Privacy policy

Last updated: 27 July 2026

Who is responsible

The operator of framz.io and cloud-cost.framz.io (“Framz”, “we”) is the data controller for personal data processed through this service. Contact: support@framz.io.

What we collect

Account data: your email address, an argon2id hash of your password rather than the password itself, an optional company name, and sign-in timestamps.

AWS metadata: through the read-only role you create. Billing and cost data, resource configuration metadata such as instance types, volume sizes and lifecycle settings, and utilisation metrics. We cannot collect the contents of your S3 objects, databases, logs or secrets, and do not. There are details on the security page.

Correspondence: emails you send us, and delivery metadata for emails we send you (a log of recipient, template and delivery status).

Why we process it (lawful bases)

To provide the service you asked for, meaning account creation, the free scan, the audit and its report, on the basis of performance of a contract. To send transactional email covering verification, password reset, scan results and report delivery, on the same basis. To keep the platform secure through rate limiting and abuse prevention, on the basis of legitimate interests. We do not send marketing email at present, and we never sell personal data or use it to train AI models.

Where it lives and who processes it

Sub-processors we rely on:

MongoDB Atlas for database hosting, encrypted at rest, with sensitive connection values carrying an additional AES-256-GCM application-level layer · Amazon Web Services for application hosting via Amplify, the scanning infrastructure and email via SES · Cal.com, used only if you book a call, where your name and email prefill the booking form under Cal.com's own privacy terms · Meta Platforms for advertising measurement, used only if you accept marketing cookies, described below · GitHub for source code hosting, which holds no customer data.

Some processors store data in the United States. Where personal data leaves the UK, transfers rely on the UK Addendum to the EU Standard Contractual Clauses or an adequacy decision.

How long we keep it

Scan findings and evidence: deleted automatically 90 days after your audit closes, or 90 days after the scan if you never purchase the audit (active monitoring-retainer clients excepted, for as long as the retainer runs). Account data: until you ask us to delete your account. Email delivery logs: 12 months. Backups age out on the database provider's standard schedule.

Your rights

Under UK GDPR you can request access to, correction of, or deletion of your personal data; object to or restrict processing; and request portability. Email dpo@framz.io and we respond within one month. You can also complain to the Information Commissioner's Office at ico.org.uk.

Cookies and analytics

Strictly necessary: two httpOnly session tokens (`cc_access`, `cc_refresh`) that keep you signed in.

Analytics:we use Google Analytics 4 to understand aggregate site usage (pages visited, referral source). GA4 sets `_ga*` cookies and processes IP addresses and device information under Google's terms; data may be processed in the United States. You can block these cookies in your browser or with the Google Analytics opt-out add-on without affecting the service.

Advertising measurement (consent only):we use the Meta Pixel and Meta Conversions API to measure the effectiveness of our advertising on Facebook and Instagram. Neither runs unless you accept marketing cookies in the consent banner (lawful basis: consent, withdrawable at any time by clearing cookies). When accepted, Meta sets the `_fbp` and `_fbc` cookies, and we send Meta Platforms conversion events (e.g. that a sign-up happened) together with a hashed form of your email address, your IP address and browser information. We never send Meta your AWS account details, scan findings or spend figures. For visitors in certain US states we enable Meta's Limited Data Use mode. See Meta's privacy policy. We also set two first-party cookies of our own: `cc_consent` (remembers your banner choice, 180 days) and `cc_attrib` (which ad or campaign first brought you here, 90 days).

Bot protection:our sign-up, sign-in and password-reset forms use Google reCAPTCHA v3, which analyses interaction signals (IP address, browser information) to distinguish humans from bots, under Google's privacy policy and terms.

Changes

We will post any changes here with a revised date, and email account holders about material ones.