Skip to main content
Fratera Procurement SolutionsFratera Procurement Solutions
Home Product Pricing Security About Partners Blog
Get in touch
Home Product Pricing Security About Partners Blog Get in touch

Privacy Policy

On this page

  • 1. Who we are and how to contact us
  • 2. Scope and our role
  • 3. Personal data we collect
  • 4. Why we use personal data
  • 5. How we disclose personal data
  • 6. Cookies and similar storage
  • 7. International transfers and data regions
  • 8. Retention
  • 9. Security
  • 10. Your rights
  • 11. Global Privacy Control and Do Not Track
  • 12. Children
  • 13. Marketing communications
  • 14. Changes to this Policy
  • 15. Contact

Version 1.0 — effective 8 September 2026.

This Privacy Policy explains how Fratera s.r.o. (Fratera, we, us) handles personal data when you visit fratera.io, contact us, participate in our partner programme, create or administer a Fratera account, or otherwise interact with us in a business capacity.

1. Who we are and how to contact us

Fratera s.r.o. is a company based in Prague, Czech Republic. For privacy questions or to exercise a right, contact:

  • Email: info@fratera.io
  • Postal address: Revoluční 28, 110 00 Prague 1, Czech Republic
  • Registration: CZ29845904
  • DUNS: 351786366
  • Principal and data-protection representative: Jan Frater

Jan Frater is Fratera's designated contact and representative for DPA and data-protection matters. Where a formally appointed Data Protection Officer or an EU, UK or other statutory representative is legally required, the applicable appointment and contact details will be published here.

2. Scope and our role

2.1 Data we control

Fratera is the Controller or Business for personal data used for its own website, sales, partner, account administration, billing, support, security, service communications, legal compliance and business operations.

2.2 Customer-controlled content

When a Fratera business customer uploads contracts, supplier contacts, employee information or other content to its tenant, the customer normally determines why and how that information is used. Fratera Processes it as the customer's Processor, Service Provider or Contractor under our Data Processing Agreement.

If your information appears in a customer's Fratera tenant, please direct your request to that customer first. We will assist the customer as required by law and our DPA. We will not disclose customer-controlled content without appropriate authorisation.

2.3 Third-party sites

This Policy does not govern websites, products or services operated independently by third parties, even if we link to them. Their notices apply to their Processing.

3. Personal data we collect

We collect only the data relevant to the interaction.

3.1 Website and enquiry data

  • name, business email, company and role;
  • the product, partnership or other topic you select;
  • your message and any information you choose to include;
  • referral information submitted through our partner page, including the referred company or contact; and
  • campaign parameters present in a link, if any. The current website preserves these parameters in links but does not use active analytics.

3.2 Account and business-relationship data

  • name, business contact details, employer and role;
  • workspace, plan, region, user role and account-administration details;
  • authentication and sign-in information managed through our authentication provider;
  • customer billing, technical, privacy and commercial contacts;
  • subscription, invoice, payment-status and tax information; and
  • communications, support requests, demonstrations, feedback and meeting notes.

Payment-card information, where accepted, is handled directly by the payment provider and is not intended to be stored by Fratera.

3.3 Service-use and security data

  • IP address, browser and device information;
  • sign-in events, session identifiers, timestamps and security events;
  • feature configuration, user permissions and operational logs;
  • support diagnostics and actions taken in the Service; and
  • essential authentication cookies and local or session storage used for sign-in, security, display preferences and navigation.

3.4 Customer-controlled content

Depending on a customer's use, its tenant may contain:

  • employee, contractor, supplier and counterparty contact details;
  • contracts, attachments, notes, messages and vendor records;
  • professional roles, approvals, delegation and audit information;
  • electronic-signature recipient details, consent, timestamps, IP/user-agent evidence and signature images;
  • financial and commercial terms contained in contracts; and
  • AI prompts, extracted text and suggested outputs when the customer enables AI features.

The Service is not designed for special-category data, highly sensitive government identifiers, payment-card data, consumer health data, biometric identification data or children's data. Uploaded documents are unstructured, so customers must decide whether it is lawful and necessary to include any sensitive information.

3.5 Sources

We obtain data:

  • directly from you;
  • from your employer or the organisation administering your account;
  • from a partner or other business contact who refers you;
  • automatically from your browser, device and use of the website or Service;
  • from integrations or services you authorise;
  • from publicly available business sources where appropriate; and
  • from service providers acting for us.

If someone refers you, we will use the information to assess and make the requested business contact. Referrers must have a reasonable basis to share your business details. We will provide this Policy at or before our first communication where required.

