Legal
Privacy Policy
Last updated: August 11, 2026
This Privacy Policy explains how Frigga Cloud Private Limited ("Frigga", "we", "us", or "our") collects, uses, shares, stores, and otherwise processes personal information in connection with our websites, applications, platforms, products, subscriptions, integrations, communications, and related services (collectively, the "Services").
Frigga provides an AI-first engineering platform connecting software development, cloud infrastructure, CI/CD, observability, incidents, security, infrastructure access, engineering workflows, and cloud costs. Our products may include Code0, Vörr AI, Runes, Brokk, Drasil, Shankh, Juno, Dvarpala, Legion, and related products, integrations, and services.
This Privacy Policy should be read together with our Terms of Service and Cookie Policy. Where applicable law requires consent for a particular processing activity, Frigga will request that consent in the manner required by law.
1. WHO WE ARE
The Services are provided by:
Frigga Cloud Private Limited
1st Floor, Evolve Co-working
Bengaluru, Karnataka 560048
India
Email: hello@frigga.cloud
Website: https://frigga.cloud/
For privacy questions, requests, complaints, or exercise of privacy rights, contact hello@frigga.cloud with the subject line "Privacy Request".
2. SCOPE
This Privacy Policy applies to personal information processed by Frigga in connection with:
Frigga websites and web forms;
- accounts and authentication;
- free trials and paid subscriptions;
- product usage;
- customer onboarding and support;
- product demonstrations, sales, partnerships, and business communications;
- billing and payment administration;
- connected integrations and engineering systems;
- security and access-management functionality;
AI-enabled functionality;
- recruitment applications and candidate communications, where applicable;
- investor, partner, vendor, and professional communications; and
- other Services that link to this Privacy Policy.
This Policy does not govern independent processing by third-party services that you choose to connect to or access through Frigga. Those third parties may have their own privacy policies and terms.
3. ROLES: CONTROLLER AND PROCESSOR
Depending on the context, Frigga may process personal information in different capacities.
3.1 Frigga as Controller / Data Fiduciary
Frigga generally determines the purpose and means of processing for information collected directly for account administration, billing, website operations, sales, marketing, support, security, recruitment, and business administration.
3.2 Frigga as Processor / Service Provider
Where an Organization uses the Services to process personal information contained in its code, logs, infrastructure, identity systems, observability systems, support materials, or other Customer Data, the Organization generally determines why and how that information is processed, and Frigga processes it on the Organization's behalf subject to the applicable agreement and, where used, a Data Processing Addendum ("DPA").
4. PERSONAL INFORMATION WE COLLECT
The categories we collect depend on how you interact with Frigga.
4.1 Account and Identity Information
This may include:
- name;
- work or personal email address;
- phone number;
- company or organization name;
- job title or role;
- username and account identifiers;
- authentication information;
- workspace, team, or organization membership; and
- information you provide when creating or managing an account.
4.2 Authentication and Credential Information
Frigga processes information needed to authenticate users and protect accounts. Where Frigga directly stores password credentials, those passwords are protected using one-way cryptographic hashing and are not stored in plaintext.
Where authentication is provided by a third-party identity provider, Frigga may receive identifiers, profile information, authentication tokens, or other data required to create and authenticate the account. Frigga does not require users to provide third-party passwords to Frigga unless a specific integration expressly requires credentials and the applicable documentation states how they are protected.
4.3 Technical and Device Information
We may automatically collect:
IP address;
- browser type and version;
- operating system and device type;
- device or application identifiers;
- language and regional settings;
- approximate location derived from IP or similar technical information;
- referring and destination URLs;
- timestamps and session information;
- application version;
- crash, performance, and diagnostic information; and
- security and anti-abuse events.
4.4 Usage and Activity Information
We may collect information about how the Services are used, including:
- products and features accessed;
- pages visited;
- subscription and billing activity;
- actions and configuration changes;
- search and query activity;
- workflow and task activity;
- interactions with AI Features;
- tool-call or usage volumes;
- errors, diagnostics, and performance events; and
- related account or workspace activity.
