Legal
Acceptable Use Policy
The conduct we require of every account on SFTP.cloud, and what we do when an account falls short of it.
Acceptable Use Policy
The conduct we require of every account on SFTP.cloud,
and what we do when an account falls short of it.
Effective
24 August 2026
Last Updated
3 September 2026
Version
1.1
1. Scope
This Acceptable Use Policy (this "Policy") governs use of SFTP.cloud (the "Service"), operated by Syncplify, Inc. ("Syncplify", "we", "us"). It applies to the customer that holds the account (the "Customer") and to every user, employee, contractor, partner, or other third party the Customer permits to access the Service (each, an "Authorized User").
The Customer is responsible for the acts and omissions of every Authorized User, including its own end users and its external transfer partners, as if they were the Customer’s own.
This Policy forms part of, and is incorporated into, the Terms of Service. Capitalized terms not defined here have the meaning given in the Terms of Service.
2. How this Policy works
Your files stay on your storage. We cannot see them, so this Policy is written around conduct rather than content.
The Service does not store Customer files.
Files move between the Customer’s storage and the Customer’s Authorized Users through the channel established by the Storage Connector. They are not persisted to storage operated by Syncplify. Syncplify does not hold credentials to Customer storage, and the Customer’s audit trail is generated within the Customer’s own environment and signed with a key Syncplify does not hold.
This determines how the Policy is enforced.
Prohibited uses are defined by conduct, not by content. We do not screen, scan, index, or review the contents of files transferred through the Service, and we have no technical means of doing so. We enforce this Policy on the basis of Service metadata that our systems generate, reports we receive, legal process, and the observable conduct of an account.
We have no duty to monitor.
Nothing in this Policy obliges Syncplify to monitor the Service or the conduct of any Authorized User, and we do not undertake to do so. We reserve the right, but accept no obligation, to investigate suspected violations and to act on them.
Our lack of visibility does not reduce the Customer’s responsibility.
The Customer remains solely responsible for the lawfulness of the data it transfers through the Service and for holding all rights, consents, and lawful bases required to transfer it. Where the Service processes personal data on the Customer’s behalf, the Data Processing Addendum, where one is in place, governs that processing.
3. Prohibited conduct
The Customer must not use the Service, and must not permit the Service to be used, to:
3.1 Compromise systems or networks
Gain or attempt to gain unauthorized access to any system, network, account, or data. Conduct port scanning, penetration testing, or vulnerability scanning against any third party. Distribute malware, ransomware, or other malicious code. Operate the Service as a staging point, relay, exfiltration channel, or command-and-control channel for an attack.
3.2 Interfere with the Service
Circumvent authentication, access controls, account limits, or usage restrictions. Probe or test the vulnerability of the Service without our prior written consent, for which see section 9. Interfere with any other Customer’s use of the Service. Reverse engineer, decompile, disassemble, or modify the Storage Connector or any other Syncplify software, except to the extent that restriction is unenforceable under applicable law.
3.3 Abuse Service resources
Impose an unreasonable or disproportionate load on Service infrastructure. Use automated means to evade rate limits, quotas, or other applicable limits. Share a single account or credential set among multiple individuals in order to avoid per-user limits or fees. Create accounts by automated means, or create multiple accounts to obtain trial or promotional benefits more than once.
3.4 Violate law
Use the Service in violation of any applicable law or regulation. Transfer data in violation of the rights of others, including intellectual property, privacy, publicity, and confidentiality rights.
3.5 Breach sanctions and export control restrictions
Use the Service in violation of export control, economic sanctions, or anti-money-laundering laws applicable to Syncplify or to the Customer. Provide access to the Service, directly or indirectly, to any person or entity that is subject to applicable economic sanctions or export restrictions, or that is located in a territory subject to comprehensive sanctions.
3.6 Facilitate abuse of others
Distribute unsolicited bulk communications. Conduct phishing, fraud, or social engineering. Harass, threaten, or stalk any person.
3.7 Misrepresent identity or authority
Impersonate any person or entity, or misrepresent an affiliation with any person or entity, in connection with use of the Service.
3.8 Transfer prohibited material
Transfer, distribute, or make available through the Service any material that is unlawful to possess, produce, or distribute under applicable law, including child sexual abuse material, material that facilitates the sexual exploitation of a minor, and material whose transfer is restricted under export control or sanctions law.
This obligation applies in full notwithstanding our inability to detect such material. Because we do not inspect file contents, we enforce this section 3.8 on the basis of reports, legal process, and account conduct, in accordance with sections 6 and 7.
4. Security obligations of the Customer
The security model of the Service depends on components under the Customer’s control. The Customer must:
- Keep the Storage Connector current. Updates are applied automatically when the Connector is idle, and can be applied with a single action when it is busy. The Customer must not disable or indefinitely defer Connector updates, and must apply any update Syncplify designates as critical without undue delay.
- Protect the credentials, keys, and certificates used by the Storage Connector, which remain in the Customer’s possession at all times.
- Configure access so that each Authorized User has only the access that user requires.
- Promptly disable Service accounts belonging to users who should no longer have access.
- Notify us promptly, and in any event without undue delay, of any suspected compromise of a Service account or of Storage Connector credentials.
Failure to meet these obligations is a violation of this Policy. The allocation of responsibility and liability between the parties is governed by the Terms of Service.
5. Copyright and repeat infringement
Because the Service does not store Customer files, Syncplify acts only as a conduit for transmissions the Customer initiates. We do not host Customer material and are not technically able to remove or disable access to an individual file.
