Terms
Master Subscription & Services Agreement
Effective Date: September 24, 2026
This Master Subscription & Services Agreement (“Agreement”) is between Cofactor AI, Inc. (“Cofactor”) and the customer identified in an executed Order (“Customer”). This Agreement is effective (“Agreement Effective Date”) as of the Effective Date of such Order and is incorporated into the Order. This Agreement allows Customer and its Affiliates to purchase access to certain of Cofactor’s Services as specified under one or more Orders. Certain capitalized terms are defined in Exhibit A, and others are defined contextually in this Agreement.
1. Services; Ordering Process
The Subscription Services provide an artificial intelligence system to deploy agents that quickly analyze operational, clinical, and academic information to generate output and automated workflows, and other services, as specified in an Order. Professional Services are provided as outlined in the applicable Order. Each Order will specify the applicable Service(s) ordered by Customer, including, as applicable, the number of units, and the time period for which such Order applies.
2. Subscription Services
2.1. Permitted Use; License. During the Term, subject to Customer’s compliance with the terms of this Agreement, Customer may access and use the Subscription Services only for its internal business purposes, in accordance with the Documentation, this Agreement, and any limitations set forth in an Order. During the Term, subject to Customer’s compliance with the terms of this Agreement, the Documentation, and any limitations set forth in an Order, Cofactor grants Customer a limited, non-transferable, revocable, non-exclusive, non-sublicensable license for each User to use the Subscription Services as described in such Order.
2.2. Users. Only Users, using the mechanisms designated by Cofactor (“Log-in Credentials”), may access and use the Subscription Services. Each User must keep its Log-in Credentials confidential and not share them with anyone else. Customer is responsible for its Users’ compliance with this Agreement and all actions taken through their Log-in Credentials (excluding misuse of the Log-in Credentials caused by Cofactor’s breach of this Agreement). Customer will promptly notify Cofactor if it becomes aware of any compromise of any Log-in Credentials. Cofactor may Process Log-in Credentials in connection with Cofactor’s provision of the Services or for Cofactor’s internal business purposes.
2.3. Restrictions. Customer will not (and will not permit anyone else to) do any of the following: (a) provide access to, distribute, sell, or sublicense a Service or Software to a third party (other than Users for access on behalf of Customer); (b) use a Service or Software on behalf of, or to provide any product or service to, third parties; (c) use a Service or Software to develop a similar or competing product or service; (d) reverse engineer, decompile, disassemble, or seek to access the source code or non-public APIs to a Service or Software, except to the extent expressly permitted by Law (and then only with prior written notice to Cofactor); (e) modify or create derivative works of a Service or Software or copy any element of a Service or Software; (f) remove or obscure any proprietary notices in a Service or Software; (g) publish benchmarks or performance information about a Service or Software; (h) interfere with the operation of a Service or Software, circumvent any access restrictions, or conduct any security or vulnerability test of a Service or Software; (i) transmit any viruses or other harmful materials to a Service or Software; (j) take any action that risks harm to others or to the security, availability, or integrity of a Service or Software; or (k) access or use a Service or Software in a manner that violates any Law.
2.4. SLA and Support. During the Term, Cofactor will use commercially reasonable efforts to provide the applicable Subscription Services in accordance with the SLA and the Support Policy.
2.5. Upgrades. Unless stated otherwise in an Order, Cofactor will make Updates to Subscription Services as Cofactor makes them available to its customers of the applicable Subscription Services generally. Customer’s purchase of access to Subscription Services is not contingent on the delivery of any future functionality or features or dependent on any oral or written public or private comments made by Cofactor regarding future functionality or features of the Subscription Services. From time to time, Cofactor, in its sole discretion, may make available Upgrades under additional or different terms. Nothing in this Agreement obligates Cofactor to make Upgrades available to Customer as part of the Services or otherwise unless specifically included in an Order.
3. Professional Services
Customer agrees to provide Cofactor with reasonable access to required information or data as needed, and Customer’s equipment and personnel, to the extent necessary to perform Professional Services. Cofactor will have no liability resulting from failure to perform due to Customer’s failure or delay in providing the foregoing in a timely manner. Any material adjustments to Professional Services pursuant to an Order will require an amendment to such Order executed by both parties prior to implementation of such adjustments (“Change Order”), which may result in additional fees. Each Change Order must include the changes to Professional Services and impact on timing and fees; once executed the Change Order is deemed part of the Order Form.
4. Data
4.1. Use of Customer Data. Customer grants Cofactor the non-exclusive, worldwide, sublicensable right to use, copy, store, disclose, transmit, transfer, publicly display, modify, and create derivative works from Customer Data as necessary to: (a) provide and support any Services and enforce this Agreement; (b) improve and develop services and products; (c) derive data and insights from Customer’s and/or its Users’ use of the Services, including, without limitation, any analytics, benchmarking, usage data, or trends with respect to the Services (collectively, “Usage Data”); (d) subject to the BAA, create and compile data that is derived or aggregated in deidentified form from (i) Customer Data; or (ii) Usage Data (collectively, “Aggregated Data”); and (e) as otherwise required by Laws or as permitted in the BAA or other writing between the parties.
4.2. Security. Cofactor will maintain, for as long as it Processes Customer Data, reasonable security measures to protect the privacy, security, and confidentiality of Customer Data.
4.3. HIPAA. To the extent Cofactor creates, receives, maintains, or transmits Protected Health Information for or on behalf of Customer as a business associate (as such terms are defined by HIPAA), the parties shall comply with the Business Associate Agreement (“BAA”) attached hereto as Exhibit B.
5. Customer Obligations
Customer is responsible for its Customer Data, including its content, completeness, and accuracy, and will comply with Laws when using the Services. Customer represents and warrants that it has made all disclosures, provided all notices, and has obtained all rights, consents, and permissions necessary for Cofactor to Process Customer Data as set forth in this Agreement and the BAA without violating or infringing Laws, third-party rights, or terms or policies that apply to the Customer Data.
