Master Services Agreement
Joymore LLC
Last Revised: July 28th 2026
IMPORTANT – READ CAREFULLY. PLEASE READ THIS MASTER SERVICES AGREEMENT (“MSA”) CAREFULLY BEFORE USING THE SERVICES OFFERED BY JOYMORE LLC (“COMPANY”). BY CLICKING “I AGREE,” CHECKING AN ACCEPTANCE BOX, OR BY ACCESSING OR USING THE SERVICES, YOU (“CUSTOMER”) AGREE TO BE BOUND BY THIS MSA AND ANY ORDER FORM REFERENCING THIS MSA (TOGETHER, THE “AGREEMENT”) TO THE EXCLUSION OF ALL OTHER TERMS. IF YOU DO NOT AGREE TO THESE TERMS, DO NOT ACCESS OR USE THE SERVICES. IF THE TERMS OF THIS AGREEMENT ARE CONSIDERED AN OFFER, ACCEPTANCE IS EXPRESSLY LIMITED TO SUCH TERMS.
1. Order Forms.
Upon mutual execution, each Order Form shall be incorporated into and form a part of the Agreement.
2. Services.
For each Order Form, subject to Customer’s compliance with the terms and conditions of this Agreement (including any limitations and restrictions set forth on the applicable Order Form), Company grants Customer a nonexclusive, limited, nonsublicensable, nontransferable right and license to access and use of the Company product(s) and/or service(s) specified in such Order Form (collectively, the “Service” or “Services”) during the applicable Order Form Term (as defined below) for the internal business purposes of Customer, only as provided herein and only in accordance with Company’s applicable official user documentation for such Services (the “Documentation”).
3. Implementation; Support.
Subject to Customer’s payment of all applicable fees, Company agrees to use commercially reasonable efforts to provide (i) standard implementation assistance for the Service only if and to the extent such assistance is set forth on such Order Form (“Implementation Assistance”) and (ii) reasonable support and maintenance for the Service.
4. Updates.
From time to time, Company may provide upgrades, patches, enhancements, or fixes for the Services to its customers generally without additional charge (“Updates”), and such Updates will become part of the Services and subject to this Agreement; provided that Company shall have no obligation under this Agreement or otherwise to provide any such Updates. Customer understands that Company may make improvements and modifications to the Services at any time in its sole discretion; provided that Company shall use commercially reasonable efforts to give Customer reasonable prior notice of any material changes that might materially adversely impact Customer’s use of the Services.
5. Fees; Payment.
Customer shall pay Company the fees as set forth in each Order Form (“Fees”). Unless otherwise specified in an Order Form, all fees shall be invoiced monthly in arrears based on Customer’s actual usage during the applicable month, and all invoices issued under this Agreement are payable in U.S. dollars within thirty (30) days from date of invoice. Support and maintenance fees shall be invoiced monthly as incurred or as otherwise set forth in an Order Form. Past due invoices are subject to interest on any outstanding balance of the lesser of 1.5% per month or the maximum amount permitted by law. Customer shall be responsible for all taxes associated with the Services (excluding taxes based on Company’s net income). All Fees paid are non-refundable and are not subject to set-off.
6. Ownership; Feedback.
As between the parties, Company and its licensors retain all right, title, and interest in and to the Services, and all software, products, works, and other intellectual property and moral rights related thereto or created, used, or provided by Company for the purposes of this Agreement, including any copies and derivative works of the foregoing. Any software which is distributed or otherwise provided to Customer hereunder (including without limitation any software identified on an Order Form) shall be deemed a part of the “Services” and subject to all of the terms and conditions of this Agreement. No rights or licenses are granted except as expressly and unambiguously set forth in this Agreement. Customer may (but is not obligated to) provide suggestions, comments or other feedback to Company with respect to the Service (“Feedback”). Customer hereby assigns to Company all right, title and interest in and to the Feedback. Nothing in this Agreement will impair Company’s right to develop, acquire, license, market, promote or distribute products, software or technologies that perform the same or similar functions as, or otherwise compete with any products, software or technologies that Customer may develop, produce, market, or distribute.
