FlowConsent
ServicesHow it worksPricingBlogDocumentation
ServicesHow it worksPricingBlogDocumentationLog inTry FlowConsent
Log inTry FlowConsent
FlowConsent

GDPR-compliant consent, EU-hosted, live in under ten minutes — without a cookie wall.

EU-HOSTED·RGPD·SOC 2
Product
  • Services
  • How it works
  • Pricing
  • Extension
Company
  • Blog
  • Documentation
  • Solutions
  • FlowConsent App
Legal
  • Privacy Policy
  • Terms of Service
  • Legal notice
  • Cookies
© 2026 FlowConsent by BeBranded. All rights reserved.
FrancaisDeutschEspanol
All systems operational

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Framework
  4. Frappe

Frappe

OtherWebsite

Related services

_

_hyperscript

_hyperscript is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. _hyperscript supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, _hyperscript ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other
A

ABP Framework

ABP Framework is a development framework and toolkit providing developers with a structured foundation for building modern web applications. It offers reusable components, standardized architecture patterns, and comprehensive documentation. ABP Framework accelerates development through code generation, testing utilities, and build optimization. With an active community and extensive ecosystem, ABP Framework enables teams to build scalable, maintainable applications following industry best practices.

Other
A

Ace

Ace is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. Ace integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, Ace helps organizations maintain robust websites that meet user expectations and technical requirements.

Other

Adobe ColdFusion

Adobe ColdFusion is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. Adobe ColdFusion supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, Adobe ColdFusion ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other

Adobe Flash

Adobe Flash is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. Adobe Flash supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, Adobe Flash ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Other
A

Adobe GoLive

Adobe GoLive is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. Adobe GoLive integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, Adobe GoLive helps organizations maintain robust websites that meet user expectations and technical requirements.

Other
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Frappe do?

Open source low code web framework behind ERPNext that is usually self hosted, so your data stays on your own server.

What Frappe is

Frappe is an open source low code web framework that serves as the foundation for ERPNext and many custom business applications. It is usually self hosted, meaning the framework and its database run on infrastructure the operator controls. Because you build and run your own application on top of it, you are the data controller and decide what personal data the system processes.

What data and cookies it sets

Frappe sets a functional session cookie that keeps a signed in user authenticated as they move through the application. The personal data it stores depends entirely on what you build, whether that is customer records, employee data or order history. By default it does not load advertising trackers, and analytics are only present if you deliberately enable them.

GDPR and ePrivacy implications

The session cookie is strictly necessary for the application to function, so it falls under the ePrivacy exemption and does not require prior consent. Any personal data your application processes is governed by the GDPR and needs a lawful basis. As the operator you are the controller and remain responsible for transparency, security and the rights of the people in your data.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Consent requirements

You do not need consent for the essential session cookie that Frappe relies on. Consent only becomes necessary if you add non essential cookies such as third party analytics or marketing tools. In that case, gate those scripts behind a clear opt in and make sure the core application still works for visitors who decline.

Data transfers and hosting

Because Frappe is self hosted, there is no inherent transfer of data to third countries; your data lives where you run the server. Transfers only arise if you host outside the European Economic Area or connect external services such as email, payment or analytics providers. Hosting the installation within the European Union keeps most international transfer concerns away.

Practical compliance steps

Map the personal data your application handles and assign a lawful basis to each use. Use the framework role and permission system to restrict access, set retention rules for old records and keep Frappe and its apps updated on secure infrastructure. If you enable analytics or integrations, document them, add a consent mechanism and reflect any transfers in your privacy notice.

GDPR consent category

Other

Websites using Frappe must obtain user consent under GDPR regulations.

Legal basisLegitimate interest or contract for processing business and user data depending on the application built; the essential session cookie relies on the strictly necessary exemption
Risk levellow
Applicable regulationsGDPR, ePrivacy Directive

DPIA considerations

Because Frappe is a framework you build applications on, your assessment should focus on the specific data your application processes rather than the framework itself. Document the personal data your app handles, the lawful basis for each use, retention rules and access controls. Where you enable optional analytics or external integrations, assess those additions and any resulting transfers separately.

Sample consent text

This site uses a strictly necessary session cookie to keep you signed in, which does not require consent. If we enable optional analytics, we will ask for your consent first and you can decline without losing access to the core functionality of the site.

Technical details

Tracking methodServer side session cookie set by the self hosted framework; optional analytics only if the operator enables it
Server locationSelf hosted; data resides wherever the site operator runs the Frappe or ERPNext installation

Third-party domains contacted

frappecloud.com

Cookies placed

NameTypeDurationPurpose
sidFunctionalSessionStores the session identifier that keeps a signed in user authenticated. Strictly necessary and exempt from consent.

This service may collect user data. Ensure GDPR compliance with FlowConsent.

Get started freeScan your site

Frequently asked questions

What cookies does Frappe set?

When self hosted, Frappe sets a functional session cookie that keeps a signed in user authenticated. It does not set advertising cookies by default, and analytics cookies appear only if you choose to enable them in your application.

Do I need consent for Frappe cookies?

No consent is needed for the essential session cookie, which is strictly necessary under the ePrivacy exemption. Consent only becomes required if you add non essential cookies such as third party analytics or marketing tools.

What is the legal basis for processing data in Frappe?

Because you build your own application, the basis depends on what you process. Common bases are contract for delivering a service, legitimate interest for internal business records and consent for marketing. Assign and document a basis for each use.

Does Frappe transfer data to the United States?

Not by itself. As a self hosted framework the data stays wherever you run the server. Transfers only occur if you host outside the European Economic Area or connect external services such as email, payment or analytics providers.

Do I need a DPIA for Frappe?

A full assessment is rarely needed for the framework itself, but it depends on the application you build. Conduct one if your app processes large volumes of personal data or special categories, and document the data flows in any case.

How do I make my Frappe deployment compliant?

Map the personal data your application handles, assign a lawful basis to each use, restrict access with roles and permissions and set retention rules. Keep Frappe and its apps updated on secure infrastructure and document any analytics or integrations you enable.

What are some alternatives to Frappe?

Other low code and ERP frameworks include Odoo, Django based builders and various open source platforms. The advantage of Frappe is that self hosting keeps your business data under your direct control.

How should I describe Frappe in my cookie policy?

List the functional session cookie as strictly necessary and explain that it keeps signed in users authenticated. If you enable analytics or other non essential cookies, list them separately and gate them behind consent.