6. Suspension of Service
Cofactor may immediately suspend Customer’s access to any or all of the Subscription Services or suspend provision of Professional Services if: (a) Customer or its Users breach Sections 2.2 (Users), 2.3 (Restrictions), or Section 6 (Customer Obligations); (b) Customer’s account is 30 days or more overdue; (c) changes to Laws or new Laws require that Cofactor suspend a Service or otherwise may impose additional liability on the part of Cofactor; or (d) Customer’s actions risk harm to any of Cofactor’s other customers or the security, availability, or integrity of a Service. Where practicable, Cofactor will use reasonable efforts to provide Customer with prior notice of the suspension (email sufficing). If the issue that led to the suspension is resolved, Cofactor will restore Customer’s access to the Service(s).
7. Customer Systems
Customer will provide and maintain any Customer Systems, including Customer’s system for maintaining and accessing electronic health records.
8. Third-Party Platforms
Use of Third-Party Platforms, including Customer’s electronic records system, is subject to Customer’s agreement with the relevant provider and not this Agreement. Cofactor does not control and has no liability for Third-Party Platforms, including their security, functionality, operation, availability, or interoperability with the Services or how the Third-Party Platforms or their providers use Customer Data. By enabling a Third-Party Platform to interact with the Subscription Services or be accessed for Professional Services, Customer authorizes Cofactor to access and exchange Customer Data with such Third-Party Platform on Customer’s behalf.
9. Commercial Terms
9.1. Term. Except as set forth in an Order, each initial term (“Initial Term”) will automatically renew for successive 12-month periods (each, a “Renewal Term”) unless either party gives the other party notice of non-renewal at least 30 days before the current Term ends.
9.2. Fees and Taxes. Fees for the Services are described in each Order (“Fees”). Customer will reimburse Cofactor for reasonable travel and lodging expenses it incurs in providing technical integration for Subscription Services and any Professional Services (“Expenses”). All Fees and Expenses will be paid in US dollars unless otherwise provided in an Order. Fees are invoiced as described on the schedule in the Order and Expenses are invoiced in arrears. Unless the Order provides otherwise, all Fees and Expenses are due within 30 days of the invoice date. Fees for renewal terms are at Cofactor’s then-current rates, regardless of any discounted pricing in a prior Order. Late payments are subject to a service charge of 1.5% per month or the maximum amount allowed by Law, whichever is less. All Fees and Expenses are non-refundable except as may be set out in Section 11.2 (Warranty Remedy), Section 15.4 (Mitigation), and the SLA. Customer is responsible for any sales, use, GST, value-added, withholding, or similar taxes or levies that apply to Orders, whether domestic or foreign, other than Cofactor’s income tax (“Taxes”). Fees and Expenses are exclusive of all Taxes.
9.3. Affiliate Orders. An Affiliate of Customer may use Services by entering into its own Order(s) as agreed with Cofactor. Each such Order creates a separate agreement between the Affiliate and Cofactor which incorporates this Agreement, with the Affiliate treated as “Customer”. Customer and Customer Affiliate are responsible for the other’s compliance obligations under each other’s agreement with Cofactor and will be jointly and severally liable under each such agreement.
10. Warranties and Disclaimers
10.1. Limited Warranty. Cofactor warrants to Customer that each of the Subscription Services will perform materially as described in its Documentation, and Cofactor will not materially decrease the overall functionality of the Subscription Services (“Performance Warranty”) during a Term (“Warranty Period”).
10.2. Warranty Remedy. If Cofactor breaches the Performance Warranty during the applicable Warranty Period and Customer makes a reasonably detailed warranty claim in the manner required by Cofactor within 30 days of discovering a breach of the Performance Warranty for the applicable Subscription Service(s), then Cofactor will use reasonable efforts to correct the non-conformity. If Cofactor cannot do so within 30 days of receipt of Customer’s warranty claim, either party may terminate the affected Order as it relates to the non-conforming Subscription Service. Cofactor will then refund to Customer any pre-paid, unused fees for the terminated portion of the Subscription Services in the applicable Term. This Section sets forth Customer’s exclusive remedy and Cofactor’s entire liability for breach of the Performance Warranty. This warranty does not apply to: (a) issues caused by Customer’s or Users’ misuse of or unauthorized modifications to the applicable Subscription Service; (b) issues in or caused by Third-Party Platforms or other third-party systems; or (c) use of the applicable Subscription Service other than according to the Documentation.
10.3. Disclaimers. Except as expressly provided in Section 11.1 (Limited Warranty), the Services are provided “AS IS”. Cofactor, on its own behalf and on behalf of its suppliers and licensors, makes no other warranties, whether express, implied, statutory, or otherwise, including warranties of merchantability, fitness for a particular purpose, title, or noninfringement. Cofactor does not warrant that Customer’s use of the Subscription Services will be uninterrupted or error-free, that Cofactor will review Customer Data for accuracy, or that it will maintain Customer Data without loss. Cofactor is not liable for delays, failures, or problems inherent in use of the Internet and electronic communications or other systems outside Cofactor’s control. Customer may have other statutory rights, but any statutorily required warranties will be limited to the shortest legally permitted period. Customer is responsible for reviewing output for accuracy, legal or regulatory compliance, and suitability to their use case, and Cofactor is not responsible for decisions made in response to the output.
11. Term and Termination
11.1. Term. The term of this Agreement (the “Term”) starts on the Agreement Effective Date and continues until expiration or termination of all Orders.
11.2. Termination. Either party may terminate this Agreement (including any or all Orders) if the other party: (a) fails to cure a material breach of this Agreement (including a failure to pay fees) within 30 days after notice; (b) ceases operation without a successor; or (c) seeks protection under a bankruptcy, receivership, trust deed, creditors’ arrangement, composition, or comparable proceeding, or if such a proceeding is instituted against that party and not dismissed within 60 days.
11.3. Effect of Termination. Upon expiration or termination of an Order, Customer’s access to Subscription Services and Cofactor’s obligations to provide the Services in the Order and any Software will cease.