7. Restrictions.
Except as expressly set forth in this Agreement, Customer shall not (and shall not permit any third party to), directly or indirectly: (a) reverse engineer, decompile, disassemble, or otherwise attempt to discover the source code, object code, or underlying structure, ideas, or algorithms of the Services (except to the extent applicable laws specifically prohibit such restriction); (b) modify, translate, or create derivative works based on the Services; (c) copy, rent, lease, distribute, pledge, assign, or otherwise transfer or encumber rights to the Services; (d) use the Services for the benefit of a third party; (e) remove or otherwise alter any proprietary notices or labels from the Services or any portion thereof; (f) use the Services to build an application or product that is competitive with any Company product or service (including the Services); (g) interfere or attempt to interfere with the proper working of the Services or any activities conducted on the Services; or (h) bypass any measures Company may use to prevent or restrict access to the Services (or other accounts, computer systems or networks connected to the Services). Customer is responsible for all of Customer’s activity in connection with the Services, including but not limited to uploading Customer Data (as defined below) onto the Services. Customer is responsible for the use of the Services by any person to whom Customer has given access to the Services. Customer (i) shall use the Services in compliance with all applicable local, state, national and foreign laws, treaties and regulations in connection with Customer’s use of the Services (including those related to data privacy, international communications, export laws and the transmission of technical or personal data laws), and (ii) shall not use the Services in a manner that violates any third-party intellectual property, contractual or other proprietary rights.
8. Customer Data.
For purposes of this Agreement, “Customer Data” shall mean any data, information, document or other material provided, uploaded, or submitted by Customer to the Services in the course of using the Services. Customer shall retain all right, title and interest in and to the Customer Data, including all intellectual property rights therein. Customer, not Company, shall have sole responsibility for the accuracy, quality, integrity, legality, reliability, appropriateness, and intellectual property ownership or right to use all Customer Data. Customer represents and warrants that: (a) it has all rights necessary to provide the Customer Data to Company as contemplated hereunder, in each case without any infringement, violation or misappropriation of any third-party rights (including, without limitation, intellectual property rights and rights of privacy) and in compliance with all applicable laws; and (b) to the extent Customer Data includes any personal information relating to any third party, it has provided all notices and obtained all consents, rights and any necessary permissions to provide such data to Company. Customer hereby grants Company a worldwide, non-exclusive, non-transferable (except as permitted under this Agreement), royalty-free license during the Order Form Term to use and modify (but not disclose) Customer Data for the purposes of (i) providing the Services to Customer and (ii) generating De-Identified Data (as defined below). Customer further grants Company a worldwide, non-exclusive, perpetual, irrevocable, royalty-free, fully paid, sublicensable and transferable license to freely use, retain and make available De-Identified Data for Company’s business purposes, including for improving, testing, and operating the Services. “De-Identified Data” means data submitted to, collected by, or generated by Company in connection with Customer’s use of the Services as well as any other data, information, documents or other materials disclosed or made available by or on behalf of Customer, but only to the extent that such data is in aggregate or de-identified form which cannot reasonably identify Customer. Company owns all rights, title and interest in and to De-Identified Data.
9. Artificial Intelligence.
Customer acknowledges and agrees that: (a) the Services incorporate artificial intelligence and machine learning technologies and are designed to generate automated responses and outputs based on Customer Data; (b) artificial intelligence and machine learning are rapidly evolving fields of study, and, due to the nature thereof, the Services may in some situations produce results that contain errors, misstatements, and that may be incomplete, incorrect or inaccurate; (c) Customer must verify the accuracy and appropriateness of any results generated from the Services before relying on them; (d) use of the Services without verifying accuracy with a qualified human could cause harm, including but not limited to legal, financial, and physical harm; (e) the Services are not intended to provide legal, financial, medical or other professional advice and may not be used as a substitute for professional advice or judgment; and (f) the Services may generate results that are similar or identical to results generated for other customers who provide similar inputs, and Customer has no rights to any such results generated through the Services by or for other customers of Company, regardless of any level of similarity to information provided to Customer. Company cannot control, and has no duty to take any action, regarding how Customer may interpret, rely on, or use any results from the Services or what actions Customer may take in connection with any results generated through the Services. Customer hereby releases Company from all liability arising from or related to Customer’s use or reliance on the Services. Customer hereby grants Company a worldwide, non-exclusive, perpetual, irrevocable, royalty-free, fully paid, sublicensable and transferable license to use any results generated through the Services in connection with the provision, operation, and improvement of the Services and Company’s (and Company’s successors’ and assigns’) businesses, including after Customer’s termination of the Services.
