frame.plus
ProductCreatorsAgenciesPricing
LEARNHow it worksThe five-stage loopWhy FrameOne system beats nine toolsAutomate your marketingSet it up once, show up everywhereDocumentationSetup, API and integrations
GET HELPSupportHumans, within the hour?FAQThe questions you'd ask anywayBlogPlaybooks from people shipping
Start free · 7 daysNo card. Every feature. Cancel whenever.
Open Frame
ProductCreatorsAgenciesPricing
RESOURCES
How it worksWhy FrameAutomate your marketingDocumentationSupportFAQBlogOpen Frame
Legal

Privacy Policy

Last updated June 2026

1. Introduction and scope

1.1 About this policy

This Privacy Policy explains how Evryone Ltd ("Evryone", the "Company", "we", "us" or "our") collects, uses, shares, stores and protects personal data in connection with Frame.plus ("Frame", the "Service" or the "Platform") — our AI marketing operating system for small businesses, founders, creators, agencies and multi-business owners.

It tells you:

  • who we are and how to contact us (including the regulator);
  • what personal data we collect, and from whom;
  • the purposes for which we use personal data and the lawful bases we rely on;
  • how we use artificial intelligence and automated processing, and our position on automated decision-making and profiling;
  • who we share personal data with, including our sub-processors;
  • when and how we transfer personal data outside the United Kingdom, and the safeguards we apply;
  • how long we keep personal data;
  • how we keep personal data secure;
  • your rights and how to exercise them;
  • our use of cookies and similar technologies;
  • our position on children's data; and
  • how we will tell you about changes to this policy.

Please read this policy carefully. By using Frame, our website or any related service, you acknowledge that you have read and understood it. Where we need your consent for a particular activity (for example, certain cookies or some marketing), we will ask for it separately.

1.2 Two different roles: when we are a "controller" and when we are a "processor"

It is important to understand that Evryone plays two distinct roles in relation to personal data, depending on the data in question. This affects who is responsible for it and who you should contact about it.

(a) Where Frame is the controller. For some personal data, Evryone decides why and how the data is processed. We are the controller for:

  • personal data relating to our Customers (the businesses and individuals who hold a Frame account) and their authorised users — including account registration, authentication, billing, support, and product usage and analytics; and
  • personal data we process for our own marketing to prospective customers.

This Privacy Policy is the primary notice for that data, and the responsibility for it sits with us.

(b) Where Frame is the processor. A large part of what Frame does is process information that a Customer uploads to, or generates through, the Platform in order to run that Customer's own marketing operations. This includes audience and contact lists, uploaded creative materials, and Outreach lead data (such as the names, business names, work email addresses, job roles and company details of leads), together with email content and email engagement events. We call this "Customer Personal Data".

For Customer Personal Data, the Customer is the controller and Evryone is the processor. We process Customer Personal Data only on the documented instructions of the relevant Customer, under a written data processing agreement (our "DPA"). The Customer is responsible for having a lawful basis to process that data and for providing privacy information to the individuals concerned.

If you are a lead, a contact, a newsletter subscriber, or an individual whose details appear in a Customer's audience list, email campaign or uploaded materials: The business that uploaded or generated your data — not Frame — is the controller of that data and is responsible for it. If you want to know why a business holds your data, to object, to unsubscribe, or to exercise your data-protection rights in relation to that data, please contact that business directly. If you do not know which business holds your data, or you cannot reach them, you can contact us at dpo@frame.plus and we will, where we are able to, pass your request to the relevant Customer and assist them in responding (we describe this further in Section 11).

Section 3 below makes clear, for each category of data, which role applies.


2. Who we are and how to contact us

2.1 The controller

The controller for the purposes described in this policy is:

Evryone Ltd, a company registered in England and Wales.

Registered office[Registered office address]
ICO registration referenceZC182890
Trading name / productFrame.plus ("Frame")

Evryone Ltd, trading as Frame.plus, is registered with the Information Commissioner's Office (ICO) as a data protection fee payer (registration reference ZC182890).