4. Why we use personal data

PurposeTypical dataGDPR/UK lawful basis
Respond to enquiries, arrange demos and manage prospectsContact, company, interest and messageLegitimate interests in responding to business enquiries; steps requested before a contract
Operate partner referralsReferrer and referred business-contact data, communicationsLegitimate interests in developing business relationships and administering the programme; contract where the partner agreement applies
Create and administer accounts and provide the ServiceAccount, workspace, authentication, configuration and support dataPerformance of the customer agreement; legitimate interests in administering business users
Bill and manage the commercial relationshipBilling contacts, plan, invoices, tax and payment statusContract; legal obligations; legitimate interests in financial administration
Send transactional and service communicationsName, email, account and event metadataContract; legitimate interests in operating and securing the Service
Provide support and improve reliabilityCommunications, diagnostics and operational telemetryContract; legitimate interests in support, reliability and product improvement
Protect the website, Service, customers and FrateraIP/device, authentication, audit, security and fraud signalsLegitimate interests in security and fraud prevention; legal obligations
Comply with law and establish, exercise or defend claimsRelevant account, transaction, communication and log dataLegal obligation; legitimate interests in legal protection
Send business marketing where permittedBusiness contact, company, preferences and interactionsConsent where required; otherwise legitimate interests in relevant B2B marketing

Where we rely on legitimate interests, we consider whether our purpose is necessary and whether your rights override it. You may object as described below. Where we rely on consent, you may withdraw it at any time without affecting earlier lawful Processing.

We do not use Customer content to train general-purpose or third-party AI models. We do not make decisions producing legal or similarly significant effects about website visitors or account users solely by automated means.

5. How we disclose personal data

We disclose data only as reasonably necessary:

5.1 Service subprocessors

For customer-controlled Service data, our authorised subprocessors are:

  • Hostinger - regional application hosting and network infrastructure;
  • Supabase - per-customer database, authentication, storage, backup and platform services;
  • Mistral AI - customer-enabled AI document extraction and analysis through a region-bound endpoint where supported; and
  • Resend - transactional email, invitations, reminders and signature links.

FrateraSign and Gotenberg are self-hosted software components and are not separate third-party subprocessors.

5.2 Website-only providers

  • Hostinger hosts the marketing website and may Process ordinary web-server request and security logs.
  • FormSubmit.co currently receives contact and partner form fields so they can be delivered to info@fratera.io. It is a website-only provider and does not Process Fratera customer tenant data for the Service.
  • Google Fonts is loaded from Google servers. A visitor's IP address and request metadata are therefore sent to Google to deliver font files.

5.3 Transactions completed through Paddle

If Paddle is identified at checkout, Paddle acts as merchant of record and authorised reseller for the transaction. The buyer purchases through the relevant Paddle entity, and Paddle independently determines how it Processes payment, billing, tax, fraud-prevention, refund and transaction-support data as a Controller. Paddle may collect the buyer's name, business and billing details, payment information, tax information, IP/device data and transaction history directly through its checkout or invoicing flow. Paddle's Buyer Terms and Privacy Notice apply to that Processing.

Fratera receives from Paddle the transaction and entitlement information reasonably necessary to provision and administer the subscription, reconcile payments, provide support and meet accounting and legal duties. Fratera does not intend to receive full payment-card details. Paddle is not a Subprocessor for customer-controlled tenant data merely because it completes a purchase; if the implementation later sends Paddle such data for Processing on Fratera's behalf, the DPA and public Subprocessor list must be updated before that Processing begins.

5.4 Other recipients

We may disclose relevant data to:

  • professional advisers, auditors, insurers and financing or corporate-transaction counterparties under confidentiality;
  • competent courts, regulators, public authorities or law enforcement where legally required; and
  • a successor in a merger, acquisition, reorganisation or sale, subject to appropriate safeguards.

We do not sell personal data for money. We do not share it for cross-context behavioural advertising and do not use it for targeted advertising. We have not knowingly sold or shared personal data of people under 16 in the preceding 12 months.

6. Cookies and similar storage

6.1 Marketing website

The website does not activate analytics or advertising cookies. It does not use tracking pixels or behavioural advertising. It may receive campaign parameters in a URL and preserve them in links without storing them.

If a deployed version stores a local preference solely to dismiss a notice, that storage, its purpose and duration will be stated here. A consent banner is not a substitute for accurate disclosure and will not be used to imply that tracking occurs where it does not.

6.2 Fratera Service

The Service uses essential authentication cookies and browser storage to keep users signed in, protect the session, support single sign-on, remember display/edit preferences and preserve navigation state. These items are necessary for or requested through the Service and are not used for advertising.

If we later add optional analytics or marketing technology, we will update this Policy and, where required, ask for prior, granular consent with an equally accessible rejection and withdrawal mechanism.

7. International transfers and data regions

Customers select an EU or US deployment region when the tenant is created. Fratera is designed to place the customer database, storage and regional application Processing in that selected region and to bind AI and transactional-email configuration to it where supported. The Order Form and DPA control any specific residency commitment.

Fratera is established in the Czech Republic. Some providers or their support functions may be located outside the EEA, United Kingdom or Switzerland. Where a restricted transfer occurs, we use a lawful mechanism such as an adequacy decision, the European Commission's Standard Contractual Clauses, the UK Addendum, or another permitted safeguard. We assess supplementary measures where required. You may request information about the relevant safeguard by contacting us.

