ModelCharter

Is Framer AI GDPR compliant?

Yes

Framer · Design

Yes. Framer offers a Data Processing Agreement (DPA) for Framer AI, the baseline GDPR control when a vendor processes personal data on your behalf.

What we checked

This assessment separates the consumer product from any business plan. It uses the vendor documents linked below; an unverified item is not a pass.

Data Processing Agreement
Confirmed
Framer publishes a DPA. A DPA is necessary but does not replace your own lawful-basis, DPIA and transfer assessment.
EU data residency
Not offered
No EU-residency option was confirmed in the sources reviewed for this profile.
Default data training
Opt-out required
Non-Enterprise customers grant Framer a license to use de-identified inputs and outputs to train Framer AI models; there is no self-serve opt-out on non-Enterprise plans other than the Enterprise contract.
Business-tier training
No by default
Enterprise customer data is not used for training, and third-party model providers are contractually barred from training on it.
Practical risk: Framer holds SOC 2 and ISO 27001, but only Enterprise excludes your site content from AI training; other plans grant a training license by default with no self-serve opt-out. Hosting is US only and Framer states it is not for PHI.

How to make a decision

Check the precise account tier, written contract and intended data before approving Framer AI. A security certification, DPA or setting can apply to only part of a vendor's service. Keep the source links with your supplier review and revisit them when the vendor changes its terms.

More on Framer AI

See the full Framer AI risk profile, with every data-handling fact and its source, or browse all rated AI tools.