Skip to content
Frameleaf
    • Library & timelineEvery photo and video, in order
    • Search & AIFind anything by describing it
    • People & petsFaces recognised on your server
    • Memories & placesRediscover moments and maps
    • SharingPartners, spaces and links
    • Photo editorNon-destructive, with versions
    • StudioA full video editor, built in
    • For photographersIngest, proof, edit and deliver
    • Library careDuplicates, repairs and trash
    • PrivacyLocked content and what stays home
  • Demo
    • iPhone & iPadNative, written in Swift
    • AndroidNative, written in Kotlin
    • Web appThe full library in any browser
    • NAS appsUnraid, Synology and TrueNAS
    • Frameleaf CloudOptional services for your server
    • Remote accessReach home without open ports
    • Cloud backupEncrypted off-site copies
    • Buddy backupBack up to a friend's server
    • Cloud GPUHeavy AI jobs, paid by use
    • Sign inManage and open your servers
  • Pricing
  • Docs
  • Sign in to Frameleaf Cloud
  • Get Frameleaf
Sign inGet Frameleaf
Legal and policiesPrivacy and data

Data Processing Addendum

Last updated October 3, 2026

On this page
  1. 1. Parties, applicability and precedence
  2. 2. Instructions and lawfulness
  3. 3. Confidentiality and safeguards
  4. 4. Subprocessors
  5. 5. Personal Data Breaches
  6. 6. Rights requests, assessments and regulator cooperation
  7. 7. Audits and evidence
  8. 8. Return, deletion and preservation
  9. 9. International transfers
  10. 10. United States state service-provider terms
  11. 11. Liability, duration and contacts
  12. Annex A — Processing description
  13. Annex B — Technical and organizational measures
  14. Annex C — Restricted-transfer activation record

1. Parties, applicability and precedence

This Data Processing Addendum (DPA) forms part of the Agreement between the customer identified in an accepted business Order (Customer) and Frameleaf, Inc., a Wyoming corporation, or the different Frameleaf supplier expressly identified and accepted in that Order (Frameleaf), where Frameleaf processes personal data on Customer’s behalf in supplying the Services. It applies automatically to that processing under an Order incorporating the Master Terms. It does not require an individual consumer to describe themselves as a business controller.

Customer Personal Data means personal information in content and related data processed on Customer’s behalf. Data Protection Law means applicable laws regulating that processing. Personal Data Breach means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data in Frameleaf’s responsibility. Unsuccessful attempts without actual compromise are not themselves a breach, but material risks may still require action.

Customer is the controller or a processor acting on a controller’s instructions; Frameleaf is its processor or subprocessor for the processing described in Annex A. Frameleaf acts separately for its own legitimate account, billing and legal-compliance data as described in the Privacy Notice. Mandatory transfer instruments prevail over this DPA; this DPA prevails over conflicting commercial terms concerning personal-data processing.

2. Instructions and lawfulness

Customer instructs Frameleaf to process data only to supply the selected Services, follow lawful documented configurations and support requests, secure and maintain those Services, and return or delete data under the Agreement. This DPA, the accepted Order and authorized service settings constitute documented instructions. An optional AI job is not authorized merely by selecting backup.

Customer is responsible for its legal basis, notices, permissions and instructions, including any authority received from another controller. Frameleaf will not knowingly process an instruction that violates applicable law. It will promptly notify Customer if it reasonably believes an instruction infringes Data Protection Law and may suspend the affected operation while the parties resolve it. Where law requires processing beyond instructions, Frameleaf will notify Customer before processing unless the law prohibits notice.

Frameleaf will not sell Customer Personal Data, use it for targeted advertising, train generalized or cross-customer models on it, or retain, use or disclose it for purposes outside this DPA except as permitted or required by applicable law. Frameleaf will not combine it with data from other customers or its own unrelated activities to create cross-customer profiles. Necessary security and service operations remain limited to permitted purposes.

