FileNest Privacy Policy & Governance
Last Updated: August 19, 2026•Gree Web Solutions
1. Introduction & Scope
Welcome to FileNest ("FileNest", "we", "us", or "our"), a service developed and maintained by Gree Web Solutions. We are committed to maintaining the confidentiality, integrity, and security of personal information collected through our website, legal policy vault services, APIs, and client-embedded applications.
This Privacy Policy details how FileNest acts as both a Data Controller for account administrative data and a Data Processor when handling policy generation and user consent records on behalf of our enterprise clients under global privacy frameworks including the European Union General Data Protection Regulation (EU GDPR) and the California Consumer Privacy Act (CCPA/CPRA).
2. Information We Collect
We collect information in three categories to deliver high-availability policy vault services:
A. Account & Registration Data
When you create a FileNest workspace, we collect your full name, business email address, company organization name, encrypted authentication credentials, and billing details processed via PCI-DSS compliant providers.
B. Telemetry & API Usage Logs
System metrics including IP address, user-agent string, operating system version, requested policy endpoints, cryptographic checksum hashes, latency metrics, and API access tokens.
C. Client Policy Disclosures & Custom Parameters
Legal parameters configured within your nested policy vaults (e.g. data retention periods, cookie tracking toggles, regional compliance rules) stored under end-to-end encryption.
3. How We Process Your Information
We process data only for legitimate legal, technical, and operational purposes:
- To generate, serve, and dynamically update legal policy documents across client domains.
- To compute SHA-256 cryptographic hashes verifying that policy text has not been tampered with.
- To prevent fraud, illegal API access, and DDoS attacks on our infrastructure.
- To send critical legal compliance notices when regional privacy regulations change.
- To fulfill legal obligations under applicable federal and international regulations.
4. Third-Party Data Sharing & Sub-processors
We share data exclusively with vetted sub-processors bound by strict Data Processing Addendums (DPAs):
| Sub-processor | Purpose | Location |
|---|---|---|
| Amazon Web Services (AWS) | Encrypted Cloud Infrastructure & CDN | EU / US Regions |
| Stripe Inc. | PCI-DSS Level 1 Payment Processing | United States |
| Cloudflare Inc. | Edge Security & DDoS Mitigation | Global Edge Network |
5. Data Protection, Security & Retention
FileNest implements defense-in-depth security standards to safeguard legal data:
AES-256 Encryption
All database records & policy snapshots encrypted at rest.
TLS 1.3 Transport
Strict HTTPS transport security with PFS certificate pinning.
Data Retention: Active account data is retained for the duration of the subscription. Upon account termination, all policy vault backups are permanently purged within 30 calendar days.
6. Your Rights Under GDPR & CCPA/CPRA
Regardless of your geographical location, FileNest grants all users comprehensive control over their personal data:
Right to Access & Portability
Request a machine-readable JSON copy of all personal records we hold.
Right to Erasure ("Right to be Forgotten")
Delete your workspace, history, and associated policy snapshots permanently.
Right to Rectification
Correct inaccurate data directly in your account dashboard.
Right to Opt-Out of Profiling
We do not engage in automated behavioral profiling or targeted advertising.
7. Contact Us & Data Protection Officer (DPO)
For questions regarding this Privacy Policy, exercising your GDPR/CCPA rights, or submitting a Data Subject Access Request (DSAR), please contact our support team at Gree Web Solutions: