Skip to main content
ControlFrame

Privacy and data notice

Effective August 28, 2026. This notice describes the public-site, inquiry, identity, session, and workspace-access data paths currently implemented by ControlFrame.

Review status
This is a factual operational notice, not a certification or substitute for a customer data-processing agreement. External counsel review is required; material changes to the implemented data path must be reflected here before release.

Lead requests

The contact and scoping details you choose to submit: name, work email, company, role, framework interests, deployment preference, and free-text context. We also retain campaign parameters and the referring page path when present; query strings are stripped from the stored referrer.

Public sales-route performance

For a 10% anonymous browser-session sample initially loaded on one of six allowlisted public sales routes—the homepage, Solutions, Auditors, Insights, Resources, or Frameworks—we measure Largest Contentful Paint, Interaction to Next Paint, and Cumulative Layout Shift. The document receives one fixed coarse route template: public-home, public-solutions, public-auditors, public-insights, public-resources, or public-frameworks. Its measurement gate closes permanently if it navigates away from the initial route. Each measurement is reduced to the metric value, compact or wide viewport class, coarse route template, and deployed source commit. We do not send a cookie, sample ID, page URL, identity field, referrer, DOM text, form value, user agent field, or Web Vitals entry object. Global Privacy Control and Do Not Track opt the browser out.

Account and workspace identity

Invitation and account flows process the name, work email, organization, membership role, invitation state, and identity-provider identifiers needed to establish the account. Password-based environments store a one-way password verifier, never the plaintext password. Enterprise single sign-on records the verified issuer, subject, authentication time, and approved authentication-method context needed to enforce access and step-up requirements.

Sessions, authorization, and audit records

ControlFrame processes signed session identifiers, tenant and project membership, role and authorization decisions, security events, and audit-log entries to authenticate users, isolate workspaces, investigate abuse, and preserve required evidence custody. These records are not used for advertising or behavioral profiling.

Why we use it

Only to respond to the request, prepare the requested working session, prevent abusive automated submissions, and understand which public ControlFrame path led to the inquiry. The form is not attached to a newsletter or automated marketing sequence.

Where it is processed

Private Netlify Blob stores hold lead records and daily Web Vitals histograms. Supabase-hosted PostgreSQL holds account, membership, session, authorization, and audit records. Resend carries configured invitation, verification, password-reset, recipient, and inquiry emails. Enterprise identity providers process sign-in under the customer's own provider relationship. Provider locations and current contractual status are stated in the subprocessor register; no broader residency promise is implied here.

Review subprocessors

Lead retention and deletion

Raw lead records are assigned a deletion time 90 days after submission and the lifecycle worker removes them automatically. If a commercial relationship begins, necessary contact information may move into the applicable customer or contracting system under its own retention terms.

Performance retention

A daily worker keeps the current UTC date and the preceding 34 UTC dates of public Web Vitals aggregates, then removes valid older aggregates. Because the application stores no per-visit performance record or sample identifier, there is no individual performance profile to access, correct, or delete. Missing metrics remain unavailable rather than being converted to zero.

Account and audit retention

Account, membership, session-security, and audit records are retained while needed to operate the workspace, enforce access, maintain evidence custody, meet an executed agreement, or satisfy a legal preservation obligation. Deactivation blocks access; deletion or correction requests are evaluated against tenant-administration, security, audit-integrity, and contractual retention requirements. A customer agreement or data-processing agreement can set a narrower schedule for a named deployment.

Security and sharing

Lead identifiers and abuse-limit keys do not expose raw email or IP values. Access is limited to operating the inquiry workflow. We do not sell submitted contact data. Service providers receive only the data required to store the request or deliver its human notification.

Access, correction, or early deletion

Email sam.sweilem@lockedinlabs.ai with the lead reference shown after submission or the work email associated with an account. We will use that information to locate the applicable record, answer a data question, correct eligible data, or process a deletion request subject to tenant-administration, audit-integrity, contractual, and legal preservation obligations.

Operator and review status

ControlFrame is operated by Locked In Labs. This notice records implemented processing paths and is not a substitute for the data-processing agreement governing a customer deployment. Counsel review remains required before relying on it for a jurisdiction-specific legal basis, international-transfer mechanism, or regulated-data engagement.

Privacy and data notice | ControlFrame