← Legal

SaaS Subscription Agreement

Last Update Date: 3 September 2026

This is the agreement Customer accepts when creating a Dental Maverick AI account. It is published here under Section 16.3, and prior versions are retained and available on request to privacy@dentalmaverick.ai. The Service Level Agreement is incorporated into it by reference; the Business Associate Agreement is executed separately and operates independently.

  1. 1. Purpose
  2. 2. Definitions
  3. 3. Access, Licence and Use
  4. 4. Ownership and Processing of Customer Data
  5. 5. Customer Obligations Regarding Data
  6. 6. Protection and Processing of Personal Data
  7. 7. Materials
  8. 8. Acceptable Use Policy (AUP)
  9. 9. Availability and Support
  10. 10. Fees, Expenses and Payments
  11. 11. Treatment of Confidential Information
  12. 12. Representations, Warranties and Disclaimers
  13. 13. Limitation of Liability
  14. 14. Indemnification
  15. 15. Term and Termination
  16. 16. Miscellaneous
  17. Annex 1 — Technical and Organisational Measures (TOM)

This Software as a Services (SaaS) Subscription Agreement (“SSA”) is entered into by and between SanctifAI Dental Inc. dba Dental Maverick AI, a Delaware corporation, located at 7415 Southwest Pkwy, Bldg 6, Austin TX 78735, USA (“Company”) and the individual or business entity that accepts this SSA (“Customer”). Each Company and Customer hereinafter shall be referred to individually as “Party” and collectively as “Parties”. This SSA, its Annex and the Service Level Agreement published at https://dentalmaverick.ai/legal/sla.html (the "SLA"), which is incorporated into this SSA by reference, shall collectively constitute the "Agreement" and become effective upon clicking “I agree to the Terms” (or similar) through Company’s online enrollment process (“Effective Date”).

By accepting this SSA, Parties signify their intent to be contractually bound by the terms and conditions set forth herein, in consideration for the mutual promises set forth below. The paid subscription plan selected by Customer through the Platform, including its tier, billing interval, pricing, and billing terms (a "Plan"), also forms part of the Agreement.

This Agreement is binding on the individual or entity identified through Company’s online enrollment process as the Customer or the Customer's representative, who, by clicking “I agree to the Terms” (or similar), certifies that: (i) they have the legal authority to enter into this Agreement and to bind their organization or the entity they represent to its terms; (ii) the registered email address fully identifies the Customer or the entity they represent; and (iii) their acceptance constitutes a valid electronic signature of all the terms contained herein.

1. Purpose

This SSA establishes the general terms and conditions applicable to the access and use of Company's Platform through Software as a Service (SaaS) Subscriptions by Customer and its Authorized End Users, as will be detailed herein and in its Annex: Technical and Organisational Measures (TOM), and in the Service Level Agreement (SLA), which is published at https://dentalmaverick.ai/legal/sla.html and incorporated into this SSA by reference. Furthermore, Parties acknowledge that the provision of Services involves processing of Protected Health Information (“PHI”); therefore, compliance with the Health Insurance Portability and Accountability Act (“HIPAA”) regulations and protection, security, and privacy of such data, will be strictly governed by the Business Associate Agreement (“BAA”), which constitutes an independent and autonomous regulatory agreement, formalized separately between Parties, and is not incorporated by reference as a commercial Annex to this SSA, but rather operates independently and in parallel.

2. Definitions

Capitalized words and phrases used in all documents constituting the Agreement will be defined in this section, and those not found here will be described in each applicable Annex or in the SLA; these definitions are as follows:

  1. 2.1 Application Documentation” will refer to the manuals, user guides, and technical specifications provided by Company in text and/or graphical documentation, which describe the features, functions and operation of the Platform.
  2. 2.2Application IP” will refer to the Platform, API, Application Documentation, and all copyrights, patents, trademarks, trade secrets, and other intellectual property or industrial property rights owned by Company, which, through this SSA, grants Customer only the limited and revocable right to access and use the Application's functionalities, with authorization to allow access and operational use by its Authorized End Users.
  3. 2.3 Application Programming Interface” or “API” will mean any application programming interface provided by or on behalf of Company to enable Customer and Authorized End Users to access and use the Platform in accordance with this SSA and its Annexes.
  4. 2.4 Platform” will refer to Company's “Dental Insurance Verification and Automation” solution, which comprises various software applications and tools and is hosted on servers owned, controlled or on behalf of Company.
  5. 2.5 Web Interface” will refer to the website or websites through which Customer’s Authorized End Users may access the Platform in accordance with the terms of this SSA and its Annexes.
  6. 2.6 “Software as a Service (SaaS) Application, or Services, or SaaS Services/Solution will refer to the Non-exclusive and non-transferable access and use of Company's software platform via the Internet, including APIs, modules, updates, and corresponding support.
  7. 2.7 Authorized End User” will refer, collectively, to any individual authorized by Customer to access or use Company’s Application or SaaS Platform, in accordance with the rights granted to Customer under this SaaS Service Agreement. Authorized End Users will be classified by Customer as either Administrator(s) or Member(s). Administrator(s) will be Customer’s representative(s), authorized to designate Members/Authorized Users, manage account credentials and subscription plans. Administrator(s) may also receive legal or suspension notices on behalf of Customer, without prejudice to Customer’s right to be notified directly, where applicable.
  8. 2.8 Customer Materials” will refer to logos, trademarks, trade names, marketing templates or content (resources) provided by Customer to Company. These materials are provided to Company (granting a limited license to use them pursuant to Section 7.2) solely to enable it to provide the Services, customize Customer's account interface, identify Customer as a user for promotional or reference purpose, or generate results as part of the Service's functionality.
  9. 2.9 Confidential Information” will refer to all written, visual, and oral information disclosed by either Party to the other, related to either Party that has been identified as confidential, or that by the nature of the circumstances surrounding disclosure, ought reasonably to be treated as confidential. Notwithstanding the foregoing, for the purposes of this SSA and all documents incorporated herein, the following shall be considered Confidential Information of Company: Company’s Application Documentation, Application’s IP, API, source code, Platform architecture, proprietary methodologies, performance indicators, future software development plans, and other technology and information to which Company holds proprietary rights, as well as the rates and prices negotiated with Customer (which may differ from the public price). To avoid any doubt, while PHI is inherently confidential, it is specifically excluded from this definition of Confidential Information and the general provisions of Section 11 of this SSA in order to comply with HIPAA regulations, which stipulate that the duty to protect health information never expires due to commercial time and remains protected even if it is leaked. Therefore, protection, privacy, and security of all PHI will be governed exclusively and strictly by the specific terms of the BAA.
  10. 2.10 “Service Level Agreements (SLAs)will refer to the Service Level Agreement published by Company at https://dentalmaverick.ai/legal/sla.html and incorporated into this SSA by reference, which specifies Company's measurable availability metrics, performance, quality of the Service, and technical support commitments.
  11. 2.11 “Plan” will refer to the paid subscription plan selected by Customer through the Platform, including its tier, features, usage limits, billing interval, and Fees, as displayed on the Platform's billing page and in the checkout flow at the time of purchase, and as further described in Section 10.
  12. 2.12Technical and Organisational Measures” “TOM” will refer to the specific security protocols, technical safeguards, and operational measures implemented by Company to protect Customer Data and Personal Data, as detailed in an Annex to this SSA. TOM includes, but is not limited to, encryption standards, access controls, and compliance criteria. Parties acknowledge that TOM serves to comply with regulatory requirements, including Annex II of the Standard Contractual Clauses (SCCs). Notwithstanding the foregoing, with respect to processing of PHI, mandatory security measures and protocols set forth in the BAA shall strictly prevail over TOM. Measures described in the TOM shall align with, and remain legally subordinate to the BAA, ensuring continued compliance with HIPAA regulations, as such regulations may be amended, updated, or supplemented from time to time.
  13. 2.13 "Business Associate Agreement" or "BAA" will refer to a separate legal agreement, entered into independently between the Parties, intended to ensure compliance with the Health Insurance Portability and Accountability Act (HIPAA) and related U.S. federal regulations concerning health privacy. Parties acknowledge that the BAA does not constitute a standard Annex to this SSA, but rather a legally distinct and superseding document that exclusively governs the protection, privacy, and processing of PHI.
  14. 2.14 Protected Health Information” or “PHI” will refer to any individually identifiable health information, including medical history, X-rays, and patient demographic data, that Company (acting as Business Associate or Data Processor) creates, receives, maintains, or transmits on behalf of Customer strictly for purpose of providing Services. Both Parties acknowledge that PHI is heavily regulated under U.S. federal law (HIPAA) and its processing is strictly governed by the BAA.
  15. 2.15 “Personal Data”, “Personally Identifiable Information” or “PII” will refer to any personal information of Customer or Customer’s Authorized End Users (such as names, email addresses, and account credentials) provided solely for the purpose of managing accounts, accessing, and using Company's IP Platform, as defined in applicable Privacy or Data Protection Laws (whether GDPR, CCPA or other applicable regulations). To the extent that any PII is linked to a patient, medical history, or the provision of healthcare services, such data shall be classified, governed, and treated exclusively as PHI under BAA, rather than standard PII under this SSA.
  16. 2.16 “Customer Data” will refer to all information and data that Customer and/or Customer's Authorized End Users upload, provide, process, or store, through Company's SaaS Platform. This term encompasses raw information, logs, transactions, operational data, activity logs, Personal Data (PII) and, specifically, PHI. The purpose of processing this Customer Data by SaaS Platform is to generate value, analytics, or functionality for Customer. While all Customer Data is subject to the security, confidentiality, and ownership provisions of this SSA, protection, processing, return, and destruction of any Customer Data that constitutes PHI will be governed strictly by the terms of the BAA.

