Franklin
About Plans
Book a demo
About Plans Privacy Policy Terms of Service
Franklin

Privacy Policy

WHAT IF spaces OÜ (registry code 16602451, Rotermanni 2, 10111 Tallinn, Estonia) ("we", "us", "our") operates Franklin, an AI-based building data and document intelligence platform (the "Platform").

This Privacy Policy explains how we collect, use, disclose, and otherwise process personal data in compliance with Regulation (EU) 2016/679 (the "GDPR") and applicable Estonian data protection law.

Version 1.1 · Effective date: 11 August 2026

1. Who Is Responsible for Your Data

We act as the data controller for personal data we collect and decide about ourselves: your account and login data, platform usage and audit logs, our communications with you, sales and marketing contacts, and website visitor data.

The Platform is built for building documents and building data, which are business documents. It is not intended for the processing of personal data, and clients are instructed not to upload documents containing personal data. Clients are responsible for ensuring that the material they upload is limited to business information. Where personal data nevertheless appears incidentally in an uploaded document (for example, a name or contact detail in a permit, contract, or drawing), we do not use it for any purpose of our own: it remains part of the client's document, is accessible only to that client's authorised users, and is deleted together with the document in accordance with Section 7 or on the client's instruction.

2. Personal Data We Collect

2.1 Account data

When an account is created for you on the Platform, we process:

  • full name and e-mail address;
  • authentication data: hashed credentials, JWT session tokens, and OAuth identifiers for supported sign-in
  • cloud-storage integrations;
  • organisation membership and assigned role (org_owner, mgmt_dev_manager, project_manager, project_member, or share_link_user);
  • user preferences and account settings.

2.2 Usage and log data

When you use the Platform, we automatically collect:

  • system and audit logs: user actions, timestamps, IP addresses, document access events, and processing operations;
  • conversational assistant history: the questions you submit and the answers generated, linked to your user ID;
  • error and diagnostic data (via our error-tracking tool), which may include user ID, e-mail, IP address, and technical context; on errors, an anonymised session replay of the user interface interaction may be captured to diagnose the issue;
  • product analytics and feature-flag data;
  • processing status and audit trails per document.

2.3 Business contact and communications data

If you contact us, request a demo, or represent a current or prospective client, we process your name, employer and role, contact details, and the content of our correspondence, stored in our e-mail and customer relationship management systems. We also use your name and e-mail address to send transactional and service communications: platform notifications, digests, invitations to shared workspaces, service and security updates, and notices of changes to this Policy or our terms. These messages form part of the service rather than marketing, so they are not subject to a marketing opt-out while your account is active; optional notification settings can be adjusted in the Platform. The newsletter and other marketing messages always carry an unsubscribe link.

2.4 Website visitor data

When you visit frnkln.ai, we process technical data (IP address, browser type, pages visited) through strictly necessary cookies and, if enabled, analytics as described in Section 9. Our content delivery and security provider processes web traffic metadata (request headers and IP addresses) to route and protect the sites.

3. Purposes and Legal Bases

Purpose

Legal basis (GDPR Art. 6)

Role

Account creation, authentication, and access control

Art. 6(1)(b) — contract performance

Controller

Providing platform features, including AI classification, extraction, search, and the conversational assistant

Art. 6(1)(b) — contract performance

Controller

Security, fraud prevention, audit logging, and incident response

Art. 6(1)(f) — legitimate interest in securing the Platform

Controller

Error tracking and platform stability

Art. 6(1)(f) — legitimate interest

Controller

Responding to enquiries; sales and account management

Art. 6(1)(f) — legitimate interest; Art. 6(1)(b) where pre-contractual

Controller

Direct marketing to business contacts (newsletter, product updates)

Art. 6(1)(f) — legitimate interest

Controller

Compliance with legal obligations (accounting, tax, responding to authorities)

Art. 6(1)(c) — legal obligation

Controller

Optional analytics and product improvement

Art. 6(1)(a) — consent (only if analytics cookies are enabled)

Controller

Where we rely on legitimate interest, we have assessed that our interest is not overridden by your rights and freedoms; you may object at any time (Section 8).

4. AI Processing — Transparency

The Platform uses third-party AI foundation models for document classification, data extraction, embeddings, and the conversational assistant. In this processing:

  • Document text and images are transmitted to the selected AI provider over encrypted connections solely for real-time processing. We do not send personal data beyond what is contained in the documents and queries being processed.
  • We do not train custom machine learning models on client data in the current service phase. We have negotiated zero-retention and no-training arrangements with our primary AI providers where available, meaning submitted content is not retained by the provider, not used to train models, and not used for service improvement.
  • All AI outputs are labelled as AI-generated, carry confidence scores where applicable, and can be reviewed and overridden by users.
  • No automated decision-making within the meaning of GDPR Article 22 takes place: AI classifications and extractions are informational, have no legal or similarly significant effect on individuals, and are subject to human review. If you believe an AI output adversely affects you, you may request human review via the contact in Section 12.
  • Under the EU AI Act (Regulation (EU) 2024/1689), the Platform's AI features fall into the limited-risk category; we meet the applicable transparency obligations through output labelling and the disclosures in this Policy and in our Terms of Service.

