Peregrin
  • Features
  • Pricing
  • About
  • Blog
  • Sign Up
  • Login
Legal

General Terms and Conditions

eParts Services LLC · Posted July 23, 2026

1. Definitions. Definitions for all capitalized terms are found in Exhibit A, hereto.

2. Services.

2.1. Availability of Services. Subject to and conditioned on Subscriber’s (which shall include its Affiliates) and its Named Users’ compliance with the terms and conditions of this Agreement including the payment of Subscription Fees, during the Term, Company shall use commercially reasonable efforts to provide access to the Software, including to host, manage, operate and maintain the Company Materials for remote electronic access and use by Subscriber and its Named Users (“Subscription Services”). The Subscription Services shall include both hosted Software and optionally related downloadable mobile or remote software for installation and use by Named Users (“End User Software”).

2.2. Service and System Control. Except as otherwise expressly provided in this Agreement, as between the parties:

2.2.1. Company has and will retain control over the operation, provision, maintenance and management of the Subscription Services, including the: (i) selection, deployment, modification and replacement of the End User Software; and (ii) performance of Support Services, upgrades, corrections and repairs.

2.2.2. Subscriber has and will retain sole control over the operation, maintenance and management of, and all access to and use of its own Subscriber Systems, and sole responsibility for all access to and use of the Services and End User Software by any Named User, including any: (i) information, instructions or materials provided by any of them pursuant to the Services; (ii) results obtained from any use of the Services; and (iii) conclusions, decisions or actions based on such use.

2.3. Artificial Intelligence Services. Company may include the use of artificial intelligence services or data processing as part of its delivery of Services (“AI”). Any Service which includes the use of AI will be clearly identified. Use of the Services by Subscriber or Named Users will not require the use of AI, which at all times shall be optional. Additional fees may be required for the use of AI by Subscriber, as set forth in the relevant Software Schedule or Statement of Work. To the extent that Subscriber elects to utilize AI-based Services, Subscriber shall do so at its own risk. AI-generated output may contain errors in content or accuracy and are only intended to assist the human end user. Subscriber is solely responsible for: (i) evaluating any AI-generated output carefully for accuracy, completeness, and other factors relevant to use; (ii) deciding whether, how, and to what extent to use the output; and (iii) decisions, actions, and omissions in reliance or based on the output.

2.4. Changes. Company reserves the right, in its sole discretion, to make any changes to the Subscription Services that it deems necessary or useful, but shall give Subscriber prior written notice of any such changes.

2.5. Suspension or Termination of Subscription Services. Company may, directly or indirectly, and by use of a Disabling Device or any other lawful means, suspend, terminate or otherwise deny Subscriber’s, any Named User’s or any other access to or use of all or any part of the Subscription Services, without incurring any resulting obligation or liability, if: (a) Company receives a judicial or other governmental demand or order, subpoena or law enforcement request that expressly or by reasonable implication requires Company to do so; or (b) Company believes, in its sole discretion, that: (i) Subscriber or any Named User has failed to comply with, any material term of this Agreement, or accessed or used the Services beyond the scope of the rights granted or for a purpose not authorized under this Agreement or in any manner that does not comply with any material instruction or requirement; (ii) Subscriber or any Named User is, has been, or is likely to be involved in any fraudulent, misleading or unlawful activities; or (iii) this Agreement expires or is terminated. This Section does not limit any of Company’s or Subscriber’s rights or remedies, whether at law, in equity or under this Agreement.

3. Authorization and Subscriber Restrictions.

3.1. Authorization. Subject to and conditioned on Subscriber’s payment of the Subscription Fees and compliance and performance in accordance with all other terms and conditions of this Agreement, Company hereby authorizes Subscriber to access and use, during the Term, the Subscription Services as Company may supply or make available to Subscriber solely for the use by and through Named Users. This authorization is non-exclusive and non-transferable, however, Subscriber may substitute different natural persons as Named Users.

3.2. Reservation of Rights. Nothing in this Agreement grants any right, title or interest in or to (including any license under) any Intellectual Property Rights in or relating to, the Services, Company Materials or End User Software, whether expressly, by implication, estoppel or otherwise. All right, title and interest in and to the Services, the Company Materials and the End User Software, are and will remain with Company.

3.3. Authorization Limitations and Restrictions. Subscriber shall not, and shall not permit any other person or entity to, access or use the Services except as expressly permitted by this Agreement. For purposes of clarity and without limiting the generality of the foregoing, Subscriber shall not, except as this Agreement expressly permits: copy, modify or create derivative works or improvements of the Services; rent, lease, lend, sell, sublicense, assign, distribute, publish, transfer or otherwise make available any Services to any other person or entity, including on or in connection with the internet or any time-sharing, service bureau, software as a service, cloud or other technology or service; reverse engineer, disassemble, decompile, decode, adapt or otherwise attempt to derive or gain access to the source code of the Services, in whole or in part; bypass or breach any security device or protection used by the Services or access or use the Services other than by a Named User through the use of his or her own then valid Access Credentials; input, upload, transmit or otherwise provide to or through the Services, any information or materials that are unlawful or injurious, or contain, transmit or activate any Harmful Code; damage, destroy, disrupt, disable, impair, interfere with or otherwise impede or harm in any manner the Services, in whole or in part; remove, delete, alter or obscure any trademarks, warranties or disclaimers, or any copyright, trademark, patent or other intellectual property or proprietary rights notices from any Services, including any copy thereof; access or use the Services in any manner or for any purpose that infringes, misappropriates or otherwise violates any Intellectual Property Right or other right of any third party, or that violates any applicable Law; access or use the Services for purposes of competitive analysis of the Services or, the development, provision or use of a competing software service or product or any other purpose that is to the Company’s detriment or commercial disadvantage; or otherwise access or use the Services beyond the scope of the authorization granted under this Agreement.

4. Subscriber Systems. Subscriber shall at all times maintain its own systems for accessing the Services and utilizing the End User Software. Company has no responsibility for the continued operation of such systems, or access to the Subscription Services or End User Software.

5. Implementation and Professional Services.

5.1. Implementation Services. Company will provide the Implementation Services upon the payment of all applicable Implementation Fees. The description, charges, and other terms applicable to the individual Implementation Services are set forth in the applicable Statement(s) of Work. Subscriber may order additional Implementation Services or other modifications of the Services through the execution of additional or modified Statements of Work.

5.2. Professional Services. Company will provide the Professional Services upon the payment of all applicable Professional Services Fees. The description, charges, and other terms applicable to the individual Professional Services are set forth in any applicable Statement(s) of Work.

5.3. Nothing in this Agreement shall be interpreted as a guarantee or absolute obligation of Subscriber to purchase any minimum or specific quantity, volume or value of Implementation Services or Professional Services from Company unless such quantities, volumes or values are expressly set forth in a Statement of Work. Company will not be bound by any purchase order terms or forms of Subscriber. Company will exercise commercially reasonable efforts to conform its services to any applicable budget identified in the Software Schedule or a relevant Statement of Work.

5.4. Evaluation and Acceptance.

5.4.1. Evaluation and Testing. Subscriber shall have the obligation to evaluate and test all relevant Deliverables as provided by Company. Company shall provide all Deliverables to Subscriber for a period of fifteen (15) days for Subscriber to review and test such Deliverables to determine whether they conform to the Specifications, Documentation and any standards, codes or other requirements (“Evaluation Criteria”).

5.4.2. Rejection and Acceptance. If the Deliverables meet or exceed the Evaluation Criteria, then Subscriber shall be obligated to accept the Deliverables and notify Company, through its Subscriber Coordinators, of its acceptance in writing. If Subscriber fails to provide a notice of acceptance or written notice of a defect within the fifteen (15) day evaluation period, then the applicable Deliverables shall be deemed accepted by Subscriber. If Subscriber reasonably determines that the Deliverables fail to comply in any material respect to the Evaluation Criteria, then Subscriber must notify Company in writing of the same within the fifteen (15) day evaluation period. Upon receipt of such notice, Company shall thereafter correct any such identified defects at Company’s sole expense. If during the performance of a Statement of Work, a Deliverable is rejected, in full or in part, as a result of a failure or defect in a previously accepted Deliverable, then the fifteen (15) day evaluation period shall restart for such previously accepted Deliverable upon rejection of the most recently received Deliverable.

