Skip to main content
  1. Legal documents/

fremai Records of Processing Activities (Article 30 GDPR)

On this page

title: fremai Records of Processing Activities (Article 30 GDPR) author: fremverk date: 2026-08-13 version: “1.0” status: Published v1.0 lang: en #

Last updated: 2026-08-13

Effective Date: 2026-08-13 — Version: 1.0 (see the change log for the effective date of each amendment)

This document is fremverk’s Article 30 Record of Processing Activities for the fremai service at fremai.eu. It records processing as of the date above and is reviewed at every sub-processor change, every privacy-impacting feature change, and at minimum quarterly. It is a fremai-specific record — not an extension of the fremforge ROPA — reflecting fremai’s distinct sub-processor chain and its metadata-only / no-content posture. A separate ROPA exists for fremverk corporate operations and is out of scope here.


1. Controller / processor identification #

  • Entity: fremverk ApS, CVR 39150689, Ringager 4C, 2. tv, 2605 Brøndby, Denmark.
  • Privacy contact: privacy@fremai.eu.
  • Representative for non-EU controllers: not applicable (fremverk is EU-established).
  • Data protection officer: not appointed — fremverk does not meet the Art. 37(1) mandatory-DPO criteria (not a public authority; core activity is AI-inference reselling, not large-scale systematic monitoring of data subjects; no Art. 9 / Art. 10 data is processed on a large scale). The privacy contact above is the single intake point.

Dual capacity. For prompt/completion routing, account, and usage metadata processed on behalf of a Customer, fremverk acts as processor and the DPA governs. For a narrow set of activities (account administration, billing, security/abuse monitoring), fremverk acts as controller. Each activity below states the capacity.

2. Sub-processor / recipient reference #

Recipients that are Article-28 sub-processors are not re-listed independently in this document. The authoritative, canonical list is the shared fremverk supplier register at fremverk’s internal supplier register (source of truth), with the customer-facing view generated as DPA Annex B and reviewed quarterly per fremverk’s supplier-review procedure. The activities below name the relevant recipient by role; consult the register for the entity, jurisdiction, certifications, and effective-from date. All security measures referenced as “Annex A” below are the technical and organisational measures in DPA Annex A.

3. Processing activities #

3.1 Inference-request handling (metadata-only) #

FieldValue
CapacityProcessor (Customer is controller).
PurposeRoute an OpenAI-compatible inference request to the EU-sovereign inference backend and return the completion; record token-usage metadata for metering and billing.
Lawful basisArt. 6(1)(b) — performance of contract (processor acting on Customer instruction).
Data subjectsCustomer’s developers/users who issue requests; any natural persons whose data the Customer chooses to include in a prompt (determined solely by the Customer).
Categories of dataPrompt and completion content — processed transiently in memory only, never persisted, never logged, never used to train any model (DPA §5, Annex A.1). Usage metadata retained: token counts (in/out), model id, latency, HTTP status, cost, key id, request timestamp.
Recipients / sub-processorsInference-backend sub-processor (model completions); infrastructure sub-processor (proxy compute, metering database). See §2 / the shared register. No CDN sits in the inference path — the api.fremai.eu/v1 data plane terminates TLS in-tenant (DPA §11).
RetentionPrompt/completion content: never retained. Raw per-request usage metadata (hot tier): 90 days. Billing-relevant usage aggregates: 5 years (Bogføringsloven §10).
EU residencyYes — EU/EEA only. Proxy on T Cloud Public (eu-de, Germany); inference backend in the EU (Dublin/EU). No transfer outside the EU/EEA.
Security (Annex A)A.1 metadata-only control; A.2 residency; A.3 encryption in transit/at rest; A.6 rate/budget/abuse limits.

3.2 Account and identity management #

FieldValue
CapacityProcessor for the Customer’s users; controller for fremverk’s own account-administration records.
PurposeCreate and secure fremai accounts and organisations; authenticate users; broker per-tenant OIDC federation; issue and manage inference keys.
Lawful basisArt. 6(1)(b) — contract; Art. 6(1)(f) — legitimate interest in securing the service.
Data subjectsCustomer developers, tenant-admins, billing-admins; fremverk operators (metadata-only, audited).
Categories of dataNames, usernames, email, organisation affiliation; OIDC subject identifiers and group claims where a Customer federates its IdP; MFA/passkey factors; API-key identifiers; short-lived OAuth access/refresh tokens. No special-category data.
Recipients / sub-processorsSelf-hosted Zitadel identity layer (customer authentication + IdP brokering) and infrastructure sub-processor, both under the infrastructure row of the shared register (§2; DPA Annex B.1). A Customer’s own federated IdP is the Customer’s processor, not fremverk’s sub-processor.
RetentionAccount/authentication records: life of the tenancy plus the audit window, then deleted or anonymised. OAuth refresh tokens: short-lived and rotated (design default 12-hour key TTL, 30-day sliding refresh).
EU residencyYes — Zitadel and control plane run on T Cloud Public (eu-de). Federated-IdP location is determined by the Customer.
Security (Annex A)A.4 access control and identity; A.5 key and credential lifecycle.