We nonetheless maintain, and reasonably implement, a policy of terminating in appropriate circumstances the accounts of Customers and Authorized Users who are repeat infringers of copyright.
Notices of claimed copyright infringement relating to the Service may be sent to copyright@sftp.cloud, and should include the information described in 17 U.S.C. § 512(c)(3). We will forward substantiated notices to the Customer concerned and will count them for the purposes of the repeat-infringer policy described above.
6. Child safety and mandatory reporting
Accounts implicated under this section are suspended immediately, without notice.
Syncplify does not scan for, and has no ability to detect, child sexual abuse material transferred through the Service. Nothing in this Policy or in applicable law obliges us to search for it.
If we obtain actual knowledge of apparent child sexual abuse material, or of an apparent violation of federal child exploitation law, in connection with use of the Service, we will report it to the CyberTipline operated by the National Center for Missing & Exploited Children and preserve the associated records, and will comply with any reporting obligation that applies to us under 18 U.S.C. § 2258A.
We will suspend the account concerned immediately, without notice and without a cure period, and we will not notify the account holder where notification is prohibited by law or where we believe in good faith that it would prejudice an investigation or place a person at risk.
7. Investigation
What we can access.
In investigating a suspected violation, responding to a complaint, or protecting the integrity of the Service, we may review Service metadata that our systems generate and hold. This includes account identifiers, connection and session records, authentication events, configured storage endpoints, transfer volumes, and administrative actions. Retention periods for this metadata are described in the Privacy Policy.
What we cannot access.
We cannot review the contents of Customer files, and we do not hold credentials to Customer storage. The Customer’s own audit trail is generated within the Customer’s environment and signed with a key we do not hold. Nothing in this Policy grants Syncplify a right of access to Customer storage or to Customer file contents, and no such access is technically available to us.
Cooperation.
Where an investigation concerns activity originating from a Customer account, the Customer agrees to cooperate reasonably with us, including by providing relevant information from its own records where it is able to do so. We will likewise cooperate reasonably with the Customer in investigating incidents affecting the Customer’s use of the Service.
Legal process.
If we receive a subpoena, court order, or other valid legal process seeking Customer information, we can produce only the Service metadata described above. We cannot produce file contents. Where we are legally permitted to do so, we will make reasonable efforts to notify the Customer before responding, so that the Customer may seek protective relief. We will not provide such notice where notification is prohibited by law or court order, or where we believe in good faith that it would create a risk of injury to any person, of destruction of evidence, or of obstruction of an investigation.
8. Enforcement
We may take the following actions in response to a violation of this Policy.
Immediate suspension.
We may suspend an account, an individual Authorized User, or specific Service functionality immediately and without prior notice where, in our reasonable judgment, the conduct presents an active security threat to the Service, to other Customers, or to third parties; exposes Syncplify to legal liability or regulatory action; violates export control or sanctions law; involves unauthorized access to systems or data; or falls within section 6. Except where section 6 or applicable law provides otherwise, we will notify the Customer promptly after taking such action.
Notice and opportunity to cure.
For violations that do not require immediate action, we will notify the Customer, describe the conduct at issue, and allow a reasonable period, ordinarily not less than ten (10) days, to correct it. If the violation is not corrected within that period, we may suspend or terminate the account.
Termination.
We may terminate the Service for cause where a violation is severe, repeated, or not corrected after notice.
Referral.
We may report conduct to law enforcement or to another competent authority where we are required to do so or where we reasonably believe it appropriate.
We will apply the least disruptive measure reasonably sufficient to address the conduct in question. Rate limiting, suspension of a single Authorized User, or suspension of a single function will be preferred over suspension or termination of an account where that is sufficient.
Effect on fees.
Where we suspend or terminate an account for violation of this Policy, fees already paid are not refundable, and fees for the remainder of the then-current subscription term remain payable, in each case except as the Terms of Service expressly provide otherwise.
No waiver.
Our failure to enforce any part of this Policy in a particular instance is not a waiver of our right to enforce it later.
9. Reporting abuse and security issues
Abuse.
Reports of suspected abuse of the Service may be sent to abuse@sftp.cloud. Please include the affected hostname or account identifier, the date, time, and time zone of the activity, and any supporting detail available.
Security vulnerabilities.
Reports of suspected vulnerabilities in the Service or in the Storage Connector may be sent to security@sftp.cloud. We will not pursue claims under section 3.2 against a researcher who reports a vulnerability to us in good faith, who does not access, alter, or exfiltrate data belonging to another party, who does not degrade the Service, and who allows us a reasonable period to remediate before disclosure.
10. Changes to this Policy
We may update this Policy from time to time. Material changes will be notified to Customers at least thirty (30) days before they take effect, by email to the account’s administrative contact or by notice within the Service. Changes required by law, or reasonably necessary to address a security, abuse, or legal risk, may take effect immediately upon notice.
Continued use of the Service after a change takes effect constitutes acceptance of the updated Policy.
11. Relationship to the Terms of Service
This Policy is incorporated into the Terms of Service and is governed by the same terms, including those addressing governing law, venue, disclaimers, limitation of liability, and indemnification. In the event of a conflict between this Policy and the Terms of Service, the Terms of Service control.
The Terms of Service are governed by the laws of the State of Delaware, without regard to its conflict of laws provisions.
12. Contact
| Purpose | Address |
|---|---|
| Abuse reports | abuse@sftp.cloud |
| Security vulnerabilities | security@sftp.cloud |
| Copyright notices | copyright@sftp.cloud |
| Legal notices | legal@sftp.cloud |
Syncplify, Inc., a Delaware corporation