Legal

Privacy Policy

Last updated: 29 July 2026

1. Who we are

Frame Foundry is operated as a joint venture between TwoTen Studio Ltd and Rare Projects Ltd, both companies registered in England and Wales (together “we”, “us”, “our”). For personal data we collect about visitors to our website and our direct customers, TwoTen Studio Ltd and Rare Projects Ltd act as joint data controllers. For personal data our customers store about their members within the platform, we act as a data processor on the customer’s behalf.

Contact for privacy matters: [email protected].

2. Personal data we collect

  • Account and contact data — name, email address, organisation, role and password when you create an account, book a demo or contact us.
  • Billing data — subscription plan, billing address and VAT number. Card details are collected and processed directly by our payment providers; we do not store full card numbers.
  • Usage data — log data, device and browser information, IP address, and how you interact with our website and the platform.
  • Communications — messages you send us, including support requests and demo enquiries.

3. How and why we use personal data

  • To provide, secure and support the Service (performance of a contract).
  • To process payments and manage subscriptions (performance of a contract; legal obligation for accounting records).
  • To improve our website and product, including analytics where you consent to analytics cookies (consent; legitimate interests).
  • To send service communications about your account (performance of a contract) and, where you opt in, marketing communications you can withdraw from at any time (consent).
  • To comply with legal obligations and enforce our terms (legal obligation; legitimate interests).

4. Sharing personal data

We share personal data only with service providers who help us run the Service — such as hosting providers, payment processors (for example Stripe, Apple Pay and PayPal), email delivery services and analytics providers — under contracts that restrict their use of the data. We may also disclose personal data where required by law. We do not sell personal data.

5. International transfers

Where personal data is transferred outside the UK or EEA, we ensure appropriate safeguards are in place, such as UK adequacy regulations or the International Data Transfer Agreement / EU Standard Contractual Clauses.

6. Retention

We keep account data for the life of your account and for up to 12 months after closure, unless a longer period is required for legal, accounting or dispute purposes. Customer Data held on behalf of customers is retained according to their instructions and deleted or returned within 30 days of contract end.

7. Your rights

Under UK GDPR you have rights to access, rectify, erase, restrict and object to processing of your personal data, to data portability, and to withdraw consent where processing is based on consent. To exercise any of these rights, email [email protected]. You also have the right to complain to the Information Commissioner’s Office (ico.org.uk).

8. Cookies

Our use of cookies and similar technologies is described in our Cookie Policy.

9. Security

We apply technical and organisational measures appropriate to the risk, including encryption in transit, access controls and regular review of our infrastructure. No system can be guaranteed 100% secure; if we become aware of a personal data breach affecting you we will notify you and the regulator where required.

10. Changes to this policy

We may update this policy from time to time. Material changes will be highlighted on this page and, where appropriate, notified to you directly. Please check back periodically.