Legal
Privacy Policy
Last updated: August 31, 2026
This Privacy Policy explains how Frigga Cloud Private Limited ("Frigga", "we", "us", or "our") collects, uses, stores, shares, and otherwise processes personal information and Customer Data in connection with our websites, software, applications, products, integrations, communications, and related services.
Frigga provides software and services for software engineering, AI-assisted engineering, cloud infrastructure, DevOps, observability, incident management, access management, and related technical operations, including Code0, Vörr, and other Frigga products and services collectively referred to as the "Services."
This Privacy Policy should be read together with our Terms of Service, Cookie Policy, and, where applicable, any Data Processing Addendum ("DPA"), order form, enterprise agreement, or other agreement between Frigga and a Customer.
1. Who We Are
The Services are provided by:
Frigga Cloud Private Limited
1st Floor, Plot No. 7F, Raj Pinnacle
Industrial Park Road, Phase 1, 6th Cross
Behind Teleradiology Solution
Doddanekundi, Bengaluru
Bengaluru Urban, Karnataka 560048
India
Website: frigga.cloud
Email: hello@frigga.cloud
For privacy requests or grievances, please use the subject line "Privacy Request" or "Privacy Grievance", as applicable.
Our Grievance Officer details are provided in Section 34.
2. Scope of This Privacy Policy
This Privacy Policy applies to information processed by Frigga in connection with:
- Frigga websites and web forms;
- Frigga accounts and authentication;
- free, trial, paid, and Enterprise subscriptions;
- Frigga software and product usage;
- Customer organizations and workspaces;
- source-code repositories and associated repository intelligence;
- cloud infrastructure and engineering integrations;
- CI/CD, observability, monitoring, security, and incident-management systems;
- Model Context Protocol ("MCP") and other tool-based integrations;
- AI-enabled functionality;
- billing and subscription administration;
- support and Customer communications;
- product demonstrations;
- sales and business communications;
- partnerships; and
- other Frigga Services that link to this Privacy Policy.
This Privacy Policy does not govern the independent processing activities of third-party products or services selected and independently controlled by a Customer.
3. Definitions
For purposes of this Privacy Policy:
"Customer" means an individual or organization that accesses, subscribes to, purchases, or otherwise uses the Services.
"Organization" means a company, business, team, or other entity that maintains or controls a Frigga workspace, account, or subscription.
"Customer Data" means data, content, information, technical data, source code, logs, configurations, infrastructure information, observability information, or other information submitted to, connected to, accessed by, transmitted through, or processed by the Services by or on behalf of a Customer.
"Repository Data" means source-code contents and associated repository information, including files, repository metadata, branches, commits, symbols, code relationships, dependencies, and similar technical information.
"Derived Repository Data" means technical representations generated from Repository Data in order to provide or improve the Services, including indexes, embeddings, and graph-based representations or relationships.
"Personal Information" or "Personal Data" means information relating to an identified or identifiable individual, as defined under applicable privacy or data-protection law.
4. Frigga's Role in Processing Information
Frigga's legal role depends on the processing activity.
4.1 Frigga as Controller or Data Fiduciary
Frigga generally determines the purposes and means of processing information used for activities such as:
- Frigga account administration;
- subscriptions and billing;
- website operation;
- Customer communications;
- security;
- fraud and abuse prevention;
- business administration;
- marketing communications where permitted;
- legal compliance; and
- Frigga's independent business, product-development, and service-improvement activities described in this Privacy Policy.
In these circumstances, Frigga may act as a controller, Data Fiduciary, business, or similar role under applicable law.
4.2 Frigga as Processor or Service Provider
Where Frigga processes Customer Data on behalf of an Organization for the purpose of providing the Services, the Organization generally determines the purpose for which that Customer Data is processed.
In these circumstances, Frigga acts as a processor, service provider, contractor, or equivalent role where those concepts apply.
Where required by applicable law, such processing will be governed by a DPA or other written data-processing terms.
