Overview and scope
Framer B.V. ("Framer", "we", "our") provides an enterprise AI platform that helps customer support teams triage tickets, generate replies and analyse conversations. This policy covers personal data we process as a data controller for our website visitors, marketing contacts and account administrators, and describes our role as a data processor for customer content submitted to the platform by our business customers.
Where we act as a processor, our processing is governed by the Data Processing Addendum (DPA) executed with the customer, and this policy is provided for transparency only.
Data we collect
We collect three broad categories of information:
- Account data — name, business email, password hash, workspace name, billing address and role assignments.
- Usage data — pages visited, feature interactions, device and browser metadata, IP address, approximate location derived from IP, and diagnostic logs.
- Customer content — support tickets, knowledge base articles, macros, chat transcripts and attachments that our customers upload or connect to the platform through supported integrations.
We do not intentionally collect special categories of personal data (health, biometric, political opinions, etc.). Customers are contractually required not to send such data unless a specific written arrangement is in place.
How we use personal data
- To provide, secure and improve the Framer platform.
- To bill customers, process credit purchases and prevent fraud.
- To respond to sales, security and support enquiries.
- To send transactional emails (invoices, security alerts, service updates).
- To send product news and marketing where you have opted in or where allowed by soft opt-in rules.
- To meet legal, tax and regulatory obligations.
Legal bases (GDPR / UK GDPR)
- Performance of a contract — to deliver the service you or your employer purchased.
- Legitimate interests — to secure the platform, prevent abuse and improve the product, balanced against your rights.
- Consent — for optional analytics, marketing cookies and marketing emails to consumer contacts.
- Legal obligation — for tax, accounting and lawful requests from regulators.
AI processing and training
Framer uses large language models to summarise tickets, retrieve knowledge and draft replies. We do not use customer content to train foundation models. Model providers used to serve inference are contractually restricted from retaining prompt or completion data beyond what is required to return the response.
Customers can turn off individual AI features in workspace settings. Where regional processing is required (e.g. EU-only inference), an eligible plan and region must be selected before enabling AI features.
International transfers
Framer operates from the European Union and the United States. Where personal data is transferred outside your region, we rely on the European Commission's Standard Contractual Clauses, the UK IDTA, adequacy decisions where available and additional technical measures such as encryption in transit and at rest.
Data retention
- Account data — kept while the account is active and for up to 24 months after closure, unless a longer statutory period applies.
- Customer content — retained per the customer's workspace configuration; deleted or exported within 30 days of a verified deletion request.
- Billing records — retained for the period required by tax law (typically 7–10 years).
- Server logs — retained for up to 90 days for security investigations.
Security
We apply role-based access controls, encryption in transit (TLS 1.2+) and at rest (AES‑256), continuous vulnerability scanning, mandatory MFA for staff, hardware security keys for privileged access and independent penetration testing at least annually.
No online service can be guaranteed 100% secure. We publish material security incidents to affected customers without undue delay in line with our contractual and regulatory obligations.
Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict or object to processing of your personal data, to portability, and to withdraw consent. To exercise these rights, contact [email protected].
If Framer processes your data on behalf of a business (for example, your employer), please contact that business first — we will assist them in responding.
Children
Framer is not intended for individuals under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with data, contact us and we will delete it.
Changes to this policy
We will post any material changes on this page and, where required, notify workspace administrators by email at least 30 days before the changes take effect.
Contact us
Framer B.V. — Rozengracht 207-B, 1016 LZ Amsterdam, Netherlands, USA.
EU representative: Framer EU Sp. z o.o. — ul. Koszykowa 61, 00‑667 Warsaw, Poland.
Email: [email protected]