except as separately agreed in writing (clause 4 and clause 8.3 of the Terms). Frayme does not use Customer Personal Data to infer characteristics about a consumer.

13.7 No training, profiling or advertising use. Frayme does not use Customer Personal Data to train, fine-tune or improve machine-learning models (clause 3.1), to profile consumers, or for targeted or cross-context behavioural advertising, and does not sell or share it. The single exception is the anonymisation instruction in clause 3.4: material that has been anonymised to the standard in clause 8.3(b) and (c) is deidentified data for the purposes of the US State Privacy Laws, is handled under clause 13.8, and is no longer Customer Personal Data.

13.8 Deidentified data. Where Frayme generates deidentified data from Customer Personal Data, including the anonymised material described in clause 3.4, Frayme will take reasonable measures to ensure that the data cannot be associated with a consumer or household, has publicly committed, in its Privacy Policy, to maintaining and using it only in deidentified form, will not attempt to reidentify it, and will contractually oblige any recipient of it to the same commitments.

13.9 Government and third-party requests. Clause 7.2 applies to requests from US courts, regulators and law-enforcement bodies.

13.10 International transfers. Clause 10 does not apply to Customer Personal Data governed solely by US State Privacy Laws. Where Customer Personal Data is governed by both a US State Privacy Law and UK, EU or Swiss law, both Parts apply to it.

13.11 Notices and contacts. All matters under this clause go to support@frayme.ai (clause 12.4).


Annex A: Details of processing

This Annex serves as Annex I.B to any incorporated Standard Contractual Clauses, and as the record of the contract particulars required by clause 13.2.

Annex B: Technical and organisational measures

This Annex serves as Annex II to any incorporated Standard Contractual Clauses, and as the description of Frayme's security measures for the purposes of clause 5(b) and the reasonable-security requirements of US State Privacy Laws. It describes the measures Frayme has in place; Frayme does not claim controls it has not implemented.

Annex C: Sub-processors and other service providers

This Annex serves as Annex III to any incorporated Standard Contractual Clauses. It is a snapshot of the Sub-processor List as at the Last updated date of this DPA (17 September 2026). The authoritative, current list is at [frayme.ai/sub-processors](https://frayme.ai/sub-processors); where the two differ, that list prevails.

Table 1: Sub-processors of Customer Personal Data

Clause 6 of this DPA, clause 13.4(e), and Annex III of any incorporated Standard Contractual Clauses, attach to this table only.

#Sub-processorPurposeData receivedRegionTransfer safeguard
1Supabase (Supabase Pte. Ltd; production database hosted on AWS eu-central-1, Frankfurt)Database (the store of request content, and the generation and usage records), authentication, row-level securityRequest content (the prompt and DATA block, every model output for the request and the returned interface specification) kept for up to 60 days and then irreversibly deleted, leaving only the non-identifying technical signal described in clause 8.1. Also holds account records, workspace records, hashed API keys and usage countersEuropean Union (Frankfurt)Stored and processed in EU data centres; EU Standard Contractual Clauses and the UK Addendum in Supabase's data processing agreement cover any remote access from outside the UK or EEA
2Modal (Modal Labs, Inc., United States)Hosts and serves Frayme's own fine-tuned model (primary inference)Prompt and DATA block content and the model's output for the request. Frayme calls the model through a web endpoint; Modal's security documentation states that request and response payloads for web endpoints are not stored and are proxied directly to the container. Container logs are retained for one day on Frayme's current planUnited States and global (no region is pinned: requests are routed through Modal's servers in Virginia and containers run where Modal has capacity)Modal Labs, Inc.'s Data Processing Addendum, which is incorporated by reference into its agreement with Frayme, incorporating the EU Standard Contractual Clauses (Modules 1 to 3 as applicable) and, for UK transfers, the ICO International Data Transfer Addendum
3Vercel (Vercel, Inc., United States)Application and API hosting (serverless functions); AI Gateway routing for the fallback pathRequest and response traffic passing through Vercel's serverless functions and, on the fallback path, through the AI Gateway to Anthropic. Frayme does not send request content to Vercel for storage and does not enable request or response logging in the AI Gateway. Vercel retains its own platform and function logs for the period stated in its documentation, typically one to seven days on Frayme's current plan, under Vercel's Data Processing AgreementUnited States (default region, Washington DC)Vercel's Data Processing Agreement, incorporating the EU Standard Contractual Clauses and the UK Addendum
4Anthropic (Anthropic, PBC, United States), engaged through the Vercel AI Gateway as Vercel's sub-processorFallback model inference: used only when the primary model's output fails validationPrompt and DATA block content, fallback requests onlyUnited StatesVercel's Data Processing Agreement (EU Standard Contractual Clauses and the UK Addendum) with onward-transfer flow-down to Anthropic; EU-US Data Privacy Framework and UK Extension where Anthropic is certified

