Infile Legal Policies
Policies for firms using Infile to collect client documents securely.
Terms governing use of the Infile document collection platform.
Effective July 12, 2026
Permitted and prohibited uses of Infile for firms and their clients.
Effective July 12, 2026
Processor terms when Infile handles personal data on your firm's behalf.
Effective July 12, 2026
Acceptable Use Policy
Effective July 12, 2026
Permitted and prohibited uses of Infile for firms and their clients.
1. Permitted Use
Infile is designed for professional firms - including CPAs, bookkeepers, and advisory practices - to collect documents and information from clients. Permitted uses include:
- Sending branded document requests and checklists to clients
- Collecting tax organizers, monthly bookkeeping packages, and onboarding documents
- Automating client reminders tied to checklist completion
- Storing and exporting client submissions for legitimate business purposes
2. Prohibited Use
You may not use Infile to:
- Violate applicable law or professional conduct obligations
- Upload malware, exploit code, or content intended to disrupt the platform
- Attempt unauthorized access to accounts, upload links, or firm data
- Collect information without a lawful basis or required client notice
- Harass, spam, or send unsolicited bulk messages unrelated to document collection
- Misrepresent your identity or firm affiliation when contacting clients
3. Client Upload Links
Passwordless upload links are scoped to individual requests. You are responsible for sending links to the correct recipient and revoking or closing requests when no longer needed. Do not publish client upload links in public channels.
4. Enforcement
We may investigate suspected violations and suspend or terminate access where we reasonably believe this policy, our Terms, or applicable law has been breached. Report abuse to support@infile.app.
Security Policy
Effective July 12, 2026
How Infile protects firm and client data on the platform.
1. Security Commitment
Infile is built to handle sensitive client documents for accounting and bookkeeping workflows. We use technical and organizational measures designed to protect confidentiality, integrity, and availability of data processed on the platform.
2. Infrastructure Security
Our security practices include:
- Encryption in transit using modern TLS for all web and API traffic
- Encryption at rest for stored files and database records
- Role-based access controls for firm team members
- Monitoring and logging of platform activity for abuse detection
- Regular review of access permissions and production changes
3. Account Security
Firm administrators should assign least-privilege roles, rotate credentials after staff changes, and enable additional account protections where available. Clients accessing passwordless upload links should receive links only from your firm through private channels.
4. Incident Response
If we become aware of a security incident that affects customer data, we will investigate promptly, take steps to contain and remediate the issue, and notify affected customers where required by law or contractual obligations.
5. Reporting Security Issues
To report a vulnerability or security concern, contact support@infile.app with sufficient detail for us to reproduce and investigate the issue. Please do not publicly disclose vulnerabilities before we have had a reasonable opportunity to respond.
Data Processing Agreement
Effective July 12, 2026
Processor terms when Infile handles personal data on your firm's behalf.
1. Roles and Scope
When your firm uses Infile to collect documents from clients, you typically act as the data controller for client personal data. Infile acts as a data processor when handling that data to provide document collection, storage, reminders, and export functionality.
2. Processing Instructions
We process personal data only to deliver, secure, support, and improve the services, and as otherwise documented in our Privacy Policy, Terms, or required by applicable law. We do not sell client personal data.
3. Subprocessors
We may use vetted subprocessors - such as cloud infrastructure and email delivery providers - to operate the platform. Subprocessors are subject to contractual obligations consistent with this DPA. A current subprocessor list is available on request at support@infile.app.
4. Data Subject Requests
Where required, we will assist your firm in responding to data subject access, correction, deletion, or portability requests relating to data processed through Infile, subject to applicable law and your instructions.
5. Data Retention and Deletion
Upon termination of your account or upon verified instruction, we will delete or return personal data within a reasonable period, except where retention is required for legal, billing, audit, or security purposes.
6. Executed DPA
Enterprise customers may request a signed Data Processing Agreement. Contact support@infile.app to request the current DPA template or discuss EU/UK Standard Contractual Clauses where applicable.
Questions about these policies? Contact our team or email support@infile.app.