10. Confidentiality.
For purposes of this Agreement, “Confidential Information” shall mean to the extent previously, presently or subsequently disclosed by or for either party (the “Disclosing Party”) to the other party (the “Receiving Party”) all financial, business, legal and technical information of the Disclosing Party or any of its affiliates, suppliers, customers and employees (including information about research, development, operations, marketing, transactions, regulatory affairs, discoveries, inventions, methods, processes, articles, materials, algorithms, software, specifications, designs, drawings, data, strategies, plans, prospects, know-how and ideas, whether tangible or intangible, and including all copies, abstracts, summaries, analyses and other derivatives thereof), that is marked or otherwise identified as proprietary or confidential at the time of disclosure, or that by its nature would be understood by a reasonable person to be proprietary or confidential. Confidential Information shall not include any information that (a) was rightfully known to the Receiving Party without restriction before receipt from the Disclosing Party, (b) is rightfully disclosed to the Receiving Party without restriction by a third party, (c) is or becomes generally known to the public without violation of this Agreement by the Receiving Party, or (d) is independently developed by the Receiving Party or its employees without access to or reliance on such information. Each party shall treat as confidential all Confidential Information of the other party, shall not use such Confidential Information except as set forth in this Agreement, and shall not disclose such Confidential Information to any third party except as expressly permitted herein without the Disclosing Party’s written consent. The Receiving Party shall use at least the same degree of care which it uses to prevent the disclosure of its own confidential information of like importance to prevent the disclosure of the Disclosing Party’s Confidential Information, but in no event less than reasonable care. The Receiving Party shall promptly notify the Disclosing Party of any actual or suspected misuse or unauthorized disclosure of any of the Confidential Information. In the event of any termination or expiration of this Agreement, the Receiving Party will either return or, at the Disclosing Party’s request, destroy the Confidential Information of the Disclosing Party; provided, however, that the Receiving Party may retain copies of the Disclosing Party’s Confidential Information for routine backup and archival purposes subject to the confidentiality obligations set forth herein. The Receiving Party may make disclosures required by law or court order provided that, if permissible pursuant to applicable law, the Receiving Party shall promptly notify the Disclosing Party of any disclosure requirement and provide reasonable assistance to the Disclosing Party in the Disclosing Party’s efforts to prevent and/or limit the disclosure.
11. Third-Party Services.
Customer acknowledges and agrees that the Services may operate on, with or using application programming interfaces (APIs) and/or other services operated or provided by third parties (“Third-Party Services”), including without limitation through integrations or connectors to such Third-Party Services that are provided by Company. Company is not responsible for the operation of any Third-Party Services nor the availability or operation of the Services to the extent such availability and operation is dependent upon Third-Party Services. Customer is solely responsible for procuring any and all rights necessary for it to access Third-Party Services (including any Customer Data or other information relating thereto) and for complying with any applicable terms or conditions thereof. Company does not make any representations or warranties with respect to Third-Party Services or any third-party providers. Any exchange of data or other interaction between Customer and a third-party provider is solely between Customer and such third-party provider and is governed by such third-party’s terms and conditions. In connection with the Services and at the direction of Customer, Company may act as a limited authorized agent of Customer through Third-Party Services to retrieve or access Customer Data using API credentials or other account credentials provided by Customer. Company acts solely on behalf of Customer and not as an agent of, or on behalf of, any such third-party provider. Customer represents and warrants that it is authorized to provide such credentials to Company and that doing so does not violate any third-party terms or applicable law. Company’s access to Customer Data via such credentials shall be solely for the purpose of providing the Services. Customer shall indemnify, defend, and hold harmless Company and its officers, directors, consultants, employees, agents, successors and assigns from and against any and all claims, liabilities, damages, costs and expenses (including reasonable attorneys’ fees) arising out of or relating to (a) Company’s access to or retrieval of Customer Data through Third-Party Services at the direction of Customer using credentials provided by Customer, or (b) Customer’s authorization of such access or failure to have the rights, licenses, permissions, or consents necessary for Company to access such Third-Party Services or Customer Data on Customer’s behalf.
12. Data Privacy Addendum.
The U.S. Privacy Law Addendum provided below (the “Addendum”) is hereby incorporated by reference and shall apply to the extent Company processes Personal Data (as such terms are defined in the Addendum) in accordance with the Addendum.
13. Term; Termination
a. Term.
