Posted/Revised: July, 2026
SAAS SUBSCRIPTION AGREEMENT
SurfaceWatch™
PLEASE READ THESE TERMS OF SERVICE CAREFULLY. BY ENTERING INTO AN ORDER THAT INCORPORATES THIS AGREEMENT, CUSTOMER AGREES TO THESE TERMS AND CONDITIONS.
This SaaS Subscription Agreement constitutes an agreement (this “Agreement”) by and between CISO Global, Inc., a Delaware corporation whose principal place of business is 6900 E. Camelback Road, Suite 900, Scottsdale, AZ 85251 (“Provider”) and the corporation, LLC, partnership, sole proprietorship, or other business entity executing an Order that incorporates this Agreement (“Customer”). This Agreement is effective as of the date Customer signs an Order which incorporates this Agreement (the “Effective Date”). Customer’s use of and Provider’s provision of Provider’s SaaS, SurfaceWatch™, are governed by this Agreement.
EACH PARTY ACKNOWLEDGES THAT IT HAS READ THIS AGREEMENT, UNDERSTANDS IT, AND AGREES TO BE BOUND BY ITS TERMS. THE PERSON EXECUTING AN ORDER THAT INCORPORATES THIS AGREEMENT ON CUSTOMER’S BEHALF REPRESENTS THAT THEY HAVE THE AUTHORITY TO BIND CUSTOMER TO THESE TERMS AND CONDITIONS.
- DEFINITIONS. The following capitalized terms will have the following meanings whenever used in this Agreement.
1.1. “AUP” means Provider’s acceptable use policy as stated in this Agreement.
1.2. “Customer Data” means all information processed or stored through the SaaS by Customer or on Customer’s behalf. Customer represents and warrants that (i) the Customer Data does not contain any unlawful content, materials, data, work, trade or service mark, trade name, link, advertising or services that actually or potentially violate any applicable law or regulation or is not used by Customer in accordance with this Agreement in a manner that infringes or misappropriates any U.S. proprietary or intellectual property of any person in the United States; (ii) Customer owns or has a licensed right to use the Customer Data, including but not limited to, the submitted domains, IP addresses, cloud accounts, assets, and third-party environments and (iv) it shall maintain all proper licenses on any and all Customer Data the subject of this Agreement.
1.3. “Documentation” means Provider’s standard user, administrator, API, and technical documentation related to use of the SaaS, as updated from time to time.
1.4. “Order” means any order form, quote, statement of work, subscription schedule, or other ordering document issued or accepted by Provider for access to or use of the SaaS that incorporates or is governed by this Agreement, including any renewal, amendment, or supplement thereto.
1.5. “Privacy/Security Law” means any applicable law or regulation governing the privacy, security, protection, processing, use, disclosure, or breach notification of personal data, but only to the extent such law or regulation applies to Provider’s handling of Customer Data under this Agreement and not to Customer’s independent collection, use, disclosure, or other processing of Customer Data.
1.6. “SaaS” means Provider’s hosted SurfaceWatch™ platform and related services identified in an Order. Customer’s subscription is measured by the domains, IP addresses, assets, users, API volume, or other metrics stated in the applicable Order (the “Subscription Metrics”).
1.7. “Term” is defined in Section 11.1 below.
1.8. “User” means any individual who uses the SaaS on Customer’s behalf or through Customer’s account or passwords, whether authorized or not. - THE SAAS.
2.1. Use of the SaaS. During the Term, Customer may access and use the SaaS for its internal business purposes pursuant to the terms of any outstanding Order, including such features and functions as the Order requires.
2.2. Documentation. Customer may reproduce and use the Documentation solely as necessary to support Users’ use of the SaaS.
2.3. SaaS Revisions. Provider may revise SaaS features and functions, including without limitation by removing such features and functions. If any such revision to the SaaS materially reduces features or functionality provided pursuant to an outstanding Order, Customer may within 30 days of notice of the revision terminate such Order, without cause, or terminate this Agreement without cause if such Order is the only one outstanding. - PAYMENT.
