Noetis — Privacy Policy
Version 1.0 · Effective date: 19 June 2026 · Last updated: 2026-06-19
This Privacy Policy explains how Final Frame ("Noetis", "we") processes personal data. It is written to comply with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and the Dutch implementation (UAVG).
1. Who we are and our two roles
Noetis processes personal data in two distinct capacities:
- As a controller — for personal data of our customers and their users
(account holders): registration, billing, account administration, support, security and our own marketing. This Policy governs that processing.
- As a processor — for personal data of our customers' **website visitors /
End Users, which we process on our customers' behalf (e.g. analytics, heatmaps, session recordings, experimentation, AI features applied to their sites). For that processing, our customer is the controller and the terms are set out in our Data Processing Agreement (DPA)**. If you are a visitor to a website built on Noetis, please consult that website operator's privacy notice; you may also contact us and we will route your request.
Controller contact: Final Frame, Defensie-eiland 110, 3441 VL Woerden, Netherlands, KvK 92376193. Privacy contact: chris@noetis.nl.
2. Personal data we process (as controller)
| Category | Examples | Source |
|---|---|---|
| Identity & account | name, email, password (hashed), organisation, role | you |
| Billing | billing name, address, VAT ID, payment status (card data is handled by Stripe; we do not store full card numbers) | you / Stripe |
| Usage & device | log data, IP address, browser/device, pages used, feature events, timestamps | automatically |
| Support & comms | messages, feedback, correspondence | you |
| Integration tokens | OAuth tokens for Google Analytics / Search Console (encrypted at rest) | you (on connect) |
| Marketing | preferences, email engagement (where applicable) | you / automatically |
We do not intentionally collect special-category data about account holders.
3. Purposes and lawful bases (Art. 6 GDPR)
| Purpose | Lawful basis |
|---|---|
| Provide, operate and secure the Service; authenticate users | Contract (Art. 6(1)(b)) |
| Billing, invoicing, fraud prevention | Contract / Legal obligation (Art. 6(1)(b),(c)) |
| Security, abuse prevention, logging, rate limiting, audit | Legitimate interests (Art. 6(1)(f)) — securing our platform |
| Product analytics and improvement (aggregated/de-identified where feasible) | Legitimate interests (Art. 6(1)(f)) |
| Service and transactional communications | Contract |
| Non-essential cookies and marketing communications | Consent (Art. 6(1)(a)) — withdrawable at any time |
| Comply with legal obligations and defend legal claims | Legal obligation / Legitimate interests |
Where we rely on legitimate interests, we balance them against your rights; you may object (see §8).
4. AI processing
Some features use AI models (operated by OpenAI and Anthropic) to generate content, recommendations and edits. Prompts and the relevant Customer content are transmitted to these providers via their APIs under terms that prohibit using that data to train their generally-available models. We do not use Customer Data or personal data to train public, shared or third-party AI models. AI output may be inaccurate; it is reviewed and published under the customer's control. See the AI Usage & Experimentation Policy.
5. Cookies, analytics, heatmaps and session recordings
- Cookies and similar technologies are described in our Cookie Policy.
Non-essential cookies are set only with consent.
- Analytics, heatmaps, funnels and session recordings on customer websites
are operated by us as processor on the customer's behalf. Session recordings and heatmaps are configured to mask sensitive inputs (e.g. passwords, payment fields) by default. The website operator (our customer) is responsible for providing notice and obtaining any required consent from its visitors.
6. Recipients and subprocessors
We share personal data with service providers ("subprocessors") who process it on our behalf under contract, including:
| Subprocessor | Purpose | Location |
|---|---|---|
| Vercel | Hosting, CDN, serverless compute | EU / US |
| Supabase | Database, authentication, file storage | EU region (where configured) |
| OpenAI | AI image/content generation | US |
| Anthropic | AI content/recommendations (Claude) | US |
| Stripe | Payment processing | EU / US |
| Resend | Transactional email | EU / US |
| Google (customer-authorised) | Analytics / Search Console data the customer connects | EU / US |
The current subprocessor list and any change-notification process are maintained in the DPA. We may also disclose data where required by law or to protect rights, safety and security, and to a successor in a merger or acquisition (with notice).
7. International transfers
Where personal data is transferred outside the EEA (e.g. to US providers), we rely on appropriate safeguards under Chapter V GDPR, primarily the European Commission's Standard Contractual Clauses (2021/914) and, where applicable, the EU–US Data Privacy Framework for certified providers, together with supplementary technical and organisational measures (encryption in transit and at rest, access controls). A copy of the relevant safeguards is available on request at chris@noetis.nl.
8. Your rights
Subject to GDPR conditions, you have the right to: access; rectification; erasure ("right to be forgotten"); restriction; data portability; object to processing based on legitimate interests or to direct marketing; and to withdraw consent at any time (without affecting prior processing). Where decisions are automated and produce legal or similarly significant effects, you have rights under Art. 22 GDPR; Noetis does not make such decisions about account holders.
To exercise rights, email chris@noetis.nl. Account holders can also export their data in-product (Settings → Export) and delete their account (Settings → Delete account). We respond within one month (extendable by two months for complex requests). You may lodge a complaint with the Dutch supervisory authority Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl) or your local authority.
For visitor data we hold as processor, we will refer your request to the relevant controller (the website operator) and assist them as required by the DPA.
9. Retention
We retain personal data only as long as necessary for the purposes above:
- Account data — for the life of the account and a limited period after
closure to handle disputes and legal obligations.
- Billing/tax records — as required by Dutch law (currently 7 years).
- Logs/security data — for a limited rolling period.
- Visitor/processor data — per the customer's instructions and the DPA
retention schedule.
See docs/DATA_RETENTION.md for the detailed schedule. On account deletion we delete or de-identify personal data except where retention is legally required.
10. Security
We apply technical and organisational measures appropriate to the risk, including encryption in transit (TLS) and at rest, application-level encryption of sensitive fields (e.g. OAuth tokens and submitted PII), role-based access control, multi-factor authentication, audit logging, rate limiting, tenant isolation, backups and incident response. See the Security & Compliance Addendum.
11. Children
The Service is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact chris@noetis.nl and we will delete it.
12. Changes
We may update this Policy. Material changes will be notified (e.g. by email or in-product) before they take effect. The "Last updated" date reflects the current version.
Contact: chris@noetis.nl