11.4. Survival. These Sections survive expiration or termination of this Agreement: 2.3 (Restrictions), 5 (Data), 6 (Customer Obligations), 10.2 (Fees and Taxes), 11.3 (Disclaimers), 12.3 (Effect of Termination), 12.4 (Survival), 13 (Ownership), 14 (Limitations of Liability), 15 (Indemnification), 16 (Confidentiality), 18 (General Terms), and Exhibit A (Definitions). Except where an exclusive remedy is provided in this Agreement, exercising a remedy under this Agreement, including termination, does not limit other remedies a party may have.
12. Ownership
Neither party grants the other any rights or licenses not expressly set out in this Agreement or the BAA. Except as expressly provided in this Agreement or the BAA, as between the parties, (i) Customer retains all intellectual property rights and other rights in Customer Data provided to Cofactor; and (ii) Cofactor and its licensors retain all intellectual property rights and other rights in the Services, Software, Documentation, Usage Data, Aggregated Data, and Cofactor technology, templates, formats, and dashboards, including any modifications or improvements to these items made by Cofactor (“Cofactor IP”). If Customer provides Cofactor with feedback or suggestions regarding the Services or other Cofactor offerings, Cofactor may use the feedback or suggestions without restriction or obligation.
13. Limitations of Liability
13.1. Consequential Damages Waiver. IN NO EVENT WILL EITHER PARTY (NOR ITS SUPPLIERS OR LICENSORS) HAVE ANY LIABILITY ARISING OUT OF OR RELATED TO THIS AGREEMENT, THE BAA, ANY ORDER, OR THE SERVICES, FOR ANY LOSS OF USE, LOST DATA, LOST REVENUES, LOSS OF GOODWILL OR REPUTATION, LOST PROFITS, FAILURE OF SECURITY MECHANISMS, INTERRUPTION OF BUSINESS, OR ANY INDIRECT, SPECIAL, INCIDENTAL, PUNITIVE, EXEMPLARY, RELIANCE, OR CONSEQUENTIAL DAMAGES OF ANY KIND, EVEN IF INFORMED OF THEIR POSSIBILITY IN ADVANCE.
13.2. Liability Cap. EXCEPT FOR EXCLUDED CLAIMS, EACH PARTY’S (AND ITS SUPPLIERS’ AND LICENSOR’S) ENTIRE MAXIMUM LIABILITY ARISING OUT OF OR RELATED TO THIS AGREEMENT, ANY ORDERS, THE BAA, OR THE SERVICES, WILL NOT EXCEED IN THE AGGREGATE THE AMOUNTS PAID BY CUSTOMER TO COFACTOR PURSUANT TO THIS AGREEMENT DURING THE 12 MONTHS PRIOR TO THE DATE ON WHICH THE APPLICABLE CLAIM GIVING RISE TO THE LIABILITY AROSE UNDER THIS AGREEMENT.
13.3. Excluded Claims. “Excluded Claims” means claims arising from: (a) a party’s gross negligence, willful misconduct, or fraud; (b) Customer’s breach of Sections 2.3 (Restrictions) or 6 (Customer Obligations); or (c) amounts payable to third parties under the indemnifying party’s obligations in Section 15 (Indemnification).
13.4. Nature of Claims and Failure of Essential Purpose. The waivers and limitations in this Section 14 apply regardless of the form of action, whether in contract, tort (including negligence), strict liability, or otherwise, and will survive and apply even if any limited remedy in this Agreement fails of its essential purpose.
14. Indemnification
14.1. Indemnification by Cofactor. Cofactor will defend Customer from and against any third-party claim to the extent alleging that a Subscription Service, when used by Customer as permitted under the applicable Order and this Agreement, infringes or misappropriates a third-party’s U.S. patent, copyright, trademark, or trade secret, and will indemnify and hold harmless Customer against any actual damages and costs awarded against Customer (including reasonable attorneys’ fees) or agreed in a settlement by Cofactor resulting from the claim.
14.2. Indemnification by Customer. Customer will defend Cofactor from and against any third-party claim to the extent resulting from Customer Data or Customer’s breach or alleged breach of Section 6 (Customer Obligations), and will indemnify and hold harmless Cofactor against any damages and costs awarded against Cofactor (including reasonable attorneys’ fees) or agreed in a settlement by Customer resulting from the claim.
14.3. Procedures. The indemnifying party’s obligations in this Section 15 are subject to it receiving: (a) prompt written notice of the claim; (b) the exclusive right to control and direct the investigation, defense, and settlement of the claim; and (c) all reasonably necessary cooperation of the indemnified party, at the indemnifying party’s expense for reasonable out-of-pocket costs. The indemnifying party may not settle any claim without the indemnified party’s prior consent if settlement would require the indemnified party to admit fault or take or refrain from taking any action (other than relating to use of the Services, when Cofactor is the indemnifying party). The indemnified party may participate in a claim with its own counsel at its own expense.
14.4. Mitigation. In response to an actual or potential infringement or misappropriation claim or otherwise relating to violation of intellectual property rights, if required by settlement or injunction or as Cofactor determines is necessary to avoid material liability, Cofactor may at its option: (a) procure rights for Customer’s continued use of the applicable Service; (b) replace or modify the allegedly infringing portion of the applicable Service to avoid infringement or misappropriation without reducing the Service’s overall functionality; or (c) terminate the affected Order and refund to Customer any pre-paid, unused fees for the terminated portion of the Term.
14.5. Exceptions. Cofactor’s obligations in this Section 15 do not apply: (a) to infringement or misappropriation resulting from Customer’s modification of Services or use of Services in combination with items not provided by Cofactor (including Third-Party Platforms) or in violation of Section 2.3 (Restrictions); (b) to infringement resulting from Software other than the most recent release; (c) to unauthorized use of Services; or (d) if Customer settles or makes any admissions about a claim without Cofactor’s prior consent.
14.6. Exclusive Remedy. This Section 15 sets out Customer’s exclusive remedy and Cofactor’s entire liability regarding infringement or misappropriation of third-party intellectual property rights.