3.1. Subscription Fees. Customer shall pay Provider the fee set forth in each Order (the “Subscription Fee”) for each Term. Provider’s invoices are due within 30 days of issuance. For late payment, Customer shall pay interest charges from the time the payment was due at the rate that is the lower of 2% per month or the highest rate permissible under applicable law. Except as expressly provided in this Agreement or an Order, Provider will not be required to credit or refund the Subscription Fee.
3.2. Taxes. Amounts due under this Agreement are payable to Provider without deduction for any tax, tariff, duty, or assessment imposed by any government authority (national, state, provincial, or local), including without limitation any sales, use, excise, ad valorem, property, withholding, or value-added tax, whether or not withheld at the source (collectively, “Sales Tax”). Except as forbidden by applicable law, Provider may require that Customer submit applicable Sales Taxes to Provider. However, the preceding sentence does not apply to the extent that Customer is tax exempt, provided it gives Provider a valid tax exemption certificate within 30 days of the Effective Date. Provider’s failure to include any applicable tax in an invoice will not waive or dismiss its rights or obligations pursuant to this Section 3.2. If applicable law requires withholding or deduction of Sales Taxes or any other tax or duty, Customer shall separately pay Provider the withheld or deducted amount, over and above fees due. For the avoidance of doubt, this Section 3.2 does not govern taxes based on Provider’s net income. - CUSTOMER DATA & PRIVACY.
4.1. Management of Customer Data in General. The provisions below of this Section 4.1 are subject to applicable law, including Privacy/Security Laws.
(a) Limited Use. Provider shall not: (i) access, process, or otherwise use Customer Data other than as necessary to facilitate the SaaS; or (ii) give Customer Data access to any third party, except Provider’s subcontractors that have a need for such access to facilitate the SaaS and are subject to a reasonable written agreement governing the use and security of Customer Data. Further, Provider shall exercise reasonable efforts to prevent unauthorized disclosure or exposure of Customer Data.
(b) De-Identified Data. Notwithstanding the provisions of this Article 4, Provider may use, reproduce, and otherwise process De-Identified Data to provide, maintain, secure, support, analyze, improve, and develop Provider’s products and services, including aggregated benchmarking and security analytics, provided that Provider will not attempt to re-identify De-Identified Data and will not publicly disclose De-Identified Data in a manner that reasonably identifies Customer, any individual, or Customer’s confidential systems or assets. (“De-Identified Data” refers to Customer Data with the following removed: information that identifies or could reasonably be used to identify an individual person, a household, or Customer.)
(c) Privacy Policy and DPA. Customer acknowledges Provider’s privacy policy provided on its website and any data processing addendum (“DPA”) incorporated into the applicable Order. Provider may revise its privacy policy from time to time, provided that revisions will not reduce Provider’s express obligations under this Agreement, an Order, or any applicable DPA during the then-current Term.
(d) Required Disclosure. Notwithstanding the provisions of this Article 4, Provider may disclose Customer Data as required by applicable law or by proper legal or governmental authority. Provider shall give Customer prompt notice of any such legal or governmental demand and reasonably cooperate with Customer in any effort to seek a protective order or otherwise to contest such required disclosure, at Customer’s expense.
(e) Risk of Exposure. Customer recognizes and agrees that hosting data online involves risks of unauthorized disclosure or exposure and that, in accessing and using the SaaS, Customer assumes such risks. Except as expressly provided in this Agreement, the SLA, or any applicable DPA or security addendum, Provider offers no representation, warranty, or guarantee that Customer Data will not be exposed or disclosed through errors or the actions of third parties.
(f) Additional Fees. Customer recognizes and agrees that Provider may charge additional fees (without limitation) (a) for activities (if any) required by Privacy/Security Laws and (b) for activities Customer requests to help it comply with Privacy/Security Laws.
4.2. Data Accuracy. Provider will have no responsibility or liability for the accuracy of data uploaded to the SaaS by Customer, including without limitation Customer Data and any other data uploaded by Users.
4.3. Erasure. Following termination or expiration of an Order, Provider may delete or de-identify Customer Data after at least 30 days, subject to any longer period stated in an Order or DPA and Provider’s standard backup, security, and legal-retention practices. Provider should provide Customer a commercially reasonable opportunity to export Customer Data then available in the SaaS before deletion, unless deletion is required for security, legal, or compliance reasons.
