Scope of This Policy

This privacy policy applies to every website we operate, every communication we send, every form you complete, and every service that FRDM Agent LLC performs for a client. It covers the information that belongs to you as a visitor to our site, to you as a customer, and to the data we handle while operating autonomous agent systems on your behalf. When we say this policy applies, we mean that it governs all of the activities described in the rest of this document. Where a particular client contract includes its own data protection agreement, that separate agreement will take precedence over the general statements of this policy only in the limited places where the two documents might conflict. In all other situations, this policy forms the honest baseline of how we treat personal information.

The scope also reaches the agents we monitor. Many of the autonomous agents we supervise process information on behalf of other teams and other companies. When an agent handles a file, a message or an order that contains personal data, that data falls within the protections described here in the same way it would if our own staff reviewed the file in person. We do not hide behind the fact that a machine moved the data. Every operation we run under a watchkeeping model is treated with the seriousness of a manual task, because to us a well supervised agent is still carrying the responsibility of a real member of your crew.

The Company We Are

FRDM Agent LLC is a company that designs autonomous agent operations systems, task queue orchestration, escalation and handoff workflows, runbook automation platforms, audit trail dashboards and integration health monitors for digital service teams. Our registered and primary place of business is located at 226 E 400 N, Washington - 84780-1733, United States (US). For the purpose of privacy law, the company is the data controller for the information we collect about our website visitors and our commercial prospects. We decide why that information is gathered and how it will be used.

For the operating data we handle on behalf of our clients, the company frequently acts as a data processor rather than a controller. That means our clients decide the purpose of the processing and give us instructions, while we carry out those instructions carefully and keep the information secure. We are transparent about which role we hold in any given situation, because data protection law draws a real line between the entity that decides and the entity that acts. When we are only processing under a client instruction, we point you to that client as the controller who can best answer questions about the substance of your data, while we remain accountable for our own handling of the technical systems.

Information We Collect

We collect information through a small number of deliberate paths, and we try never to scoop up more than we need. The information we gather falls into four general groups. First, information you hand to us by filling a form or writing an email. Second, technical information that our website collects as you browse. Third, information related to the delivery of our services, such as the agent fleet details you share when we carry out a watch review. Fourth, information your own customers trust to us only when we run a system that touches their records as part of the monitoring work for your team.

None of this collection is a secret. We want every visitor to understand exactly what we hold about them and why we hold it. Where we collect information that you do not actively give us, we explain clearly in the sections below what triggers that collection and how long the information stays with us. If a form on our website asks a question that we genuinely do not need for the service you requested, we leave that question out. We prefer a shorter form that collects only what matters over a longer form that quietly gathers extras no one will ever use.

Information You Provide Directly

There are several moments when you decide to provide information to us directly. When you fill in the contact form on our website, we receive your name, your email address, a subject line and the message you choose to write. When you book a watch review with FRDM Agent LLC, we may ask for your company name, your role, the size of your existing fleet of agents and the general shape of the problem you are trying to solve. When you speak to a member of our team or write to our email address, we keep the correspondence so we can answer your questions accurately and so you do not have to repeat the same background information on every call.

We treat the details you provide during an early conversation with the same care we treat finished client information. A draft architecture you share even before signing a contract is confidential to you, and we will not reuse it for another prospect or publish it in any form. The only exception comes where the law genuinely requires us to respond to a valid request from an authority. Outside of those lawful requirements, the material you place in our hands stays under our watch and under our responsibility for as long as we have reason to hold it and no longer.

Information Collected Automatically

When any visitor opens pages on our website, standard technical systems record a small set of routine details. Our hosting service logs the internet protocol address of the device, the general type of browser, the operating system, the time of the visit and the pages that were requested. These logs exist to protect the security of the site, to spot abusive traffic and to help us understand broadly whether parts of the website are being read successfully. We do not build a personal profile of any single anonymous visitor from these logs on a normal day.

