Conversion Optimization
Frosmo
EU-Made Report an errorPanel rating · 6 judges · How to read the stars
Category median
Sovereignty: 2 of 4 dimensions proven
0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.
by Frosmo Technologies Oy · frosmo.com
Report an error on this page Is this your product? →
Read this page as one judge. Each weighs the same scores by what they care about.
The panel's verdict
Frosmo is a Helsinki-based personalisation and testing platform for e-commerce, contracted through Frosmo Technologies Oy under Finnish law with arbitration in Helsinki. The bench scores it strongest on sovereignty, range 4-6: the growth lead gave 6 for the Finnish entity, the attached data processing annex and named Amazon S3 in Europe and Cloudfront outside Europe, while four judges held at 4 because the captured no-transfer statement covers the Frosmo sites rather than customer deployments. Experimentation scope follows at 3-4, on homepage documentation of client-side A/B testing, rule-based targeting, real-time segmentation and personalisation placements. The floor is statistical rigour, scored 0 with no public information naming a method that decides a winner; consent and tracking sits at 1, with no public information on when the script runs relative to consent. Performance impact splits 0-1 over the same gap — no published script size, flicker handling or Core Web Vitals figures. No prices appear on any captured page; the terms fix EUR billing mechanics and a defined Monthly Sessions metric.
Speaks for it
- Sovereignty scored highest of the criteria at 4-6, on a Finnish contracting entity, Helsinki arbitration and a data processing annex attached to the agreement.
- Experimentation scope scored 3-4, with client-side A/B testing, rule-based targeting, real-time segmentation and personalisation placements documented on the homepage.
- Customer data remains the property of the customer under the terms of service.
- The terms define an API and JavaScript tags for integration, and the homepage claims compatibility with any CDP or CRM using Google's data standards.
Held against it
- Statistical rigour scored 0, with no public information naming a statistical method, sample-size guidance or protection against reading a test early.
- Consent and tracking scored 1, with no public information on what the platform script stores on visitors' devices or when it runs relative to consent.
- Performance impact scored 0-1, with no published script size, loading behaviour, flicker handling or Core Web Vitals figures.
- Data and integrations scored 2-3, with no public information on exporting visitor-level results or a documented API for reading experiment results.
- No price figures appear on any captured page, though the terms define the Monthly Sessions metric, under which a visit ends after 30 minutes of inactivity.
Best for
- You run an e-commerce or iGaming site and want on-page personalisation — placements, rule-based targeting, real-time segmentation — alongside client-side A/B testing.
- Your procurement requires a Finnish contracting entity, Finnish governing law, Helsinki arbitration and a data processing annex in the agreement.
- Your marketing team wants a no-code interface for building targeting and recommendation strategies without engineering work.
Avoid if
- You must defend a test's winner to an analytics or finance team with a named statistical method, intervals and sample-size guidance.
- Your data protection officer needs documented script behaviour on visitors' devices before and after consent, as German operators face under the TDDDG.
- Your page-speed budget requires published script-size or Core Web Vitals figures before a snippet can ship.
- You need to export visitor-level results or re-run experiment numbers in your own warehouse or analytics.
The scores
Experiment types & delivery
Show reasoningHide reasoning
How this is scored
What can be tested and where: client-side changes through an editor, server-side and feature experiments through SDKs, multivariate and multi-page tests, and personalisation — judged on what the documentation shows rather than on the feature grid.
0 — Simple A/B split of one page element through a visual editor; no server-side option, no targeting beyond URL.
3 — Client-side A/B and split-URL tests with basic audience targeting, and no SDK or server-side delivery.
5 — Client-side and server-side experiments through documented SDKs for common languages, multivariate and multi-page tests, audience targeting on behaviour and attributes, and rule-based personalisation.
8 — Feature-flag-based experiments sharing one audience and metric model with web tests, mutually exclusive experiment groups, holdouts, edge or CDN delivery, and personalisation that can itself be tested against a control.
