Legal

Data Processing Addendum

How we process personal data on your behalf when you use Frontminder.

No developer needed Free trial: 100 messages

Last updated: September 11, 2026

This Data Processing Addendum ("DPA") describes how Frontminder, operated by an independent individual (a sole operator, not an incorporated business), processes personal data on behalf of a customer ("Customer") when the Customer uses the Service. It supplements our Terms of Service and Privacy Policy. Where the Customer is subject to a data-protection law that requires a written data-processing agreement, this DPA (once executed) is intended to satisfy that requirement.

Roles of the parties

For personal data contained in Customer Content — including the conversations and leads captured by the Customer’s agents and the knowledge-base content the Customer uploads — the Customer is the controller and Frontminder is the processor. Frontminder processes that data only on the Customer’s documented instructions, which include the configuration choices made in the Service and these terms. For account and billing data about the Customer itself, Frontminder acts as a controller under its Privacy Policy.

Scope and purpose of processing

Frontminder’s obligations

Frontminder will: (a) process personal data only on the Customer’s instructions; (b) ensure personnel with access are bound by confidentiality; (c) implement appropriate technical and organizational security measures (see below); (d) assist the Customer, taking into account the nature of processing, with data-subject requests and with security, breach-notification, and impact-assessment obligations; (e) notify the Customer without undue delay after becoming aware of a personal-data breach; and (f) at the Customer’s choice, delete or return personal data at the end of the engagement, subject to legal retention.

Security

Frontminder maintains measures designed to protect personal data, including encryption in transit, hashed credentials, access controls, logging, and separation of tenant data. These controls may be updated to maintain or improve protection.

Sub-processors

The Customer authorizes Frontminder to engage the sub-processors listed at Sub-processors to process personal data. Frontminder imposes data-protection obligations on each sub-processor and remains responsible for their performance. Frontminder will update that page before adding or replacing a sub-processor, and the Customer may object on reasonable data-protection grounds; if the objection cannot be resolved, the Customer may discontinue the affected feature.

International transfers

Some sub-processors may process personal data in a country other than the Customer’s own. Where a transfer requires a lawful mechanism, Frontminder will rely on an appropriate safeguard, such as standard contractual clauses or an approved transfer framework.

Data-subject requests

Because the Customer is the controller of end-user data, requests from end users to access, correct, or delete their data should be directed to the Customer. Frontminder will provide reasonable assistance, including tools within the Service to locate, export, and delete conversations and leads.

Retention and deletion

Frontminder retains Customer Content for the duration of the subscription and deletes or de-identifies it within a commercially reasonable period afterward, unless a longer period is required by law. The Customer can delete content from within the Service at any time.

Liability and precedence

This DPA is subject to the limitations of liability in the Terms of Service. If there is a conflict between this DPA and the Terms regarding the processing of personal data, this DPA controls for that subject.

How to execute

A countersigned copy of the full DPA is available on request. Contact support@frontminder.com to request one or to ask a question about our data-processing practices.

Create an AI agent in 15 minutes

Free trial: 100 messages. No code, no card. Website chat first, more channels at launch.