3. Confidentiality and safeguards

Frameleaf will limit data access to authorized people with a legitimate need and ensure they are bound by confidentiality duties that survive access. It will apply the measures in Annex B and the Security, Retention and Deletion Schedule, maintain appropriate written policies, train relevant personnel and periodically assess the measures in light of the processing risk.

Frameleaf may improve or replace a technical measure but will not materially reduce the overall contracted level of protection during the term without an agreed lawful alternative. It will account for readable content, keys, metadata and encrypted payloads separately; encryption does not justify ignoring access controls, deletion protection or recovery dependencies.

4. Subprocessors

Customer generally authorizes the subprocessors identified in the applicable register made available before processing begins through frameleaf.app or [email protected]. That register must identify the legal entity, function, processing location and material data categories, and provide a contact or change-subscription mechanism. A generic description of an unnamed cloud provider is not the completed register.

Frameleaf will give at least 30 days’ advance notice of a new or replacement subprocessor before it processes affected data, except where a necessary urgent security or continuity replacement requires shorter notice. In that case Frameleaf will provide as much notice as reasonably possible, explain the reason and maintain equivalent protection.

Customer may object during the notice period on reasonable documented data-protection grounds. The parties will seek a commercially reasonable resolution, such as an alternative configuration. If no resolution is available before affected processing must begin, Customer may terminate the affected service without penalty and receive a pro-rata refund for unused prepaid service. Frameleaf must not continue a restricted transfer merely because a commercial negotiation is unresolved.

Frameleaf will contractually bind subprocessors to materially equivalent applicable data-protection obligations and remains responsible to Customer for their performance of those obligations. Frameleaf’s affiliate is not exempt from these requirements merely because it is affiliated. Customer’s independently chosen hosting provider is not a Frameleaf subprocessor by that fact alone.

5. Personal Data Breaches

Frameleaf will notify Customer without undue delay and, in any event, within 72 hours after becoming aware of a Personal Data Breach affecting Customer Personal Data, unless a shorter mandatory deadline applies. It will not wait for a complete forensic investigation before sending an initial notice. Awareness requires a reasonable degree of certainty that a qualifying breach occurred, not every unsuccessful attack or unverified alert.

Initial and supplemental notices will describe, to the extent known, the nature and timing, affected services and categories, approximate scope, likely consequences, containment and remediation measures, recommended customer steps and the incident contact. Frameleaf will distinguish known facts from estimates and provide material updates. It will preserve relevant evidence proportionately and document its response.

Customer is responsible for notifications it must make as controller, with Frameleaf’s reasonable assistance. Frameleaf will not identify Customer publicly or notify Customer’s data subjects on its behalf without authorization unless legally required, in which case it will coordinate where permitted. Notice is not an admission of fault. Frameleaf bears the cost of its own required response and cannot condition urgent statutory assistance on advance payment.

6. Rights requests, assessments and regulator cooperation

Taking account of the nature of processing, Frameleaf will reasonably assist Customer with access, correction, portability, deletion, restriction, objection and other valid rights requests. Requests concerning Customer-controlled content received directly by Frameleaf will be forwarded promptly where appropriate, and Frameleaf will not substantively respond on Customer’s behalf without authorization unless law requires it. Requests concerning Frameleaf’s own controller processing remain Frameleaf’s responsibility.

Frameleaf will provide information reasonably needed for Customer’s security assessments, data-protection impact assessments, consultations with authorities and transfer assessments. It will cooperate with competent regulators as required. Extraordinary custom assistance may be charged at an agreed reasonable rate, but ordinary compliance assistance, correcting Frameleaf’s own breach and urgent duties imposed by law are not withheld pending a fee negotiation.

7. Audits and evidence

Frameleaf will make available information reasonably necessary to demonstrate compliance, initially through relevant written responses, policy summaries, security evidence and independently prepared reports where such reports exist. It will not imply that an unavailable certification or report exists.

If that evidence is insufficient, Customer or an independent qualified auditor bound to confidentiality may conduct a proportionate audit, ordinarily once in twelve months with reasonable advance notice. Additional audits are permitted where required by law, a regulator or a material incident reasonably justifies them. Audits must protect other customers’ information, security and business continuity; restrictions cannot make a mandatory audit right illusory. Each party ordinarily bears its own costs, except that Frameleaf bears reasonable corrective and re-audit costs attributable to a demonstrated material breach by Frameleaf, subject to an agreed reasonable scope.