4.5 Information You Provide Directly
We may collect information you provide when you:
- create an account;
- start a trial or purchase a subscription;
- request a product demonstration;
- contact sales or customer support;
- submit a website form;
- participate in surveys or beta programs;
- provide Feedback;
- apply for employment;
- communicate with Frigga personnel; or
- otherwise interact with Frigga.
4.6 Billing and Payment Information
When you purchase a Service, we may collect billing name and address, company information, tax information, subscription details, transaction identifiers, payment status, currency, amount, payment-method type, invoices, and limited payment metadata.
Payments may be processed by authorized third-party payment processors, including Razorpay and other providers selected by Frigga. Where payment-card credentials are collected through a processor-hosted payment flow, Frigga does not receive or store complete card numbers or CVVs. The payment processor may independently process payment information under its own privacy policy and applicable financial regulations.
4.7 Support and Communications
When you communicate with Frigga, we may process emails, tickets, chat communications, meeting information, call recordings where legally permitted and appropriately disclosed, attachments, troubleshooting information, account details, and records of communications.
4.8 Recruitment Information
If you apply for a role with Frigga, we may process your CV or resume, work history, education, portfolio or profile links, skills, interview notes, assessment information, compensation expectations, references, and recruitment communications.
4.9 Business, Partner, Vendor, and Investor Information
We may process professional contact information, company or firm details, role, meeting requests, commercial communications, contract information, and related business records concerning prospective customers, partners, vendors, advisers, or investors.
5. INFORMATION FROM CONNECTED SYSTEMS
Certain Frigga Services connect to systems you authorize, including source-code repositories, cloud infrastructure, CI/CD platforms, monitoring and logging systems, incident-management systems, ticketing platforms, identity providers, security systems, cloud-cost systems, and other engineering systems.
Depending on the product and configuration, Frigga may receive or process:
- repository, branch, commit, and code-related metadata;
- build, deployment, pipeline, and artifact information;
- infrastructure and cloud-resource metadata;
- configuration information;
- logs, metrics, traces, errors, and alerts;
- incidents and on-call information;
- user, role, permission, authentication, and access-event data;
- cloud resource, billing, cost, and usage data;
- task, ticket, workflow, and project information; and
- other technical context required for enabled functionality.
The exact data depends on the permissions and integrations selected by you. Organizations are responsible for ensuring they are authorized to connect third-party systems and to provide Frigga with the resulting data.
6. OBSERVABILITY, IDENTITY, AND ACCESS DATA
Products such as Drasil, Shankh, and Dvarpala may process technical and operational data that can incidentally contain personal information, including usernames, email addresses, IP addresses, request identifiers, error messages, incident details, authentication events, access requests, approvals, revocations, roles, permissions, timestamps, audit events, or other data generated by customer systems.
Customers should configure logs, telemetry, and connected systems to avoid transmitting unnecessary personal or sensitive information.
7. AI AND MACHINE-LEARNING FEATURES
Certain Services use AI, machine learning, embeddings, retrieval systems, or other automated technologies to understand engineering context, identify relationships, improve retrieval, generate code or technical output, summarize information, provide recommendations, classify events, automate engineering tasks, or identify anomalies.
Inputs to AI-enabled functionality may include Customer Data and technical context necessary to provide the requested feature.
Unless a customer expressly opts in or a signed agreement states otherwise, Frigga does not use Customer Data to train general-purpose AI models for Frigga or unrelated third parties.
Where Frigga uses third-party AI providers, Frigga may disclose information necessary to provide the requested functionality and will use reasonable contractual and technical measures appropriate to the processing, including restrictions on independent general-purpose model training where commercially available and applicable.
AI outputs may be subject to human review by authorized users or Frigga personnel where necessary for support, safety, quality, or service delivery.
8. COOKIES AND SIMILAR TECHNOLOGIES
Frigga may use cookies, local storage, pixels, SDKs, tags, scripts, or similar technologies for authentication, security, sessions, preferences, analytics, performance, fraud prevention, and, where enabled, marketing.
