Registration is now open for 2026 OffenderWatch Symposium
See Details

MASTER SUBSCRIPTION SERVICES AGREEMENT

Last modified: September 23, 2026

This Master Subscription Services Agreement is by and between Watch Systems LLC (“Company”), and the governmental entity identified as “Customer” below (“Customer”) (each, a “Party” and together, the “Parties”), and is effective as of the last date of execution below (the “Effective Date”). In consideration of the agreements below, Company and Customer agree as follows:

Article 1

DEFINITIONS AND CONSTRUCTION

1.1 Definitions. The following defined terms used in the Agreement will have the meanings specified below:

“Agreement” means, collectively, this Master Subscription Services Agreement, and each Subscription Form and SOW that are then in effect.

“Applicable Registry Laws” means, collectively, the Sex Offender Registration and Notification Act (“SORNA”) (34 U.S.C. § 20901 et seq.), Title I of the Adam Walsh Child Protection and Safety Act of 2006, 28 C.F.R. Part 72, and all other applicable Laws governing the registration, notification, monitoring, supervision, or public disclosure of information relating to sex offenders, as each may be amended or replaced from time to time.

“Authorized Registry Purpose” means a purpose that is (a) expressly authorized or required by Applicable Registry Laws, (b) reasonably necessary for Customer’s lawful governmental functions relating to sex offender registration, notification, supervision, monitoring, community safety, law enforcement, or criminal justice administration, or (c) expressly authorized by the Agreement, a Subscription Form, or Customer’s documented lawful instructions to Company for processing Customer Data.

CJIS Requirements” means the Criminal Justice Information Services (CJIS) Security Policy published by the Federal Bureau of Investigation, as amended from time to time, and any related requirements imposed by a CJIS Systems Agency, State Identification Bureau, or equivalent authority.

“Commencement Date” means the date a Subscription Term begins as specified on the applicable Subscription Form.

“Company Extension” means software created by Company through its performance of Professional Services that communicates through a SaaS Application’s API to modify or supplement the functionality of that application. See Company SaaS Extension Policy for the terms governing Company Extensions and Customer-created extensions.

“Company Indemnitees” means the Company Parties and their respective owners, directors, officers, employees, representatives, and agents, and their respective successors and permitted assigns.

“Company IP” means the SaaS Applications, SaaS Services, Company Extensions, Documentation, Company’s Confidential Information, all related and underlying technology and documentation, and any modifications or improvements to or derivative works based on, any of them.

“Company Parties” means Company and its affiliates.

“Confidential Information” means (a) nonpublic technical and non-technical data or information, including trade secrets, whether in oral, written, graphical or electronic form, that is announced or labeled to be the confidential information of a Party, or which, by its nature, the disclosing Party would reasonably deem to be confidential, (b) the SaaS Applications, including the Documentation, and (c) the terms of the Agreement. Confidential Information does not include Customer Data (which is subject to separate obligations and restrictions in the Agreement).

“Criminal Justice Information” means criminal justice information identified or supplied by Customer and subject to the CJIS Security Policy or other CJIS Requirements, including criminal history record information and law enforcement sensitive information.

“Customer Data” means all information, content, records, configurations, settings, instructions, and data that Customer or a person or system acting on Customer’s behalf or under Customer’s authority provides, submits, transmits, uploads, makes available, or directs Company to process through the Services. Customer Data excludes Usage Data and Company IP.

“Customer Indemnitees” means Customer and its current and former officers, officials, employees, representatives, agents, and authorized contractors, service providers, and other Customer Personnel, but only to the extent acting in an official or authorized capacity for Customer in connection with the Agreement, and their respective successors and permitted assigns.

“Customer Input” means suggestions, enhancement requests, recommendations, or other feedback provided by the Customer Parties to Company relating to the operation or functionality of the SaaS Services.

“Customer Parties” means Customer and Customer Personnel.

“Customer Personnel” means Customer’s employees, employees of independent staffing agencies engaged by Customer for the sole purpose of staff augmentation, and, with Company’s consent, employees of other third-party service providers, in each case, who are authorized by Customer to use the SaaS Services, who are under nondisclosure and nonuse obligations comparable to the nondisclosure and nonuse provisions set out in the Agreement, and for whom Customer assumes responsibility for compliance with the terms and conditions of the Agreement.

“Customer Registry Decisions” means all decisions, determinations, configurations, settings, approvals, rejections, designations, instructions, classifications, legal determinations, and actions by Customer or Customer Personnel relating to Registrant Data, including (a) the acceptance, rejection, or processing of data or submissions, (b) public and nonpublic classifications, (c) publication, dissemination, disclosure, withholding, or restriction, (d) correction, removal, takedown, warning, notification, and due-process decisions, (e) deadlines, workflows, reminders, notices, tier assignments, public website settings, NSOPW feeds, interagency sharing, and field-level disclosure settings within the SaaS Services, (f) the determination of which Applicable Registry Laws, CJIS Requirements, public-records Laws, constitutional requirements, and agency policies apply and how they apply, (g) retention, destruction, legal holds, and records-management instructions, and (h) any other exercise of Customer’s legal authority as a Registry Authority or Governmental Entity.

