4,577 words, 118 clausesupdated June 12, 2026read 11/10/2026source
·Version 1.7 Effective June 12, 2026
·This website (www.framer.com) (the "Website"), is owned and operated by Framer B.V.
·Framer B.V. provides a platform for designing and publishing interactive websites (the "Service").
·Framer B.V. is an entity incorporated under the laws of the Netherlands and registered in the Netherlands with the Dutch Chamber of Commerce under registration number 59920637. Framer B.V. has its registered office at Rozengracht 207B, 1016 LZ Amsterdam, the Netherlands.
·This privacy statement ("Privacy Statement") specifies how Framer B.V. and its affiliates (hereinafter referred to as "Framer", "we", "us", "our") process personal data of its Users in different contexts.
·To understand Framer's obligations and your rights under this Privacy Statement, it helps to identify your relationship with Framer.
·In providing the Website, our Service and in relation to applicants, we may process the following personal data:
| Personal data of whom? | Types of personal data | Purpose (see below) |
|---|---|---|
| Website visitors | Data collected through cookies: IP address; Cookie information as mentioned in our Cookie Statement. Security, anti-spam and anti-abuse signals (such as device and browser characteristics, interaction patterns and network signals) used to detect and prevent bots, spam and malicious activity. | 2, 3, 7, 8, 9 |
| Individuals who submit inquiries | Data that personally identifies you when you e-mail us or otherwise correspond: First and last name; Contact information (e.g., email address and phone number); The content of your message to us; Company; Country; Where applicable, Framer ID, project link, and Framer site URL | 1, 3, 5, 8, 9 |
| Potential customers | Data from individuals or companies who shared their contact information with us, whether it has been through a form on the Website, from information collected at a trade or marketing event, or from those have reached out directly to us: First and last name; Contact information (e.g. (company) email address and (company) phone number); Job title; Company; Address; Country. | 1, 3, 5, 7, 8, 9 |
| Customers (or employees and contractors of Customers) that use our Service | Data required to enter into a contract with the Customer, for the use of our Service by the Customer and data generated when using our Service: First and last name; Contact information (e.g. (company) email address and (company) phone number); Billing information; Billing name and address; VAT number; If the payment method is a debit or credit card, card type, expiration date and last four digits of the card number. Full card details are collected and processed directly by a PCI-compliant payment provider The number of employees within the company of the customer that will be using the Service; IP address; Device ID; Project ID; Framer ID; Location data; Login and password; Security, anti-spam and anti-abuse signals (such as device and browser characteristics, interaction patterns and network signals) used to detect and prevent bots, spam and malicious activity. | 1, 2, 4, 5, 7, 8, 9 |
| Affiliates (e.g. Framer partners, Framer Community participants and Framer experts) | Data required to engage an affiliate and to enter into a contract with an affiliate: First and last name; E-mail address; Country; Payment information; VAT number. | 1, 3, 4, 5, 8, 9 |
| Job applicants | Data required to process an application and to contact a job applicant after the application, i.e.: First and last name; Contact information (e.g. email address and phone number); Country; Branch/position; Resume; Motivation; LinkedIn. | 6, 8, 9 |
·We only process your personal data if we have a valid legal ground to do so. The Regulation 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC ("GDPR") specifically states these legal grounds. In the case of Framer these are: performance of a contract, legitimate interest, compliance with a legal obligation and sometimes consent.
·The purposes for which we process personal data, and the legal ground for each, are set out in the table below. # | Purpose | Legal ground
| 1 | To enter into and for the performance of agreements, with regard to our Service. | Performance of contract (Article 6(1)(b) GDPR) |
|---|---|---|
| 2 | To offer, maintain, secure and improve the Website and our Service, including to detect and prevent spam, automated abuse and malicious activity and to maintain the integrity and security of the platform. | Legitimate interest (Article 6(1)(f) GDPR) |
| 3 | To have and maintain contact with you, for example, through our contact form and to provide customer support. | Legitimate interest (Article 6(1)(f) GDPR) |
| 4 | To establish and maintain contact with (potential) customers and (potential) other business relations. | Legitimate interest (Article 6(1)(f) GDPR) |
| 5 | Internal business and management operations, for example financial processing. | Legitimate interest (Article 6(1)(f) GDPR); legal obligation (Article 6(1)(c) GDPR) |
| 6 | To assess whether you are a viable candidate for our company and to further process the application. | Performance of contract (Article 6(1)(b) GDPR); legitimate interest (Article 6(1)(f) GDPR); consent (Article 6(1)(a) GDPR, but only to keep your personal data for a longer period) |
| 7 | Marketing activities. | Consent (Article 6(1)(a) GDPR); legitimate interest (Article 6(1)(f) GDPR), as applicable and honoring your right to object |
| 8 | To establish, exercise and defend our rights. | Legitimate interest (Article 6(1)(f) GDPR) |
| 9 | To comply with applicable laws and regulations, including tax legislation (Algemene wet inzake rijksbelastingen), various statutory retention periods and the pension act (Pensioenwet), or an injunction or request from authorized regulators or other government agencies. | Comply with a legal obligation (Article 6(1)(c) GDPR); legitimate interest (Article 6(1)(f) GDPR) |
·Legitimate interest: We will only process personal data based on legitimate interest if our interests outweigh the privacy interests of the person to whom the data relates. In that case, the legitimate interests of Framer correspond to the purposes set out below. For further information on the balancing of interests in a specific case, please contact us using the contact details at the bottom of this Privacy Statement. It may also be the case that Framer has to process personal data to comply with an applicable legal obligation, for example to meet applicable minimum retention periods.
