How the Framely service processes personal data under the EU General Data Protection Regulation (GDPR) when you use the dashboard at https://app.framely.site, the website https://framely.site and websites published on the platform. Version of October 7, 2026.
Framely is a builder of static websites and landing pages: a dashboard for creating and editing websites, hosting of published websites, collection of form submissions and related features ("Service"). The Service is operated from the European Union by the Framely service ("Framely", "we", "us").
In this Policy, "User" means a person with a Framely account, "Site Owner" means a User who created a website in the Service, "Visitor" means a person who opens a website published in the Service, and "Lead" means data a Visitor submits through a form on a Site Owner's website.
Use of the Service is governed by the Terms and Conditions at https://framely.site/terms-and-conditions. Terms such as "personal data", "controller", "processor" and "processing" have the meaning given in the GDPR.
All requests, including those about personal data, are accepted through the form at https://app.framely.site/en/report.
Framely is the controller for the personal data of Users (account, sign-in, settings, correspondence), of people who submit a report about a website, and for technical data of visitors to the dashboard and the Framely website.
For Leads and other Visitor data collected on a Site Owner's website, the Site Owner is the controller: they decide which fields the form has, why they need the data and what they do with it. Framely is the processor and handles that data only on the Site Owner's instructions and only to provide the Service to them: to receive the Lead, store it, show it in the "Leads" section, export it to CSV and send the notifications the Site Owner has set up. The processing terms required by Article 28 GDPR are part of the Terms and Conditions.
The Site Owner is responsible for having a lawful basis, for informing Visitors through their own privacy notice (a link to it can be set in the form settings), for obtaining consent where it is needed and for answering Visitors' requests. Visitors who want to access, correct or delete data in a Lead should contact the owner of the website concerned. If such a request reaches us, we will forward it to the Site Owner and help them respond.
Users: • name and email address; • password, stored only as a hash; • whether the email is verified, interface language, role and account ban status; • if you sign in with Google: your Google account identifier, name, email, profile picture URL and the access tokens Google issues at sign-in; • session data: IP address, browser details (user agent), when the session was created and when it expires; • content you place in the Service: websites, pages, blog posts, texts, uploaded images, domain settings, email addresses for lead notifications, a Telegram chat ID and bot token (the token is stored encrypted); • the business description you enter to generate a website with AI.
Visitors of Site Owners' websites (we act as processor): • the data entered in the form; the fields are chosen by the Site Owner (usually name, phone, email and comment; for catalog orders also product, size and colour); • the consent text shown with the form and the time the form was sent; • IP address, user agent and the address of the page the form was sent from (referrer).
People who submit a report through the /report form: • the website address, reason and description of the report; • email, if provided; • IP address.
Everyone who visits the dashboard, the Framely website or a published website: • IP address and technical request data, used to deliver pages, protect against abuse and limit request rates; • data collected by Google reCAPTCHA on the sign-up and password reset pages (section 5).
We do not use web analytics or advertising trackers. We do not ask for special categories of personal data. Site Owners may not collect passwords, bank card details or other credentials through forms.
• Registration, sign-in and account management, including Google sign-in: performance of the contract with you (Article 6(1)(b) GDPR). • Service emails (email verification, password reset, email change confirmation, password change notice, new lead notifications): performance of the contract (Article 6(1)(b)). • Creating, storing, publishing and hosting websites and blog posts, uploading images, connecting custom domains: performance of the contract (Article 6(1)(b)). • Generating a website with AI from the description you entered, at your request: performance of the contract (Article 6(1)(b)). • Receiving and storing Leads and notifying the Site Owner by email or Telegram: on the Site Owner's instructions as processor; the lawful basis for this processing is the Site Owner's responsibility. • Protecting the Service against spam, bots and abuse (reCAPTCHA, rate limiting, blocking disposable email addresses, checking links on published websites with Google Safe Browsing, checking forms for signs of phishing): our legitimate interest and that of other Users and Visitors in a secure Service (Article 6(1)(f)). • Handling reports, moderation and blocking websites and accounts that break the rules: our legitimate interest (Article 6(1)(f)) and, where applicable, compliance with legal obligations (Article 6(1)(c)). • Answering your requests and exercising your rights: performance of the contract and compliance with the GDPR (Article 6(1)(b) and (c)). • Establishing, exercising or defending legal claims: our legitimate interest (Article 6(1)(f)).
Where we rely on legitimate interests, you may object (section 9). Where processing is based on consent, you may withdraw it at any time without affecting earlier processing.
We do not send marketing emails and do not make decisions based solely on automated processing that produce legal or similarly significant effects. Automated checks at publishing may stop a publication or flag a website for review; the decision to block is taken by a person.
We do not sell personal data. We share it only with the following recipients and only as far as needed for the purposes above: • Google (Google LLC, USA, and Google Ireland Limited): Google sign-in, if you choose it; reCAPTCHA v3 on the sign-up and password reset pages, which receives browser data and your IP address (loaded through www.recaptcha.net); Google Safe Browsing, which receives the addresses of links on pages being published. Google's privacy policy: https://policies.google.com/privacy. • Resend (USA): delivery of service emails and lead notifications, including the recipient address and the email text. On the paid plan the lead email contains all fields of the Lead; on the free plan it only says that a new lead has arrived. • DeepSeek (People's Republic of China): AI website generation. Only the description text you entered is sent. Please do not include personal data in it. • Telegram: only on the paid plan and only if the Site Owner connects their own Telegram bot; the content of each Lead is sent to the chat they specified. The Site Owner chooses this channel. • Cloudflare (Cloudflare, Inc., USA): the dashboard at app.framely.site runs through the Cloudflare network, so requests to the dashboard, including IP addresses and the data sent, pass through it. Published websites and form submissions do not go through Cloudflare. • Our hosting provider, which rents us the servers that run the database, file storage and published websites. • Professional advisers and public authorities, where required by law or needed to establish, exercise or defend legal claims.