4.4. Excluded Data. Customer warrants that (a) it has not and will not transmit Excluded Data (as defined below), or permit transmission of Excluded Data, to Provider or its computers or other media and, (b) to the best of its knowledge, Customer Data does not and will not include Excluded Data. Customer shall inform Provider of any Excluded Data within Customer Data promptly after discovery (without limiting Provider’s rights or remedies). Customer recognizes and agrees that: (i) the provisions of this Agreement related to Customer Data do not apply to Excluded Data; (ii) Provider has no liability for any failure to provide protections in the Excluded Data Laws (as defined below) or otherwise to protect Excluded Data; and (iii) Provider’s systems are not intended for management or protection of Excluded Data and may not provide adequate or legally required security for Excluded Data. Provider is not responsible or liable for any data exposure or disclosure or related loss to the extent that it involves Excluded Data. (“Excluded Data” means any data or information that is subject to heightened legal, regulatory, contractual, or industry-specific security, privacy, retention, transmission, processing, or access requirements that Provider has not expressly agreed in writing to support, including without limitation, protected health information, payment card information, nonpublic financial information, government classified information, export-controlled technical data, biometric or genetic data, children’s personal information, Social Security numbers, driver’s license or other government identification numbers, and any other data subject to specialized legal, regulatory, contractual, or industry-specific security or privacy requirements unless Provider has expressly agreed in writing to receive, process, or protect such data. “Excluded Data Laws” means any law or regulation governing Excluded Data, including without limitation any law or regulation protecting privacy or security rights of Excluded Data subjects.) - CUSTOMER’S RESPONSIBILITIES & RESTRICTIONS.
5.1. Acceptable Use Policy. Customer shall not, and shall not permit any User or third party to: (a) use the SaaS for service bureau, outsourcing, hosting, application service provider, time-sharing, or similar purposes, or otherwise make the SaaS available to or for the benefit of any third party; (b) provide SaaS passwords, credentials, or other log-in information to any third party; (c) share, disclose, publish, or otherwise make available to any third party any non-public SaaS features, functionality, content, screenshots, benchmarking or performance results, security information, or other non-public information regarding the SaaS; (d) access or use the SaaS to build or support a competitive product or service, to build a product or service using similar ideas, features, functions, or graphics, or to copy any ideas, features, functions, or graphics of the SaaS; (e) engage in web scraping, data scraping, data harvesting, or similar activity on or related to the SaaS, including without limitation through software that simulates human activity or through any bot, crawler, spider, or other automated tool; (f) interfere with or disrupt the integrity, security, availability, or performance of the SaaS; (g) attempt to gain unauthorized access to the SaaS or any related systems, networks, or data; (h) upload, transmit, or introduce malicious code, viruses, worms, time bombs, Trojan horses, or other harmful code; (i) use the SaaS in violation of applicable law or third-party rights; or (j) use the SaaS to probe, scan, test, monitor, or assess any systems, networks, domains, IP addresses, or assets without all required rights, consents, and authorizations. If Provider reasonably suspects any breach of this Section 5.1, including without limitation by any User, Provider may suspend Customer’s access to the SaaS without advance notice, in addition to any other rights or remedies available to Provider. Neither this Agreement nor the AUP requires Provider to take any action against Customer, any User, or any third party for violating this Section 5.1 or this Agreement, but Provider may take any such action it deems appropriate.
5.2. Unauthorized Access. Customer shall take reasonable steps to prevent unauthorized access to the SaaS, including without limitation by protecting its passwords and other log-in information. Customer shall notify Provider immediately of any known or suspected unauthorized use of the SaaS or breach of its security and shall use commercially reasonable efforts to stop and mitigate such breach.
5.3. Compliance with Laws. In its use of the SaaS, Customer shall comply with all applicable laws, including without limitation any and all Privacy/Security laws.