Analytics of this kind tells us which sections interest people and which sections are being missed, and that helps us keep the content honest and useful. We make our own products out of the aggregate patterns, never out of any one private trail through the site. If you visit without completing a form, we generally have no ordinary way to link the technical logs back to your identity, because you have not given us a name to connect them to. When you do complete a form, we keep the confidentiality of the whole visit intact and use the technical details only for security and for making the site behave well on your device.

Information About Agent Operations

A meaningful part of the information we handle is not about you as a person at all, but about the operations of the autonomous agents we supervise. When we design a console for your team, we gather descriptions of your agent workload, the names of your queues, the integrations in use and the typical patterns of an incident in your environment. We treat this operational knowledge as your trade confidence, and we do not share the inner workings of your fleet with any other customer.

Because our systems record audit trails so that your team can answer hard questions later, the machines we operate may capture fragments of actual messages, file names, order IDs and decision logs as they pass through your service. All of that material is handled strictly under the data protection agreement we sign with your organisation. We hold the material only to the degree needed to run the monitoring, we do not remove it from the agreed environment without permission, and we return or delete the operational data according to the schedule your contract sets out. To the people whose personal records pass through such an agent, those people should treat the operator of the service as the main data controller, with FRDM Agent LLC as a careful processor following instructions.

How We Use Information

We use the information we hold for a limited set of purposes that are clear and easy to follow. We use contact details to answer your messages and to carry forward the conversations that become a review or a build. We use your company and fleet details to design the correct system, to run the watchkeeping we discuss and to keep the audits accurate. We use the technical logs to protect our site and to improve the experience of future visitors. We use aggregated, anonymised numbers to describe the kind of work we do without ever revealing the identity of a single customer or a single user of a client service.

Only rarely do we use information for any purpose beyond the one for which it was collected. When a new purpose would arise, we weigh whether it sits reasonably within the expectations we set when gathering the data. If it clearly does not, we will not proceed on silent grounds; we will seek fresh consent or a lawful basis before we change the course. We also hold ourselves to a principle that may sound simple but that guides every decision we make, namely that we would be comfortable explaining any use of your information to you directly if you asked. If an internal use would embarrass us when spoken aloud into the light of a simple question, then we will not make that use in the first place.

Lawful Bases for Processing

Data protection law in the United States and in the regions we serve expects an organisation to rest every act of processing on a sound foundation. For most of the information you give us directly, we rely on consent or on the legitimate interests of running and improving our business while safeguarding your own interests. When you ask a question, send a signal or request a watch review, there is often an implicit request on your side, and processing your message to answer you serves that natural exchange rather than harming you.

Where we operate agent systems on contract, we rely on the contract itself as the lawful basis, together with any separate data processing agreement you sign with FRDM Agent LLC. Where we must retain documents to satisfy accounting, tax or legal obligations, we rely on compliance with a legal requirement. Where we act as a processor for a client, we point to the client as the controller that holds the appropriate lawful basis for the underlying work, and we follow the instructions that client lawfully gives us. We are happy to discuss the specific basis that applies to any particular piece of handling you ask about, and our contact details at the end of this policy are a reliable route to that conversation.

Cookies and Similar Technologies

Cookies are small text files that a website stores on a device to remember a limited amount of information across visits. We use a modest number of cookies and similar technologies for reasons that are mostly functional rather than intrusive. We may use a cookie that remembers your preference to keep the navigation drawer closed or open, and we may use a security related token to keep a legitimate session safe. We do not run advertising networks that track you across unrelated websites to build a commercial portrait of your interests.

Where an analytics script places a cookie, we configure it to be as unobtrusive as the technology allows, and we use the resulting data only in the aggregated fashion described earlier in this document. Your browser gives you the tools to refuse or to delete cookies at any time, and the core pages of our website remain perfectly readable without them. Should we later introduce a technology whose purpose is not strictly necessary, we will tell you plainly and give you a choice before it runs, rather than sneaking a track downstream of this policy.

