Terms of Service
Version 1.0, effective September 22, 2026
These Terms of Service (the "Terms") are a binding agreement between Filohealth Software, Inc., registration number 10746556, a corporation incorporated in the State of Delaware, United States, with its registered address at 2810 North Church Street, STE 90642, Wilmington, DE 19802, United States, operating the website https://filo.inc and https://meetfilo.io and reachable at daniel@meetfilo.io ("Filo", "we", "us", "our"), and the business or professional that uses the Filo services ("Customer", "you", "your"). By ticking an acceptance box, signing an order form, creating an account, or using the services, you accept these Terms in full. If you accept on behalf of a business, you confirm that you are authorized to bind that business, and "you" means that business. If you do not accept these Terms, do not use the services.
1. Who these Terms are for
The services are offered only to businesses, professionals, and organizations acting in the course of their trade, business, craft, or profession. They are not offered to consumers. By accepting these Terms you confirm that you are not acting as a consumer within the meaning of Article 2(1) of Directive 2011/83/EU or of equivalent law where you are established, and that consumer withdrawal and distance selling rights do not apply to this agreement. The 30-day satisfaction guarantee below is given to you by contract, not because consumer law requires it.
Everyone who accepts these Terms or uses the services must be at least 18 years old and have the legal capacity to enter into a binding contract. You confirm that you have that capacity and, where you act for a business, the authority to bind it.
These Terms, the Data Processing Agreement, any order form or written agreement signed between us, and the documents they refer to, form the whole agreement between us. Where they conflict, the order of precedence in the miscellaneous section at the end of these Terms applies.
2. The services
Filo provides AI-assisted software for healthcare and wellness businesses, delivered as a hosted service over the internet, together with hands-on help from the Filo team as described in the assisted delivery section below (the "services"). No copy of the software is delivered to you and no software is licensed to you for installation. The services are built for three things:
- Handling customer and lead conversations: answering messages and calls, qualifying leads, and booking appointments on your behalf across the channels you connect, such as WhatsApp, Instagram, and Facebook Messenger.
- Generating content for social media: drafting, designing, scheduling, and publishing posts to the social media accounts you connect, such as Instagram, Facebook, and TikTok, and reporting how those posts perform.
- Creating and managing advertising campaigns: producing ad creatives and setting up, running, and optimizing campaigns in your connected advertising accounts, such as Meta Ads.
3. Assisted delivery and support
Filo is not only self-serve software. Members of the Filo team may help deliver the services: setting up your workspace and integrations, configuring and operating features on your behalf, reviewing or producing content and campaigns, troubleshooting problems, and stepping in to handle tasks in the product when you ask for help or when we consider it necessary to keep the services working for you. This assistance is part of the services and is covered by these Terms, including the confidentiality section and the Data Processing Agreement.
To provide it, authorized Filo personnel may access your workspace, the accounts you have connected, and Customer Data, to the extent needed for the task. Such access is limited to trained personnel bound by confidentiality obligations, is logged, and is used only to provide the services. You may ask us at any time, at daniel@meetfilo.io, to limit or stop hands-on assistance for your workspace, and we may decline a request for assistance that would breach these Terms, applicable law, or a connected platform's rules.
Work done by Filo personnel on your behalf is done on your instructions and within the settings, budgets, and approvals you have given. You remain responsible for the content, messages, and ads published under your name and for reviewing anything we prepare for you, as set out in the AI features section. Assistance is provided on a reasonable efforts basis; specific service levels or response times apply only where agreed in writing.
4. Your license to use the services
For as long as this agreement is in force and your fees are paid, Filo grants you a limited, non-exclusive, non-transferable, non-sublicensable, revocable license to access and use the services, through the interfaces we provide, for the internal business purposes of the business named on your account. The license covers your employees, contractors, and agents whom you invite to your workspace ("authorized users"), and you are responsible for their acts and omissions as if they were your own.
The license does not include, and these Terms do not grant, any right to the source code, models, prompts, or underlying technology of the services, any right to use the services for the benefit of a third party, or any right in the Filo name, logo, or other branding beyond a plain factual statement that you use Filo. All rights not expressly granted are reserved. The prohibited activities section sets out what you must not do with the services.
If you breach these Terms in a material way, the license ends immediately and automatically for as long as the breach continues, and we may suspend or terminate your access as set out in the term, suspension, and termination section, without that being our only remedy.
5. Availability, maintenance, and changes to the services
We aim to keep the services available at all times, and we monitor them continuously, but we do not commit to a specific uptime percentage, support response time, or service credit unless we have agreed one with you in writing in an order form or a separate service level agreement. The services are provided "as is" and "as available", as set out in the warranty disclaimer.
We may carry out planned maintenance, and will give you notice in the product or by email where it is likely to interrupt your use and it is practicable to do so. We may carry out emergency maintenance, or suspend part of the services at short notice, where needed to protect the security, integrity, or lawful operation of the services. The services also depend on your internet connection and on third-party platforms and providers whose availability we do not control.
We may improve, modify, add, or remove features over time, including to reflect changes made by the platforms we connect to. We will not materially reduce the core functionality of the services during a paid term without giving you at least 30 days' notice; if we do, you may terminate the affected services by written notice within 30 days of the notice and we will refund the fees you have prepaid for the period after termination, calculated pro rata.
6. Accounts, users, and account security
To use the services you create an account and a workspace. You must give accurate, current, and complete information when you register and keep it accurate, including your business name, registered address, billing contact, and, where you have one, your VAT identification number. We may refuse a registration, and we may verify the information you give us.
You are responsible for keeping your credentials confidential, for enabling the security features we make available such as multi-factor authentication where offered, and for all activity that happens under your account and workspace, including activity by the authorized users you invite and by anyone using their credentials. Do not share credentials between people; invite a user instead. You must remove users who no longer need access.
Notify us promptly at daniel@meetfilo.io if you suspect unauthorized access to your account, your workspace, or a connected platform account. We may require a password reset, revoke sessions or tokens, or suspend access while we investigate.
We reserve the right to remove or reclaim a username, workspace name, or workspace address that infringes a third party's rights, impersonates another business, or is unlawful or misleading, and to change it where we must do so for technical or legal reasons, giving you notice where practicable.
7. Your representations and undertakings
Each time you use the services, you represent and undertake that:
- The registration and billing information you give us is true, accurate, current, and complete, and you will keep it that way.
