Framer AI procurement policy evidence
Only topics backed by verified findings appear below. Each row preserves the platform's exact policy words and capture provenance.
| Topic | Plan or tier | Risk | Their words | Source |
|---|---|---|---|---|
| DPA, audit rights & data residency | All applicable tiers | low | “ ISO 27001 is the globally accepted standard for assessing the life cycle of an organization’s security practices. It is a rigorous assessment of both risk, compliance, and governance that verifies that an organization has a mature, well-managed approach to information security. Framer has achieved ISO 27001 compliance. The ISO 27001 certificate and statement of applicability are available to Enterprise customers upon request.” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ The security of your Personal Information is important to us. We therefore aim to safeguard and protect your Personal Information from unauthorized access, improper use or disclosure, unauthorized modification, or unlawful destruction or accidental loss, and we utilize and maintain certain reasonable processes, systems, and technologies to do so. This also means that our personnel is only allowed to access or process Personal Information if this is reasonably required to do so for work related tasks, to adhere to your request or to fulfill a legal obligation on behalf of us. Please remember that no method of transmission over the internet, or method of electronic storage, is 100% secure or error-free. While we strive to use commercially acceptable means to protect your Personal Information, we cannot guarantee its absolute security. Accordingly, we cannot be held responsible for unauthorized or unintended access that is beyond our control. Transferring Personal Information: As also mentioned above, where Personal Information is transferred outside the European Economic Area to our affiliated companies or to third party service providers, we will take steps to ensure that your Personal Information is protected by the same level of protection as if it remained within the European Economic Area, including by entering into data transfer agreements using the European Commission approved Standard Contractual Clauses. We contractually require agents, service providers, and affiliates who may process Personal Information related to the Services to provide the same level of protection for Personal Information as required under the GDPR. ” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ - Promptly notifying our customers if we have any reason to believe that law applicable to us would prevent us from complying with our customers’ processing instructions;” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ As of July 16, 2020, we no longer rely on the Privacy Shield as a transfer mechanism for data transfers given the EU-U.S. Privacy Shield and Swiss-U.S. Privacy Shield are no longer valid as a result of the CJEU ruling in Schrems II. However, to the extent Framer has ongoing obligations under our existing Privacy Shield Certification, we will continue to honor them . Our Privacy Shield certification is available here .” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ Framer Enterprise includes all our general security measures, plus additional features and enhancements to provide even more customization and privacy.” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ As of July 16, 2020, we no longer rely on the Privacy Shield as a transfer mechanism for data transfers given the EU-U.S. Privacy Shield and the Swiss-U.S. Privacy Shield are no longer valid as a result of the CJEU ruling in Schrems II. However, to the extent Framer has ongoing obligations under our existing Privacy Shield Certification, we will continue to honor them. Our Privacy Shield certification is available here . Where Personal Information is transferred outside the European Economic Area to our affiliated companies or to third party service providers, we will take steps to ensure that your Personal Information is protected by the same level of protection as if it remained within the European Economic Area, including by entering into data transfer agreements using the European Commission approved Standard Contractual Clauses, or by relying on certification schemes such as the Privacy Shield. We contractually require agents, service providers, and affiliates who may process Personal Information related to the Services to provide the same level of protection for Personal Information as required under the European Union General Data Protection Regulation ("GDPR"). Framer complies with the EU-U.S. Privacy Shield Framework and Swiss-U.S. Privacy Shield Framework as set forth by the U.S. Department of Commerce regarding the collection, use, and retention of personal information transferred from the European Union and Switzerland to the United States. ” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ Framer uses the AWS-managed data stores Aurora, DynamoDB, ElastiCache, and S3 to store customer data, including backups. All these AWS services have been configured to use encryption at rest using AES with 256-bit keys.” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ We are committed to processing personal data in accordance with our obligations as a data “processor” or “subprocessor” under applicable EU data protection laws. If your organization is based in the EU or is otherwise directly or indirectly subject to EU data protection laws, including the GDPR, we have executed, or upon request by your organization will execute, and have otherwise committed to comply with the applicable Standard Contractual Clauses approved by the European Commission related to our processing or subprocessing of personal data in connection with the services we provide to your organization as our customer. For our customers to which such EU data protection laws apply, these requirements include:” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “Framer has certified to the Department of Commerce that it adheres to the Privacy Shield Principles of (1) Notice; (2) Choice; (3) Accountability for Onward Transfer; (4) Security; (5) Data Integrity and Purpose Limitation; (6) Access; and (7) Recourse, Enforcement and Liability (collectively, the “Privacy Shield