Table 2: Other service providers, for which Frayme is a controller

These providers handle Frayme's own account, workspace, billing, sign-in, email and operational-metadata. They are described here for transparency. The processing listed in this table does not involve Request Content and is not processing of Customer Personal Data under this DPA, so clause 6 and Annex III of the SCCs do not attach to it; it is described in the Privacy Policy. Supabase and Vercel also appear in Table 1, for the different processing described there.

#ProviderPurposeData receivedRegionTransfer safeguard
1Supabase (Supabase Pte. Ltd; production database hosted on AWS eu-central-1, Frankfurt)Authentication; account and workspace records; hashed API keys; usage and billing countersSign-up details, workspace records, hashed API keys, usage countersEuropean Union (Frankfurt)Stored and processed in EU data centres; EU Standard Contractual Clauses and the UK Addendum in Supabase's data processing agreement cover any remote access from outside the UK or EEA
2Langfuse Cloud (Finto Technologies GmbH, Germany)Operational tracing, debugging and per-request cost attributionMetadata only: timings, token counts, cost, model name, validation outcome and failure category, linked to workspace and API-key identifiers. No prompt, no DATA block and no model output is sent to LangfuseEuropean Union (Langfuse Cloud EU region, Ireland)Processed and stored in EU data centres by an EU-established provider; no restricted transfer
3Vercel (Vercel, Inc., United States)Website and dashboard hosting; Vercel Web Analytics: cookieless page-view counts for frayme.ai and app.frayme.aiPage URL, referrer, coarse device and browser information, and a short-lived pseudonymous visitor code that Vercel derives server-side from the incoming request and resets daily. Only totals are kept, and Frayme stores none of the underlying dataUnited States (default region)Vercel's Data Processing Agreement, incorporating the EU Standard Contractual Clauses and the UK Addendum
4Stripe (Stripe, Inc., United States)Subscription billingBilling contact and payment metadata; card details never reach FraymeUnited States and European UnionEU Standard Contractual Clauses and the UK Addendum in Stripe's data processing agreement; EU-US Data Privacy Framework and UK Extension where the recipient is certified
5Google (Google Ireland Limited for users in the EEA and the UK; Google LLC, United States)Optional "Sign in with Google": Google acts as an independent identity provider, not as Frayme's processorName, email address and Google account ID, sent by Google to Frayme when a user signs in; Frayme sends Google only the sign-in requestIreland and United StatesGoogle processes sign-in data as an independent controller under its own terms; EU-US Data Privacy Framework and UK Extension where the recipient is certified
6Resend (Resend, Inc., United States), used by Supabase Auth as its SMTP providerTransactional email: sign-up verification, magic links and password resets. Open and click tracking are switched offEmail address and message contentUnited StatesEU Standard Contractual Clauses and the UK Addendum in Resend's data processing agreement; EU-US Data Privacy Framework and UK Extension where the recipient is certified

Frayme has no relationship with OpenAI and sends no data to OpenAI. The @ai-sdk/openai-compatible package in Frayme's code is a protocol adapter for Frayme's own model, hosted by Modal, which exposes an OpenAI-shaped API; no OpenAI account, key or data flow exists. The explanation is repeated on the Sub-processor List.


Questions about this DPA: support@frayme.ai · Frayme Ltd, 15 Carraway Street, Reading, England, RG1 3GB · EU representative under Article 27 EU GDPR: DPO Europe GmbH, Auguste-Viktoria-Allee 20A, 13403 Berlin, Germany, representative@data-privacy-office.eu

Related documents: Terms of Service · Acceptable Use Policy · Privacy Policy · Sub-processor List · Security · IP and Content Complaints