“Customer Support” means technical support and related services included in the Subscription Services provided by Company to Customer pursuant to Company’s standard customer support policies as they exist or may be modified from time to time.

“Customer Terms” has the meaning set forth in Section 15.11.

“Data Breach” means a Security Incident (or series of related Security Incidents) involving unauthorized use or disclosure of Customer Data caused directly by Company’s failure to maintain or adhere to the Security Program or Company’s gross negligence or willful misconduct.

“Data Center” means a third-party owned cloud-computing data center contracted by Company to host one or more of the SaaS Applications in connection with its provision of SaaS Services.

“Documentation” means documentation regarding a SaaS Application’s computer software, which may include release notes, one or more user, installation or configuration guides, minimum system requirements, including software or browser requirements, and other documents, as they may exist or be modified from time to time.

“Due Date” means thirty (30) days following an invoice date.

“Fees” means all fees and reimbursement for Reimbursable Expenses, payable by Customer to Company for the Services, and all taxes and associated interest and penalties payable by Customer to Company pursuant to the Agreement.

“Force Majeure” means any cause beyond the reasonable control of a Party that interrupts, delays or prevents that Party’s performance as required, including, to the extent beyond that Party’s reasonable control: unusually severe weather; damage to machinery or equipment; disruption or shortage in public or private services such as transportation, communications, electric power, or other utilities or vital infrastructure; disruption or failure of the Internet, the Data Center infrastructure, or other computer networks, or major computer or software systems; Law; judicial or governmental actions; civil disturbances, riots, epidemics, wars, terrorist attacks, sabotage, embargos, natural disasters, or fires; or acts of God.

“Governmental Entity” means the government of the United States, any state, territory, possession, or federally recognized Indian tribe, and any local government, county, parish, municipality, political subdivision, department, agency, instrumentality, court, corrections authority, probation or parole authority, law enforcement agency, public safety or criminal justice agency, registry authority, or other governmental body or entity of any of the foregoing, in each case acting in its governmental capacity.

“Indemnifying Party” means a Party obligated to provide indemnification under Article 10.

“Indemnitee” means a Customer Indemnitee or Company Indemnitee, as applicable.

“Information Assets” means data, software and systems that are managed to ensure their confidentiality, integrity and availability.

“Law” means any declaration, decree, directive, legislative enactment, statute, order, ordinance, regulation, rule or other binding action of or by any governmental authority.

“Malware” means software viruses, worms, Trojan horses, time bombs, back doors, or other disabling or harmful computer code, files, scripts, agents, programs, or devices.

“Mandatory Government Requirements” has the meaning set forth in Section 14.2.

“Person” means a natural person or a corporation, partnership, limited liability company, trust, governmental body or agency, or other legal entity.

“Premature Termination” means Customer’s termination of the Agreement or its subscription to one or more SaaS Services where not permitted under the Agreement, or Company’s termination of the Agreement or Customer’s subscription to one or more SaaS Services pursuant to Section 12.2.

“Professional Services” means information technology services provided by Company to Customer related to one or more SaaS Applications, including software configuration, integration with Customer systems, creation of Company Extensions, consulting, analysis, and training, in accordance with the Agreement and any applicable SOWs, but not including SaaS Services and Customer Support.

“Professional Services Fees” means the fees for Professional Services charged for time and materials or on another basis agreed to by the Parties.

“Protected Registry Fields” means categories of Registrant Data that Customer designates for restricted handling or that Applicable Registry Laws require Customer to withhold, redact, or otherwise protect from public disclosure, including victim identity information, Social Security numbers, non-conviction arrest information, internet identifiers, remote communication identifiers, passport and immigration-document numbers, and any other information that Applicable Registry Laws require to be excluded from public registry websites or otherwise restricted, including, for public registry website purposes, information exempted from public disclosure by the Attorney General under 34 U.S.C. § 20920(b) or by applicable state registry law, except to the extent that disclosure is expressly permitted or required by Applicable Registry Laws for a specific recipient or purpose.

“Public Registry Data” means the subset of Registrant Data that Customer, in the exercise of its authority as a Registry Authority and in compliance with Applicable Registry Laws, has designated for publication on a public sex offender registry website or inclusion in the Dru Sjodin National Sex Offender Public Website (NSOPW).

“Registrant” means a natural person who is subject to a sex offender registration obligation under Applicable Registry Laws and whose information is included in Registrant Data supplied by or on behalf of Customer or by a person or system acting under Customer’s authority.

“Registrant Data” means Customer Data that identifies, relates to, describes, or is reasonably capable of being associated with a Registrant, including Registration Information, together with any outputs generated or processed by the SaaS Services from that data. Registrant Data is a subcategory of Customer Data.

“Registration Information” means the subset of Registrant Data collected directly from or submitted by a Registrant in connection with registration, identity verification, supervision, monitoring, or reporting, including information required or permitted under Applicable Registry Laws.

“Registry Authority” means the law enforcement agency, corrections agency, probation or parole authority, registry authority, or other Governmental Entity that is responsible under Applicable Registry Laws for administering, maintaining, or enforcing sex offender registration and notification requirements within its jurisdiction.

