Legal
Privacy
Effective: 11 September 2026.
Who we are
FRAME XYZ INC. ("Frame", "we") is responsible for the website information described in this notice. It covers frame.xyz, our enquiry and Blueprint forms, and our EuroFinance photo experience. Contact [email protected] about privacy or your information. Customer platform services are governed by their applicable agreements and notices.
Enquiries and requested downloads
We receive the information you enter, such as your name, work email, company, role and message. Some forms also accept your industry or payment volumes. We use these details to respond, provide the requested material and manage the resulting business conversation.
Blueprint guide requests send your email to HubSpot. Calculator report requests also send your selected workflow and currency, the financial assumptions you enter, and the calculated annual net recurring benefit. Workflow notes are not included. Form submissions include the submitting page and campaign information in its URL. An existing HubSpot visitor identifier is included for attribution only when you have accepted optional tracking.
You can browse without submitting a form. Required fields are needed to process the request. Submitting a form or requesting a report is separate from accepting optional tracking and is not consent to a marketing-email subscription.
Website visits and optional tools
Hosting and security services process network and browser information to deliver the website and prevent abuse. Cloudflare Turnstile verifies enquiry forms independently of optional tracking consent.
After you select Accept optional, Google Analytics, HubSpot, LinkedIn Insight, Snitcher, Vector and Swan can receive IP addresses, browser and device information, identifiers, pages viewed, referring pages and interaction information. We use these tools to understand visits, measure marketing, build advertising audiences and identify potential business interest.
Snitcher identifies visiting companies. Vector and Swan can also match visits with individual business contacts using their identification and enrichment services. Depending on the provider, available information and visitor location, matches may include a name, work email, job title or company. These services can use their own data sources and data partners to make a match.
Open to withdraw permission. See our cookie notice for the tools, storage and choices involved.
EuroFinance photos
When you take or upload a photo through the event service, we store the original and branded image, a collection-code reference, timestamps and temporary download records. Collection does not require your name or email. A browser identifier and hashed IP address help limit guessing and automated abuse.
Someone with your collection code can retrieve your photo, so keep the code private. Individual download links expire after ten minutes; you can use the collection code again while the photo remains available.
The event page and photo collection experience use the same optional tools described above, including when you enter a code, retrieve a photo or use the download button. These tools run only if you have accepted optional tracking. The photo events we send describe collection starting, retrieval succeeding or failing, and use of the download button, with fixed page and form labels. We do not include collection codes, photo contents or private download links in those events. Staff photo-desk pages, sign-in pages, photo APIs and image responses do not load these optional tools.
Why we may use this information
- Legitimate interests: responding to business enquiries and requested downloads, maintaining the related conversation, delivering a photo you request, and keeping these services secure. Our interests are providing the requested service, maintaining relevant business relationships and preventing misuse. We limit this use to what is needed and consider your expectations and rights.
- Consent: optional website analytics, advertising and visitor identification. Where you separately opt in to marketing email, we rely on that consent for the subscription. You can withdraw consent at any time.
- Legal obligations: where we must handle a data-rights request or retain particular information to meet an applicable legal requirement.
Services that receive information
Cloudflare provides website delivery, security and photo-service storage and infrastructure. The photo application also uses OpenAI Sites hosting. Postmark delivers enquiry email, and HubSpot receives contact records and Blueprint submissions. Optional tracking providers receive the visit information described above when you accept those tools. Our cookie notice links to their information.
Some providers operate internationally, so information may be processed outside your country, including in the United States. Our policy requires an applicable transfer basis and, where necessary, safeguards for restricted transfers. Supplier-specific processing locations and transfer arrangements are being checked against that requirement. Contact [email protected] for the current position or information about the applicable safeguards.
How long we keep information
Our policy is to review enquiry, download and associated prospect or campaign records monthly, and delete or anonymise records more than 24 months after your last meaningful interaction with us unless there is a documented continuing need, such as an active customer relationship or an applicable legal obligation. A meaningful interaction is a request, reply, meeting or active business conversation; a passive email open or automated tracking event does not restart this period. We remove information sooner when it is no longer needed.
This is a periodic retention process, not automatic deletion on a fixed day. Records in email, CRM, advertising accounts and other provider systems need their own settings or deletion actions. Our supplier retention review is in progress. Operational security records are reviewed for removal when they are no longer needed to investigate or prevent abuse.
Photo access expires no later than 30 days after creation. The service is configured to run hourly cleanup of expired image files and download records; physical deletion can occur after access expires. Residual photo metadata is separate: our policy is to remove it in the next monthly review once 90 days have passed since the photo expired. That metadata removal is a manual process. To request earlier removal, email us with the collection code and event details.
We act on marketing objections and opt-outs without waiting for the retention review. We keep the minimum suppression record needed to avoid contacting you again, and review that need annually. Records needed for a legal obligation or claim are restricted to that purpose and reviewed separately.
Your rights and choices
Depending on the law that applies and the processing involved, you may have rights to access, correct or erase information, restrict processing, object to processing, receive a portable copy and withdraw consent. You can object to the use of your personal information for direct marketing at any time. Use an unsubscribe link where provided, or email [email protected].
Withdrawing optional tracking permission stops future optional tracking in that browser. It does not itself delete information already received by us or a provider, and does not affect processing that was lawful before withdrawal. Contact us for a data-rights request. We may need proportionate information to confirm your identity and locate the records.
You may complain to the relevant data protection authority, including the UK Information Commissioner's Office or the authority where you live or work in the EEA. You do not have to contact us first.
Updates
We update this notice when our practices or policy change and show the effective date above. Where a new use requires your consent, we will request it.