10 — One experimentation programme across every surface: web, app, server and edge from the same platform, experiment interactions managed, a documented experiment lifecycle from hypothesis to archived result, and a library of past results a team can search.
The Growth Lead
The captured pages show client-side A/B testing together with rule-based targeting, real-time behavioural segmentation and placements that personalise any site element, which is more than a single-element split. But everything rests on a homepage capability list; we found no public information on server-side SDKs, feature flags, or multivariate and multi-page tests in the captured pages, even though a documentation portal is referenced in the terms. 1 3
The E-Commerce Manager
The homepage lists A/B testing alongside rule-based content and product targeting, dynamic segmentation on real-time data, personalised placements on any site element, and a no-code UI for building strategies — real personalisation capability on paper. I found no public information on server-side or SDK delivery, multivariate and multi-page tests, holdouts, or whether a personalisation can be run against a control group, which is exactly the proof I would need before trusting it on my product pages. 1 3
The Product Engineer
The homepage sells "AI-driven, automated optimization and A/B testing", rule-based targeting and placements that can personalise any element of the site — a client-side testing and personalisation pitch. We found no public information on server-side SDKs, feature flags, edge delivery or mutually exclusive experiments, and the captured pages never open the public documentation portal the terms point to. As far as I can see this is script-on-page testing with behavioural targeting, and nothing more. 1 3
The CRO Consultant
Personalisation is clearly the core sell — placements, rule-based targeting, real-time segmentation, with A/B testing named as one AI-driven bullet — but all of it is homepage marketing copy, and the terms point to a documentation portal whose contents were not captured. I found no public information on a visual editor, server-side or SDK delivery, multivariate or multi-page tests, holdouts, or mutually exclusive experiments. That supports an on-page personalisation programme, not a mixed web and server-side roadmap. 1 3
The Data Protection Officer
The homepage documents A/B testing, rule-based targeting and dynamic segmentation of visitors based on real-time data, with personalisation through a no-code interface and placements on any site element. We found no public information on server-side delivery, SDKs, multivariate or multi-page tests, feature flags or holdouts, so on the evidence captured delivery appears client-side only. 1 3
The Skeptic
The homepage markets client-side A/B testing, rule-based and real-time visitor targeting, placements, personalised search and recommendations through a no-code UI, which sits above a plain split test. We found no public information on server-side or SDK delivery, feature flags, holdouts or mutually exclusive experiment groups, and the API in the terms is defined for integrating customer applications rather than as documented experiment delivery. 1 3
Statistical method & guardrails
Show reasoningHide reasoning
How this is scored
Which statistics decide the winner and what protects the customer from misreading them. Scored on what the vendor documents: the method by name, how peeking and multiple comparisons are handled, and whether sample ratio mismatch is detected.
0 — A "winner" or "probability to beat" figure with no documented method, no stated sample-size guidance and no warning against stopping early.
3 — The method is named (frequentist or Bayesian) but its assumptions are not documented, and nothing prevents a test from being called while it is still underpowered.
5 — Documented method with confidence or credible intervals, a sample-size or test-duration calculator, and stated guidance on when a result may be read.
8 — Sequential testing or an equivalent documented protection against peeking, correction for multiple metrics or variants, sample ratio mismatch detection, variance reduction such as CUPED, and guardrail metrics that can stop a harmful test.
10 — The statistics are auditable: methodology published in enough detail to reproduce a result, the choice of method explained per use case, raw per-visitor data available for independent re-analysis, and the interface refuses to present an underpowered result as a conclusion.