5.4.3. Merger of Deliverables. Upon acceptance by Subscriber, all Deliverables shall be merged and become a part of the Software, Services and/or Documentation as appropriate.

6. Service Level and Support.

6.1. Service Level. Subject to the terms and conditions of this Agreement, Company will use commercially reasonable efforts to make the Services available for Subscriber’s use 99.5% of each calendar month, based upon a 720 hour month, less scheduled downtime. Company makes no other representation or warranty of any kind with respect to availability of the Subscription Services, the use of the End User Software, the compatibility of the Subscription Services with any third party software or the compatibility of the End User Software. To the extent Company does not comply with the availability provision of this Section, upon request of Subscriber Company will offer a credit to Subscriber of ten (10%) percent of the following calendar month Subscription Fees invoice. Company has no other obligation to issue any credit for downtime of the Subscription Services or inoperability of the End User Software.

6.2. Support. Subject to payment of all Subscription Fees, Company will make the Support Services available during its then-current Business Hours. Such technical support shall include, but is not limited to, troubleshooting, problem diagnosis, release or system management, and recommendations for fully utilizing the Subscription Services in accordance with the Documentation. Subscriber will identify no more than two (2) Subscriber Coordinators for each Company Software product. Subscriber Coordinators shall report problems with the Services (each such report, a “Service Request”) as soon as practicable for entry into Company’s support tracking system. Subscriber Coordinators and staff will be provided with training sessions offered by Company to ensure that he or she is (a) knowledgeable about the operation of the Services and any administrative tools provided therefor, and (b) qualified to perform problem determination and remedial functions with respect to the Subscription Services. Such training sessions will be at mutually agreed upon rates. Subscriber will be solely responsible for all travel and other expenses incurred in connection with such training sessions and will be billed separately. Upon mutual agreement it will be determined if Subscriber Coordinators require additional training, Subscriber will promptly ensure that such Subscriber Coordinators receive such training at Subscriber’s expense.

6.3. Fixes. As part of Support Services, Company shall make commercially reasonable efforts to provide Fixes for Errors identified in a Service Request in accordance with the Response Time, Effort Level, and Escalation Path (as defined in the Service Levels) guidelines outlined below for the applicable Severity Levels (as defined in the Service Levels as identified in the chart attached hereto as Exhibit C (together, the “Service Levels”). Company’s obligations with respect to Service Levels are contingent upon Subscriber: (i) devoting an appropriate level of effort to resolving the Error as is required of Company, (ii) responding to requests made by Company within the applicable Response Time (including the timely provision of access to the Software), and (iii) assigning its most qualified personnel to help Company address the Error.

6.4. Exclusions. Company shall have no obligation to Subscriber to the extent any Subscription Services are adversely affected by:

i. use of the Subscription Services in combination with other software, equipment or communications networks that are not referenced in the Documentation or otherwise approved in writing by Company;

ii. any modification to the Subscriber Systems without appropriate notification to Company and appropriate testing;

iii. any modification to Subscriber’s third party software to the extent interoperable with the Subscription Services made without reasonable notice to Company;

iv. viruses or other malware introduced through no fault of Company;

v. use of the Subscription Services other than as permitted by Company; or

vi. Subscriber’s failure to perform Subscriber responsibilities in accordance with this Agreement.

6.5. Data Backup. Company will maintain Subscriber Data in compliance with the Company Security Addendum as set forth in Exhibit D, hereto. EXCEPT AS MAY BE CAUSED BY COMPANY’S NEGLIGENCE OR WILLFUL MISCONDUCT, COMPANY HAS NO OBLIGATION OR LIABILITY FOR ANY LOSS, ALTERATION, DESTRUCTION, DAMAGE, CORRUPTION OR RECOVERY OF SUBSCRIBER DATA OTHER THAN AS SET FORTH IN EXHIBIT D.

7. Fees; Payment Terms.

7.1. Fees. Subscriber shall pay Company the Fees set forth on the Software Schedule and/or the appropriate Statement of Work associated therewith.

7.2. Taxes. All Fees and other amounts payable by Subscriber under this Agreement are exclusive of taxes and similar assessments. Subscriber is responsible for all sales, use and excise taxes, and any other similar taxes, duties and charges of any kind imposed by any federal, state or local governmental or regulatory authority on any amounts payable by Subscriber hereunder, other than any taxes imposed on Company’s income.

7.3. Payments. Subscriber shall make all payments hereunder in US dollars. Unless otherwise stated in writing by Company, terms are Net 30 Days. Except as provided herein, Fees are non-refundable.

8. Intellectual Property Rights; Confidentiality and Data.

8.1. Services and Company Materials. All right, title and interest in and to the Services, End User Software, Anonymized Data and Company Materials, including all Intellectual Property Rights therein, are and will remain with Company. Subscriber has no right, license or authorization with respect to any of the Services, End User Software or Company Materials. All other rights in and to the Services, End User Software and Company Materials are expressly reserved by Company.

8.2. Subscriber Data. As between Subscriber and Company, Subscriber is and will remain the sole and exclusive owner of all right, title and interest in and to all Subscriber Data, including all Intellectual Property Rights relating thereto, subject to the rights and permissions granted in Section 8.3.

8.3. Consent to Use Subscriber Data. Subscriber hereby grants, for the Term, all such rights and permissions in or relating to Subscriber Data: (a) to Company and its affiliates as necessary or useful to perform the Services; and (b) to Company and its affiliates as are necessary or useful to enforce this Agreement and exercise and perform its rights and obligations hereunder. Company and its affiliates may use Subscriber Data to improve the Services and for internal statistical and benchmarking purposes. Subscriber further agrees and consents that Company and its affiliates may create de-identified/anonymized and/or aggregated data from the Subscriber Data which will contain no Confidential Information of Subscriber nor be attributable to Subscriber (“Anonymized Data”), which will be the sole property of Company.

8.4. Use of Anonymized Data. Anonymized Data and associated benchmarks may be published within the Services or in the form of other content which may show a summary of results for a certain category or question type. Anonymized Data may also be incorporated into AI-based systems, models and data structures for training as well as delivery of Company’s products and services, including without limitation, subscription services to third party subscribers.

8.5. Confidentiality. In connection with this Agreement each party (as the “Disclosing Party”) may disclose or make available Confidential Information to the other party (as the “Receiving Party”). Subject to the limitations of this Section, “Confidential Information” means information in any form or medium (whether oral, written, electronic or other) that the Disclosing Party considers confidential or proprietary, including information consisting of or relating to the Disclosing Party’s customer information or data, technology, trade secrets, know-how, business operations, plans, strategies, and pricing, and information with respect to which the Disclosing Party has contractual or other confidentiality obligations, in each case, whether or not marked, designated or otherwise identified as “confidential.” Without limiting the foregoing: all Services and Documentation are Confidential Information of Company and the financial terms of this Agreement are the Confidential Information of Company and Subscriber. Confidential Information does not include information that: (a) was rightfully known to the Receiving Party without restriction on use or disclosure prior to such information’s being disclosed or made available to the Receiving Party in connection with this Agreement; (b) was or becomes generally known by the public other than by the Receiving Party’s noncompliance with this Agreement; or (c) was or is received by the Receiving Party on a non-confidential basis from a third party that was not or is not, at the time of such receipt, under any obligation to maintain its confidentiality.

8.6. Limitations. As a condition to being provided with any disclosure of or access to Confidential Information, the Receiving Party shall: not access or use Confidential Information other than as necessary to exercise its rights or perform its obligations under and in accordance with this Agreement; and not disclose or permit access to Confidential Information; safeguard the Confidential Information from unauthorized use, access or disclosure using at least the degree of care it uses to protect its sensitive information and in no event less than a reasonable degree of care. If the Receiving Party is compelled by applicable Law or legal proceeding to disclose any Confidential Information then, to the extent permitted by applicable Law, the Receiving Party shall: (a) promptly, and prior to such disclosure, notify the Disclosing Party in writing of such requirement so that the Disclosing Party can seek a protective order or other remedy; and (b) provide reasonable assistance to the Disclosing Party in opposing such disclosure or seeking a protective order or other limitations on disclosure.