- You have the legal capacity to enter into this agreement and, where you act for a business, the authority to bind it, and you agree to comply with these Terms.
- You are not a minor, and you will not let a minor use the services through your account.
- You will not access the services through automated or non-human means, such as a bot or a script, outside the interfaces we document, and you will not register an account by automated means.
- You will use the services only for lawful purposes and in line with these Terms.
- You hold the registrations, licenses, and professional authorizations required to operate your healthcare or wellness business and to advertise it in the markets where you operate, and you will comply with the advertising and communication rules of your profession and your regulator.
- You will not use the services in a way that breaches the terms of a platform you have connected, or that causes us to breach them.
8. Prohibited activities
You may use the services only for the purposes described in these Terms. In particular, you will not, and will not allow anyone else to:
- Use the services in violation of applicable law, including healthcare, advertising, consumer protection, privacy, and anti-spam laws.
- Submit or publish content that is unlawful, infringing, defamatory, discriminatory, or deceptive, or that you do not have the right to use.
- Send unsolicited messages, or messages outside the consent, opt-in, and messaging rules of the channels involved, or harvest contact details for that purpose.
- Retrieve data from the services by scraping, crawling, automated extraction, or any means other than the interfaces we document, or create a database or a derived dataset from the services.
- Circumvent, disable, or interfere with security features, rate limits, usage limits, access controls, or the geographic or account boundaries of the services.
- Probe, scan, or test the vulnerability of the services or of any system connected to them without our prior written permission, or breach any security or authentication measure.
- Decompile, disassemble, or reverse engineer any part of the services, or attempt to derive their source code, models, weights, or prompts, except to the extent this restriction cannot be excluded by law, including Article 6 of Directive 2009/24/EC, and then only after asking us in writing for the information you need.
- Use the services, or any output of the services, to develop, train, fine-tune, evaluate, or benchmark a competing product, model, or service, or to build a substitute for the services.
- Resell, sublicense, rent, lease, time-share, or provide the services to third parties outside your own business, or operate a service bureau or agency offering on top of them, without our written agreement.
- Impersonate another person or business, misrepresent your affiliation with us, or remove, obscure, or alter any proprietary notice, watermark, or machine-readable marking.
- Upload or transmit malware, viruses, or any code designed to disrupt, damage, or gain unauthorized access to a system, or send material that places an unreasonable load on our infrastructure.
- Use the services for medical diagnosis, triage, treatment decisions, or emergency handling, or in any of the ways prohibited in the AI features and EU AI Act sections.
- Use the services in a way that damages, disables, overburdens, or impairs them, or that interferes with another customer's use.
9. Your content and Customer Data
You retain all rights to the data and content you, your authorized users, and your patients or clients submit to or generate through the services, including messages, contacts, images, videos, documents, brand materials, and business information ("Customer Data"). We claim no ownership in it.
You grant Filo a worldwide, non-exclusive, royalty-free license to host, store, copy, transmit, display, adapt, and otherwise process Customer Data solely to provide, secure, and support the services for you, including to publish content to the accounts you connect, to send the messages you or the services send on your behalf, and to create backups. The license is limited to the term of this agreement, plus the short period needed for backups to expire on their normal cycle after deletion. It ends when the Data Processing Agreement's return and deletion obligations are performed.
You represent and warrant, for all Customer Data you submit, that:
- You own it or hold all rights, licenses, and permissions needed for us to process it and publish it as described in these Terms.
- You have the consent of any person whose name, image, voice, likeness, or testimonial appears in it, including staff, patients, and clients, for the use you make of it, and you can produce that consent on request.
- It does not infringe any copyright, trade mark, trade secret, database right, personality right, or other right of a third party.
- It is not unlawful, obscene, harassing, discriminatory, or otherwise contrary to these Terms, and it does not contain malware.
- You have a lawful basis for the personal data it contains, and you have given the privacy notices your own patients, clients, and contacts are entitled to.
- It contains only the personal data and health information needed for the purpose you submit it for, and nothing you are prohibited from disclosing.
10. AI features and how you must use them
Parts of the services use artificial intelligence to draft content and images, answer messages, handle calls, transcribe audio, and suggest campaigns. These features are built on models provided by the AI subprocessors listed at the Filo Trust Center, currently OpenAI for language models, Deepgram for speech to text, ElevenLabs for speech synthesis, and LiveKit for real-time audio. Each is engaged under a written agreement, is configured for processing in the European Union, and is contractually prohibited from using Customer Data to train or improve any model. The controls we have configured at each of them, and the dates we verified them, are published at the Filo Trust Center.
AI output is probabilistic. The same input can produce different output, output can be inaccurate, incomplete, out of date, or invented, and it can resemble output generated for someone else. We do not warrant that AI output is accurate, complete, suitable, original, or free of third-party rights. You are responsible for reviewing AI-generated content, messages, and ads before they go out, and for everything that is published or sent under your name.
Where the product asks for your approval before publishing or sending, that approval is your instruction and your editorial decision. Where you switch on automatic replies, automatic publishing, or automatic campaign changes, you accept that content will be sent or published without prior human review, you remain responsible for it, and you are expected to supervise the feature, review the logs the product provides, and switch it off if it is not performing as you need. You can switch automation off at any time in your workspace settings.
The services do not provide medical advice, are not a medical device, and must not be relied on for diagnosis, triage, treatment, or emergencies. You will make sure your patients and clients know how to reach emergency care and a human member of your team.
You will not use the AI features to produce, publish, or send:
- Content using the name, image, voice, or likeness of a real person without that person's consent, including patients, staff, public figures, and other businesses' customers.
- Synthetic images, audio, or video that depict a real person or a real event in a way that is misleading, including deepfakes, or that present AI-generated results as real treatment results.
- Content that infringes a third party's copyright, trade mark, design, or other right, or that imitates another business's brand so as to confuse.
- Advertising that is not recognizable as advertising, hidden or undisclosed commercial communications, paid endorsements presented as independent, or fake reviews and testimonials, which are prohibited under Annex I of Directive 2005/29/EC and equivalent national law.
- Health claims, treatment outcome claims, price claims, or before-and-after material that you cannot substantiate or that your profession's advertising rules prohibit.
- Content directed at children, or content exploiting a person's illness, age, or vulnerability.
