Effective September 14, 2026
Scope and data roles
This notice covers the DueFiles website, accounts, vendor submission pages, product communications, support, and sales interactions. It does not cover a customer's own privacy practices or third-party services that operate under separate notices.
DueFiles controls personal information used to run its website, administer accounts, secure the service, and manage direct business relationships. For documents, vendor records, requirements, and other workspace content, the customer determines why the information is processed and DueFiles processes it to provide the service.
Information we handle
The service handles the information needed to operate a vendor compliance workflow:
- Account and organization data: name, work email, organization, role, and workspace settings.
- Vendor and insurance data: vendor contacts, broker contacts, requirements, certificates, endorsements, policy details, and submitted document text.
- Review and activity data: extraction results, confidence indicators, decisions, exceptions, reminders, and event history.
- Communications: sales, security, privacy, accessibility, legal, and support correspondence.
- Technical data: session identifiers and service logs that can include request time, browser or device details, IP address, route, and error information.
- Applicant data: information supplied in response to a published role, when DueFiles is hiring.
Where information comes from
Information comes directly from account users, vendors, brokers, job candidates, and people who contact DueFiles. Customers also provide vendor records and invite others to submit documents. The service creates technical, extraction, review, and activity data as people use the product.
How we use information
DueFiles uses information to provide and administer the service, authenticate users, collect documents, extract fields, compare evidence with customer-configured requirements, support human review, deliver reminders, respond to requests, secure and troubleshoot the platform, enforce agreements, and comply with law.
Where a law requires a legal basis, processing rests on performance of a contract, steps requested before a contract, legitimate interests in operating and protecting a business service, compliance with legal obligations, or consent for a specific optional activity. Consent can be withdrawn for future processing at any time without changing processing that was already lawful.
Document extraction and decisions
DueFiles uses rules and, when configured, an AI service to extract document fields and map them to requirements. Extraction can be incomplete or incorrect, so confidence and source evidence remain available for review. DueFiles does not make solely automated decisions that produce legal or similarly significant effects. The customer's authorized users control approvals, rejections, and exceptions.
No sale or behavioral advertising
DueFiles does not sell personal information. DueFiles does not share personal information for cross-context behavioral advertising and does not use customer documents to advertise to vendors, brokers, or account users.
Retention and deletion
DueFiles keeps personal information for the account term and as needed to provide the service, maintain security and audit records, resolve disputes, enforce agreements, and meet legal obligations. Retention can vary by record type, customer instructions, workspace configuration, backup cycle, and legal requirement. When retention ends, information is deleted or de-identified according to the applicable process.
Security
DueFiles applies transport protection, authenticated workspace boundaries, scoped submission links, server-side input validation, and attributable activity records to the workflows that handle customer information. Security also depends on customers controlling accounts, recipients, requirements, and exported data. Read the security overview or contact the security team for the current review materials relevant to an Enterprise evaluation.
Privacy rights and choices
Depending on location and the relationship with DueFiles, a person can have rights to access, correct, delete, restrict, object to, or receive a copy of personal information, and to appeal a denied request or complain to a regulator. DueFiles does not discriminate against a person for exercising a privacy right.
Workspace data is controlled by the customer, so vendor contacts and account users should first contact the organization that requested or entered the information. Requests about information DueFiles controls can be sent to privacy@duefiles.com. DueFiles verifies identity and authority before acting on a request and honors authorized agents where required.
International processing
Information can be processed in locations where DueFiles and its service providers operate. When a cross-border transfer requires a legal safeguard, DueFiles uses the transfer mechanism required for the applicable service and jurisdiction. Enterprise customers can request the contractual data terms relevant to their deployment.
Children
DueFiles is a business service and is not directed to children under 18. The service does not knowingly collect personal information from a child for the child's own use. Send a deletion request to the privacy team if information was submitted contrary to this restriction.
Changes and contact
Material changes will appear on this page with a revised effective date. When a change requires additional notice or consent, DueFiles provides it through the service or the relevant contact channel.
Send privacy questions and rights requests to privacy@duefiles.com. Send security reports to security@duefiles.com. Contractual notices must follow the notice method in the applicable customer agreement.