9. Term and Termination.

9.1. Term. The term of this Agreement commences as of the Effective Date and, unless terminated earlier pursuant to any of the Agreement’s express provisions, will continue in effect as set forth on the Software Schedule or the relevant Statement of Work (the “Term”). This Agreement and each Statement of Work shall automatically renew for successive terms equal in length to the shorter of (a) the then-expiring term of the applicable Statement of Work and (b) twelve (12) months, absent written notice of termination by Subscriber no less than thirty (30) days prior to the expiration date of the then-current term. Company may increase the Fees for any renewal term by providing written notice to Subscriber no less than forty-five (45) days prior to the commencement of such renewal term, provided that no such increase shall exceed nine percent (9%) of the Fees payable for the immediately preceding term.

9.2. Termination for Cause. In addition to any other express termination right set forth elsewhere in this Agreement or a Statement of Work, Company may terminate this Agreement, effective on written notice to Subscriber, if Subscriber fails to pay any undisputed amount when due hereunder, and such failure continues more than thirty (30) days after Company’s delivery of written notice thereof. Either party may terminate this Agreement or any Statement of Work, effective on written notice to the other party, if the other party materially breaches this Agreement, and such breach: (i) is incapable of cure; or (ii) being capable of cure, remains uncured thirty (30) days after the non-breaching party provides the breaching party with written notice of such breach; and either party may terminate this Agreement, effective immediately upon written notice to the other party, if the other party: (i) becomes insolvent or is generally unable to pay, or fails to pay, its debts as they become due; (ii) files or has filed against it, a petition for voluntary or involuntary bankruptcy or otherwise becomes subject, voluntarily or involuntarily, to any proceeding under any domestic or foreign bankruptcy or insolvency Law; (iii) makes or seeks to make a general assignment for the benefit of its creditors; or (iv) applies for or has appointed a receiver, trustee, custodian or similar agent appointed by order of any court of competent jurisdiction to take charge of or sell any material portion of its property or business.

9.3. Refund of Fees Upon Termination. If Subscriber is terminating this Agreement for cause as set forth in Section 9.2, Company shall refund any prepaid Fees calculated from the effective date of termination to the end of the then-current term. If Company terminates this Agreement for cause as set forth in Section 9.2, Subscriber remains liable for all unpaid fees that are payable for the entire subscription period and/or no refund of prepaid fees shall be allowed to Subscriber.

9.4. Effect of Expiration or Termination. Upon any expiration or termination of this Agreement, except as expressly otherwise provided in this Agreement: all rights, licenses, consents and authorizations granted by either party to the other hereunder will immediately terminate; Company shall immediately cease all use of any Subscriber Data or Subscriber’s Confidential Information and (i) return to Subscriber, or at Subscriber’s written request destroy, all documents and tangible materials containing, reflecting, incorporating or based on Subscriber Data or Subscriber’s Confidential Information; (ii) provide Subscriber with a flat file of Subscriber Data within a commercially reasonable period of time and (iii) permanently erase all Subscriber Data and Subscriber’s Confidential Information from all systems Company directly controls. Subscriber shall immediately cease all use of any Services or Company Materials and (i) return to Company, or at Company’s written request destroy, all documents and tangible materials containing, reflecting, incorporating or based on any Company Materials or Company’s Confidential Information; and (ii) permanently erase all Company Materials and Company’s Confidential Information from all systems Subscriber directly controls. Company may disable all Subscriber and Named User access to the Services and Company Materials.

10. Representations and Warranties.

10.1. Mutual Representations and Warranties. Each party represents and warrants to the other party that: it is duly organized, validly existing and in good standing as a corporation or other entity under the Laws of the jurisdiction of its incorporation or other organization; it has the full right, power and authority to enter into and perform its obligations and grant the rights, licenses, consents and authorizations it grants or is required to grant under this Agreement; the execution of this Agreement by its representative whose signature is set forth at the end of this Agreement has been duly authorized by all necessary corporate or organizational action of such party; and when executed and delivered by both parties, this Agreement will constitute the legal, valid and binding obligation of such party, enforceable against such party in accordance with its terms.

10.2. Additional Company Representations and Warranties. Company represents and warrants that the Services and End User Software will perform substantially in accordance with the Company Materials. Company further represents, warrants and covenants to Subscriber that when used by Subscriber in accordance with this Agreement, no Services or End User Software as delivered by Company does or will: infringe, misappropriate or otherwise violate any United States intellectual property right of any third party.

10.3. DISCLAIMER OF WARRANTIES. EXCEPT FOR THE EXPRESS WARRANTIES SET FORTH IN THIS SECTION, ALL SERVICES AND COMPANY MATERIALS ARE PROVIDED “AS IS” AND COMPANY HEREBY DISCLAIMS ALL WARRANTIES, WHETHER EXPRESS, IMPLIED, STATUTORY OR OTHER, AND COMPANY SPECIFICALLY DISCLAIMS ALL IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND ALL WARRANTIES ARISING FROM COURSE OF DEALING, USAGE OR TRADE PRACTICE. WITHOUT LIMITING THE FOREGOING, COMPANY MAKES NO WARRANTY OF ANY KIND THAT THE SERVICES OR COMPANY MATERIALS, OR ANY PRODUCTS OR RESULTS OF THE USE THEREOF, WILL MEET SUBSCRIBER’S OR ANY OTHER PERSON’S REQUIREMENTS, OPERATE WITHOUT INTERRUPTION, ACHIEVE ANY INTENDED RESULT, BE COMPATIBLE OR WORK WITH ANY SOFTWARE, SYSTEM OR OTHER SERVICES, OR BE SECURE, ACCURATE, COMPLETE, FREE OF HARMFUL CODE OR ERROR FREE.

11. Indemnifications.

11.1. Company Infringement Indemnification. Company shall indemnify, defend and hold harmless the Subscriber party and its officers, shareholders, and the directors, agents, and employees thereof (collectively, and alternatively with Company, as appropriate, the “Indemnified Parties” and individually, an “Indemnified Party”) from and against any and all Losses incurred by Subscriber arising out of or relating to any claim, suit, action or proceeding (each, an “Action”) by a third party that the Services, End User Software or Company Materials or Subscriber’s use of the Services, End User Software, or Company Materials (excluding Subscriber Data) in compliance with this Agreement infringes a U.S. Intellectual Property Right. The foregoing obligation does not apply to any Action or Losses arising out of or relating to any: access to or use of the Services, End User Software or Company Materials in combination with any hardware, system, software, network or other materials or service not provided or authorized in writing by Company; modification of the Services, End User Software or Company Materials; or failure to timely implement any modifications, upgrades, replacements or enhancements made available to Subscriber by or on behalf of Company.

11.2. Subscriber Infringement Indemnification. Subscriber shall indemnify, defend and hold harmless Company and the relevant Indemnified Parties from and against any and all Losses incurred by such indemnitee in connection with any Action by a third party that arises out of or relates to any: Subscriber Data or any other materials or information provided solely by or on behalf of Subscriber or any Named User; or breach of any of its representations, warranties, covenants or obligations under this Agreement. The foregoing obligation does not apply to any Action or Losses arising out of or relating to any Subscriber Data or any other materials or information developed by Subscriber or any Named User at the direction of Company

11.3. Mitigation. If any of the Services, End User Software or Company Materials are, or in Company’s opinion are likely to be, claimed to infringe, misappropriate or otherwise violate any third-party Intellectual Property Right, or if Subscriber’s or any Named User’s use of the Services, End User Software or Company Materials is enjoined or threatened to be enjoined, Company may, at its option and sole cost and expense: obtain the right for Subscriber to continue to use the Services and Company Materials as contemplated by this Agreement; modify or replace the Services, End User Software and/or Company Materials, in whole or in part, to avoid infringement and make the Services, End User Software and/or Company Materials (as so modified or replaced) non-infringing; or by written notice to Subscriber, terminate this Agreement and require Subscriber to immediately cease any use of the Services, End User Software and/or Company Materials.