This Agreement will commence upon the effective date of the first Order Form, and, unless earlier terminated in accordance herewith, will last until the expiration of all Order Form Terms. For each Order Form, unless otherwise specified therein, the Order Form Term shall begin as of the effective date set forth on such Order Form, and unless earlier terminated as set forth herein, shall continue for the initial term specified on such Order Form (the “Initial Term”). Following the Initial Term, the Order Form shall automatically renew for additional successive periods as set forth in the applicable Order Form (each, a “Renewal Term”) unless either party notifies the other party of such party’s intent not to renew no later than sixty (60) days prior to the expiration of the Initial Term or then-current Renewal Term, as applicable. The Initial Term and each Renewal Term (if any) are collectively referred to herein as the “Order Form Term”.
b. Termination.
Either party may terminate this Agreement, effective on written notice to the other party, if the other party materially breaches this Agreement, and such breach remains uncured thirty (30) days after the non-breaching party provides the breaching party with written notice of such breach.
c. Suspension.
Without limiting the foregoing, Company may suspend or limit Customer’s access to or use of the Services if (a) Customer’s account is more than thirty (30) days past due, or (b) Customer’s use of the Services results in (or is reasonably likely to result in) damage to or material degradation of the Services, which interferes with Company’s ability to provide access to the Services to other customers; provided that in the case of subsection (b): (i) Company shall use reasonable good faith efforts to work with Customer to resolve or mitigate the damage or degradation in order to resolve the issue without resorting to suspension or limitation; (ii) prior to any such suspension or limitation, Company shall use commercially reasonable efforts to provide notice to Customer describing the nature of the damage or degradation; and (iii) Company shall reinstate Customer’s use of or access to the Services, as applicable, if Customer remediates the issue promptly following receipt of such notice.
d. Effects of Termination; Survival.
Upon any expiration or termination of any Order Form or this Agreement, all corresponding rights, obligations and licenses of the parties shall cease, except that (i) all obligations that accrued prior to the effective date of termination (including without limitation, all payment obligations) shall survive; (ii) Customer shall immediately cease use of the Services; and (iii) all provisions of this Agreement which by their nature should survive termination shall survive, including, without limitation, accrued payment obligations, warranty disclaimers, confidentiality, indemnity and limitations of liability.
14. Indemnification.
a.
Customer will indemnify and hold Company, its officers, directors, consultants, employees, agents, successors and assigns harmless from any and all amounts actually paid to any third party in connection with claims, liabilities, damages, costs and expenses (including, but not limited to, reasonable attorneys’ fees) relating to any claim caused by (i) modifications to the Services made by a party other than Company or its agents, or otherwise not approved by Company or its agents or allowed under this Agreement; (ii) the combination, operation or use of the Services with equipment, devices, data (including Customer Data) or software not provided or approved by Company; (iii) Customer’s failure to use updated or modified versions of the Services provided by Company to avoid a claim; (iv) Customer’s use of the Services other than in accordance with this Agreement; (v) Customer’s breach of any representation, warranty or obligation under this Agreement; and (vi) any Customer Data or any other data, information, documents or other materials disclosed or made available by or on behalf of Customer for use in connection with the Services (including any claim that such Customer Data or other materials violates any law, rule, or regulation or infringe or violate the rights of a third party). If Company receives any notice or claim that Customer Data may violate any law, rule, or regulation or infringe or violate the rights of a third party, Company may (but is not required to) suspend the Services hereunder with respect to such Customer Data.
b.
Any claim for indemnification hereunder is contingent upon Company providing (i) prompt written notice of the liability, (ii) reasonable cooperation, information, and assistance in connection therewith, and (iii) Customer with the sole control and authority to defend, settle or compromise such liability, provided that the Company may participate in such defense at its sole cost. Customer will not make any settlement that requires a materially adverse act or admission by Company without Company’s written consent (such consent not to be unreasonably delayed, conditioned or withheld).
15. Warranties and Disclaimers.
a. Mutual.
Each party represents and warrants that (i) it is duly organized and validly existing under the laws of the jurisdiction in which it is organized, (ii) it has full power and authority, and has obtained all approvals, permissions and consents necessary, to enter into this Agreement and to perform its obligations hereunder, (iii) this Agreement is legally binding upon it, and (iv) the execution, delivery and performance of this Agreement does not and will not conflict with any agreement to which it is a party.
b. Disclaimers.