5. Information We Collect
The information Frigga processes depends on the Services used and the Customer's configuration.
5.1 Account and Organization Information
We may process:
- name;
- email address;
- Organization name;
- job title or role;
- account identifiers;
- workspace membership;
- Organization membership;
- permissions;
- product access;
- subscription information;
- Organization user counts;
- account status;
- configuration settings; and
- similar account-management information.
5.2 Authentication Information
Frigga processes information necessary to authenticate users and protect accounts.
This may include:
- authentication identifiers;
- session information;
- authentication tokens;
- one-time-password records;
- OAuth information; and
- information received from an identity or authentication provider.
Where Frigga directly stores password credentials, passwords are protected using one-way cryptographic hashing and are not stored as plaintext passwords.
5.3 Integration Credentials
Customers may authorize Frigga to connect to repositories, cloud platforms, CI/CD systems, monitoring systems, observability platforms, or other technical services.
Frigga may process:
- OAuth credentials;
- API tokens;
- access credentials;
- cloud credentials;
- repository access tokens; and
- similar authentication material necessary to operate the Customer-authorized integration.
Stored integration credentials are encrypted at rest.
Credentials are decrypted only when reasonably necessary to perform an authorized integration operation.
Frigga does not intentionally expose stored credential values through ordinary user interfaces, AI tool responses, or Customer-facing logs.
When an integration is disconnected, Frigga deletes the stored credential record associated with that connection.
5.4 Device and Technical Information
We may automatically process:
- IP address;
- browser type and version;
- operating system;
- device type;
- application or extension version;
- device or application identifiers;
- timestamps;
- session information;
- diagnostic information;
- performance information;
- crash information; and
- security events.
5.5 Usage Information
We may process information relating to use of the Services, including:
- products and features accessed;
- tool usage;
- workspace activity;
- subscription usage;
- repository operations;
- integration activity;
- configuration changes;
- technical errors;
- diagnostic events;
- security events; and
- service-performance information.
5.6 Communications
When an individual communicates with Frigga, we may process information contained in:
- emails;
- support communications;
- forms;
- meeting requests;
- feedback;
- attachments;
- technical troubleshooting information; and
- other communications with Frigga.
5.7 Billing Information
For paid Services, Frigga may process:
- billing name;
- billing address;
- Organization details;
- tax information;
- subscription information;
- invoice information;
- transaction identifiers;
- payment status;
- payment amount;
- currency; and
- limited payment-method metadata.
Payment processing may be performed through authorised payment aggregator platforms.
Where payment-card information is entered directly into a processor-hosted payment flow, Frigga does not receive or store complete payment-card numbers or card verification values.
5.8 Local Software
6. Sources of Information
Frigga may obtain information:
- directly from users;
- from an Organization or Organization administrator;
- automatically through the Services;
- from Customer-authorized integrations;
- from authentication or OAuth providers;
- from payment processors;
- from devices, applications, and browsers;
- from service providers;
- from Customer communications; and
- from publicly available business information where used for legitimate business purposes.
Where an Organization provides information concerning its users, personnel, repositories, infrastructure, or systems, that Organization is responsible for ensuring that it has appropriate authority to provide or make that information available to Frigga.
7. Repository and Source-Code Processing
Certain Frigga Services require access to Customer repositories.
When a Customer connects a repository to a Service that requires repository processing, Frigga may temporarily clone that repository to Frigga-managed infrastructure in order to provide the applicable Service.
Repository Data may include:
- source-code files;
- file contents;
- directory structure;
- repository metadata;
- commits;
- branches;
- symbols;
- dependency information;
- code relationships;
- comments;
- configuration information; and
- other technical repository information.
Repository Data is retained while the Customer maintains and uses the applicable Service requiring that repository.
Frigga does not acquire ownership of Customer source code merely because it is processed through the Services.
8. Indexes, Embeddings, and Graph Representations
Frigga may generate technical representations from Repository Data to provide repository intelligence, search, contextual retrieval, relationship analysis, and related functionality.
