Version 1.0 — effective 8 September 2026.
This Privacy Policy explains how Fratera s.r.o. (Fratera, we, us) handles personal data when you visit fratera.io, contact us, participate in our partner programme, create or administer a Fratera account, or otherwise interact with us in a business capacity.
1. Who we are and how to contact us
Fratera s.r.o. is a company based in Prague, Czech Republic. For privacy questions or to exercise a right, contact:
- Email: info@fratera.io
- Postal address: Revoluční 28, 110 00 Prague 1, Czech Republic
- Registration: CZ29845904
- DUNS: 351786366
- Principal and data-protection representative: Jan Frater
Jan Frater is Fratera's designated contact and representative for DPA and data-protection matters. Where a formally appointed Data Protection Officer or an EU, UK or other statutory representative is legally required, the applicable appointment and contact details will be published here.
2. Scope and our role
2.1 Data we control
Fratera is the Controller or Business for personal data used for its own website, sales, partner, account administration, billing, support, security, service communications, legal compliance and business operations.
2.2 Customer-controlled content
When a Fratera business customer uploads contracts, supplier contacts, employee information or other content to its tenant, the customer normally determines why and how that information is used. Fratera Processes it as the customer's Processor, Service Provider or Contractor under our Data Processing Agreement.
If your information appears in a customer's Fratera tenant, please direct your request to that customer first. We will assist the customer as required by law and our DPA. We will not disclose customer-controlled content without appropriate authorisation.
2.3 Third-party sites
This Policy does not govern websites, products or services operated independently by third parties, even if we link to them. Their notices apply to their Processing.
3. Personal data we collect
We collect only the data relevant to the interaction.
3.1 Website and enquiry data
- name, business email, company and role;
- the product, partnership or other topic you select;
- your message and any information you choose to include;
- referral information submitted through our partner page, including the referred company or contact; and
- campaign parameters present in a link, if any. The current website preserves these parameters in links but does not use active analytics.
3.2 Account and business-relationship data
- name, business contact details, employer and role;
- workspace, plan, region, user role and account-administration details;
- authentication and sign-in information managed through our authentication provider;
- customer billing, technical, privacy and commercial contacts;
- subscription, invoice, payment-status and tax information; and
- communications, support requests, demonstrations, feedback and meeting notes.
Payment-card information, where accepted, is handled directly by the payment provider and is not intended to be stored by Fratera.
3.3 Service-use and security data
- IP address, browser and device information;
- sign-in events, session identifiers, timestamps and security events;
- feature configuration, user permissions and operational logs;
- support diagnostics and actions taken in the Service; and
- essential authentication cookies and local or session storage used for sign-in, security, display preferences and navigation.
3.4 Customer-controlled content
Depending on a customer's use, its tenant may contain:
- employee, contractor, supplier and counterparty contact details;
- contracts, attachments, notes, messages and vendor records;
- professional roles, approvals, delegation and audit information;
- electronic-signature recipient details, consent, timestamps, IP/user-agent evidence and signature images;
- financial and commercial terms contained in contracts; and
- AI prompts, extracted text and suggested outputs when the customer enables AI features.
The Service is not designed for special-category data, highly sensitive government identifiers, payment-card data, consumer health data, biometric identification data or children's data. Uploaded documents are unstructured, so customers must decide whether it is lawful and necessary to include any sensitive information.
3.5 Sources
We obtain data:
- directly from you;
- from your employer or the organisation administering your account;
- from a partner or other business contact who refers you;
- automatically from your browser, device and use of the website or Service;
- from integrations or services you authorise;
- from publicly available business sources where appropriate; and
- from service providers acting for us.
If someone refers you, we will use the information to assess and make the requested business contact. Referrers must have a reasonable basis to share your business details. We will provide this Policy at or before our first communication where required.
4. Why we use personal data
| Purpose | Typical data | GDPR/UK lawful basis |
|---|---|---|
| Respond to enquiries, arrange demos and manage prospects | Contact, company, interest and message | Legitimate interests in responding to business enquiries; steps requested before a contract |
| Operate partner referrals | Referrer and referred business-contact data, communications | Legitimate interests in developing business relationships and administering the programme; contract where the partner agreement applies |
| Create and administer accounts and provide the Service | Account, workspace, authentication, configuration and support data | Performance of the customer agreement; legitimate interests in administering business users |
| Bill and manage the commercial relationship | Billing contacts, plan, invoices, tax and payment status | Contract; legal obligations; legitimate interests in financial administration |
| Send transactional and service communications | Name, email, account and event metadata | Contract; legitimate interests in operating and securing the Service |
| Provide support and improve reliability | Communications, diagnostics and operational telemetry | Contract; legitimate interests in support, reliability and product improvement |
| Protect the website, Service, customers and Fratera | IP/device, authentication, audit, security and fraud signals | Legitimate interests in security and fraud prevention; legal obligations |
| Comply with law and establish, exercise or defend claims | Relevant account, transaction, communication and log data | Legal obligation; legitimate interests in legal protection |
| Send business marketing where permitted | Business contact, company, preferences and interactions | Consent where required; otherwise legitimate interests in relevant B2B marketing |
Where we rely on legitimate interests, we consider whether our purpose is necessary and whether your rights override it. You may object as described below. Where we rely on consent, you may withdraw it at any time without affecting earlier lawful Processing.