The Growth Lead
We found no public information on how a winning variant is decided: no named method, no sample-size or duration guidance, and no warning against stopping a test early. The only related language is "AI-driven, automated optimization and A/B testing" and "Reporting – total transparency", and I cannot defend a revenue claim to finance on copy that names no method. 1
The E-Commerce Manager
The only statistical statements on the captured pages are "AI-driven, automated optimization and A/B testing" and "Reporting – total transparency" — no method named, no intervals, no sample-size guidance, nothing on early stopping or sample ratio checks. I found no public information on how a winner is decided, so I cannot tell whether a result is safe to act on. 1
The Product Engineer
The only statistics-adjacent language anywhere is "AI-driven, automated optimization and A/B testing", and we found no public information naming a method, giving sample-size or duration guidance, or addressing peeking and multiple comparisons. Without a documented way a winner is decided, an experiment result from this platform is a claim I cannot reproduce or defend. 1
The CRO Consultant
Nothing captured names a statistical method, offers sample-size guidance, or warns against reading a test early; the closest I get is a "total transparency" claim about reporting on the homepage. With no documented method, I have nothing to defend to a client's analytics team. 1
The Data Protection Officer
We found no public information on the statistical method, sample-size or test-duration guidance, intervals, or any protection against peeking; sample ratio mismatch detection is likewise unevidenced. The captured pages describe reporting as "total transparency" without stating which statistics decide a winner or when a result may be read. 1 3
The Skeptic
I read for the method and found none: the pages offer 'AI-driven, automated optimization and A/B testing' and reporting with 'total transparency', and we found no public information naming a statistical method, sample-size guidance, protection against peeking, sample ratio mismatch checks or correction for multiple comparisons. Automated optimisation without a documented method is marketing, and I score it as such. 1
Consent & visitor tracking
Show reasoningHide reasoning
How this is scored
Whether the test script respects §25 TDDDG and the ePrivacy rules as evidenced on the vendor's own pages: when the script runs relative to consent, what it stores on the device, whether a cookieless or consent-free mode exists, and how visitor identifiers are handled.
0 — Nothing on the vendor's pages says what the script stores on the device or whether it runs before consent; consent is described as the customer's problem.
3 — Cookies or local storage are listed, and a consent integration is mentioned, but the documentation does not say what the script does before consent is given.
5 — Documented behaviour before and after consent, integration with common consent management platforms, a published list of cookies and storage keys with their lifetime, and IP anonymisation described.
8 — A documented consent-pending mode that holds tracking until consent while variants can still be served, a cookieless or first-party-only option, retention of visitor data stated, and guidance on the legal basis for testing in the EU.
10 — Built for §25 TDDDG: the default configuration stores nothing on the device without consent, a server-side or cookieless mode documented end to end, per-visitor data deletable on request, and the vendor states in writing how each mode maps to consent requirements.
The Growth Lead
Nothing in the captured pages says what the testing script stores on a visitor's device or whether it runs before consent; the statement about not collecting personal data by default covers the Frosmo sites, and the consent tool named (Usercentrics) is listed for Frosmo's own website rather than documented as a platform integration. For deployment in Germany under the TDDDG I need documented behaviour before and after consent, and we found no public information on it. 2
The E-Commerce Manager
The captured privacy policy describes the vendor's own website — no personal data collected by default there, EU/ETA users kept within the region, Usercentrics handling consent on their own pages — and the terms include a data processing annex. I found no public information on what the platform script stores on my visitors' devices, when it runs relative to consent, or on any cookieless or consent-pending mode. 2 3 1
The Product Engineer
The privacy policy covers frosmo.com itself — personal data is stated as not collected by default there and a consent tool runs on the site — but we found no public information on what the tracking script stores on a customer's visitors or when it runs relative to consent. A data processing annex is referenced in the terms, with no captured content showing it documents the script's on-device behaviour. As evidenced, working out consent compliance is left entirely to the customer. 2 3
The CRO Consultant
The privacy policy speaks to Frosmo's own sites — no personal data collected there by default, Usercentrics handling consent on frosmo.com — and the customer contract includes a data processing annex. But I found no public information on what the platform script stores on a customer's visitors, when it runs relative to consent, or how visitor identifiers are handled, which is exactly what a DPO will ask me. 2 3
The Data Protection Officer
I have to answer whether the test script may run before the consent banner is answered, and we found no public information on this, nor any published list of cookies or storage keys for the platform script — exactly what a German operator must know under §25 TDDDG. The consent management tool named in the privacy policy serves the vendor's own website, and the statements about not collecting personal data by default are scoped to the Frosmo sites, not to the customer's visitors. 2
The Skeptic
The privacy policy speaks to the Frosmo sites themselves, where the vendor states no personal data is collected by default and a consent tool runs, but we found no public information on what the testing script stores on a customer's visitors' devices, when it runs relative to consent, or how visitor identifiers are handled. A data-processing annex in the terms covering personal data is the only documented hook. 2 3
Snippet performance & flicker
Show reasoningHide reasoning
How this is scored
The cost the client-side snippet imposes on the page it tests: blocking load, flicker of original content, script weight and the effect on Core Web Vitals — scored on what the vendor measures and publishes, not on "lightning fast".