11.4. General Indemnification. Each Party shall indemnify and hold harmless the other party and all relevant Indemnified Parties from and against all Losses resulting from any injury to person, life, or property or injury resulting in the death of any person or persons, arising out of or in connection with the performance of this Agreement or progress of the work to be done hereunder, including those alleged to be the result of the negligence of one or more Indemnified Parties. In the event one or more of the Indemnified Parties is made a party to any suit or litigation (whether or not the Indemnified Parties are the only parties alleged to be negligent) because of injury or damage or alleged injury or damage to person, life, or property or injury or alleged injury resulting in the death of any person or persons arising out of or in connection with the performance of this Agreement or progress of the work to be done hereunder, the indemnifying Party shall defend such action on behalf of the Indemnified Party or Parties by counsel chosen by the indemnifying Party, and shall pay all damages, costs, expenses, and attorneys' fees incurred in connection with such defense. If judgment shall be obtained, then the indemnifying Party shall pay and satisfy such judgement to the extent that the indemnifying Party is found liable. If a claim shall be allowed in any of such proceedings against any of the Indemnified Parties or a settlement is reached, the indemnifying Party shall pay and satisfy such claim, or settlement.

11.5. Indemnification Procedure. Each party shall promptly notify the other party in writing of any Action for which such party believes it is entitled to be indemnified. The party seeking indemnification shall cooperate with the other party at the indemnifying party’s sole cost and expense. The indemnifying party shall have the right to take control of the defense and investigation of such Action and shall employ counsel of its choice to handle and defend the same.

THIS SECTION SETS FORTH SUBSCRIBER’S SOLE REMEDIES AND COMPANY’S SOLE LIABILITY AND OBLIGATION FOR ANY ACTUAL, THREATENED OR ALLEGED CLAIMS THAT THIS AGREEMENT OR ANY SUBJECT MATTER HEREOF (INCLUDING THE SERVICES AND COMPANY MATERIALS) INFRINGES, MISAPPROPRIATES OR OTHERWISE VIOLATES ANY THIRD PARTY INTELLECTUAL PROPERTY RIGHT.

12. Limitations of Liability.

OTHER THAN AS SET FORTH HEREIN, IN NO EVENT WILL COMPANY BE LIABLE UNDER OR IN CONNECTION WITH THIS AGREEMENT OR ITS SUBJECT MATTER UNDER ANY LEGAL OR EQUITABLE THEORY, INCLUDING BREACH OF CONTRACT, TORT (INCLUDING NEGLIGENCE), STRICT LIABILITY AND OTHERWISE, FOR ANY: (a) LOSS OF PRODUCTION, USE, BUSINESS, REVENUE OR PROFIT OR DIMINUTION IN VALUE; (b) IMPAIRMENT, INABILITY TO USE OR LOSS, INTERRUPTION OR DELAY OF THE SERVICES, (c) LOSS, DAMAGE, CORRUPTION OR RECOVERY OF DATA, OR BREACH OF DATA OR SYSTEM SECURITY, OR (d) CONSEQUENTIAL, INCIDENTAL, INDIRECT, EXEMPLARY, SPECIAL, ENHANCED OR PUNITIVE DAMAGES, REGARDLESS OF WHETHER SUCH PERSONS WERE ADVISED OF THE POSSIBILITY OF SUCH LOSSES OR DAMAGES OR SUCH LOSSES OR DAMAGES WERE OTHERWISE FORESEEABLE, AND NOTWITHSTANDING THE FAILURE OF ANY AGREED OR OTHER REMEDY OF ITS ESSENTIAL PURPOSE.

UNDER NO CIRCUMSTANCES WILL COMPANY BE LIABLE FOR ANY DAMAGE OF ANY KIND TO PERSON OR PROPERTY CAUSED TO OR BY SUBSCRIBER BASED UPON ANY USE OF AI.

OTHER THAN AS SET FORTH HEREIN, IN NO EVENT WILL THE COLLECTIVE AGGREGATE LIABILITY OF EITHER PARTY UNDER OR IN CONNECTION WITH THIS AGREEMENT OR ITS SUBJECT MATTER, UNDER ANY LEGAL OR EQUITABLE THEORY, INCLUDING BREACH OF CONTRACT, TORT (INCLUDING NEGLIGENCE), STRICT LIABILITY AND OTHERWISE, EXCEED THE LICENSE FEES RECEIVED BY COMPANY OR PAID BY SUBSCRIBER FOR THE PRECEDING ONE YEAR PERIOD. THE FOREGOING LIMITATION APPLIES NOTWITHSTANDING THE FAILURE OF ANY AGREED OR OTHER REMEDY OF ITS ESSENTIAL PURPOSE. THE FOREGOING LIMITATION DOES NOT APPLY TO INDEMNIFICATION OBLIGATIONS HEREIN.

13. Force Majeure. In no event will either party be liable or responsible to the other party, or be deemed to have defaulted under or breached this Agreement, for any failure or delay in fulfilling or performing any term of this Agreement, (except for any payment obligation), when and to the extent such failure or delay is caused by any circumstances beyond such party’s reasonable control (a “Force Majeure Event”), including acts of God, flood, fire, earthquake or explosion, war, terrorism, invasion, riot or other civil unrest, embargoes or blockades in effect on or after the date of this Agreement, national or regional emergency, strikes, labor stoppages or slowdowns or other industrial disturbances, passage of Law or any action taken by a governmental or public authority, including imposing an embargo, export or import restriction, quota or other restriction or prohibition or any complete or partial government shutdown, or national or regional shortage of adequate power or telecommunications or transportation. In the event of any failure or delay caused by a Force Majeure Event, the affected party shall give prompt written notice to the other party stating the period of time the occurrence is expected to continue and use commercially reasonable efforts to end the failure or delay and minimize the effects of such Force Majeure Event.

14. Miscellaneous.

14.1. Further Assurances. Upon a party’s reasonable request, the other party shall, at the requesting party’s sole cost and expense, execute and deliver all such documents and instruments, and take all such further actions, necessary to give full effect to this Agreement.

14.2. Relationship of the Parties. The relationship between the parties is that of independent contractors. Nothing contained in this Agreement shall be construed as creating any agency, partnership, joint venture or other form of joint enterprise, employment or fiduciary relationship between the parties, and neither party shall have authority to contract for or bind the other party in any manner whatsoever.

14.3. Headings. The headings in this Agreement are for reference only and do not affect the interpretation of this Agreement.

14.4. Entire Agreement. This Agreement, together with each Statement of Work, constitutes the sole and entire agreement of the parties with respect to the subject matter of this Agreement and supersedes all prior and contemporaneous understandings, agreements, representations and warranties, both written and oral, with respect to such subject matter. In the event of any conflict or inconsistency between this Agreement and a Statement of Work, the terms of this Agreement shall control, except to the extent the Statement of Work expressly identifies the provision of this Agreement to be modified and states that it supersedes that provision, in which case the Statement of Work shall control for purposes of that Statement of Work only.

14.5. Assignment. Neither party shall assign or otherwise transfer any of its rights, or delegate or otherwise transfer any of its obligations or performance, under this Agreement, in each case whether voluntarily, involuntarily, by operation of law or otherwise, without the other party’s prior written consent, which consent may be given or withheld in the party’s sole discretion. For purposes of the preceding sentence, and without limiting its generality, any merger, consolidation or reorganization involving either party (regardless of whether Subscriber or Company is a surviving or disappearing entity) will be deemed to be a transfer of rights, obligations or performance under this Agreement for which the other party’s prior written consent is required. No delegation or other transfer will relieve either party of any of its obligations or performance under this Agreement. Any purported assignment, delegation or transfer in violation of this Section is void. This Agreement is binding upon and inures to the benefit of the parties hereto and their respective permitted successors and assigns.

14.6. Amendment and Modification; Waiver. No amendment to or modification of this Agreement is effective unless it is in writing and signed by each party. No waiver by any party of any of the provisions hereof shall be effective unless explicitly set forth in writing and signed by the party so waiving. Except as otherwise set forth in this Agreement, no failure to exercise, or delay in exercising, any rights, remedy, power or privilege arising from this Agreement shall operate or be construed as a waiver thereof; nor shall any single or partial exercise of any right, remedy, power or privilege hereunder preclude any other or further exercise thereof or the exercise of any other right, remedy, power or privilege.

14.7. Severability. If any term or provision of this Agreement is invalid, illegal or unenforceable in any jurisdiction, such invalidity, illegality or unenforceability shall not affect any other term or provision of this Agreement or invalidate or render unenforceable such term or provision in any other jurisdiction. Upon such determination that any term or other provision is invalid, illegal or unenforceable, the parties hereto shall negotiate in good faith to modify this Agreement so as to effect the original intent of the parties as closely as possible in a mutually acceptable manner in order that the transactions contemplated hereby be consummated as originally contemplated to the greatest extent possible.