5.4. Users & SaaS Access. Customer is responsible and liable for: (a) all access to and use of the SaaS by Users, including without limitation any unauthorized User conduct and any User conduct that would violate the AUP or any requirement of this Agreement applicable to Customer; (b) all access to and use of the SaaS through Customer’s account, credentials, systems, networks, or integrations, whether authorized or unauthorized; and (c) all acts and omissions of Users and any other person or entity who accesses or uses the SaaS through Customer’s account or credentials, as if such acts and omissions were Customer’s own. - IP & FEEDBACK.
6.1. IP Rights to the SaaS. Provider retains all right, title, and interest in and to the SaaS, including without limitation all software used to provide the SaaS and all graphics, user interfaces, logos, and trademarks reproduced through the SaaS. This Agreement does not grant Customer any intellectual property license or rights in or to the SaaS or any of its components, except to the limited extent that such rights are necessary for Customer’s use of the SaaS as specifically authorized by this Agreement. Customer recognizes that the SaaS and its components are protected by trademark, copyright and other laws.
6.2. Feedback. Provider has not agreed to and does not agree to treat as confidential any Feedback (as defined below) that Customer or Users give Provider, and nothing in this Agreement or in the parties’ dealings arising out of or related to this Agreement will restrict Provider’s right to use, profit from, disclose, publish, keep secret, or otherwise exploit Feedback, without compensating or crediting Customer. Feedback will not be considered Customer’s trade secret. (“Feedback” refers to any suggestion or idea for improving or otherwise modifying any of Provider’s products or services.) - CONFIDENTIAL INFORMATION. “Confidential Information” means any nonpublic information disclosed by either party (the “Disclosing Party”) to the other party (the “Receiving Party”) either directly or indirectly, in writing, orally, or by inspection of tangible objects, and designated as confidential or which, under the circumstances surrounding disclosure, ought to be treated as confidential by the Receiving Party. Confidential Information includes, without limitation, nonpublic information relating to released or unreleased services or products, Documentation, intellectual property, trade secrets, business policies or practices, marketing plans, forecasts, projections and analyses, intellectual property development, financial information, customer information, Customer Data, security information, pricing, and other information the Disclosing Party is obligated to treat as confidential. Notwithstanding the foregoing, Confidential Information does not include information that: (i) is in the Receiving Party’s possession at the time of disclosure without obligation of confidentiality; (ii) is independently developed by the Receiving Party without use of or reference to Confidential Information; (iii) becomes known publicly, before or after disclosure, other than as a result of the Receiving Party’s improper action or inaction; or (iv) is approved for release in writing by the Disclosing Party. Each party is on notice that Confidential Information may include valuable trade secrets.
7.1. Nondisclosure. The Receiving Party shall not use Confidential Information for any purpose other than performing or receiving services under this Agreement (the “Purpose”). The Receiving Party: (a) shall not disclose Confidential Information to any employee or contractor unless such person needs access in order to facilitate the Purpose and is bound by written confidentiality obligations no less restrictive than those of this Article 7; and (b) shall not disclose Confidential Information to any other third party without the Disclosing Party’s prior written consent. Without limiting the generality of the foregoing, the Receiving Party shall protect Confidential Information with the same degree of care it uses to protect its own confidential information of similar nature and importance, but with no less than reasonable care. The Receiving Party shall promptly notify the Disclosing Party of any misuse or misappropriation of Confidential Information that comes to the Receiving Party’s attention. Notwithstanding the foregoing, the Receiving Party may disclose Confidential Information as required by applicable law or by proper legal or governmental authority. The Receiving Party shall give the Disclosing Party prompt notice of any such legal or governmental demand and reasonably cooperate with the Disclosing Party in any effort to seek a protective order or otherwise to contest such required disclosure, at the Disclosing Party’s expense.
7.2. Termination & Return. With respect to each item of Confidential Information, the obligations of Section 7.1 above (Nondisclosure) will terminate two years after the termination of the Order; provided that such obligations related to Confidential Information constituting trade secrets will continue so long as such information remains subject to trade secret protection pursuant to applicable law. Upon termination of the Order, the Receiving Party shall return all copies of Confidential Information to the Disclosing Party or certify, in writing, the destruction thereof, except for archival, backup, legal, compliance, or security records retained in accordance with the Receiving Party’s standard retention practices and continuing confidentiality obligations.