3. Access, Licence and Use

  1. 3.1 Company Ownership. Customer acknowledges that Company and Company’s licensors are the sole and exclusive owners of all rights, title, and interest in and to the Services, the SaaS Application, the underlying software, source code, interfaces, associated Documentation, updates, underlying ideas, and all related Intellectual Property (IP), Company's pre-existing IP, and any improvements or modifications to the Services. This SSA grants Customer a license to access and use the Services, but does not transfer ownership of the Service or any of the elements described in the preceding paragraph, but rather a limited and revocable right of use.
  2. 3.2 Retained Rights. As between the Parties, subject to the rights granted in this SSA, Company retains all right, title and interest in and to the Application IP and its components, and Customer acknowledges that it neither owns nor acquires any additional rights not expressly granted by this SSA. Customer further acknowledges that Company retains their rights to use the Application IP for any purpose in Company’s sole discretion.
  3. 3.3 Application Documentation License. Subject to the terms and conditions contained in this SSA, Company grants the Customer a limited, non-exclusive, non-transferable, non-sublicensable, and revocable license to access and use the Services or Application SaaS or Documentation, solely for Customer's business purposes and to provide Services to its Authorized End Users in connection with their access to and use of this Platform. The license granted to Customer and the services provided to Authorized End Users are limited and conditioned on the Plan selected by Customer, including its features and usage limits.
  4. 3.4 Provision of Access. The right of access and use granted by Company to Customer in the preceding clause implies that Customer may access the features and functions of the Platform (including without limitation, through any APIs that may be provided by Company in connection with the same) during the Term of this SSA and all the documents constituting the Agreement, solely for access and use by Authorized End Users in accordance with this SSA and the Plan selected by Customer. Company shall provide to Customer the necessary passwords and network links or connections to allow Customer to access the Platform. Company shall also provide Customer the Application Documentation, if required, to be used by Customer in accessing and using the Platform.
  5. 3.5 Authorized End User Access to Services. Customer will ensure that Authorized End Users are subject to a binding and enforceable contractual agreement that, by its terms, provides the same or greater protection for Company’s Confidential Information and the Application's IP than that stipulated in this SSA. Furthermore, Customer shall ensure that Authorized End Users are aware of the provisions of this SSA and all documents constitute the Agreement applicable to their use of Company’s Platform IP and shall guarantee their full compliance with such provisions. Customer acknowledges and agrees that, as between Customer and Company, Customer shall be responsible for all acts and omissions of Authorized End Users, and any act or omission of an Authorized End User that constitutes a breach of this SSA or any documents that constitute the Agreement shall be deemed a breach by Customer.
  6. 3.6 Usage Restrictions (Anti-Piracy and Express Prohibition). Customer will not, and shall ensure that all Authorized End Users do not:
    1. Copy or duplicate any of the Application IP;
    2. Decompile or disassemble the Application IP, or reverse engineer or otherwise attempt, to obtain or perceive the source code from which any software component of any of the Application IP is compiled or interpreted, or apply any other process or procedure to derive the source code of any software included in the Application IP, or attempt to do any of the foregoing, and Customer acknowledges that nothing in the Agreement will be construed to grant Customer any right to obtain or use such source code;
    3. Modify, alter, tamper with or repair any of the Application IP, or create any derivative product from any of the foregoing, or attempt to do any of the foregoing, except with the prior written consent of Company;
    4. Interfere or attempt to interfere in any manner with the functionality or proper working of any of the Application IP;
    5. Remove, obscure, or alter any notice of any intellectual property or proprietary right appearing on or contained within any of the Application IP;
    6. Assign, license, sublicense, sell, resell, lease, rent or distribute access to the Application IP to third Parties or otherwise transfer or convey, or pledge as security or otherwise encumber, Customer’s rights under Sections 3.1 and 3.2.
    7. Use the SaaS Application for illegal purposes including not to store or transmit illegal material. Customer will ensure that its use of any of the Application IP complies with all applicable laws, statutes, regulations or rules, including any export and import requirements and will not use or compile any of the Application IP for the purpose of any illegal activities;
    8. Combined use of the SaaS Application with other software, hardware, or technology not provided by Company;
    9. Build a competitive product or service or use the Service to develop a product or service that competes with Company's Service;
    10. Conduct security testing (such as pen testing) without prior written consent from Company; and
    11. Violate the Acceptable Use Policy (AUP) detailed in Section 8 of this SSA.

    Customer will comply with the Service Documentation and any reasonable additional written requirements provided by Company to Customer regarding the security or integrity of the Platform.

4. Ownership and Processing of Customer Data

  1. 4.1 Data Ownership. Customer is the sole and exclusive owner of Customer Data as well as it is of its pre-existing Intellectual Property and retains all rights, title, and interest therein. Company shall only have a limited right to access, host, store, transmit, display, process, and use Customer Data (including Customer's Authorized End Users) to the extent necessary to provide the Services in accordance with the terms of this Service Agreement (SSA) and all documents constituting the Agreement.
  2. 4.2 Customer Responsibility. Customer is solely responsible for the legality, reliability, accuracy, quality, and integrity of Customer Data and for obtaining all necessary permissions and consents for Company to process such Data within the terms of the provision of the Services set forth in this SSA and all documents constituting the Agreement.
  3. 4.3 Limited License Granted to Company. Customer grants Company a limited, non-exclusive, non-transferable worldwide, royalty-free license to host, store, process, transmit, and display Customer Data, solely to the extent necessary to provide the Services and fulfill its obligations under this SSA.
  4. 4.4 Use of Aggregated and Anonymized Data. Without prejudice to Customer's proprietary data rights recognized in this SSA, Customer grants Company a perpetual and irrevocable license to collect, use, and disclose aggregated or anonymized data derived from the use of Company's SaaS Application and the operational performance of the Services (including the improvement of the SaaS Application), so that Company may use such data solely for business purposes, benchmarking, statistical analysis, and for the improvement and development of products and services, provided that such information does not individually identify Customer or Customer’s Authorized End Users, except for patient medical data considered PHI, which is strictly protected and governed by the BAA. Company is strictly prohibited from using PHI to train, improve, or adjust Artificial Intelligence models. Therefore, no license or permission is granted to Company to use such data for AI training purposes, even if the PHI has been aggregated, anonymized, or de-identified.
  5. 4.5 Security Measures. Company will maintain industry standard technical and organizational security measures (including encryption and backups) designed to protect Customer Data against unauthorized destruction, loss, alteration, disclosure, and access. These measures are formally set forth in the Technical and Organisational Measures Annex (TOM) to this SSA, and will be detailed in Company’s Information Security Policy available at https://dentalmaverick.ai/legal/security.html.

