Legal · Security & Compliance

Security & Compliance

Franstorm AI LLC describes our security framework, infrastructure practices, data-protection controls, access-management procedures, incident-response practices, and compliance principles.

ASection A

Introduction & Security Philosophy

At Franstorm AI LLC ("Franstorm," "Franstorm AI," "we," "us," or "our"), protecting Customer Data and maintaining the security, confidentiality, integrity, and availability of our Services are fundamental components of how we operate.

Franstorm provides cloud-based CRM, automation, communication, AI-enabled, lead-management, integration, and related business services. Because these Services may involve the processing of Personal Data and other Customer Data, we maintain technical and organizational measures designed to protect information throughout its lifecycle.

Read together with: our Terms of Service, Privacy Policy, GDPR Compliance Policy, Data Processing Agreement (DPA), Acceptable Use Policy, and other applicable contractual or security documentation. Applicable controls may depend on the Services, Subscription, configuration, location, and contractual arrangement.

Our security principles

Confidentiality

Protecting Customer Data and Personal Data from unauthorized access or disclosure.

Integrity

Protecting information and systems against unauthorized or accidental modification.

Availability

Maintaining appropriate availability of systems and Services.

Least Privilege

Limiting access to individuals who reasonably require it to perform authorized responsibilities.

Defense in Depth

Multiple layers of technical and organizational security measures.

Data Minimization

Limiting collection and processing of Personal Data to what's reasonably necessary.

Privacy by Design

Considering privacy during design and development of systems, products, and processes.

Accountability

Maintaining policies, procedures, records, and controls to demonstrate responsible practices.

BSection B

Infrastructure & Data Security

Cloud-based infrastructure

Franstorm operates primarily through cloud-based infrastructure and does not rely on Customer-managed on-premise Franstorm servers or routers for delivery of its standard cloud Services. Cloud infrastructure allows Franstorm to use scalable security, availability, monitoring, access-management, and data-protection capabilities provided through established infrastructure providers.

Amazon Web Services

Franstorm may use Amazon Web Services ("AWS") as an infrastructure and hosting provider for applicable Services. Franstorm remains responsible for the security responsibilities assigned to it within the applicable cloud shared-responsibility model. Use of AWS infrastructure does not transfer Franstorm's contractual data-protection responsibilities to the Customer.

Data security

Franstorm implements technical and organizational measures designed to protect Customer Data and Personal Data against unauthorized access, unauthorized disclosure, accidental loss, unlawful processing, unauthorized alteration, destruction, misuse, and other reasonably foreseeable security risks. Controls may vary according to the nature and sensitivity of the information, relevant system, and associated risks.

Encryption

Data in Transit

Information transmitted between supported systems, applications, integrations, and users may be protected using secure encrypted communication protocols where appropriate.

Data at Rest

Appropriate encryption mechanisms may be used to protect stored data where technically appropriate and supported by infrastructure.

Encryption operates alongside access controls, authentication, monitoring, and organizational safeguards.

CSection C

Access & Authentication

Access control

Access to Franstorm systems and Customer Data is restricted according to legitimate operational requirements, and is not granted merely because an individual is employed or contracted by Franstorm — it must connect to an authorized operational, support, security, compliance, or technical requirement.

ControlPurpose
Role-based accessAccess tied to job function
Least privilegeMinimum access necessary
Authentication requirementsVerify identity before access
Password policiesEnforce strong credentials
Multi-factor authenticationAdditional layer where appropriate
Access reviews & revocationRemove access no longer needed

Authentication & Account security

Customers are responsible for protecting their own usernames, passwords, authentication credentials, API credentials, integration tokens, and connected third-party accounts. Credentials must not be shared with unauthorized individuals, and Customers must promptly notify Franstorm of any suspected compromise.

Multi-Factor Authentication (MFA)

Where supported or appropriate, Franstorm may provide or require MFA to reduce the likelihood that a compromised password alone permits unauthorized Account access. Customers are encouraged to enable MFA whenever available.