0 — A synchronous snippet with no stated size, no flicker handling and no mention of performance.
3 — An anti-flicker snippet that hides the page until the test loads, with a timeout, and no published figures for script size or load cost.
5 — Script size and loading behaviour documented, asynchronous loading option, flicker handling explained with its trade-off, and CDN delivery of the snippet.
8 — Published performance figures including impact on Core Web Vitals, a self-hosting or first-party-domain option for the script, per-project bundles containing only active experiments, and a server-side or edge alternative for flicker-sensitive tests.
10 — Performance is a stated commitment: measured overhead published and maintained, flicker eliminated by edge or server-side rendering as a documented path, and tooling that shows the customer what their own configuration costs the page.
The Growth Lead
We found no public information on snippet size, loading behaviour, flicker handling, or any measured effect on Core Web Vitals. The only signal that a script exists is a contract clause in which the customer undertakes not to modify the JavaScripts, which says nothing about what the script costs the page. 3
The E-Commerce Manager
The platform ships as JavaScript tags per the terms, and I found no public information on script size, loading behaviour, flicker handling or any measured effect on Core Web Vitals. On a shop where a tenth of a second shows in the conversion rate, an unevidenced snippet is a risk I price in, not out. 3
The Product Engineer
We found no published figures for script size, load cost or Core Web Vitals impact, and no public information on any anti-flicker handling. The only delivery evidence is the terms naming Amazon S3 in Europe and Cloudfront outside Europe, alongside a clause barring the customer from modifying the JavaScript — so the team running the tests cannot even tune the snippet's cost themselves. 3
The CRO Consultant
The terms mention Javascripts as part of the platform, but I found no public information on script size, loading behaviour, anti-flicker handling, or any Core Web Vitals figures. Nothing measured and published means nothing a client can hold the vendor to. 3
The Data Protection Officer
We found no published script size, loading behaviour, flicker handling or Core Web Vitals figures on the captured pages. The only delivery-adjacent fact is the terms' mention of CloudFront use outside Europe, which does not document how the snippet loads on the customer's page. 1 3
The Skeptic
The terms define Javascript tags as the integration mechanism and name Amazon S3 in Europe and Cloudfront elsewhere as cloud infrastructure, but we found no public information on script size, loading behaviour, flicker handling or any measured effect on Core Web Vitals. Without a published figure, what the snippet costs a page is an open question. 3
Analytics, data export & integrations
Show reasoningHide reasoning
How this is scored
Getting results and raw data out: integration with analytics and tag management, export of visitor-level results, warehouse-native analysis, and an API — because an experiment result that cannot be checked in the customer's own data is a claim, not a finding.
0 — Results visible in the vendor's dashboard only; no export, no analytics integration, no API.
3 — CSV export of aggregated results and one analytics integration, with no visitor-level data and no documented API.
5 — Integrations with common analytics and tag managers, export of results, and a documented API for managing experiments and reading results.