    Notwithstanding the foregoing, where Customer Data involves PHI, Parties acknowledge that the applicable security measures shall be those established in the BAA, which must strictly align with the mandatory safeguards under HIPAA, as such regulations may be amended from time to time.

  6. 4.6 Security Incident Notification. Company will notify Customer without undue delay and no later than seventy-two (72) hours after confirmation of any unauthorized access, use, alteration, or disclosure of Customer Data (a "Security Incident"). Company will reasonably cooperate with Customer to mitigate the impact of the Incident and comply with regulatory notification requirements. Except in the event of a Security Incident involving PHI, which shall be notified to Customer strictly within forty-eight (48) hours of its discovery, as established in the BAA.
  7. 4.7 Post-Termination Data Export. Upon termination of this SSA, Company will make Customer Data available for download in an industry-standard format (e.g., CSV, JSON) for a period of thirty (30) calendar days (“Grace Period”). Notwithstanding the foregoing, return, extraction, or transfer of any PHI shall be governed strictly by procedures and timelines set forth in the BAA.
  8. 4.8 Post-Termination Deletion (Purge). After the Grace Period ends, Company will have no obligation to retain Customer Data and will securely delete or anonymize such Data from all production systems, backups, and archives, unless its retention is required by applicable law. With respect to any PHI, Company shall securely destroy or return all such data in strict compliance with BAA and HIPAA regulations, prioritizing the BAA's destruction protocols over any standard anonymization practices. Company will provide certification of such deletion upon Customer's request.
  9. 4.9 Disclaimer of Liability. Company will not be liable for the loss or destruction of Customer Data upon Termination of the SSA if Customer does not export it during the Grace Period.

5. Customer Obligations Regarding Data

  1. 5.1 Consent to and Acceptance of the Privacy Policy. Customer represents and warrants that they have read and agree or consent to Company's Privacy Policy, available for review at the following address on the corporate website: https://dentalmaverick.ai/legal/privacy.html, and understands that this policy governs the collection and use of data related to Customer's use of the Service, including, but not limited to, registration, support, and diagnostic data.
  2. 5.2 Consent to Tracking Technologies. Customer agrees that Company may use cookies, pixels, beacons, or other tracking technologies to deliver and provide the Services and measure the performance of its SaaS Platform and/or the user experience. Company’s current Cookie Policy is available at https://dentalmaverick.ai/legal/cookies.html. If Customer does not consent to the provisions of the preceding paragraph, they may not be able to access and use all of Company’s Services.
  3. 5.3 Guarantee of Legality of Content. Customer warrants that Customer’s Data, as uploaded or transmitted to the Service, does not violate any law, regulation, or Third-Party rights (including intellectual property or privacy rights), and does not contain illegal or defamatory material.
  4. 5.4 Guarantee of Consent. Customer warrants that it has obtained all necessary consents and permissions from Authorized End Users for the collection, processing, and transfer of their Personal Data to Company, as required by applicable law. Whenever Personal Data involves or constitutes Protected Health Information, Customer, as Covered Entity, is solely responsible for (i) obtaining valid patient consent where required by applicable law prior to transferring such PHI to Company, (ii) its own notice of privacy practices, (iii) obtaining and retaining any patient authorization required of it by applicable law, and (iv) maintaining supporting documentation of any such consent or authorization. Company processes PHI solely as Business Associate on Customer's behalf and only for the purposes permitted by the BAA. Customer will notify Company without undue delay in writing of any patient restriction or revocation that affects Company's processing of that patient's PHI.
  5. 5.5 Use of Passwords and Credentials. Customer is solely responsible for maintaining the confidentiality and security of all passwords and access credentials for its Authorized End Users and for the account in general. Customer agrees not to share user credentials. It establishes that the perimeter security of access to the account (which is under Customer's control) is its responsibility.
  6. 5.6 Notification of Unauthorized Use. Customer must notify Company without undue delay if it suspects or detects any unauthorized use of its account or any security breach in its systems that may affect the Service. Customer allows Company to take prompt preventive or corrective measures, including forcing a logout, suspending the service, or resetting passwords.
  7. 5.7 Customer Security Settings. Customer is responsible for properly configuring and managing the access controls and roles available on the platform to restrict access to its Data only to Authorized End Users as established in the Application Documentation.
  8. 5.8 Data Format and Requirements. Customer must ensure that the Data uploaded to the Service complies with the format specifications and technical requirements described in the Application Documentation. To the extent Customer or each Authorized End User generates new data, collects, uses, stores, and discloses Third-Party data through or in connection with the use of Company's Application IP, Customer and/or each Authorized End User must accurately and adequately disclose, through a privacy policy or otherwise, how they collect, use, store and disclose data.
  9. 5.9 Personal Data Handling Report. Customer must inform Company if, as a Customer or Customer's Authorized End User, it collects and chooses to provide or upload to Company's IP platform data that could be classified as Personally Identifiable Information (PII) or Personal Data, as defined by the Health Insurance Portability and Accountability Act (HIPAA), General Data Protection Regulation (GDPR), California Consumer Protection Act (CCPA), or other state, federal, or international data privacy legislation or regulation.
  10. 5.10 Procedure in case of handling of Personal Data. If the preceding section applies, and the handling of Personal Data is confirmed within the Service provided by Company, Customer must define the processing of this Personal Data (documented Customer Instructions) in the BAA, in accordance with the Personal Data Protection terms set forth in this SSA and applicable Data Protection laws. Notwithstanding the foregoing, if such Personal Data constitutes PHI, the BAA shall define its processing, and its provisions shall strictly prevail over any provision contained in this SSA.

6. Protection and Processing of Personal Data

  1. 6.1 Functions and Purpose. Parties agree that, with respect to any Personal Data of Customer or its authorized end users processed under this Agreement and the documents constituting it, Customer is the Data Controller and Company is the Data Processor. Company will process such personal data solely for the purpose of providing the Services agreed to in this Agreement and the documents constituting it. Personal Data that Customer or its authorized end users choose to upload to Company's IP Platform for processing, as well as its processing, will be specified in the BAA, and shall be governed exclusively by the BAA where such data is deemed to constitute PHI, strictly subject to HIPAA regulations, notwithstanding any commercial terms specified in this SSA or the Plan.
  2. 6.2 HIPAA Compliance and Incorporation by Reference. Parties acknowledge that Customer Data, or the data of its authorized end users, which will be processed pursuant to this SSA, may include PHI regulated by HIPAA. Parties agree that the protection, privacy, security, and processing of all such PHI shall be strictly governed by the terms of the BAA executed by Parties. The terms of the BAA are hereby incorporated into this SSA by reference and constitute an integral part of the Agreement.
  3. 6.3 Confidentiality and Limited Use. Company undertakes:
    1. Not to process the Personal Data of Customer or its authorized end users for any purpose other than providing the Service.
    2. To Ensure that all personnel authorized to access Personal Data have received appropriate training and are subject to a legal or contractual obligation of confidentiality.
    3. To Process Personal Data only in accordance with Customer's documented instructions, set forth in the BAA.
    4. According to the Section 4.6, to Notify Customer without undue delay of any security breach affecting Personal Data no later than seventy-two (72) hours after Company determines and confirms, following verification, that a security breach has occurred. Except in the event of a Security Incident involving PHI, which shall be notified to Customer strictly within forty-eight (48) hours of its discovery, as established in the BAA.
  4. 6.4 Security (Technical and Organizational Measures). Company will maintain standard technical and organizational security measures for protection of Personal Data; such measures are set forth in the Technical and Organizational Measures Annex (TOM) and may be further described in the BAA. For avoidance of doubt, with respect to the processing of PHI, these measures shall strictly align with, and remain legally subordinate to, mandatory security protocols and HIPAA regulations established in the BAA executed by Parties, which shall strictly prevail in the event of any conflict.
  5. 6.5 Subprocessors. Customer authorizes Company to engage Subprocessors when necessary. If so, Company will maintain an up-to-date list of Subprocessors and ensure that they are subject to written obligations imposing the same level of data protection required by this Section.
  6. 6.6 Assistance to the Data Controller. Company will assist Customer, in fulfilling its obligations under applicable Data Protection Law, including, where necessary, responding to data subject requests, including rights of access, erasure, and others. Basic assistance provided through the Platform's standard features will be included in the paid subscription Plans. But if Customer requires extraordinary assistance involving manual intervention or specialized professional services, such assistance will be provided subject to prior agreement on the cost, which will be agreed in writing before such costs are incurred.
  7. 6.7 Data Protection Laws. Parties agree to comply with all applicable data protection laws and privacy regulations applicable to their duties and obligations, including, but not limited to, Health Insurance Portability and Accountability Act (HIPAA) and General Data Protection Regulation (GDPR), as such regulations may be amended, updated, or supplemented from time to time. For avoidance of doubt, regarding collection, processing, security, and transfer of PHI and Personal Data, Parties acknowledge and agree that such statutory compliance shall be strictly governed by, and executed in accordance with, mandatory safeguards and protocols established in the BAA and Annex TOM executed between Parties.

