Appearance
Org Admin Addendum
DRAFT — FOR LEGAL REVIEW. This document has not been reviewed by a lawyer and does not constitute legal advice. All [PLACEHOLDER] markers must be replaced before publication.
Effective date: [PLACEHOLDER — date] Version: 1.0
This Org Admin Addendum ("Addendum") supplements the Terms of Service and Privacy Policy and applies specifically to users with the Organisation Administrator role ("Org Admin"). By accepting this Addendum, you acknowledge the heightened responsibilities that come with the Org Admin role.
Important. Frankfig is a secure messaging and document-signing platform. It is infrastructure for professional communications — it is not a compliance system, a regulated record-keeping service, or an AML/CTF reporting entity. The obligations described in this Addendum rest with you and your organisation, not with Frankfig.
1. Your role and responsibilities
As an Org Admin, you are responsible for:
- Managing your organisation's account, users, and subscription;
- Ensuring that your organisation's use of the Service complies with all applicable laws and professional obligations;
- Making informed decisions about account closure, data export, and retention.
2. AML/CTF compliance
Frankfig is not an AML/CTF reporting entity and does not carry out customer due diligence on behalf of its customers. If your organisation operates in a regulated sector (such as the legal profession or real estate), you are the reporting entity and are responsible for:
- Conducting any required customer identification and verification;
- Complying with the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) and any applicable AUSTRAC guidance;
- Maintaining AML/CTF records as required by law;
- Reporting suspicious matters to AUSTRAC.
The identity and credential information stored in the Service (participant names, licence numbers, verified credentials) exists to give communications an auditable, attributable record — for evidentiary clarity, not for regulated due diligence purposes. This information does not substitute for your own AML/CTF obligations.
3. Record-keeping and litigation holds
Frankfig is messaging and signing infrastructure — it is not your long-term record-keeper.
3.1 Your record-keeping obligations. You are solely responsible for maintaining records that you are required to keep by law, professional rules, or contractual obligation — including but not limited to records required by the Legal Profession Uniform Law, state property legislation, or AUSTRAC.
3.2 Export before closure. Before closing your Frankfig account, you must export all data you need to retain. The in-app export function is available at any time. After the account enters the grace period and is eventually archived and purged, Frankfig cannot guarantee recovery of that data.
3.3 Litigation holds. If your organisation becomes subject to a litigation hold or regulatory investigation requiring preservation of records, it is your responsibility to export and preserve the relevant data from Frankfig before initiating account closure. Frankfig does not hold data on behalf of third-party legal proceedings.
3.4 Frankfig's retention windows. After you close your account:
- A 30-day grace period during which any Org Admin login cancels the deletion;
- An archive period of up to 84 months (~7 years) during which Frankfig platform administrators can restore or export data on request;
- After the archive window, all operational and personal data is permanently purged.
These retention windows are a business choice, not a statutory obligation. See the Privacy Policy for the full detail. You should not rely on these windows as a substitute for your own record-keeping.
4. Data export
4.1 You may export your organisation's data at any time via the in-app export function. Exports include threads, messages, documents, and participant/credential records.
4.2 The export-access log (recording who downloaded what and when) is retained separately as a security record and is not deleted as part of the account purge.
4.3 Frankfig's own billing records (invoices, payment history) are retained for tax purposes and are not part of the customer-data purge.
5. User management
5.1 You are responsible for adding and removing users from your organisation and for ensuring that only authorised individuals have access to the Service.
5.2 When a team member leaves, you must promptly suspend or remove their account.
5.3 On downgrade to the Free tier, accounts that exceed the seat limit will be locked. Locked users cannot log in; their data is preserved. You must manage which users retain access within your tier's limits.
6. Security obligations
6.1 You are responsible for maintaining the confidentiality of your Org Admin credentials.
6.2 You must enforce appropriate internal policies around use of the Service, including multi-factor authentication for privileged users.
6.3 You must notify Frankfig promptly at [PLACEHOLDER — security contact] of any suspected security incident or unauthorised access.
7. Acknowledgement
By accepting this Addendum, you confirm that you:
- Understand that Frankfig is not an AML/CTF reporting entity and that your organisation's compliance obligations are your own;
- Have read and understood your record-keeping obligations and the need to export data before closing the account;
- Accept responsibility for user management within your organisation.
This document is a DRAFT. It must be reviewed by qualified Australian legal counsel — in particular the AML/CTF and record-keeping sections — before publication. All [PLACEHOLDER] markers must be resolved.