Service administrators can view accounts and websites and sign in to an account on a User's behalf, only for support at the User's request, handling reports and moderation.
Some recipients are located outside the European Economic Area (EEA), in particular in the USA (Google, Resend, Cloudflare) and China (DeepSeek), and Telegram may process data in various countries.
We transfer personal data outside the EEA only in line with Chapter V GDPR: • to countries covered by an adequacy decision of the European Commission, including to US companies certified under the EU-US Data Privacy Framework; • otherwise on the basis of the Standard Contractual Clauses adopted by the European Commission, where applicable, together with supplementary measures where needed; • in limited cases, where the transfer is necessary to perform a contract with you or at your request (Article 49(1)(b) GDPR), for example when you ask us to generate a website with AI or a Site Owner chooses Telegram notifications.
China has no adequacy decision. For DeepSeek we limit the transfer to the description text you type in and ask you not to include personal data. You can request information about the safeguards for a given transfer through the contact form.
• Account data: for as long as the account exists. After an account is deleted, its data is erased within 30 days unless the law requires us to keep it longer. • Sessions: up to 30 days from the last extension. Signing out ends a session; a password reset or an account ban ends all sessions, and a password change ends sessions on other devices. • Email verification and password reset links: 24 hours and 1 hour respectively. • Rate-limit counters, which may contain an IP address or email: from 1 minute to 24 hours. • Leads: until the Site Owner deletes them in the "Leads" section, or the website or the Site Owner's account is deleted. The Service does not delete leads automatically; the Site Owner, as controller, decides how long to keep them. • Websites, pages, blog posts and uploaded images: until the User deletes them. Copies of published versions and uploaded files may remain in file storage for a short time after deletion until they are removed. • Reports: for as long as needed to handle them and to prevent repeated violations. • Server logs: for a limited period needed to run and secure the Service.
We take appropriate technical and organisational measures under Article 32 GDPR, including: • encrypted connections (HTTPS/TLS) for the dashboard and published websites; • storing passwords only as hashes and Telegram bot tokens in encrypted form; • email verification, ending all sessions on password reset and notifying you of password changes; • rate limiting, bot protection and checking uploaded files by their content; • a database and file storage that are not reachable from the internet; only the web server is exposed; • access control: only designated people have administrator rights.
Code a User adds in a Custom HTML block is never executed inside the dashboard and is output only on a published website with its own domain.
If a personal data breach occurs, we will notify the competent supervisory authority and affected people where the GDPR requires it, and inform affected Site Owners without undue delay.
Under the GDPR you have the right to: • access your personal data and receive a copy of it; • have inaccurate data rectified and incomplete data completed; • have your data erased; • restrict processing; • data portability: receive the data you gave us in a structured, commonly used, machine-readable format, or have it sent to another controller; • object to processing based on our legitimate interests; • withdraw consent at any time, where processing is based on consent; • lodge a complaint with a data protection supervisory authority, in particular in the EU member state of your habitual residence, place of work or the place of the alleged infringement.
You can change your name, email and password yourself in the account settings (/settings), and Site Owners can delete websites and leads in the dashboard. To delete your account or exercise other rights, send a request through https://app.framely.site/en/report, giving the email linked to your account. We may ask you to confirm the request from that address. We reply within one month; for complex or numerous requests this may be extended by two further months, and we will tell you why.
Visitors of websites built with the Service should contact the owner of the website about their Leads (section 2).
Under the ePrivacy rules, we store or read information on your device without consent only where it is strictly necessary for a service you request. The dashboard (app.framely.site) uses only such strictly necessary cookies: • the session cookie of our authentication system, which keeps you signed in. A session lasts up to 30 days and is extended while you use the Service; • NEXT_LOCALE, which remembers the interface language (en or ru), kept for 1 year.
Published websites on the free plan show a "This site is made with Framely" panel. If you hide it, your browser remembers this in sessionStorage (key framely:badge-hidden) until the tab is closed. No cookie is set and nothing is sent to our servers.
The sign-up and password reset pages load Google reCAPTCHA v3 to protect these forms from bots. Google may set its own cookies and collect browser details and on-page activity for this purpose.
We do not use analytics or advertising cookies. A Site Owner may add third-party services to their website, such as YouTube videos, maps or their own HTML code. YouTube videos (youtube-nocookie) and maps load only after a click on the placeholder. The Site Owner is responsible for any third-party code they add and for any consent it requires.
The Service is not intended for people under 16, and we do not knowingly collect their data. If you believe a child under 16 has registered, let us know through https://app.framely.site/en/report and we will delete the account.
We may update this Policy, for example when we add features or sub-processors. The new version is published on this page with its date. We will tell Users about material changes in advance by email or in the dashboard.
The Framely service, https://framely.site.
Requests on any matter, including personal data and the exercise of your rights: https://app.framely.site/en/report.