These representations may include:
- repository indexes;
- embeddings;
- software or repository graphs;
- symbol relationships;
- dependency relationships; and
- other Derived Repository Data.
These technical representations remain associated with the applicable Customer or repository and are processed as Customer Data.
Repository Deletion
When a Customer deletes or disconnects a repository, Frigga immediately deletes the corresponding repository data from Frigga's active repository-processing systems, including:
- the cloned repository and source-code contents;
- repository indexes;
- embeddings;
- software or repository graph representations; and
- other repository-derived data maintained for operation of the Services.
Repository deletion does not require deletion of the Customer's Frigga account or Organization.
9. Cloud, Observability, CI/CD, and Connected Systems
Customers may authorize Frigga to connect to engineering systems including:
- cloud infrastructure;
- monitoring systems;
- observability systems;
- logging platforms;
- tracing platforms;
- CI/CD systems;
- incident-management systems;
- security systems;
- source-control systems; and
- other engineering tools.
Depending on the integration, Frigga may process:
- cloud-resource metadata;
- infrastructure configuration;
- deployment information;
- pipeline information;
- logs;
- metrics;
- traces;
- alerts;
- errors;
- incidents;
- resource usage;
- cost information;
- access events; and
- similar engineering information.
The information accessible to Frigga depends on the permissions and scopes authorized by the Customer.
For certain Vörr integrations, telemetry such as metrics, logs, traces, errors, or related technical evidence may be retrieved from connected services on demand and processed transiently or briefly cached rather than being persistently copied into Vörr.
Frigga may apply filtering or redaction to technical information returned through supported connector paths in order to reduce exposure of credentials, secrets, or unnecessary sensitive information.
Customers are responsible for ensuring they have appropriate authority to connect their systems to Frigga.
10. MCP and Customer-Controlled AI Clients
Certain Frigga Services, including Vörr functionality, may expose engineering context and technical capabilities through the Model Context Protocol ("MCP") or similar tool-based interfaces.
10.1 How MCP Processing Works
An authorized third-party AI client may determine that additional Customer context is required and invoke an authorized Frigga tool.
Frigga processes the tool request and returns the requested context or technical response to the Customer's authorized client or environment.
Any subsequent use or transmission of that response by the Customer's AI client is controlled by the Customer's:
- selected AI software;
- model provider;
- provider configuration;
- credentials;
- subscription; and
- contractual relationship with that provider.
Frigga does not control the independent processing performed by the Customer-selected AI provider after information has been returned to the Customer's AI client.
10.2 MCP Audit Information
Frigga may maintain operational and security audit records relating to MCP activity.
Depending on the applicable configuration, these records may include:
- Organization identifier;
- authenticated user;
- user role;
- tool invoked;
- calling application;
- execution status;
- execution timestamp; and
- execution duration.
Frigga does not use MCP audit records as a mechanism to routinely store the complete request payload or complete response payload of every tool invocation.
10.3 Separate Frigga AI Features
Certain separate Frigga functionality may use third-party AI providers where that functionality is enabled.
For example, Frigga may use third-party AI services for limited activities such as structured business-information extraction, classification, analysis, or other AI-assisted features.
Where Frigga itself invokes such a provider, Frigga limits the information provided to what is reasonably necessary for the applicable function and handles the processing in accordance with this Privacy Policy and applicable law.
Third-party AI providers used by Frigga are addressed in Section 16.
11. Organization Administrators
Where an individual uses Frigga through an Organization, authorized Organization administrators may manage the individual's access to Organization-controlled Services.
Administrators may be able to view or manage information such as:
- user name;
- work email address;
- role;
- Organization membership;
- workspace membership;
- product subscriptions;
- product access;
- permissions;
- account or workspace status; and
- Organization user counts.
Organization administrators may also add, suspend, remove, or modify users and their access.
Frigga does not provide Organization administrators with unrelated personal information merely because an individual is associated with that Organization.