“Restricted Registry Data” means Registrant Data that is not Public Registry Data or is not designated by Customer for general public disclosure, including Protected Registry Fields and any other nonpublic Registrant Data.

“Reimbursable Expenses” means all pre-approved, out-of-pocket expenses incurred by Company in performing Professional Services or Customer Support for Customer.

“SaaS Application” means each Internet-based software-as-a-service application specified on the Subscription Forms, including APIs, and where the context requires, the relevant Documentation, but excluding in all cases all Third-Party Applications incorporated into, integrated with, provided with, or otherwise made available through any SaaS Application.

“SaaS Services” means the subscription-based cloud services providing Customer remote access to and use of the SaaS Applications (including any Company Extensions) and Third-Party Applications running in a cloud environment.

“Security Incident” means an unauthorized access to, or acquisition, deletion, alteration, use, unavailability, or disclosure of, Customer Data in Company’s possession or control in connection with Company’s provision of the SaaS Services, except to the extent caused solely by Customer, Customer Personnel, or Customer’s systems, credentials, configurations, instructions, or downstream recipients.

“Sensitive Registry Data” means Registrant Data that includes Protected Registry Fields, Criminal Justice Information, or any other category of Registrant Data that Applicable Registry Laws or the CJIS Security Policy require to be subject to enhanced access controls, encryption, logging, or restricted dissemination.

“Services” means the services, including SaaS Services, Professional Services, and Customer Support, provided by Company to Customer under the Agreement.

“SOW” means a written statement of work in the form provided by Company that Company and Customer enter into pursuant to the Agreement and that describes the applicable Professional Services that Customer has agreed to acquire from Company. For the avoidance of doubt, Customer’s purchase orders, order forms, specifications, change orders, or other similar customer-issued documents will not constitute SOWs.

“Subscription Fees” means the fees for the SaaS Services and related Customer Support.

“Subscription Form” means a written order in the form provided by Company that Company and Customer enter into pursuant to the Agreement and that specifies the applicable Subscription Services that Customer has agreed to obtain from Company and the Commencement Date, Subscription Term, Usage Limitations, and Subscription Fees for those Services. For the avoidance of doubt, Customer’s purchase orders, order forms, specifications, change orders, or other similar customer-issued documents will not constitute Subscription Forms.

“Subscription Period” means a period to which a payment of Subscription Fees relates as set out in a Subscription Form.

“Subscription Services” means the SaaS Services and the related Customer Support.

“Subscription Term” means the term of Customer’s subscription to a SaaS Service as shown on a Subscription Form.

“Third-Party Applications” means any software application that is owned or provided by or through any third-party.

“Usage Data” means transaction, usage, telemetry, performance, diagnostic, and service-operation data collected by or on behalf of Company relating to the operation, support, security, or Customer’s use of the SaaS Services.

“Usage Limitations” means the permitted levels of use of a SaaS Service as specified on the applicable Subscription Form (such as number of permitted users, or number or identity of permitted sites).

1.2 Conflicts. Except as otherwise agreed by the Parties, if there is a conflict involving the terms of the Agreement, the following order of precedence will apply: (a) applicable mandatory provisions of Law that cannot lawfully be waived or modified by contract, (b) this Master Subscription Services Agreement, including any amendment expressly executed by authorized representatives of both Parties, (c) any Subscription Form, but solely with respect to the specific SaaS Services, Usage Limitations, Subscription Fees, Subscription Term and other commercial matters expressly stated therein, (d) any SOW, but solely with respect to the specific Professional Services, Professional Services Fees and other commercial matters expressly stated therein, and (e) any other document, but only to the extent expressly accepted in writing by an authorized representative of Company. The provisions of Article 7 will control over general confidentiality, privacy, and data security provisions of the Agreement with respect to Registrant Data, except to the extent that mandatory Law requires otherwise. Notwithstanding the foregoing provisions of this Section, for matters within the scope of Criminal Justice Information, including handling, security, access, use, disclosure, dissemination, retention, return, deletion, and disposition, mandatory nonwaivable Law will control generally, and the official FBI-approved CJIS Security Addendum, including its certification page, will have highest priority among the contract documents, followed by this Master Subscription Services Agreement, and then any Subscription Form, SOW, or any other document as provided in this Section. The official FBI-approved CJIS Security Addendum may be modified only by the FBI or with required FBI approval and cannot be altered, amended, or superseded by any conflicting term in the Agreement.

1.3 Interpretation. The attached Exhibit 1 is incorporated into and deemed part of this Master Subscription Services Agreement for all purposes. All references to this Master Subscription Services Agreement include the attached Exhibit 1. Unless otherwise expressly stated, all references to Articles, Sections, subsections, and clauses refer to those of this Master Subscription Services Agreement, and the words “hereof,” “herein,” and “hereunder” refer to the Agreement as a whole. The word “or” is not exclusive. The word “include” and its derivatives are not terms of limitation. The words “will” and “shall” are expressions of command, not merely of future intent or expectation. Unless otherwise expressly stated, the words “day,” “month” and “year” mean, respectively, calendar day, calendar month and calendar year. References to any Law will be to such Law as amended, or to a newly adopted Law replacing such Law. Headings are included for ease of reference only and will not affect the interpretation or construction of the Agreement.