8 — Visitor-level raw data export or streaming to a data warehouse, warehouse-native analysis on the customer's own metrics, CDP integration for audiences, and an API with stated limits.
10 — The platform treats the customer's warehouse as the source of truth: metrics defined once and computed there, full historical experiment data exportable in open formats, and a versioned API a team can build its own programme tooling on.
The Growth Lead
The terms define an API for integrating customer applications with the platform, the homepage lists commerce platforms such as Shopify and Magento, and claims integration with any CDP or CRM using Google's data standards — but these are claims and contract definitions rather than documented integrations. We found no public information on export of results, visitor-level data, or a documented API for reading experiment results, so I could not check a Frosmo uplift in our own analytics. 1 3
The E-Commerce Manager
The terms define an API and JavaScript tags for integrating my applications with the platform, and the homepage claims it integrates with any CDP or CRM. I found no public information on exporting visitor-level results, streaming data to a warehouse, or a documented API for reading experiment results, so I could not verify a test's outcome in my own analytics. 3 1
The Product Engineer
The terms define an API for integrating customer applications and the homepage claims it works with any CDP or CRM on Google's data standards, but we found no documented API for reading results, no export path and no visitor-level data. "Reporting – total transparency" is a marketing line, not a data contract. I could not re-run an experiment's numbers in my own warehouse on any of this evidence. 1 3
The CRO Consultant
An API is named in the terms strictly for integrating the customer's applications, and the homepage claims integration with any CDP or CRM, Google-standard data tracking, and connectors for the common ecommerce platforms. But I found no public information on results export, visitor-level data, warehouse delivery, or an API for reading experiment results, so I cannot see how to check a finding in the client's own data. 1 3
The Data Protection Officer
The terms define an API for integrating customer applications, and the homepage claims integration with any CDP or CRM using Google's data standards, but these are contractual and marketing statements rather than documentation. We found no public information on result export, visitor-level data access, or warehouse-native analysis. 1 3
The Skeptic
The terms define an API and Javascript tags for integration, the homepage claims compatibility with any CDP or CRM and Google's data standards, and customer data ownership is contractual. We found no public information on documented API endpoints, exports of visitor-level results or warehouse delivery, so on this evidence I see no path shown for checking an experiment result in the customer's own data. 1 3
European sovereignty
panel opinion
Show reasoningHide reasoning
How this is scored
Where visitor data is processed and stored and who the contracting entity is. Independently sourced by the sovereignty pipeline; weighted higher here than in categories that hold only the customer's own data, because the script runs on every visitor to the customer's site and their behaviour is what the platform records.
0 — Non-EU vendor and contracting entity, hosting unstated, subprocessors unnamed, and visitor data leaving the EU without a stated safeguard.
3 — EU data residency offered as an option or an enterprise add-on while the contracting entity is non-EU, or the subprocessor list is absent.
5 — EU processing of visitor data as standard and an EU contracting entity, but parts of the chain — CDN, support access, analytics — are non-EU without an explained safeguard.
8 — EU hosting on named infrastructure including the delivery of the snippet, EU contracting entity, subprocessor list published, and a DPA covering the visitor data the script collects.
10 — Sovereign end to end and evidenced: vendor, entity, hosting, snippet delivery and every subprocessor European, certification published, and no visitor data reaching a non-EU party at any point.