7. Materials

  1. 7.1 Customer Materials. Company acknowledges that Customer owns and has rights to all Customer Materials that it provides to Company, uploads to Company's SaaS Platform, or allows access to through the SaaS Platform, for the purpose of personalization or identification.
  2. 7.2 License Grant. Customer hereby grants Company a worldwide, non-exclusive, non-transferable, royalty-free and irrevocable license during the Term of this Agreement to display, reproduce, and use Customer Materials solely to the extent necessary to:
    1. Provide and operate the Service for Customer's benefit (including technical adjustments for improved Customer visibility in the interface)); and
    2. Identify, publicize, and promote Customer as an active user of the Service across any and all of Company's marketing advertising, and promotional channels (including, without limitation, Company’s corporate websites, social media platforms, investor pitch decks, sales presentations, printed or digital commercial brochures, and platform case studies or success stories).

    License acquired by Company over Customer Material under this clause shall permit company to resize, format, or adjust the layout of Customer Materials strictly limited to the technical adjustments necessary for the proper display, aesthetic integration of said Customer Materials within the Platform (pursuant to Subsection a) and across authorized marketing and promotional channels (pursuant to Subsection b), guaranteeing that Customer retains all original intellectual property rights, and provided that such necessary adjustments do not alter in any way the original colors, typography, or core design of Customer's registered trademarks.

  3. 7.3 Reference Use. Pursuant to the preceding clause and for the duration of this Agreement, Customer consents to the inclusion of its Customer Materials (including, without limitation, corporate name, trademark, and logo) in Company's public Customer directory on its website and other promotional channels.
  4. 7.4 Right of Supervision. Customer grants Company the right to monitor Customer and its Authorized End User’s use of the SaaS Platform, as well as the right to collect and use data resulting from such monitoring for the purpose of managing and improving the SaaS Platform and related Services, and for providing support to Customer.
  5. 7.5 Guarantee of Ownership. Customer represents and warrants that it has sufficient rights to transmit or otherwise permit access to any such Customer Materials to Company, including any data or information contained therein and that, to the extent Customer shares or otherwise permits Company or the Platform to make use of any credentials to obtain such data or information, that such sharing of credentials shall not violate the rights of, or any contractual obligations with, any third party.
  6. 7.6 Material Transfer. Customer acknowledges that Company may transfer Customer Materials internationally, solely for purposes of providing services in accordance with this SSA and the documents comprising the Agreement. However, Company will not transfer Customer Materials to any countries which are listed as restricted locations by the Office of Foreign Assets Control (OFAC), United States Department of State, or United States Department of Commerce sanctions program. For avoidance of doubt, Customer Materials strictly exclude Customer Data and PHI. Any international transfer of Customer Data or PHI shall be strictly governed by, and legally subordinate to, Standard Contractual Clauses (SCCs) and the applicable BAA.
  7. 7.7 Material Archive. Customer acknowledges that Company may, in its discretion, archive Customer Materials that are two (2) or more years old such that this archived Customer Materials are not readily accessible through Platform. Customer expressly acknowledges that this archival right does not apply to Customer Data nor PHI, which shall be subject to strict data minimization, retention limits, and deletion protocols set forth in the BAA and Annex TOM.

8. Acceptable Use Policy (AUP)

  1. 8.1 Lawful and Acceptable Use. Customer agrees not to use the Services to upload, post, store, or transmit Customer Data that is unlawful, defamatory, harassing, abusive, infringes the intellectual property of others, or violates privacy.
  2. 8.2 Prohibition of Technical Abuse. Customer may not:
    1. Introduce viruses, worms, malware, or any destructive or malicious code into the SaaS Application.
    2. Attempt to gain unauthorized access to the systems or data of other Company customers.
    3. Use the SaaS Application in a manner that causes an undue or disproportionately large load on Company's infrastructure.
  3. 8.3 Right of Suspension for Breach. Company reserves the right to suspend the access to the Service of SaaS Platform to Customer's or Authorized User's, upon prior written notice, if:
    1. Customer breaches any payment obligation, and such breach is not remedied within thirty (30) calendar days following written notice from Company; or
    2. Customer breaches any other provision of this SSA, or any document that constitutes the Agreement, and such breach is not remedied within thirty (30) calendar days following written notice from Company.

    Once the deadlines stipulated in paragraphs a) or b) have been met and the non-compliance has not been corrected or remedied, Company will suspend the Service and notify Customer that the suspension has become effective.

  4. 8.4 Immediate Suspension. As soon as it detects a threat or Infraction, Company reserves the right to suspend to Customer's or Authorized End User’s access to the Service of SaaS Platform immediately and without prior notice if Company determines in its reasonable discretion that Customer's or Authorized End User's account use of the Service (Causes of Infraction):
    1. Endangers the security, integrity, or availability of the Service for other customers;
    2. Involves threat or attack on any portion of all the Application IP;
    3. Involves the use of malware, malicious code, or hacking activities;
    4. Violates any case of the Prohibition of Technical Abuse Clause established in Section 8.2;
    5. Violates any case of the Lawful Acceptable Use Clause established in Section 8.1;
    6. Poses a risk of legal liability to Company;
    7. Violates applicable laws; or
    8. Uses it for fraudulent or illegal activities.
  5. 8.5 Immediate Suspension Procedure. Once immediate suspension is implemented, Company will send Customer an initial written notification within twenty-four (24) business hours (Preliminary Notification), describing the identified violation(s) that motivate or justify the immediate suspension (in accordance with the grounds established in the previous section), reserving the right to supplement this initial notification if additional violations are discovered during the investigation (Supplementary Notification). After being notified with the Preliminary and Supplementary Notifications, Customer will have seven (7) business days to respond, justify, or clarify, on their own behalf or on behalf of the Authorized End Users, regarding the violations attributed to them, so that Company can evaluate the termination of this Service Agreement or determine the necessary steps to resume service. If Customer is found to be in breach of contract and liable in whole or in part, the service may only be resumed if Customer remedies or repairs any damage and agrees not to repeat the breach, under penalty of permanent suspension, termination of this SaaS Agreement and all accompanying documentation, and, if applicable, reporting to the competent authorities or exercising Company's rights in the event of legal violations.

    The service will not be permanently resumed if it is prohibited by applicable regulations and/or could compromise Company with illegal or fraudulent activities, with Customer being solely responsible to the authorities and the Law for the use and the results of the use that it and the Authorized End Users make or have made through Access to the SaaS Platform.