7.3. Injunction. Each party agrees that: (a) no adequate remedy exists at law if it breaches any of its obligations in this Article 7; (b) it would be difficult to determine the damages resulting from its breach of this Article 7, and such breach would cause irreparable harm to the other party; and (c) a grant of injunctive relief provides the best remedy for any such breach, without any requirement that the non-breaching party prove actual damage or post a bond or other security. Each party waives any opposition to such injunctive relief or any right to such proof, bond, or other security. (This Section 7.3 does not limit either party’s right to injunctive relief for breaches not listed.)
7.4. Retention of Rights. This Agreement does not transfer ownership of Confidential Information or grant a license thereto. Provider will retain all right, title, and interest in and to all Confidential Information.
7.5. Exception & Immunity. Pursuant to the Defend Trade Secrets Act of 2016, 18 USC Section 1833(b), Customer is on notice and acknowledges that, notwithstanding the foregoing or any other provision of this Agreement:
(a) Immunity. An individual shall not be held criminally or civilly liable under any Federal or State trade secret law for the disclosure of a trade secret that- (A) is made- (i) in confidence to a Federal, State, or local government official, either directly or indirectly, or to an attorney; and (ii) solely for the purpose of reporting or investigating a suspected violation of law; or (B) is made in a complaint or other document filed in a lawsuit or other proceeding, if such filing is made under seal.
(b) Use of Trade Secret Information in Anti-Retaliation Lawsuit. An individual who files a lawsuit for retaliation by an employer for reporting a suspected violation of law may disclose the trade secret to the attorney of the individual and use the trade secret information in the court proceeding, if the individual- (A) files any document containing the trade secret under seal; and (B) does not disclose the trade secret, except pursuant to court order. - REPRESENTATIONS & WARRANTIES.
8.1. From Provider. Provider represents and warrants that it is the owner of the SaaS and of each and every component thereof, or the recipient of a valid license thereto, and that it has and will maintain the full power and authority to grant the rights to use the SaaS set forth in this Agreement without the further consent of any third party. Provider further warrants that, during the Term, the SaaS will materially conform to the Documentation and any applicable SLA, if any. Provider’s representations and warranties do not apply to use of the SaaS in combination with hardware, software, data, or services not provided by Provider, or to Customer’s misuse, unauthorized modification, or breach of this Agreement. In case of breach of this Section 8.1, Provider, at its own expense, shall promptly: (a) secure for Customer the right to continue using the SaaS; (b) replace or modify the SaaS to make it non-infringing or conforming; or if such remedies are not commercially practical in Provider’s reasonable opinion, (c) credit prepaid unused fees for the affected SaaS for the remainder of the then-current Term following the date after which Customer access to the affected SaaS ceases as a result of such breach. This Section 8.1, in conjunction with Customer’s right to terminate this Agreement where applicable, states Customer’s sole remedy and Provider’s entire liability for breach of the warranty above in this Section 8.1.
8.2. From Customer. Customer represents and warrants that: (a) it has the full right and authority to enter into, execute, and perform its obligations under this Agreement and that no pending or threatened claim or litigation known to it would have a material adverse impact on its ability to perform as required by this Agreement; (b) it has accurately identified itself and it has not provided any inaccurate information about itself to or through the SaaS; and (c) it is a corporation, the sole proprietorship of an individual 18 years or older, or another entity authorized to do business pursuant to applicable law.