Article 2

SUBSCRIPTION SERVICES

2.1 Provision of Subscription Services. Company will make available to Customer under all applicable proprietary rights of Company the SaaS Services specified on one or more Subscription Forms, and related Customer Support, during the applicable Subscription Term, subject to the terms of the Agreement. The SaaS Services provide functionality for Customer to submit, configure, store, process, and obtain outputs from Customer Data. Customer or persons or systems acting on Customer’s behalf or under its authority supply all Customer Data processed under the Agreement, and Company does not provide, license, transfer, broker, sell, or otherwise make available to Customer any data from another source. When executed by an authorized representative of each Party, a Subscription Form will automatically become part of the Agreement without further action by the Parties.

2.2 Customer Right to Use. Customer has the right, through Customer Personnel, to use the Subscription Services only (a) on a subscription basis during the Subscription Term, (b) in accordance with the Documentation, (c) subject to (i) the Usage Limitations, (ii) any additional terms applicable to a Subscription Service (as set out in Exhibit 1 to this Master Subscription Services Agreement), (iii) any terms imposed by suppliers of Third-Party Applications, (iv) the terms of Article 7, and (v) other terms specified in the applicable Subscription Form, and (d) solely in the ordinary course of Customer’s governmental operations and functions. Company grants Customer no rights or implied licenses in the Subscription Services, or any intellectual property rights in them, other than as expressly granted in the Agreement.

2.3 Use by Customer Personnel. Customer will ensure that Customer Personnel (a) access the SaaS Services or Registrant Data only when they have a need to do so for an Authorized Registry Purpose, (b) before receiving access, are bound by written confidentiality, security, use, disclosure, and data-handling restrictions at least as protective as those in the Agreement, and (c) comply with the Agreement, with Customer responsible for their acts and omissions relating to the Agreement.

2.4 Updates to the Subscription Services. Company makes reasonable updates or modifications to the Subscription Services from time to time and in accordance with its standard policies, provided that those updates or modifications will not cause a material degradation of the Subscription Services. All updates are mandatory with deployment at Company’s sole discretion, and must be accepted by Customer.

2.5 Restrictions. Customer will not, and will not permit any Customer Personnel or third party to, (a) allow anyone other than Customer Personnel to use the Subscription Services without Company’s prior written consent, (b) use the Subscription Services for the benefit of any third party, except as expressly permitted by Article 7, (c) work around any technical limitations intended to restrict the manner in which Customer may use the Subscription Services, (d) disassemble, reverse engineer, or decompile the Subscription Services or access them to create (i) any software, service, or product performing or containing comparable functions or features, or (ii) a competitive software, product, or service using similar ideas, features, functions, or graphics as the SaaS Services, (e) copy, modify, or create any derivative works based on the Subscription Services, or any of the SaaS Services’ features, functions, interfaces, integrations, or graphics, (f) sell, resell, license, sublicense, distribute, make available, rent, or lease any of the Subscription Services, or include any of the Subscription Services in a service bureau or outsourcing offering, (g) use the SaaS Services to store or transmit infringing, libelous, or otherwise unlawful or tortious material, or in violation of a Law or of third-party privacy rights, (h) use the SaaS Services to store or transmit Malware or (i) permit direct or indirect access to or use of the Subscription Services in a way that circumvents the Usage Limitations.

2.6 Suspension. Company may suspend Customer’s or any Customer Personnel’s access to the SaaS Services (in whole or in part), block data exports, quarantine Customer Data, disable publication or API feeds, or decline to execute Customer’s instructions, in each case without liability or penalty if Company reasonably determines that continued access or activity, including any Customer instruction, configuration, or use of Customer Data, may (a) violate Applicable Registry Laws or other Law, (b) expose Protected Registry Fields or Sensitive Registry Data to unauthorized recipients, (c) compromise the security, integrity, or availability of the SaaS Services, Customer Data, or other customers’ data, (d) be outside the scope of the Agreement or Customer’s documented lawful instructions, or (e) create material liability for Company. Company will provide Customer with prompt notice of any such action and will cooperate in good faith to resolve the underlying concern as expeditiously as reasonably practicable.

2.7 Third-Party Applications. Customer acknowledges that certain SaaS Applications may be powered by Third-Party Applications. Third-Party Applications are not governed by any of the provisions of the Agreement. Rather, they are governed exclusively by the terms and conditions issued by the applicable third-party vendors. Customer will obtain, review and accept such terms and conditions prior to using any Third-Party Applications. Notwithstanding anything to the contrary, Customer agrees that (a) any use of, exchange of data with or other interaction between Customer and a Third-Party Application is solely between Customer and the applicable third-party vendor and is governed by that third-party’s terms, conditions and privacy policies, and (b) Company will have no obligations, responsibilities or liability with respect to any Third-Party Application.

2.8 Usage Verification. To verify Customer’s compliance with the restrictions in Section 2.5 and the Usage Limitations, Company may monitor Customer’s use of the SaaS Services, and, on Company’s request, Customer will provide responses, certified by an authorized representative of Customer, to Company’s usage surveys and other reasonable requests for information.