12. Personnel Access to Customer Data
Frigga personnel do not have direct access to Customer source code or other Customer Data through ordinary internal systems or workflows.
Customer Data is stored and processed within secured Frigga-managed systems that use access controls, authentication safeguards, and encryption protections appropriate to the applicable data and system.
Frigga customer-support personnel cannot access Customer source code or other Customer Data unless the Customer expressly authorizes such access for a specific support, troubleshooting, or service-related purpose.
Where Customer-authorized access is provided:
- access is limited to the information reasonably necessary for the authorized purpose;
- access is limited to the personnel required to perform that purpose;
- access is subject to Frigga's applicable security and access-control measures; and
- authorized personnel remain subject to confidentiality obligations.
Automated Frigga systems may process Customer Data as necessary to provide and operate the Services without requiring routine human access.
Any disclosure required by binding law or legal process is governed separately by the legal-disclosure provisions of this Privacy Policy.
13. How We Use Information
Frigga may process information for the following purposes.
Providing the Services
Including to:
- create accounts;
- authenticate users;
- administer Organizations and workspaces;
- provide product functionality;
- process repositories;
- create indexes, embeddings, and graphs;
- operate authorized integrations;
- provide contextual retrieval;
- process MCP requests;
- administer subscriptions;
- process billing; and
- provide Customer support.
Security and Reliability
Including to:
- protect accounts;
- prevent unauthorized access;
- investigate security events;
- detect abuse;
- maintain service reliability;
- diagnose errors;
- enforce applicable terms; and
- protect Frigga's systems.
Product Analytics and Improvement
Frigga may use usage, performance, diagnostic, aggregated, or appropriately de-identified information to:
- understand product usage;
- improve usability;
- improve reliability;
- fix bugs;
- evaluate features; and
- develop Services.
Communications
Including to:
- respond to inquiries;
- send authentication messages;
- provide support;
- communicate security information;
- communicate billing or subscription information;
- send product updates; and
- send marketing communications where permitted by applicable law.
Business and Legal Administration
Including to:
- administer contracts;
- maintain business records;
- maintain accounting and tax records;
- comply with applicable law;
- establish or defend legal claims; and
- manage Customer and business relationships.
14. Legal Bases for Processing
Where applicable law requires a legal basis for processing, the applicable legal basis depends on the processing activity and jurisdiction.
Contractual Necessity
Frigga may process information where necessary to:
- create and administer an account;
- provide a requested Service;
- maintain an Organization workspace;
- operate Customer-authorized integrations;
- provide support;
- administer a subscription; or
- process billing.
Legitimate Interests
Where permitted by applicable law, Frigga may rely on legitimate interests for activities such as:
- securing the Services;
- preventing fraud or abuse;
- maintaining reliability;
- diagnosing technical issues;
- improving Services;
- managing business relationships; and
- lawful business-to-business communications.
Where Frigga relies on legitimate interests, Frigga considers the purpose, necessity of the processing, and impact on affected individuals as required by applicable law.
Consent
Where applicable law requires consent, Frigga may rely on consent for specific processing activities such as certain marketing communications or non-essential tracking technologies.
Where processing is based on consent, statutory rights concerning withdrawal of consent remain available to the extent provided by applicable law.
Legal Obligations
Frigga may process information where necessary to comply with:
- laws;
- regulations;
- court orders;
- tax obligations;
- accounting requirements; or
- other binding legal requirements.
15. How We Share Information
Frigga does not sell Customer Data.
Frigga does not disclose Customer Data to third parties for their independent marketing purposes.
Frigga may share information in the following circumstances.
Service Providers and Subprocessors
Frigga may use service providers to support:
- hosting;
- cloud infrastructure;
- storage;
- email delivery;
- DNS and network services;
- payment processing;
- authentication;
- security;
- monitoring;
- communications; and
- other technical or business functions.
Customer-Directed Integrations
Frigga may exchange information with a third-party system when a Customer directs or authorizes Frigga to connect to that system.