Essential technologies may be used where necessary for the website or Service to function. Where applicable law requires consent for non-essential technologies, Frigga will not intentionally activate them until the required consent is obtained.
More information is provided in our Cookie Policy.
9. HOW WE USE PERSONAL INFORMATION
We may use personal information to:
Provide and Administer the Services
- create and manage accounts and workspaces;
- authenticate users;
- provide subscriptions and product functionality;
- process integrations and AI Features;
- provide customer support;
- process payments, invoices, and billing;
- administer trials, subscriptions, renewals, and cancellations; and
- deliver requested products and services.
Security, Fraud Prevention, and Reliability
- protect accounts and infrastructure;
- detect unauthorized access, fraud, abuse, or malicious activity;
- investigate security incidents;
- enforce our Terms;
- debug and monitor performance; and
- maintain backups and business continuity.
Product Improvement and Analytics
- understand how users interact with the Services;
- measure performance and reliability;
- debug and test;
- improve features and documentation;
- develop new functionality; and
- analyze aggregated or appropriately de-identified usage patterns.
Communications
- respond to inquiries;
- send account, billing, support, security, and service notices;
- provide product updates; and
- send marketing communications where permitted by law and subject to applicable opt-out or consent requirements.
Recruitment and Business Administration
- evaluate candidates;
- manage customer, partner, vendor, investor, and professional relationships;
- administer contracts and corporate records; and
- maintain accounting, tax, audit, and compliance records.
Legal and Compliance
- comply with legal obligations and lawful requests;
- protect rights, safety, and legal interests;
- establish, exercise, or defend legal claims;
- resolve disputes; and
- prevent unlawful use of the Services.
10. LEGAL BASES FOR PROCESSING
Where laws such as the GDPR or UK GDPR apply, Frigga may rely on one or more of the following legal bases:
Contract - where processing is necessary to provide requested Services or perform a contract;
Legitimate interests - including security, fraud prevention, product improvement, customer administration, and business operations, where those interests are not overridden by applicable rights;
Consent - where applicable law requires consent, including for certain marketing or non-essential cookies;
Legal obligation - where processing is necessary to comply with law; and
Vital interests or other lawful bases - where recognized by applicable law.
For individuals in India, Frigga processes personal data on lawful grounds available under applicable Indian law. As provisions of the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 become applicable to Frigga, Frigga will implement the notices, consent mechanisms, security safeguards, grievance mechanisms, rights processes, and other measures required by those provisions.
11. HOW WE SHARE PERSONAL INFORMATION
Frigga may share personal information with the following categories of recipients where reasonably necessary:
11.1 Service Providers and Subprocessors
Providers supporting cloud infrastructure, hosting, databases, authentication, analytics, monitoring, communications, email, CRM, payment processing, security, support, logging, error monitoring, AI functionality, and other business or technical operations.
11.2 Customer-Directed Integrations
Third parties where you direct Frigga to send data or enable an integration.
11.3 Professional Advisers
Auditors, insurers, accountants, legal counsel, compliance consultants, and other professional advisers subject to appropriate duties of confidentiality.
11.4 Legal and Safety Disclosures
Government authorities, courts, regulators, law-enforcement bodies, or other parties where disclosure is required by law or reasonably necessary to protect rights, safety, security, or prevent fraud and abuse.
11.5 Corporate Transactions
Potential or actual acquirers, investors, financing parties, or successors in connection with a merger, financing, acquisition, restructuring, sale of assets, or similar transaction, subject to appropriate confidentiality and applicable law.
Frigga does not intentionally disclose Customer Data publicly or to unrelated third parties for their independent marketing purposes.
12. SUBPROCESSORS
Frigga may use third-party subprocessors to provide the Services. For enterprise customers, subprocessor information and applicable notice or objection rights may be provided through a DPA, security documentation, or a maintained subprocessor list.
Frigga may update subprocessors as necessary to operate or improve the Services, subject to applicable contractual and legal requirements.
