Version 1.0 — effective 8 September 2026.
This Data Processing Agreement (the DPA) forms part of the agreement between Fratera s.r.o., Revoluční 28, 110 00 Prague 1, Czech Republic, registration CZ29845904, DUNS 351786366 (Fratera) and the customer identified in an Order Form or other agreement that incorporates this DPA (Customer). Fratera is represented for DPA and data-protection matters by Jan Frater. This DPA applies when Fratera Processes Customer Personal Data to provide the Services.
This is one global DPA. Sections 1-14 and Annexes 1-3 apply generally. Annex 4A adds European terms; Annex 4B adds United States terms. A jurisdictional annex applies only to the extent that its Applicable Data Protection Law applies. The annexes explain differences without duplicating the common terms.
1. Definitions
1.1 Affiliate means an entity that controls, is controlled by, or is under common control with a party.
1.2 Applicable Data Protection Law means any law governing the Processing of Customer Personal Data that applies to a party in its role under this DPA, including, where applicable: (a) the GDPR and national laws implementing or supplementing it; (b) the UK GDPR and the UK Data Protection Act 2018; (c) the Swiss Federal Act on Data Protection; and (d) United States state privacy laws identified in Annex 4B.
1.3 Customer Data means data submitted to or collected through the Services by or for Customer, including contracts, documents, vendor records, workflow data and account content.
1.4 Customer Personal Data means Personal Data contained in Customer Data that Fratera Processes on Customer's behalf. It does not include personal data for which Fratera determines the purposes and means of Processing, such as its own business-contact, billing, security and legal-compliance data, which is governed by Fratera's Privacy Policy.
1.5 Data Breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data Processed by Fratera. It does not include unsuccessful attempts or events that do not compromise Customer Personal Data.
1.6 Data Protection Law Terms means Controller, Processor, Data Subject, Personal Data, Process/Processing, Supervisory Authority, Business, Consumer, Contractor, Service Provider, Sale, Share, Targeted Advertising and similar terms. They have the meanings given by the Applicable Data Protection Law. If a law uses different terminology, the closest equivalent applies.
1.7 Documented Instructions means the Agreement, this DPA, Customer's configuration and authorised use of the Services, and additional written instructions that are consistent with the Agreement.
1.8 GDPR means Regulation (EU) 2016/679. UK GDPR has the meaning given in section 3(10), as supplemented by section 205(4), of the UK Data Protection Act 2018.
1.9 Order Form means an ordering document, statement of work or accepted subscription order describing the Services purchased by Customer.
1.10 Services means Fratera's contract lifecycle and supplier relationship management services described in the Agreement or Order Form.
1.11 Standard Contractual Clauses or EU SCCs means the clauses in the Annex to Commission Implementing Decision (EU) 2021/914, as amended or replaced in accordance with law.
1.12 Subprocessor means a third party engaged by Fratera to Process Customer Personal Data on Customer's behalf. It excludes Fratera personnel and third parties that Process personal data solely for their own purposes as independent Controllers.
2. Scope and roles
2.1 Customer appoints Fratera to Process Customer Personal Data to provide, secure, support and maintain the Services and as otherwise described in Annex 1. Fratera accepts the appointment.
2.2 As between the parties, Customer is the Controller or Business and Fratera is the Processor, Service Provider or Contractor. If Customer Processes Customer Personal Data for another Controller, Customer is a Processor and Fratera is its Subprocessor.
2.3 Customer is responsible for: (a) the lawfulness, fairness and transparency of its Processing; (b) providing required notices and obtaining required consents or other lawful bases; (c) the accuracy and quality of Customer Personal Data; (d) issuing lawful instructions; and (e) deciding which people may access or submit data to the Services.
2.4 Fratera is an independent Controller for personal data it Processes for its own account administration, billing, fraud prevention, security, service communications, legal compliance and business relationship management. Fratera will not treat Customer content as its own Controller data merely because it is necessary to operate or secure the Services.