15. Confidentiality
15.1. Definition. “Confidential Information” means information disclosed to the receiving party (“Recipient”) under this Agreement that is designated by the disclosing party (“Discloser”) as proprietary or confidential or that should be reasonably understood to be proprietary or confidential due to its nature and the circumstances of its disclosure. Cofactor’s Confidential Information includes but is not limited to Cofactor IP, the terms and conditions of this Agreement, and any technical or performance information about the Software and Services.
15.2. Obligations. As Recipient, each party will: (a) hold Confidential Information in confidence and not disclose it to third parties except as permitted in this Agreement or BAA; and (b) only use Confidential Information to fulfill its obligations and exercise its rights in this Agreement. At Discloser’s request, Recipient will delete all Confidential Information, except, in the case where Cofactor is the Recipient, Cofactor may retain the Customer’s Confidential Information to the extent required to continue to provide the Services and perform this Agreement. Recipient may disclose Confidential Information to its employees, agents, contractors, and other representatives having a legitimate need to know (including, for Cofactor, the subcontractors referenced in Section 20.9) provided it remains responsible for their compliance with this Section 16 and they are bound to confidentiality obligations no less protective than this Section 16.
15.3. Exclusions. These confidentiality obligations do not apply to information that Recipient can document: (a) is or becomes public knowledge through no breach of confidentiality obligations; (b) it rightfully knew or possessed prior to receipt under this Agreement without an obligation of confidentiality; (c) it rightfully received from a third party without breach of confidentiality obligations; or (d) it independently developed without use of, or reference to, Confidential Information. In the event of a conflict between this Section 16, and Section 5 of this Agreement or Section 16 and the BAA, the BAA and Section 5 will control.
15.4. Remedies. Unauthorized use or disclosure of Confidential Information may cause substantial harm for which damages alone are an insufficient remedy. Each party may seek appropriate equitable relief, in addition to other available remedies, for breach or threatened breach of this Section 16.
15.5. Required Disclosures. Nothing in this Agreement prohibits either party from making disclosures, including of Customer Data and other Confidential Information, if required by Law, subpoena, or court order, provided (if permitted by Law) it notifies the other party in advance and cooperates in any effort to obtain confidential treatment.
16. Publicity
Neither party may publicly announce that the parties have entered into this Agreement, except with the other party’s prior consent or as required by Laws.
17. General Terms
17.1. Assignment. Neither party may assign this Agreement without the prior consent of the other party, except that either party may assign this Agreement in connection with a merger, reorganization, acquisition, or other transfer of all or substantially all its assets or voting securities to the other party involved in such transaction. Any non-permitted assignment is void. This Agreement will bind and inure to the benefit of each party’s permitted successors and assigns.
17.2. Governing Law, Jurisdiction and Venue. This Agreement is governed by the laws of the State of Delaware and the United States without regard to conflicts of laws provisions that would result in the application of the laws of another jurisdiction and without regard to the United Nations Convention on the International Sale of Goods. The jurisdiction and venue for actions related to this Agreement will be the state and United States federal courts located in Delaware, and both parties submit to the personal jurisdiction of those courts. No action, regardless of form, may be brought by Customer hereunder more than two (2) years after the date such claim arose.
17.3. Attorneys’ Fees and Costs. The prevailing party in any action to enforce this Agreement will be entitled to recover its attorneys’ fees and costs in connection with such action.
17.4. Notices. Except as set out in this Agreement, any notice or consent under this Agreement must be in writing and will be deemed given: (a) upon receipt if by personal delivery; (b) upon receipt if by certified or registered U.S. mail (return receipt requested); or (c) one day after dispatch if by a commercial overnight delivery service. Notices may not be sent via email unless otherwise expressly permitted elsewhere in this Agreement. Either party may update its address with notice to the other party. Cofactor may also send operational notices to Customer by email or through the Services. Notices to Cofactor shall be sent to Attn: General Counsel, Cofactor, 215 N Peoria Street, Ste 8, Chicago, IL, 60607, with a copy to amtantravahi@cofactorai.com. Notices to Customer shall be sent to the address in the Order.
17.5. Entire Agreement. The Agreement and all Orders, Exhibits, Schedules, and the Policies, is the parties’ entire agreement regarding its subject matter and supersedes any prior or contemporaneous agreements regarding its subject matter. In this Agreement, headings are for convenience only and “including” and similar terms are to be construed without limitation. This Agreement may be executed in counterparts (including electronic copies and PDFs), each of which is deemed an original and which together form one and the same agreement.
17.6. Amendments. Any amendments, modifications, or supplements to this Agreement must be in writing and signed by each party’s authorized representatives or, as appropriate, agreed through electronic means provided by Cofactor. Nonetheless, with notice to Customer, Cofactor may modify the Policies to reflect new features or changing practices, but the modifications will not materially decrease Cofactor’s overall obligations during the Term. The terms in any Customer purchase order or business form will not amend or modify this Agreement and are expressly rejected by Cofactor; any of these Customer documents are for administrative purposes only and have no legal effect.
17.7. Waivers and Severability. Waivers must be signed by the waiving party’s authorized representative and cannot be implied from conduct. If any provision of this Agreement is held invalid, illegal, or unenforceable, it will be limited to the minimum extent necessary so the rest of this Agreement remains in effect.
17.8. Force Majeure. Neither party is liable for any delay or failure to perform any obligation under this Agreement (except for a failure to pay fees) due to events beyond its reasonable control, such as a strike, blockade, war, pandemic, act of terrorism, riot, Internet or utility failures, refusal of government license, or natural disaster (“Force Majeure Events”).
17.9. Subcontractors. Cofactor may use subcontractors and permit them to exercise Cofactor’s rights, but Cofactor remains responsible for their compliance with this Agreement and for its overall performance under this Agreement.