14.8. Governing Law; Submission to Jurisdiction. This Agreement is governed by and construed in accordance with the internal laws of the State of Pennsylvania without giving effect to any choice or conflict of law provision or rule that would require or permit the application of the laws of any jurisdiction other than those of the State of Pennsylvania. Any legal suit, action or proceeding arising out of or related to this Agreement or the licenses granted hereunder shall be instituted exclusively in the federal courts of the United States or the courts of the State of Pennsylvania in each case located in Pennsylvania, and each party irrevocably submits to the exclusive jurisdiction of such courts in any such suit, action or proceeding. Service of process, summons, notice or other document by mail to such party’s address set forth herein shall be effective service of process for any suit, action or other proceeding brought in any such court.

14.9. Counterparts; Electronic Execution. This Agreement may be executed in counterparts, each of which is deemed an original, but all of which together are deemed to be one and the same agreement. A signed copy of this Agreement delivered by means of electronic transmission is deemed to have the same legal effect as delivery of an original signed copy of this Agreement.

Exhibit A – Definitions

“Access Credentials” means any user name, identification number, password, license or security key, security token, PIN or other security code, method, technology or device used, alone or in combination, to verify a Named User’s identity and authorization to access and use the Services.

“Affiliates” means any corporation, firm, limited liability company, partnership or other entity that directly or indirectly controls or is controlled by or is under common control with Subscriber as of the Effective Date of this Agreement. As used in this Section, control means ownership, directly or through one or more Affiliates, of fifty percent (50%) or more of the shares of stock entitled to vote for the election of directors, in the case of a corporation, or fifty percent (50%) or more of the equity interests in the case of any other type of legal entity, or status as a general partner in any partnership, or any other arrangement whereby a party controls or has the right to control the Board of Directors or equivalent governing body of a corporation or other entity, or if such level of ownership or control is prohibited in any country, any entity owned or controlled by or owning or controlling at the maximum control or ownership right permitted in the country where such entity exists. For the purpose of clarity, any entity or facility acquired by and/or coming under the control of Subscriber subsequent to the Effective Date shall not be included as an Affiliate.

“Agreement” means these General Terms and Conditions, including all exhibits hereto, together with each Statement of Work entered into by the parties that references and incorporates these General Terms and Conditions.

“AI” has the meaning set forth in Section 2.3.

“Anonymized Data” has the meaning set forth in Section 8.3.

“Business Hours” means Company’s then current business hours on any day other than a Saturday, Sunday or legal holiday in the State of Pennsylvania .

“Action” has the meaning set forth in Section 11.1.

“Confidential Information” has the meaning set forth in Section 8.4.

“Deliverables” shall mean all work product to be delivered to Subscriber by Company pursuant to a Statement of Work associated with this Agreement and specifically identified as such therein. For the avoidance of doubt, Deliverables shall not include the Software or any customization or configuration thereof.

“Disabling Device” means any software, hardware or other technology, device or means (including any back door, time bomb, time out, drop dead device, software routine or other disabling device) used by Company or its designee to disable Subscriber’s or any Named User’s access to or use of the Subscription Services automatically with the passage of time or under the positive control of Company or its designee.

“Disclosing Party” has the meaning set forth in Section 8.4.

“Documentation” means any manuals, instructions, videos or other documents or materials that Company provides or makes available to Subscriber which describe the functionality, components, features or requirements of the Services.

“End User Software” has the meaning set forth in Section 2.1.

“Error” means a failure of the Subscription Services to substantially comply with the applicable published Documentation.

“Evaluation Criteria” has the meaning set forth in Section 5.2.1.

“Fix” means a correction of an Error, including a work-around, in order for the Subscription Services to function in accordance with the applicable published Documentation.

“Fees” means Implementation Fees, Professional Services Fees and Subscription Fees.

“Force Majeure Event” has the meaning set forth in Section 13.

“Company Materials” means the Services, Software, Documentation and any and all other information, data, documents, materials, works and other content, devices, methods, processes, software and other technologies and inventions, including any deliverables, technical or functional descriptions, requirements, plans or reports, that are provided or used by Company in connection with the Services.

“Harmful Code” means any software, hardware or other technology, device or means, including any virus, worm, malware or other malicious computer code, the purpose or effect of which is to (a) permit unauthorized access to, or to destroy, disrupt, disable, distort, or otherwise harm or impede in any manner any (i) computer, software, firmware, hardware, system or network or (ii) any application or function of any of the foregoing or the security, integrity, confidentiality or use of any data processed thereby, or (b) prevent Subscriber or any Named User from accessing or using the Services as intended by this Agreement. Harmful Code does not include any Disabling Device.

“Implementation Fees” means the fees for implementation and initial configuration of the Subscription Services as set forth in the Software Schedule or relevant Statement of Work.

“Implementation Services” means all of the services and Deliverables ordered by Subscriber for the initiation and configuration of Subscription Services, all as set forth on the corresponding Statement of Work.

“Indemnified Parties” has the meaning set forth in Section 11.1.

“Intellectual Property Rights” means any and all registered and unregistered rights granted, applied for or otherwise now or hereafter in existence under or related to any patent, copyright, trademark, trade secret, database protection or other intellectual property rights laws, and all similar or equivalent rights or forms of protection, in any part of the world.

“Law” means any statute, law, ordinance, regulation, rule, code, order, constitution, treaty, common law, judgment, decree or other requirement of any federal, state, local or foreign government or political subdivision thereof, or any arbitrator, court or tribunal of competent jurisdiction.

“Losses” means any and all losses, damages, liabilities, deficiencies, claims, actions, judgments, settlements, interest, awards, penalties, fines, costs or expenses of whatever kind, including reasonable attorneys’ fees and the costs of enforcing any right to indemnification hereunder and the cost of pursuing any insurance.

“Named User” means each named individual authorized to use the Services pursuant to Section 3.1 and the other terms and conditions of this Agreement.

“Professional Services Fees” means the fees for Professional Services as set forth in the Software Schedule or relevant Statement of Work.

“Professional Services” means all of the services and Deliverables other than Implementation Services and Subscription Services ordered by Subscriber, all as set forth on a corresponding Statement of Work.

“Receiving Party” has the meaning set forth in Section 8.4.

“Services” means Subscription Services, Professional Services and Implementation Services.

“Service Level” has the meaning set forth in Section 6.3.

“Service Request” has the meaning set forth in Section 6.2.

“Software” means the remotely accessible Company programs, services and functionality as more fully identified on the Software Schedule.

“Software Schedule” means the schedule of Software, Services and Fees set forth in the applicable Statement of Work.

“Specifications” means the applicable published Company functional specifications for a Deliverable or Service, including all Documentation.

“Statement(s) of Work” means each statement of work or order document executed by Subscriber that references and incorporates this Agreement and that describes the Software, Services and Fees being provided to Subscriber. Each Statement of Work shall identify at least one authorized contact for each party for the purpose of reporting and notices.

“Subscriber Coordinator” means an individual identified by Subscriber to serve as administrative liaison to Company for all matters pertaining to the Support Services.

“Subscriber Data” means information, data and other content, in any form or medium, that is collected, uploaded or otherwise received, directly or indirectly from Subscriber through the use of the Services.

“Subscriber Systems” means the Subscriber’s information technology infrastructure, including computers, software, hardware, databases, electronic systems (including database management systems) and networks, whether operated directly by Subscriber or through the use of third-party services.

“Subscription Fees” means the fees for Subscription Services set forth in the Software Schedule or relevant Statement of Work.

“Subscription Services” has the meaning set forth in Section 2.1.

“Support” means Company’s provision of qualified technical representatives by telephone, email or other remote means to assist Subscriber Coordinators with the operation of and answering of questions related to the Subscription Services.

“Term” has the meaning set forth in Section 9.1.

Exhibit B – Software Schedule

[Intentionally omitted. The Software, Services and Fees applicable to Subscriber are set forth in the applicable Statement of Work.]

Exhibit C - Service Levels

Severity Level Response Times Effort Level and Escalation Path

Critical

An error for which there is no work-around, which causes the design making capability of the Subscription Services to be unavailable and which requires immediate attention.