3. Instructions and permitted Processing
3.1 Fratera will Process Customer Personal Data only on Documented Instructions, including transfers of Personal Data, unless applicable law requires otherwise. If law requires Processing not instructed by Customer, Fratera will inform Customer before Processing unless the law prohibits notice on important grounds of public interest.
3.2 Fratera will promptly inform Customer if, in its reasonable opinion, an instruction infringes Applicable Data Protection Law. Fratera may suspend the affected Processing until the parties resolve the issue.
3.3 Fratera will not use Customer Personal Data for advertising, profiling unrelated to the Services, data brokerage, or training general-purpose or third-party machine-learning models. AI features are assistive: model output does not grant access, make authorisation decisions, or independently change Customer records, commercial amounts or dates. Customer may disable AI document processing where the Service configuration permits.
3.4 Customer authorises Fratera to create service telemetry that does not identify a natural person or Customer and cannot reasonably be re-associated with Customer Personal Data. Fratera may use that telemetry to operate, secure and improve the Services. This permission does not authorise use of contract text, document content or identifiable Customer records for model training or unrelated product development.
4. Confidentiality and personnel
4.1 Fratera will ensure that persons authorised to Process Customer Personal Data are bound by confidentiality obligations or an appropriate statutory duty of confidentiality and receive access only as necessary for their duties.
4.2 Fratera will provide appropriate privacy and security instructions to authorised personnel and will remain responsible for their compliance with this DPA.
5. Security
5.1 Taking into account the state of the art, implementation costs, the nature, scope, context and purposes of Processing, and risks to individuals, Fratera will implement and maintain appropriate technical and organisational measures. The current measures are described in Annex 2.
5.2 Fratera may update the measures to reflect technical progress, provided that the overall level of protection is not materially reduced. Fratera does not represent that any system is completely secure.
5.3 Customer is responsible for securely configuring its tenant, assigning appropriate roles and visibility groups, maintaining authorised-user lists, protecting credentials, using available authentication controls, and promptly notifying Fratera of suspected account compromise.
6. Data Breaches
6.1 Fratera will notify Customer without undue delay after becoming aware of a Data Breach. Notice will be sent to Customer's designated privacy or security contact, or otherwise to its account administrator.
6.2 To the extent known and reasonably available, Fratera will provide: (a) the nature of the Data Breach; (b) categories and approximate numbers of affected individuals and records; (c) likely consequences; (d) measures taken or proposed to address and mitigate it; and (e) a contact for follow-up. Fratera may provide information in phases.
6.3 Fratera will take reasonable steps to contain, investigate and remediate the Data Breach and will reasonably assist Customer with legally required notifications. Fratera's notice is not an admission of fault or liability.
6.4 Customer is responsible for determining whether to notify individuals, regulators or other parties, unless Applicable Data Protection Law assigns that obligation directly to Fratera.
7. Data Subject and Consumer requests
7.1 Taking into account the nature of Processing, Fratera will provide reasonable assistance, through Service functionality or otherwise, for Customer to respond to requests to access, know, correct, delete, restrict, object, opt out or receive a portable copy of Customer Personal Data.
7.2 If Fratera receives a request relating to Customer Personal Data directly from an individual, Fratera will, where legally permitted, direct the individual to Customer or promptly forward the request. Fratera will not respond substantively except on Customer's Documented Instructions or as required by law.
7.3 Customer will reimburse reasonable costs for assistance that is unusually burdensome or outside normal Service functionality, except to the extent the assistance is required because Fratera breached this DPA.
8. Regulatory assistance
8.1 Taking into account the nature of Processing and information available to it, Fratera will reasonably assist Customer with: (a) security-of-processing obligations; (b) Data Breach assessments and notifications; (c) data protection impact assessments or comparable state risk assessments; and (d) prior consultation with a Supervisory Authority.
8.2 Fratera will provide information reasonably necessary to demonstrate compliance with this DPA and will cooperate with competent regulators as required by Applicable Data Protection Law.