2.9 Duty to Cooperate. Customer will provide all information, access, security authorization, communications mechanisms, workspace, computing resources, and other services and support materials that Company may reasonably require to timely provide the Subscription Services, perform its other obligations, or exercise its rights under the Agreement.

2.10 Notification of Violation of Company’s Rights. If Customer becomes aware of any threatened, suspected, or actual misappropriation, theft, misuse, or unauthorized use of any of the Subscription Services, Customer promptly will notify Company of that fact and reasonably cooperate with Company regarding Company’s actions to rectify the situation.

2.11 Fees. For the Subscription Services, Customer will pay the Subscription Fees set out on the applicable Subscription Form.

Article 3

PROFESSIONAL SERVICES

3.1 Engagement. Customer may acquire Professional Services pursuant to an SOW. When executed by an authorized representative of each Party, an SOW will automatically become part of the Agreement without further action by the Parties. Customer may terminate all or a portion of those Professional Services not yet performed on thirty (30) days’ written notice.

3.2 Change Order. If a Party requests a change to an SOW that Company believes will result in a change in the scope of Professional Services or the schedule for completing the work or the estimate of the Professional Services Fees, then Company will provide Customer a written change order identifying the changes, and Customer will indicate its acceptance by signing the change order.

3.3 Personnel. If Customer notifies Company that it is not satisfied with a Company resource assigned to perform Professional Services, Company will take reasonable action to resolve Customer’s concerns short of removal. If the Parties mutually determine that it is necessary to replace a resource, Company will replace them in a reasonable time with a resource having the appropriate training, skills, and experience. Each Party will use reasonable efforts to minimize turnover of their respective personnel involved in a Professional Services engagement.

3.4 Acceptance. Except as otherwise agreed, where an SOW provides for acceptance of specified Professional Services deliverables, then Customer will accept or reject those deliverables within ten (10) days after their receipt based on the specifications in the applicable SOW. Any rejection must be reasonable and identify the reasons for the rejection, including a list of errors or deficiencies. Customer’s failure to reject the deliverables within ten (10) days will be deemed an acceptance. Following Customer’s rejection, Company will use reasonable efforts to correct the errors or deficiencies within a reasonable time. If Company fails to correct the errors or deficiencies within a reasonable time, Customer may terminate the applicable Professional Services and any other adversely impacted Professional Services, and Company will refund the Professional Services Fees for those and those other adversely impacted Professional Services.

3.5 Fees and Reimbursable Expenses. For Professional Services rendered prior to termination of an applicable SOW, Customer will pay Company (a) the Professional Services Fees and (b) the amount of Reimbursable Expenses determined in accordance with the then-current Company Employee Travel & Expense Reimbursement Policy.

Article 4

FEES

4.1 Invoicing and Payment. Unless otherwise agreed by the Parties, Company will invoice Customer as follows: (a) the Subscription Fees for any initial Subscription Period on or about the Commencement Date of the applicable Subscription Form, and subsequent Subscription Fees no less than thirty (30) days in advance of the applicable Subscription Period; (b) Professional Services Fees and Reimbursable Expenses on a monthly basis; and (c) any other amounts as specified in the Agreement or as agreed by the Parties. Customer may request deviations from Company’s regular invoicing practices, such as using an outsourcing service or entering billing hours into Customer’s system and Company may reasonably decline these requests or charge a reasonable administrative fee to cover all related direct costs. Customer will notify Company of any invoiced amounts that it disputes in good faith and provide reasonable support for its position prior to the Due Date of the applicable invoice. Unless otherwise specified in the applicable Subscription Form, Customer will pay all undisputed Fees and other amounts due to Company on or before the Due Date of the applicable invoice, and all disputed Fees and other amounts resolved in Company’s favor promptly following that resolution.

4.2 Late Payment. Time is of the essence with respect to Customer’s payment obligations. If any amounts owed by Customer remain unpaid for forty-five (45) days following their Due Date, (a) interest will accrue from the Due Date at the lesser rate of (i) 1.5% per month, or (ii) the maximum rate permitted by Law, (b) Company will have the right to recover its collection agency fees, court costs, and reasonable attorney’s fees incurred in collecting the late payments, and (c) in addition to any other rights or remedies Company has under the Agreement, Company may, on at least five (5) business days’ written notice to Customer, suspend the SaaS Service or performance of Professional Services until Customer pays all outstanding amounts due.

4.3 Taxes. The Fees do not include, and Customer is solely responsible for, any direct or indirect local, state, federal or foreign sales, use, property, excise, value added, gross receipts, or other taxes levied as a result of the transactions contemplated in the Agreement (but not employment taxes or taxes based on net income), including Company’s sale, license, or provision to Customer, or Customer’s purchase, license, receipt, or use, of the Services, SaaS Applications or Third-Party Applications, including any interest and penalties for failure timely to pay those taxes, except to the extent Company’s negligence caused the interest or penalty to accrue. If Company has the legal obligation to pay or collect taxes for which Customer is responsible under this Section, Company will invoice Customer for those taxes, and Customer will pay that amount on or before the Due Date, unless Customer provides Company with a valid tax exemption certificate authorized by the appropriate taxing authority. Customer will deduct from all payments of Fees the amount of all legally required tax withholdings and provide Company with official tax receipts or other evidence issued by the applicable tax authorities for those payments.

