Underdatabehandlere
Tredjepartsleverandører som behandler data på vegne av Fronterio.
Vi bruker underdatabehandlerne nedenfor til å levere plattformen. Vesentlige endringer varsles til organisasjonseiere minst 30 dager i forveien.
Connecting Microsoft 365?
Microsoft tenant integrations (Copilot tracker, SharePoint sync, Teams agent, Copilot Studio, Azure AI Foundry) are not Fronterio sub-processors. They are your own tenant. For a per-integration view of what Fronterio reads, writes, and never accesses, see the Microsoft data access overview.
View Microsoft data access overview →- Formål
- Primary database, authentication, file storage.
- Data som behandles
- Account data, organisation data, uploaded files.
- Behandlingsregion
- EU (Frankfurt, eu-central-1)
- Overføringsmekanisme
- Processing within EU
- Formål
- Application hosting and serverless function execution.
- Data som behandles
- Request metadata (no persistent PII storage).
- Behandlingsregion
- EU (Stockholm, arn1)
- Overføringsmekanisme
- Processing within EU
- Formål
- AI model inference for the AI Consultant, assessment scoring and generated reports, for organisations subscribing via Microsoft Marketplace. The same models as the direct provider, hosted on Azure in the EU (Sweden Central).
- Data som behandles
- Organisation-level context, anonymised conversation content, assessment dimension scores
- Behandlingsregion
- EU (Sweden Central)
- Overføringsmekanisme
- EU-US Data Privacy Framework + Standard Contractual Clauses
- Formål
- AI model inference for the AI Consultant, assessments and generated reports.
- Data som behandles
- Org-level aggregated context (never PII), conversation content submitted by the user.
- Behandlingsregion
- US
- Overføringsmekanisme
- EU Standard Contractual Clauses (SCCs) + EU-US Data Privacy Framework
- Formål
- Subscription billing, payment processing, tax calculation.
- Data som behandles
- Billing contact, card token (never card number), invoice metadata.
- Behandlingsregion
- EU (Ireland) with global processing
- Overføringsmekanisme
- EU SCCs
- Formål
- Transactional and lifecycle email delivery.
- Data som behandles
- Recipient email, email subject/body content.
- Behandlingsregion
- US
- Overføringsmekanisme
- EU SCCs
- Formål
- Server-side product analytics events (event names + anonymous properties only).
- Data som behandles
- Event names, org-level properties, no PII.
- Behandlingsregion
- EU (eu.posthog.com)
- Overføringsmekanisme
- Processing within EU
- Formål
- Error tracking and performance monitoring.
- Data som behandles
- Error stack traces, breadcrumbs, user id (if logged in).
- Behandlingsregion
- EU (de.sentry.io)
- Overføringsmekanisme
- Processing within EU
- Formål
- Distributed rate limiting and request counters.
- Data som behandles
- Rate-limit keys (no PII), counters.
- Behandlingsregion
- EU
- Overføringsmekanisme
- Processing within EU
- Formål
- Read sensitivity-label metadata from the customer's own M365 tenant via Microsoft Graph (informationProtection/policy/labels) so the EU AI Act risk classifier can elevate tiers when high-confidentiality data is in scope.
- Data som behandles
- Sensitivity-label IDs, names, and confidentiality levels. Never document or message contents. Never DLP rule details.
- Behandlingsregion
- Customer M365 tenant region (typically EU)
- Overføringsmekanisme
- Processing executes within the customer's tenant; Microsoft acts as the customer's own data processor under the customer's existing M365 DPA.
Innsigelse mot en underdatabehandler
Du har rett til å protestere mot en underdatabehandlerendring. Kontakt personvernombudet vårt innenfor innsigelsesperioden.