8.3. Warranty Disclaimers. Except to the extent set forth in Section 8.1 above, CUSTOMER ACCEPTS THE SAAS “AS IS,” WITH NO REPRESENTATION OR WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING WITHOUT LIMITATION IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, OR NONINFRINGEMENT OF INTELLECTUAL PROPERTY RIGHTS, OR ANY IMPLIED WARRANTY ARISING FROM STATUTE, COURSE OF DEALING, COURSE OF PERFORMANCE, OR USAGE OF TRADE. WITHOUT LIMITING THE GENERALITY OF THE FOREGOING: (a) EXCEPT AS EXPRESSLY PROVIDED IN ARTICLE 9, PROVIDER HAS NO OTHER OBLIGATION TO INDEMNIFY OR DEFEND CUSTOMER OR USERS AGAINST CLAIMS RELATED TO INFRINGEMENT OF INTELLECTUAL PROPERTY; (b) PROVIDER DOES NOT REPRESENT OR WARRANT THAT THE SAAS WILL PERFORM WITHOUT INTERRUPTION OR ERROR; (c) PROVIDER DOES NOT REPRESENT OR WARRANT THAT THE SAAS IS SECURE FROM HACKING OR OTHER UNAUTHORIZED INTRUSION OR THAT CUSTOMER DATA WILL REMAIN PRIVATE OR SECURE EXCEPT AS EXPRESSLY PROVIDED IN A DPA OR SECURITY ADDENDUM; AND (d) PROVIDER DOES NOT WARRANT THAT THE SAAS WILL IDENTIFY ALL ASSETS, EXPOSURES, VULNERABILITIES, THREATS, INCIDENTS, OR MISCONFIGURATIONS, THAT RESULTS WILL BE COMPLETE OR ERROR-FREE, OR THAT THERE WILL BE NO FALSE POSITIVES OR FALSE NEGATIVES. - INDEMNIFICATION.
9.1. Provider. Provider shall defend, indemnify, and hold harmless Customer against any third-party claim alleging that the SaaS, as provided by Provider and used in accordance with this Agreement and the Documentation, infringes or misappropriates a U.S. patent, copyright, trademark, or trade secret, subject to exclusions for Customer Data, Customer modifications, unauthorized use, and combinations not provided by Provider. Provider may procure continued use, modify or replace the SaaS, or terminate the affected Order and credit prepaid unused fees as Customer’s sole remedy for such claim.
9.2. Customer. Customer shall defend, indemnify, and hold harmless Provider and the Provider Associates against any third-party claim, suit, or proceeding arising out of or related to Customer’s or any User’s use or misuse of the SaaS, Customer Data, unauthorized scanning or monitoring, breach of Section 5.1, violation of law, or infringement or violation of third-party rights by materials or data submitted through Customer’s account, except to the extent caused by Provider’s gross negligence, willful misconduct, or breach of this Agreement. Customer’s obligations include settlement at Customer’s expense, payment of final judgments and court costs, and reimbursement of reasonable attorneys’ fees incurred before Customer’s assumption of the defense.
9.3. Settlement Rights. Provider will have the right, not to be exercised unreasonably, to reject any settlement or compromise that requires Provider or a Provider Associate to admit wrongdoing or liability or subjects either of them to an ongoing affirmative obligation. (“Provider Associates” are Provider’s officers, directors, shareholders, parents, subsidiaries, agents, successors, and assigns. A “Data Incident” is any unauthorized disclosure of, access to, or use of Customer Data, including Excluded Data, or violation of Privacy/Security Law through Customer’s account.) - LIMITATION OF LIABILITY.
10.1. Dollar Cap. PROVIDER’S CUMULATIVE LIABILITY FOR ALL CLAIMS ARISING OUT OF OR RELATED TO THIS AGREEMENT WILL NOT EXCEED THE FEES PAID BY CUSTOMER TO PROVIDER FOR THE ORDER GIVING RISE TO THE LIABILITY DURING THE TWELVE (12) MONTHS PRECEDING THE CLAIM GIVING RISE TO SUCH LIABILITY.
10.2. Excluded Damages. Except with regard to breaches of Article 7 (Confidential Information), IN NO EVENT WILL PROVIDER BE LIABLE FOR LOST PROFITS OR LOSS OF BUSINESS OR FOR ANY CONSEQUENTIAL, INDIRECT, SPECIAL, INCIDENTAL, OR PUNITIVE DAMAGES ARISING OUT OF OR RELATED TO THIS AGREEMENT.