9. Subprocessors
9.1 Customer gives Fratera general written authorisation to use the Subprocessors listed in Annex 3 and to appoint replacements or additional Subprocessors under this section.
9.2 Fratera will provide at least 30 days' prior notice of a new Subprocessor that will Process Customer Personal Data. Notice may be provided through a maintained subprocessor page, email or an in-product notice. Customer must keep its notice contact current.
9.3 Customer may object during the notice period on reasonable, documented data-protection grounds. The parties will work in good faith to address the objection, including by making a commercially reasonable configuration change where available. If no reasonable solution is available, Customer may terminate only the affected Service by written notice before the Subprocessor begins Processing and receive a pro-rata refund of prepaid fees for the terminated post-effective period. This is Customer's sole remedy for a reasonable Subprocessor objection.
9.4 Fratera will enter into a written agreement with each Subprocessor that imposes data-protection obligations that are no less protective, in substance, than those applicable to Fratera under this DPA for the relevant Processing. Fratera remains responsible for its Subprocessors' performance to the extent required by Applicable Data Protection Law.
9.5 Fratera will ensure that any restricted international transfer to a Subprocessor uses a lawful transfer mechanism and, where required, supplementary measures and a transfer assessment. Fratera will not claim participation in an adequacy or certification framework unless the relevant entity is actively listed or otherwise eligible.
10. Location and international transfers
10.1 Customer selects a deployment region in its Order Form or onboarding instructions. The selected region is a binding instruction for the Customer tenant. Fratera will deploy the Customer database, storage and regional application processing for that region and configure region-bound AI and transactional-email services where available, as described in Annex 3.
10.2 Fratera will not change Customer's selected region without Customer's written instruction, except for temporary emergency processing that is necessary to protect the Services or Customer Personal Data and is permitted by law and the Agreement. Any planned interim or cross-region application processing must be expressly disclosed in the Order Form or other written instruction.
10.3 If a transfer between the parties is a restricted transfer under European Data Protection Law and no adequacy decision or other lawful mechanism applies, Annex 4A incorporates the appropriate EU SCC module and, for UK transfers, the UK Addendum. If Fratera, rather than Customer, exports Customer Personal Data to a third-country Subprocessor, Fratera will enter into the appropriate transfer instrument with that Subprocessor; the parties will not mischaracterise Customer as exporter for that separate transfer.
11. Return, export and deletion
11.1 During the subscription, users may export records and documents they are authorised to access. On Customer's written request, Fratera will provide a full-tenant export using elevated operational access from Customer's selected region in a commonly usable format, subject to identity and authority verification. The production format and turnaround will be stated in the Order Form or support documentation.
11.2 At the end of the Services, Customer may instruct Fratera to return or delete Customer Personal Data. Unless the Agreement states otherwise, Customer must request an export before termination or during the agreed post-termination retrieval period.
11.3 After the retrieval period, Fratera will delete the live Customer database and storage dedicated to Customer, except to the extent law requires retention. Data retained by law will remain protected and will not be Processed for another purpose.
11.4 Customer Personal Data in backups may remain until overwritten under Fratera's documented backup cycle. During that period it will be isolated from ordinary use and protected under this DPA; if restored, it will be deleted again unless needed for lawful disaster recovery. Fratera will propagate applicable deletion instructions to Subprocessors.
11.5 On request, Fratera will provide reasonable confirmation of completed live-system deletion. Any formal deletion certificate, retrieval period, deletion deadline and maximum backup tail are governed by the Order Form or applicable retention schedule.
12. Demonstrating compliance and audits
12.1 Fratera will make available information reasonably necessary to demonstrate compliance, beginning with current security documentation, architecture descriptions, policies, questionnaire responses and relevant independent reports that Fratera has available. Fratera does not represent that it holds a certification unless expressly stated in current documentation.
