WHAT IF spaces OÜ (registry code 16602451, Rotermanni 2, 10111 Tallinn, Estonia) ("we", "us", "our") operates Franklin, an AI-based building data and document intelligence platform (the "Platform").
This Privacy Policy explains how we collect, use, disclose, and otherwise process personal data in compliance with Regulation (EU) 2016/679 (the "GDPR") and applicable Estonian data protection law.
Version 1.1 · Effective date: 11 August 2026
1. Who Is Responsible for Your Data
We act as the data controller for personal data we collect and decide about ourselves: your account and login data, platform usage and audit logs, our communications with you, sales and marketing contacts, and website visitor data.
The Platform is built for building documents and building data, which are business documents. It is not intended for the processing of personal data, and clients are instructed not to upload documents containing personal data. Clients are responsible for ensuring that the material they upload is limited to business information. Where personal data nevertheless appears incidentally in an uploaded document (for example, a name or contact detail in a permit, contract, or drawing), we do not use it for any purpose of our own: it remains part of the client's document, is accessible only to that client's authorised users, and is deleted together with the document in accordance with Section 7 or on the client's instruction.
2. Personal Data We Collect
2.1 Account data
When an account is created for you on the Platform, we process:
- full name and e-mail address;
- authentication data: hashed credentials, JWT session tokens, and OAuth identifiers for supported sign-in
- cloud-storage integrations;
- organisation membership and assigned role (org_owner, mgmt_dev_manager, project_manager, project_member, or share_link_user);
- user preferences and account settings.
2.2 Usage and log data
When you use the Platform, we automatically collect:
- system and audit logs: user actions, timestamps, IP addresses, document access events, and processing operations;
- conversational assistant history: the questions you submit and the answers generated, linked to your user ID;
- error and diagnostic data (via our error-tracking tool), which may include user ID, e-mail, IP address, and technical context; on errors, an anonymised session replay of the user interface interaction may be captured to diagnose the issue;
- product analytics and feature-flag data;
- processing status and audit trails per document.
2.3 Business contact and communications data
If you contact us, request a demo, or represent a current or prospective client, we process your name, employer and role, contact details, and the content of our correspondence, stored in our e-mail and customer relationship management systems. We also use your name and e-mail address to send transactional and service communications: platform notifications, digests, invitations to shared workspaces, service and security updates, and notices of changes to this Policy or our terms. These messages form part of the service rather than marketing, so they are not subject to a marketing opt-out while your account is active; optional notification settings can be adjusted in the Platform. The newsletter and other marketing messages always carry an unsubscribe link.
2.4 Website visitor data
When you visit frnkln.ai, we process technical data (IP address, browser type, pages visited) through strictly necessary cookies and, if enabled, analytics as described in Section 9. Our content delivery and security provider processes web traffic metadata (request headers and IP addresses) to route and protect the sites.
3. Purposes and Legal Bases
|
Purpose |
Legal basis (GDPR Art. 6) |
Role |
|---|---|---|
|
Account creation, authentication, and access control |
Art. 6(1)(b) — contract performance |
Controller |
|
Providing platform features, including AI classification, extraction, search, and the conversational assistant |
Art. 6(1)(b) — contract performance |
Controller |
|
Security, fraud prevention, audit logging, and incident response |
Art. 6(1)(f) — legitimate interest in securing the Platform |
Controller |
Error tracking and platform stability |
Art. 6(1)(f) — legitimate interest |
Controller |
|
Responding to enquiries; sales and account management |
Art. 6(1)(f) — legitimate interest; Art. 6(1)(b) where pre-contractual |
Controller |
|
Direct marketing to business contacts (newsletter, product updates) |
Art. 6(1)(f) — legitimate interest |
Controller |
|
Compliance with legal obligations (accounting, tax, responding to authorities) |
Art. 6(1)(c) — legal obligation |
Controller |
Optional analytics and product improvement |
Art. 6(1)(a) — consent (only if analytics cookies are enabled) |
Controller |
Where we rely on legitimate interest, we have assessed that our interest is not overridden by your rights and freedoms; you may object at any time (Section 8).
4. AI Processing — Transparency
The Platform uses third-party AI foundation models for document classification, data extraction, embeddings, and the conversational assistant. In this processing:
- Document text and images are transmitted to the selected AI provider over encrypted connections solely for real-time processing. We do not send personal data beyond what is contained in the documents and queries being processed.
- We do not train custom machine learning models on client data in the current service phase. We have negotiated zero-retention and no-training arrangements with our primary AI providers where available, meaning submitted content is not retained by the provider, not used to train models, and not used for service improvement.
- All AI outputs are labelled as AI-generated, carry confidence scores where applicable, and can be reviewed and overridden by users.
- No automated decision-making within the meaning of GDPR Article 22 takes place: AI classifications and extractions are informational, have no legal or similarly significant effect on individuals, and are subject to human review. If you believe an AI output adversely affects you, you may request human review via the contact in Section 12.
- Under the EU AI Act (Regulation (EU) 2024/1689), the Platform's AI features fall into the limited-risk category; we meet the applicable transparency obligations through output labelling and the disclosures in this Policy and in our Terms of Service.