8. Return, deletion and preservation

During the service and applicable retrieval period, Customer may obtain its content through the supported export and restore methods. Cloud Backup retrieval requires the customer-provided bucket key at the authorized storage endpoint and the supported manifests and tools; the storage endpoint decrypts SSE-C objects for the authorized download. Buddy Backup requires the customer-controlled vault keys to decrypt peer-stored blocks. Customer remains responsible for recovery secrets unavailable to Frameleaf.

At service end or on a valid earlier deletion instruction, Frameleaf will return or delete Customer Personal Data according to Customer’s lawful choice and the Security Schedule. Residual copies are isolated and deleted within the stated maximum periods unless a specific legal obligation or an expressly selected lawful immutable-retention rule requires longer preservation. Retained data will not be used for ordinary new purposes. On request, Frameleaf will confirm completion or identify the lawful category and duration of an exception, without falsely certifying physical overwrite of every storage sector.

9. International transfers

Frameleaf will not begin a restricted international transfer without a lawful mechanism and the necessary completed details. The parties will evaluate actual processing countries, remote access, onward transfers, encryption and key access, not merely the country in a billing address.

Where an approved standard contractual clause instrument is needed, the parties will execute or validly incorporate the applicable official text, complete its mandatory annexes and perform any required transfer assessment before transfer. Annex C is the implementation record; it is not a substitute for official mandatory clauses. No certification, adequacy determination or data privacy framework participation is asserted unless it actually applies to the relevant entity and transfer.

If a transfer mechanism becomes unavailable, Frameleaf will promptly inform Customer and adopt a lawful alternative, restrict the affected processing or allow termination of the affected service with a pro-rata unused-service refund. Commercial confidentiality will not prevent disclosure required by a competent authority or mandatory transfer clause, subject to lawful safeguards.

10. United States state service-provider terms

Where applicable state law requires processor, contractor or service-provider restrictions, Frameleaf will process Customer Personal Data solely for the limited business purposes specified here, not sell or share it as those laws define, not use it outside the direct business relationship except as law permits, and provide the same level of privacy protection required of its role. Frameleaf certifies its understanding of and compliance with these contractual restrictions.

Customer may take reasonable and appropriate steps to verify compliance and stop and remediate unauthorized use. Frameleaf will notify Customer if it determines it can no longer meet the applicable obligations. These provisions do not reclassify information Frameleaf legitimately processes as a separate controller for its own account administration, but that distinction cannot be used to evade restrictions on Customer content.

11. Liability, duration and contacts

The Master Terms’ liability provisions apply between the parties except where mandatory law or an applicable transfer instrument requires otherwise. No commercial cap limits a data subject’s mandatory rights against the responsible party. The parties remain independently responsible for their own compliance; this DPA is not an unrestricted customer indemnity.

This DPA continues while Frameleaf retains Customer Personal Data under it. Contact [email protected] for privacy operations and [email protected] for incident coordination. Customer’s authorized privacy and incident contacts are those recorded in the Order or subsequent authenticated notice.

Annex A — Processing description

Subject matter and duration: selected connectivity, encrypted backup, restoration, AI and support processing during the service term and the applicable retrieval and deletion periods.

Nature and purpose: receive and transport authorized data; store encrypted recovery material; manage manifests and retention; return data; perform separately instructed AI operations; secure the service; investigate authorized support requests; and delete data according to instructions.

Data subjects: Customer’s authorized users, employees or contractors where applicable; household members; and people whose information appears in lawfully submitted media or metadata. Customer must identify any material expansion to vulnerable populations or regulated processing before activation.