11. EU AI Act: our role and yours
This section applies where Regulation (EU) 2024/1689 (the "AI Act") applies to you or to us. Filo is the provider of the AI systems built into the services, within the meaning of Article 3(3): we develop them and place them on the market under our own name. When you use them under your own authority in the course of your business, you are the deployer within the meaning of Article 3(4). We are not the provider of the general purpose AI models underlying the services; those are provided by the AI subprocessors named in the AI features section.
Under Article 25 of the AI Act you become the provider of an AI system, with the obligations that come with it, if you put your own name or trade mark on it, make a substantial modification to it, or change its intended purpose so that it becomes high-risk. You agree not to do any of these things without our prior written agreement, and you accept the consequences if you do.
Transparency. Under Article 50(1), our assistant identifies itself as an AI assistant when it interacts with a person in chat or on a call, unless that is obvious from the circumstances. You will not configure, instruct, or edit the services so as to deny that a person is dealing with an AI system, or to present the assistant as a named human member of your staff. Under Article 50(2), we mark the synthetic image, audio, and video content that the services generate in a machine-readable format where the model provider supports it, for example through embedded content credentials, and we will follow the technical standards for such marking as they become available. You will not remove, alter, or obscure those markings.
Your disclosure duties as deployer. Under Article 50(4), where you publish AI-generated or AI-manipulated text to inform the public on matters of public interest, or publish a deepfake, you must disclose that the content is artificially generated or manipulated, in the form and at the time the AI Act requires. Under Article 50(1) and (4) you must also make sure the people who message or call you are informed, in a clear and distinguishable way, at the latest at the time of the first interaction, that they are interacting with an AI system. The product provides settings and message text to help you do this, and you are responsible for keeping them switched on and accurate.
AI literacy. Under Article 4, each party will take measures to ensure a sufficient level of AI literacy among the staff who operate the services on its behalf, taking account of their technical knowledge, their training, and the context of use. We provide documentation, in-product guidance, and onboarding for the AI features; you will make sure the people in your business who use them have read it and understand what the features do, what they cannot do, and how to escalate to a human.
Prohibited practices. You will not use the services for any of the practices prohibited by Article 5, including subliminal, manipulative, or deceptive techniques that materially distort a person's behavior, exploiting the vulnerabilities of a person because of their age, disability, or social or economic situation, social scoring, inferring emotions of your employees, biometric categorization, or untargeted scraping of facial images.
High-risk uses. The services are not designed, tested, or intended for use as a high-risk AI system within the meaning of Article 6 and Annex III, including medical triage or emergency dispatch, decisions about access to healthcare or other essential services, employment, recruitment, or worker management decisions, creditworthiness assessment, or biometric identification. You will not use them for those purposes. If you do, you do so at your own risk, you assume the provider obligations under Article 25, and you will indemnify us as set out in the indemnification section.
No automated decisions about individuals. The services are not intended to take decisions based solely on automated processing that produce legal effects on a person or similarly significantly affect them within the meaning of Article 22 GDPR. Clinical decisions, decisions to accept or refuse a patient, and decisions about treatment or pricing remain decisions taken by a human in your business. If you choose to configure the services in a way that produces such a decision, you are the controller for it and you are responsible for the legal basis, the safeguards, and the right to obtain human intervention.
Cooperation with authorities. Each party will cooperate with the competent national authorities in good faith, and provide the other with the information and documentation reasonably needed for it to meet its own obligations under the AI Act, including on request the information a deployer needs under Article 26 and the logs the services keep. A party that receives a request or an investigation concerning the services will notify the other without undue delay, unless prohibited by law.
12. Model training, aggregates, and public web data
Filo does not use Customer Data, including the content of conversations, calls, contacts, images, or documents, to train, fine-tune, or improve any AI model, whether our own or a third party's, and we contractually prohibit our subprocessors from doing so. This applies to aggregated and anonymized derivatives of Customer Data as well: we do not build training sets, benchmarks, or prediction models out of your data. We use aggregated, non-personal operating statistics, such as request counts, error rates, latency, and usage volumes, only to run, secure, troubleshoot, and bill the services.
Public web data. To build your brand kit, to keep your content accurate, and to research market and format trends, the services collect information that is publicly available on the open web, including your own website when you ask us to scan it and the public pages of the platforms you connect. Where this involves text and data mining within the meaning of Article 4 of Directive (EU) 2019/790, we rely on that exception, we respect machine-readable reservations of rights including robots.txt and equivalent signals, we identify our crawler, and we do not bypass logins, paywalls, or technical protection measures. We do not collect personal data from the open web to build profiles of individuals.
When you ask us to scan a website, you confirm that you are entitled to have it scanned and that doing so does not breach anyone's rights or the terms of the site.
13. Intellectual property
Filo and its licensors own the services and everything in them, including the software, the user interface, the designs, the templates, the prompts and prompt chains, the illustration and design systems, the documentation, and the Filo name, logo, and other branding. These are protected by copyright, trade mark, database, and trade secret law. These Terms grant you no rights in them other than the license in the license section.
Output. Subject to your payment of the fees and to the rights of third parties, Filo assigns to you, or where assignment is not possible grants you an exclusive, perpetual, worldwide, royalty-free license to, whatever rights Filo may hold in the posts, captions, images, ad creatives, and messages the services generate specifically for your workspace ("Output"), so that you can use, publish, adapt, and commercialize them without restriction. You acknowledge that material generated by an AI system without sufficient human creative input may not be protected by copyright at all in many jurisdictions, including the United States and the European Union, that Filo therefore cannot and does not warrant that you have enforceable exclusive rights in Output, and that similar Output may be generated for other customers. Your rights in the Customer Data you supplied are not affected.
Feedback. If you send us feedback, suggestions, feature requests, or ideas about the services, you assign them to us, with all rights in them, free of charge, and where an assignment is not effective you grant us a perpetual, irrevocable, worldwide, royalty-free, sublicensable license to use them for any purpose. We may use feedback without attribution, confidentiality, or any payment to you. Feedback must not contain Customer Data or personal data.
References. We will not use your name, logo, or a description of your business as a public reference, case study, or testimonial without your prior written consent, which you may withdraw for future use at any time.
Breach. Unauthorized use of the services or of our intellectual property is a material breach of these Terms. It ends your license immediately, entitles us to suspend or terminate your access, and entitles us to seek injunctive relief and any other remedy available at law, in addition to damages.
