fremai Privacy Notice
On this page
title: fremai Privacy Notice author: fremverk date: 2026-08-13 version: “1.0” status: Published v1.0 lang: en #
Last updated: 2026-08-13
Effective Date: 2026-08-13 — Version: 1.0 (see the change log for the effective date of each amendment)
This Privacy Notice explains how fremverk ApS processes personal data in connection with the fremai
service at fremai.eu. For personal data that fremverk processes on behalf of a Customer (as
processor), the DPA governs and this notice is informational; for the narrow set of
activities where fremverk is itself the controller (account administration, billing, security), this
notice is the primary disclosure.
1. Who this notice is for #
- Customers and their Users — developers and organisations using fremai.
- Individuals whose personal data may appear in prompts — determined solely by the Customer. Note: fremai never stores prompt or completion content (§3), so this category has minimal standing data at fremverk.
- Prospects and correspondents — people who contact fremverk about fremai.
2. Controller and privacy contact #
fremverk ApS, CVR 39150689, Ringager 4C, 2. tv, 2605 Brøndby, Denmark.
Privacy contact: privacy@fremai.eu.
fremverk is not required to designate a Data Protection Officer under GDPR Art. 37; the contact above is the single intake point for privacy matters.
3. What we process, why, and on what legal basis #
3.1 Prompt and completion content — not retained #
fremai proxies prompts to the inference backend and returns completions. Content is processed only transiently in memory and is never persisted, logged, or used to train or improve any model (see DPA §5). fremverk cannot read content beyond routing it. This is the sovereignty spine of the service. Any personal data a Customer places in a prompt is the Customer’s responsibility as controller.
3.2 Account and authentication data #
Names, usernames, email, organisation affiliation, MFA factors, API-key identifiers, and short-lived OAuth tokens — processed to create and secure accounts and issue keys. Basis: contract (Art. 6(1)(b)) and legitimate interest in securing the service (Art. 6(1)(f)).
3.3 Usage and technical metadata #
Token counts, model id, latency, HTTP status, cost, key id, timestamp, IP addresses, and rate-limit counters — processed to meter, bill, rate-limit, and secure the service. Basis: contract and legitimate interest.
3.4 Billing and commercial data #
Organisation legal name, billing contact, VAT number, credit-ledger and invoice records — processed to charge and account for the service. Raw card data is handled by Mollie; fremverk does not see it. Basis: contract and legal obligation (bookkeeping law).
3.5 Audit and security logs #
Tamper-evident audit events (key issue/revoke, login, budget/quota change, admin action, export) and security signals — processed to secure the service and meet accountability duties. Basis: legitimate interest and legal obligation. No prompt/completion content is in these logs.
3.6 Support correspondence #
What you send to fremai support/abuse/security/privacy addresses. Basis: legitimate interest in responding.
4. Where the data is processed #
All fremai processing is inside the EU/EEA. Compute, database, cache, key management, and
observability run on T Cloud Public (eu-de, Germany), operated by Deutsche Telekom AG / T-Systems.
Inference runs on the EU-sovereign Backend (Dublin/EU). The inference path terminates TLS in-tenant and
does not traverse a CDN — prompts never reach a third-party edge. Public site / docs / console assets
are delivered via Bunny CDN at EU points of presence only, which never see the inference/prompt path.
5. CLOUD Act / US extraterritorial-law posture #
fremverk is a Danish entity; its processing infrastructure and sub-processors are EU/EEA-based. On the content path every entity that holds or could access your data is European, and the Backend is Irish-incorporated with EU-only hosting. One entity in that path — the colocation provider housing the Backend’s Dublin hardware — has a US parent; DPA §11 states this openly and explains why it creates no practical CLOUD Act exposure, since a colocation provider holds no key, has no logical access, and nothing is persisted there. The card-payment chain (Mollie) involves card networks with US parents; customers preferring to avoid this may pay by SEPA Direct Debit.
6. Retention #
- Prompt / completion content — never retained.
- Audit metadata — 3 years (tamper-evident, WORM-anchored).
- Billing-relevant usage aggregates and invoices — 5 years (Danish bookkeeping law).
- Raw per-request usage metadata (hot tier) — 90 days, then deleted. Aggregated monthly totals are kept for billing and the statutory record above.
- OAuth refresh tokens — short-lived and rotated.
- Account/authentication data — for the life of the tenancy plus the audit window, then deleted or anonymised.
7. Your rights #
Subject to the GDPR, you have the rights of access, rectification, erasure, restriction, portability, and objection, and the right not to be subject to solely-automated decisions with legal or similarly significant effect. Where fremverk processes your data as a Customer’s processor, please direct requests to the Customer (the controller); fremverk assists per DPA §7. Where fremverk is the controller (account/billing/security), contact the privacy address in §2. You may also complain to a supervisory authority (§9).
8. Automated decision-making and profiling #
fremai does not make solely-automated decisions producing legal or similarly significant effects about individuals. Automated metadata-based controls (spend-anomaly throttling, rate limiting, leaked-key revocation) act on account/usage signals to protect the service and do not evaluate personal characteristics of a data subject.
9. Supervisory authority #
fremverk’s lead supervisory authority is the Danish Data Protection Agency (Datatilsynet), Carl
Jacobsens Vej 35, 2500 Valby, Denmark — dt@datatilsynet.dk. You may also complain to the authority in
your country of residence.
10. Sub-processors #
The current sub-processor list is in DPA Annex B and on the
trust center at www.fremai.eu/trust. Changes follow the 30-day notice and objection procedure in
DPA §10.
11. Children #
fremai is a business/developer service not directed at children and is not intended for use by individuals under 16.
12. Changes to this notice #
fremverk may update this notice; material changes are announced per Terms §8.
Change log #
| Version | Date | Change |
|---|---|---|
| 1.0 | 2026-08-13 | First published version. Draft marker removed; privacy@fremai.eu provisioned. |
| 0.1 | 2026-07-06 | Initial fremai-specific draft. Not published; pending counsel review. |