2.2 How to contact us

PurposeContact
Privacy and data-protection questionsprivacy@frame.plus
Data subject requests (access, erasure, etc.) and DPO mattersdpo@frame.plus (attention: the Data Protection Lead)
General and legal enquirieslegal@frame.plus
By postData Protection Lead, Evryone Ltd, [Registered office address]

We have appointed a Data Protection Lead who is responsible for overseeing compliance with this policy and with data-protection law. If you have any concern about how we handle your personal data, please contact us first so that we can try to resolve it.

2.3 Your right to complain to the regulator

You have the right to lodge a complaint with the supervisory authority for data protection in the UK:

Information Commissioner's Office (ICO) Website: ico.org.uk Helpline: 0303 123 1113 Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

We would, however, appreciate the chance to deal with your concerns before you approach the ICO, so please consider contacting us first.

If you are located in the European Union or European Economic Area, you may also have the right to complain to your local data-protection supervisory authority.

2.4 The law we follow

We comply with:

  • the UK GDPR (the retained EU General Data Protection Regulation as it forms part of UK law);
  • the Data Protection Act 2018 ("DPA 2018"); and
  • the Privacy and Electronic Communications Regulations 2003 ("PECR").

Where we process personal data of individuals in the EU/EEA, the EU GDPR (Regulation (EU) 2016/679) may also apply.

This policy is governed by, and should be read in accordance with, the laws of England and Wales.


3. The personal data we collect, and from whom

This section describes the categories of personal data we handle. It is divided into:

  • Section 3.1 — Data we process as controller (mainly about Customers, their authorised users, prospects and website visitors); and
  • Section 3.2 — Data we process as processor (Customer Personal Data, where the Customer is the controller).

We do not intend to process special-category data (such as data revealing health, racial or ethnic origin, religious beliefs, political opinions, trade-union membership, sexual life or orientation, genetic or biometric data), and we instruct Customers not to upload special-category data to Frame. Please do not provide special-category data to us unless we have specifically asked for it and explained why.

3.1 Personal data we process as controller

CategoryWhat it includesWhere we get it from
Account and identity dataYour name, your business's name and business details, your work email address, your role within the business, account preferences and settings.Directly from you when you create or manage an account; from colleagues who invite you to a Customer account; from your business during onboarding.
Authentication dataFrame uses passwordless sign-in. We do not store passwords. We process one-time email codes, sign-in tokens, signed session tokens and related authentication metadata.Generated by us and by your interaction with the sign-in process.
Billing and subscription dataSubscription plan, Frame Credit, Video Credit and Email Send balances and usage, invoices, transaction history and limited billing metadata. Full card details are handled by our payment processor, Stripe — Frame does not store full card numbers.From you when you subscribe; from Stripe (e.g. confirmation of payment, last four digits, card brand, billing country).
Product usage and analytics dataHow you use Frame — features used, content created, campaigns and calendars configured, approvals, credits consumed, dates and times of activity, and similar product telemetry.Generated automatically as you use the Platform.
Support and communications dataMessages you send us, support tickets, chat logs, feedback, survey responses and call notes.Directly from you when you contact us.
Account-deletion audit dataWhen an account is deleted, we retain a random deletion reference, a keyed one-way hash of the deleted account identifier, the account creation and deletion dates, and totals showing the number of owned businesses and memberships removed. We do not retain the account holder's name or email address in this record.Generated by us when an account holder completes self-service account deletion.
Onboarding and brand-study dataInformation gathered when you set up your brand "brain", including details you provide and the results of our automated website study (an automated review of your business website to learn about your brand). This can include personal data if your website contains it.From you, and from the public content of the website you ask us to study.
Device, log and technical dataIP address, device and browser type, operating system, language settings, referring/exit pages, access times, error logs and similar diagnostic information.Collected automatically from your device when you use the website or Platform. Website usage analytics is collected only after you enable the analytics category in the Cookie Banner.
Cookie and similar identifiersCookie IDs and similar identifiers used for authentication, security, preferences and (where you consent) analytics. See Section 12 and our Cookie Policy.Collected via cookies and similar technologies, subject to your choices.
Prospect and marketing dataBusiness contact details of prospective customers (e.g. name, work email, business name), marketing preferences, and your interactions with our marketing communications.From you when you express interest, sign up to hear from us, attend an event, or download materials; from lawful business sources; and through our website.