17.10. Independent Contractors. The parties are independent contractors, not agents, partners, or joint venturers.
17.11. Export. Customer will comply with all relevant U.S. and foreign export and import Laws in using any Service. Customer: (a) represents and warrants that it is not listed on any U.S. government list of prohibited or restricted parties or located in (or a national of) a country that is subject to a U.S. government embargo or that has been designated by the U.S. government as a “terrorist supporting” country; (b) agrees not to access or use Services in violation of any U.S. export embargo, prohibition, or restriction; and (c) will not submit to the Services any information controlled under the U.S. International Traffic in Arms Regulations.
18.12. Open Source. The Software may incorporate third-party open source software (“OSS”). To the extent required by the OSS license, that license will apply to the OSS on a stand-alone basis instead of this Agreement.
17.13. Government End-Users. Elements of the Services are commercial computer software. If the user or licensee of the Services is an agency, department, or other entity of the United States Government, the use, duplication, reproduction, release, modification, disclosure, or transfer of the Services or any related documentation of any kind, including technical data and manuals, is restricted by the terms of this Agreement in accordance with Federal Acquisition Regulation 12.212 for civilian purposes and Defense Federal Acquisition Regulation Supplement 227.7202 for military purposes. The Services were developed fully at private expense. All other use is prohibited.
17.14. Conflicts in Interpretation. If there are inconsistencies or conflicts between the terms of the body of this Agreement, any Order, and the terms of any Schedules, Exhibits, attachments, addenda, Policies, Documentation, and other documents attached to or incorporated by reference in this Agreement, the order of precedence is as follows: (a) the terms contained in the body of this Agreement; (b) the terms of the Schedules, Exhibits, attachments, addenda, and Policies to this Agreement; and (c) the Documentation.
Exhibit A: Definitions
1.1. “Affiliate” means an entity directly or indirectly owned or controlled by a party, where “ownership” means the beneficial ownership of 50% or more of an entity’s voting equity securities or other equivalent voting interests and “control” means the power to direct the management or affairs of an entity.
1.2. “Customer Data” means any data or information that: (a) Customer (including its Users) submits to the Services, including from Third-Party Platforms; and (b) is Processed by Cofactor to provide the Services to Customer. Customer Data may include information generated from the use of the Services, such as technical logs, data, and learnings about Customer’s use of the Services.
1.3. “Customer Systems” means Customer’s hardware, software, other technology, and infrastructure that Customer is required to provide and maintain in order for Customer to access and use the Services.
1.4. “Documentation” means the then-current version of Cofactor’s usage guidelines and standard technical documentation for the Services that Cofactor makes generally available to its customers that it provides the applicable Services to.
1.5. “Exhibit” means an exhibit attached to the Agreement.
1.6. “HIPAA” means the Health Insurance Portability and Accountability Act of 1996, as amended by the Health Information Technology for Economic and Clinical Health (HITECH) Act, and the Privacy, Security, Breach Notification, and Enforcement Rules at 45 CFR Part 160 and Part 164, each as amended from time to time.
1.7. “Laws” means all applicable relevant local, state, federal and international laws, regulations and conventions, including those related to data privacy and data transfer, international communications, and export of data, including Customer Personal Data and Customer Personal Information.
1.8. “Order” means an order that describes the Services being purchased by Customer that is executed by the parties and references this Agreement.
1.9. “Policies” means the SLA and Support Policy.
1.10. “Process” means to collect, access, use, disclose, transfer, transmit, store, host, or otherwise process.
1.11. “Schedule” means a document that adds and/or adjusts certain terms of the Agreement as they apply to the purchase of one or more Services. Each Schedule is governed by and a part of the terms of this Agreement.
1.12. “Service” or “Services” means the then-current version of Cofactor’s proprietary cloud service (“Subscription Services”) and other professional, consulting, developmental, training, educational, or advisory services provided by Cofactor as identified in the applicable Order (“Professional Services”) that are identified in the relevant Order. Subscription Services includes the Software and Documentation for the Subscription Services.
1.13. “SLA” means the then-current version of Cofactor’s Service Level Agreement applicable to the Services. The version in effect as of the Agreement Effective Date is attached as Exhibit C.
1.14. “Software” means any software, scripts, or other code required by Cofactor to operate a Service.
1.15. “Term” includes the Initial Term and any Renewal Term during which Customer’s subscription to access and use the Subscription Services or the Professional Services is in effect, as identified in the applicable Order and pursuant to this Agreement.
1.16. “Support” means support for the Services as described in the Support Policy.
1.17. “Support Policy” means the then-current version of Cofactor’s customer support policy with respect to the Services. The version in effect as of the Agreement Effective Date is attached as Exhibit D.
1.18. “Third-Party Platform” means any third-party platform, add-on, service, or product not provided by Cofactor that Customer elects to integrate or enable for use with any Service.
1.19. “Updates” means any updates, modifications, or bug fixes to the Services or Documentation that Cofactor provides free of additional charge to its customers using a Service.
1.20. “Upgrades” means additions, enhancements, upgrades, new services, or modules that include new features and substantial increases in functionality to the Services that Cofactor makes available to its customers for an additional fee.
1.21. “User” means any employee or contractor of Customer or its Affiliates that Customer allows to use the Services on Customer’s behalf.
Exhibit B: Business Associate Agreement
This Business Associate Agreement (“BAA”) is entered into by and between Cofactor AI, Inc. (“Business Associate”) and Customer (“Covered Entity”) and is effective (“Effective Date”) as of the effective date of the Order (“Order”) into which it is incorporated. Business Associate and Covered Entity may be referred to herein collectively as the “Parties” or individually as a “Party”. This BAA is incorporated into and made part of the Master Subscription & Services Agreement (“Agreement”).
WHEREAS, Business Associate provides certain Services to Covered Entity pursuant to the Order and Agreement;
WHEREAS, in connection with these Services, Business Associate may create, receive, maintain, or transmit PHI from, to, or on behalf of, Covered Entity, which PHI is subject to certain protections under the HIPAA Rules; and
WHEREAS, this BAA defines the rights and responsibilities of each Party with respect to PHI exchanged pursuant to this BAA and the Agreement;
NOW, THEREFORE, for good and valuable consideration, the receipt and sufficiency of which are hereby acknowledged, the Parties agree as follows:
1. Scope; Definitions
(a) This BAA shall only be effective to the extent Business Associate has agreed to perform Services that require Business Associate to create, receive, maintain, or transmit PHI pursuant to the Agreement.