Critical issues must be reported by phone to initiate an appropriate response to a Critical error. Requests initiated by email or web interface are logged without a Severity Level until reviewed by Company and validated as a higher priority.

During regular business-hours, if support personnel are not reached by phone, Company will respond to a Critical support voice message as soon as possible by a return communication to Subscriber to validate receipt of the critical support call and begin the process of addressing the issue.

Company will respond to Subscriber within 4 business hours with a status update of the reported critical issue and provide further updates for unresolved issues on agreed upon intervals until the issue is resolved. Subscriber is expected to respond to a Company inquiry or request within three hours.

Company will make reasonably diligent efforts to resolve the error on a 24x7 basis or as otherwise agreed by the Parties. A request shall be escalated to Company management if a Fix is not provided within 1 business day of Company’s receipt of the Subscriber report of an error in this category.

High

An error other than a Critical Severity Level error for which there is no work-around that results in a loss of access to the Subscription Services or that causes features of the Subscription Services to not work or which limits access or use of the Subscription Services causing the Subscriber to miss required business deadlines.

High severity errors must be reported by phone to initiate a High severity appropriate response. Requests initiated by email or web
interface are logged without a Severity Level until reviewed by Company and validated as a higher priority.

Company will respond to the Subscriber within 1 business day and will update the Subscriber at least every other day. Subscriber will respond to a Company inquiry or request within 1 business day.

Company will make reasonably diligent efforts to resolve the error during normal business hours. A request shall be escalated to Company management if a Fix is not provided within three business days of Company’s receipt of the Subscriber report of an error in this category. 

Medium

An error other than a Critical or High Severity Level error that has a material impact on the functionality of the Subscription Services that results in an inconvenient use of or access to the system (e.g., a feature is not working as documented but a workaround is available and business functions are not materially impaired).

Company will respond to the Subscriber within 2 business days. 

Company will reasonably attempt to resolve the error during normal business hours. 

Low

An error other than a Critical, High, or Medium Severity Level error that is typically cosmetic and does not degrade the use of the system.

Company will respond to the Subscriber within 3 business days or as otherwise agreed by the Parties. 

Company will reasonably attempt to resolve the error during normal business hours. 

Feature Request

A service request for an enhancement or new functionality.

N/A

The request will be evaluated for future product enhancement on a case by case basis.

Exhibit D – Company Security Addendum

1. DEFINITIONS

1.1. “Security” means Company’s technological, physical, administrative and procedural safeguards, including but not limited to policies, procedures, guidelines, practices, standards, controls, hardware, software, firmware and physical security measures, which, in whole or part, (1) protect the confidentiality, integrity or availability of Subscriber Data; (2) prevent the unauthorized use of or unauthorized access to Subscriber Systems; or (3) minimize the risk of a Security Breach or Malicious Code infection of Subscriber Systems.

1.2. “Security Breach” means any actual or reasonably suspected: (1) unauthorized use of, or unauthorized access to, Subscriber Systems; (2) inability to access Subscriber Data or Subscriber Systems due to a malicious use, attack or exploit of such Subscriber Data or systems; (3) unauthorized access to or theft of Subscriber Data; (4) unauthorized use of Subscriber Data by a person with authorized access to such Subscriber Data for purposes of theft, fraud or identity theft; (5) unauthorized disclosure or alteration of Subscriber Data; (6) transmission of Malicious Code to Subscriber Systems resulting (in whole or part) from the foregoing described in (1) – (6); or (7) loss of Subscriber Data, including without limitation, any of the foregoing described in (1) – (6) caused by or resulting from a failure, breach of, lack of or inadequacy of Security, physical intrusion of facilities, theft or loss of documents, laptops or storage media, or employee or Company malfeasance. For the avoidance of doubt, “Security Breach” includes any access, acquisition, use, disclosure, modification, or destruction of Personal Information that is unauthorized or that may otherwise violate applicable Privacy Laws or other federal, state, or local laws, including without limitation any actual or suspected data breaches.

1.3. “Security Coordinator” means the individual working for each party that shall act as the security liaison between Subscriber and Company, oversee compliance with the data security provisions of this Agreement, receive notice of Security Breaches, coordinate Security Breach incident response and remedial action, and provide notice, reporting and work to undertake other actions and duties as set forth in this Agreement.

1.4. “Metadata” means data about data, or a set of data that describes and gives information about other data, or all of the contextual, processing, and use information needed to identify and certify the scope, authenticity, and integrity of active or archival electronic information or records, such as a file’s name, a file’s location (e.g., directory structure or pathname), file format or file type, file size, file dates (e.g., creation date, date of last data modification, date of last data access, and date of last metadata modification), and file permissions (e.g., who can read the data, who can write to it, and who can run it). It includes any Metadata related to or derived from any Subscriber Data.

All capitalized terms not defined in this Addendum shall have the meaning set forth in the Agreement or applicable Privacy Law(s). Nothing in this Addendum shall be construed to limit any rights expressly granted to Company under the Agreement, and in the event of any conflict between this Addendum and any such express grant, the Agreement shall control.

2. INFORMATION PRIVACY AND SECURITY

2.1. Data Privacy Compliance.

2.1.1. Permitted Use and Disclosure. Company may only Process Subscriber Data for or on behalf of Subscriber (i) as reasonably necessary to perform Services under the Agreement, (ii) as permitted or required by applicable law, including applicable Privacy Laws, and (iii) as otherwise permitted or required by this Addendum or the Agreement. For the avoidance of doubt, where required by the applicable state or federal law, Company will not use Subscriber Data to build or modify household or individual profiles to use in providing services to another business or correcting or augmenting data acquired from another source.

2.1.2. Prohibitions. Except as expressly permitted under the Agreement, Company shall not use any Subscriber Data for purposes other than carrying out the Work specified in the Agreement and shall not distribute, repurpose or share across other applications, environments or business units of Company. Company shall not transmit, exchange or otherwise pass Subscriber Data to other vendors or interested parties except to subcontractors engaged in accordance with Section 2.7 of this Addendum or as otherwise agreed to in writing by Subscriber. If applicable under state or federal law, Company shall not engage in any activity that constitute the Sale of Subscriber Data. For the avoidance of doubt, “Sale” shall have the meaning ascribed to it in the relevant law.

2.1.3. Assistance with Subscriber Obligations. Company shall provide commercially reasonable assistance, taking into account the nature of the Services and the information available to Company, in connection with Subscriber’s obligations to respond to verifiable requests by individuals (or their lawful representatives) (“Data Subjects”) for exercising their rights under applicable Privacy Laws. Where applicable under relevant laws, if Company receives a request from a Data Subject (or their lawful representative) for the disclosure of information or deletion of Subscriber Data, Company shall notify Subscriber and if agreed by Subscriber, act on behalf of Subscriber in responding to the request.

2.2. Data Privacy and Security Certifications. Company acknowledges and understands there is the potential for Subscriber to be susceptible to data theft, Security Breaches, virus or other malicious code installations, or other cyber threats caused by or through the Services, including Company’s access to the Subscriber’s information technology including its Systems, including emails sent from Company that may contain virus, other malicious code installations, or other cyber threats. Company hereby certifies it has implemented the following security and privacy standards:

2.2.1. Conducted an internal review of Company’s solution and its own data privacy and security measures that demonstrates that Company is at minimum compliant with the security standards set forth herein;

2.2.2. All third party facilities utilized to store Subscriber Data maintain a System and Organizational Controls (SOC) 2 type ii report, ISO 27001 certification, or similar compliance documentation, which Company assesses at least annually and will make available to Subscriber upon written request;

2.2.3. Maintains an information security program aligned with System and Organizational Controls (SOC) 2 type ii requirements and, upon completion of its internal SOC 2 type ii audit, will make the resulting report (which may be redacted) available to Subscriber upon written request;

2.2.4. Implemented and maintain appropriate and reasonable administrative, technical, and physical safeguards (including training on these policies and safeguards) designed to detect, prevent, and mitigate the risk of Security Breaches;

2.2.5. Developed a system and policies for reporting any unauthorized use, disclosure, loss, or theft of Subscriber Personally Identifiable Information (“PII”), Confidential Information, or other sensitive Subscriber Data in accordance with the notification timeframes set forth in this Addendum, and, where applicable in compliance with these requirements;