Data categories: selected photographs, videos, audio and associated metadata; backup payloads, database dumps and manifests; account, peer or device identifiers needed for the service; instructed prompts and outputs; operational and support information. Cloud AI may receive prepared full-media inputs, not only small previews. Uploads go directly to ephemeral processing workers and are deleted immediately when the job finishes; no completed-job upload archive is retained. Delivered results and non-content operational records follow their separate lifecycles. Cloud Backup uses storage-provider SSE-C; Buddy Backup encrypts at the source. The Backup Agreement and Security Schedule specify readability and key custody.

Sensitive data and safeguards: media may reveal health, location, ethnicity, beliefs, intimate life or information about children. Cloud descriptions can include separately enabled identity naming or medical signals, but face detection and recognition run on Customer’s configured machine-learning service. Library database backups may contain local face data under the backup encryption boundary. The service is not authorized for unrestricted biometric surveillance, regulated clinical processing or other specially regulated use absent a separate written agreement and suitable safeguards.

Frequency: recurring or continuous authorized transport and scheduled backup; AI processing per selected job or rule. Customer controls selection and scheduling subject to the Plan. Customer instructions and contacts: as identified in the accepted Order and authenticated service configuration.

Annex B — Technical and organizational measures

Frameleaf will maintain role-based least-privilege access; strong authentication for administrative systems; access logging and revocation; confidentiality and security training; supported encryption in transit and for persistent backup storage; separation of tenants and environments; controlled key handling consistent with the selected mode; vulnerability and patch management; secure development and change controls; incident response; documented retention and deletion; protection of recovery manifests and dependencies; and periodic testing proportionate to risk.

The Security Schedule provides the operative detail. Any numerical availability, recovery, geographic or certification commitment must be expressly identified in the Order and supported by the implementation. Customer is responsible for its endpoints, authorized users and customer-held keys; Frameleaf remains responsible for safeguards within its control.

Annex C — Restricted-transfer activation record

For each restricted transfer, the signed or electronically accepted transfer record must identify: exporter and importer legal identities and roles; authorized contacts; countries and processing; applicable Data Protection Law; transfer mechanism and official version; required clause modules and options; competent supervisory authority and courts where applicable; completed processing and security annexes; authorized subprocessors; supplementary measures and transfer-assessment record; and acceptance date.

For an EEA transfer requiring the European Commission’s standard contractual clauses, use the official applicable instrument and the module matching the actual controller-to-processor or processor-to-processor relationship. For a UK transfer, use the applicable authorized UK instrument or addendum with its required tables. For Switzerland or another jurisdiction, complete the legally required adaptation without contradicting mandatory clauses. Until a necessary record and instrument are completed, the affected restricted transfer is not authorized by this DPA.

More in Privacy and data

  • Privacy NoticeWhat each service collects, who receives it, where it is processed and your privacy rights.
  • Cookie and Similar Technologies NoticeNecessary and optional technologies, and how to set your preferences.
  • Biometric and Sensitive Features NoticeFace recognition on your server and in the cloud, consent, purpose limits and destruction.
  • Security, Retention and Deletion ScheduleOur security baseline and how long backups, AI jobs, relay data, logs and account data are kept.

All legal documents

Frameleaf

A photo and video library for home servers. The Frameleaf Library community edition is open source under AGPLv3.

GitHub

Features

  • Library & timeline
  • Search & AI
  • People & pets
  • Memories & places
  • Sharing
  • Photo editor
  • Studio
  • For photographers
  • Library care
  • Privacy

Apps

  • iPhone & iPad
  • Android
  • Web app
  • NAS apps

Cloud

  • Frameleaf Cloud
  • Remote access
  • Cloud backup
  • Buddy backup
  • Cloud GPU
  • Pricing
  • Sign in to Frameleaf Cloud
  • Status

Get started

  • Get Frameleaf
  • Try the demo
  • Switch to Frameleaf
  • Install guide
  • Documentation
  • FAQ
  • Open source
  • Photo credits

Legal & policies

  • All legal documents
  • Terms of Service
  • Privacy Notice
  • Acceptable Use
  • Refund Policy
  • Security Policy
  • Cookies
© 2026 Frameleaf. Frameleaf Library community edition licensed under AGPLv3.