·Consent: Where we rely on consent as the legal ground, you may withdraw that consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
·We obtain your personal data in various ways:
·In principle, you are under no obligation to provide any information about yourself to us. However, refusal to supply certain information could have a negative influence on, for example, your experiences on or functionality of our Website. If the provision of certain personal data is a legal or contractual obligation or an essential requirement for concluding an agreement with us, we will separately provide additional information about this for as far as this is not clear in advance. In this case we will also inform you about the possible consequences if this information is not provided.
·We only share your personal data with third parties if:
·We could share your personal data on a need-to-know basis with the parties mentioned below. In this context, "need-to-know" means that a party only gets access to personal data if and insofar as this is required for the professional service provided by this party:
·Framer may use automated systems and artificial intelligence ("AI") tools to support certain internal business operations, including customer support, troubleshooting, product improvement, security monitoring, analytics, and service optimisation.
·In connection with these activities, personal data submitted to or processed through our Service may be processed by such tools on our behalf and subject to applicable confidentiality, security, and data protection safeguards.
·We do not use customer personal data to train third-party general-purpose AI models unless expressly disclosed otherwise or permitted in our agreements with customers.
·Framer may transfer personal data to third parties (e.g., our cloud service provider) located outside the EEA. This will involve transferring your data to countries outside the EEA and UK ("Third Countries"), including the United States of America ("U.S."), where the servers we use are located. A list of countries to which Framer transfers personal data can be found in Framer's Trust Center (available at https://trust.framer.com). Any data transfer shall always take place in compliance with Chapter V of the GDPR and additional recommendation or decision issued in this regard by the European Data Protection Board ("EDPB"), European Commission, or other competent authority or body under the applicable laws.
·If you are a resident of a U.S. state with comprehensive privacy laws, including residents of California., you may have additional rights. Please see section 13 ("Your U.S. State Privacy Rights (California and other U.S. states") for further details.
·Transfers of your personal data to a country outside the EEA may in the first place be legitimized based on a so-called adequacy decision. This is a decision in which the European Commission states that e.g. a certain country offers a level of data protection similar to the GDPR. The current list of adequacy decisions of the European Commission is available here. An example of transfer of Framer based on an adequacy decision is the transfer of your personal data to the U.S. (insofar as the recipient is certified under the Data Privacy Framework). The transfer of your data from the UK to a third party outside the UK may primarily be legitimized based on an adequacy regulation of the UK government. An overview of the applicable adequacy regulations of the UK government is available here.
·If we transfer personal data to Third Countries to which no adequacy decision or adequacy regulation applies, we will conclude the applicable version of the model clauses to safeguard data protection as published by the European Commission, so called standard contractual clauses ("Transfer SCCs"). If deemed required under the applicable law, additional measures will be taken. This may concern technical, organizational and/or contractual measures. Where the UK GDPR is applicable, a UK Addendum will be added to the Transfer SCCs, as required by UK laws and regulations.
·Further information on our legitimization of data transfers to Third Countries will be provided upon your request. Please use our contact details to make such a request, as stated below.
·Protecting your privacy and personal data is very important to us. Therefore, Framer has implemented appropriate technical and organizational measures to protect and secure the personal data we process, in order to prevent violations of the confidentiality, integrity and availability of data.
·Framer has internal processes according to which we safeguard an appropriate level of technical and organisational security. That includes ensuring only authorised personnel have access to that personal data and taking reasonable steps to prevent data breaches, monitoring and acting upon unauthorized access, improper use or disclosure, unauthorized modification, and unlawful destruction or accidental loss. We also have technologies and systems in place to utilize and maintain processes aimed at safeguarding and ensuring an appropriate level of technical and organizational security.
·In relation to the processing of your personal data by Framer, you have the following privacy rights:
·You can exercise the privacy rights above free of charge by e-mail via the contact details displayed below. If requests are manifestly unfounded or excessive, in particular because of the repetitive character, we have the right to either charge a reasonable fee or refuse to comply with the request. In addition, we may request specific information to help us confirm your identity before we further respond to a privacy request. Finally, we will provide information about the follow-up of the request without undue delay and in principle within one month of receipt of the request. Depending on the complexity of the request and the number of requests, this period can be extended by another two months.
·In general, Framer does not keep personal data for longer than is necessary in relation to the purposes for which we process the personal data. Specific retention periods that Framer applies are the following:
·There could, however, be exceptions applicable to the general retention terms. In view of this, shorter retention periods could apply: if an individual exercises certain privacy rights, it is possible that we retain it for a shorter period of time. Longer retention periods could also apply. In certain situations, we process personal data of individuals for a longer period of time than what is necessary for the purpose of the processing. This is for instance the case when we have to process personal data for a longer period of time:
·This section applies to residents of U.S. states with comprehensive privacy laws ("U.S. State Privacy Laws"), including residents of California under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (the "CCPA"). It supplements the information above and applies only where Framer acts as a business or controller; where Framer processes personal information on behalf of a Customer, the Customer is responsible for its own disclosures and for responding to its consumers' requests.
·The Service is not for use by children under the age of 16 years and we do not knowingly collect, store, share, or use personal data of children under 16 years. If you are under the age of 16 years, please do not provide any personal data, even if prompted by the Service to do so. If you are under the age of 16 years and you have provided personal, please ask your parents or guardians) to notify us and we will delete all such personal data.
·If you have any questions regarding this Privacy Statement, or data collection by Framer in particular, please contact us at legal@framer.com or by using the contact information below:
·Framer B.V. Rozengracht 207B 1016 LZ Amsterdam The Netherlands
·Occasionally, we may need to update or change this Privacy Statement. In case of important changes, we will inform you in an appropriate manner and ask you to take note of the changes made. The latest version of the Privacy Statement is always available on our Website.
·Version 1.7 June 16, 2026