10.3. Clarifications & Disclaimers. THE LIABILITIES LIMITED BY THIS ARTICLE 10 APPLY TO THE BENEFIT OF PROVIDER’S OFFICERS, DIRECTORS, EMPLOYEES, AGENTS, AND THIRD PARTY CONTRACTORS, AS WELL AS: (a) TO LIABILITY FOR NEGLIGENCE; (b) REGARDLESS OF THE FORM OF ACTION, WHETHER IN CONTRACT, TORT, STRICT PRODUCT LIABILITY, OR OTHERWISE; (c) EVEN IF PROVIDER IS ADVISED IN ADVANCE OF THE POSSIBILITY OF THE DAMAGES IN QUESTION AND EVEN IF SUCH DAMAGES WERE FORESEEABLE; AND (d) EVEN IF CUSTOMER’S REMEDIES FAIL OF THEIR ESSENTIAL PURPOSE. Customer acknowledges and agrees that Provider has based its pricing on and entered into this Agreement in reliance upon the limitations of liability and disclaimers of warranties and damages in this Article 10 and that such terms form an essential basis of the bargain between the parties. If applicable law limits the application of the provisions of this Article 10, Provider’s liability will be limited to the maximum extent permissible. For the avoidance of doubt, Provider’s liability limits and other rights set forth in this Article 10 apply likewise to Provider’s affiliates, licensors, suppliers, advertisers, agents, sponsors, directors, officers, employees, consultants, and other representatives. - TERM & TERMINATION.
11.1. Term. The term of this Agreement (the “Term”) will commence on the signing of an Order and will continue for the period set forth in the Order. Thereafter, the Term will renew for successive twelve (12) month periods, unless either party refuses such renewal by written notice 30 or more days before the renewal date.
11.2. Termination for Cause. Either party may terminate this Agreement for the other’s material breach by written notice specifying in detail the nature of the breach, effective in 30 days unless the other party first cures such breach, or effective immediately if the breach is not subject to cure.
11.3. Termination for Convenience. Either party may terminate this Agreement without cause upon thirty (30) days written notice to the other party, provided that with respect to an outstanding Order, termination shall be effective only upon completion or termination of the Order. However, if Customer terminates an Order prior to the end of the applicable Term, then Customer shall owe to Provider, as an early termination fee, an amount equal to One Hundred Percent (100%) of the monthly recurring charges due under the terminated Order for the remainder of the Term of such Order.
11.4. Effects of Termination. Upon termination of this Agreement, Customer shall cease all use of the SaaS and delete, destroy, or return all copies of the Documentation in its possession or control. Provider should make Customer Data then available in the SaaS available for export for at least 30 days after termination or expiration unless prohibited by law, security requirements, or non-payment, and may delete or de-identify Customer Data thereafter subject to the DPA and retention practices. The following provisions will survive termination or expiration of this Agreement: (a) any obligation of Customer to pay fees incurred before termination; (b) Articles and Sections 4.2 (De-Identified Data), 4.8 (Erasure), 6 (IP & Feedback), 7 (Confidential Information), 8.3 (Warranty Disclaimers), 9 (Indemnification), and 10 (Limitation of Liability); and (c) any other provision of this Agreement that must survive to fulfill its essential purpose. - MISCELLANEOUS.
12.1. Independent Contractors. The parties are independent contractors and shall so represent themselves in all regards. Neither party is the agent of the other, and neither may make commitments on the other’s behalf.
12.2. Notices. All notices permitted or required under this Agreement shall be in writing and shall be delivered by personal delivery, electronic mail, or by certified or registered mail, return receipt requested, and shall be deemed given upon personal delivery, five (5) days after deposit in the mail, or upon acknowledgement of receipt of electronic transmission. Notices shall be sent to the addresses set forth in the Order or such other address as either party may specify in writing.
12.3. Force Majeure. No delay, failure, or default, other than a failure to pay fees when due, will constitute a breach of this Agreement to the extent caused by acts of war, terrorism, hurricanes, earthquakes, epidemics, other acts of God or of nature, strikes or other labor disputes, riots or other acts of civil disorder, embargoes, government orders responding to any of the foregoing, or other causes beyond the performing party’s reasonable control.