How We Share Information

We share personal and operational information only where there is a lawful and legitimate reason to do so, and we share the narrowest slice that reason actually requires. We share information with the software and infrastructure providers we rely on to run our own systems, which falls to the next section. We share aggregated statistics that carry no personal identity when we describe our capability to a prospect or in a public setting. And on a rare occasion forced by law, we may respond to a valid legal process that requires the release of specific records, after we have checked the request is genuine and appropriately scoped.

We never sell personal information. We never rent information about your fleet to an advertiser. We never trade contact lists or hand over the details of your customers so that some unrelated company can approach them. If the entire ownership of FRDM Agent LLC ever changes hands, whether through a sale, a merger or any similar transaction, the information we hold would move with the business, but we would require the new owner to honour the commitments of this policy in writing before any transfer closes.

Service Providers and Subprocessors

To deliver our work we rely on a small set of trusted vendors. Our website is hosted by an infrastructure provider that keeps the servers running and patches them for security. We use a communications system to handle email and to run the calls and meetings that a watch review requires. We may use a cloud platform to store project documents and audit records under encryption, and we may use an accounting or payment service to handle the financial side of a contract.

Every subprocessor we engage receives only the information required to perform its narrow function, and each one is bound by a data protection agreement at least as strict as the promises we make to you in this policy. Before we add a new provider that will touch personal or operational data, we review its security posture, its regional hosting and its own commitments, and we add it to the list only when we are satisfied. If you would like the names of our current subprocessors, ask us through the contact channel below and we will provide the current list without delay.

Data Retention Schedules

We do not keep information forever, and we do not delete it carelessly. We keep contact form messages and email correspondence for a period of time long enough to complete the conversation and to honour any follow up you request, and no longer than the reasonable business need and applicable law permit. We retain project and audit documents for the length of your engagement plus the retention window agreed in your contract, so that any regulatory or contractual demand could still be met from the record.

Technical server logs are rotated automatically after a short window, typically a matter of weeks, because long log keeping multiplies risk without adding much value. When we reach the end of a retention period, records are destroyed by secure deletion in the case of digital data and by shredding in the case of paper, such that the information cannot be resurrected from a forgotten backup any more easily than it can be read from a discarded hard drive. We view a tidy deletion schedule as a form of respect, because holding data no one needs is itself a small risk that a good keeper should refuse to carry.

Security of Information

We protect the information we hold with safeguards that are appropriate to how sensitive the information is and how easy it would be for an attacker to harm it. Access to our own systems is limited to the people who need it for their work, protected by strong passwords, multi factor authentication and least privilege principles. Data in transit across the public internet is encrypted, and records at rest are stored on encrypted volumes. We keep the software we run patched and we review the access of former staff and partners immediately when their role ends.

No company can promise that a determined and resourced attacker will never succeed, and we do not make that empty promise. What we can promise is that we run a genuine program of security work, that we respond quickly when something looks wrong, and that we tell the right people the truth if a breach ever touches their information, without delaying the notice until a marketing team has polished the wording. We also build security into the systems we design for our clients, because an audit trail that exists only on paper is the very last thing a good watchkeeper should trust.

Children and Minors

The websites and services of FRDM Agent LLC are directed to business and technical professionals, and they are not intended for children. We do not knowingly collect personal information from children, and we do not build products whose normal use draws in children as a target audience. A first party online service aimed at minors is a different matter from a professional monitoring tool, and none of the software we design is aimed at children in the sense that data protection rules use that phrase.

If we become aware that we have unintentionally received personal information from a child without the appropriate consent of a parent or guardian, we will delete that information promptly once we confirm it qualifies. If a parent or guardian believes that a child has submitted personal information to us through a form or an email, that parent should contact us through the details at the end of this policy, and we will investigate and remove the material quickly and without argument. We take this duty seriously rather than treating it as a line of legalese, because a child who runs up against a monitoring company should be protected by our own good sense before a regulation ever needs to intervene.

International Transfers

FRDM Agent LLC is based in the United States, and the information we collect on this website is primarily stored and processed in facilities located in the United States. If a visitor, a customer or a data subject is located in the European Economic Area, the United Kingdom or another region whose law restricts the transfer of personal data across borders, that legal framework may apply even though our servers sit in the United States. We take reasonable steps to support lawful international transfers of information that fall under such rules.