5. Infrastructure Service Providers
We share personal data only with service providers that help us operate the Platform, bound by data processing terms, and with professional advisers and authorities where required by law. Our current infrastructure service providers:
|
Provider |
Service |
Data processed |
Location |
Transfer mechanism |
|---|---|---|---|---|
Hetzner Online GmbH (Germany) |
Dedicated server hosting — document processing pipeline, assistant, orchestrator |
Documents, AI processing data, assistant data |
EU (Germany) |
N/A (intra-EEA) |
Supabase, Inc. (USA) |
Managed PostgreSQL, authentication, storage, edge functions, realtime |
User data, documents, metadata, embeddings, audit logs |
EU (Ireland, AWS eu-west-1) |
SCCs (with US parent entity) |
Cloudflare, Inc. (USA) |
Frontend hosting (Pages); secure ingress to assistant and API (Tunnel) |
Web traffic (headers, IP addresses) |
Global edge CDN |
SCCs |
OpenAI, Inc. (USA) |
GPT and text-embedding models |
Document text, embeddings |
USA (API) |
SCCs (zero-retention API arrangement) |
Anthropic, PBC (USA) |
Claude models (via API) |
Document text, assistant queries |
USA (API) |
SCCs (zero-retention where available) |
Google LLC (USA) |
Gemini models |
Document images |
USA (API) |
SCCs |
Mistral AI (France) |
Mistral language and vision models |
Document text, images |
EU (France) |
N/A (intra-EEA) |
Functional Software, Inc. (USA) |
Sentry — error tracking |
Error logs, stack traces, user context |
USA |
SCCs |
Dokobit UAB (Lithuania, EU) |
Qualified electronic signing (integration deployed; production activation in progress) |
Signer identification data (name, personal identification code, signature) |
EU |
N/A (intra-EEA) |
Resend, Inc. (USA) |
Transactional e-mail (platform notifications, digests, invites) |
Recipient name, e-mail address, notification content |
EU |
SCCs / DPF |
PostHog (EU cloud) |
Product analytics and feature flags in the application (localStorage-based, no session recording, respects Do-Not-Track) |
Usage events, user ID, device/browser data |
EU (eu.i.posthog.com) |
N/A (intra-EEA) |
MailerLite (Lithuania, EU) |
Newsletter delivery |
Name, e-mail, engagement data |
EU |
N/A (intra-EEA) |
We may also disclose personal data to professional advisers (legal, accounting, audit) under confidentiality obligations, and to courts or public authorities where required by law.
6. International Transfers
Personal data is hosted in the EU (Germany and Ireland). Some infrastructure providers listed above are located in, or have parent entities in, the United States. For such transfers we rely on European Commission-approved Standard Contractual Clauses (GDPR Art. 46(2)(c)), supplemented where appropriate by additional safeguards following EDPB guidance (encryption in transit, zero-retention API arrangements, data minimisation), and where a provider holds a valid certification under the EU–U.S. Data Privacy Framework on an adequacy decision.
7. Retention
|
Data type |
Retention period |
|---|---|
Account data (name, e-mail, preferences, roles) |
Duration of the service relationship + 90 days after termination |
Conversational assistant history |
Duration of the service relationship + 90 days after termination |
System logs and audit trails |
30 days by default |
Error tracking data (Sentry) |
90 days by default |
Business contact and correspondence data |
Duration of the business relationship + up to 3 years after last contact |
|
Newsletter subscriber data (name, e-mail, engagement data) |
Until you unsubscribe or withdraw consent, then deleted within 30 days. |
|
Accounting records containing personal data (invoices, contracts) |
7 years (Estonian Accounting Act) |
Building documents and extracted data |
Retained for the duration of the service agreement and deleted 90 days after termination. |
When a retention period expires, we delete or irreversibly anonymise the data. Copies in encrypted backups are overwritten in accordance with the backup rotation cycle. Data may be retained beyond standard schedules if subject to an ongoing legal hold, dispute, or regulatory investigation.
8. Your Rights
Under the GDPR you have the right to: access the personal data we hold about you (Art. 15); rectification of inaccurate data (Art. 16); erasure in certain circumstances (Art. 17); restriction of processing (Art. 18); data portability in a structured, commonly used, machine-readable format (Art. 20); object to processing based on legitimate interest, including direct marketing (Art. 21); and to withdraw consent at any time where processing is based on consent, without affecting prior processing.
To exercise these rights, contact us at hello@frnkln.ai. We may need to verify your identity. We will respond within one month; this period may be extended by two further months for complex or numerous requests, in which case we will inform you within the first month.
If your request concerns personal data contained in a client's building documents, we will refer the request to the relevant client organisation (the controller) and support its response, as we are not permitted to act on such data independently.
You also have the right to lodge a complaint with a supervisory authority, in particular the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), www.aki.ee, info@aki.ee, or the authority of your habitual residence.
9. Cookies and Similar Technologies
Cookies and similar technologies used on our website and in the Platform are managed through a cookie consent banner. The banner is shown on your first visit and lets you accept or reject each category of non-essential cookies before it is set. The current, itemised list of cookies in use, including their provider, purpose, and storage duration, is maintained in the banner's settings panel rather than in this Policy, so that it stays accurate as our tooling changes. You can review, change, or withdraw your choices at any time by reopening the banner from the link in the website footer.
10. Security
We protect personal data with technical and organisational measures including encryption in transit (TLS 1.2+), encryption at rest, database row-level security isolating each organisation's data, role-based access control, multi-factor authentication for administrative access, audit logging, monitored error tracking, and documented incident response procedures. A summary of our security measures is published in the Franklin Security Overview on frnkln.ai. No system is entirely immune to breaches, please use strong, unique passwords and report suspicious activity immediately. In case of the user not using the aforementioned measures, and that is the most probable cause of breach, we assume no liability for any damages.
11. Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in our data handling practices, legal requirements, or operational reasons. Material changes will be notified by updating the version and date above and, where appropriate, by notice to your registered e-mail address or in the Platform. The current version is always available on the Franklin website (frnkln.ai).