Agen.co enables organizations to securely expose enterprise context to internal agents, copilots, and AI workflows through an identity-aware control layer that governs access, reduces risk, and centralizes oversight.
A low-code CIAM platform for managing customer identity as you scale.
Empower your workforce with secure agents
This Data Processing Addendum, including Schedule A and Annexes I-III (collectively, the “DPA”), forms an integral part of the main agreement between the parties (the “Agreement”) entered between Frontegg Ltd. or Frontegg, Inc., in accordance with the specific Frontegg entity entering into the Agreement (“Company“) and the counterparty agreeing to these terms (“Customer”; each “Party” and together “Parties”) and applies to the extent that Company processes Personal Data on behalf of the Customer, in the course of its performance of its obligations under the Agreement. This DPA will be effective and replaces any previously applicable terms relating to its subject matter, from the effective date of the Agreement.
By accepting this DPA (personally or on behalf of Customer), you warrant that: (a) you have full legal authority to enter into this DPA; (b) you have read and understood this DPA and agree to its terms. If you do not have the legal authority to enter into this DPA on behalf of yourself or Customer, please do not accept this DPA.
All capitalized terms not defined herein shall have the meaning set forth in the Agreement.
By accepting this DPA, the Customer acknowledges that it has read and understood the terms of this DPA and agrees to be legally bound by it.
Schedule A – Standard Contractual Clauses and the UK Addendum
Annex I – Description of Processing Activities
V Customer’s employees
V Customer’s customers
☐ Other: ________
☐ Financial and payment data (e.g. credit card number, bank account, transactions)
☐ Governmental IDs (passport, driver’s license)
V Device identifiers and internet or electronic network activity (IP addresses, GAID/IDFA, browsing history, timestamps)
V Geo-location information
☐ Genetic or biometric data
☐ Health data
☐ Racial or ethnic origin, religious or philosophical beliefs
☐ Political opinions, religious or philosophical beliefs
☐ Precise Geo-location information
☐ Government identifier (social security, driver’s license, state identification card, or passport number)
☐ Financial account and login information
☐ Sexual orientation;
☐ Citizenship or citizenship status;
☐ Known child
V Analytics
☐ Advertising (including auditing related to Advertising)
☐ Payment processing
☐ Consultation
V Security, integrity and maintaining quality of the Company’s services
☐ Transient use
V Other (including the provision of services of behalf of the Company): ________
V Continuous
☐ N/A
Annex II – Technical and Organizational Measures to Ensure the Security of the Data
This Annex forms part of the DPA and describes the technical and organizational security measures implemented by the Data Importer.
Data Importer complies and will continue to comply with SOC 2 Type-2. Without detracting from the generality of the foregoing declaration, Data Importer implements appropriate technical and organizational security measures intended to protect Personal Data against accidental or unauthorized loss, destruction, alteration, disclosure or access, composed of the following:
Annex III – List of Sub-Processors
Data Importer’s Sub-processors are listed in https://frontegg.com/trust-center/privacy/sub-processors. Data Importer may replace or appoint new Sub-processors from time to time in accordance with the DPA.
Contact the Frontegg team to disclose any suspicious activity