EXCEPT AS EXPRESSLY SET FORTH HEREIN, THE SERVICES ARE PROVIDED “AS IS” AND “AS AVAILABLE” AND ARE WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF TITLE, NON-INFRINGEMENT, MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE, AND ANY WARRANTIES IMPLIED BY ANY COURSE OF PERFORMANCE, USAGE OF TRADE, OR COURSE OF DEALING, ALL OF WHICH ARE EXPRESSLY DISCLAIMED. COMPANY AND ITS LICENSORS DO NOT REPRESENT OR WARRANT THAT (A) THE USE OF THE SERVICES WILL BE SECURE, TIMELY, UNINTERRUPTED OR ERROR-FREE, (B) THE SERVICES OR RESULTS GENERATED FROM THE SERVICES (OR ANY PORTION THEREOF) WILL MEET REQUIREMENTS OR EXPECTATIONS, (C) THE SERVICES, THE RESULTS GENERATED FROM THE SERVICES, OR THE SERVER(S) THAT MAKE THE SERVICES AVAILABLE ARE FREE OF VIRUSES OR OTHER HARMFUL COMPONENTS, OR (D) THAT THE SERVICES OR THE RESULTS GENERATED FROM THE SERVICES (OR ANY PORTION THEREOF, INCLUDING ANY INFORMATION OR CONTENT ACCESSED ON CONNECTION THEREWITH) ARE ACCURATE, COMPLETE, ERROR-FREE, OR UP-TO-DATE. WITHOUT LIMITING THE FOREGOING, COMPANY WILL NOT BE RESPONSIBLE FOR ANY ACTIONS TAKEN BASED ON THE RESULTS GENERATED FROM THE SERVICES. CUSTOMER ASSUMES ALL RISKS ASSOCIATED WITH ITS USE OF SUCH RESULTS.
16. Limitation of Liability.
EXCEPT FOR THE PARTIES’ INDEMNIFICATION OBLIGATIONS UNDER SECTION 14, BREACHES OF SECTIONS 7 (RESTRICTIONS) OR 10 (CONFIDENTIALITY), GROSS NEGLIGENCE AND WILLFUL MISCONDUCT, IN NO EVENT SHALL EITHER PARTY, OR ITS OFFICERS, DIRECTORS, EMPLOYEES, AGENTS, PARTNERS, SUPPLIERS OR LICENSORS, BE LIABLE UNDER CONTRACT, TORT, STRICT LIABILITY, NEGLIGENCE OR ANY OTHER LEGAL OR EQUITABLE THEORY WITH RESPECT TO THE SUBJECT MATTER OF THIS AGREEMENT (A) FOR ANY LOST PROFITS, DATA LOSS, COST OF PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES, OR SPECIAL, INDIRECT, INCIDENTAL, PUNITIVE, OR CONSEQUENTIAL DAMAGES OF ANY KIND WHATSOEVER, SUBSTITUTE GOODS OR SERVICES (HOWEVER ARISING), (B) FOR ANY BUGS, VIRUSES, TROJAN HORSES, OR THE LIKE (REGARDLESS OF THE SOURCE OF ORIGINATION), OR (C) FOR ANY DIRECT DAMAGES IN EXCESS OF (IN THE AGGREGATE) THE FEES PAID (OR PAYABLE) BY CUSTOMER TO COMPANY HEREUNDER IN THE TWELVE (12) MONTHS PRIOR TO THE EVENT GIVING RISE TO A CLAIM HEREUNDER.
17. Publicity.
Customer hereby consents to inclusion of its name and logo in Company’s public-facing client lists and marketing materials that may be published as part of its marketing and promotional efforts, including on Company’s website. Customer also agrees that Company may (but is under no obligation to) issue press releases and publish testimonials and case studies with statements attributed to a named employee of Customer.