13. INTERNATIONAL DATA TRANSFERS
Frigga is based in India and provides Services internationally. Personal information may therefore be processed in countries other than the country in which it was collected.
Where applicable law requires a transfer mechanism or safeguard, Frigga will use an appropriate mechanism such as standard contractual clauses, contractual protections, adequacy mechanisms, or another legally recognized transfer basis.
Cross-border processing of personal data relating to Indian users will be subject to restrictions or requirements that are applicable to Frigga under Indian law from time to time.
14. DATA RETENTION
Frigga retains personal information only for as long as reasonably necessary for the purpose for which it was collected or for another lawful purpose, including to provide Services, maintain accounts, satisfy contractual obligations, comply with tax, accounting, security, legal, or regulatory requirements, resolve disputes, prevent fraud, and enforce agreements.
Retention periods vary by category and context. Factors include the duration of the customer relationship, the type and sensitivity of the data, contractual commitments, backup and disaster-recovery cycles, security requirements, legal limitation periods, and statutory record-retention requirements.
Frigga maintains internal retention practices and may specify customer-data deletion periods in a DPA, Order Form, product documentation, or enterprise agreement. When personal information is no longer required, Frigga will delete, anonymize, or securely dispose of it in accordance with applicable law and documented retention practices.
15. CUSTOMER DATA AFTER TERMINATION
Customer Data may remain available for a limited period after termination to support account closure, export, backups, disaster recovery, security, legal obligations, and dispute resolution.
Customers should export data they require before the applicable deletion period expires. Frigga may permanently delete Customer Data after the applicable retention period, subject to contractual commitments and law.
16. SECURITY
Frigga uses technical and organizational safeguards designed to protect personal information against unauthorized access, loss, misuse, alteration, or disclosure. Depending on the Service and context, these measures may include access controls, authentication, encryption, cryptographic protection, logging, monitoring, network security, secure development practices, vulnerability management, backup and recovery controls, incident response, employee confidentiality obligations, and third-party security requirements.
No security method can guarantee absolute security. Customers and users must also maintain appropriate account, endpoint, credential, permission, and integration security.
17. PERSONAL DATA BREACHES AND SECURITY INCIDENTS
Frigga assesses and responds to security incidents involving personal information in accordance with its incident-response procedures and applicable law.
Where legally required, Frigga will notify affected customers, individuals, regulators, or other authorities within the applicable timeframe and provide information required by law. Where Frigga acts as a processor for an Organization, incident notification and cooperation obligations may be governed by the applicable DPA.
18. YOUR PRIVACY RIGHTS
Depending on your location and applicable law, you may have rights to:
- obtain information about processing;
- access personal information;
- correct, complete, or update inaccurate information;
- request deletion or erasure;
- restrict or object to certain processing;
- obtain portable information where applicable;
- withdraw consent;
- opt out of certain marketing communications;
- object to certain automated decision-making or profiling where applicable;
- nominate another person to exercise rights where a law provides such a right; and
- lodge a complaint with a competent data-protection authority.
Rights vary by jurisdiction and may be subject to lawful exceptions.
19. HOW TO EXERCISE YOUR RIGHTS
Submit privacy requests to hello@frigga.cloud with the subject line "Privacy Request" and provide enough information for us to understand the request and reasonably verify your identity.
Frigga may request additional verification where necessary to prevent unauthorized disclosure, modification, or deletion of personal information. Frigga will respond within the timeframe required by applicable law.
Where consent is the basis for processing, you may withdraw consent through the available account or consent mechanism or by contacting us. Withdrawal does not affect processing that was lawful before withdrawal and does not prevent processing that is independently required or permitted by law.
20. ACCOUNT DELETION
Where an account-deletion mechanism is available, you may use it to request closure or deletion. You may also contact hello@frigga.cloud.
Account deletion may result in loss of access to Services and associated information. Certain records may be retained where required or permitted for law, security, fraud prevention, dispute resolution, billing, or legitimate business-record purposes.
21. MARKETING COMMUNICATIONS
Where permitted by law, Frigga may send newsletters, product updates, educational content, product announcements, and promotional communications.