14. Connected platforms and third-party services
The services interoperate with third-party platforms and providers, such as social media platforms, messaging channels, advertising platforms, and payment services. Your use of those platforms is governed by their own terms, and Filo is not responsible for their availability or conduct. A current list of the subprocessors we use to provide the services is published at the Filo Trust Center.
Connected platforms. When you choose to link an account, the services connect to the WhatsApp Business Platform, Instagram, Facebook Messenger, Facebook Pages, and Meta Ads, operated by Meta Platforms ("Meta"), and to TikTok. By connecting an account you authorize Filo to access it through the platform's official interfaces, within the permissions you grant during the connection, and to act on it on your behalf for the purposes of the services: receiving and replying to messages, publishing content, reading how your posts and ads perform, and setting up and managing advertising campaigns. The data we receive from each platform and how we handle it are described in our Privacy Policy. You can disconnect an account at any time from your workspace settings or by removing Filo in the platform's own settings, after which we stop accessing it. Disconnecting does not delete the data already in your workspace, which is returned and deleted under the Data Processing Agreement.
Google. Where you sign in with Google or connect a Google account, Filo's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. We request the narrowest scopes the feature needs, we use Google user data only to provide the feature you asked for, we do not use it for advertising, we do not sell it, we do not transfer it except as needed to provide the feature, to comply with law, or as part of a merger where you are given notice, and we do not allow humans to read it except with your consent, for security or to comply with law, or where the data is aggregated and anonymized. You can disconnect Google access at any time in your profile settings or in your Google account.
Your use of a connected platform through the services is also subject to that platform's terms and policies, which you agree to comply with, including the Meta Platform Terms and Developer Policies, the WhatsApp Business Terms of Service and WhatsApp Business Messaging Policy, the Instagram and Facebook terms and community standards, Meta's Advertising Standards, and the TikTok Terms of Service and Community Guidelines. Platforms may change, limit, suspend, or withdraw access to their interfaces or to your accounts at any time. This may affect all or part of the services, and Filo is not liable for the consequences. Where a platform change makes a material part of the services permanently unavailable to you, you may terminate the affected services and we will refund prepaid fees for the period after termination, calculated pro rata.
When you communicate with people through a connected platform, you are responsible for:
- Having the consent or opt-in that the platform and applicable law require before messaging a person, including for marketing messages, and honoring opt-out requests promptly.
- Respecting the platform's messaging rules, such as WhatsApp's customer service window and approved message templates, and the messaging windows on Instagram and Messenger.
- The content of the messages, posts, and ads published under your name, whether written by you, generated by Filo's AI features, or prepared by Filo personnel on your instructions.
15. Design and media tool integrations
Where the services offer an integration with a third-party design, media, or stock content tool, for example to import templates, images, fonts, or video into your workspace, that integration is provided for convenience, as available, and subject to that tool's own terms, license conditions, and usage limits. We may add, change, or withdraw such an integration, and the tool's provider may do the same without notice to us.
You are responsible for holding the licenses and rights needed for anything you import through such an integration, including stock images, fonts, music, and templates, and for using it within the scope of those licenses when it is published through the services. Import, export, and volume limits set by us or by the tool may apply, and we may apply fair use limits to protect the services. Material you import is Customer Data and is covered by your representations in the content section.
16. Third-party websites and content
The services and our websites may contain links to third-party websites, applications, and content, and may display content retrieved from them. We do not investigate, monitor, or endorse them, we are not responsible for their accuracy, legality, or safety, and their inclusion does not imply any approval or association. If you leave the services for a third-party website, these Terms no longer apply, and you should read that site's own terms and privacy notice.
You access third-party websites and content, and enter into transactions with third parties, at your own risk. You will hold us harmless from any loss you suffer as a result, and any dispute about a third party's products, services, or content is between you and that third party.
17. Reviews, testimonials, and references
If you post a review, rating, or testimonial about Filo, whether in the product, on our website, or on a review platform at our invitation, it must be based on your own firsthand experience, it must be honest and not misleading, and you must disclose any payment, discount, or other incentive you received for it. It must not contain offensive, abusive, discriminatory, or unlawful material, must not include personal data of patients or other third parties, and must not be submitted by someone with an undisclosed connection to us or to a competitor.
You grant us a perpetual, worldwide, non-exclusive, royalty-free, sublicensable license to use, reproduce, adapt for length or format, publish, and display any review or testimonial you submit, together with the first name and business name you provide with it. We may refuse, edit, or remove a review that breaches this section, and we do not remove or suppress negative reviews for being negative.
18. Advertising spend
Our fees cover the Filo software and services only. They do not include advertising spend. Any budget spent on ads is paid by you directly to the advertising platform, such as Meta, under that platform's own terms, and is never billed or marked up by Filo.
Where you connect an advertising account, you authorize Filo to create, launch, pause, and optimize campaigns within the budgets and limits you set in the platform or agree with us in writing. You remain the account holder and advertiser of record, you are responsible for the budgets, payment methods, and spending limits configured in your advertising accounts, and you are responsible for the content of ads published under your name complying with applicable advertising and healthcare marketing rules. We will not exceed a budget you have set without your approval, but we are not liable for spend that results from settings you or the platform control, or from platform behavior outside our control.
19. Fees and payment
Payments are processed by Stripe, our payment provider. When you pay, you also agree to Stripe's terms, and Stripe handles your card and bank details; Filo never stores them. Prices, currency, and billing period are those shown at checkout or agreed with you in writing, plus applicable taxes.
By giving us a payment method you authorize us, and Stripe on our behalf, to charge it automatically for the fees due, including recurring subscription fees, on each billing date, until you cancel. Fees are billed in advance for each billing period. You will keep a valid payment method on file for as long as the subscription runs, and you will keep your billing details current. Invoices are issued electronically to the billing email on your account.
Taxes. Our fees do not include VAT, sales tax, or similar taxes. Filo is established in the United States. If you are a business established in the European Union, we do not charge you VAT: the supply falls under the reverse charge mechanism (Article 196 of Council Directive 2006/112/EC), and you are responsible for accounting for VAT in your own country. Our invoices state this. You agree to give us your business address and, where you have one, your VAT identification number at checkout and to keep them accurate. Where the reverse charge does not apply, or where the law of another country places a tax on the fees, we may add that tax to your invoice or you may be required to pay it directly.
