Security & Ethics Policy
Filesie builds and operates B2B growth systems involving prospect research, business contact data, email infrastructure, campaign management and communication workflows. Security and ethical conduct are fundamental to how we deliver these services.
- Confidentiality: protect client, prospect and business information from unauthorised disclosure.
- Integrity: maintain accurate campaign, suppression and account information and prevent unauthorised alteration.
- Availability: operate systems with reasonable resilience and continuity controls.
- Least privilege: provide users and vendors only the access necessary for their role.
- Accountability: maintain reasonable records of access, campaign activity and security events where appropriate.
- Collect and process prospect information only for legitimate, defined business purposes.
- Limit access to client and prospect data to authorised personnel.
- Use appropriate safeguards for credentials, API keys, mailboxes and campaign platforms.
- Do not knowingly sell, disclose or repurpose client prospect data outside the agreed service purpose, except where required by law or necessary for approved service providers.
- Maintain suppression and opt-out information so that recipients who have asked not to be contacted are not inadvertently reintroduced into campaigns.
- Use controlled sending domains and mailboxes.
- Implement appropriate authentication such as SPF, DKIM and DMARC where applicable.
- Protect mailbox credentials and administrative access.
- Monitor unusual sending activity, bounces, complaints and authentication issues.
- Do not use compromised accounts, stolen credentials or unauthorised infrastructure.
- Targeting should be based on legitimate business relevance rather than sensitive personal characteristics.
- Messaging should be truthful, proportionate and relevant to the recipient’s professional context.
- Do not impersonate individuals or organisations.
- Do not fabricate case studies, customer relationships, referrals, awards, results or urgency.
- Do not use deceptive tracking, malicious links or harmful attachments.
- Respect opt-outs, complaints and requests to stop communication.
Where AI or automation is used in research, segmentation, personalisation or campaign operations, Filesie will apply reasonable human oversight and quality control. AI-generated content must be reviewed for factual accuracy, inappropriate personalisation, confidentiality concerns and compliance risk before material use.
Filesie may use third-party providers for hosting, email delivery, CRM, data, analytics, support and other operational functions. Providers should be assessed for suitability, security and privacy practices before being used for material client or prospect data. Filesie will not knowingly engage providers whose practices materially conflict with our security and privacy standards.
Filesie may use third-party providers for hosting, email delivery, CRM, data, analytics, support and other operational functions. Providers should be assessed for suitability, security and privacy practices before being used for material client or prospect data. Filesie will not knowingly engage providers whose practices materially conflict with our security and privacy standards.
Suspected unauthorised access, credential compromise, data exposure, malicious activity or material campaign abuse should be escalated promptly. Filesie will assess the incident, contain it where appropriate, investigate the cause and take reasonable remediation and notification steps required by applicable law and contractual obligations.
Filesie may refuse, pause or terminate activities that it reasonably believes involve fraud, deception, unlawful data use, malicious activity, harassment, discriminatory targeting, impersonation, security abuse or material regulatory risk.
Employees and contractors working on Filesie campaigns are expected to protect credentials and confidential information, follow access controls, report suspected incidents, respect recipient preferences and avoid using company systems for unauthorised or harmful activity.
This policy describes Filesie’s operating standards and compliance approach. It is not legal advice or a jurisdiction-specific legal opinion. Electronic marketing, privacy, data protection and communications laws may apply differently depending on the recipient, sender, message, data source and jurisdiction. Appropriate local legal advice should be obtained where required.
This policy is effective as of September 24, 2026.