Data Location and Export
Last updated: September 16, 2026
This page publishes the information referred to in Section 11.4 of the Terms and Conditions and required by Articles 26 and 28 of Regulation (EU) 2023/2854 (the Data Act): where Frontierz stores and processes data, the measures that protect that data against unlawful access by authorities outside the European Union, and the formats, interfaces and procedure available to a customer that exports its data or switches to another provider. It is maintained by Founderz AI, S.L., trading as Frontierz, Carrer Pau Vila 13-15, 2-4, 08174 Sant Cugat del Vallès, Barcelona, Spain.
It describes the standard deployment of Frontierz Studio, AI Fellows, Learning Paths and related services. A customer's Order or data processing agreement may specify different arrangements, which then prevail. The Privacy Policy explains personal-data processing; Schedule 1 of the Terms and Conditions sets out Frontierz's obligations as processor.
1. Where data is stored and processed
Frontierz runs on Microsoft Azure in the regions below. All of them are located in the European Union, and the infrastructure in each is subject to Union law and to the law of the Member State named.
| Azure region | Country | Use |
|---|---|---|
| West Europe | Netherlands | Production and staging environments, databases, file storage, backups and this website. Primary location of stored service data, including accounts, Knowledge Base files, transcripts, assessments, reports and certificates. |
| North Europe | Ireland | Geo-redundant replicas of production data, maintained for resilience and recovery. |
| Sweden Central | Sweden | AI Fellow inference on Azure AI Foundry, the Frontierz AI safety resources (key management, storage and machine-learning workspaces) and AI configuration data. |
| France Central | France | Replica of the Sweden Central AI resources, providing redundancy for inference. |
Live voice audio, camera snapshots and screen frames travel between the user's browser and the AI resources in Sweden Central or France Central for the duration of the session and are not stored as recordings. Where the Order provides customer-managed AI (BYOAI), inference instead uses the Azure resources the customer designates; the other locations above continue to apply to platform hosting and stored records.
Application performance monitoring, error monitoring, the optional WebRTC relay and website form handling are performed by the providers identified in the Privacy Policy. They receive technical telemetry, connection metadata or website inquiries, not learning records or Knowledge Base content. Customer billing is handled by Frontierz through invoices, purchase orders and bank transfer; no online payment processor receives customer data. Their legal entities, processing locations and transfer safeguards are stated in the customer's data processing agreement and subprocessor list and are available on request from rgpd@founderz.com.
Frontierz shall inform customers in advance, in accordance with Schedule 1 of the Terms and Conditions, before stored service data is moved to a region in another country.
2. Protection against unlawful third-country access
Article 28(1)(b) of the Data Act requires a description of the measures that prevent access to, or transfer of, data held in the Union by authorities of a non-EU country where that access or transfer would conflict with Union or Member State law. Frontierz applies the following measures.
- EU establishment and hosting. Founderz AI, S.L. is established in Spain. Service data is stored only in the EU regions listed above, operated by Microsoft under its Azure Product Terms and Data Protection Addendum, which set out Microsoft's commitments on the handling of government requests for customer data.
- Encryption. Data is encrypted in transit with TLS 1.2 or higher and at rest by the Azure storage platform. Voice media on the primary WebRTC path is encrypted between the browser and the Azure realtime endpoint using DTLS-SRTP.
- Access control. Production access is limited to authorized Frontierz personnel through managed identities with multi-factor authentication, is logged and is scoped by tenant. Frontierz establishes no inbound connections to customer networks.
- Handling of authority requests. Frontierz does not grant any non-EU authority direct access to service data. If Frontierz receives a request or decision from a non-EU court or authority for access to or transfer of data held in the Union, it shall verify the legal basis, seek review by the competent body where the request conflicts with Union or Member State law, disclose only the minimum data the request lawfully requires and inform the affected customer before any disclosure unless legally prohibited. Where an international agreement, such as a mutual legal assistance treaty, governs the request, Frontierz shall follow that procedure.
- No unauthorized transfers. Under Schedule 1 of the Terms and Conditions, Frontierz transfers customer personal data outside the European Economic Area only on the customer's documented authorization and under a valid Chapter V GDPR mechanism.
3. Export formats and interfaces
This section is the register of data structures, formats and interfaces in which exportable data is available, as required by Article 26(b) of the Data Act. Customer administrators can perform the exports below in Frontierz Studio at any time, subject to their role; Managers are limited to their assigned Learning Paths and AI Fellows. Route names follow the current Frontierz Admin Manual.
| Data | Route in Frontierz Studio | Format |
|---|---|---|
| Conversation transcripts and metadata for an AI Fellow | AI Fellow monitor, Conversations, Export all | ZIP archive containing conversations.csv (Conversation UUID, AI Fellow, Channel, Messages, Total minutes, Started at, Last message at) and one CSV per conversation with Role, Content and Time columns. User identity columns are omitted; transcript text is exported as stored. |
| Learning Path progress and assessment data | Learning Path, Manage Users, Export Data | CSV with per-user progress, session and objective completion and assessment data for that Learning Path. |
| Access list and activity for a private AI Fellow | AI Fellow, Manage Users, Export CSV | CSV listing the users with access and their activity columns. |
| Authored Learning Paths | Learning Path dashboard, Actions, Export | Frontierz Learning Path file (.frontierz.json, JSON): name, language, tags, global objectives, session notes, Fellow Sessions, badges, info screens, objectives, path and session knowledge text, AI Simulations and communication settings. Enrollments, progress, reports, custom Connector attachments, SCORM sessions and original knowledge file binaries are not included. |
| AI-written reports (Learning Path, AI Fellow and user reports) and practice feedback | Report, Actions, Print Report or Save as PDF | PDF, through the browser print dialog. |
| Completion certificates | Certificate page, Actions, Download as PDF or Export to LinkedIn | PDF; LinkedIn certification entry. |
| Connector execution logs | Connectors Library, Connector, Executions | Timestamp, input, response and status, viewable per execution in Studio; supplied as CSV or JSON in the exit export. |
| User directory | Access Management; SCIM 2.0 where enabled | CSV in the documented import layout (Name, Surname, Email); where provisioning is enabled, SCIM GET /Users returns the account inventory as SCIM JSON. |
| Knowledge Base files, session files and imported SCORM packages | Returned in the exit export | Original uploaded formats (PDF, Word, PowerPoint, Excel, CSV, text, Markdown, images, audio and video; SCORM .zip). |
At exit, and on request during the contract, Frontierz assembles the data listed in Section 11.3 of the Terms and Conditions as CSV and JSON files, with uploaded files in their original formats, and transfers it over an encrypted channel. The export includes the identifiers needed to relate users, conversations, sessions, objectives and assessments to one another. Frontierz source code, model weights, internal platform architecture and other customers' data are excluded.
Formats and interfaces follow open specifications: CSV (RFC 4180), JSON (RFC 8259), PDF, SCORM 1.2 and SCORM 2004, LTI 1.3 Advantage for LMS launch and grade passback, SCIM 2.0 (RFC 7643 and RFC 7644) for provisioning where enabled, and HTTP or MCP for custom Connectors.
4. Switching procedure and known limitations
The contractual switching rights are set out in Section 11 of the Terms and Conditions. In practice the process runs as follows.
- Notice. The customer gives written notice of switching, transfer to its own infrastructure or erasure. The notice period is at most two months. Each party appoints an exit coordinator.
- Planning. At the start of the notice period the parties confirm the data in scope, the formats, the destination and the migration approach.
- Export and transfer. Frontierz delivers the export described in Section 3 over an encrypted channel and confirms completeness and integrity with the customer. Administrators may also run the Studio exports themselves at any time.
- Transition. The transition period is thirty calendar days, extendable once at the customer's request. Frontierz maintains the contracted service, security and support throughout.
- Retrieval and erasure. A retrieval period of at least thirty calendar days follows transition. Frontierz then erases the customer's data, including backups under their expiry lifecycle, revokes access, removes identity federation and issues written confirmation of erasure.
Known limitations:
- AI Fellow configurations, AI Simulations and Learning Paths export in the Frontierz Learning Path format. Another provider can read the JSON, but reproducing the same session behavior depends on that provider's own AI models and features. Functional equivalence of AI-generated behavior cannot be guaranteed.
- Custom Connector definitions are exported as configuration records (endpoint, fields and settings) without credentials, which the customer re-enters at the destination.
- Assessments, feedback and reports written by AI Fellows are exported as text. They are not regenerated at the destination.
- Certificates already issued remain valid documents, but their public links stop working once the workspace is erased. Download or archive them before erasure.
- Until January 12, 2027 any switching charge must be stated before contracting and may cover only directly attributable costs; from that date no switching or data-egress charge applies.
5. Contact and updates
Requests for exports, switching support or the current subprocessor list may be sent to hello@frontierz.com. Personal-data questions may be sent to rgpd@founderz.com. This page forms part of the pre-contractual information referred to in Section 11.4 of the Terms and Conditions. Frontierz updates it when hosting regions, providers, export formats or the switching procedure change, and shows the revision date above.