3.3 Billing and payment #

FieldValue
CapacityController (fremverk bills the Customer in its own name).
PurposeCharge prepaid top-ups and postpaid enterprise invoices; issue invoices/credit notes; reconcile payments.
Lawful basisArt. 6(1)(b) — contract; Art. 6(1)(c) — legal obligation (Danish bookkeeping law).
Data subjectsBilling and administrative contacts of the Customer.
Categories of dataOrganisation legal name, billing contact, VAT number, credit-ledger and invoice records, payment-result metadata. Raw card/PAN data is never seen or stored by fremverk — it is processed by the payment sub-processor only.
Recipients / sub-processorsPayment-processing sub-processor (card / SEPA top-ups) and accounting/invoice-rendering sub-processor. See §2 / the shared register. EU Commission VIES receives the VAT identifier only (carve-out, not an Art. 28 sub-processor).
RetentionInvoices and billing-relevant records: 5 years from the end of the accounting year (Bogføringsloven §10).
EU residencyYes at fremverk’s scope. The card-network chain via the payment sub-processor retains globally-clearing card networks (Visa/Mastercard) with US parents; SEPA Direct Debit is offered as a fully-EU alternative.
Security (Annex A)A.3 encryption; A.4 access control.

3.4 Audit logging and integrity #

FieldValue
CapacityProcessor (per-tenant audit trail) and controller (fremverk’s own accountability records).
PurposeRecord security-relevant events for accountability, incident response, and customer-verifiable audit; meet Art. 32 obligations.
Lawful basisArt. 6(1)(f) — legitimate interest in security; Art. 6(1)(c) — legal obligation.
Data subjectsAny user whose action produces an audit event; fremverk operators.
Categories of dataEvent metadata: actor identifier, action, structured event fields, timestamp, chain hashes. No prompt/completion content is in the audit log — there is none to log.
Recipients / sub-processorsInfrastructure sub-processor (metering database + WORM-anchored object storage), under the infrastructure row of the shared register (§2).
RetentionAudit metadata: 3 years, tamper-evident (SHA-256 per-tenant hash chain), WORM-anchored to object storage.
EU residencyYes — T Cloud Public (eu-de).
Security (Annex A)A.7 audit logging and integrity.

3.5 Abuse and spend monitoring (metadata-based) #

FieldValue
CapacityController (fremverk protects the service and bounds its own financial exposure).
PurposeDetect and throttle runaway or compromised keys, enforce rate/budget/concurrency limits, and revoke leaked keys — operating on account/usage metadata only, per design §4.18.
Lawful basisArt. 6(1)(f) — legitimate interest in service security, abuse prevention, and financial-exposure control.
Data subjectsHolders of inference keys (developers, tenant-admins).
Categories of dataPer-key spend rate, token/request counts, concurrency, IP addresses, rate-limit counters, budget thresholds, key id. No prompt/completion content is inspected or moderated (DPA §5; design §4.12).
Recipients / sub-processorsInfrastructure sub-processor (counters in cache/database) and — for leaked-key notifications — third-party secret-scanning partner programmes that notify on the sk-fremai-… prefix. See §2.
RetentionRate-limit / concurrency counters: ephemeral. Spend-anomaly and enforcement events: recorded as audit metadata per §3.4 (3-year window).
EU residencyYes — T Cloud Public (eu-de).
Security (Annex A)A.6 rate-limiting, budgets, and abuse controls; A.5 key lifecycle.

4. Cross-cutting controls #

  • Metadata-only / no-content floor — the defining invariant: prompt/completion bodies are never written to disk, database, or logs, and are never used to train any model (DPA §5, Annex A.1).
  • Encryption — TLS 1.2+ in transit on every hop; at-rest encryption with fremverk-managed DEW KMS keys (Annex A.3).
  • Access control — least-privilege operator roles via fremverk’s workforce IdP; tenant isolation is logical (LiteLLM org/team/user/key scoping + control-plane row-level security), shared fremai database (Annex A.4).
  • Data-subject rights — operational paths in DPA §7 and Privacy Notice §7.
  • International transfers — none on any fremai processing path; all processing is EU/EEA-located (DPA §11). One entity on the inference path, the colocation provider for the Backend’s Dublin hardware, has a US parent; §11 records this and the reasons it creates no practical CLOUD Act exposure.

5. Change log #

VersionDateChange
1.02026-08-13First published version. Draft marker removed; privacy@fremai.eu provisioned.
0.12026-07-06Initial fremai-specific ROPA draft. Five processing activities recorded. Sub-processors referenced to the shared register rather than re-listed. Not published; pending counsel review.