  6. 8.6 Suspension of Service with Notice. Company reserves the right to suspend to Customer's or Authorized End Users access the Services of SaaS Platform, with prior written notice if:
    1. Company’s provision of the Platform becomes prohibited by applicable law;
    2. Customer has ceased to continue its business in the ordinary course, or made an assignment for the benefit of creditors or similar disposition of its assets, or become the subject of any bankruptcy, reorganization, liquidation, dissolution or similar proceeding;
    3. Suspension may be technically necessary for updates or improvements; or
    4. Any other circumstance arises that is not foreseen in this agreement but requires immediate attention to ensure the security, integrity, or legal compliance of the Services.
  7. 8.7 Suspension Notice. Company will make commercially reasonable efforts to provide written notice of any Service Suspension to Customer (including prior or subsequent notices after the suspension, regardless of the cause). This notice may be sent to email addresses provided by Customer as formal channels of communication between Parties. Any other necessary communication regarding the suspension or resumption of access to the Application's IP address after any Service Suspension will be communicated by Company in writing, which may also be sent by email. Company will make every effort to resume access to the Platform as soon as reasonably possible after the event that resulted in the Service Suspension is resolved.
  8. 8.8 Suspension Liability. Company will have no liability for any damage, liabilities, losses (including any loss of data or profits) or any other consequences that Customer or any Authorized User may suffer as a result of a Service Suspension carried out in accordance with the terms of this Agreement.
  9. 8.9 Resource Availability. Company does not set predefined and fixed limits on disk storage or bandwidth usage, in order to allow for Customer growth. However, this commitment is subject to the provisions of clauses 8.10 and 8.11.
  10. 8.10 Fair and Reasonable Use. Customer guarantees that its use of resources will be fair, reasonable, and will not impair the quality, performance, or availability of the Service for other users. Use will be considered unreasonable, among other things, when:
    1. Customer breaches any term of this Agreement or its Appendices.
    2. Customer infringes the Intellectual Property rights of Company or third parties (including hosting illegal or pirated material).
    3. Resource consumption is disproportionate to typical usage patterns for similar services or causes technical degradation to Company's infrastructure.
  11. 8.11 Right of Intervention and Mitigation. If Company, in its sole discretion, determines that Customer's use jeopardizes the stability or security of the Platform, Company may:
    1. Notify Customer to immediately reduce its consumption; or
    2. Immediately suspend or limit access to the Service if there is an imminent risk of system failure or damage to the infrastructure, without incurring any liability to Company.

9. Availability and Support

  1. 9.1 Exclusive Remedy. If Company fails to meet the Availability Commitment established in the SLA, Customer's sole recourse, and Company's sole liability, shall be the Service Credits established in the SLA. Customer acknowledges that this recourse is final and binding.
  2. 9.2 Technical Support. Company will provide the technical support described in the SLA.
  3. 9.3 Assistance to Company. Customer will, at its own expense, provide assistance to Company, including, but not limited to, access to and use of, Customer facilities and equipment, as well as assistance from Customer personnel, to the extent reasonably necessary to enable Company to perform its obligations under this SSA and all documents that constitute the Agreement, including, without limitation, any obligations with respect to support services.

10. Fees, Expenses and Payments

  1. 10.1 Plans and Fees. Access to basic Platform functionality is free of charge. Company offers paid subscription Plans for access to additional Platform functionality, on monthly and annual billing terms. Custom plans are available by contacting Company and are governed by the terms agreed in writing for that plan. The fees for the Plan selected by Customer (the "Fees") are those displayed on the Platform's billing page and in the checkout flow at the time of purchase; annual Plans are billed in advance for the full annual period.
  2. 10.2 Locations. Unless the applicable Plan states otherwise, a subscription entitles Authorized End Users at a single practice location to access the Platform. Customer must obtain a subscription, or pay the applicable additional-location Fee, for each further location at which Authorized End Users access the Platform. Company may invoice the Fees for additional locations separately from the Plan rather than charging them through the Billing Portal. Invoiced amounts are due within ten (10) calendar days of the invoice date, and Company may suspend access to the paid features in the Platform if invoiced amounts remain unpaid after written notice. Customer must notify Company of any dispute regarding an invoice within ten (10) calendar days of receipt and pay the undisputed portion by the due date.
  3. 10.3 Automatic Renewal; Payment Authorization. Each subscription renews automatically at the end of each billing period, monthly for monthly Plans and annually for annual Plans, and the payment method on file will be charged the then-current Fees at the start of each renewal period, until Customer cancels. Customer affirmatively consents to these automatic-renewal terms during the checkout flow, and by subscribing authorizes Company, through its payment processor, to charge the payment method on file for the recurring Fees and any applicable taxes. For annual Plans, Company will send a renewal reminder to the email address associated with Customer's account at least thirty (30) calendar days before each renewal. Customer may cancel online at any time through the billing portal, effective at the end of the then-current billing period.
  4. 10.4 Payment Processing. Payments are processed by Stripe, Inc. ("Stripe"), Company's third-party payment processor. Customer provides its payment card information directly to Stripe through Stripe-hosted payment pages; Company does not collect, store, or have access to full payment card numbers. Customer's provision of payment information to Stripe is subject to Stripe's own terms of service and privacy policy (available at https://stripe.com/legal and https://stripe.com/privacy).
  5. 10.5 Billing Portal. Customer may manage its subscription through a Stripe-hosted customer billing portal accessible from the Platform's billing page, including updating payment methods, viewing invoices and receipts, and canceling the subscription.
  6. 10.6 Failed Payments; Grace Period; Suspension. If a renewal charge fails, the payment processor will retry the charge over a limited period, during which Customer's access to the Platform continues and Customer may cure the failure by updating its payment method through the billing portal. If payment is not collected and the subscription lapses or is terminated for nonpayment, Company may suspend Customer's access to the paid features in the Platform until Customer establishes an active subscription. Suspension for nonpayment does not relieve Customer of Fees already owed, and Company may terminate the Agreement for breach under Section 15.3 if nonpayment persists.
  7. 10.7 No Refunds. Except as expressly stated in this Agreement or as required by applicable law, Fees are prepaid and non-refundable (except for Service Credits issued under the SLA).
  8. 10.8 Taxes. Customer will be responsible for payment of any applicable sales, use and other taxes and all applicable export and import fees, customs duties and similar charges (other than taxes based on Company’s income), and any related penalties and interest for the grant of license rights hereunder, or the delivery of related services. Customer will make all required payments to Company free and clear of, and without reduction for, any withholding taxes. Any such taxes imposed on payments to Company will be Customer’s sole responsibility, and Customer will, upon Company’s request, provide Company with official receipts issued by the appropriate taxing authorities, or such other evidence as Company may reasonably request, to establish that such taxes have been paid.
  9. 10.9 Fee Changes. Company may modify the Fees applicable to renewal periods by providing Customer with written notice at least thirty (30) calendar days before the change takes effect; the modified Fees apply beginning with the next renewal period that starts after the effective date of the change. If Customer does not agree to the modified Fees, Customer may cancel the subscription before that renewal period begins.
  10. 10.10 Plan Changes. Customer may request a Plan change by contacting Company; changes take effect as agreed in writing, and no proration applies unless expressly agreed.
  11. 10.11 Complimentary Access. Company may, at its discretion, provide Customer with free, pilot, or otherwise complimentary access to the Platform. Complimentary access is revocable and does not renew as a paid subscription. No Fees are due for complimentary access. Company will provide Customer with written notice at least fifteen (15) calendar days before any Fees apply to a Customer whose access has been complimentary; continued use after that notice period requires selection of a Plan, and if Customer does not select a Plan, the Agreement terminates at the end of the notice period without charge to Customer.
  12. 10.12 Customer Operating Expenses. Customer will bear all expenses incurred in performance of its obligations established in this SSA and all documents that constitute the Agreement, including, without limitation, through use by Customer and/or any Authorized End User of the Platform, and/or through provision of support to Authorized End Users with respect to such use of the Platform SaaS.