Non-payment. If a payment fails, we may retry it and will tell you. Undisputed amounts that remain unpaid 10 days after we notify you may carry interest at the statutory rate for late payment in commercial transactions, which for customers in the European Union is the rate under Directive 2011/7/EU, together with the fixed recovery amount that Directive provides. We may suspend the services after reasonable notice while amounts remain overdue, and we may terminate for non-payment as set out in the termination section. Your right to export your data under the Data Processing Agreement is not affected by a payment dispute.
Depending on your plan, fees are structured in one of two ways:
- A one-time setup fee, followed by a recurring subscription that starts once setup is complete.
- A recurring subscription only, billed monthly or annually.
20. Subscriptions, renewal, and cancellation
Subscriptions are billed in advance at the start of each billing period and renew automatically for successive periods of the same length until cancelled. You may cancel at any time from your billing settings or by emailing daniel@meetfilo.io. Cancellation takes effect at the end of the current billing period, and you keep access until then. Except under the 30-day satisfaction guarantee below, where a refund is expressly provided for elsewhere in these Terms, or where required by law, fees already paid are not refunded, and no refund or credit is given for partial billing periods or for periods in which you did not use the services.
We may change our prices with at least 30 days' notice; a change applies from your next renewal after the notice period, and you may cancel before that renewal if you do not accept the new price.
21. 30-day satisfaction guarantee
If you are not satisfied with Filo for any reason, you can request a full refund within 30 calendar days from the date of your first payment to Filo. The refund covers everything you have paid us in that period, including any setup fee and any subscription fees, whether monthly or annual. To request it, email daniel@meetfilo.io from the email address on your account before the 30-day period ends. We will confirm the request and issue the refund to your original payment method through Stripe within 10 business days. Your subscription is cancelled and your access to the services ends when the refund is issued, and your data is returned and deleted as set out in the Data Processing Agreement.
The guarantee applies once per customer and does not cover advertising spend or other amounts paid to third parties such as Meta, which are outside our control. Requests received after the 30-day period, and payments made after it, are subject to the cancellation terms above. The guarantee is in addition to, and does not limit, any mandatory refund rights you have under applicable law.
22. Corrections and errors
The product, our websites, and our marketing material may contain typographical errors, inaccuracies, or omissions, including in prices, plan descriptions, and availability. We may correct them and may update information at any time without prior notice.
Where a price was displayed or charged in error and the error was obvious, we are not obliged to supply the services at that price. We will tell you before we do anything, and you may either confirm the order at the correct price or cancel it, in which case we refund what you paid for the cancelled part. Correcting an error does not by itself entitle you to a refund of fees properly charged.
23. Data protection: our roles and the Data Processing Agreement
Two different roles apply. For your account, billing, support, and website data, Filo is the controller and our Privacy Policy explains what we do. For the personal data inside your workspace, including your patients' and clients' data and the content of conversations and calls, you are the controller and Filo is the processor acting on your behalf.
Our Data Processing Agreement ("DPA"), available from the Filo Trust Center in an EU version meeting Article 28(3) GDPR and a United States version covering HIPAA and CCPA, is incorporated into these Terms and applies to that processing. You can generate and sign a copy for your business from the Filo Trust Center. Where the DPA conflicts with these Terms on the processing of personal data, the DPA prevails. Where you are a HIPAA covered entity or business associate, a Business Associate Agreement is available and takes precedence for protected health information.
The DPA sets out, and we commit here, that Filo:
- Processes Customer Data only on your documented instructions, which are these Terms, the DPA, and the settings and actions you take in the product, and tells you if an instruction appears to infringe data protection law (Article 28(3)(a) GDPR).
- Ensures that the people authorized to process Customer Data are bound by confidentiality obligations (Article 28(3)(b) GDPR).
- Implements the technical and organizational measures described in the next section but one (Articles 28(3)(c) and 32 GDPR).
- Engages subprocessors only under the conditions in the subprocessors section (Articles 28(2) and 28(4) GDPR).
- Helps you respond to data subject requests, and assists you with security, breach notification, impact assessments, and prior consultation (Articles 28(3)(e) and (f), and 32 to 36 GDPR).
- Notifies you of a personal data breach affecting Customer Data without undue delay, and within 24 hours of becoming aware of it under the EU DPA, with the information you need for your own notification duties (Article 33(2) GDPR).
- Makes available the information needed to demonstrate compliance and allows and contributes to audits, on the terms in the DPA (Article 28(3)(h) GDPR).
- Deletes or returns Customer Data at the end of the services, at your choice, and deletes existing copies unless law requires it to be kept (Article 28(3)(g) GDPR).
- Does not use Customer Data for its own purposes, including product development, research, or model training, and prohibits its subprocessors from doing so.
24. Hosting, international transfers, and retention
Customer Data is hosted in the European Union: the application backend, the background workers, and the database run in Amsterdam, Netherlands, file storage runs in Frankfurt, Germany, and the AI subprocessors process in the European Union. The current hosting locations of every subprocessor are published at the Filo Trust Center and attached to the EU DPA as an annex.
Filo is established in the United States, and a transfer of personal data to us as a company can occur, for example when our personnel provide the hands-on assistance described above. Transfers of personal data out of the European Economic Area or the United Kingdom are covered by the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, incorporated into the EU DPA, together with the UK International Data Transfer Addendum where the UK GDPR applies, and by the transfer impact assessment and supplementary measures described in the DPA. Where a subprocessor in the United States is certified under the EU-U.S. Data Privacy Framework, as Stripe is, we may also rely on the European Commission's adequacy decision of 10 July 2023, without that replacing the Clauses.
Retention. Customer Data is kept for as long as your workspace is active, and then handled under the DPA's return and deletion clause. Some categories are deleted sooner, automatically:
- Call recordings and call audio: deleted no later than 30 days after the call.
- Call transcripts: deleted no later than 12 months after the call.
- Files sent by your patients and clients in a conversation, such as photos, voice messages, videos, and documents: deleted no later than 90 days after they arrive. The text we derived from a file, such as a description or a transcript, stays with the message.
- Contact lists uploaded for a messaging campaign, both the file as uploaded and the cleaned recipient list: deleted no later than 12 months after upload. The messages sent stay with the conversation.
25. Subprocessors
You give Filo a general written authorization to engage subprocessors to process Customer Data, under Article 28(2) GDPR and on the conditions in this section and in the DPA. The current list, with each subprocessor's purpose, processing location and region, data categories, agreement, safeguards, and transfer mechanism, is published at the Filo Trust Center with a version number, a publication date, and a change log.