Principles”). To learn more about the Privacy Shield program, and to view our certification, please visit https://www.privacyshield.gov/ . As further set forth in the Privacy Shield Principles, we remain potentially liable if a third party processing Personal Data received from the EU or Switzerland on our behalf processes that Personal Data in a manner that is inconsistent with the Privacy Shield Principles (unless we can prove that we are not responsible for the event giving rise to the damage). Framer is subject to the investigatory and enforcement powers of the Federal Trade Commission with respect to any failure to comply with the Privacy Shield Principles. EU and Swiss individuals with inquiries or complaints regarding U.S. privacy practices should contact us at compliance@framer.com. In compliance with the Privacy Shield Principles, Framer commits to resolve complaints about our collection or use of your personal information. EU and Swiss individuals with inquiries or complaints regarding our Privacy Shield policy should first contact Framer at: support@framer.com. Framer has further committed to refer unresolved Privacy Shield complaints to Jams ADR, an alternative dispute resolution provider located in the United States. ” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ - Processing personal data only in compliance with our customers’ instructions, and promptly informing them if we cannot comply;” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ Framer is committed to ensuring that all our customer and employee personal data are treated in a way that complies with the EU’s General Data Protection Regulation (GDPR).” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ - To obtain, or see a copy of the appropriate safeguards under which your Personal Information is transferred to a third country or international organization outside of the European Economic Area; and” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | medium | “ Framer maintains a number of information security policies that form the basis of our information security program. All Framer employees are required to review these policies as part of their on-boarding. These security policies cover the following topics and are available to Enterprise customers upon request:” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “ - Submitting our data processing facilities to audit by our customers;” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | medium | “ SOC 2 is a globally recognized auditing standard for service organizations that demonstrates adequate controls and processes. Framer has successfully completed the SOC 2 Type 1 audit and the SOC 2 Type 2 audit. Framer’s SOC 2 report covers the trust services principles and criteria security and availability. A copy of the most recent audit report is available to Enterprise customers upon request.” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “Submitting our data processing facilities to audit by our customers;” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | medium | “ All of Framer’s services are hosted in Amazon Web Services (AWS) facilities in the United States. Services are distributed across multiple AWS availability zones. These zones are hosted in physically separate data centers, protecting services against single data center failures. You can find more information about AWS security practices on their cloud security page .” | Captured 2026-06-07Open source →Finding permalink → |
| DPA, audit rights & data residency | All applicable tiers | low | “Where Personal Information is transferred outside the European Economic Area to our affiliated companies or to third party service providers, we will take steps to ensure that your Personal Information is protected by the same level of protection as if it remained within the European Economic Area, including by entering into data transfer agreements using the European Commission approved Standard Contractual Clauses. We contractually require agents, service providers, and affiliates who may process Personal Information related to the Services to provide the same level of protection for Personal Information as required under the European Union General Data Protection Regulation ("GDPR").” | Captured 2026-06-07Open source →Finding permalink → |
| Data retention | All applicable tiers | medium | “In general the collected Personal Information is not stored by us for longer than three years, unless you do a prior deletion request. However, in some circumstances, we may retain certain Personal Information for other periods of time, for instance where we are required to do so in accordance with legal, tax, and accounting requirements, or if required by a legal process, legal authority, or other governmental entity having authority to make the request, for so long as required. In specific circumstances, we may also retain certain Personal Information for longer periods of time corresponding to a statute of limitation, so that we have an accurate record of your dealings with us in the event of any complaints or challenges.” | Captured 2026-06-07Open source →Finding permalink → |
| Data retention | All applicable tiers | low | “ All Framer customer data is stored redundantly at multiple AWS data centers (availability zones) to ensure availability. Framer has well-tested backup and restoration procedures in place, which allow for quick recovery in the case of single data center failures and disasters. Customer data is continuously backed up and stored off-site. The restoration of backups are fully tested every 30 days to ensure that our processes and tools work as expected.” | Captured 2026-06-07Open source →Finding permalink → |