11. Treatment of Confidential Information

  1. 11.1 Non-Disclosure Obligation. Parties agree not to disclose Confidential Information (this includes all information contained in this SSA and all documents that form part of this Agreement) to any person, Third-Party, or entity without the prior and necessary consent of the other Party, nor to use the other Party's Confidential Information for purposes other than those established in this SSA or the documents that constitute the Agreement, except in the cases of the Exceptions established in this SSA.
  2. 11.2 Consent for Disclosure. Notwithstanding the agreement between both Parties not to disclose Confidential Information, as stipulated in the preceding section, and provided that it is not a cause of exception to the Non-Disclosure Obligation established in this SSA, either Party may request written consent and authorization from the other Party to disclose Confidential Information to unauthorized third parties, specifying in its request the scope, justification, and purpose of the request. Party owning the Confidential Information may refuse at any time without such refusal constituting a breach of this SSA. If consent is given for the use of Confidential Information, the requesting Party shall be responsible for the results of its use.
  3. 11.3 Validity of Confidential Information. During the term of this SSA and while confidentiality obligations remain in effect, Parties agree to maintain the strict confidentiality of the other Party's Confidential Information ("Confidential Information") for a period of four (4) years after the termination of this SSA, and indefinitely in the case of trade secrets or business secrets, and all Confidential Information related to Company's intellectual property (including the SaaS Platform and API). Notwithstanding the foregoing, obligations relating to privacy, protection, and destruction of PHI shall not be subject to this time limitation and shall survive in strict accordance with the BAA and applicable HIPAA regulations.
  4. 11.4 Usage Terms. Parties agree that under no circumstances will it be necessary for their Confidential Information to be marked as "Confidential Information" to be protected as such. Parties agree to follow following conditions for handling of Confidential Information as mutual obligation, and each Party agrees to following:
    1. To use the Confidential Information disclosed by other Party only for purposes described in this SSA or documents that constitute the Agreement;
    2. Not to reproduce the Confidential Information disclosed by other Party and to keep it confidential, protecting it from disclosure and use by third parties; and
    3. To return or destroy all Confidential Information disclosed by the other Party in its possession upon the termination or expiration of this SSA and documents that constitute the Agreement.

    Notwithstanding the foregoing, Parties expressly acknowledge that whenever Confidential Information involves or constitutes PHI or Personal Data, its use, reproduction, protection, retention, and return or destruction shall be strictly governed by, and legally subordinate to, mandatory safeguards, HIPAA minimum necessary rules, and protocols established in the BAA and Annex TOM, which shall strictly prevail over this Section.

  5. 11.5 Exceptions to the Non-Disclosure Obligation. For standard commercial Confidential Information, neither Party shall be in breach of the non-disclosure obligation established in the preceding section when the following cases arise, in which the Confidential Information (Exceptions):
    1. Is or becomes public domain before disclosure, without causing fault to the Discloser;
    2. Was in the possession of the Recipient or was known to the Recipient before receiving it from the Discloser;
    3. Was lawfully disclosed to the Recipient by a third party;
    4. Was independently developed by the Recipient without using the Discloser's Confidential Information;
    5. Is required by a valid court order or other governmental order;
    6. Is required by law;
    7. It’s transmission, knowledge, and use are necessary for the provision of the Services and must be communicated (in tangible or intangible format) to the Recipient's authorized employees, advisors, or consultants who are subject to contractual obligations of confidentiality and data protection, under terms and conditions are at least as stringent as those set forth in this SSA. Company reserves the right to use, move, or remove intangible Confidential Information stored in the memories of its authorized employees, advisors, or consultants, in compliance with or when required by law; or
    8. It’s transmission is necessary to establish the rights of either Party under this SSA, and in this case, such transmission shall not be considered a breach of the confidentiality obligations contained in this Section, nor a waiver of confidentiality for other purposes.

    The exceptions listed in this section apply solely and exclusively to commercial Confidential Information. Under no circumstances shall these exceptions authorize the disclosure of PHI. Any required disclosure of PHI (including disclosures required by law, court order, or governmental request) shall not be governed by this SSA, but shall be managed exclusively in accordance with the procedures, restrictions, and notification requirements set forth in the BAA and applicable HIPAA regulations.

12. Representations, Warranties and Disclaimers

  1. 12.1 Mutual Representations and Warranties. Each Party represents and warrant:
    1. That each Party is duly incorporated, validly exists, and fully complies with its obligations under the laws of its jurisdiction of incorporation or organization, and therefore has the legal authority to:
      1. Enter into this SSA and all the documents comprising this Agreement; and
      2. Comply with all applicable laws in the performance of its obligations under this SSA and all the documents comprising the Agreement.
    2. That the execution and performance of this SSA and the documents comprising the Agreement will not contravene or infringe any legal provision applicable to such Party; and
    3. That this SSA and the documents comprising the Agreement, once executed and delivered, will constitute a valid and binding obligation for both Parties and will be enforceable in accordance with its terms.
  2. 12.2 Service Warranty: Company warrants that:
    1. Services will function substantially in accordance with this SSA and the documents comprising the Agreement;
    2. It will provide the Services in a professional and diligent manner; and
    3. SaaS Platform, as provided, does not infringe any Third-Party Intellectual Property Rights.
  3. 12.3 General Disclaimer. Except for the express warranties and representations set forth in this SSA, Company provides the Service "as is" and disclaims all other implied promises, representations, and warranties of merchantability, fitness for a particular purpose, title, non infringement, peaceful enjoyment, system integration, and/or data accuracy, or any other warranties, to the fullest extent permitted by law.
  4. 12.4 Non-Disclosure Agreement Warranty. Parties shall ensure that all their employees, consultants, and agents who have access to Confidential Information (including Customer Data and Authorized End User information) have signed or are subject to contractual confidentiality obligations at least as stringent as those set forth in this SSA. Furthermore, whenever such access involves PHI, Parties warrant that said personnel shall be granted access solely to extent strictly necessary (Minimum Necessary Rule), have undergone appropriate data protection and HIPAA compliance training, and are subject to appropriate disciplinary sanctions for privacy violations, in strict accordance with mandatory safeguards established in the applicable BAA.
  5. 12.5 Disclaimer for AI-Generated Results. Company does not guarantee the absolute accuracy of the results provided, as these depend on the accuracy of Customer Data and the algorithmic results of Artificial Intelligence (AI). Customer acknowledges and agrees that the Services, including the SaaS Platform and AI results, are designed exclusively to provide technical, analytical, and administrative support. Company does not offer medical, dental, or healthcare advice, nor does it practice medicine or dentistry. The results generated by the AI ​​are offered solely as supplementary tools to assist Customer and its authorized professionals. Company makes no warranties or representations regarding the medical accuracy, clinical validity, or diagnostic suitability of said results.

13. Limitation of Liability

  1. 13.1 Exclusion of indirect damages. In no event shall Company be liable to Customer or Customer’s Authorized End Users for any indirect, incidental, punitive, special, exemplary, or consequential damages (including, but not limited to, loss of data, business interruption, loss of profits, savings, earnings, or revenue) arising out of or related to the subject matter of this SSA or any document constituting the Agreement, even if Company has been advised of the possibility of such damages.
  2. 13.2 Maximum Limit of Liability. Company's total cumulative liability to Customer under this SSA shall not exceed the total amount of Fees paid by Customer to Company during the six (6) months prior to the date of the event giving rise to liability.

    ThIs standard limitation of liability established here shall not apply to following cases:

    1. Indemnification obligations; or
    2. Breach of confidentiality obligations; or
    3. Violations of Company's IP rights; or
    4. Fraud or willful misconduct;

    In the specific event of claims, damages or regulatory penalties arising directly from a material breach of the BAA or applicable data privacy laws (including HIPAA), the standard limitation of liability shall not apply, and instead, Company's liability for such breaches shall be strictly limited to the maximum coverage limit available under the Company's active cybersecurity and data privacy insurance policy in effect at the time of the claim.

  3. 13.3 Exclusion of Liability for Customer Decisions. Company shall not be liable for any direct or indirect damages, losses, claims of medical negligence, or financial liabilities arising from clinical or operational decisions made by Customer or its Authorized End Users, whether based, in whole or in part, on use of Services. Company provides technology and administrative support and does not practice medicine or dentistry. Customer and its Authorized End Users licensed dental/healthcare professionals retain absolute, sole, and exclusive liability for all final medical or dental diagnoses, treatment decisions, patient care, and accuracy and validity of any claims submitted to insurers.
  4. 13.4 Exclusions of Liability for Use. Company will not be liable for any loss or damage resulting from:
    1. Use of the SaaS Application in a manner not authorized by this Agreement or the Documentation;
    2. Combination of the SaaS Application with hardware, software, or data not provided or approved by Company; or
    3. Internet access failures or factors beyond Company's control.