Customer-Controlled AI Providers
Where a Customer's AI client receives information from Frigga through MCP or another tool interface, subsequent processing by that AI provider is controlled by the Customer's selected environment and provider relationship.
Professional Advisers
Frigga may provide information where reasonably necessary to:
- legal counsel;
- accountants;
- auditors;
- insurers; and
- similar professional advisers
subject to appropriate confidentiality obligations.
Legal Requirements
Frigga may disclose information where disclosure is required under applicable law, court order, regulatory requirement, or other binding legal process.
Corporate Transactions
Information may be disclosed where reasonably necessary in connection with:
- financing;
- merger;
- acquisition;
- restructuring;
- reorganization;
- sale of assets; or
- similar corporate transaction,
subject to appropriate confidentiality and applicable law.
16. Subprocessors and Service Providers
Frigga currently uses the following material providers, as applicable to the Services used by the Customer:
| Provider | Purpose |
|---|---|
| DigitalOcean | Frigga-managed cloud infrastructure, compute, database infrastructure, and object storage |
| Cloudflare | DNS, network delivery, and security-related services |
| Brevo | Transactional and service email delivery |
| Authorised payment aggregator platforms | Payment processing where applicable |
| Anthropic | AI processing for specific Frigga-controlled AI features where enabled |
| OAuth / identity providers selected or authorized by Customers | Authentication and Customer-authorized account connections |
Frigga may also use internally operated or open-source infrastructure components, including database, monitoring, and metrics systems, within Frigga-managed infrastructure.
Frigga requires service providers that process Customer Data on Frigga's behalf to be subject to appropriate confidentiality, security, and data-protection obligations.
Where Frigga acts as a processor and relies on general authorization for subprocessors, Frigga will provide applicable Customers with notice of material new or replacement subprocessors and an opportunity to object where required by applicable law or the applicable DPA.
Frigga may maintain or publish a more detailed Subprocessor List separately as its provider ecosystem develops.
17. Data Location and International Transfers
Frigga Cloud Private Limited is based in India.
Frigga's primary Frigga-managed infrastructure used for storage and processing of Customer product data is located in India.
This includes Frigga-managed infrastructure hosted through DigitalOcean in its Bangalore, India region.
Frigga-managed database and object-storage infrastructure used for Customer product data is also operated within Frigga's India-based infrastructure architecture.
Certain third-party providers, including communications, network, payment, or AI providers, may process limited information outside India depending on their infrastructure and the particular Service used.
Where applicable law requires additional safeguards for an international transfer of personal information, Frigga will implement an appropriate lawful transfer mechanism.
For transfers subject to GDPR restrictions, such mechanisms may include the European Commission's Standard Contractual Clauses or another mechanism recognized under applicable law where required and applicable.
Frigga does not represent that every third-party provider used by Frigga operates exclusively within India.
18. Data Retention and Deletion
Frigga retains information only for as long as reasonably necessary for the purpose for which it is processed, subject to applicable contractual, security, accounting, tax, and legal requirements.
Frigga uses different retention rules for different categories of information.
18.1 Repository Data
Repository Data is retained while the Customer maintains and uses the applicable Service requiring access to that repository.
When a repository is deleted or disconnected, Frigga immediately deletes the corresponding operational repository copy, index, embeddings, and graph-derived repository information from the applicable active repository-processing systems.
18.2 Account Data
When a Frigga user account is deleted, Frigga removes the operational user-account data associated with that account from applicable active account systems within approximately one hour.
This does not require Frigga to delete records that must or may lawfully be retained for purposes such as:
- tax;
- accounting;
- invoices;
- fraud prevention;
- security;
- contractual records;
- dispute resolution; or
- legal claims.
18.3 Integration Credentials
Stored credentials associated with an integration are deleted when the applicable integration is disconnected.
18.4 Other Information
Operational, security, communication, billing, and other business information is retained only for the period reasonably necessary for the applicable purpose or as required by applicable law.