We do not use Customer content to train general-purpose or third-party AI models. We do not make decisions producing legal or similarly significant effects about website visitors or account users solely by automated means.
5. How we disclose personal data
We disclose data only as reasonably necessary:
5.1 Service subprocessors
For customer-controlled Service data, our authorised subprocessors are:
- Hostinger - regional application hosting and network infrastructure;
- Supabase - per-customer database, authentication, storage, backup and platform services;
- Mistral AI - customer-enabled AI document extraction and analysis through a region-bound endpoint where supported; and
- Resend - transactional email, invitations, reminders and signature links.
FrateraSign and Gotenberg are self-hosted software components and are not separate third-party subprocessors.
5.2 Website-only providers
- Hostinger hosts the marketing website and may Process ordinary web-server request and security logs.
- FormSubmit.co currently receives contact and partner form fields so they can be delivered to
info@fratera.io. It is a website-only provider and does not Process Fratera customer tenant data for the Service. - Google Fonts is loaded from Google servers. A visitor's IP address and request metadata are therefore sent to Google to deliver font files.
5.3 Transactions completed through Paddle
If Paddle is identified at checkout, Paddle acts as merchant of record and authorised reseller for the transaction. The buyer purchases through the relevant Paddle entity, and Paddle independently determines how it Processes payment, billing, tax, fraud-prevention, refund and transaction-support data as a Controller. Paddle may collect the buyer's name, business and billing details, payment information, tax information, IP/device data and transaction history directly through its checkout or invoicing flow. Paddle's Buyer Terms and Privacy Notice apply to that Processing.
Fratera receives from Paddle the transaction and entitlement information reasonably necessary to provision and administer the subscription, reconcile payments, provide support and meet accounting and legal duties. Fratera does not intend to receive full payment-card details. Paddle is not a Subprocessor for customer-controlled tenant data merely because it completes a purchase; if the implementation later sends Paddle such data for Processing on Fratera's behalf, the DPA and public Subprocessor list must be updated before that Processing begins.
5.4 Other recipients
We may disclose relevant data to:
- professional advisers, auditors, insurers and financing or corporate-transaction counterparties under confidentiality;
- competent courts, regulators, public authorities or law enforcement where legally required; and
- a successor in a merger, acquisition, reorganisation or sale, subject to appropriate safeguards.
We do not sell personal data for money. We do not share it for cross-context behavioural advertising and do not use it for targeted advertising. We have not knowingly sold or shared personal data of people under 16 in the preceding 12 months.
6. Cookies and similar storage
6.1 Marketing website
The website does not activate analytics or advertising cookies. It does not use tracking pixels or behavioural advertising. It may receive campaign parameters in a URL and preserve them in links without storing them.
If a deployed version stores a local preference solely to dismiss a notice, that storage, its purpose and duration will be stated here. A consent banner is not a substitute for accurate disclosure and will not be used to imply that tracking occurs where it does not.
6.2 Fratera Service
The Service uses essential authentication cookies and browser storage to keep users signed in, protect the session, support single sign-on, remember display/edit preferences and preserve navigation state. These items are necessary for or requested through the Service and are not used for advertising.
If we later add optional analytics or marketing technology, we will update this Policy and, where required, ask for prior, granular consent with an equally accessible rejection and withdrawal mechanism.
7. International transfers and data regions
Customers select an EU or US deployment region when the tenant is created. Fratera is designed to place the customer database, storage and regional application Processing in that selected region and to bind AI and transactional-email configuration to it where supported. The Order Form and DPA control any specific residency commitment.
Fratera is established in the Czech Republic. Some providers or their support functions may be located outside the EEA, United Kingdom or Switzerland. Where a restricted transfer occurs, we use a lawful mechanism such as an adequacy decision, the European Commission's Standard Contractual Clauses, the UK Addendum, or another permitted safeguard. We assess supplementary measures where required. You may request information about the relevant safeguard by contacting us.