Changes and objection. We give you prior written notice, by email or through the subscription mechanism at the Filo Trust Center, before we add or replace a subprocessor, and before we change the hosting location, processing region, or transfer mechanism of an existing one. The notice period is at least 14 days, and at least 30 days where the change concerns an AI subprocessor. You may object in writing within the notice period on reasonable data protection grounds. While a timely objection is pending we do not engage the new subprocessor for your data, we discuss the objection in good faith, and we propose alternatives where commercially reasonable. If it is not resolved within 30 days you may terminate the affected services by written notice, and we refund prepaid fees for the period after termination, calculated pro rata.
Flow-down. Each subprocessor is bound by a written agreement imposing data protection obligations no less protective than those we owe you, as required by Article 28(4) GDPR, including the prohibition on model training, and Filo remains fully liable to you for their performance.
Platforms you connect yourself, such as Meta and TikTok, are not our subprocessors. When you link an account, data flows between you and that platform under the terms you have with it, and the platform acts as its own controller for what it does with that data. The same is true of an advertising account you connect.
The categories of subprocessor we use today are:
- Hosting and infrastructure: the application backend, background workers, and the database (Railway, Amsterdam, Netherlands), file and media storage (Amazon Web Services, Frankfurt, Germany), and web application hosting and content delivery (Vercel, Frankfurt, Germany).
- AI: language models (OpenAI, EU data residency), speech to text (Deepgram, EU endpoint), speech synthesis (ElevenLabs, isolated EU environment), and real-time voice infrastructure (LiveKit, Frankfurt and Paris). Each is configured so that data is not used for model training and is retained for no longer than the request requires.
- Payments: card and bank payment processing, invoicing, and fraud prevention (Stripe, United States, under the EU-U.S. Data Privacy Framework and the Standard Contractual Clauses). No health data is shared with our payment provider.
- Email and notifications: transactional email (Resend, Dublin, Ireland) and SMS and voice notifications (Twilio, Ireland).
- Product analytics: anonymous product usage events without persistent identifiers (PostHog, Frankfurt, Germany).
- Support: the systems we use to answer your support requests, which are the email and product systems listed above.
26. Technical and organizational measures
Filo implements the technical and organizational measures required by Article 32 GDPR, appropriate to the risk of processing health-related data. The measures in force are described at the Filo Trust Center and annexed to the DPA, and include:
- Access control: role-based access with least privilege, single sign-on and multi-factor authentication for administrative access to our systems, separate production and non-production environments, access reviews every quarter, and prompt removal of access when someone leaves.
- Encryption: all personal data encrypted in transit with TLS 1.2 or higher and at rest with AES-256, encrypted backups, and encrypted media transport for real-time audio.
- Operational security: private networking between the application and the database, secrets held in managed secret storage and never in source code, hardened managed infrastructure, and logging and monitoring of access to production systems.
- Backups and continuity: daily encrypted backups, tested restores, and redundant infrastructure, with recovery procedures documented.
- People: written confidentiality obligations for everyone with access, security and data protection training, and access granted only to personnel who need it for a task.
- Secure development: code review before deployment, dependency and vulnerability scanning, staged deployments, and separation of duties between development and production access.
- Incident handling: a documented incident response plan, detection and escalation paths, and notification to affected customers without undue delay, within 24 hours under the EU DPA and 72 hours under the United States DPA.
- Vendor management: every subprocessor risk-assessed and bound by a data processing agreement, or a business associate agreement where HIPAA applies, before it is used.
- Physical security: no Filo data centers; hosting is delegated to certified providers whose facilities are covered by ISO 27001 and SOC 2 audits, with their reports available on request where the provider permits.
- Data minimization: only the content needed for a task is sent to AI subprocessors, retention periods are enforced automatically, and pseudonymized or aggregated data is used where it is sufficient.
27. Confidentiality
Each party will protect the other's non-public information with at least reasonable care, use it only as needed to perform under these Terms, and not disclose it to third parties except to employees, advisors, and subprocessors bound by confidentiality obligations, or where required by law. Where disclosure is required by law, the disclosing party will, where lawful, give the other party notice in time to seek protection.
These obligations do not apply to information that is or becomes public without a breach of this section, was already known to the receiving party without a duty of confidentiality, is received from a third party entitled to disclose it, or is independently developed without use of the other party's information. They continue for five years after this agreement ends, and for as long as the information remains a trade secret. Personal data is governed by the DPA rather than by this section.
28. Copyright complaints
We respect the intellectual property of others. If you believe that material available through the services infringes a copyright you own or control, send a written notice to our designated copyright agent at daniel@meetfilo.io, or by post to Copyright Agent, Filohealth Software, Inc., 2810 North Church Street, STE 90642, Wilmington, DE 19802, United States.
To be effective under 17 U.S.C. section 512(c)(3), your notice must include: your physical or electronic signature; identification of the copyrighted work you claim has been infringed; identification of the material you claim is infringing and information reasonably sufficient for us to locate it; your address, telephone number, and email address; a statement that you have a good faith belief that the use is not authorized by the copyright owner, its agent, or the law; and a statement, made under penalty of perjury, that the information in the notice is accurate and that you are the owner or authorized to act on the owner's behalf. Notices under other applicable copyright law should contain equivalent information.
On receipt of an effective notice we may remove or disable access to the material and will notify the customer concerned, who may send a counter notification meeting 17 U.S.C. section 512(g)(3). We terminate, in appropriate circumstances, the accounts of repeat infringers. Anyone who knowingly misrepresents that material is infringing, or that it was removed by mistake, may be liable for damages under 17 U.S.C. section 512(f).
29. How we manage the services
We may, but are not obliged to, monitor the services for breaches of these Terms, for security threats, and for compliance with the rules of connected platforms, and we may review content that is reported to us. We do not pre-screen Customer Data and we are not the author or editor of the content you publish.
Where content or activity breaches these Terms, applicable law, or a connected platform's rules, we may refuse, restrict, remove, or disable access to it, limit or throttle automated or excessive usage, take appropriate legal action, and, in line with the term, suspension, and termination section, suspend or terminate the account concerned. We will tell you what we have done and why, unless telling you would be unlawful or would compromise security or an investigation, and you may contest the decision by writing to daniel@meetfilo.io.