| Data retention | All applicable tiers | low | “ - To delete your Personal Information (where it is no longer necessary in relation to the purposes for which it was collected or processed). We strive to anonymize your Personal Information within 30 days after your deletion request;” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ - Otherwise protect our property, legal rights, or that of others.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “We may share Personal Information with third parties in connection with potential or actual sale of our company or any of our assets, or those of any affiliated company, in which case Personal Information held by us about our customers and/or users may be one of the transferred assets.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “If you do not receive timely acknowledgment of your complaint from us, or if we have not addressed your complaint to your satisfaction, please contact or visit https://www.jamsadr.com/eu-us-privacy-shield for more information or to file a complaint. The services of Jams ADR are provided at no cost to you. If your complaint still remains unresolved, then you have the right to invoke binding arbitration by the Privacy Shield Panel upon written notice to Framer at: support@framer.com. We may share Personal Information with third parties in connection with potential or actual sale of our company or any of our assets, or those of any affiliated company, in which case Personal Information held by us about our customers and/or users may be one of the transferred assets. In accordance with our legal obligations and our privacy statement , we may also process Personal Information, subject to a lawful request, to public authorities for law enforcement or national security purposes. Further we may also disclose Personal Information where otherwise required by local law or regulations.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ - We believe it is needed to enforce our Terms of Service, or that it is legally required;” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ We may share Personal Information with third parties in connection with potential or actual sale of our company or any of our assets, or those of any affiliated company, in which case Personal Information held by us about our customers and/or users may be one of the transferred assets. In accordance with our legal obligations, we may also process Personal Information, subject to a lawful request, to public authorities for law enforcement or national security purposes. Further we may also disclose Personal Information where otherwise required by local law or regulations.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | low | “ - Doing so is appropriate to carry out your own request;” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “ We operate worldwide and we may share your Personal Information with our affiliated businesses as part of our business operations, administration of the Services and to comply with local laws and regulations. We may also appoint third party service providers (who will operate under our instructions) to assist us in providing information, products or services to you, in conducting and managing our business, or in managing and improving our Services. We may share your personal data with these affiliates and third parties to perform services that the third parties have been engaged by us to perform on our behalf, subject to appropriate contractual restrictions and security measures, or if we believe it is reasonably necessary to prevent harm or loss, or if we believe that the disclosure will further an investigation of suspected or actual illegal activities. We reserve the right to share any information that is not deemed Personal Information or is not otherwise subject to contractual restrictions. Where Personal Information is transferred outside the European Economic Area to our affiliated companies or to third party service providers, we will take steps to ensure that your Personal Information is protected by the same level of protection as if it remained within the European Economic Area, including by entering into data transfer agreements using the European Commission approved Standard Contractual Clauses. We contractually require agents, service providers, and affiliates who may process Personal Information related to the Services to provide the same level of protection for Personal Information as required under the European Union General Data Protection Regulation ("GDPR"). ” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | low | “ - Providing a copy or summary of the applicable contract between us and our customer to individuals who are unable to obtain such a copy or summary directly from their organization;” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “In accordance with our legal obligations, we may also process Personal Information, subject to a lawful request, to public authorities for law enforcement or national security purposes. Further we may also disclose Personal Information where otherwise required by local law or regulations.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | low | “ - Obtaining consent from our customers for our use of any service providers who will be processing any personal data; and” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | medium | “We operate worldwide and we may share your Personal Information with our affiliated businesses as part of our business operations, administration of the Services and to comply with local laws and regulations. We may also appoint third party service providers (who will operate under our instructions) to assist us in providing information, products or services to you, in conducting and managing our business, or in managing and improving our Services. We may share your personal data with these affiliates and third parties to perform services that the third parties have been engaged by us to perform on our behalf, subject to appropriate contractual restrictions and security measures, or if we believe it is reasonably necessary to prevent harm or loss, or if we believe that the disclosure will further an investigation of suspected or actual illegal activities.” | Captured 2026-06-07Open source →Finding permalink → |
| Subprocessors & data sharing | All applicable tiers | low | “ - Ensuring that any such service providers agree in writing to comply with these requirements.” | Captured 2026-06-07Open source →Finding permalink → |
Informational only, not legal advice. Terms can change; verify every cited source and capture date during procurement review.
AIRIN Brief
Built for compliance officers, legal counsel, and SaaS founders. Subscribe to the email digest — one short brief when a tracked vendor materially changes its terms, training policy, or risk rating. Prefer in-app? Watch platforms in your alerts inbox instead.