DepreciationConverter

Vendor file

Everything your WISP needs about us, on one page.

16 CFR §314.4(f) requires you to select service providers capable of maintaining appropriate safeguards, to require those safeguards by contract, and to reassess them periodically. Print this page, or lift the sections into your plan.

Vendor summary

Service
Transcription of depreciation schedules into tax-software import files
Category of data received
Tax return information: asset descriptions, dates, dollar amounts, methods and lives
Data explicitly NOT required
SSN, EIN and other taxpayer identifiers — detected and redacted on upload
Processing location
United States only, including AI inference
Subprocessors
US cloud hosting; US AI inference provider under a no-training commitment; Stripe for payment (card data never reaches us)
Model training
Prohibited. Customer data is not used to train AI models by us or any subprocessor
Retention
Automatic deletion within 30 days; immediate deletion on request from the conversion screen
Encryption
TLS in transit; encrypted at rest
Access control
Signed-in account or per-session unguessable link; staff access limited to operations and support
Regulatory basis
Auxiliary services under Treas. Reg. §301.7216-2(d)(1) — US-only, no substantive determinations
Professional judgment
None exercised. The tool transcribes and flags; the preparer decides
Certification status
SOC 2 Type I in progress; Type II to follow
Incident notification
Written notice to affected firms without unreasonable delay
Reassessment cadence
This page is the current record; re-check it at each season's vendor review

Drop-in paragraph for your WISP

Adapt as needed; your plan, your wording.

The Firm uses DepreciationConverter to transcribe fixed-asset depreciation schedules received from prior preparers into the import format of the Firm's tax preparation software. The vendor receives tax return information limited to asset-level descriptions, dates, amounts, methods and lives; taxpayer identification numbers are redacted by the vendor on receipt and are not retained. All processing, including any artificial intelligence inference, occurs within the United States, so the disclosure falls within the auxiliary-services provision of Treas. Reg. §301.7216-2(d)(1) and does not require taxpayer consent. The vendor does not use Firm or client data to train artificial intelligence models, encrypts data in transit and at rest, and deletes uploaded documents and extracted data within thirty days. The vendor performs transcription only and exercises no professional judgment; all depreciation determinations remain with the Firm. The Firm reviews the vendor's published security and regulatory disclosures at each annual vendor assessment.

Full security page →

Something missing?

If your firm's review needs a signed exhibit, a specific representation, or an answer this page doesn't cover, write to [email protected] and we'll turn it around rather than route you to a call.