Frigga maintains internal retention practices appropriate to the categories of information it processes.
When information is no longer required, Frigga deletes, anonymizes, or otherwise disposes of it in accordance with applicable law and Frigga's operational practices.
19. Account, Repository, and Subscription Actions
Subscription cancellation, account deletion, Organization deletion, repository deletion, and integration disconnection are separate actions.
For example:
- deleting a repository does not require deleting the Customer's entire account;
- disconnecting an integration removes the applicable stored integration credential without requiring account deletion; and
- cancelling a paid subscription does not automatically constitute deletion of all legally retainable account or transaction records.
Customers may request account deletion using the applicable account mechanism or by contacting Frigga at hello@frigga.cloud.
Frigga will process authenticated account-deletion requests in accordance with this Privacy Policy and applicable law.
20. Security
Frigga implements technical and organizational measures designed to protect Customer Data and Personal Information from unauthorized access, alteration, loss, misuse, or disclosure.
Depending on the processing activity, such safeguards may include:
- authentication controls;
- identity and access controls;
- encryption;
- encryption of stored integration credentials;
- network controls;
- monitoring;
- audit logging;
- secure development practices;
- data filtering and redaction;
- incident-response procedures;
- confidentiality obligations; and
- access restrictions.
Frigga does not claim that any technical or organizational security measure can guarantee absolute security.
Customers are also responsible for appropriately securing their:
- accounts;
- endpoints;
- credentials;
- integrations;
- third-party systems;
- permissions; and
- selected AI providers.
Frigga does not represent in this Privacy Policy that it holds any particular security certification unless that certification has been separately confirmed and is currently applicable.
21. Security Incidents
Frigga assesses and responds to security incidents involving Personal Information or Customer Data in accordance with applicable incident-response practices and legal requirements.
Where notification is required by applicable law, Frigga will notify affected Customers, individuals, regulators, or other authorities within the period and in the manner required under the applicable law.
Where Frigga acts as a processor, applicable incident-notification obligations may also be governed by the relevant DPA or Customer agreement.
22. Privacy Rights
Privacy rights vary by jurisdiction.
Depending on applicable law, an individual may have the right to:
- receive information concerning processing;
- request access to Personal Information;
- correct inaccurate information;
- request deletion or erasure;
- object to certain processing;
- restrict certain processing;
- receive portable data where applicable;
- withdraw consent where consent is the legal basis;
- opt out of certain marketing;
- opt out of sale, sharing, or targeted advertising where applicable;
- exercise rights relating to qualifying automated decision-making;
- nominate another person where applicable law provides a nomination right; and
- lodge a complaint or grievance with Frigga or an applicable regulatory authority.
These rights are subject to applicable law, exemptions, verification requirements, and Frigga's role in the relevant processing.
Requests Concerning Organization Customer Data
Where Frigga processes Personal Information solely on behalf of an Organization, the Organization is generally responsible for responding to privacy-rights requests concerning that Customer Data.
An individual seeking to exercise rights concerning information controlled by their employer or another Organization should ordinarily direct the request to that Organization.
Where Frigga receives such a request directly, Frigga may refer or forward it to the relevant Organization and will provide reasonable assistance as required under applicable law and the applicable DPA.
23. How to Exercise Privacy Rights and Response Periods
Privacy requests may be sent to:
hello@frigga.cloud
Please use the subject line:
Privacy Request
Frigga may request information reasonably necessary to:
- understand the request;
- verify the identity of the requester;
- verify the requester's authority; and
- prevent unauthorized access, modification, or deletion.
Where applicable:
European Economic Area and UK
Requests governed by the GDPR or UK GDPR will be handled without undue delay and generally within one month of receipt.
Where permitted by applicable law, the response period may be extended where necessary due to the complexity or number of requests, and Frigga will provide the required notice of such extension.
California
Applicable verified California consumer requests will generally be handled within 45 calendar days, subject to extensions permitted under applicable California law.