Password security

Users should use strong passwords, avoid reuse across unrelated services, never disclose passwords, and update compromised passwords immediately. Franstorm personnel should never request a Customer's complete password through ordinary support communications.

Personnel security & confidentiality

Access to Customer Data and Personal Data is restricted to authorized Personnel, contractors, consultants, Subprocessors, and other persons with a legitimate need. Authorized persons are required to respect applicable confidentiality and security obligations across Personal Data, Account security, access management, security incidents, and acceptable use.

DSection D

Subprocessors, Privacy & Secure Development

Subprocessor security

Franstorm may engage Subprocessors and third-party service providers to support delivery and operation of the Services. Where a Subprocessor processes Personal Data on Franstorm's behalf, Franstorm requires appropriate contractual and data-protection safeguards consistent with applicable Data Protection Laws and the Franstorm DPA. Subprocessors may only process Personal Data for authorized purposes per contractual instructions.

Data pseudonymization & minimization

Franstorm applies data-minimization principles and may pseudonymize Personal Data where reasonably possible, including reducing, replacing, masking, or truncating non-essential identifiers. Pseudonymization does not necessarily make information anonymous and does not remove applicable obligations where the information remains Personal Data.

Privacy by Design and by Default

Franstorm incorporates privacy and data-protection considerations into relevant product-development and operational processes, including what Personal Data is required, why it's processed, how long it's retained, who has access, appropriate security controls, transfer requirements, Customer configuration options, Data Subject rights, and applicable legal obligations. Where required, Franstorm may conduct or assist with Data Protection Impact Assessments (DPIAs).

Secure product development

Development controls

Access restrictions, code and configuration review, dependency management, environment separation.

Deployment & monitoring

Testing, secure deployment procedures, logging and monitoring, remediation of identified issues.

Vulnerability management

Franstorm performs security assessments and vulnerability-management activities appropriate to its Services and infrastructure. Identified vulnerabilities are evaluated on severity, likelihood of exploitation, potential impact, affected systems, and exposure, with remediation prioritized by risk.

Security reviews & audits

Franstorm conducts internal security reviews and maintains related documentation. Where required by an applicable DPA or contractual obligation, Franstorm may provide reasonable information to demonstrate compliance. Customer audits are subject to applicable contractual terms, confidentiality, security limitations, reasonable notice, and cost allocation.

Logging & monitoring

Franstorm may maintain technical logs and monitoring mechanisms supporting system security, troubleshooting, service availability, incident investigation, fraud detection, performance monitoring, access analysis, abuse prevention, and legal or regulatory compliance. Logs may include IP addresses, timestamps, browser/device information, request information, and authentication events.

ESection E

Incidents, Continuity & Retention

Security incident management

Franstorm maintains processes to identify, assess, investigate, contain, remediate, and document security incidents.

  1. Detection and initial assessment
  2. Containment
  3. Investigation
  4. Remediation
  5. Recovery
  6. Impact assessment
  7. Notification where legally or contractually required
  8. Post-incident review

Personal Data breach notification

Where Franstorm acts as Processor, it will follow the Personal Data Breach notification requirements in the applicable DPA, notifying the Customer within the contractually specified period after becoming aware of a qualifying breach. Under GDPR, a qualifying breach may require notification to the competent supervisory authority within 72 hours of becoming aware of it, unless unlikely to result in risk to individuals' rights and freedoms. Where legally required due to high risk, affected Data Subjects will also be informed without undue delay.

Business continuity & availability

Franstorm takes reasonable measures to maintain the availability and resilience of its cloud Services, including infrastructure redundancy, cloud-provider capabilities, monitoring, recovery procedures, and backups where applicable. No cloud or internet-based Service can guarantee uninterrupted availability; it may be affected by maintenance, infrastructure failures, internet outages, third-party interruptions, or events beyond Franstorm's reasonable control.

Backup & recovery

Franstorm may maintain backup and recovery mechanisms appropriate to the Services and infrastructure. Backups support operational resilience and should not substitute for Customer-controlled records or exports. Backup retention and deletion may follow separate schedules from active production data.