Article 5

CONFIDENTIALITY

5.1 Receiving Party Obligations. Each Party acknowledges that it may be provided or otherwise gain access to the other Party’s Confidential Information during the term of the Agreement. Except as provided in Sections 5.2 or 5.3, with respect to the other Party’s Confidential Information, each Party will:

(a) protect it with a reasonable level of care and at a level no less than the level of care that Party uses to protect its own Confidential Information;

(b) not, without the prior written consent of the other Party, disclose it to any third party, except to that Party’s employees or agents or, in Company’s case, to the contractors and subcontractors of Company Parties involved in Company’s provision of Services who (i) reasonably need to know it to assist that Party, or act on its behalf, in exercising that Party’s rights or performing its obligations under the Agreement, (ii) are informed of the confidential nature of it, and (iii) are subject to nondisclosure obligations and limitations on use with respect to it no less restrictive than the provisions of this Article;

(c) not, without the prior written consent of the other Party, use it, or permit it to be accessed or used, for any purpose other than as reasonably necessary to exercise that Party’s rights or perform its obligations under the Agreement; and

(d) be responsible for the acts or omissions of its employees or agents relating to their obligations described in Section 5.1(b)(iii).

5.2 Exceptions to Nondisclosure Obligations. A Party’s nondisclosure obligations set out in Section 5.1 will not apply with respect to the other Party’s Confidential Information that (a) becomes available to that Party on a nonconfidential basis from a third party, provided, to the best of that Party’s knowledge, that third party was not prohibited from disclosing it on a nonconfidential basis at the time that third party made the disclosure, (b) was known by or in the possession of that Party, as established by documentary evidence, prior to that Party’s receipt of it, or (c) that Party has developed independently, as established by documentary evidence, without reference to any Confidential Information received from the other Party or accessed as a result of the Agreement. In addition, a Party may disclose the other Party’s Confidential Information if required by Law; provided that the disclosing Party first will, to the extent legally permitted, make reasonable efforts to notify the other Party promptly of that requirement so that the other Party may seek, at its sole cost and expense, a protective order or other remedy, and will use its reasonable efforts to obtain confidential treatment or a protective order with respect to the information. With respect to Customer’s obligations under applicable public-records, open-records, freedom-of-information or similar Laws, the provisions of Section 14.4 will govern. Finally, Company may use Customer’s name, including any trade name, and logo (in accordance with any trademark guidelines provided by Customer) in Company’s promotional materials, including its press releases, customer lists, and presentations to third parties, and may include a brief description of the SaaS Applications and the Services.

5.3 Duration. The covenants in Sections 5.1(a) and (b) will continue throughout the term of the Agreement and for an additional two (2) years following its expiration or termination; provided, with respect to Confidential Information that constitutes trade secrets under applicable Law, the Parties obligations will only terminate when that Confidential Information no longer constitutes trade secrets. Section 5.1(c) will continue during the term of the Agreement and indefinitely following its expiration or termination.

5.4 Return of Confidential Information. On the request by the other Party, a Party promptly will return to the other Party, or destroy, all copies and embodiments of the other Party’s Confidential Information except to the extent reasonably necessary or appropriate for continuing to perform its obligations under the Agreement or to comply with applicable Law; except that the above requirement will not apply to latent data, such as deleted files, memory dumps, swap files, temporary files, printer spool files, and metadata, that are generally retrievable only by computer forensics experts and considered inaccessible without the use of specialized tools and techniques.

Article 6

DATA SECURITY

6.1 Company Security Program. Company will maintain and adhere to an information security program (as amended, or any newly adopted program replacing that program) (“Security Program”) designed to protect the confidentiality and security of Customer Data while being processed and maintained in the SaaS Services. Company may update the Security Program from time to time so long as the updates will not materially diminish the Security Program’s protections. The current Security Program includes SOC reports for the SaaS Services, consistent with industry standards. Any applicable official FBI-approved CJIS Security Addendum controls within its scope under Section 1.2. The Parties acknowledge that Company will maintain and process Customer Data in a cloud environment in connection with its provision of SaaS Services, and that Company’s obligations with respect to Customer Data are set forth exclusively in this Article and Article 7.

6.2 Customer’s Obligations. Customer will implement, maintain, and adhere to appropriate organizational, administrative, and technical security measures, consistent with Customer’s governmental obligations and applicable Law, to prevent unauthorized access to or use or appropriation of Customer Data and Company’s and Customer’s non-public Information Assets. Those measures, which may include firewalls, encryption protocols, access codes, least-privilege controls, user lifecycle controls, secure export procedures, and other appropriate protections, will be consistent with industry standards and applicable Law. In addition, Customer will implement and maintain the agency-side measures and controls allocated to it under Article 7 and any applicable CJIS Security Addendum. Customer is solely responsible for the security of Customer’s systems, credentials, Customer Personnel, integrations, configurations, publication settings, and Customer Data before submission to or after export from the SaaS Services, and for the acts of downstream recipients selected or authorized by Customer.

