Framewyre Privacy Policy

What we store, where it lives, who can touch it, and how to get it deleted.

Effective date: [EFFECTIVE DATE]  ·  Last updated: [LAST UPDATED DATE]

Draft notice. This document is an unreviewed template. It is not legal advice and has not been checked by an attorney or a privacy specialist. Every [PLACEHOLDER] must be completed, the subprocessor list confirmed against what the service actually uses, and the whole document reviewed by a qualified lawyer before any customer relies on it.

1. Who we are and what this covers

[COMPANY LEGAL NAME] (“we”, “us”) operates Framewyre, a construction CRM sold on subscription to contracting businesses. This policy explains how we handle information in connection with the Framewyre service, the Framewyre websites, and the signup and billing flow.

Two different roles. For information about the contractor who subscribes (account owners and their users), we act as the controller. For the records a contractor stores about their own clients, leads, employees and subcontractors (“Customer Data”), the contractor is the controller and we act as a processor on their instructions. If you are a homeowner or client of a contractor who uses Framewyre, please contact that contractor directly about your data — we will refer such requests to them.

2. What we store

2.1 Account and subscription information

2.2 Customer Data inside your workspace

Whatever you put into Framewyre, which typically includes: leads and their contact details; clients; projects, schedules and tasks; estimates, proposals, change orders and signatures; invoices, payments and ledger entries; suppliers, subcontractors and ratings; timesheets; tools and equipment records; uploaded documents and photos; and the content and metadata of calls, SMS, voicemail and email handled through the connected communication features.

2.3 Technical and usage information

2.4 What we do not want

Framewyre is not designed for payment card numbers, government identity numbers, or protected health information. Please do not upload them.

3. Each customer’s data is isolated

Every subscribing business gets its own workspace (a “tenant”). Records are stored against that tenant, and requests are scoped to the tenant of the signed-in user, so one contractor’s workspace is not readable from another contractor’s account. We do not pool one customer’s records with another’s, and we do not sell, rent or share Customer Data with other customers.

Within our own organisation, access to production data is limited to personnel who need it to operate or support the Service, and is used only for that purpose — for example to investigate a fault you reported or to meet a legal obligation.

4. Why we process information

Where a lawful basis is required, we rely on performance of our contract with you, our legitimate interests in operating and securing the Service, your consent where we ask for it, and compliance with legal obligations.

We do not sell personal information, and we do not use Customer Data to train general-purpose AI models. Where an AI-assisted feature is used inside your workspace, only the content needed for that request is sent to the AI provider described in section 5, for the purpose of returning that result to you.

5. Subprocessors we rely on

We use a small number of reputable third-party providers to run the Service. They act on our instructions, are bound by confidentiality and data-protection obligations, and may only use the data to provide their service to us. Described in general terms, they are:

A current, named list of subprocessors is available at [SUBPROCESSOR LIST URL OR “on request from [PRIVACY EMAIL]”]. We will give notice of a new subprocessor at [SUBPROCESSOR NOTICE METHOD] before it starts processing Customer Data.

Apart from these providers, we disclose information only: to you and your authorised users; where you tell us to (for example, sending a proposal to your client); to professional advisers under confidentiality; where required by law or valid legal process; to protect our rights or someone’s safety; or to an acquirer in a merger or sale, subject to this policy.

6. Where data is processed

Data is processed in [HOSTING REGION / COUNTRY]. If information is transferred to another country, we use an approved transfer mechanism such as standard contractual clauses where one is required.

7. Security

We use measures appropriate to the Service, including encryption in transit, hashed passwords, per-tenant scoping of data access, role-based permissions inside each workspace, and restricted administrative access. No online service can be guaranteed perfectly secure; see the “as is” and liability sections of the Terms of Service and the Beta / No-Fault Policy.

If a breach affects your data and notification is required, we will notify you at the account email address without undue delay and describe what we know and what we are doing.

8. Retention and deletion

Deletion on request. You can ask us to delete your workspace and its data at any time by emailing [PRIVACY EMAIL] from the account owner’s address. We will verify the request, confirm what will be deleted, and complete it within [DELETION REQUEST SLA], except for records we must keep by law. Deletion is permanent and cannot be undone — export first.

9. Your rights and how to make a data request

Depending on where you live, you may have rights to access, correct, delete, restrict or object to processing of your personal information, to receive a portable copy, and to withdraw consent. We do not discriminate against you for exercising these rights.

Contact for data requests: [PRIVACY EMAIL]
Postal address: [MAILING ADDRESS]
Data protection contact: [DATA PROTECTION CONTACT / DPO, IF ANY]

We will acknowledge a request within [REQUEST ACKNOWLEDGEMENT PERIOD] and respond within [REQUEST RESPONSE PERIOD]. We may need to verify your identity first. If you are an end client of a contractor who uses Framewyre, we will forward your request to that contractor, who controls the data.

If you are unhappy with our response you may complain to your local data protection or privacy regulator, in addition to contacting us.

10. Children

Framewyre is a business tool and is not directed to children. We do not knowingly collect personal information from children under [MINIMUM AGE].

11. Changes to this policy

We may update this policy. Material changes will be notified by email to account owners or in the product at least [PRIVACY CHANGE NOTICE PERIOD] before they take effect, and the “last updated” date above will change.