Skip to main content

Legal documents

The full set of fremforge legal and compliance documents. Each page below is rendered from a canonical markdown source kept in lockstep with the marketing site; if a rendered page ever disagrees with its source, the source governs.

Customer-facing agreements #

  • Terms of Service - the master agreement governing use of the fremforge product.
  • Privacy Notice - categories of data processed, lawful bases, retention, GDPR rights.
  • Data Processing Agreement - GDPR Art. 28 processor terms, sub-processor list, international-transfers posture, audit rights.
  • Acceptable Use Policy - lawful-use rules, prohibited content, DSA Art. 16 notice-and-action, enforcement actions.
  • Service Level Agreement - uptime targets, planned-maintenance windows, security-patch SLA, incident communication, service-credit calculation.
  • Cookie Policy - cookies, consent posture, analytics stance.

fremverk-as-Controller documents #

  • Record of Processing Activities (ROPA) - the GDPR Art. 30 register for fremverk-as-Controller activities (HR, billing, audit-chain integrity, sub-processor selection).
  • DPIA - Audit Monitoring - Data Protection Impact Assessment for the platform-wide audit-monitoring activities fremverk operates as Controller.
  • Controller-side Incident Response - scope and availability of the runbook for breaches affecting fremverk-as-Controller activities (per DPA §8.5). The runbook itself is classified internal and is available to customers and auditors under NDA.

Website notices #

The marketing website at www.frem.sh is governed by separate, narrower notices that cover only the marketing site (not the product):

Once self-serve signup opens, the product Terms and Privacy Notice above supersede these website notices for product users.

  • Trust & compliance - overall security posture, sub-processors, and certifications.
  • Security - vulnerability disclosure and incident communication.
  • Status - current uptime and maintenance windows.

DPIA - Audit Monitoring

title: Data Protection Impact Assessment — audit-stream and authentication-monitoring processing controller: fremverk ApS, CVR 39150689 dpo_role: not designated under GDPR Art. 37 — role-equivalent privacy-contact mailbox is compliance@frem.sh (per ROPA + Product Privacy Notice §2 / §2 — DPO assessment) date: 2026-05-25 version: 1.2 status: in force related:

fremforge Acceptable Use Policy

title: fremforge Acceptable Use Policy author: fremverk date: 2026-08-05 status: Published v1.5 version: “1.5” lang: en # Last updated: 2026-08-05

fremforge Accessibility Statement

title: fremforge Accessibility Statement author: fremverk date: 2026-08-11 status: Published v1.4 version: “1.4” lang: en # Last updated: 2026-08-11

fremforge Cookie Policy

title: fremforge Cookie Policy author: fremverk date: 2026-08-05 status: Published v1.5 version: “1.5” lang: en # Last updated: 2026-08-05

fremforge Data Processing Agreement

title: fremforge Data Processing Agreement author: fremverk date: 2026-08-20 status: Published v1.36 version: “1.36” lang: en # Last updated: 2026-08-20

fremforge Product Privacy Notice

title: fremforge Product Privacy Notice author: fremverk date: 2026-08-20 status: Published v1.17 version: “1.17” lang: en # Last updated: 2026-08-20

fremforge Service Level Agreement

title: fremforge Service Level Agreement author: fremverk date: 2026-08-05 status: Published v1.5 version: “1.5” lang: en # Last updated: 2026-08-05

fremforge Terms of Service

title: fremforge Terms of Service author: fremverk date: 2026-08-13 status: Published v1.8 version: “1.8” lang: en # Last updated: 2026-08-13

fremverk Controller-side Incident Response

Scope # fremverk maintains a controller-side incident-response runbook governing our response to Personal Data Breaches affecting fremverk-as-Controller processing activities — breaches where fremverk owes the GDPR Art. 33 (72-hour Datatilsynet notification) and Art. 34 (data-subject communication) duties directly, rather than in our role as a Customer-as-Controller’s processor.

fremverk Record of Processing Activities (ROPA)

title: Records of Processing Activities (Article 30 GDPR) date: 2026-09-06 version: “1.8” status: Active. Reviewed quarterly; updated on every sub-processor change, every new processing activity, and every significant change to legal basis or retention. controller: fremverk ApS, CVR 39150689, Ringager 4C, 2. tv, 2605 Brøndby, Denmark contact: compliance@frem.sh dpo: not appointed (fremverk does not meet the Art. 37(1) mandatory-DPO criteria — not a public authority, core activities are Git hosting + CI infrastructure not large-scale systematic monitoring of data subjects, and Customer Personal Data does not include Art. 9 special-category or Art. 10 criminal-conviction data on a large scale). Assessment dated 2026-05-10; re-evaluated and CONFIRMED UNCHANGED 2026-08-16 against three material processing changes — see §3A. Cadence remains annual with the next §A.9 DR-drill review window (or sooner on material change to processing scope), so the next scheduled re-evaluation is 2027-05-10. compliance@frem.sh handles DSARs and supervisory-authority correspondence. # Records of Processing Activities # Last updated: 2026-09-06