12.4. Assignment & Successors. Neither party may assign this Agreement or any rights or obligations hereunder without the other party’s prior written consent, except that either party may assign this Agreement without consent to an affiliate or in connection with a merger, reorganization, sale of all or substantially all assets, or change of control, provided the assignee assumes the assigning party’s obligations. This Agreement will be binding upon and inure to the benefit of the parties’ respective successors and permitted assigns.
12.5. Severability. To the extent permitted by applicable law, the parties hereby waive any provision of law that would render any clause of this Agreement invalid or otherwise unenforceable in any respect. In the event that a provision of this Agreement is held to be invalid or otherwise unenforceable, such provision will be interpreted to fulfill its intended purpose to the maximum extent permitted by applicable law, and the remaining provisions of this Agreement will continue in full force and effect.
12.6. No Waiver. Neither party will be deemed to have waived any of its rights under this Agreement by lapse of time or by any statement or representation other than by an authorized representative in an explicit written waiver. No waiver of a breach of this Agreement will constitute a waiver of any other breach of this Agreement.
12.7. Choice of Law & Jurisdiction. This Agreement and all claims arising out of or related to this Agreement will be governed solely by the internal laws of the State of Arizona, including without limitation applicable federal law, without reference to: (a) any conflicts of law principle that would apply the substantive laws of another jurisdiction to the parties’ rights or duties; (b) the 1980 United Nations Convention on Contracts for the International Sale of Goods; or (c) other international laws. The parties consent to the personal and exclusive jurisdiction of the state courts located in Maricopa County, Arizona and the federal courts located in the District of Arizona. This Section 12.7 governs all claims arising out of or related to this Agreement, including without limitation tort claims. THE PARTIES WAIVE ANY RIGHT TO TRIAL BY JURY IN ANY CLAIM OR ACTION, WHETHER SOUNDING IN CONTRACT, TORT OR OTHERWISE, BETWEEN THE PARTIES ARISING OUT OF THIS AGREEMENT OR THE TRANSACTIONS RELATED HERETO.
12.8. Conflicts. In the event of any conflict, the following order of precedence applies: (1) the applicable Order or statement of work; (2) any applicable DPA; (3) any applicable SLA; (4) this Agreement; and (5) any Provider policy posted online, including without limitation the AUP or Privacy Policy, except where a policy expressly states that it controls for security or acceptable-use enforcement.
12.9. Construction. The parties agree that the terms of this Agreement result from negotiations between them. This Agreement will not be construed in favor of or against either party by reason of authorship.
12.10. Technology Export. Customer shall not: (a) permit any third party to access or use the SaaS in violation of any U.S. law or regulation; (b) export any software provided by Provider or otherwise remove it from the United States except in compliance with all applicable U.S. laws and regulations; (c) access or use the SaaS from any country or region subject to U.S. embargo or comprehensive sanctions; or (d) permit access to or use of the SaaS by any person or entity on a restricted-party list or for any prohibited end use. Without limiting the generality of the foregoing, Customer shall not permit any third party to access or use the SaaS in, or export such software to, a country subject to a United States embargo.
12.11. Entire Agreement. This Agreement sets forth the entire agreement of the parties and supersedes all prior or contemporaneous writings, negotiations, and discussions with respect to its subject matter. Neither party has relied upon any such prior or contemporaneous communications.
12.12. Amendment. Provider may amend this Agreement from time to time by posting an amended version at its website and sending Customer written notice thereof. Such amendment will be deemed accepted and become effective 30 days after such notice (the “Proposed Amendment Date”) unless Customer first gives Provider written notice of rejection of the amendment. In the event of such rejection, this Agreement will continue under its original provisions for the then-current Term, and the amendment will become effective at the start of Customer’s next Term following the Proposed Amendment Date unless Customer first terminates this Agreement pursuant to Article 11, Term & Termination. Customer’s continued use of the SaaS following the effective date of an amendment will confirm Customer’s consent thereto. Provider may revise the Privacy Policy and Acceptable Use Policy at any time by posting a new version of either at the Website, and such new version will become effective on the date it is posted; provided if such amendment materially reduces Customer’s rights or protections, notice and consent will be subject to the requirements above in this Section 12.12.