ASection A
Introduction & Security Philosophy
At Franstorm AI LLC ("Franstorm," "Franstorm AI," "we," "us," or "our"), protecting Customer Data and maintaining the security, confidentiality, integrity, and availability of our Services are fundamental components of how we operate.
Franstorm provides cloud-based CRM, automation, communication, AI-enabled, lead-management, integration, and related business services. Because these Services may involve the processing of Personal Data and other Customer Data, we maintain technical and organizational measures designed to protect information throughout its lifecycle.
Our security principles
Confidentiality
Protecting Customer Data and Personal Data from unauthorized access or disclosure.
Integrity
Protecting information and systems against unauthorized or accidental modification.
Availability
Maintaining appropriate availability of systems and Services.
Least Privilege
Limiting access to individuals who reasonably require it to perform authorized responsibilities.
Defense in Depth
Multiple layers of technical and organizational security measures.
Data Minimization
Limiting collection and processing of Personal Data to what's reasonably necessary.
Privacy by Design
Considering privacy during design and development of systems, products, and processes.
Accountability
Maintaining policies, procedures, records, and controls to demonstrate responsible practices.
BSection B
Infrastructure & Data Security
Cloud-based infrastructure
Franstorm operates primarily through cloud-based infrastructure and does not rely on Customer-managed on-premise Franstorm servers or routers for delivery of its standard cloud Services. Cloud infrastructure allows Franstorm to use scalable security, availability, monitoring, access-management, and data-protection capabilities provided through established infrastructure providers.
Amazon Web Services
Franstorm may use Amazon Web Services ("AWS") as an infrastructure and hosting provider for applicable Services. Franstorm remains responsible for the security responsibilities assigned to it within the applicable cloud shared-responsibility model. Use of AWS infrastructure does not transfer Franstorm's contractual data-protection responsibilities to the Customer.
Data security
Franstorm implements technical and organizational measures designed to protect Customer Data and Personal Data against unauthorized access, unauthorized disclosure, accidental loss, unlawful processing, unauthorized alteration, destruction, misuse, and other reasonably foreseeable security risks. Controls may vary according to the nature and sensitivity of the information, relevant system, and associated risks.
Encryption
Data in Transit
Information transmitted between supported systems, applications, integrations, and users may be protected using secure encrypted communication protocols where appropriate.
Data at Rest
Appropriate encryption mechanisms may be used to protect stored data where technically appropriate and supported by infrastructure.
Encryption operates alongside access controls, authentication, monitoring, and organizational safeguards.
CSection C
Access & Authentication
Access control
Access to Franstorm systems and Customer Data is restricted according to legitimate operational requirements, and is not granted merely because an individual is employed or contracted by Franstorm — it must connect to an authorized operational, support, security, compliance, or technical requirement.
| Control | Purpose |
|---|---|
| Role-based access | Access tied to job function |
| Least privilege | Minimum access necessary |
| Authentication requirements | Verify identity before access |
| Password policies | Enforce strong credentials |
| Multi-factor authentication | Additional layer where appropriate |
| Access reviews & revocation | Remove access no longer needed |
Authentication & Account security
Customers are responsible for protecting their own usernames, passwords, authentication credentials, API credentials, integration tokens, and connected third-party accounts. Credentials must not be shared with unauthorized individuals, and Customers must promptly notify Franstorm of any suspected compromise.
Multi-Factor Authentication (MFA)
Where supported or appropriate, Franstorm may provide or require MFA to reduce the likelihood that a compromised password alone permits unauthorized Account access. Customers are encouraged to enable MFA whenever available.
Password security
Users should use strong passwords, avoid reuse across unrelated services, never disclose passwords, and update compromised passwords immediately. Franstorm personnel should never request a Customer's complete password through ordinary support communications.
Personnel security & confidentiality
Access to Customer Data and Personal Data is restricted to authorized Personnel, contractors, consultants, Subprocessors, and other persons with a legitimate need. Authorized persons are required to respect applicable confidentiality and security obligations across Personal Data, Account security, access management, security incidents, and acceptable use.
DSection D
Subprocessors, Privacy & Secure Development
Subprocessor security
Franstorm may engage Subprocessors and third-party service providers to support delivery and operation of the Services. Where a Subprocessor processes Personal Data on Franstorm's behalf, Franstorm requires appropriate contractual and data-protection safeguards consistent with applicable Data Protection Laws and the Franstorm DPA. Subprocessors may only process Personal Data for authorized purposes per contractual instructions.
Data pseudonymization & minimization
Franstorm applies data-minimization principles and may pseudonymize Personal Data where reasonably possible, including reducing, replacing, masking, or truncating non-essential identifiers. Pseudonymization does not necessarily make information anonymous and does not remove applicable obligations where the information remains Personal Data.