India
Privacy grievances governed by applicable Indian requirements will be handled within the period required by applicable law.
Where Frigga applies its Indian privacy-grievance process, Frigga's operational target is to address the grievance within one month.
As additional provisions of the Digital Personal Data Protection Act, 2023 and Digital Personal Data Protection Rules, 2025 become applicable, Frigga will operate the applicable rights, grievance, notice, and response mechanisms required under those provisions.
24. Marketing Communications
Frigga may send lawful:
- product updates;
- company news;
- newsletters;
- technical content;
- release information;
- event communications; and
- other business or promotional communications.
Recipients may unsubscribe from marketing communications using the unsubscribe mechanism provided in the communication or by contacting Frigga.
Frigga may use providers such as Brevo for email delivery.
Unsubscribing from marketing does not prevent Frigga from sending necessary:
- authentication messages;
- account notices;
- transactional messages;
- service notifications;
- billing information;
- security notices; or
- legal notices.
25. Cookies and Similar Technologies
Frigga may use cookies and similar technologies necessary for:
- authentication;
- session management;
- security;
- preferences;
- product functionality; and
- limited operational analytics where applicable.
Frigga does not currently use Personal Information for cross-context behavioural advertising.
Where applicable law requires consent before non-essential cookies or similar technologies are used, Frigga will provide an appropriate consent or preference mechanism.
Additional information is provided in Frigga's separate Cookie Policy.
26. California and Other U.S. State Privacy Disclosures
Where the California Consumer Privacy Act ("CCPA") or another applicable U.S. state privacy law applies, eligible individuals may have additional rights concerning:
- access;
- correction;
- deletion;
- portability;
- sale;
- sharing;
- targeted advertising;
- sensitive Personal Information; and
- qualifying automated decision-making.
Frigga does not sell Personal Information as the term "sell" is defined under applicable California privacy law.
Frigga does not share Personal Information for cross-context behavioural advertising as the term "share" is defined under applicable California privacy law.
Frigga does not unlawfully discriminate against an individual for exercising applicable privacy rights.
Where a legally recognized browser-based opt-out preference signal applies to Frigga's processing, Frigga will process such signals as required by applicable law.
If Frigga materially changes its advertising or tracking practices, this Privacy Policy and applicable preference mechanisms will be updated accordingly.
Frigga does not use or disclose Sensitive Personal Information for purposes of inferring characteristics about individuals or for purposes other than those permitted under applicable California law, unless separately disclosed.
27. European Economic Area and United Kingdom
Where the GDPR or UK GDPR applies, Frigga processes Personal Data in accordance with applicable requirements concerning:
- lawful processing;
- transparency;
- data-subject rights;
- security;
- data minimization;
- retention;
- controller and processor responsibilities;
- processor agreements; and
- international transfers.
Where Frigga processes Customer Data as a processor, the applicable DPA or other written data-processing terms govern that processing.
Individuals may have the right to lodge a complaint with the supervisory authority applicable to them.
Where Frigga is required under applicable European or UK law to appoint a local representative, the applicable representative details will be made available through Frigga's privacy documentation.
28. India-Specific Privacy Information
Frigga Cloud Private Limited is incorporated in India and maintains its primary Frigga-managed Customer product infrastructure in India.
Frigga processes Personal Data in accordance with applicable Indian privacy and data-protection requirements.
This includes applicable provisions of:
- the Information Technology Act, 2000;
- applicable rules issued under that Act;
- the Digital Personal Data Protection Act, 2023; and
- the Digital Personal Data Protection Rules, 2025,
in each case to the extent those provisions are in force and applicable to the relevant processing activity.
As applicable DPDP provisions become operational, Frigga will implement the notices, rights mechanisms, security safeguards, grievance mechanisms, consent processes where required, and other obligations applicable to Frigga's processing.
Nothing in this Privacy Policy is intended to limit any mandatory statutory right available under applicable Indian law.