We do not claim that a provider participates in the EU-US Data Privacy Framework or UK Extension unless its relevant legal entity is actively certified.
8. Retention
We keep personal data only for as long as needed for the purpose, including security, dispute and legal-retention needs. The applicable retention criteria are:
| Data | Retention / criterion |
|---|---|
| Website enquiries and ordinary prospect communications | Up to 24 months after the last meaningful interaction, unless a relationship continues or earlier deletion is appropriate |
| Unsuccessful partner referrals | Up to 12 months after the referral closes, subject to objection or deletion rights |
| Customer business contacts and account records | During the customer relationship and then up to 12 months after decommissioning for direct operational contacts; limited contract, invoice and legal records longer where required by law |
| Marketing preferences and suppression records | Until opt-out, then a minimal suppression record for as long as needed to honour the choice |
| Website server/security logs | Hostinger's documented operational retention period, extended where reasonably necessary to investigate an incident or comply with law |
| Service authentication, audit and security logs | For the period configured for the Service or reasonably necessary for security, accountability and legal requirements; customer audit records may be retained according to the customer agreement |
| Customer-controlled tenant data | As instructed by the customer and described in the DPA, Order Form and configured retention policy |
| Customer database and files after termination | Available during the agreed retrieval period, then live systems deleted; backup copies expire under the applicable documented backup cycle |
| Billing, tax and corporate records | For the period required by applicable accounting, tax and corporate law |
Within the Service, a customer may configure retention and scheduled deletion for contracts, vendors and documents. The current product default is a recoverable 30-day deletion window, subject to customer configuration and legal hold.
9. Security
We use administrative, technical and organisational measures designed to protect personal data. Service measures include a separate database per customer, database-enforced row-level access control, restricted operational credentials, encryption at rest and in transit through the platform, audit records, regional Processing, backups and controlled deletion.
No service is completely secure. Do not send us sensitive information through the public contact form. If you believe an account or data may be at risk, contact info@fratera.io promptly.
We do not claim ISO 27001, SOC 2, independent penetration-test completion or 24/7 monitoring unless a current written statement says otherwise.
10. Your rights
Depending on your location and the Processing, you may have the right to:
- receive information about our Processing;
- access or obtain a portable copy of personal data;
- correct inaccurate data;
- delete data;
- restrict or object to Processing;
- withdraw consent;
- opt out of Sale, Share, Targeted Advertising or qualifying profiling;
- limit certain uses of sensitive personal data;
- appeal a refusal of a US state privacy request; and
- complain to a regulator.
To exercise a right, email info@fratera.io with enough information to identify the relationship and request. We may verify your identity and authority and will use the information only for verification. An authorised agent may submit a request where law permits; we may require proof of authority and direct identity confirmation.
We will not discriminate against you for exercising a privacy right. If we deny an appealable US request, our response will explain how to appeal and how to contact the relevant state Attorney General.
For EEA matters, you may complain to the Czech Office for Personal Data Protection (UOOU) or the Supervisory Authority where you live or work. Contact details for UOOU are available at https://uoou.gov.cz/en.
If the data is in a customer's Fratera tenant, contact the customer first because it normally controls that data.
11. Global Privacy Control and Do Not Track
Because we do not Sell, Share or use personal data for Targeted Advertising, there is currently no advertising opt-out to apply. Where law requires, we will treat a recognised Global Privacy Control or universal opt-out signal as a request for the browser or device that sends it.
There is no common legal standard for browser Do Not Track signals, and the current website does not change behaviour in response. Third-party website resources may receive network requests as described in section 5.2; we do not permit them to use those requests for cross-site behavioural advertising on our behalf.
12. Children
Fratera is a business service and is not directed to children. The website and Service are not intended for anyone under 18, and we do not knowingly collect personal data from a child under 13. If we learn that we have done so without a lawful basis, we will take appropriate steps to delete it.
13. Marketing communications
You may opt out of marketing at any time through the message instructions or by emailing us. You will still receive necessary security, account, transactional and legal communications.
14. Changes to this Policy
We may update this Policy to reflect changes in the Services, providers or law. We will post the updated version with a revised date and provide additional notice where a change materially affects rights or Processing. Earlier versions will be retained where reasonably practicable.
15. Contact
Questions, requests and complaints may be sent to:
- Fratera s.r.o.
- Revoluční 28
- 110 00 Prague 1
- Czech Republic
- Registration: CZ29845904
- DUNS: 351786366
- Principal and data-protection representative: Jan Frater
info@fratera.io