Privacy by Design and by Default
Franstorm incorporates privacy and data-protection considerations into relevant product-development and operational processes, including what Personal Data is required, why it's processed, how long it's retained, who has access, appropriate security controls, transfer requirements, Customer configuration options, Data Subject rights, and applicable legal obligations. Where required, Franstorm may conduct or assist with Data Protection Impact Assessments (DPIAs).
Secure product development
Development controls
Access restrictions, code and configuration review, dependency management, environment separation.
Deployment & monitoring
Testing, secure deployment procedures, logging and monitoring, remediation of identified issues.
Vulnerability management
Franstorm performs security assessments and vulnerability-management activities appropriate to its Services and infrastructure. Identified vulnerabilities are evaluated on severity, likelihood of exploitation, potential impact, affected systems, and exposure, with remediation prioritized by risk.
Security reviews & audits
Franstorm conducts internal security reviews and maintains related documentation. Where required by an applicable DPA or contractual obligation, Franstorm may provide reasonable information to demonstrate compliance. Customer audits are subject to applicable contractual terms, confidentiality, security limitations, reasonable notice, and cost allocation.
Logging & monitoring
Franstorm may maintain technical logs and monitoring mechanisms supporting system security, troubleshooting, service availability, incident investigation, fraud detection, performance monitoring, access analysis, abuse prevention, and legal or regulatory compliance. Logs may include IP addresses, timestamps, browser/device information, request information, and authentication events.
ESection E
Incidents, Continuity & Retention
Security incident management
Franstorm maintains processes to identify, assess, investigate, contain, remediate, and document security incidents.
- Detection and initial assessment
- Containment
- Investigation
- Remediation
- Recovery
- Impact assessment
- Notification where legally or contractually required
- Post-incident review
Personal Data breach notification
Where Franstorm acts as Processor, it will follow the Personal Data Breach notification requirements in the applicable DPA, notifying the Customer within the contractually specified period after becoming aware of a qualifying breach. Under GDPR, a qualifying breach may require notification to the competent supervisory authority within 72 hours of becoming aware of it, unless unlikely to result in risk to individuals' rights and freedoms. Where legally required due to high risk, affected Data Subjects will also be informed without undue delay.
Business continuity & availability
Franstorm takes reasonable measures to maintain the availability and resilience of its cloud Services, including infrastructure redundancy, cloud-provider capabilities, monitoring, recovery procedures, and backups where applicable. No cloud or internet-based Service can guarantee uninterrupted availability; it may be affected by maintenance, infrastructure failures, internet outages, third-party interruptions, or events beyond Franstorm's reasonable control.
Backup & recovery
Franstorm may maintain backup and recovery mechanisms appropriate to the Services and infrastructure. Backups support operational resilience and should not substitute for Customer-controlled records or exports. Backup retention and deletion may follow separate schedules from active production data.
Retention & secure deletion
Franstorm retains Personal Data only for periods reasonably necessary for the purposes collected, or as otherwise required by law, contract, security, dispute resolution, or legitimate business obligations. When no longer required, data may be securely deleted, destroyed, anonymized, or disposed of. Where Franstorm acts as Processor, return or deletion following termination is handled per the applicable DPA — Customers should export needed information before access ends, where export functionality is available.
FSection F
Compliance & Data Subject Rights
GDPR compliance
Franstorm maintains a GDPR compliance framework intended to support compliance with Regulation (EU) 2016/679 where applicable, addressing lawfulness, fairness and transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality, and accountability. Additional information is in Franstorm's GDPR Compliance Policy.
Data Subject rights
Where applicable, Franstorm supports rights relating to access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and complaints to supervisory authorities. Where Franstorm acts as Processor, the Customer generally remains responsible for responding to requests relating to Customer-controlled Personal Data, and Franstorm will provide reasonable assistance per the applicable DPA.
International data transfers
Franstorm may process Personal Data outside the country in which a Customer or Data Subject is located. Where required, Franstorm will use appropriate transfer mechanisms, which may include:
- Standard Contractual Clauses approved by the European Commission
- Adequacy decisions
- Applicable Data Privacy Framework mechanisms where valid
- Binding Corporate Rules where applicable
- Other legally recognized transfer safeguards
Third-party integrations
Franstorm may integrate with third-party platforms including email, calendar, cloud storage, productivity, and communication applications. Enabling an integration exchanges certain Customer Data with the selected provider to perform the requested functionality. Customers are responsible for choosing which integrations to enable and reviewing relevant third-party privacy practices, which operate independently of Franstorm.
Google API integrations
Where Customers connect supported Google services, Franstorm may access information necessary to provide the integration through applicable Google APIs. Franstorm's use and transfer of this information adheres to the Google API Services User Data Policy, including applicable Limited Use requirements. Users may revoke permissions through Google Account or integration controls.
Contact
Get in Touch
Franstorm AI LLC
2108 South Blvd #211, Charlotte, NC 28203, United States
Security & General Support: support@franstorm.com
Privacy & Data Protection: privacy@franstorm.com
Website: www.franstorm.com