18. Miscellaneous.
This Agreement (including all Order Forms) represents the entire agreement between Customer and Company with respect to the subject matter hereof, and supersedes all prior or contemporaneous communications and proposals (whether oral, written or electronic) between Customer and Company with respect thereto. In the event of any conflict between the terms of the MSA and the terms of an Order Form, the terms of the MSA shall control unless the Order Form states that a specific provision of the MSA will be superseded by a specific provision of the Order Form. The Agreement shall be governed by and construed in accordance with the laws of the state of California, excluding its conflicts of law rules, and the parties consent to exclusive jurisdiction and venue in the state and federal courts located in San Francisco County, California. Company reserves the right to modify the MSA (or any portion thereof) at any time in its sole discretion by posting a revised version on the Company website provided at Joymore.com or by notifying you by e-mail. The “Last Revised” above indicates when this MSA was last updated. If we make future revisions to the MSA, the updating of the date at the top of this MSA will serve as notice to you of the changes. It is Customer’s responsibility to check this MSA periodically for changes. Unless otherwise stated, the amended MSA will be effective immediately, and Customer’s continued access to or use of the Services after any modification becomes effective constitutes Customer’s acceptance of the modified Agreement. If Customer does not agree to any modification, Customer’s sole remedy is to discontinue use of the Services and terminate this Agreement in accordance with Section 13. Neither party may assign any of its rights or obligations hereunder without the other party’s consent; provided that (a) either party may assign all of its rights and obligations hereunder without such consent to a successor-in-interest in connection with a sale of all or substantially all of such party’s assets or stock, and (b) Company may utilize subcontractors in the performance of its obligations hereunder. No agency, partnership, joint venture, or employment relationship is created as a result of this Agreement and neither party has any authority of any kind to bind the other in any respect. In any action or proceeding to enforce rights under this Agreement, the prevailing party shall be entitled to recover costs and attorneys’ fees. Neither party will be liable for any failure or delay in performance (other than payment obligations) to the extent caused by events beyond its reasonable control that could not have been avoided through reasonable business continuity planning, provided that the affected party promptly notifies the other party, uses commercially reasonable efforts to mitigate the effects and resume performance, and, notwithstanding the foregoing, Customer’s payment obligations remain unaffected. If any provision of this Agreement is held to be unenforceable for any reason, such provision shall be reformed only to the extent necessary to make it enforceable. The failure of either party to act with respect to a breach of this Agreement by the other party shall not constitute a waiver and shall not limit such party’s rights with respect to such breach or any subsequent breaches.
U.S. Privacy Law Addendum
This United States Privacy Law Addendum (the “Addendum”) forms part of and is incorporated into the Master Services Agreement (the “Agreement”) entered into by and between the customer identified in the Agreement (“Customer”) and Joymore LLC (“Company”) (and, together, the “Parties”). Any capitalized terms that are used but not defined herein shall have the definitions set forth in the Agreement. Where there is a conflict between the Agreement and this Addendum, this Addendum will control.
1. Definitions.
a. “Authorized Subprocessor”
means a third-party entity engaged by Company to process Personal Data in order to provide the Services and that has been approved by Customer in accordance with Section 6.
b. “Company Account Data”
means personal data that relates to Company’s relationship with Customer, including the names or contact information of individuals authorized by Customer to access Customer’s account and billing information of individuals that Customer has associated with its account.
c. “Company Usage Data”
means Service usage data collected and processed by Company in connection with the provision of the Services, including without limitation data used to identify the source and destination of a communication, activity logs, and similar data.
d. “Consumer”
means a natural person whose Personal Data is protected by Privacy Laws.
e. “Consumer Request”
means a request from a Consumer to exercise their rights over Personal Data afforded pursuant to Privacy Laws.
f. “Controller”
means the natural or legal person that, alone or jointly with others, determines the purpose and means of processing Personal Data. “Controller” includes the term “Business” or equivalent term under Privacy Laws.
g. “Personal Data”
means any information provided to Company by or on behalf of Customer in connection with the Services that relates to an identified or identifiable Consumer and constitutes “personal data,” “personal information,” or equivalent term under Privacy Laws.
h. “Privacy Laws”
means any applicable laws and regulations in any relevant jurisdiction relating to the processing of Personal Data. Privacy Laws includes but are not limited to, U.S. state comprehensive privacy laws, such as the California Consumer Privacy Act, as amended by the California Privacy Rights Act of 2020 (the “CCPA”), in each case as updated, amended or replaced from time to time. The terms “affiliates,” “business purpose,” “Controller,” “Personal Data Breach,” “Processor,” “process” or “processing,” “sell,” or “share,” shall have the meaning set forth for that or any equivalent term under Privacy Laws. For the avoidance of doubt, the terms “Controller” and “Processor” include “Business” and “Service Provider,” respectively, as defined in the CCPA.