3.2 Customer Personal Data we process as processor

Where you are a Customer, you upload to and generate within Frame personal data about other people so that Frame can run your marketing. We process this Customer Personal Data as your processor, on your documented instructions, under our DPA. You are the controller of this data. The categories include:

CategoryWhat it typically includes
Leads / contacts (Outreach)Names, business names, work email addresses, job titles and company information, and public profile data sourced through lead-generation features.
Audience and mailing-list contactsContacts and subscribers in audience and mailing lists you upload or build in Frame.
Email message contentThe content of marketing, outreach and newsletter emails sent through Frame, including AI-drafted replies in the Outreach inbox, and inbound emails received in connection with your campaigns.
Email engagement / event dataSends, opens, clicks, replies, bounces, complaints and unsubscribes recorded against your campaigns and contacts.
Uploaded brand assetsImages, video, documents and other creative materials you upload, which may incidentally contain personal data (for example, identifiable people appearing in photographs or video).
Generated contentContent created through Creative Studio and other generative features that may incorporate or reference the above.

We process Customer Personal Data only to provide the Service to the relevant Customer, in accordance with our DPA. As your processor, we do not decide the purposes for which this data is used and we do not use it for our own purposes.


4. The purposes for which we use personal data, and our lawful bases

We only process personal data where we have a lawful basis to do so. The table below sets out, for each purpose, the relevant lawful basis under Article 6 of the UK GDPR. This table concerns the data for which we are the controller (Section 3.1). For Customer Personal Data (Section 3.2), the Customer determines the purposes and lawful basis — see Section 4.2.

4.1 Purposes and lawful bases (Frame as controller)

#PurposePersonal data usedLawful basis (UK GDPR Art 6)
1Creating and administering your account; passwordless sign-in and authenticationAccount, identity, authentication dataContract — Art 6(1)(b): necessary to provide the Service you have signed up for
2Providing the core Service — onboarding and website study, the brand "brain", content planning, Creative Studio (AI image and video generation), the content calendar, scheduling, grouped approvals, publishing, Outreach, Analytics and the Frame AI chat assistantAccount, usage, onboarding and brand-study dataContract — Art 6(1)(b)
3Billing, taking payment, managing your separate Frame Credit, Video Credit and Email Send balances, and managing subscriptionsBilling and subscription dataContract — Art 6(1)(b)
4Customer support, responding to queries and managing our relationship with youSupport and communications data, account dataContract — Art 6(1)(b); and Legitimate interests — Art 6(1)(f): to manage and support our customers effectively
5Keeping the Service secure; preventing, detecting and investigating fraud, abuse and misuse; protecting our systems and other usersUsage, device/log/IP data, authentication dataLegitimate interests — Art 6(1)(f): to protect the security and integrity of the Service and our users
6Improving and developing the Service, including troubleshooting, testing, research and product analytics on how authenticated customers use FrameUsage, device/log data (aggregated or pseudonymised where feasible)Legitimate interests — Art 6(1)(f): to operate, maintain and improve a high-quality Service
7Measuring consented visits to frame.plus, navigation, advertising attribution and sign-up conversionWebsite visitor identifier, page/click events, IP address, country code, campaign parameters, advertising click-ID type and one-way hash, and sign-up linkageConsent — Art 6(1)(a) UK GDPR and PECR; you can withdraw it at any time
8Establishing, exercising or defending legal claims, and protecting our legal rightsAny relevant dataLegitimate interests — Art 6(1)(f): to protect our legal position
9Complying with tax, accounting, regulatory and other legal obligations (including retaining financial records)Billing/transaction data, account dataLegal obligation — Art 6(1)(c)
10Sending our own marketing communications to prospects and (where lawful) existing customers, and measuring their effectivenessProspect and marketing data, contact dataConsent — Art 6(1)(a) / PECR, with a soft opt-in for existing customers where permitted (see Section 4.3)
11Setting non-essential cookies and similar technologiesCookie and device identifiersConsent — Art 6(1)(a) / PECR (see Section 12 and the Cookie Policy)
12Communicating service and administrative messages (e.g. security notices, changes to terms, billing notices)Account, contact dataContract — Art 6(1)(b); and/or Legal obligation — Art 6(1)(c); and/or Legitimate interests — Art 6(1)(f)
13Recording and evidencing completed account deletions, investigating deletion-related disputes, and protecting our legal positionAccount-deletion audit dataLegitimate interests — Art 6(1)(f): to maintain a proportionate, security-protected record that deletion was completed and to establish, exercise or defend legal claims