Retention & secure deletion

Franstorm retains Personal Data only for periods reasonably necessary for the purposes collected, or as otherwise required by law, contract, security, dispute resolution, or legitimate business obligations. When no longer required, data may be securely deleted, destroyed, anonymized, or disposed of. Where Franstorm acts as Processor, return or deletion following termination is handled per the applicable DPA — Customers should export needed information before access ends, where export functionality is available.

FSection F

Compliance & Data Subject Rights

GDPR compliance

Franstorm maintains a GDPR compliance framework intended to support compliance with Regulation (EU) 2016/679 where applicable, addressing lawfulness, fairness and transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality, and accountability. Additional information is in Franstorm's GDPR Compliance Policy.

Data Subject rights

Where applicable, Franstorm supports rights relating to access, rectification, erasure, restriction, portability, objection, withdrawal of consent, and complaints to supervisory authorities. Where Franstorm acts as Processor, the Customer generally remains responsible for responding to requests relating to Customer-controlled Personal Data, and Franstorm will provide reasonable assistance per the applicable DPA.

International data transfers

Franstorm may process Personal Data outside the country in which a Customer or Data Subject is located. Where required, Franstorm will use appropriate transfer mechanisms, which may include:

  • Standard Contractual Clauses approved by the European Commission
  • Adequacy decisions
  • Applicable Data Privacy Framework mechanisms where valid
  • Binding Corporate Rules where applicable
  • Other legally recognized transfer safeguards

Third-party integrations

Franstorm may integrate with third-party platforms including email, calendar, cloud storage, productivity, and communication applications. Enabling an integration exchanges certain Customer Data with the selected provider to perform the requested functionality. Customers are responsible for choosing which integrations to enable and reviewing relevant third-party privacy practices, which operate independently of Franstorm.

Google API integrations

Where Customers connect supported Google services, Franstorm may access information necessary to provide the integration through applicable Google APIs. Franstorm's use and transfer of this information adheres to the Google API Services User Data Policy, including applicable Limited Use requirements. Users may revoke permissions through Google Account or integration controls.

GSection G

Shared Responsibility, Disclosure & Contact

Customer security responsibilities

Security is a shared responsibility. Customers are responsible for:

  • Protecting login credentials
  • Configuring appropriate User permissions
  • Removing access for former employees or unauthorized Users
  • Enabling available security controls
  • Securing devices used to access Franstorm
  • Maintaining secure third-party integrations
  • Protecting API keys and tokens
  • Reviewing Account activity where appropriate
  • Ensuring Customer Data is collected and processed lawfully
  • Promptly reporting suspected unauthorized activity

Franstorm cannot protect against security incidents caused solely by Customer actions outside its reasonable control, such as voluntary disclosure of passwords to unauthorized persons.

Responsible disclosure

Security researchers who believe they've identified a potential vulnerability should report it privately and responsibly, with sufficient information to reproduce the issue. Researchers must not access more data than necessary to demonstrate the issue, disrupt the Services, destroy or alter Customer Data, conduct social engineering, disclose vulnerabilities publicly before Franstorm has had a reasonable opportunity to investigate, or use research as a basis for extortion.

No absolute security guarantee. No internet transmission, cloud infrastructure, software platform, or electronic storage environment can be guaranteed completely secure. Franstorm continually evaluates its practices and may update controls as technologies, threats, regulations, and business requirements evolve.

Related policies

This Policy should be read together with Franstorm's Terms of Service, Privacy Policy, GDPR Compliance Policy, Data Processing Agreement (DPA), and Acceptable Use Policy. If an executed DPA, Services Agreement, order form, or other specific agreement imposes different or additional security obligations, that agreement controls to the extent expressly provided.

Contact

Get in Touch

Franstorm AI LLC

2108 South Blvd #211, Charlotte, NC 28203, United States

Security & General Support: support@franstorm.com

Privacy & Data Protection: privacy@franstorm.com

Website: www.franstorm.com