29. Government and Legal Requests
Frigga may disclose information where required by applicable law, court order, regulation, or other binding legal process.
Where legally permitted and appropriate, Frigga will seek to notify the affected Customer before disclosing Customer Data in response to a governmental or law-enforcement request.
Frigga reviews legal requests for appropriate authority and scope.
Where reasonably appropriate and legally available, Frigga may seek clarification, narrow a request, or challenge a request that appears unlawful or materially overbroad.
Frigga will not provide Customer Data to government authorities merely upon an informal request where binding legal process is required.
30. Children
Frigga products are general-purpose software and engineering tools and are not designed to provide or expose violent, sexually explicit, or other content that Frigga considers inappropriate for children.
Frigga does not specifically design, market, or operate the Services as children's services and does not intentionally profile children or collect Personal Information for child-directed advertising.
Frigga does not independently determine whether a particular user is permitted to use a Frigga product based solely on age, except where age restrictions or other protections are required by applicable law.
Where a child or minor uses a Frigga product, responsibility for authorizing and supervising that use rests with the applicable parent, legal guardian, educational institution, Organization, or other responsible party, as applicable.
Frigga will comply with any specific obligations relating to children or minors that apply under applicable law.
31. Automated Decision-Making
Frigga's AI-enabled functionality may provide:
- engineering context;
- technical analysis;
- recommendations;
- generated technical output;
- search or retrieval results; and
- workflow assistance.
Frigga does not use Personal Information to make solely automated decisions that produce legal or similarly significant effects on individuals.
If Frigga introduces such processing in the future, Frigga will provide any additional disclosures, rights, or controls required by applicable law.
32. Third-Party Services
The Services may connect to or interact with third-party:
- developer tools;
- cloud platforms;
- source-control platforms;
- observability systems;
- AI clients;
- payment services; and
- other external systems.
Where a Customer independently chooses, configures, or controls a third-party service, the third party's independent processing is governed by its own terms and privacy practices.
Frigga is not responsible for processing independently performed by third parties outside Frigga's control.
Users may configure locally operated Frigga software to interact with third-party AI models, model providers, APIs, extensions, integrations, or other external services. Where information is transmitted from a user's local environment to a third party as a result of the user's configuration or selection of that third-party service, the transmission and subsequent processing are governed by the user's relationship with that third party and the third party's applicable terms and privacy practices.
Frigga does not control or assume responsibility for the independent processing practices of third-party services selected or configured by the user. Users are responsible for reviewing the privacy, confidentiality, security, and data-usage terms of those services before transmitting Customer Data or confidential information to them.
Nothing in this section limits Frigga's responsibility for information that Frigga itself receives, collects, or processes through Frigga-operated infrastructure.
33. Changes to This Privacy Policy
Frigga may update this Privacy Policy to reflect changes to:
- the Services;
- Frigga's processing activities;
- AI-enabled functionality or data-processing practices;
- integrations;
- service providers;
- applicable laws; or
- business operations.
Where required by applicable law, Frigga will provide appropriate notice before a material change becomes effective and obtain consent where legally required.
Material historical versions may be retained or archived by Frigga so that significant changes to this Privacy Policy can be identified.
34. Grievance Officer and Privacy Contact
For questions concerning this Privacy Policy, privacy-rights requests, Personal Data, or privacy grievances, contact:
Shafan Muhammed
Chief Operating Officer and Grievance Officer
Frigga Cloud Private Limited
Email: hello@frigga.cloud
Privacy Request Subject: Privacy Request
Grievance Subject: Privacy Grievance
Registered Address:
1st Floor, Plot No. 7F, Raj Pinnacle
Industrial Park Road, Phase 1, 6th Cross
Behind Teleradiology Solution
Doddanekundi, Bengaluru
Bengaluru Urban, Karnataka 560048
India
Frigga will acknowledge, investigate, and respond to privacy requests and grievances in accordance with the timelines described in Section 23 and applicable law.