title: fremai Records of Processing Activities (Article 30 GDPR)
author: fremverk
date: 2026-08-13
version: “1.0”
status: Published v1.0
lang: en
#
Last updated: 2026-08-13
Effective Date: 2026-08-13 — Version: 1.0 (see the change log for the effective date of each amendment)
This document is fremverk’s Article 30 Record of Processing Activities for the fremai service at
fremai.eu. It records processing as of the date above and is reviewed at every sub-processor change,
every privacy-impacting feature change, and at minimum quarterly. It is a fremai-specific record — not
an extension of the fremforge ROPA — reflecting fremai’s distinct sub-processor chain and its
metadata-only / no-content posture. A separate ROPA exists for fremverk corporate operations and is
out of scope here.
1. Controller / processor identification
#
- Entity: fremverk ApS, CVR 39150689, Ringager 4C, 2. tv, 2605 Brøndby, Denmark.
- Privacy contact:
privacy@fremai.eu. - Representative for non-EU controllers: not applicable (fremverk is EU-established).
- Data protection officer: not appointed — fremverk does not meet the Art. 37(1) mandatory-DPO
criteria (not a public authority; core activity is AI-inference reselling, not large-scale systematic
monitoring of data subjects; no Art. 9 / Art. 10 data is processed on a large scale). The privacy
contact above is the single intake point.
Dual capacity. For prompt/completion routing, account, and usage metadata processed on behalf of a
Customer, fremverk acts as processor and the DPA governs. For a narrow set of
activities (account administration, billing, security/abuse monitoring), fremverk acts as controller.
Each activity below states the capacity.
2. Sub-processor / recipient reference
#
Recipients that are Article-28 sub-processors are not re-listed independently in this document. The
authoritative, canonical list is the shared fremverk supplier register at
fremverk’s internal supplier register (source of truth),
with the customer-facing view generated as DPA Annex B and
reviewed quarterly per fremverk’s supplier-review procedure.
The activities below name the relevant recipient by role; consult the register for the entity,
jurisdiction, certifications, and effective-from date. All security measures referenced as “Annex A”
below are the technical and organisational measures in DPA Annex A.
3. Processing activities
#
| Field | Value |
|---|
| Capacity | Processor (Customer is controller). |
| Purpose | Route an OpenAI-compatible inference request to the EU-sovereign inference backend and return the completion; record token-usage metadata for metering and billing. |
| Lawful basis | Art. 6(1)(b) — performance of contract (processor acting on Customer instruction). |
| Data subjects | Customer’s developers/users who issue requests; any natural persons whose data the Customer chooses to include in a prompt (determined solely by the Customer). |
| Categories of data | Prompt and completion content — processed transiently in memory only, never persisted, never logged, never used to train any model (DPA §5, Annex A.1). Usage metadata retained: token counts (in/out), model id, latency, HTTP status, cost, key id, request timestamp. |
| Recipients / sub-processors | Inference-backend sub-processor (model completions); infrastructure sub-processor (proxy compute, metering database). See §2 / the shared register. No CDN sits in the inference path — the api.fremai.eu/v1 data plane terminates TLS in-tenant (DPA §11). |
| Retention | Prompt/completion content: never retained. Raw per-request usage metadata (hot tier): 90 days. Billing-relevant usage aggregates: 5 years (Bogføringsloven §10). |
| EU residency | Yes — EU/EEA only. Proxy on T Cloud Public (eu-de, Germany); inference backend in the EU (Dublin/EU). No transfer outside the EU/EEA. |
| Security (Annex A) | A.1 metadata-only control; A.2 residency; A.3 encryption in transit/at rest; A.6 rate/budget/abuse limits. |
3.2 Account and identity management
#
| Field | Value |
|---|
| Capacity | Processor for the Customer’s users; controller for fremverk’s own account-administration records. |
| Purpose | Create and secure fremai accounts and organisations; authenticate users; broker per-tenant OIDC federation; issue and manage inference keys. |
| Lawful basis | Art. 6(1)(b) — contract; Art. 6(1)(f) — legitimate interest in securing the service. |
| Data subjects | Customer developers, tenant-admins, billing-admins; fremverk operators (metadata-only, audited). |
| Categories of data | Names, usernames, email, organisation affiliation; OIDC subject identifiers and group claims where a Customer federates its IdP; MFA/passkey factors; API-key identifiers; short-lived OAuth access/refresh tokens. No special-category data. |
| Recipients / sub-processors | Self-hosted Zitadel identity layer (customer authentication + IdP brokering) and infrastructure sub-processor, both under the infrastructure row of the shared register (§2; DPA Annex B.1). A Customer’s own federated IdP is the Customer’s processor, not fremverk’s sub-processor. |
| Retention | Account/authentication records: life of the tenancy plus the audit window, then deleted or anonymised. OAuth refresh tokens: short-lived and rotated (design default 12-hour key TTL, 30-day sliding refresh). |
