Legal · DPA

Data Processing Addendum

For firms processing client data through File2Insight. This page is a template for an early-stage product and isn't legal advice.

Last updated · June 2026
01

Roles

For data in the files you upload — including your clients' data — you are the controller and File2Insight is the processor. We process that data only on your documented instructions.

This addendum forms part of the Terms of Service for customers who need it.

02

Scope of processing

We process uploaded files to profile, clean, reconcile, and report as directed through the product, plus any scheduled refreshes you configure.

Processing lasts for the term of your subscription and the retention window described in the Privacy Policy.

03

Security measures

Tenant isolation, immutable source storage, a permission-gated write path, PII masking before model calls, and an exportable audit trail of every state change.

Secure-tier customers can deploy inside their own environment for stricter residency requirements.

04

Subprocessors

We engage vetted infrastructure and model subprocessors under terms consistent with this addendum, and will give notice of material changes so you can object.

05

Assistance & breach notice

We help you respond to data-subject requests and, where a personal-data breach affects your data, notify you without undue delay with the information you need to meet your obligations.

06

Return & deletion

On termination, you can export your data; after the retention window we delete or anonymize it, except where law requires retention.