2.2.6. Any transmission of data between Subscriber and the Company is encrypted in transit and meets the Encryption requirements outlined in the Data Encryption Standards below including a recent and secure version of https (TLS v1.2 or higher) or a secure file transfer protocol ( SFTP), and if the latter, and the file contains PII, the file should remain encrypted while at rest;

2.2.7. Company supports the exchange of encrypted files with Subscriber using industry-standard encryption methods supported by the Services;

2.2.8. Where supported by the applicable Software, Company’s solution or Services will accept a Security Assertion Markup Language (“SAML”) 2.0 security token from Subscriber’s identity provider so that Subscriber may manage both account authentication and multi-factor authentication (MFA);

2.2.9. All Subscriber Data is maintained in the U.S.A. Company will provide Subscriber reasonable notice of any changes to data residency

2.2.10. Company maintains Subscriber Data in a hosted solution and has identified its hosting provider (e.g. AWS, Azure, etc.) to Subscriber and will provide Subscriber reasonable notice of any changes to the host provider;

2.2.11. Company personnel receive training on applicable Privacy Law, including annual security training including phishing education and awareness and understand the limitations and restrictions of Privacy Law and will comply with them;

2.2.12. Any and all data exchanged shall be used expressly and solely for the purposes enumerated or otherwise permitted in the Agreement;

2.2.13. Except as expressly permitted under the Agreement, Subscriber Data will not be distributed, repurposed or shared across other applications, or environments; and

2.2.14. No Subscriber Data will be transmitted, exchanged or otherwise passed to other vendors or interested parties except to subcontractors engaged in accordance with Section 2.7 of this Addendum or as otherwise agreed to in writing by Subscriber.

2.3. Data Security Compliance

2.3.1. Company Duties and Responsibilities. Company duties and responsibilities include, but are not limited to: (1) protecting Subscriber Data and other Subscriber information assets on a daily basis through adherence to the security policies and standards set forth in this Agreement; (2) receiving approval from Subscriber prior to accessing Subscriber Data in Subscriber Systems; (3) adhering to Subscriber’s security requirements and controls as set forth in this Agreement; (4) not disseminating Confidential Information to which Company has been granted access without authorization from Subscriber; and (5) applying the baseline Encryption standards identified in this Data Security Compliance section as appropriate based on the sensitivity of the applicable Subscriber Data.

2.3.2. Security Safeguards. Company agrees that, beginning on the Effective Date, and continuing as long as Company controls, possesses, stores, transmits or otherwise Processes Subscriber Data, Company shall employ and maintain reasonable Security designed to: (1) ensure that all Subscriber Data is protected from unauthorized use, alteration, access or disclosure, and to protect and ensure the confidentiality, integrity and availability of Subscriber Data; (2) prevent unauthorized access to and unauthorized use of, and ensure the availability of, Subscriber Systems; and (3) prevent a Security Breach or Malicious Code infection of Subscriber Systems. Such Security shall, without limitation, be consistent with all applicable Privacy Laws, and shall be informed by relevant industry standards, including the following “Security Safeguards”:

2.3.2.1. Restrict Access. Company shall implement reasonable restrictions regarding physical and electronic access to Subscriber Data and Subscriber Systems, including but not limited to physical access controls, secure user authentication protocols, secure access control methods, firewall protection, malware protection, and use of Encryption for laptops, mobile devices and Subscriber Data being transmitted across the public Internet or wirelessly, and as otherwise required by Privacy Law. Company shall prevent terminated personnel from accessing Subscriber Data and Subscriber Systems by terminating their physical and electronic access to such information and systems within one (1) business day.

2.3.2.2. Data Security Program. Develop and maintain a reasonable and appropriate written data security program that includes technological, physical, administrative and procedural controls to protect the confidentiality, integrity and availability of Subscriber Data and Subscriber Systems, that encompasses access, retention and transport of Subscriber Data, and that provides for disciplinary action in the event of its violation.

2.3.2.3. Monitoring and Assessment. Company shall employ assessment, monitoring and auditing procedures to ensure internal compliance with these Security Safeguards, informed by relevant industry standards, including but not limited to such review and monitoring as described in the Security reporting, Audits, and Review of Systems section.

2.3.2.4. Secure Transmission. Any and all electronic transmission or exchange of system and application data with Subscriber and/or any other parties expressly designated by Subscriber shall take place via secure means (using HTTPS or SFTP or equivalent).

2.3.2.5. Annual Assessment. Company shall conduct a complete assessment of the Security Safeguards at least annually and, upon written request, provide a summary of the results of this assessment to Subscriber.

2.3.3. Industry Security Standards. In the event of any conflict between or among Company’s obligation to employ and maintain reasonable Security, its obligation to meet relevant industry standards for Security, and/or any obligation herein, Company shall use commercially reasonable efforts to resolve such conflict in a manner that reasonably protects the confidentiality, integrity and availability of Subscriber Data.

2.4. Data Encryption Standards.

2.4.1. Encryption Standards. To the extent Company processes any Subscriber Data, Company agrees to comply with the standards set forth in this Encryption Standards section, as an effective baseline of the appropriate system, administrative, and physical controls to apply to Subscriber Data stored on any systems, applications or locations on-premises or outside of the Subscriber network. These Encryption standards identify baseline security measures to protect Subscriber Data-at-Rest or Subscriber Data-in-Transit, and Company agrees to implement such measures as applicable. Company may update its Encryption standards from time to time, provided that any such update does not materially reduce the overall protection of Subscriber Data.

2.4.2. Transport Layer Security. At a minimum, Company represents and warrants that, with respect to Subscriber Data, it shall implement and use Transport Layer Security (TLS) as a cryptographic protocol with industry standard cipher suites to guard against unauthorized access to or disclosure of Subscriber Data. Industry-standard protocols and ciphers such as TLS v1.2 or above, or Advanced Encryption Standard-256 (AES-256), shall be used for all Subscriber Data transmitted over open networks such as the Internet. This baseline requirement to use TLS Encryption is subject to change as more secure protocols become available.

2.4.3. Data Transmission and Access. Company shall transmit any Subscriber Data including, without limitation, PII or Confidential Information, via encrypted communication to ensure Subscriber Data is not transmitted in clear text. Applications of Encryption for data transmission include but are not limited to those identified in this Section, for file transfers can be achieved via the use of an encrypted transmission protocol or network servers such as Secure Copy Protocol (SCP) or SFTP, or by transferring a file that has been encrypted prior to the transmission.

2.4.4. Email. Any Subscriber Data that includes PII or Confidential Information and is transmitted by Company in email messages shall be encrypted in transit using industry-standard means, such as TLS-encrypted email transport, a secure web application, or a secure message format, given email is exposed to the possibility of unauthorized access at a number of points throughout the delivery process.

2.4.5. Account Access. Encryption of Confidential Information or PII for account access, such as login passwords which are transmitted during remote login sessions and in connection with remote-control functionality for computers, shall be provided through the use of secure applications or protocols.

2.4.6. Remote File Access. Encryption of Subscriber Data transmitted by remote file access shall be provided through the use of encrypted transmission protocols such as TLS or Internet Protocol Security (IPSEC) to prevent unauthorized interception.

2.4.7. Data Storage. Company shall encrypt any Subscriber Data that includes PII or Confidential Information and is stored in Subscriber Systems, databases, and/or portable media using industry-standard Encryption processes (e.g., AES-256). Public data classifications do not require Encryption when stored.

2.4.8. Portable Devices. Encryption of PII or Confidential Information stored on portable computer devices (e.g. smart phones, tablets, laptops, and/or desktops), as well as storage media, (e.g. CDs, DVDs, and USB devices) shall be provided through the use of a whole disk encryption tool or one that can at least be configured to encrypt all sensitive Subscriber Data. Encryption of PII or Confidential Information shall be provided to facilitate the secure transport of individual files over a network without transmission or to off-line storage devices (e.g. CDs, DVDs, or USB drives), as applicable.

2.4.9. Servers and Backups. Company shall encrypt Subscriber Data at rest using industry-standard methods, which may include database-, volume- or storage-level Encryption. Confidential Information or PII contained in Company backups and/or archive copies shall be provided Encryption to prevent unauthorized access.