6.3 Security Incident. If either Party learns that there has been a Security Incident affecting Customer Data in its possession or control that it reasonably determines has compromised or is reasonably likely to compromise Customer Data, it will notify the other Party within twenty-four (24) hours following that determination. Company’s notification and cooperation obligations apply to Security Incidents within Company’s systems or control; Customer’s notification and cooperation obligations apply to incidents caused by Customer, Customer Personnel, Customer’s systems, credentials, configurations, instructions, publication or disclosure decisions, or downstream recipients. Following notice, the Parties will cooperate in implementing a plan to investigate, contain, remediate, and mitigate adverse consequences, with assistance outside Company’s express obligations under the Agreement provided at Customer’s expense. Neither Party’s obligation to notify or cooperate constitutes an admission of fault, liability, or responsibility.

Article 7

Sex Offender Registry Data
and Compliance

7.1 Purpose and Allocation of Roles. This Article establishes the rights, obligations, restrictions, and allocation of responsibility for Customer-supplied Registrant Data and compliance with Applicable Registry Laws. Company is a SaaS provider processing Customer Data on Customer’s behalf and under Customer’s documented lawful instructions. Customer is the Registry Authority for its jurisdiction and is solely responsible for Customer Registry Decisions. Nothing in the Agreement makes Company a governmental or law enforcement agency, Registry Authority, or independent source, verifier, or decision-maker with respect to Customer Data.

7.2 Applicable Registry Laws and Customer Registry Decisions. Customer will comply with all Applicable Registry Laws and other Laws applicable to its role as a Governmental Entity and Registry Authority and, as applicable, as the provider, controller, business, or agency responsible for Customer Data. Customer is solely responsible for (a) identifying the legal and agency requirements applicable to Customer and its jurisdiction, (b) providing Company with the Customer Data, configurations, classifications, and other documented lawful instructions Customer wants Company to process, (c) configuring the SaaS Services to reflect Customer’s legal determinations, (d) making all legal determinations regarding the classification, publication, restriction, correction, retention, and destruction of Customer-supplied Registrant Data, and (e) identifying in writing any jurisdiction-specific requirement that requires Company to take or refrain from taking a specific action. Subscription Forms may identify additional jurisdiction-specific rules, configurations, and requirements. Company is responsible only for its express obligations under the Agreement, the Security Program, an applicable Subscription Form, or an executed official CJIS Security Addendum. Company will use commercially reasonable efforts to support Customer’s documented lawful configurations and instructions but neither provides legal advice nor warrants that any configuration, output, publication, or workflow satisfies any particular Law.

7.3 Customer-Supplied Registrant Data and Processing Instructions. Customer will provide all Customer Data and documented lawful instructions that it wants Company to process through the SaaS Services. Company will process that data on Customer’s behalf in accordance with the Agreement and applicable Law, and has no obligation to supply or obtain data from Registrants or any other source.

7.4 Authorized Registry Purposes and Prohibited Uses. Customer will access and use Customer Data and outputs generated from Customer Data solely for Authorized Registry Purposes. Without limiting Section 2.5, Customer will not, and will not permit Customer Personnel or any third party to, use Customer Data for any purpose that is not an Authorized Registry Purpose, including (a) using Customer Data to unlawfully injure, harass, threaten, stalk, discriminate against, or commit a crime against any Registrant or other person identified in it, (b) selling, licensing, commercializing, or using Customer Data for advertising, marketing, profiling, or scoring unrelated to public safety or law enforcement, (c) scraping, bulk-downloading, or bulk-exporting Customer Data except through features expressly provided in the SaaS Services, (d) disclosing or publishing Protected Registry Fields or Restricted Registry Data except as expressly permitted by Applicable Registry Laws, (e) re-identifying deidentified or anonymized outputs derived from Customer Data or training machine-learning or AI systems unrelated to the SaaS Services, or (f) exporting Customer Data outside the United States of America except as required by Applicable Registry Laws for an Authorized Registry Purpose.

7.5 Protected Registry Fields and Public Dissemination Controls. Customer acknowledges that Applicable Registry Laws require certain categories of Registrant Data to be withheld, redacted, or otherwise protected from public disclosure. Customer is solely responsible for (a) identifying all Protected Registry Fields under Applicable Registry Laws applicable to Customer’s jurisdiction, (b) designating public and nonpublic data, (c) configuring the SaaS Services to restrict the publication, export, API disclosure, and interagency dissemination of Protected Registry Fields, and (d) ensuring that Customer’s publication and dissemination settings comply with Applicable Registry Laws. Customer must not configure the SaaS Services to publish on any public registry website victim identity information, Social Security numbers, non-conviction arrest information, internet identifiers, remote communication identifiers, or any other Protected Registry Field that the Attorney General or applicable state registry law requires to be excluded from public disclosure, unless the specific Applicable Registry Law expressly permits that disclosure. Company will implement reasonable technical controls within the SaaS Services based on Customer’s instructions to support field-level disclosure restrictions, but Customer is solely responsible for the accuracy and legal adequacy of Customer’s classifications and configuration of those controls.