The Growth Lead
The contracting entity is Finnish with Finnish law, Helsinki arbitration, a data processing annex attached to the agreement, and named infrastructure — Amazon's S3 service in Europe and Cloudfront outside Europe — alongside a statement that EU/EEA users' personal data does not leave the EU/EEA. What holds this back is that the no-transfer statement covers the Frosmo sites and user interfaces rather than the customer platform's visitors, and the same policy indicates third-party processing may take place in the US, so the delivery chain on every visitor of ours is not documented end to end. 2 3
The E-Commerce Manager
The terms give a Finnish contracting entity under Finnish law with arbitration in Helsinki, name Amazon S3 in Europe for storage with Cloudfront used outside Europe, and include a data processing annex. The no-transfer statement I found covers users of the vendor's own sites rather than my shop's visitors, and I found no public information on where the platform processes visitor data, which infrastructure delivers the script to EU visitors, or any certification. 3 2 1
The Product Engineer
Frosmo Technologies Oy contracts under Finnish law with arbitration in Helsinki, a data processing annex exists, and the terms name Amazon S3 in Europe and Cloudfront outside Europe as infrastructure. We found no public information on where the platform hosts the visitor data the script records on customer sites — the privacy policy's promise of no transfers outside the EU/EEA speaks about the Frosmo sites and user interfaces, not customer deployments. An EU entity with a partially named chain and unlocated visitor data is not a sovereignty story I can build on yet. 2 3
The CRO Consultant
The captured pages give a Finnish contracting entity under Finnish law with arbitration in Helsinki, name Amazon's S3 for storage in Europe and Cloudfront for use outside Europe, and include a data processing annex. The only no-transfer statement captured is scoped to users of Frosmo's own sites and interfaces, the non-European CDN component appears without an explained safeguard, and I found no published certification or complete subprocessor list for the platform chain. 2 3
The Data Protection Officer
The contracting side is Frosmo Technologies Oy under Finnish law with arbitration in Helsinki, and a Data Processing Annex exists as part of the agreement, which is a good start. But the only infrastructure statement places Amazon S3 in Europe and CloudFront outside Europe, we found no public information on where platform visitor data is processed, and the privacy policy's no-transfer statement is scoped to the Frosmo sites and user interfaces rather than the customer's visitors — so the chain including the CDN is not shown to stay in the EU. 2 3
The Skeptic
The contracting entity is Frosmo Technologies Oy under Finnish law with arbitration in Helsinki, the terms name Amazon S3 in Europe and Cloudfront outside Europe, and a data-processing annex covers personal data. Residency for the customer's visitor data is not confirmed on the captured pages — the no-transfer statement in the privacy policy covers users of the Frosmo sites — and we found no public information on certification. 2 3
Pricing transparency
not rated — the vendor publishes no price
Show reasoningHide reasoning
How this is scored
A category priced by traffic — monthly tracked users, visitors or impressions — where the tier a site lands in depends on numbers the buyer has to estimate. Whether a buyer can compute the real annual cost including traffic limits, overage, server-side or personalisation modules and seats — from public pages alone.
0 — No public prices at all; every tier is a sales conversation.
3 — A starting price or a free tier exists, but the traffic metric, the limits and what happens above them are unstated — the invoice is unknowable.
5 — Tier prices public with the traffic metric and its limits defined, but at least one commonly needed piece (server-side SDKs, personalisation, overage) is unpriced or "contact sales".
8 — Every tier priced publicly with the traffic metric defined, limits, overage rates, module prices, minimum term and VAT treatment stated.
10 — Complete price computability: annual invoice derivable for a given traffic volume, set of modules and team size, with overage and every add-on published.