2.5. Security Reporting, Audits, and Review of Systems.

2.5.1. Security Reporting and Review. During the Term, Subscriber shall have the following security reporting and review rights:

2.5.1.1. Security Audit Reports. Company engages independent third parties to audit and assess Company’s information security program, including SOC 2 Type 2 audits and annual penetration testing. Upon Subscriber’s written request, no more than once per calendar year, Company will make available to Subscriber summaries of the results of such third-party audits and assessments (redacted as appropriate). Subscriber shall not be entitled to audit, inspect, or test Company’s information security program, facilities, or Systems.

2.5.1.2. Annual Internal Company Review. Company shall review the effectiveness of its information security program at least annually and shall revise its program in light of any deficiencies in existing programs, relevant changes in technology, the sensitivity, nature and quantity of the Subscriber Data it holds, internal or external threats to information and Company’s own changing business arrangements. Company shall provide Subscriber with a summary of the results of such review upon Subscriber’s written request.

2.5.1.3. Contingency and Recovery Plans. Company shall establish and maintain contingency plans, recovery plans and proper risk controls to ensure Company’s continued performance under the Agreement. Company shall provide summaries of the plans to Subscriber upon written request.

2.5.1.4. Review of Systems. Company shall maintain system records and logs in accordance with its documented data retention schedule and, in connection with any Security Breach affecting Subscriber Data, shall afford Subscriber reasonable access to relevant records of system activity pertaining to Subscriber Data. Company acknowledges and agrees that records of system activity and of Subscriber Data handling may be evidence (subject to appropriate chain of custody procedures) in the event of a Security Breach or other inappropriate activity. Upon Subscriber’s request, Company shall deliver copies of such relevant records to Subscriber for use in any legal, investigatory or regulatory proceeding.

2.5.1.5. Reports. During each calendar year, Company will make available to Subscriber, upon written request, summaries of the SOC 2 Type 2 reports, ISO 27001 certifications, or similar compliance documentation for vendor data centers from which the Services are provided to Subscriber.

2.6. Data Backup and Recovery.

2.6.1. Policies, Plans, and Procedures. Company shall establish and maintain policies and procedures relevant to contingency plans, recovery plans and proper risk controls to ensure Company’s continued performance under the Agreement. These policies and procedures shall include, but not be limited to, recovery strategy, documented recovery plans covering all areas of operations necessary to delivering Company’s Services pursuant to the Agreement, vital records protection and testing plans. The plans shall provide for off-site or geographically redundant backup of Subscriber Data and the critical systems and data necessary to deliver the Services.

2.6.2. Recovery Strategy and Objectives. The recovery strategy shall provide for recovery after both short- and long-term disruptions in facilities, environmental support and data processing equipment. Company’s recovery objectives (time to full restoration and amount of lost data tolerated) shall be defined in Company’s documented business continuity and disaster recovery plan based on the criticality of the applicable systems and services. Any Subscriber-specific recovery objectives shall be established by mutual written agreement of the parties.

2.7. Subcontractors.

2.7.1. Subscriber Consent to Use of Subcontractors. Subscriber hereby provides general written authorization for Company to engage subcontractors (including hosting and cloud infrastructure providers) to Process Subscriber Data in connection with the Services, provided that Company remains responsible for the performance of such subcontractors and complies with Section 2.7.2. Company will make a list of its material subcontractors available to Subscriber upon written request.

2.7.2. Subcontractor Obligations. To the extent that Company is permitted to engage subcontractors in connection with Company’s performance of the Services under the terms of the Agreement, Company shall ensure that any subcontractors create, receive, maintain, or transmit Subscriber Data on behalf of Company agree in writing to the same restrictions and conditions that apply through this Addendum to Company with respect to such information. For the avoidance of doubt, Company shall ensure that all subcontractors or other third parties who have access to Subscriber Data have a written information security program and plan substantially equivalent to the program utilized by Company.

2.8. Security Breaches.

2.8.1. Cooperation. Company agrees to reasonably cooperate and coordinate with Subscriber concerning: (1) Subscriber’s investigation, enforcement, monitoring, document preparation, notification requirements and reporting concerning Security Breaches and Company’s and Subscriber’s compliance with Privacy Law; and (2) and any other activities or duties set forth under this Agreement for which cooperation between Subscriber and Company may be reasonably required.

2.8.2. Security Breach Policies and Procedures. Company shall maintain policies and procedures for responding to Security Breaches, including without limitation, assigning and training an individual to serve as Security Coordinator and training Company’s personnel with access to Subscriber Data to recognize Security Breaches and to escalate and notify the Security Coordinator of the foregoing.

2.8.3. Duty to Provide Notice. Company will provide notice to Subscriber’s Security Coordinator and any other person designated by Subscriber without undue delay, and in any event within seventy-two (72) hours after Company confirmed a Security Breach impacting Subscriber.

2.8.4. Security Breach Response. In the event of a Security Breach, Company will use commercially reasonable efforts to prevent, contain, and mitigate the impact of such Security Breach. If time is critical, corrective action shall not be delayed, provided that Company shall not take any actions that result in the destruction of evidence relating to such Security Breach. In addition, Company shall:

2.8.4.1. Promptly conduct a reasonable investigation of the reasons for and circumstances surrounding such Security Breach;

2.8.4.2. Collect and preserve evidence concerning the discovery, cause, vulnerability, remedial actions and impact related to such Security Breach in accordance with Company’s incident response procedures;

2.8.4.3. Document the incident response and remedial actions taken;

2.8.4.4. If requested by Subscriber, provide reasonable assistance with legally required notifications to individuals or entities whose information was or may have been affected, and otherwise promptly take such actions and provide such information for which Subscriber may request assistance in order to fulfill requests of such individuals or entities, including, without limitation, requests to access, delete, opt out of the sale of, or receive information about the processing of, PII pertaining to them.

2.8.4.5. Promptly, and in no event more than ten (10) business days after the date Company confirmed a Security Breach impacting Subscriber, provide a written summary report to Subscriber concerning such Security Breach. Such reports shall include all information required to be reported under applicable Privacy Law, to the extent that such information is known or possible to determine (or is available to Company through the exercise of reasonable diligence), as well as such other information as Subscriber may reasonably request.

2.9. Storage and Processing of Subscriber Data.

2.9.1. Secure Storage. All Subscriber Data must be stored in a physically and logically secure environment that protects it from unauthorized access, modification, theft, misuse or destruction. In addition to the standards set forth above, Company shall maintain a reasonable and appropriate level of physical security controls over its facilities. Subscriber Data is stored in third-party data centers whose providers maintain their own physical security and environmental controls, which Company assesses at least annually through vendor-supplied SOC 2 reports, ISO 27001 certifications, or similar compliance documentation. Further, Company will maintain a reasonable and appropriate level of data security controls for its facilities and Subscriber Systems, including, but not limited to, logical access controls (including user sign-on identification and authentication), data access controls (including password protection of applications, data files and libraries), accountability tracking, anti-virus software, secured printers, restricted download to disk capability and provision for system back up.

Exhibit E - Statement(s) of Work

[Intentionally omitted. Statements of Work are executed separately by the parties and incorporate this Agreement by reference.]

Version History

  • July 23, 2026 Current version
Peregrin

Simplifying purchasing for HVAC Controls contractors.

Navigation

Features Pricing Why Peregrin About Blog Free Guide Events Contact Terms & Conditions About eParts Services

Contact Us

eParts Services LLC

+1 844.722.7278

[email protected]

SOC 2 Type II Certified

1 Save 20% off your base subscription fee for life. Must start a subscription within 60 days of launch. Ending the subscription will end this benefit. This offer applies only to new customers of eParts Services LLC.

All third-party product names, logos, and brands referenced on this site are the property of their respective owners. Peregrin is not affiliated with, endorsed by, or sponsored by these vendors unless explicitly stated. Vendor names and logos are used solely to indicate compatibility and supported integrations.

© 2026 eParts Services LLC

Free Playbook — 5 strategies to cut procurement costs 30-50%

Get the Playbook Early Access
Free playbook · Instant download
30–50%
Lower procurement costs

Wait — don't leave empty-handed.

Grab the Procurement Savings Playbook: the exact 5 plays HVAC controls contractors use to cut costs and win hours back on every project.

  • 5 sourcing tactics that pay for themselves on job #1
  • Supplier negotiation scripts you can use tomorrow
  • The PO workflow that kills 80% of rework
Send me the playbook

No spam. Unsubscribe in one click.