Where we rely on legitimate interests, we have carried out (or will carry out) a balancing assessment to ensure our interests are not overridden by your interests, rights and freedoms. You can ask us for more information about any of these assessments by contacting privacy@frame.plus, and you have the right to object to processing based on legitimate interests (see Section 11).

4.2 Lawful basis for Customer Personal Data (Frame as processor)

For Customer Personal Data, the Customer determines the purposes and the lawful basis. Frame processes it only on the Customer's documented instructions. We require Customers, under our DPA and terms, to warrant that they have a valid lawful basis for the data they upload and process through Frame and that they have provided any required privacy information to the individuals concerned.

4.3 Electronic marketing and PECR (important for Outreach)

Electronic marketing is also regulated by PECR. The rules differ depending on whether we — or a Customer using Outreach — are marketing to the recipient, and on the type of recipient:

(a) Our own marketing. Where we send our own marketing, we rely on consent or, for our existing customers in respect of similar products and services, the PECR soft opt-in, in each case with a clear and easy way to opt out in every message.

(b) Customer marketing via Outreach. When a Customer uses Outreach to send marketing email, the Customer is responsible for the lawful basis. Under PECR:

  • Marketing email to "corporate subscribers" (corporate bodies such as limited companies, limited liability partnerships and public bodies) is permitted without prior consent, provided the recipient can object/opt out and the sender is clearly identified. A Customer relying on this will typically rely on legitimate interests, supported by a legitimate interests assessment (LIA).
  • Marketing email to "individual subscribers" (consumers, sole traders, and non-LLP partnerships) generally requires consent or the PECR soft opt-in.

Frame requires Customers to warrant that they have a valid lawful basis and to honour objections and unsubscribe requests. To support compliant marketing, Frame provides one-click unsubscribe, suppression lists (so that people who opt out are not contacted again), and sender identification in outbound email. However, the responsibility for lawful targeting and for honouring opt-outs rests with the Customer as controller.


5. Artificial intelligence, automated processing and profiling

Frame is an AI-powered platform. We want to be transparent about how AI is used and about your rights in relation to automated processing.

5.1 How we use AI

  • Frame AI chat assistant — an AI assistant that helps you operate the Platform and answer questions.
  • Content generation — AI is used to plan and generate marketing content (copy, strategy, images, video and long-form articles) which is produced continuously in the background for you to review and approve.
  • Lead targeting and Outreach — AI is used to assist with lead generation and to draft suggested email replies, which you review.
  • Automated website study and brand "brain" — AI reviews your business website and inputs to build a profile of your brand to inform content.

These features may involve profiling in the sense that data is analysed to generate insights, suggestions or targeting (for example, identifying potential leads or tailoring content). Where lead generation analyses public business information to suggest prospects, the Customer is the controller of that activity.