14. Indemnification

  1. 14.1 Intellectual Property Indemnity. Company agrees to defend and indemnify Customer against any Third-Party claims alleging that SaaS Solution or Platform infringes their Intellectual Property. Company will suspend access to and use of the Service if a court order compels it to suspend all or part of the Service's functions due to infringement of third-party intellectual property rights. If only part of the Service's functions are involved in the claim, Company may, at its sole discretion, replace allegedly infringing material with alternative material to ensure continued provision of the Service.
  2. 14.2 Customer Indemnification Obligations. Customer shall indemnify and hold harmless Company from and against any and all claims, liabilities, costs, losses, damages, judgments, penalties, interest, and expenses (including attorneys’ fees) arising out of or relating to any claim, action, audit, investigation, inquiry, or other proceeding initiated by any Third-Party (“Claim”) that results from or relates to:
    1. Negligence or willful misconduct of Customer or any Authorized End User in connection with the use of the Services provided by Company;
    2. Use by Customer or any Authorized End User of the SaaS Application in a manner not authorized or contemplated in this SSA or any document constituting the Agreement, including, but not limited to, any actual or alleged infringement of any of Company’s Intellectual Property Rights;
    3. Any actual or alleged breach of Customer's representations, warranties, or obligations set forth in all documents constituting the Agreement;
    4. Use of an outdated or modified version of the SaaS Application other than the current version made available by Company to Customer;
    5. Any Material IP Application, owned or distributed by Customer and not Company’s Service.
    6. Any Customer or Customer End-User Data provided to Company and/or arising from the use of the Services and not due to the SaaS Platform, including violation of the law or third-party rights; or
    7. Any actual or alleged breach of Customer's obligations under Guarantee of Consent (Section 5.4), failure to obtain any patient consent or authorization required of Customer prior to transferring PHI, or any violation of HIPAA regulations applicable to Customer as Covered Entity.
    8. Customer's failure to comply with any law related to this SSA; or
    9. Any of the grounds for Usage Restrictions (Anti-Piracy and Express Prohibition) Section 3.6 sets forth in this SSA.

15. Term and Termination

  1. 15.1 Term. This SSA will become effective on the Effective Date and will remain in effect for as long as Customer accesses or uses the Platform, whether under a paid Plan or under free or complimentary access.
  2. 15.2 Term and Renewal of the Subscription. Each subscription begins on the date Customer completes the checkout flow for the selected Plan and continues for the billing period selected by Customer (monthly or annual). The subscription renews automatically at the end of each billing period, in accordance with Section 10.3, until Customer cancels. There is no minimum term and no notice period: Customer may cancel at any time through the billing portal, with cancellation effective at the end of the then-current billing period.
  3. 15.3 Termination for Breach. Either Party may terminate this SSA or any of the documents comprising the Agreement in the event of a breach by the other Party (the breaching Party), by providing written notice specifying the breach(es) and granting thirty (30) calendar days following receipt of such notice for the breach(es) to be remedied. If the breach is not remedied within this period, the following shall apply:
    1. Termination of this SSA and all documents constituting the Agreement, if Company is the breaching Party.
    2. Company may suspend the Service if Customer is the breaching Party, exercising its right to suspend as set forth in Section 8 of this SSA, and will subsequently terminate this SSA and all documents constituting the Agreement.
  4. 15.4 Obligations Upon Termination: Upon termination of this SSA, the following shall apply:
    1. Customer’s right to access and use the Service through the SaaS Platform shall expire;
    2. Customer must provide proof that there are no outstanding amounts;
    3. Company shall return Customer's Data as established in Section 4.7;
    4. Both Parties shall destroy the other Party's Confidential Information and materials, unless a written request for return instead of destruction is made as established in Section 15.6;
    5. All sections protecting Company's and Customer’s rights to Intellectual Property, Confidentiality, and Limitation of Liability shall survive the termination or expiration of this SSA; and
    6. Sections described in Section 15.7 shall survive the termination or expiration of this SSA.
  5. 15.5 Data Return Upon Termination. Provided Customer pays all outstanding amounts after the termination of this SSA, Company will make Customer Data available for download for a period of thirty (30) calendar days (“Grace Period”), in accordance with Section 4.7 of this SSA. After this period, Company will delete Customer Data in accordance with Section 4.8, unless its retention is required by law. With respect to any PHI, such data shall be securely returned or destroyed strictly in accordance with the protocols and timelines set forth in the BAA.
  6. 15.6 Destruction of Confidential Information Upon Termination. Upon termination of this SSA both parties shall delete the other party's Confidential Information from computer storage systems or any other media, including, but not limited to, online and offline libraries, unless the owning Party requests its return in writing instead of destruction within the first ten (10) calendar days following the termination of this SSA. With respect to any PHI, such data shall be securely returned or destroyed strictly in accordance with the protocols and timelines set forth in the BAA.
  7. 15.7 Survival after Termination. Provisions of Sections 3.1, 3.2, 11-14, 15.4-15.7 and 16 will survive the termination of this SSA.

16. Miscellaneous

  1. 16.1 Entire Agreement and Order of Precedence. This SSA, all its Annexes and the SLA constitute the entire Agreement between the Parties with respect to its subject matter and may not be modified or terminated except by a written Addendum signed by authorized representatives of Customer and Company. The Annexes will be incorporated into this SSA by reference. In the event of any discrepancy between the terms of an Annex or the SLA and this SSA, the terms and conditions of this SSA will prevail, with exception of (i) the Plan, which shall prevail solely and exclusively with respect to the Fees and the billing interval selected by Customer, and (ii) the SLA, which shall prevail solely and exclusively with respect to the Availability Commitment, Service Credits, and support response times. Furthermore, in the event of any conflict or inconsistency between the terms of this SSA and the BAA independently executed by Parties, the BAA shall prevail solely and exclusively with respect to the protection, privacy, and processing of PHI and compliance with HIPAA regulations. The provisions of this SSA supersede all contemporaneous oral agreements and all prior quotations, communications, agreements, and understandings, whether oral or written, between the Parties, as well as any oral or written representations by either Party with respect to the subject matter of this SSA, and any letters of intent or memoranda of understanding entered into by the Parties with respect to the Services. No conflicting or inconsistent term, condition, restriction, or other provision contained in delivery memoranda, invoices, letters, or other documents shall be binding upon a Party unless expressly agreed to by that Party in writing.
  2. 16.2 Amendments or Modifications. No amendment or modification of this SSA or any Annex shall be valid unless such Amendment or Addendum is made in writing and signed by the authorized representatives of both Parties. This Section does not apply to the SLA, which Company may revise in accordance with the terms of the SLA itself. Acceptance of a later version of this SSA through Company’s Platform, in the manner described in the preamble to this SSA, satisfies the writing and signature requirement of this Section.
  3. 16.3 Changes to this SSA. Company may publish a new version of this SSA at https://dentalmaverick.ai/legal with a new Last Update Date. The version accepted by Customer continues to apply to Customer until Customer accepts a later version, except that the then-current version applies to Customer from the start of Customer’s next billing period following publication. Where a revision materially reduces Customer’s rights or increases Customer’s obligations, it takes effect for Customer thirty (30) days after Company notifies Customer, and Customer may cancel the subscription before it takes effect. Prior versions are retained and available on request to privacy@dentalmaverick.ai.
  4. 16.4 Notices. Routine communications under this SSA may be made by email. Any legal notice under this SSA, including, but not limited to, notices of termination, breach, indemnification, or other non-routine matters, will be effective only if delivered in writing and sent to the Party’s applicable address indicated in the first paragraph of this SSA and, in the case of Customer, to the registered email address and the Administrator designated in Customer’s account. Unless both Parties agree that sending an email and confirmation of receipt is sufficient. Notwithstanding the foregoing, notice will be deemed given:
    1. On the date of delivery if delivered personally;
    2. One (1) day after delivery if sent by a nationally recognized express courier service; or
    3. Upon receipt, if sent by U.S. Certified Mail Return Shipping.
  5. 16.5 Severability. If any provision of this SSA is invalid or unenforceable for any reason in any jurisdiction, such provision will be construed to have been adjusted to the minimum extent necessary to cure such invalidity or unenforceability. The invalidity or unenforceability of one or more of the provisions contained in this SSA will not invalidate or render unenforceable in any other case, circumstance or jurisdiction, nor of rendering any other provisions of this SSA invalid or unenforceable whatsoever.
  6. 16.6 Waiver. No waiver under this SSA will be valid or binding unless set forth in writing and duly executed by the Party against whom enforcement of such waiver is sought. Any such waiver will constitute a waiver only with respect to the specific matter described therein and will in no way impair the rights of the Party granting such waiver in any other respect or at any other time. Any delay or forbearance by either Party in exercising any right hereunder will not be deemed a waiver of that right.
  7. 16.7 Force Majeure Events. Neither Party shall be liable for any failure or delay in performing this SSA or any of the documents comprising the Agreement if such failure or delay is due to causes beyond its reasonable control, including acts of war, natural disasters, earthquakes, floods, embargoes, riots, sabotage, acts of government, or internet service failures not attributable to the Party's actions or omissions, and such failure or delay could not have been avoided by reasonable precautions nor can it reasonably be remedied by the Party through the use of alternative sources, contingency plans, or other means (hereinafter, “Force Majeure Events”), provided that the affected Party:
    1. Promptly notifies the other Party of such cause, and
    2. Makes commercially reasonable efforts to remedy such failure or delay immediately or as soon as reasonably practicable after the cessation of the circumstances that caused such failure or delay.