12.2 No more than once in any 12-month period, Customer may request a remote audit of Fratera's compliance with this DPA on at least 30 days' notice. The frequency and notice limits do not apply following a confirmed Data Breach affecting Customer Personal Data, a regulator's request, or reasonable evidence of material non-compliance.
12.3 An audit must: (a) be scoped to Customer Personal Data and controls relevant to the Services; (b) occur during normal business hours without unreasonably disrupting operations; (c) protect other customers' data, Fratera confidential information and system security; and (d) be performed by Customer or an independent auditor that is not a Fratera competitor and is bound by confidentiality.
12.4 Customer bears its audit costs and Fratera's reasonable costs for assistance beyond ordinary documentation, unless the audit identifies Fratera's material breach of this DPA. Nothing in this section limits a competent regulator's powers or a non-waivable inspection right.
13. Liability and precedence
13.1 Each party's liability arising from this DPA is subject to the exclusions and limitations in the Agreement, except to the extent prohibited by Applicable Data Protection Law or by the EU SCCs or UK Addendum.
13.2 If there is a conflict concerning the Processing of Customer Personal Data, the following order applies: (a) the EU SCCs or UK Addendum for a restricted transfer; (b) the applicable jurisdictional terms in Annex 4; (c) this DPA; and (d) the Agreement.
14. General
14.1 This DPA begins when Customer accepts the Agreement or an Order Form incorporating it and continues while Fratera Processes Customer Personal Data.
14.2 Amendments must be in writing, except that Fratera may update Annex 3 under section 9 and may update this DPA where reasonably necessary to comply with law, without materially reducing Customer's protection. Material changes will be notified in advance where practicable.
14.3 Governing law and venue are those in the Agreement, except where Annex 4 or a mandatory transfer instrument requires otherwise.
14.4 Electronic acceptance, an Order Form reference, or signature by authorised representatives is sufficient to bind the parties.
Annex 1 - Processing details
A. Subject matter and duration
Fratera Processes Customer Personal Data to provide, secure, support, maintain and improve the contracted operation of the Services. Processing continues for the subscription term and the limited export, retrieval, deletion and backup periods described in the Agreement and section 11.
B. Nature and purpose
The Processing may include collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure to authorised recipients, transmission to authorised Subprocessors, alignment, restriction, export, backup and deletion. Purposes are:
- contract and document storage and management;
- supplier and business-contact relationship management;
- user authentication, permissions and access control;
- workflows, approvals, reminders, notifications and audit trails;
- electronic-signature preparation, execution records and document sealing;
- customer-enabled AI-assisted document extraction, review and question answering with human verification;
- support, troubleshooting, security, continuity, export and deletion; and
- other activities initiated by authorised users within the documented Services.
C. Data subjects
- Customer employees, contractors, authorised users and administrators;
- Customer's suppliers, vendors, counterparties and their personnel;
- contract stakeholders, approvers, reviewers, delegates, witnesses and signatories;
- contacts whose details appear in contracts, attachments, communications or vendor records; and
- other individuals whose Personal Data Customer lawfully submits to the Services.
D. Categories of Personal Data
- identifiers and business contact details, such as name, employer, title, business email, business phone and signature;
- account and authentication data, including user identifier, role, group, login and security events;
- professional, organisational and relationship information;
- contract, vendor, procurement, approval, workflow and audit information;
- documents, attachments, messages, notes and other content selected by Customer;
- electronic-signature records, signing order, consent, timestamps and transaction evidence;
- device, browser, IP address and service-log data generated through authorised use; and
- support and configuration information.
E. Sensitive and special-category data
The Services are not designed for special-category data under GDPR, highly sensitive government identifiers, payment-card data, consumer health data, precise geolocation, biometric identification data, or children's data. Customer will not submit such data unless expressly agreed in an Order Form with appropriate safeguards. Incidental sensitive data embedded in a contract remains Customer Personal Data and is protected under this DPA.
F. Frequency
Continuous or intermittent, as initiated by Customer and its authorised users during the subscription and limited post-termination period.