To deliver these features, relevant inputs (which may include personal data contained in your prompts, briefs, brand materials or contact data) are sent to the AI sub-processors listed in Section 6. Our AI sub-processors are contractually prohibited from using API data submitted through Frame to train their models (see Section 6).

5.2 Our position on solely-automated decisions (Article 22)

Article 22 of the UK GDPR gives individuals the right not to be subject to a decision based solely on automated processing (including profiling) that produces legal effects or similarly significant effects about them.

Frame does not make solely-automated decisions that produce legal or similarly significant effects about individuals without a lawful basis and appropriate safeguards. In particular:

  • Frame generates and suggests content, targeting and replies — but a human (you, the Customer) reviews, approves and decides what is published, sent or actioned. Content is generated in the background and presented for your approval; nothing is published or sent purely by the machine without that human approval step being available to you.
  • Where any feature could amount to solely-automated decision-making with significant effects, we will ensure an appropriate lawful basis applies and that safeguards are in place, including the ability to obtain human intervention, to express your point of view, and to contest the decision.

If you believe an automated decision has been made about you in connection with a Customer's use of Frame, please contact the relevant Customer (controller) in the first instance; you may also contact us at dpo@frame.plus.


6. Sharing your personal data and our sub-processors

6.1 Who we share data with

We share personal data only where necessary and lawful, with:

  • Our sub-processors — service providers who process personal data on our behalf to help us deliver Frame (see the list below). They act under written contracts that require them to protect personal data and to process it only on our instructions.
  • Stripe — our payment processor, which acts as an independent controller for payment data it processes (see Section 6.2).
  • Professional advisers — lawyers, auditors, accountants and insurers, where necessary.
  • Authorities and third parties — where required by law, regulation, legal process or governmental request, or to establish, exercise or defend legal claims, or to protect the rights, property or safety of Evryone, our users or others.
  • In a corporate transaction — if we are involved in a merger, acquisition, financing, reorganisation or sale of assets, in which case personal data may be transferred subject to appropriate confidentiality and protection.

We do not sell your personal data.

6.2 Our sub-processors

The table below summarises the third parties that process personal data to help us provide Frame, the purpose, and (where relevant) the location and transfer safeguard. We maintain a current, more detailed Sub-Processor List which is available in our Data Processing Agreement (the sub-processor list is Annex 3 of the DPA), and our Data Processing Agreement (DPA) is available at our Data Processing Agreement (the sub-processor list is Annex 3 of the DPA). We update the Sub-Processor List when sub-processors change.

Sub-processorPurposeLocation / regionTransfer safeguard (where outside UK)
Amazon Web Services (AWS) — Amazon SES v2, Amazon S3, Amazon SNS/SQSTransactional, marketing, outreach and system email sending and inbound receiving (SES v2); storage of uploaded and generated assets, email attachments and raw inbound email (S3); delivery/bounce/complaint/open/click/unsubscribe and inbound event handling (SNS/SQS). Primary data hosting region: AWS Europe (London) — eu-west-2 (United Kingdom).UK (eu-west-2). AWS is US-headquartered.UK hosting; for any transfers outside the UK, the AWS DPA with the UK IDTA / EU SCCs + UK Addendum
MongoDB AtlasPrimary application databaseAWS Europe (London), eu-west-2. Provider US-headquartered.SCCs / UK IDTA
Upstash (Redis)Queues and cache for background jobs (TLS enabled)European UnionTransfer safeguards as applicable
StripePayment processing and subscription billing. Stripe acts as an independent controller for payment data.UK / EU / USStripe DPA + SCCs / IDTA
OpenAIFrame AI chat and still-image generation (ChatGPT Image)United StatesOpenAI API DPA; UK Extension to the EU–US Data Privacy Framework / IDTA. API data is not used to train models.
Anthropic (Claude)Creative orchestration, planning, copy/strategy drafting and reviewUnited StatesAnthropic Commercial Terms + DPA; IDTA. API data is not used to train models.
DeepSeekLong-form blog/article generationChina (People's Republic of China)No UK adequacy decision. Requires an IDTA and a documented Transfer Risk Assessment (TRA). Higher-risk transfer — see Section 7.3
SeedancePremium UGC video generationoutside the UK and EEA (a restricted transfer safeguarded by the UK IDTA / SCCs and a Transfer Risk Assessment)Treated as a restricted transfer requiring IDTA / SCCs + TRA. Higher-risk transfer — see Section 7.3
PexelsStock imagery (no Customer personal data expected to be sent)England and WalesNo Customer personal data expected; safeguards as applicable
ZernioSocial account connection, social publishing/scheduling and ads connectionEuropean UnionDPA + transfer safeguards as applicable
Hosting / CDNHosting and content delivery for the web appAmazon Web Services (AWS)Safeguards as applicable