    However, if such Party is prevented or delayed in performance for more than ninety (90) days, the other Party may terminate this Contract by written notice.

  8. 16.8 Independent Contractors. In this SSA and all documents constituting the Agreement, the Parties are and act as independent contractors. This SSA does not create, shall not be construed as, nor is it intended to create a partnership, franchise, joint venture, agency, fiduciary, or employment relationship between the Parties.
  9. 16.9 Assignment or Delegation. Neither Party shall assign any of its rights or delegate any of its duties under this SSA or any document that constitutes the Agreement without the express, prior written consent of the other Party. In the absence of such consent, any attempted assignment or delegation will be null, void and of no effect. Notwithstanding the foregoing, Company may assign this SSA, without consent, in the event of a merger, sale, transfer or other disposition of all or the greater part its stock or assets, including in the event of assignment of this SSA to an affiliated entity. Furthermore, Customer expressly acknowledges and agrees that Company may delegate performance of specific operational or technical duties (including data processing) to its authorized subcontractors and Sub-processors, provided that such delegation strictly complies with sub-processor authorization protocols set forth in the applicable BAA, and that Company remains fully liable to Customer for performance of such subcontractors.
  10. 16.10 Governing Law and Jurisdiction. The parties agree that this SSA and all documents constituting the Agreement shall be interpreted and governed in all respects by the laws of the State of Texas from EEUU, without regard to any conflict of laws principles. The Parties expressly and irrevocably agree to submit any dispute or controversy arising out of this SSA or any document forming part of the Agreement to the exclusive jurisdiction of the courts of Austin, Texas. Each party waives any objection to the jurisdiction or venue of such courts for any action, claim, or proceeding.
  11. 16.11 No Solicitation of Personnel. During the term of this SSA and for a period of two (2) years (the "Restricted Period") following the termination or expiration of the last active subscription, Customer agrees not to solicit, induce, or encourage (directly or indirectly) any person who is or has been an employee, contractor, or consultant of Company with whom Customer has had substantial contact as a result of the provision of the Services.
  12. 16.12 Prohibition of Circumvention. During the term of this SSA and for a period of two (2) years (the "Restricted Period") following the termination or expiration of the last active subscription, Customer shall not, directly or indirectly, circumvent or interfere with Company in negotiating or execution of agreements similar to this SSA, or solicit, contract, or enter into agreements with employees, contractors, or consultants, companies, providers, authorized sub-processor, that Company has introduced to Customer for the provision of Services under this agreement, and whose ultimate objective is to provide or receive services identical or substantially similar to those provided by Company, unless Company has given its prior written consent.

    Notwithstanding the foregoing, the restrictions in this subsection shall not apply to any pre-existing, documented, and independent commercial relationship between Customer and a Sub-processor established prior to the Effective Date of this SSA. However, Customer is strictly prohibited from expanding, modifying, or utilizing such pre-existing relationship to circumvent Company for the provision of services identical or substantially similar to the Services (including automated insurance eligibility verification, claim preparation and submission, and AI-assisted narrative generation) provided under this SSA.

  13. 16.13 Equitable Remedies and Injunctive Relief. Parties acknowledge that a breach of the obligations set forth in Section 3 (Access, Licence and Use) or Section 11 (Confidentiality) could cause irreparable harm to the non-breaching Party, for which monetary compensation would be an inadequate remedy. Therefore, in the event of any actual or threatened breach of these Sections, the non-breaching Party shall be entitled to seek injunctive relief, equitable relief, or a writ of mandamus, without posting a bond and without prejudice to any other available legal or monetary remedies.
  14. 16.14 Responsibility for Authorized Users. Customer shall be responsible for the compliance of its Authorized Users and any person accessing the Service through Customer's credentials with this SSA. Any act or omission by such Authorized Users that constitutes a breach of this Agreement shall be deemed a breach by Customer.
  15. 16.15 Reference. Company may identify Customer as a customer of the Platform, publish a testimonial or quotation provided by Customer for that purpose and attributed to Customer or its personnel, and may include Customer’s name and logo in its customer lists, on its corporate Website at https://dentalmaverick.ai/ and in its sales and marketing materials, as provided in Section 7.3 and without further approval. Company will remove Customer’s name and logo from such materials within a reasonable period following Customer’s written request. A press release announcing Customer, a white paper or case study describing Customer’s use of the Platform, each remain subject to Customer’s prior written approval, which may be given by email.
  16. 16.16 Counterparts. This SSA may be executed in any number of counterparts, each of which when so executed will be deemed to be an original and all of which when taken together will constitute documents that comprise the Agreement.

Annex 1 — Technical and Organisational Measures (TOM)

This Technical and Organisational Measures document ("TOM") is Annex 1 to, and forms an integral part of, the Software as a Service Subscription Agreement ("SSA") between SanctifAI Dental Inc. dba Dental Maverick AI, a Delaware corporation with registered address at 7415 Southwest Pkwy, Building 6, Austin, TX 78735, USA ("Company"), and the customer that accepted the SSA ("Customer"). Each is a "Party" and together the "Parties".

Company, in its capacity as Data Importer, will implement and maintain following technical and organizational measures to ensure an adequate level of security for Personal Data, taking into account the nature, scope, context, and purpose of the processing.

Parties acknowledge that these TOM serve to fulfill regulatory requirements, including those set forth in Annex II of the Standard Contractual Clauses (SCCs). Notwithstanding the foregoing, whenever personal information is processed, or relates to, PHI, such processing shall be governed by the mandatory security measures and protocols established in the BAA; application of said measures and protocols shall take strict priority and prevail over the provisions of these TOM.

These are general technical and organizational measures of the Service:

Pseudonymization and encryption measures for personal data:

All Personal Data, particularly PHI, will be encrypted using military-grade encryption standards: AES-256 for data at rest and TLS 1.3 for data in transit.

User Identification and Authorization Measures:

Access to the system and data is strictly governed by the mandatory use of Multi-Factor Authentication (MFA) and the Principle of Least Privilege (PoLP).

Data Importer will grant data access to personnel only to the extent strictly necessary, ensuring that all authorized individuals are subject to a strict duty of confidentiality.

Measures to Ensure the Ongoing Confidentiality, Integrity, Availability, and Resilience of Processing Systems:

Data Importer hosts the Service on infrastructure operated by subcontractors that maintain recognised independent security certifications; copies of the applicable certifications and reports are available to Customer on request.

System compliance and resilience are continuously monitored and validated through periodic penetration testing and independent security assessments.

Measures to Ensure Limited Data Retention:

Data Importer applies strict data minimization and retention protocols. Customer data will be securely deleted or anonymized upon completion of the service, or deleted no later than one month after completion and acceptance of the delivery, depending on the project scope.

Internal IT Governance and IT Security:

The specific, detailed, and day-to-day operational aspects of these technical and organizational measures are thoroughly documented in the company's Information Security Policy, Data Retention and Deletion Policy, and Threat Intelligence Policy.

Light