G. Customer instructions for retention
Customer may configure available retention settings and issue deletion or legal-hold instructions consistent with the Agreement. The default retrieval period, live deletion deadline and maximum backup tail are governed by the Order Form or applicable retention schedule.
Annex 2 - Technical and organisational measures
Fratera's measures are proportionate to the Services and the risks known at the effective date. They include:
1. Tenant and storage isolation
- a separate PostgreSQL database and storage environment for each Customer tenant;
- region selected and locked at provisioning;
- regional application services designed to keep Customer processing in the selected region; and
- a global control plane limited to routing, provisioning and credentials, not Customer contract content.
2. Access control
- database row-level security enabled and default-deny across application tables;
- authorisation evaluated inside the Customer database for application and direct API access;
- role-, permission- and restricted-visibility controls;
- multi-step privileged operations that re-check permissions;
- no service-role credential in the browser or ordinary user-facing web tier; and
- controls intended to prevent removal of a tenant's last technical administrator.
3. Authentication and credential security
- individual user accounts and session controls;
- server-enforced password controls and available single sign-on features according to the subscribed edition;
- secret values kept in restricted secrets storage and not committed to source code or exposed to the client; and
- least-privilege access and credential rotation procedures appropriate to the credential.
4. Encryption and transport
- encryption at rest provided by the regional database, storage and hosting platforms;
- TLS-protected network communications for the web application, APIs and vendor connections; and
- protected database connections and controlled storage access.
5. Logging and integrity
- append-oriented audit records for key approval, access and record changes;
- database-guarded contract lifecycle transitions;
- verification of tenant routing rather than reliance on a customer-supplied database identifier; and
- controls against unauthorised code execution and exposure of privileged credentials.
6. Availability, backup and recovery
- per-tenant backups and platform recovery capabilities according to the subscribed infrastructure plan;
- regional deployment and operational recovery procedures;
- dedicated Customer silos that can be restored or deleted independently; and
- documented continuity and offboarding procedures, subject to the applicable recovery and retention schedule.
7. AI controls
- region-bound AI endpoints where the AI feature is enabled;
- Customer content not used to train general-purpose or third-party models by Fratera;
- AI output excluded from authorisation and other critical access decisions;
- human review before extracted values or suggested changes become authoritative; and
- contract-question access bounded to documents the requesting user is already authorised to view.
8. Organisational controls
- confidentiality obligations for authorised personnel;
- controlled production access based on operational need;
- security and privacy review of material system changes;
- vulnerability and dependency management appropriate to the service stage; and
- incident investigation, communication and remediation procedures.
Fratera does not claim ISO 27001, SOC 2, a completed independent penetration test, or 24/7 security monitoring unless a then-current written statement expressly confirms it.
Annex 3 - Authorised Subprocessors
The following Subprocessors are authorised for the specified limited purposes. The applicable contracting entity and processing location depend on the Customer's selected region and configuration.
| Subprocessor | Purpose | Customer data involved | Location / transfer note |
|---|---|---|---|
| Hostinger | Regional application hosting, network and related infrastructure | Customer Personal Data processed transiently by the regional app tier; encrypted service traffic and operational logs | Regional infrastructure selected for Customer; provider support and operations may Process data as described for the applicable service. |
| Supabase | Per-tenant PostgreSQL database, authentication, document storage, backups and platform services | Customer content, account data, files, database records and security logs | Customer-selected EU or US project region and its relevant underlying infrastructure. |
| Mistral AI | Customer-enabled AI document extraction, OCR, contract analysis and bounded question answering | Selected document content and prompts/outputs necessary for the requested AI feature | Region-bound EU or US endpoint where supported. AI may be disabled per tenant. Restricted transfers are governed by section 10 and Annex 4A. |
| Resend | Transactional email, invitations, reminders, notifications and signature links | Recipient name/email, message metadata and limited notification content | Regional sending configuration where supported. Restricted transfers are governed by section 10 and Annex 4A. |
Not Subprocessors: FrateraSign and Gotenberg are self-hosted software components operated within Fratera's regional infrastructure; they are not third-party processors merely because Fratera uses their software.