Each sub-processor is engaged under a written agreement requiring appropriate technical and organisational security measures and compliance with applicable data-protection law, and we carry out due diligence before engaging them.


7. International transfers

7.1 Where your data is hosted

Most personal data processed through Frame is hosted in the United Kingdom, in AWS Europe (London) — eu-west-2. Wherever we can, we keep data within the UK or EEA.

7.2 When we transfer data outside the UK, and the safeguards we use

Some of our sub-processors are located outside the UK. In particular:

  • United States — OpenAI, Anthropic and the AWS parent company are US-headquartered, and Stripe operates across the UK/EU/US.
  • China — content may be sent to DeepSeek (and possibly Seedance) for content generation.

When we transfer personal data outside the UK to a country that is not covered by UK "adequacy" regulations, we put in place an appropriate safeguard under Article 46 of the UK GDPR. Depending on the recipient, we rely on:

  • the UK International Data Transfer Agreement (IDTA), or the EU Standard Contractual Clauses (SCCs) together with the UK Addendum;
  • the UK Extension to the EU–US Data Privacy Framework, where the recipient is certified and the Extension applies; and
  • a documented Transfer Risk Assessment (TRA) where required, together with supplementary measures.

You can ask us for more information about the safeguards we use for a particular transfer, or for a copy of the relevant clauses (with commercial terms redacted), by contacting privacy@frame.plus.

7.3 Higher-risk transfers — China (DeepSeek and possibly Seedance)

We want to be honest and specific about this. Some content-generation features may send data — including briefs or prompts that could contain personal data — to providers located in China (DeepSeek for long-form articles, and possibly Seedance for premium video generation).

China does not benefit from a UK adequacy decision. These transfers are therefore treated as higher-risk restricted transfers. For these transfers we:

  • put in place an IDTA (or SCCs + UK Addendum) with the provider;
  • carry out and document a Transfer Risk Assessment (TRA) specific to that transfer;
  • apply data minimisation — we limit the personal data included in prompts and briefs to what is necessary;
  • do not send special-category data and instruct Customers not to upload it; and
  • apply contractual and technical safeguards to reduce risk.

If you have particular concerns about content generation involving providers located in China, please contact privacy@frame.plus. Where feasible, configuration options may allow certain features to be limited or disabled — speak to us or check your account settings.


8. How long we keep personal data

We keep personal data only for as long as we need it for the purposes set out in this policy, and to meet our legal, regulatory, accounting and reporting obligations. A summary is below; full details are in our Data Retention and Deletion Policy (available to customers on request).