We may also manage the services in ways that protect our rights and property and keep the services working properly, including removing files that are unusually large or that place an unreasonable load on the infrastructure, and disabling an integration that a platform has restricted.
30. Warranty disclaimer
The services are provided "as is" and "as available", with all faults. To the maximum extent permitted by law, Filo disclaims all warranties, express or implied, including merchantability, fitness for a particular purpose, and non-infringement, and does not warrant that the services will be uninterrupted, secure, or error-free, that defects will be corrected, or that AI output will be accurate, complete, original, or free of third-party rights.
Results depend on your business, your market, your advertising budget, and the behavior of third-party platforms. Filo does not guarantee any particular number of leads, bookings, followers, or sales, or any particular advertising performance or return on ad spend. Your remedy if you are not satisfied is the 30-day satisfaction guarantee above and your right to cancel.
Nothing in this section excludes a warranty or a liability that cannot be excluded under the law that governs this agreement or under mandatory law where you are established.
31. Limitation of liability
To the maximum extent permitted by law, neither party is liable for indirect, incidental, special, consequential, or punitive damages, or for lost profits, revenue, goodwill, or reputational harm, however arising.
General cap. Each party's total liability under these Terms is limited to the fees paid or payable by you for the services in the 12 months before the event giving rise to liability.
Data protection cap. In place of the general cap, each party's total liability for breaches of its confidentiality, security, and data protection obligations under these Terms and the Data Processing Agreement is limited to three times the fees paid or payable by you for the services in the 12 months before the event giving rise to liability.
Attribution. Filo is liable under the data protection cap only for damage caused by a breach by Filo or its subprocessors of these Terms, the Data Processing Agreement, or your documented instructions, consistent with Article 82(2) GDPR. Consistent with Article 82(3) GDPR, Filo is exempt from liability where it shows that it is not in any way responsible for the event giving rise to the damage. Whether an event is attributable to Filo is established from the facts of the incident, including the access and audit logs of both parties, and each party will cooperate in good faith in that investigation.
Where both parties contributed to the damage, each party's liability is reduced in proportion to its share of responsibility, in line with Article 82(5) GDPR.
These limits do not apply to your payment obligations, your breach of the prohibited activities section, your indemnification obligations, either party's gross negligence, willful misconduct, or fraud, death or personal injury caused by negligence, or any liability that cannot be limited by law.
Time limit for claims. Except for claims for unpaid fees and for claims that mandatory law does not allow to be limited in time, neither party may bring a claim under these Terms more than 12 months after the party bringing it knew, or should reasonably have known, of the facts giving rise to it.
Filo is not liable for damage caused by you or your personnel, including:
- Sharing or losing credentials.
- User permissions you configure.
- Data or messages sent to the wrong person by your staff.
- The compromise of your own systems or of third-party systems you connect to the services.
- Processing carried out on your instructions.
- Content you approved, or that you allowed the services to send automatically, after switching on an automation feature.
32. Indemnification
You will defend Filo, its officers, directors, employees, and agents against any third-party claim, and indemnify them against the damages, fines, settlements, and reasonable legal costs finally awarded or agreed, arising out of or connected with:
- Customer Data and any content published or sent through your account, whether written by you, generated by AI, or prepared by us on your instructions.
- Your use of Output, including its publication, and any claim that it infringes a third party's intellectual property or personality rights.
- Your breach of these Terms, of the Data Processing Agreement, or of the rules of a connected platform.
- Your violation of applicable law, including healthcare, advertising, consumer protection, privacy, and anti-spam law, and of the AI Act obligations that fall on you as deployer.
- A claim by one of your patients, clients, or contacts about a message, post, or ad sent or published through your account, or about how their personal data was handled by you.
- Your use of the services for a high-risk purpose, as described in the EU AI Act section.
33. Indemnity procedure and our defense of the services
Conditions. Our right to be indemnified depends on us notifying you of the claim without undue delay, giving you control of the defense and settlement, and cooperating at your expense. You may not settle a claim in a way that admits our liability, imposes an obligation on us, or fails to release us unconditionally, without our written consent. We may take part in the defense with our own counsel at our own cost.
Our defense of the services. Filo will defend you against a third-party claim that the services, as provided by us and used in accordance with these Terms, infringe that party's intellectual property rights, and will pay the damages and costs finally awarded or agreed, subject to the general cap in the limitation of liability section and to you notifying us without undue delay, giving us control of the defense, and cooperating. This does not apply to a claim arising from Customer Data, from Output, from your instructions, from use in breach of these Terms, from a combination with something we did not supply, or from a modification not made by us. If a claim is made or looks likely, we may obtain the right for you to continue using the services, modify or replace the affected part so that it is no longer infringing, or, if neither is reasonably available, terminate the affected services and refund prepaid fees for the period after termination, calculated pro rata. This is your exclusive remedy for a claim of that kind.
34. Term, suspension, and termination
These Terms apply from the date you accept them until your account is closed or the subscription ends. Either party may terminate for material breach that remains uncured 30 days after written notice describing the breach, and either party may terminate immediately if the other becomes insolvent, enters liquidation, or ceases business.
Suspension. We may suspend all or part of the services immediately where needed to protect the services, other customers, or third parties, where a connected platform requires it, where required by law, or where fees remain overdue after notice. We will limit the suspension to what is necessary, tell you the reason where we lawfully can, and lift it once the cause is resolved.
Termination by us. We may also terminate this agreement and close your account, at our discretion and with 30 days' notice, refunding prepaid fees for the period after termination, calculated pro rata. Where we terminate for your material breach, for unlawful use, or for a breach of the prohibited activities section, no refund is due, and you may not register a new account, or have one registered on your behalf or for an affiliate, without our written consent.
Effect. On termination your license ends, access to the services ends, and you must stop using them. For 30 days after termination we keep Customer Data available for export unless we are required to delete it sooner or the account was terminated for unlawful activity, and after that we return or delete it as set out in the Data Processing Agreement. Fees already due remain payable. The sections on intellectual property, confidentiality, data protection, warranty disclaimer, limitation of liability, indemnification, governing law, dispute resolution, and miscellaneous survive termination.
35. Changes to these Terms
We may update these Terms, for example to reflect new features, new legal requirements, or changes in how we deliver the services. Where the change is material, we will tell you in the product or by email at least 30 days before it takes effect and ask you to accept the new version before you continue using the services. If you do not accept it, you may terminate before the change takes effect and we will refund prepaid fees for the period after termination, calculated pro rata. Changes that are not material, such as corrections, clarifications, and updated legal references, take effect when published.