Annex 4A - European terms
1. Application
This Annex applies to Customer Personal Data subject to the GDPR, UK GDPR or Swiss Federal Act on Data Protection (European Data Protection Law).
2. Article 28 terms
The parties intend sections 1-14 and Annexes 1-3 to satisfy Article 28(3)-(4) GDPR and the corresponding UK and Swiss requirements. The parties will interpret them consistently with European Data Protection Law. Fratera will immediately inform Customer if it believes it can no longer comply and will take reasonable and appropriate steps to remediate.
3. Restricted transfers between Customer and Fratera
3.1 The EU SCCs are incorporated by reference only when a transfer of Customer Personal Data between Customer and Fratera is a restricted transfer and no adequacy decision or other lawful mechanism applies.
3.2 Module selection. Module Two applies where Customer is a Controller and Fratera is a Processor. Module Three applies where Customer is a Processor and Fratera is a Subprocessor.
3.3 Selections. Clause 7 (docking) applies. In Clause 9, Option 2 (general written authorisation) applies with the 30-day notice period in section 9. In Clause 11, the optional independent dispute-resolution language does not apply. For Modules Two and Three, the optional wording in Clause 13(a) applies where the data exporter is established outside the EEA but subject to GDPR and has appointed a representative.
3.4 Clause 17 and 18. Option 1 applies. The law of the Czech Republic governs the EU SCCs, and the courts of Prague, Czech Republic are the forum, unless the EU SCCs require another EU Member State law or court in the circumstances.
3.5 Appendix completion. Customer is the data exporter and Fratera is the data importer; their identities and contacts are those in the Agreement and Order Form. Annex 1 of this DPA completes Annex I.B of the EU SCCs; Customer's competent Supervisory Authority under GDPR completes Annex I.C; Annex 2 completes Annex II; and Annex 3 completes Annex III.
3.6 The parties will not modify the EU SCCs except by choosing permitted modules/options and completing or updating the Appendix. The EU SCCs prevail over conflicting terms.
4. Fratera-to-Subprocessor transfers
Where Fratera exports Customer Personal Data to a Subprocessor in a country without an applicable adequacy decision, Fratera will use the appropriate EU SCC module or another lawful mechanism and will complete any required transfer assessment and supplementary measures. Customer authorises Fratera to act as exporter for that onward transfer. Fratera will provide relevant information about the mechanism on reasonable request, subject to confidentiality.
5. Transfer assessments and public-authority requests
Fratera will assess, as required by law, whether the laws and practices of a destination country affect the effectiveness of the selected safeguards, document that assessment, implement supplementary measures where necessary, and suspend an affected transfer if an essentially equivalent level of protection cannot be maintained. To the extent legally permitted, Fratera will notify Customer of binding public-authority requests for Customer Personal Data and will review and challenge unlawful or disproportionate requests.
6. United Kingdom
For a UK restricted transfer relying on the EU SCCs, the parties incorporate the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, version B1.0, in force 21 March 2022, as revised under its mandatory clauses (UK Addendum).
- Table 1 is completed by the parties' details in the Agreement and Order Form.
- Table 2 selects the EU SCC module and options in section 3 of this Annex.
- Table 3 is completed by Annexes 1-3 of this DPA.
- Table 4 permits either party to end the UK Addendum as provided by its mandatory clauses.
- Part 2 Mandatory Clauses are incorporated using the ICO-approved alternative incorporation wording and prevail over conflicting terms.
The parties will complete any required UK transfer risk assessment. EU SCCs alone are not treated as a UK transfer mechanism.
7. Switzerland
For Swiss Personal Data, references in the EU SCCs to GDPR include the Swiss Federal Act on Data Protection where applicable; the competent authority is the Swiss Federal Data Protection and Information Commissioner; references to EU Member States are read to include Switzerland where required; and data subjects in Switzerland may exercise rights under the clauses. The parties will make any further adaptations required by Swiss law without reducing protection.