(b) All terms used but not defined herein shall have the meaning set forth in the HIPAA Rules or the Agreement, as applicable.
(c) The following capitalized terms are specifically defined as follows:
(i) “Business Associate” has the same meaning as the term “business associate” at 45 CFR 160.103, and, subject to Section 1(a), in reference to the Party to this BAA, shall mean Cofactor AI, Inc.
(ii) “Covered Entity” has the same meaning as the term “covered entity” at 45 CFR 160.103, and in reference to the Party to this BAA, shall mean Covered Entity named in the preamble.
(iii) “Breach” has the meaning given to the term “breach” at 45 C.F.R. 164.402, as applied to Unsecured PHI created, received, maintained or transmitted by Business Associate from or on behalf of Covered Entity.
(iv) “Electronic Protected Health Information” or “ePHI” has the same general meaning as the term “electronic protected health information” at 45 C.F.R. § 160.103, but for purposes of this BAA is limited to the ePHI created, received, transmitted, or maintained by Business Associate for or on behalf of Covered Entity.
(v) “HIPAA Rules” means the Health Insurance Portability and Accountability Act of 1996, Pub. L. 104-191, the Health Information Technology for Economic and Clinical Health (HITECH) Act, as incorporated in title XIII of division A and title IV of division B of the American Recovery and Reinvestment Act of 2009 (ARRA), Public Law 111–5, and the Privacy, Security, Breach Notification, and Enforcement Rules at 45 CFR Part 160 and Part 164, each as amended from time to time.
(vi) “Individual” has the same meaning as the term “individual” at 45 CFR § 160.103 and includes a person who qualifies as a personal representative in accordance with 45 CFR § 164.502(g).
(vii) “Protected Health Information” or “PHI” has the same general meaning as the term “protected health information” at 45 C.F.R. § 160.103, but for purpose of this BAA is limited to the PHI created, received, transmitted, or maintained by Business Associate for or on behalf of Covered Entity.
(viii) “Security Incident” has the meaning given to the term “security incident” at 45 C.F.R. § 164.304, as applied to PHI under this BAA.
(ix) “Services” means the services that Business Associate provides to Covered Entity pursuant to the Agreement and any Order thereto.
(x) “Unsecured PHI” has the meaning given to the term “unsecured protected health information” at 45 C.F.R. 164.402, as applied to PHI under this BAA.
(xi) “Unsuccessful Security Incidents” means, without limitation, pings and other broadcast attacks on Business Associate’s firewall, port scans, unsuccessful log-on attempts, denial of service attacks, and any combination of the above, so long as no such incident results in unauthorized access, Use or Disclosure of Covered Entity’s ePHI.
2. Obligations and Activities of Business Associate
(a) Business Associate agrees not to Use or Disclose PHI received or created by Business Associate except as permitted by this BAA, the Agreement, or as Required by Law.
(b) Business Associate agrees to use appropriate safeguards, and to comply with Subpart C of 45 CFR Part 164 with respect to ePHI, to prevent Use or Disclosure of PHI other than as provided for by this BAA, the Agreement, or as Required by Law.
(c) To the extent known to or discovered by Business Associate, Business Associate will promptly report to Covered Entity any Use or Disclosure of PHI not permitted by this BAA, including any Breach of Unsecured PHI as required by 45 C.F.R. §164.410, and any Security Incident of which it becomes aware. Notwithstanding the foregoing, the Parties acknowledge and agree that this Section 2(c) constitutes notice by Business Associate to Covered Entity of the ongoing existence and occurrence or attempts of Unsuccessful Security Incidents for which no additional notice to Covered Entity shall be required. Notifications, if any, will be delivered to contacts identified by Covered Entity pursuant to the Agreement. Business Associate’s obligation to report is not and will not be construed as an acknowledgement of any fault or liability with respect to any Use, Disclosure, Security Incident, or Breach.
(d) Business Associate agrees, in accordance with 45 CFR 164.502(e)(1)(ii) and 164.308(b)(2), if applicable, to obtain from any Subcontractor that creates, receives, maintains, or transmits PHI on behalf of Business Associate pursuant to this BAA and the Agreement, reasonable written assurances that the Subcontractor will adhere to substantially the same restrictions and conditions that apply to Business Associate pursuant to this BAA with respect to such PHI.
(e) To the extent Business Associate maintains a Designated Record Set, Business Associate agrees to make available, at the request of Covered Entity, PHI that is maintained in a Designated Record Set (if any) as necessary to allow Covered Entity to satisfy its obligations under 45 C.F.R. §164.524.
(f) To the extent Business Associate maintains a Designated Record Set, Business Associate agrees to make amendment(s) to PHI maintained in a Designated Record Set (if any), as requested by the Covered Entity, pursuant to 45 C.F.R. §164.526, or take other measures as reasonably necessary to enable Covered Entity to satisfy its obligations under 45 C.F.R. §164.526.
(g) Business Associate agrees to maintain and make available to Covered Entity the information required to provide an accounting of Disclosures, as reasonably necessary to satisfy Covered Entity’s obligations under 45 C.F.R. §164.528.
(h) For clarity, with respect to the forgoing Sections 2(e)-(g), in no case shall Business Associate be responsible for responding directly to any Individual who submits a request to Business Associate pursuant to 45 CFR §§ 164.524 - 164.528; provided, however, that Business Associate shall promptly forward such requests to Covered Entity in accordance with Sections 2(e)-(g).
(i) To the extent that Business Associate is to carry out one or more of Covered Entity’s obligation(s) under Subpart E of 45 CFR Part 164, Business Associate agrees to comply with the requirements of Subpart E that apply to Covered Entity in the performance of such obligation(s).