DataRetention (summary)
Account dataKept for the life of your account. When you complete self-service account deletion, the account and associated data are permanently deleted, subject to the separate limited records and backup periods described below.
Account-deletion audit recordRetained for 6 years from the account deletion date and then automatically deleted. The record contains only a random deletion reference, a keyed one-way hash, the account creation and deletion dates, and deletion totals. It contains no name, email address, content, contacts, assets or credentials and is restricted to deletion audit, dispute and legal-claims purposes.
Financial / transaction recordsRetained for 6 years to comply with UK tax and accounting law.
Customer Personal Data (processor data)Returned or deleted on the Customer's instruction, or within 30 days of termination of the Customer's contract, with backups purged within 90 days, in each case as set out in the DPA.
PECR / unsubscribe suppression dataRetained even after other data is deleted, because we must keep a record of opt-outs in order to honour them and not contact people who have unsubscribed.
Security logsRetained for 12 months for security, monitoring and incident-investigation purposes.
Consented website analytics eventsRetained for 180 days, including the visitor identifier, IP address, country code, page/click events and sign-up attribution, then automatically deleted or aggregated.
Marketing data (our own marketing)Kept until you unsubscribe or withdraw consent, after which we retain minimal data needed to honour your preference.

Frame retains only a one-way hashed deletion record with the account date and deletion totals. It cannot be used to restore your data. Although the hash is designed not to reveal the original account identifier, we treat the audit record as pseudonymised personal data, protect it accordingly, and do not use it for marketing, profiling or product personalisation.

An automated database retention control permanently removes the account-deletion audit record when its six-year expiry date is reached. We use secure deletion methods when disposing of personal data, including anonymisation, pseudonymisation or aggregation where appropriate.


9. How we keep personal data secure

We take the security of personal data seriously and apply a programme of technical and organisational measures (TOMs). A summary is below; full details are in our Information Security Policy and Technical and Organisational Measures (summarised in Annex 2 of the DPA; full document available on request).

Our measures include:

  • Encryption in transit (TLS 1.2+) and at rest (AES-256 via AWS KMS / database encryption);
  • Passwordless authentication (email one-time codes) and signed session tokens — we do not store passwords;
  • Role-based access control and least-privilege access;
  • Secrets and key management;
  • Network segmentation and firewalls;
  • Centralised logging, monitoring and alerting (including via SNS/SQS events);
  • Automated backups and tested restore procedures;
  • Vulnerability management and patching;
  • a secure software development lifecycle (SDLC) and code review;
  • sub-processor due diligence and data processing agreements;
  • data minimisation and pseudonymisation where feasible;
  • staff confidentiality obligations and data-protection training; and
  • a documented incident-response process, including notifying the ICO within 72 hours of a notifiable personal-data breach and informing affected individuals and Customers without undue delay where required.

No system is completely secure, but we work hard to protect personal data and to keep our measures under review.


10. Your rights

Subject to certain conditions and exemptions under the UK GDPR and DPA 2018, you have the following rights in relation to your personal data:

  • Right to be informed — to know how your personal data is used (this policy provides that information).
  • Right of access — to obtain a copy of the personal data we hold about you and certain information about how we use it.
  • Right to rectification — to have inaccurate personal data corrected and incomplete data completed.
  • Right to erasure ("right to be forgotten") — to have your personal data deleted in certain circumstances.
  • Right to restriction — to ask us to limit how we use your personal data in certain circumstances.
  • Right to data portability — to receive certain personal data in a structured, commonly-used, machine-readable format, and to have it transmitted to another controller where technically feasible.
  • Right to object — to object to processing based on legitimate interests, and an absolute right to object to direct marketing at any time.
  • Right to withdraw consent — where we rely on consent, to withdraw it at any time (this does not affect the lawfulness of processing before withdrawal).
  • Rights in relation to automated decision-making and profiling — see Section 5.
  • Right to complain to the ICO — see Section 2.3.

10.1 How to exercise your rights

To exercise any of these rights in relation to data for which we are the controller, please contact dpo@frame.plus (or write to us at the postal address in Section 2.2). We may need to verify your identity before responding. We will respond within one month; if your request is complex or you have made several requests, we may extend this by up to two further months and will let you know.

We do not usually charge a fee, but we may charge a reasonable fee, or refuse to act, where a request is manifestly unfounded or excessive.

To object to or unsubscribe from our marketing, use the unsubscribe link in any marketing email, or email privacy@frame.plus. We will action this promptly.