| EU residency | Yes — Zitadel and control plane run on T Cloud Public (eu-de). Federated-IdP location is determined by the Customer. |
| Security (Annex A) | A.4 access control and identity; A.5 key and credential lifecycle. |
3.3 Billing and payment
#
| Field | Value |
|---|
| Capacity | Controller (fremverk bills the Customer in its own name). |
| Purpose | Charge prepaid top-ups and postpaid enterprise invoices; issue invoices/credit notes; reconcile payments. |
| Lawful basis | Art. 6(1)(b) — contract; Art. 6(1)(c) — legal obligation (Danish bookkeeping law). |
| Data subjects | Billing and administrative contacts of the Customer. |
| Categories of data | Organisation legal name, billing contact, VAT number, credit-ledger and invoice records, payment-result metadata. Raw card/PAN data is never seen or stored by fremverk — it is processed by the payment sub-processor only. |
| Recipients / sub-processors | Payment-processing sub-processor (card / SEPA top-ups) and accounting/invoice-rendering sub-processor. See §2 / the shared register. EU Commission VIES receives the VAT identifier only (carve-out, not an Art. 28 sub-processor). |
| Retention | Invoices and billing-relevant records: 5 years from the end of the accounting year (Bogføringsloven §10). |
| EU residency | Yes at fremverk’s scope. The card-network chain via the payment sub-processor retains globally-clearing card networks (Visa/Mastercard) with US parents; SEPA Direct Debit is offered as a fully-EU alternative. |
| Security (Annex A) | A.3 encryption; A.4 access control. |
3.4 Audit logging and integrity
#
| Field | Value |
|---|
| Capacity | Processor (per-tenant audit trail) and controller (fremverk’s own accountability records). |
| Purpose | Record security-relevant events for accountability, incident response, and customer-verifiable audit; meet Art. 32 obligations. |
| Lawful basis | Art. 6(1)(f) — legitimate interest in security; Art. 6(1)(c) — legal obligation. |
| Data subjects | Any user whose action produces an audit event; fremverk operators. |
| Categories of data | Event metadata: actor identifier, action, structured event fields, timestamp, chain hashes. No prompt/completion content is in the audit log — there is none to log. |
| Recipients / sub-processors | Infrastructure sub-processor (metering database + WORM-anchored object storage), under the infrastructure row of the shared register (§2). |
| Retention | Audit metadata: 3 years, tamper-evident (SHA-256 per-tenant hash chain), WORM-anchored to object storage. |
| EU residency | Yes — T Cloud Public (eu-de). |
| Security (Annex A) | A.7 audit logging and integrity. |
| Field | Value |
|---|
| Capacity | Controller (fremverk protects the service and bounds its own financial exposure). |
| Purpose | Detect and throttle runaway or compromised keys, enforce rate/budget/concurrency limits, and revoke leaked keys — operating on account/usage metadata only, per design §4.18. |
| Lawful basis | Art. 6(1)(f) — legitimate interest in service security, abuse prevention, and financial-exposure control. |
| Data subjects | Holders of inference keys (developers, tenant-admins). |
| Categories of data | Per-key spend rate, token/request counts, concurrency, IP addresses, rate-limit counters, budget thresholds, key id. No prompt/completion content is inspected or moderated (DPA §5; design §4.12). |
| Recipients / sub-processors | Infrastructure sub-processor (counters in cache/database) and — for leaked-key notifications — third-party secret-scanning partner programmes that notify on the sk-fremai-… prefix. See §2. |
| Retention | Rate-limit / concurrency counters: ephemeral. Spend-anomaly and enforcement events: recorded as audit metadata per §3.4 (3-year window). |
| EU residency | Yes — T Cloud Public (eu-de). |
| Security (Annex A) | A.6 rate-limiting, budgets, and abuse controls; A.5 key lifecycle. |
4. Cross-cutting controls
#
- Metadata-only / no-content floor — the defining invariant: prompt/completion bodies are never
written to disk, database, or logs, and are never used to train any model (DPA §5, Annex A.1).
- Encryption — TLS 1.2+ in transit on every hop; at-rest encryption with fremverk-managed DEW KMS
keys (Annex A.3).
- Access control — least-privilege operator roles via fremverk’s workforce IdP; tenant isolation is
logical (LiteLLM org/team/user/key scoping + control-plane row-level security), shared fremai
database (Annex A.4).
- Data-subject rights — operational paths in DPA §7 and
Privacy Notice §7.
- International transfers — none on any fremai processing path; all processing is EU/EEA-located
(DPA §11). One entity on the inference path, the
colocation provider for the Backend’s Dublin hardware, has a US parent; §11 records this and the reasons
it creates no practical CLOUD Act exposure.
5. Change log
#
| Version | Date | Change |
|---|
| 1.0 | 2026-08-13 | First published version. Draft marker removed; privacy@fremai.eu provisioned. |
| 0.1 | 2026-07-06 | Initial fremai-specific ROPA draft. Five processing activities recorded. Sub-processors referenced to the shared register rather than re-listed. Not published; pending counsel review. |