You may unsubscribe using the mechanism included in the message or by contacting Frigga. Service, account, security, transactional, legal, and billing communications may continue where necessary.
22. CHILDREN'S PRIVACY
Frigga's Services are not directed to individuals under 18 years of age, and Frigga does not knowingly permit individuals under 18 to create individual user accounts unless a specific Service expressly supports such use and the required authorization or consent has been obtained.
If you believe a person under 18 has provided personal information to Frigga in circumstances not permitted by law, contact hello@frigga.cloud.
23. SENSITIVE OR SPECIAL-CATEGORY INFORMATION
Frigga does not intentionally require sensitive or special-category personal information for ordinary website, account, or subscription use unless a particular Service expressly supports such processing.
Connected logs, telemetry, customer systems, or support materials may incidentally contain sensitive information. Customers are responsible for configuring integrations to minimize unnecessary collection and to ensure they have lawful authority for the data they provide.
24. AUTOMATED DECISION-MAKING
AI Features primarily provide engineering analysis, recommendations, generated output, or automation in support of users and Organizations. Frigga does not ordinarily use website or account personal information to make solely automated decisions that produce legal or similarly significant effects on individuals, unless such processing is specifically disclosed and permitted by applicable law.
25. THIRD-PARTY LINKS AND SERVICES
The Services may contain links to or integrations with third-party services. Frigga is not responsible for independent privacy practices of third parties. Review the privacy policies of third parties before providing them with personal information.
26. CALIFORNIA AND OTHER U.S. STATE PRIVACY RIGHTS
Depending on applicable thresholds and your location, U.S. state privacy laws may provide additional rights concerning access, correction, deletion, portability, targeted advertising, sale or sharing, and certain profiling.
Frigga does not sell personal information for monetary consideration in the ordinary operation of the Services. Frigga also does not intentionally share personal information for cross-context behavioral advertising unless such activity is disclosed and any legally required opt-out mechanism is provided.
Frigga will not discriminate against individuals for exercising applicable privacy rights.
27. EEA AND UNITED KINGDOM
If the GDPR or UK GDPR applies, Frigga will process personal data in accordance with applicable controller or processor obligations, including lawful-basis, transparency, data-subject rights, processor-contract, security, and international-transfer requirements.
Where Frigga acts as a processor, the applicable DPA governs that processing. Individuals may lodge complaints with the supervisory authority applicable to them.
28. INDIA-SPECIFIC PRIVACY INFORMATION
Frigga is incorporated in India. Indian privacy and data-protection law applies to Frigga to the extent provided by law.
As provisions of the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 become effective and applicable, Frigga will provide notices and rights mechanisms required by those provisions, maintain reasonable security safeguards, support grievance redressal, and comply with applicable requirements concerning consent, processing, retention, breach response, children, processors, and cross-border transfers.
Nothing in this Policy limits rights available under mandatory Indian law.
29. COOKIE AND TRACKING CHOICES
Where a cookie preference mechanism is made available, you may use it to manage non-essential cookie and similar-technology choices. You may also use browser or device settings to block or delete cookies, although doing so may affect functionality.
Where applicable law requires prior consent for non-essential cookies or similar technologies, Frigga will provide an appropriate choice mechanism and will honor withdrawal of consent going forward.
See the Cookie Policy for details.
30. CHANGES TO THIS PRIVACY POLICY
Frigga may update this Privacy Policy periodically. Material changes may be notified through the Services, website, email, account notification, or another reasonable method.
The "Last Updated" date identifies the latest revision. Where applicable law requires consent to a material change, Frigga will obtain that consent.
31. CONTACT AND PRIVACY GRIEVANCES
For privacy questions, rights requests, or grievances, contact:
Frigga Cloud Private Limited
1st Floor, Evolve Co-working
Bengaluru, Karnataka 560048
India
Email: hello@frigga.cloud
Website: https://frigga.cloud/
Frigga's current designated consumer/privacy grievance contact and escalation details are published on the Contact Us page. Complaints and privacy requests will be handled within the periods required by applicable law.