Annex 4B - United States state privacy terms
1. Application and roles
This Annex applies only to Customer Personal Data governed by a United States state comprehensive privacy law that requires a contract between a Business/Controller and its Service Provider/Contractor/Processor (US State Privacy Law). For that data, Customer is the Business or Controller and Fratera is the Service Provider, Contractor or Processor. These statutory roles do not change the parties' roles for other data.
2. Limited and specific business purposes
Fratera will Process covered Customer Personal Data only for the following limited and specific purposes, as applicable to Customer's order and configuration:
- hosting Customer's isolated database, files and tenant application;
- authenticating authorised users and enforcing Customer-configured permissions;
- storing, organising, retrieving and exporting contracts, supplier records and documents;
- operating approvals, reminders, notifications, audit logs and electronic-signature workflows;
- performing Customer-enabled AI document extraction or analysis;
- providing support, troubleshooting, security, backup, recovery and deletion; and
- complying with Customer's lawful, documented instructions.
A generic reference to the Agreement does not expand these purposes.
3. California restrictions
To the extent the California Consumer Privacy Act, as amended (CCPA), applies, Fratera will:
3.1 not Sell or Share covered Customer Personal Data;
3.2 not retain, use or disclose it outside the direct business relationship with Customer or for a commercial purpose other than the limited and specific purposes in section 2, except as permitted by the CCPA;
3.3 not combine it with Personal Information received from or on behalf of another person, or collected from Fratera's own interaction with an individual, except as permitted by the CCPA;
3.4 provide the same level of privacy protection required of Customer for the covered data;
3.5 notify Customer without undue delay if Fratera determines that it can no longer meet its obligations under the CCPA;
3.6 permit Customer, on reasonable notice, to take reasonable and appropriate steps to verify that Fratera uses the data consistently with Customer's CCPA obligations, including the compliance and audit measures in section 12;
3.7 cooperate with reasonable steps requested by Customer to stop and remediate unauthorised Processing; and
3.8 require each Subprocessor Processing the covered data to comply with equivalent restrictions.
4. Other state processor duties
Where required by US State Privacy Law, Fratera will:
- follow Customer's instructions and assist Customer in meeting its duties;
- ensure each person Processing the data is subject to confidentiality;
- provide reasonable security appropriate to the nature of the data;
- assist with Consumer rights requests and appeals, including access, correction, deletion, portability, opt-out and sensitive-data requests;
- assist with required data-protection or risk assessments;
- make information available to demonstrate compliance;
- engage Subprocessors under written contracts with equivalent obligations; and
- return or delete data at Customer's direction as described in section 11.
5. No targeted advertising or qualifying profiling
Fratera will not use Customer Personal Data for cross-context behavioural advertising, Targeted Advertising, Sale, Share or profiling in furtherance of decisions producing legal or similarly significant effects, except on Customer's express Documented Instructions where lawful and expressly covered by the Services.
6. Consumer requests and deletion
Fratera will provide self-service tools where available and otherwise reasonable assistance for verified Consumer requests. Deletion from archival backups may be delayed until the backup is restored or accessed under the documented backup cycle, provided the data is not used for another purpose and is deleted if restored. Fratera may retain a minimal suppression record solely to document and maintain a deletion request where permitted by law.
7. State-law priority
If this Annex conflicts with a mandatory US State Privacy Law requirement, that requirement controls only for the covered Processing. The rest of the DPA remains effective.
Acceptance
The parties may accept this DPA through an Order Form, electronic acceptance, or signatures below.
| FRATERA S.R.O. | CUSTOMER |
|---|---|
| Name: Jan Frater | Legal name: _________________________ |
| Title: Principal / data-protection representative | Name: ______________________________ |
| Date: ________________________________ | Title: _______________________________ |
| Signature: ____________________________ | Date: ________________________________ |
| Signature: ___________________________ |