(j) Business Associate agrees to make its internal practices, books, and records, regarding the Use and Disclosure of PHI created or received by Business Associate for or on behalf of the Covered Entity available to the Secretary for purposes of the Secretary determining compliance with the HIPAA Rules.
3. Permitted Uses and Disclosures by Business Associate
(a) Business Associate may Use or Disclose PHI to perform any and all functions, activities, obligations, and Services as set forth in the Agreement or as Required by Law.
(b) Business Associate may Use PHI for its proper management and administration, or to carry out its legal responsibilities.
(c) Business Associate may Disclose PHI for its proper management and administration, or to carry out its legal responsibilities, provided the Disclosures are (i) Required by Law, or (ii) Business Associate obtains reasonable assurances from the person to whom the information is Disclosed that the information will remain confidential and Used or further Disclosed only as Required by Law or for the purposes for which it was Disclosed to the person, and the person notifies Business Associate of any instances of which it is aware in which the confidentiality of the information has been breached.
(d) Business Associate may provide Data Aggregation services relating to the Health Care Operations of Covered Entity as permitted by 45 C.F.R. § 164.504(e)(2)(i)(B). Business Associate may de-identify PHI in accordance with 45 C.F.R. §§ 164.502(d)(1) and 45 CFR § 164.514(b) and use such de-identified data for Business Associate’s internal and commercial purposes. The parties agree that information so de-identified is no longer PHI. Business Associate owns all right, title and interest in the de-identified health information created under the Agreement and the compilation of de-identified health information created under the Agreement with de-identified health information that Business Associate receives (or creates from data received) from third-party data sources. This paragraph shall survive the termination of the applicable Order, the Agreement, or this BAA.
4. Obligations of Covered Entity
During the Term of this BAA, Covered Entity shall:
(i) Notify Business Associate of any limitations in its Notice of Privacy Practices, to the extent that such limitation may affect Business Associate’s Use or Disclosure of PHI;
(ii) Notify Business Associate of any confidential communication request or restriction to the use or disclosure of PHI that Covered Entity has agreed to in accordance with 45 C.F.R. § 164.522, to the extent that such changes may affect Business Associate’s Use or Disclosure of PHI;
(iii) Notify Business Associate of any changes in, or revocation of, permission by an Individual to Use or Disclose PHI, to the extent that such changes may affect Business Associate’s Use or Disclosure of PHI;
(iv) Not request Business Associate to Use or Disclose PHI in any manner that would not be permissible under the HIPAA Rules if done by Covered Entity (other than as permitted pursuant to Sections 3(b)-(e) above);
(v) Obtain any consent, authorization, or permission that may be required by the HIPAA Rules or any other applicable federal, state, or local laws and/or regulations prior to furnishing Business Associate the PHI pertaining to an Individual. Covered Entity represents and warrants that its notice of privacy practices permits Covered Entity to use and disclose PHI in the manner that Business Associate is authorized to Use and Disclose PHI under the Agreement and this BAA; and
(vi) Comply with all of the HIPAA Rules requirements applicable to Covered Entity. Covered Entity is responsible for implementing appropriate privacy and security safeguards to protect its PHI in compliance with HIPAA. It is Covered Entity’s obligation to not store or process PHI in an online service, or otherwise provide, PHI to Business Associate for performance of Services, until this BAA is effective as to the applicable Services.
5. Term and Termination
(a) Term. The Term of this BAA shall commence on the Effective Date and, except for the rights and obligations set forth in this BAA specifically surviving termination, shall terminate upon the termination or expiration of the Agreement, unless otherwise earlier terminated for cause in accordance with this Section 5.
(b) Termination for Cause. In addition to any termination provisions set forth in the applicable Agreement, either Party may terminate this BAA if such Party determines, in good faith and after reasonable investigation, that the other Party has violated a material term of this BAA, and the breaching Party has failed to cure such material breach or end the violation within thirty (30) days of notice of such alleged breach.
(c) Effect of Termination. Upon termination or expiration of this BAA for any reason, Business Associate shall:
(i) Retain only that PHI which is necessary for Business Associate to continue its proper management and administration or to carry out its legal responsibilities (if any);
(ii) Return to Covered Entity or destroy the remaining PHI that Business Associate still maintains in any form that is not necessary to carry out Section 5(d)(i);
(iii) Continue to use appropriate safeguards and comply with Subpart C of 45 CFR Part 164 with respect to ePHI to prevent Use or Disclosure of the PHI, other than as provided for in this Section 5(d), for as long as Business Associate retains the PHI;
(iv) Not Use or Disclose the PHI retained by Business Associate other than for the purposes for which such PHI was retained and subject to the same conditions set out at Sections 3(b)-(d) which applied prior to termination; and
(v) Return to Covered Entity or destroy the PHI retained by Business Associate when it is no longer needed by Business Associate for its proper management and administration, or to carry out its legal responsibilities.
6. Limitation of Liability
Notwithstanding anything to the contrary set forth herein, the Parties acknowledge and agree that any limitation on either Party’s liability set forth in the Agreement shall apply to limit such Party’s total aggregate liability for all claims arising under or related to this BAA, all Orders, and the Agreement.
7. Miscellaneous
This BAA is governed by, and will be construed in accordance with, the laws of the State that govern the Agreement. Any action relating to this BAA must be commenced within two years after the date upon which the cause of action accrued. This BAA may only be assigned in connection with an assignment of the Agreement. If any part of a provision of this BAA is found illegal or unenforceable, it will be enforced to the maximum extent permissible, and the legality and enforceability of the remainder of that provision and all other provisions of this BAA will not be affected. All notices relating to the Parties’ legal rights and remedies under this BAA will be provided in writing to a Party, will be sent to its address set forth in the Agreement, or to such other address as may be designated by that Party by notice to the sending Party, and will reference this BAA. This BAA may be modified, or any rights under it waived, only by a written agreement executed by the authorized representatives of the Parties. In the event a change in the HIPAA Rules require the Parties to amend this BAA, the Parties agree to negotiate such amendment in good faith, provided that either Party may terminate this BAA upon notice if the Parties are unable to mutually agree upon and execute such amendment.