2. Description of Processing.
a. Nature and Purpose of Processing:
Except with respect to Company Account Data and Company Usage Data, Company shall process Personal Data provided by Customer under the Agreement as necessary to provide the Services under the Agreement, for the purposes specified in the Agreement and this Addendum, and in accordance with Customer’s instructions as set forth in this Addendum. Such purposes shall include, without limitation, access to the Company’s cloud-based contract intelligence platform designed for real estate brokerages.
b. Duration of Processing:
Company shall process Personal Data provided by Customer as long as required (i) to provide the Services to Customer under the Agreement, or (ii) by applicable law or regulation.
c. Categories of Consumers:
Company may process Personal Data relating to the following categories of Consumers: (i) Customer’s personnel, including any brokers, agents, and representatives, and (ii) individuals whose Personal Data is contained in contracts, agreements, transaction documents, and other records submitted by or on behalf of Customer to the Services.
d. Categories of Personal Data:
Company may process the following categories of Personal Data: name, address, signature, contact information (e.g., email address, phone number), professional information (occupation, title), and any other Personal Data submitted to the Services by or on behalf of Customer in accordance with the Agreement and this Addendum.
3. Customer’s Obligations.
Customer shall, in its use of the Services, at all times process Personal Data, and provide instructions for the processing of Personal Data, in compliance with Privacy Laws. Customer shall ensure that the processing of Personal Data in accordance with Customer’s instructions will not cause Company to be in breach of the Privacy Laws. Customer is solely responsible for the accuracy, quality, and legality of (i) the Personal Data provided to Company by or on behalf of Customer, (ii) the means by which Customer acquired any such Personal Data, and (iii) the instructions it provides to Company regarding the processing of such Personal Data. Customer shall not provide or make available to Company any Personal Data in violation of the Agreement or otherwise inappropriate for the nature of the Services, and shall indemnify Company from all claims and losses in connection therewith.
4. Use of Personal Data.
Company shall not: (i) sell or share Personal Data; (ii) retain, use, or disclose Personal Data outside of Company’s direct business relationship with Customer or for any purpose other than to perform the Services and other obligations under the Agreement, which constitutes a business purpose under the Privacy Laws, except as otherwise permitted in the Agreement or by Privacy Laws; and (iii) combine Personal Data received from, or on behalf of, Customer with Personal Data that it receives from, or on behalf of, another party or person, except as necessary to provide the Services or as otherwise permitted under Privacy Laws.
5. Audit.
To the extent required by applicable Privacy Laws, and upon Customer’s written request at reasonable intervals, and subject to reasonable confidentiality controls, Company shall either (i) make available for Customer’s review copies of certifications or reports demonstrating Company’s compliance with prevailing data security standards applicable to the processing of Personal Data provided by Customer under the Agreement, or (ii) if the provision of reports or certifications pursuant to (i) is not reasonably sufficient under the applicable Privacy Laws, allow Customer or Customer’s independent third party representative to conduct an audit or assessment of Company’s policies and technical and organizational measures using an appropriate and accepted control standard or framework and assessment procedure for such assessments, that (a) Customer provides reasonable prior written notice of any such request for an audit and such inspection shall not be unreasonably disruptive to Company’s business; (b) such audit shall only be performed during business hours and occur no more than once per calendar year; and (c) such audit shall be restricted to data relevant to Customer. Customer shall be responsible for the costs of any such audits or inspections, including without limitation a reimbursement to Company for any time expended for on-site audits. To the extent permitted under Privacy Laws, if Customer determines that Company is processing Personal Data in an unauthorized manner, Customer may, taking into account the nature of Company’s processing and the nature of the Personal Data processed by Company on behalf of Customer, and upon providing prior written notice, take commercially reasonable and appropriate steps to stop and remediate such unauthorized processing.
6. Authorized Subprocessors.
a.
Company may or may not include a list of its current Authorized Subprocessors (the “List”) in the Authorized Subprocessors section at the bottom of this Addendum. Customer should request the List from Company if needed. Such List may be updated by Company from time to time. Company may provide a mechanism to subscribe to notifications of new subprocessors and Customer agrees to subscribe to such notifications where available. At least ten (10) days before enabling any third party other than existing Authorized Subprocessors to access or participate in the processing of Personal Data, Company will add such third party to the List and notify Customer via email. Customer may object to such an engagement by informing Company within ten (10) days of receipt of the aforementioned notice to Customer, provided such objection is in writing and based on reasonable grounds relating to data protection. If Customer does not object during this period, that third party will be deemed an Authorized Subprocessor. Customer acknowledges that certain subprocessors are essential to providing the Services and that objecting to the use of a subprocessor may prevent Company from offering the Services to Customer.
b.