The version number and effective date at the top of this document identify the current Terms. We keep a record of the version you accepted, when you accepted it, and from which device, and we can provide it on request. Continuing to use the services after a change has taken effect means you accept it.
36. Electronic communications and signatures
You agree to contract electronically. Ticking an acceptance box, clicking a button marked as acceptance, or signing electronically has the same legal effect as a handwritten signature, and you waive any requirement of a non-electronic signature or of delivery of non-electronic records, to the extent the law allows. For customers in the United States this is given effect by the E-SIGN Act, 15 U.S.C. section 7001, and applicable state law; for customers in the European Union, an electronic signature is not denied legal effect solely because it is electronic, under Article 25 of Regulation (EU) No 910/2014 (eIDAS).
Notices. We send notices to the email address on your account or show them in the product; you send notices to daniel@meetfilo.io, and, where a notice starts a legal deadline, also by post to the address above. A notice by email is treated as received on the next business day after it is sent, unless the sender receives a delivery failure. Keep the email address on your account current: notices sent to it are effective even if you no longer read it.
37. Governing law and competent courts
Which law and which courts apply depends on where your business is established, as shown by the registered address in your account at the time a claim is brought. The choice is made under Article 3 of Regulation (EC) No 593/2008 (Rome I) and, for jurisdiction, Article 25 of Regulation (EU) No 1215/2012 (Brussels I bis), where those apply.
Italy. If your business is established in Italy, these Terms are governed by Italian law, excluding its conflict of laws rules, and the parties agree to the exclusive jurisdiction of the Tribunale di Milano, Sezione Specializzata in materia di Impresa (the specialized business division established by Legislative Decree No. 168 of 27 June 2003).
Spain. If your business is established in Spain, these Terms are governed by Spanish common law (derecho común), excluding its conflict of laws rules and any regional foral law, and the parties agree to the exclusive jurisdiction of the commercial courts of Madrid, that is the Sección de lo Mercantil of the Tribunal de Instancia de Madrid, previously the Juzgados de lo Mercantil de Madrid, expressly waiving any other forum to which they might otherwise be entitled.
Everywhere else. If your business is established anywhere else, these Terms are governed by the laws of the State of Delaware, United States, excluding its conflict of laws rules, and the parties agree to the exclusive jurisdiction of the courts located in New Castle County, Delaware, namely the Delaware Court of Chancery and, where it does not have jurisdiction, the Superior Court of the State of Delaware or the United States District Court for the District of Delaware. Each party consents to personal jurisdiction there and waives any objection based on inconvenient forum.
Common rules. The United Nations Convention on Contracts for the International Sale of Goods (Vienna, 1980) and the Uniform Computer Information Transactions Act do not apply. Either party may apply to any court with jurisdiction for interim or protective measures, including an injunction to protect intellectual property or confidential information, as permitted by Article 35 of Brussels I bis where it applies. Nothing in this section deprives you of the mandatory protections of the law of the country where you are established, or of the right to bring a data protection claim where Article 79 GDPR allows it.
38. Dispute resolution
Before going to court, the parties will try to resolve a dispute amicably. The party raising it sends a written notice to daniel@meetfilo.io, or to the customer's account email, describing the dispute, the relevant facts, and the outcome sought. Within 15 days the parties, each represented by someone with authority to settle, will meet, by video call if that is easier, and negotiate in good faith.
If the dispute is not resolved within 30 days of the notice, either party may bring proceedings before the courts named in the governing law section. This section does not prevent either party from seeking interim or protective relief at any time, or from pursuing undisputed unpaid fees. Each party brings claims only in its own capacity and not as a representative or member of a class, to the extent permitted by applicable law. Each party bears its own costs of the amicable stage.
39. Miscellaneous
Entire agreement and precedence. These Terms, the Data Processing Agreement, any Business Associate Agreement, any order form or written agreement signed by both parties, and the documents they refer to, are the entire agreement between us about the services and replace any earlier proposal or understanding. Where they conflict, the following order applies: first, a Business Associate Agreement for protected health information; second, the Data Processing Agreement for the processing of personal data; third, a signed order form or written agreement; fourth, these Terms; and last, any policy or documentation referred to in them. Your purchase order terms and similar standard terms do not apply, even if we do not object to them.
Waiver, assignment, and severability. A failure to enforce a right is not a waiver of it, and a waiver is effective only in writing and for the occasion given. You may not assign or transfer this agreement without our written consent, which we will not unreasonably withhold; we may assign it to an affiliate or to a successor in a merger, reorganization, or sale of the business to which it relates, on notice to you. If a provision is held invalid or unenforceable, it is adjusted to the minimum extent needed to make it valid, or severed if that is not possible, and the rest of the Terms remain in force.
Force majeure. Neither party is liable for a delay or failure caused by an event beyond its reasonable control, including natural disaster, fire, flood, epidemic, war, terrorism, civil unrest, strike, failure of the public internet or of electricity supply, failure or discontinuation of a third-party platform or infrastructure provider, cyber attack on infrastructure it does not control, government act, or embargo. The affected party will tell the other and resume performance as soon as it can. This does not excuse an obligation to pay amounts already due. If the event lasts more than 60 days, either party may terminate the affected services with prepaid fees refunded pro rata.
Relationship and interpretation. Nothing in these Terms creates a partnership, joint venture, agency, franchise, or employment relationship between the parties, and neither may bind the other. Headings are for convenience only. "Including" means "including without limitation". References to a statute or regulation include its amendments and successors. No provision is interpreted against the party that drafted it. There are no third-party beneficiaries, except that the Filo indemnified persons named in the indemnification section may rely on that section.
Language. These Terms are made in English. Translations are provided only as a courtesy to help you understand them; the English version is the only binding one, and if a translation differs from it, the English text prevails, including for the interpretation of any defined term.
40. Contact us
Filohealth Software, Inc., registration number 10746556, 2810 North Church Street, STE 90642, Wilmington, DE 19802, United States. Website: https://filo.inc and https://meetfilo.io. Email: daniel@meetfilo.io, which reaches us for questions about these Terms, for privacy and data protection requests, for security reports, for copyright notices, and for support. Our subprocessor list, security measures, and Data Processing Agreement are published at the Filo Trust Center.