1. Service provider and contact
These terms apply to the use of Workfiles. The service is provided by Securesoft OÜ, registry code 17530831. For questions, contact info@failijagaja.ee.
By using the service, you agree to these terms. If you use the service on behalf of an organization, you confirm that you have authority to use the service and purchase subscriptions on behalf of that organization.
2. Service description
Workfiles is a secure document exchange and digital signing service. The service allows signed-in users to upload files, store them encrypted, share them by personal code, email address or domain, track access, manage organization licenses and create signing workflows.
The sender must be authenticated to use the service. The service supports Smart-ID, Mobile-ID and ID card authentication through Authentigate.
3. Account and authentication
- You are responsible for using the service only within your own or your organization’s lawful authority.
- You must not allow another person to use your authentication method, session or account.
- If you suspect account misuse, you must notify info@failijagaja.ee without delay.
- The provider may revoke a session, restrict access or suspend suspicious activity for security reasons.
4. Rights to files and documents
All rights to uploaded files and documents remain with you or the actual rights holder. Securesoft OÜ does not claim ownership of your files.
You grant Securesoft OÜ a limited right to process files only to the extent necessary to provide the service: upload, encrypted storage, access control, download, signing workflow execution, technical support, security and compliance with legal obligations.
Workfiles does not use your files for advertising, sale to third parties or training artificial intelligence models.
5. Prohibited use
- Do not upload or share content that you have no right to use or that violates law, contract or third-party rights.
- Do not use the service for malware, phishing, spam, fraud, threats, harassment, illegal surveillance or other harmful activity.
- Do not attempt to bypass or damage the service’s security mechanisms, encryption, authentication, access control, rate limits or storage limits.
- Do not share other people’s personal codes, email addresses or documents without a lawful basis.
- Do not use the service in high-risk situations where temporary service interruption could create direct risk to life, health or critical property.
6. Access rules and recipient responsibility
The sender is responsible for ensuring that recipient personal codes, countries, email addresses and domains are correct and that there is a lawful basis for sending the documents to those recipients.
If you share a file by email or domain, remember that the service verifies email access with an OTP code, but the security of the recipient’s email account depends on the recipient’s email provider and behavior.
7. Signing workflows
The signing feature allows users to create workflows, invite signers, manage versions, verify access by email OTP and store workflow events. The service may store signer names, email addresses, expected personal codes, statuses, events, IP addresses and user-agent values.
The provider is not responsible for whether a document prepared by the user is substantively correct, legally sufficient or suitable for a specific transaction. Where needed, the document and signing process should be reviewed by a lawyer.
8. Retention and deletion
- The free plan allows limited file retention. The maximum file retention period in the free plan is up to 7 days.
- After the retention period ends, expired files are deleted automatically by the nightly cleanup process. Deletion may not happen at the exact expiry moment, but within a reasonable time after the period ends.
- Paid plans can use retention until manually deleted if the account or organization plan is active, the storage limit has not been exceeded, and the file or workflow is not deleted earlier.
- The sender or organization is responsible for deleting files when there is no longer a need or lawful basis to keep them.
9. File Deletion and Recovery
To protect privacy and security, we do not restore files that have been permanently deleted by the user. Users are responsible for keeping any necessary copies before deletion.
10. Plans, limits and billing
The free plan includes 500 MB of uploads per calendar month. Paid plans have the storage, license count and other limits set for the selected plan. For example, 50 GB of storage means the total amount of actively stored files and workflows in the organization or account, not a single-file limit or monthly transfer volume.
Organization users can share different files as long as the organization’s total used storage does not exceed the plan storage limit. The same storage may include shared files, files received through file requests and files in signing workflows. If a limit is reached, upload or some features may be restricted until storage is freed or the plan is changed.
Payments and subscriptions are processed through Stripe. Stripe may display its own terms and privacy information. The subscription price, period and plan features are shown on the pricing page or during checkout before purchase.
If payment fails or the subscription ends, paid plan access and organization features may be restricted.
11. Organizations, roles and licenses
Organization plans allow management of members, roles, permissions, user seats and ownership transfers. The organization owner or an authorized user is responsible for deciding who receives access, roles or user seats.
A user seat may allow a user to use the organization’s file storage limit. Admin rights do not necessarily mean the right to upload files under the organization file storage if there is no active user seat.
12. Security
The service uses AES-256-GCM encryption, access control, session hashing, short-lived upload intents, OTP code hashing and audit logs. These measures reduce risk, but no internet service can promise absolute security.
The user is responsible for the security of their device, email account, authentication methods and network connection.
13. Availability and changes
We aim to keep the service stable and secure, but the service may be temporarily unavailable because of maintenance, updates, technical issues, third-party provider failures or force majeure.
We may change the service, features, plans and these terms. We will notify users of material changes in a reasonable way.
14. Limitation of liability
Securesoft OÜ is not responsible for loss of files, documents, workflows or data to the extent caused by the user’s actions or omissions, including permanent deletion of a file, failure to keep a necessary copy, incorrect recipient details, misuse of an account or authentication method, or insufficient security of the user’s device, network or email account.
Securesoft OÜ is not responsible for outages, errors, delays, data loss or security incidents of third-party providers, including authentication, payment, email or cloud storage providers, unless liability arises from Securesoft OÜ’s own breach of mandatory law or intentional or grossly negligent conduct.
Nothing in these terms limits liability where such limitation is not permitted by applicable law, including mandatory consumer rights or data protection rights.
15. Privacy and data protection
Personal data processing is described in the privacy policy. These terms and the privacy policy together form the core rules for using the service.
16. Withdrawal and Refunds
Consumer customers may be entitled to request a refund of their most recent payment in accordance with applicable law.
Refund requests should generally be submitted within 14 days of purchase.
Refund eligibility may be limited where the service has already been used.
When assessing service usage, we may take into account factors including the volume of uploaded, processed or shared data.
Where the service has been used before a withdrawal request is submitted, the service provider may be entitled to charge for the portion of the service already provided.
Additional refund conditions may be communicated during the purchase process or through customer support.
17. Governing law and disputes
The service is governed by Estonian law unless mandatory consumer protection or data protection law provides otherwise. Disputes will first be attempted to be resolved by negotiation. If no agreement is reached, the dispute will be resolved by the competent Estonian court, unless mandatory law provides another jurisdiction.