Privacy Policy

Effective date: September 01, 2026

This Privacy Policy explains how Francis ApS ("Francis", "we", "us") handles personal data about visitors to our website, our Users, and our marketing contacts.

It doesn't cover the data you put into the Francis platform to do your work, your financial and business data, and anything else in your Workspace. We handle that on your organisation's behalf under your Terms of Service and Data Processing Addendum (DPA).

Who we are

Francis ApS (CVR 42336866), Nordre Fasanvej 108B, 2TV, 2000 Frederiksberg, Denmark, is the controller of the personal data described here. For any privacy question, contact us at support@francis.app.

The data we collect

Account and relationship data. When you create or administer an account, we collect details such as your name, email address, job title and company.

Website and usage data. When you visit our website we automatically receive standard technical data: your IP address, device and browser information, the pages you view, the date and time, and your general (city/region-level) location.

Cookies and similar technologies. We use only essential cookies, needed to run our website and Platform securely; we don't use analytics or advertising cookies. The details are in our Cookie Policy.

Messages you send us. When you contact us (for example, by email or the support chat), we keep that correspondence so we can help you.

Calls and meetings. When we have a call or meeting with you, such as a demo, onboarding or support session, we may record it and keep a recording or transcript, so we can follow up accurately and support you properly. Someone from Francis is always on the call, and you can ask us to stop recording, or to delete a recording or transcript at any time, at support@francis.app. We may also review these conversations to capture feedback and improve our products and services, as described below.

Contacts we collect from other sources. To reach a finance audience that may be interested in Francis, we collect limited business contact details, such as name, job title, company, and a work email or phone number, from publicly available professional sources and from third-party data providers. We check that someone is a relevant fit before adding them or getting in touch.

You don't need to identify yourself just to browse the website; personal data is only required if you create an account.

We use the data above to:

  • Provide and administer your account and our website: performance of our contract with you.
  • Bill and take payment: performance of our contract, and compliance with legal obligations (e.g. bookkeeping law).
  • Keep our service secure, prevent fraud and abuse, and send you service messages (billing, security and operational notices): our legitimate interests in keeping the Services secure, preventing fraud, and operating our business reliably, and compliance with legal obligations.
  • Record calls and meetings: our legitimate interest in having an accurate record of what we discussed and agreed, rather than relying on notes. You can ask us not to record, or to delete a recording, at any time.
  • Improve and develop our products and services: our legitimate interest in understanding how customers use Francis and what they need, so we can build and improve features. This includes analysing our conversations with you (such as call transcripts, emails and support chats) to capture feedback and improve onboarding, and we may use AI tools to help. We don't use your Customer Data for product development, and we never use it to train AI models.
  • Send you marketing about Francis: your consent. You can opt out at any time using the unsubscribe link or by emailing support@francis.app.
  • Reach out to a finance audience about Francis: our legitimate interest in promoting our business to people likely to be interested. You can object at any time, and we'll stop contacting you and delete your details, just email support@francis.app.
  • Produce aggregated or anonymised insights (for example, usage trends) that don't identify you.
  • Comply with the law and respond to lawful requests: compliance with legal obligations.

Where we rely on your consent, you can withdraw it at any time. We do not use personal data to train or improve AI or machine-learning models, except data that has been aggregated and irreversibly anonymised so that it no longer identifies you, consistent with our Terms of Service. We also don't make decisions about you by solely automated means that have legal or similarly significant effects on you.

Who we share it with

  • Service providers. Companies that help us run Francis handle personal data on our behalf and only on our instructions. These include providers for hosting and infrastructure, email and communications, customer support, payment and billing, CRM and marketing, contact-data enrichment, design and product development, and AI providers that help us assist support and analyse our conversations with you. Any AI provider we use is contractually barred from using your data to train its models, and keeps it only for a limited period, and only to deliver the service to us, to detect and prevent misuse of its services, or where the law requires it. The sub-processors that handle the data you put into the Platform (where we act as your processor) are listed in or referenced by our DPA. A current list of the providers that handle the account, contact and marketing data covered by this Policy is available on request at support@francis.app.
  • Professional advisers and authorities, where we're legally required to, or to establish or defend legal claims.
  • A buyer or investor, if we're involved in a financing, merger, acquisition or sale of our business.

We do not sell your personal data, and we don't use third-party advertising networks or tracking cookies. Our website uses only essential cookies, as described in our Cookie Policy.

International transfers

We process personal data in the EU. Some of our service providers may process it outside the EU/EEA, including in the United States and the United Kingdom. Where that happens, we put appropriate safeguards in place as required by the GDPR, such as the European Commission's Standard Contractual Clauses, an adequacy decision, or another lawful transfer mechanism where applicable. You can ask us which countries are involved, and for a copy of the safeguards we rely on, by emailing support@francis.app. This mirrors the approach in our Terms of Service and DPA.

How long we keep it

We keep personal data only as long as we need it for the purposes above:

  • Account data: while you are part of a Workspace. Once you are no longer associated with any Workspace and have not signed in for more than three months, we anonymise your personal data.
  • Marketing data: until you opt out or ask us to stop.
  • Website and technical data (such as server, delivery and security logs, including IP addresses): we keep these only as long as we need them to keep the website and Platform secure and working properly, and delete them once we don't.
  • Conversations and correspondence (emails, support chats, and call recordings or transcripts): we keep these only as long as we need them for the purposes described above, such as supporting you, keeping our records, and improving our products, after which we delete or anonymise them.

We also keep records we're legally required to retain (for example, invoicing data under bookkeeping law). When we no longer need personal data, we delete it securely. In-product Customer Data is kept and deleted as described in the Terms of Service and DPA.

Your rights

If you're in the EU, EEA, UK or a country with similar laws, you have the right to:

  • be informed about how we use your personal data;
  • access your data and have it corrected;
  • have your data erased ("right to be forgotten");
  • restrict or object to how we use it;
  • data portability;
  • withdraw consent, where we rely on it; and
  • complain to a supervisory authority.

To exercise any of these, email us at support@francis.app and we'll respond within the time the law requires. You can also complain to the Danish Data Protection Agency, Datatilsynet (see how to complain), or to the authority in your own country.

Security

We use appropriate technical and organisational measures to protect personal data. No website or internet transmission is ever completely secure, so we can't guarantee absolute security, but we work to protect your data and keep our measures current. More detail on how we protect Customer Data is in our DPA.

Children

Francis is a business product, not intended for or directed at children. We don't knowingly collect personal data from children.

Our website may link to other sites we don't control. We're not responsible for their content or privacy practices, so please review their own policies before sharing data with them.

Changes to this Policy

We may update this Policy from time to time. We'll post changes here with a new effective date, and we'll give you appropriate notice of any material change.

Contact

Questions about this Policy? Email us at support@francis.app.

Controller: Francis ApS, CVR 42336866, Nordre Fasanvej 108B, 2TV, 2000 Frederiksberg, Denmark.