5. Infrastructure Service Providers

We share personal data only with service providers that help us operate the Platform, bound by data processing terms, and with professional advisers and authorities where required by law. Our current infrastructure service providers:

Provider

Service

Data processed

Location

Transfer mechanism

Hetzner Online GmbH (Germany)

Dedicated server hosting — document processing pipeline, assistant, orchestrator

Documents, AI processing data, assistant data

EU (Germany)

N/A (intra-EEA)

Supabase, Inc. (USA)

Managed PostgreSQL, authentication, storage, edge functions, realtime

User data, documents, metadata, embeddings, audit logs

EU (Ireland, AWS eu-west-1)

SCCs (with US parent entity)

Cloudflare, Inc. (USA)

Frontend hosting (Pages); secure ingress to assistant and API (Tunnel)

Web traffic (headers, IP addresses)

Global edge CDN

SCCs

OpenAI, Inc. (USA)

GPT and text-embedding models

Document text, embeddings

USA (API)

SCCs (zero-retention API arrangement)

Anthropic, PBC (USA)

Claude models (via API)

Document text, assistant queries

USA (API)

SCCs (zero-retention where available)

Google LLC (USA)

Gemini models

Document images

USA (API)

SCCs

Mistral AI (France)

Mistral language and vision models

Document text, images

EU (France)

N/A (intra-EEA)

Functional Software, Inc. (USA)

Sentry — error tracking

Error logs, stack traces, user context

USA

SCCs

Dokobit UAB (Lithuania, EU)

Qualified electronic signing (integration deployed; production activation in progress)

Signer identification data (name, personal identification code, signature)

EU

N/A (intra-EEA)

Resend, Inc. (USA)

Transactional e-mail (platform notifications, digests, invites)

Recipient name, e-mail address, notification content

EU

SCCs / DPF

PostHog (EU cloud)

Product analytics and feature flags in the application (localStorage-based, no session recording, respects Do-Not-Track)

Usage events, user ID, device/browser data

EU (eu.i.posthog.com)

N/A (intra-EEA)

MailerLite (Lithuania, EU)

Newsletter delivery

Name, e-mail, engagement data

EU

N/A (intra-EEA)

We may also disclose personal data to professional advisers (legal, accounting, audit) under confidentiality obligations, and to courts or public authorities where required by law.

6. International Transfers

Personal data is hosted in the EU (Germany and Ireland). Some infrastructure providers listed above are located in, or have parent entities in, the United States. For such transfers we rely on European Commission-approved Standard Contractual Clauses (GDPR Art. 46(2)(c)), supplemented where appropriate by additional safeguards following EDPB guidance (encryption in transit, zero-retention API arrangements, data minimisation), and where a provider holds a valid certification under the EU–U.S. Data Privacy Framework on an adequacy decision.

7. Retention

Data type

Retention period

Account data (name, e-mail, preferences, roles)

Duration of the service relationship + 90 days after termination

Conversational assistant history

Duration of the service relationship + 90 days after termination

System logs and audit trails

30 days by default

Error tracking data (Sentry)

90 days by default

Business contact and correspondence data

Duration of the business relationship + up to 3 years after last contact

Newsletter subscriber data (name, e-mail, engagement data)

Until you unsubscribe or withdraw consent, then deleted within 30 days.

Accounting records containing personal data (invoices, contracts)

7 years (Estonian Accounting Act)

Building documents and extracted data

Retained for the duration of the service agreement and deleted 90 days after termination.

When a retention period expires, we delete or irreversibly anonymise the data. Copies in encrypted backups are overwritten in accordance with the backup rotation cycle. Data may be retained beyond standard schedules if subject to an ongoing legal hold, dispute, or regulatory investigation.

8. Your Rights

Under the GDPR you have the right to: access the personal data we hold about you (Art. 15); rectification of inaccurate data (Art. 16); erasure in certain circumstances (Art. 17); restriction of processing (Art. 18); data portability in a structured, commonly used, machine-readable format (Art. 20); object to processing based on legitimate interest, including direct marketing (Art. 21); and to withdraw consent at any time where processing is based on consent, without affecting prior processing.

To exercise these rights, contact us at hello@frnkln.ai. We may need to verify your identity. We will respond within one month; this period may be extended by two further months for complex or numerous requests, in which case we will inform you within the first month.

If your request concerns personal data contained in a client's building documents, we will refer the request to the relevant client organisation (the controller) and support its response, as we are not permitted to act on such data independently.

You also have the right to lodge a complaint with a supervisory authority, in particular the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), www.aki.ee, info@aki.ee, or the authority of your habitual residence.

9. Cookies and Similar Technologies

Cookies and similar technologies used on our website and in the Platform are managed through a cookie consent banner. The banner is shown on your first visit and lets you accept or reject each category of non-essential cookies before it is set. The current, itemised list of cookies in use, including their provider, purpose, and storage duration, is maintained in the banner's settings panel rather than in this Policy, so that it stays accurate as our tooling changes. You can review, change, or withdraw your choices at any time by reopening the banner from the link in the website footer.

10. Security

We protect personal data with technical and organisational measures including encryption in transit (TLS 1.2+), encryption at rest, database row-level security isolating each organisation's data, role-based access control, multi-factor authentication for administrative access, audit logging, monitored error tracking, and documented incident response procedures. A summary of our security measures is published in the Franklin Security Overview on frnkln.ai. No system is entirely immune to breaches, please use strong, unique passwords and report suspicious activity immediately. In case of the user not using the aforementioned measures, and that is the most probable cause of breach, we assume no liability for any damages.

11. Changes to This Policy

We may update this Privacy Policy periodically to reflect changes in our data handling practices, legal requirements, or operational reasons. Material changes will be notified by updating the version and date above and, where appropriate, by notice to your registered e-mail address or in the Platform. The current version is always available on the Franklin website (frnkln.ai).

Franklin

One place for everything known about a building project - every drawing, model and decision, compared, tracked and organised.

About Plans Privacy Terms hello@frnkln.ai
© 2026 WHAT IF spaces OÜ Reg. nr. 16602451 Rotermanni 2-11, Tallinn, Estonia