If Customer reasonably objects to an engagement in accordance with Section 6(a), and Company cannot provide a commercially reasonable alternative within a reasonable period of time, Customer may discontinue the use of the affected Service by providing written notice to Company. Discontinuation shall not relieve Customer of any fees owed to Company under the Agreement.
c.
Company will enter into a written agreement with the Authorized Subprocessor imposing on the Authorized Subprocessor data protection obligations comparable to those imposed on Company under this Addendum with respect to the protection of Personal Data. Company will be responsible for its Authorized Subprocessors to the extent required by Privacy Laws.
7. Confidentiality and Security of Personal Data.
a.
Company shall ensure that any person it authorizes to process Personal Data has agreed to protect Personal Data in accordance with Company’s confidentiality obligations in the Agreement. Customer agrees that Company may disclose Personal Data to its advisers, auditors or other third parties as reasonably required in connection with the performance of its obligations under this Addendum, the Agreement, or the provision of Services to Customer.
b.
Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Company shall maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk of processing Personal Data.
8. Personal Data Breach.
a.
In the event of a Personal Data Breach, Company shall, without undue delay, inform Customer of the Personal Data Breach and take such steps as Company in its sole discretion deems necessary and reasonable to remediate such Personal Data Breach, to the extent that remediation is within Company’s reasonable control.
b.
In the event of a Personal Data Breach, Company shall, taking into account the nature of the processing and the information available to Company, provide Customer with reasonable cooperation and assistance necessary for Customer to comply with its obligations under Privacy Laws with respect to notifying (i) the relevant regulatory agency and (ii) Consumers affected by such Personal Data Breach without undue delay.
c.
The obligations described in Sections 8(a) and 8(b) shall not apply in the event that a Personal Data Breach results from the actions or omissions of Customer. Company’s obligation to report or respond to a Personal Data Breach under Sections 8(a) and 8(b) will not be construed as an acknowledgement by Company of any fault or liability with respect to the Personal Data Breach.
9. Data Protection Assessments.
Taking into account the nature of Company’s processing and the information available to Company, Company shall reasonably cooperate with Customer to conduct any data protection or privacy impact assessments as required by Privacy Laws, including by providing Customer with information and documents necessary for such assessments that Customer cannot otherwise obtain without Company’s assistance. Notwithstanding the foregoing, Customer and Company each remain responsible only for the measures respectively allocated to them under Privacy Laws pertaining to any such assessment.
10. Consumer Request.
Company shall, to the extent permitted by Privacy Laws, notify Customer upon receipt of a Consumer Request. If Company receives a Consumer Request in relation to Personal Data, Company will advise the Consumer to submit their request to Customer and Customer will be responsible for responding to such request, including, where necessary, by using the functionality of the Services. Customer is solely responsible for ensuring that Consumer Requests are communicated to Company, and, if applicable, for ensuring that a record of consent to processing is maintained with respect to each Consumer.
11. Return or Destruction of Personal Data.
Upon the termination or expiration of the Agreement, at Customer’s choice, Company shall return or delete Personal Data, unless further storage of such Personal Data is required or authorized by applicable law. If return or destruction is impracticable or prohibited by law, rule or regulation, Company shall take measures to block such Personal Data from any further processing (except to the extent necessary for its continued hosting or processing required by law, rule or regulation) and shall continue to appropriately protect the Personal Data remaining in its possession, custody, or control.
12. Company’s Role as a Controller.
The parties acknowledge and agree that with respect to Company Account Data and Company Usage Data, Company is an independent controller, not a joint controller with Customer. Company will process Company Account Data and Company Usage Data as a controller (i) to manage the relationship with Customer; (ii) to carry out Company’s core business operations, such as accounting, audits, tax preparation and filing and compliance purposes; (iii) to monitor, investigate, prevent and detect fraud, security incidents and other misuse of the Services, and to prevent harm to Customer; (iv) for identity verification purposes; (v) to comply with legal or regulatory obligations applicable to the processing and retention of Personal Data to which Company is subject; and (vi) as otherwise permitted under Privacy Laws and in accordance with this Addendum and the Agreement. Company may also process Company Usage Data as a controller to provide, optimize, and maintain the Services, to the extent permitted by Privacy Laws. Any processing by Company as a controller shall be in accordance with Company’s privacy policy.
Authorized Subprocessors
Company may or may not include its current Authorized Subprocessors here. Customer should request a current list of Authorized Subprocessors from Company if needed.