The Growth Lead
We found no public price figures in the captured pages, so every tier is a sales conversation, though the terms do pin down the commercial mechanics: prices quoted and payable in EUR, VAT excluded and paid by the customer, 30 days net, fees based on services purchased rather than actual usage, and a defined "Monthly Sessions" visit metric. Without a single published price point I cannot estimate the annual invoice for our traffic volume, let alone budget it for the board. 3
The E-Commerce Manager
No price figures of any kind appear on the captured pages — every tier is a sales conversation — even though the terms publish the mechanics: prices quoted in EUR and exclusive of taxes, fees based on services purchased rather than actual usage, thirty-day proration, and three months' notice for increases. The "Monthly Sessions" metric is at least defined precisely (a visit ends after thirty minutes of inactivity or cleared browser data), but with no tier prices, limits or overage rates published I cannot estimate my annual invoice at any traffic level. 3 1
The Product Engineer
We found no public prices at all — no public information on tiers, a starting price or a free tier — only contract mechanics in EUR: fees based on services purchased rather than usage, VAT-exclusive, thirty days net, with three months' notice of increases. The one useful public definition is the billing metric, monthly sessions as visits registered by the platform, though no public price attaches to it, so the annual invoice is unknowable from these pages. 3
The CRO Consultant
No prices appear on any captured page, so every tier is a sales conversation. The terms do define the traffic metric precisely — a monthly session ends after 30 minutes of inactivity — alongside EUR invoicing, 30 days net payment and VAT-exclusive fees, which tells me the metric and the payment mechanics but not one euro I could put in a budget. 1 3
The Data Protection Officer
We found no public prices at all, so every tier is a sales conversation and a buyer cannot estimate an invoice from public pages. The terms do define the billing metric, "Monthly Sessions" as visits ending after 30 minutes of inactivity, state that all prices are quoted and payable in EUR and are exclusive of all applicable taxes, and set the payment terms — but no tier price, limit or overage rate is published. 3
The Skeptic
We found no public information on tier prices, traffic limits, overage rates or module prices, so the real annual cost stays a matter for the sales conversation. What the terms fix is mechanics only: prices quoted in EUR, 30 days net, VAT-exclusive, non-refundable, fees based on services purchased rather than actual usage, and three months' notice of increases. 3
European sovereignty — proven facts
2 of 4 dimensions provenBuilt only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.
| Legal entity | Incorporated in FI | 3/3 pts | 2 Report an error |
|---|---|---|---|
| Ownership | Not determined | — | uncited Report an error |
| Data residency | Not determined ⚠ unverified | — | uncited Report an error |
| Subprocessors | US CLOUD Act reach ⚠ unverified | 0/2 pts | 4 Report an error |
Where this could be wrong
- Evidence ages. The oldest capture behind this page is from 22 Sep 2026. Vendors change pricing and policies without notice; every fact reflects its source as of the capture date shown in the registry.
- Weak sourcing — Data residency. Not confirmed on the vendor’s own pages as captured.
- Weak sourcing — Subprocessors. The US parent Amazon Web Services, Inc. is named directly rather than an EU contracting entity, and no server region is given, though the same annex bars transfers outside the EU/EEA without the customer's written consent.
- AI can misread a source. Extraction and judgement are automated; a citation guarantees traceability, not infallibility. If something here is wrong, say so — no account needed, every report is decided within 5 business days, and accepted corrections are published.
What we left out
A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.
- 6 compliance facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 6 legal facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 2 subprocessors facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 1 pricing fact could not be confirmed on the vendor’s page as captured and was left out of this page and of the panel’s material. Know more? Tell us
- 1 product fact could not be confirmed on the vendor’s page as captured and was left out of this page and of the panel’s material. Know more? Tell us
- 1 sovereignty dimension could not be confirmed on the vendor’s own pages and is shown as unknown. Know more? Tell us
- 6 of the readings below were written against an earlier fact sheet — a fact has been corrected, added or pulled since. Until the panel next runs on this product you are reading the older judgement. Know more? Tell us
Sources (6)
The pages every claim on this page was read from — each one checked, dated, and kept verifiable.
- 1 Vendor homepage frosmo.com Checked 22 Sep 2026 Details →
- 2 Privacy policy frosmo.com Checked 22 Sep 2026 Details →
- 3 Terms of service frosmo.com Checked 22 Sep 2026 Details →
- 4 Data processing agreement (dpa) frosmo.com Checked 30 Sep 2026 Details →
- 5 Experiment types & delivery — found from sitemap frosmo.com Checked 1 Oct 2026 Details →
- 6 Experiment types & delivery — found from sitemap frosmo.com Checked 1 Oct 2026 Details →