Those steps can include reliance on recognised adequacy decisions where they apply to the destination, standard contractual clauses with our vendors and processors, and supplementary safeguards tailored to the region concerned. When we act as a processor for a client whose users are protected by a regional law, we will follow the transfer mechanisms that the client and its counsel direct, because they are the controller best placed to make the lawful choice. Any visitor who has specific questions about where a particular piece of their information is stored should contact us, and we will give an honest answer about our regional storage footprint rather than a vague reassurance.

Your Privacy Rights

Your rights over your information vary by where you live, but most modern privacy laws converge on a familiar set of powers, and we honour them within reason wherever they apply. You may ask us for a copy of the personal information we hold about you. You may ask us to correct information that is wrong or to complete information that is incomplete. You may ask us to delete personal information that we no longer have a lawful reason to keep. You may ask us to restrict or to stop a particular processing activity, or to hand you a portable copy of data you supplied in answer to your own request.

To exercise any of these rights, contact us through the details at the end of this policy and identify yourself plainly, so that we can be sure we answer the correct person and do not leak one account to another. We will respond within the window your local law sets, usually within thirty days, and we will explain any refusal in plain terms rather than hiding behind a slogan. In most cases these rights are free to exercise, though a law may allow a small fee when a request is clearly excessive or repetitive, in which case we would explain the basis for that charge before asking for payment. You also hold the right to lodge a complaint with your own data protection authority, and you may do so without first asking our permission, because that authority exists to protect you and not to please us.

Third Party Services and Links

Our website may contain links that lead away from our own pages to the sites of partners, customers or useful references on the wider internet. When you leave our site by following such a link, the privacy policy of the destination site governs your activity there, and we hold no responsibility for how that third party treats your information. We choose links with care and we avoid pointing you toward services we would not use ourselves, but we cannot stand watch over the entire reach of the web.

The tools that our agent operations systems integrate with belong to their own providers and come with their own terms. When we monitor an integration, we do not impersonate that provider or change its privacy promises; we simply observe the connection from the position a monitored customer occupies. Should a third party service in any of our engaged systems change its data practices in a way that affects the protections you expect, we will raise that change with you during the relevant watch run and include the consequence in our audit notes, so that the decision stays with the controller who owns the service rather than drifting silently into a corner of an agreement nobody rereads.

Changes to This Policy

We review this privacy policy whenever the way we work changes materially, whenever the law moves, or whenever a careful reader points out something we could state more honestly. When a change alters the way we treat personal information in a way that you would reasonably want to know about before it happens, we will draw your attention to the new version rather than burying a quiet edit in the history of a seldom visited page. Material changes carry a fresh updated date at the top of this document so the sharp keeper of any copy can see at once that the text is the current issue.

Because the plain language of this policy matters more than any decorative wrapper around it, we will preserve the spirit of the original while improving the accuracy of the words. Older versions of this policy may be retained in our archive so that a past request can still be understood against the rules that applied at the moment it arrived. We do not treat a change to a policy as a licence to misapply information gathered under an earlier promise. If a different practice is truly warranted, we will say so clearly and, where needed, seek fresh consent rather than quietly stretching the old one.

Contacting the Company

If you have a question about this privacy policy, about the information we hold, or about a request you would like to make over your personal data, the surest route is to write to the address below and mark your note for the attention of the privacy watch. You may also telephone our office lines during standing business hours, or send a message to the email address of the Company. We read our messages on a regular schedule and we aim to answer any genuine privacy query within a small number of business days.

The Company can be reached at FRDM Agent LLC, 226 E 400 N, Washington - 84780-1733, United States (US), by email at update@frdmagent.mom, or by telephone at +12233343920. When you write, please describe the request clearly and give us a way to reach you for any necessary follow up. We may ask you to confirm your identity by a small and proportionate method before we act, so that we never hand information to someone who merely claims to be you. This policy belongs on the chart table of our relationship, and we keep it close to hand for as long as we sail together.