Legal · Privacy

Privacy Policy

This Privacy Policy explains what personal data we collect when you use Framer, how we use it, how we protect it and the choices you have. It applies to our website, product and related enterprise services.

This page is maintained by Framer B.V. to answer common questions about how we operate our service. It is provided for transparency and is not legal advice or a certification of compliance. For binding terms, please refer to your executed order form or Master Services Agreement.
01

Overview and scope

Framer B.V. ("Framer", "we", "our") provides an enterprise AI platform that helps customer support teams triage tickets, generate replies and analyse conversations. This policy covers personal data we process as a data controller for our website visitors, marketing contacts and account administrators, and describes our role as a data processor for customer content submitted to the platform by our business customers.

Where we act as a processor, our processing is governed by the Data Processing Addendum (DPA) executed with the customer, and this policy is provided for transparency only.

02

Data we collect

We collect three broad categories of information:

  • Account data — name, business email, password hash, workspace name, billing address and role assignments.
  • Usage data — pages visited, feature interactions, device and browser metadata, IP address, approximate location derived from IP, and diagnostic logs.
  • Customer content — support tickets, knowledge base articles, macros, chat transcripts and attachments that our customers upload or connect to the platform through supported integrations.

We do not intentionally collect special categories of personal data (health, biometric, political opinions, etc.). Customers are contractually required not to send such data unless a specific written arrangement is in place.

03

How we use personal data

  • To provide, secure and improve the Framer platform.
  • To bill customers, process credit purchases and prevent fraud.
  • To respond to sales, security and support enquiries.
  • To send transactional emails (invoices, security alerts, service updates).
  • To send product news and marketing where you have opted in or where allowed by soft opt-in rules.
  • To meet legal, tax and regulatory obligations.
05

AI processing and training

Framer uses large language models to summarise tickets, retrieve knowledge and draft replies. We do not use customer content to train foundation models. Model providers used to serve inference are contractually restricted from retaining prompt or completion data beyond what is required to return the response.

Customers can turn off individual AI features in workspace settings. Where regional processing is required (e.g. EU-only inference), an eligible plan and region must be selected before enabling AI features.

06

How we share data

We share personal data with:

  • Vetted subprocessors that host, secure, monitor or bill the service.
  • Payment providers when you buy credits.
  • Professional advisers under confidentiality (auditors, lawyers).
  • Authorities where legally required, following our published law enforcement guidelines.
  • Successors in the event of a merger, acquisition or asset sale, subject to equivalent protections.

We do not sell personal data and we do not share it for cross-context behavioural advertising.

07

International transfers

Framer operates from the European Union and the United States. Where personal data is transferred outside your region, we rely on the European Commission's Standard Contractual Clauses, the UK IDTA, adequacy decisions where available and additional technical measures such as encryption in transit and at rest.

08

Data retention

  • Account data — kept while the account is active and for up to 24 months after closure, unless a longer statutory period applies.
  • Customer content — retained per the customer's workspace configuration; deleted or exported within 30 days of a verified deletion request.
  • Billing records — retained for the period required by tax law (typically 7–10 years).
  • Server logs — retained for up to 90 days for security investigations.
09

Security

We apply role-based access controls, encryption in transit (TLS 1.2+) and at rest (AES‑256), continuous vulnerability scanning, mandatory MFA for staff, hardware security keys for privileged access and independent penetration testing at least annually.

No online service can be guaranteed 100% secure. We publish material security incidents to affected customers without undue delay in line with our contractual and regulatory obligations.

10

Your rights

Depending on where you live, you may have the right to access, correct, delete, restrict or object to processing of your personal data, to portability, and to withdraw consent. To exercise these rights, contact [email protected].

If Framer processes your data on behalf of a business (for example, your employer), please contact that business first — we will assist them in responding.

11

Children

Framer is not intended for individuals under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with data, contact us and we will delete it.

12

Changes to this policy

We will post any material changes on this page and, where required, notify workspace administrators by email at least 30 days before the changes take effect.

13

Contact us

Framer B.V. — Rozengracht 207-B, 1016 LZ Amsterdam, Netherlands, USA.

EU representative: Framer EU Sp. z o.o. — ul. Koszykowa 61, 00‑667 Warsaw, Poland.

Email: [email protected]

Questions about this document? Contact us at [email protected] or visit our contact page.