Exhibit C: Service Level Agreement
The terms of this Service Level Agreement apply with respect to the Services described in Orders.
A. Additional Defined Terms. In addition to capitalized terms used in the Agreement, the capitalized terms in this Service Level Agreement have the following definitions:
a. “Emergency Maintenance” means critical changes to a Service that cannot wait for Scheduled Maintenance including changes that could destabilize the Service if not addressed expeditiously, security related issues, or technical problems that could impact the availability of a Service.
b. “Scheduled Maintenance” means Cofactor’s scheduled routine maintenance for a Service including to fix non-critical errors and implement Service changes including to the Software.
c. “Uptime” means the time a Service is available during each calendar month.
B. Target Uptime. Cofactor will use commercially reasonable efforts to meet or exceed an Uptime of 99.5%.
C. Exclusions. The calculation of Uptime will not include unavailability due to any of the following (collectively “Uptime Exclusions”): (a) Customer’s use of a Service in a manner not authorized in the Agreement, Documentation, or AUP; (b) general Internet problems; (c) Force Majeure Events or other factors outside of Cofactor’s reasonable control; (d) Customer Software, equipment, network connections or other infrastructure; (e) Third-Party Platforms or other third party systems, acts, or omissions; (f) Scheduled Maintenance; or (g) Emergency Maintenance.
D. Service Credits. If a Service fails to meet Uptime in a particular calendar month, Cofactor verifies such failure, and Customer makes a request for credit within 30 days after the end of such calendar month, Customer will be entitled to a credit based on the monthly fees due for the affected Service in such calendar month, which will be calculated as follows (“Service Credit”):
- Uptime of 98.00% to 99.49%: Service Credit of 5% of calendar monthly fees
- Uptime of 96.00% to 97.99%: Service Credit of 7% of calendar monthly fees
- Uptime below 96.00%: Service Credit of 10% of calendar monthly fees
Cofactor will apply each Service Credit to Customer’s next invoice if Customer’s account is fully paid up and there are no outstanding payment issues or disputes. Customer will not receive any refund for any unused Service Credits. Service Credits in any calendar month will not exceed 10% of the calendar monthly fees due. Service Credits constitute liquidated damages and are not a penalty. Service Credits are Customer’s exclusive remedy, and Cofactor’s entire liability, for Cofactor’s failure to meet the Uptime.
Exhibit D: Support Policy
Cofactor will remotely provide assistance to Customer with the resolution of problems with the Services described in Orders in accordance with the following terms.
A. Support Hours. Support is provided during Cofactor’s normal business hours (9AM to 6PM Central Time, not including Saturdays and Sundays and holidays) (“Support Hours” and “Support Days” respectively). Cofactor’s holidays include: New Year’s Day, Martin Luther King Jr. Day, Presidents’ Day, Memorial Day, Juneteenth, Independence Day, Labor Day, Columbus Day, Veterans Day, Thanksgiving Day, Christmas Day.
B. Incident Submission and Customer Cooperation. Customer shall identify, investigate and attempt to resolve all problems with the Service (each an “Incident”) prior to contacting Cofactor, and should only escalate Customer problems to Cofactor after exhausting all reasonable means available to Customer to resolve the Incident, including Documentation and training. In the event Customer is not able to resolve the Incident, it should be escalated to Cofactor Support using the following process. Customer may report Incidents by contacting Cofactor at the applicable email or phone number specified below. Customer shall report all Priority Level 1 Incidents by phone and email to the phone number and email address set forth below. All other Incidents shall be reported by email. Customer agrees to provide Cofactor with reasonable access to all necessary personnel to answer questions about any Incidents reported by Customer regarding the Service. Cofactor does not guarantee performance of the Services if such access is not provided by Customer. When reporting an Incident, Customer shall provide information as reasonably required for Cofactor which includes the following information to Cofactor regarding the Incident:
- Date Observed
- Start time of Incident
- Feature
- Client OS
- Client Browser type and Version
- Aspects of the Service that are unavailable or not functioning correctly
- Error Code or Wording of any message displayed by the Service and frequency
- Relevant log files or data
- List of steps Customer has used to reproduce Incident
- Repeatable by Others: Yes/No
- Additional Info/Attachments
C. Primary Contacts. Customer shall appoint 2 individuals to serve as primary contacts between Customer and Cofactor and all of Customer’s support inquiries shall be initiated through these contacts.
D. Incident Response. Cofactor’s Support personnel will assign a priority level (“Priority Level”) to each Incident and seek to provide responses in accordance with the following. For all Priority Levels, contact Cofactor at 956-340-7173 and compliance@cofactorai.com.
- Priority Level 1 (Target Response Time: 2 Business Hours). The Service is unavailable such that Customer’s business is critically affected and a Workaround is unavailable. A “Workaround” means a temporary modification or change to the Service that circumvents or effectively mitigates the adverse effects of an Incident so that the Service performs in accordance with the applicable Documentation.
- Priority Level 2 (Target Response Time: 1 Business Day). An Incident where the Service is responding and functional but performance is degraded and potentially has severe impact on operation of the Service for multiple Users.
- Priority Level 3 (Target Response Time: 5 Business Days). Non-critical issue; no significant impact on performance of the Service but User experience may be affected.
- Priority Level 4 (Target Response Time: 20 Business Days). No impact to the functionality of Service or to Customer’s business. This includes requests about the Service such as an enhancement, information, documentation, and how-to questions.
E. Support by Customer. Customer will provide all support to its Users and will manage and perform all communication with its customers. At no time will Cofactor be expected to communicate directly with Customer’s customers.
F. Exclusions. Cofactor will have no obligation to provide Support to the extent an Incident arises from: (a) use of the Services, including, without limitation, in a manner not consistent with the Documentation, AUP or specifications; (b) use of the Services in conjunction with systems, products or components not reasonably anticipated to be used with the Services or a part thereof; (c) modifications to the Services that were neither made by or authorized by Cofactor; or (d) Third-Party Platforms or other third-party systems.