10.2 Requests about Customer Personal Data (processor data)

If your request concerns data that a Customer uploaded to or generated in Frame (for example, you are a lead, contact or subscriber of a business that uses Frame), that business is the controller and is responsible for responding. Please contact that business directly. If you cannot identify or reach them, contact dpo@frame.plus: we will, where we reasonably can, route your request to the relevant Customer and assist them in responding, as required under our DPA. We may need to consult with the Customer before acting, and in some cases we may be unable to identify which Customer holds your data.


11. Cookies and similar technologies

Our marketing site (frame.plus) uses a consent banner. It creates the first-party frame_website_visitor_id local-storage identifier and sends website analytics events only when you enable Usage analytics. When a consented visit arrives through an advertising link, we may retain its campaign parameters and advertising click-ID type and store a one-way hash of the click ID; we do not retain the raw click ID in website analytics. The Frame app (app.frame.plus) keeps you signed in by storing your session token in your browser's localStorage — a strictly-necessary technology — not in a cookie. Frame uses no analytics before consent and no third-party tracking technology for first-party website analytics.

Because Usage analytics, live chat and marketing measurement are non-essential, the Cookie Banner is shown before any of them load. We honour a recognised Global Privacy Control (GPC) signal as a request to reject non-essential technologies. We do not currently respond to Do Not Track (DNT) browser signals, as there is no agreed industry standard.

The table below sets out the strictly-necessary technologies we use:

Name / technologyTypeSet byPurposeDuration
App session tokenStrictly necessary (localStorage)app.frame.plusKeeps you signed inPersists until sign-out or expiry
Security / integrityStrictly necessaryapp.frame.plusSecurity and integrity of the ServiceSession / as needed

Functional chat, usage analytics and advertising measurement are optional categories controlled by the Cookie Banner. For full details, please see our Cookie Policy.


12. Children

Frame is a business-to-business service intended for use by adults aged 18 and over in a professional or business capacity. The Service is not directed at, or intended for, children, and we do not knowingly collect personal data from anyone under 18. If you believe a child has provided personal data to us, please contact privacy@frame.plus and we will take appropriate steps to delete it.

Customers must not use Frame to process the personal data of children, and must not upload such data, unless they have a lawful basis and have informed us.


13. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements or other factors. When we make changes, we will revise the "Last updated" date and version number at the top of this policy.

If the changes are significant, we will take reasonable steps to bring them to your attention — for example, by notice on our website or by email to account holders — before they take effect, where appropriate. We encourage you to review this policy periodically. Your continued use of Frame after an update takes effect indicates your acknowledgement of the updated policy, to the extent permitted by law.


14. Related documents

This policy should be read together with:

  • the Cookie Policy — our Cookie Policy;
  • the Retention & Deletion Policy — our Data Retention and Deletion Policy (available to customers on request);
  • the Information Security Policy / Technical and Organisational Measures — our Information Security Policy and Technical and Organisational Measures (summarised in Annex 2 of the DPA; full document available on request);
  • the Sub-Processor List — our Data Processing Agreement (the sub-processor list is Annex 3 of the DPA); and
  • the Data Processing Agreement (DPA) — our Data Processing Agreement (the sub-processor list is Annex 3 of the DPA) (which governs our processing of Customer Personal Data as processor).

End of Privacy Policy — Evryone Ltd (t/a Frame.plus) — v1.1 — Last updated: 26 July 2026.

frame.plus

The AI marketing operating system. Set up your business once, Frame keeps it visible.

support@ticket.frame.plus

PRODUCT

Product tourHow it worksWatch it workFor creatorsFor agenciesPricing

COMPANY

About FrameDocumentationSupportFAQBlog

LEGAL

Privacy PolicyCookie PolicyTerms of ServiceData Processing Agreement
© 2026 EVRYONE LTD, TRADING AS FRAME.PLUS. ALL RIGHTS RESERVED.
AI MARKETING OS
frame.plus