We do not claim that a provider participates in the EU-US Data Privacy Framework or UK Extension unless its relevant legal entity is actively certified.

8. Retention

We keep personal data only for as long as needed for the purpose, including security, dispute and legal-retention needs. The applicable retention criteria are:

DataRetention / criterion
Website enquiries and ordinary prospect communicationsUp to 24 months after the last meaningful interaction, unless a relationship continues or earlier deletion is appropriate
Unsuccessful partner referralsUp to 12 months after the referral closes, subject to objection or deletion rights
Customer business contacts and account recordsDuring the customer relationship and then up to 12 months after decommissioning for direct operational contacts; limited contract, invoice and legal records longer where required by law
Marketing preferences and suppression recordsUntil opt-out, then a minimal suppression record for as long as needed to honour the choice
Website server/security logsHostinger's documented operational retention period, extended where reasonably necessary to investigate an incident or comply with law
Service authentication, audit and security logsFor the period configured for the Service or reasonably necessary for security, accountability and legal requirements; customer audit records may be retained according to the customer agreement
Customer-controlled tenant dataAs instructed by the customer and described in the DPA, Order Form and configured retention policy
Customer database and files after terminationAvailable during the agreed retrieval period, then live systems deleted; backup copies expire under the applicable documented backup cycle
Billing, tax and corporate recordsFor the period required by applicable accounting, tax and corporate law

Within the Service, a customer may configure retention and scheduled deletion for contracts, vendors and documents. The current product default is a recoverable 30-day deletion window, subject to customer configuration and legal hold.

9. Security

We use administrative, technical and organisational measures designed to protect personal data. Service measures include a separate database per customer, database-enforced row-level access control, restricted operational credentials, encryption at rest and in transit through the platform, audit records, regional Processing, backups and controlled deletion.

No service is completely secure. Do not send us sensitive information through the public contact form. If you believe an account or data may be at risk, contact info@fratera.io promptly.

We do not claim ISO 27001, SOC 2, independent penetration-test completion or 24/7 monitoring unless a current written statement says otherwise.

10. Your rights

Depending on your location and the Processing, you may have the right to:

  • receive information about our Processing;
  • access or obtain a portable copy of personal data;
  • correct inaccurate data;
  • delete data;
  • restrict or object to Processing;
  • withdraw consent;
  • opt out of Sale, Share, Targeted Advertising or qualifying profiling;
  • limit certain uses of sensitive personal data;
  • appeal a refusal of a US state privacy request; and
  • complain to a regulator.

To exercise a right, email info@fratera.io with enough information to identify the relationship and request. We may verify your identity and authority and will use the information only for verification. An authorised agent may submit a request where law permits; we may require proof of authority and direct identity confirmation.

We will not discriminate against you for exercising a privacy right. If we deny an appealable US request, our response will explain how to appeal and how to contact the relevant state Attorney General.

For EEA matters, you may complain to the Czech Office for Personal Data Protection (UOOU) or the Supervisory Authority where you live or work. Contact details for UOOU are available at https://uoou.gov.cz/en.

If the data is in a customer's Fratera tenant, contact the customer first because it normally controls that data.

11. Global Privacy Control and Do Not Track

Because we do not Sell, Share or use personal data for Targeted Advertising, there is currently no advertising opt-out to apply. Where law requires, we will treat a recognised Global Privacy Control or universal opt-out signal as a request for the browser or device that sends it.

There is no common legal standard for browser Do Not Track signals, and the current website does not change behaviour in response. Third-party website resources may receive network requests as described in section 5.2; we do not permit them to use those requests for cross-site behavioural advertising on our behalf.

12. Children

Fratera is a business service and is not directed to children. The website and Service are not intended for anyone under 18, and we do not knowingly collect personal data from a child under 13. If we learn that we have done so without a lawful basis, we will take appropriate steps to delete it.

13. Marketing communications

You may opt out of marketing at any time through the message instructions or by emailing us. You will still receive necessary security, account, transactional and legal communications.

14. Changes to this Policy

We may update this Policy to reflect changes in the Services, providers or law. We will post the updated version with a revised date and provide additional notice where a change materially affects rights or Processing. Earlier versions will be retained where reasonably practicable.

15. Contact

Questions, requests and complaints may be sent to:

  • Fratera s.r.o.
  • Revoluční 28
  • 110 00 Prague 1
  • Czech Republic
  • Registration: CZ29845904
  • DUNS: 351786366
  • Principal and data-protection representative: Jan Frater
  • info@fratera.io
Fratera Procurement SolutionsFratera Procurement Solutions

Enterprise-capable contract and vendor management for procurement teams. Your data, your database.

Product

Contracts Renewals Vendors 360 Workflows E-Signing Smart AI Assistant

Company

Pricing Security About Partners Blog

Legal

Terms of Service Refund Policy Privacy Policy Data Processing Agreement info@fratera.io
© 2026 Fratera s.r.o., Prague. All rights reserved. EU & US data residency