7.6 Customer Publication, NSOPW, Public Records, and Warning and Correction Obligations. To the extent Customer publishes Customer-supplied Registrant Data or outputs generated from that data on a public sex offender registry website or participates in the Dru Sjodin National Sex Offender Public Website (NSOPW), Customer is solely responsible for (a) designating which Registrant Data constitutes Public Registry Data, (b) ensuring that such publication complies with all Applicable Registry Laws, including the exclusion of victim identity information, Social Security numbers, non-conviction arrest information, and other Protected Registry Fields from public disclosure, (c) displaying on its public registry website the correction instructions and anti-harassment warnings required by Applicable Registry Laws, and (d) maintaining procedures for Registrants and members of the public to request corrections to published information. If Customer uses the SaaS Services to operate or contribute to a public sex offender registry website, Customer is responsible for ensuring compliance with 34 U.S.C. §§ 20920 and 20922, including required field-search capabilities, safety and educational resource links, and NSOPW submission requirements. Company will provide SaaS Services features to support Customer’s publication and NSOPW participation but is not responsible for the content, accuracy, or legal compliance of Customer’s public registry website or NSOPW submissions.

7.7 Accuracy, Currency, and Correction Workflow. Customer is solely responsible for the accuracy, completeness, and quality of Registrant Data, including collecting, validating, submitting, and updating registry records and determining the identity of Registrants. Customer will provide to Company any correction request, removal or takedown instruction, update, supplementation, or other change that Customer elects to process through the SaaS Services. Company will process those Customer-provided inputs through the SaaS Services but does not independently verify Registrant Data, adjudicate correction requests, or make registry or due-process decisions. Customer’s supervising agency has sole authority to approve or deny corrections to a Registrant’s registration record. Customer will process corrections and updates in accordance with Applicable Registry Laws, including any required timeframes. Customer, not Company, is responsible for determining and administering any hearing, review, appeal, correction, removal, or risk-classification procedure required by Applicable Registry Laws.

7.8 Interagency Sharing, Onward Transfer, and Third-Party Recipients. Customer may share Registrant Data and outputs with other law enforcement agencies, criminal justice agencies, Registry Authorities, and other governmental entities solely for Authorized Registry Purposes and in compliance with Applicable Registry Laws. Customer is solely responsible for (a) determining which recipients are authorized to receive Registrant Data, (b) ensuring that onward transfers comply with all field-level restrictions, Protected Registry Field protections, and dissemination limitations, and (c) maintaining records of interagency disclosures to the extent required by Law. Company may provide technical functionality enabling Customer to transmit data to authorized recipients, but Company does not independently disclose Customer Data, determine authorized recipients, or assume responsibility for recipients’ conduct after Customer’s disclosure.

7.9 CJIS, Criminal Justice Information, and Agency Security Requirements. Company’s obligations with respect to CJIS Requirements are limited to the express obligations in the Agreement, the Security Program, this Section, and any executed official CJIS Security Addendum. Customer will identify in writing, before execution of this Master Subscription Services Agreement or in a Subscription Form, whether any Customer-supplied Registrant Data constitutes Criminal Justice Information, criminal history record information, or other data subject to CJIS Requirements. Company has no obligation to process such data until all required CJIS documentation and authorizations are completed. Any official FBI-approved CJIS Security Addendum executed by the Parties will control within its scope. Customer is solely responsible for all agency-side CJIS obligations, including obtaining and maintaining CJIS authorization, identifying data subject to CJIS Requirements, managing user access and personnel security, providing CJIS training, and ensuring Customer’s handling of Customer Data complies with the CJIS Security Policy. Company will maintain and adhere to the Security Program and any applicable executed CJIS Security Addendum only to the extent expressly required for Company’s processing of Customer-submitted data on Customer’s behalf. Unless a Subscription Form expressly provides for Company’s direct access to CJIS Systems and the Parties have executed the applicable CJIS Security Addendum, the SaaS Services do not contemplate Company obtaining direct access to CJIS Systems, NCIC, or related federal systems.

7.10 Audits, Logging, and Cooperation. Company will maintain audit logs of access to and material actions taken with respect to Registrant Data within the SaaS Services in accordance with Company’s standard data-retention policies, the Security Program, and applicable Law. Company will make available relevant audit logs through the SaaS Services or upon reasonable written request, subject to confidentiality, security, privilege, and other customers’ data restrictions. Customer may, no more than once per twelve (12)-month period and upon at least thirty (30) days’ prior written notice, audit Company’s compliance with this Article and the applicable data-security provisions during normal business hours without materially interfering with Company’s operations. Any audit will be limited to applicable processing activities, subject to reasonable scope and confidentiality restrictions, and may require a mutually agreed-upon independent third-party auditor. Customer will bear its own audit costs and Company’s reasonable out-of-pocket costs. Customer will first rely on Company’s SOC reports and other compliance documentation; an on-site audit is permitted only to the extent required by Law or reasonably necessary to investigate a material unresolved compliance issue. Company will cooperate reasonably with any permitted audit.

7.11 Breach, Security Incident, and Misconfiguration Cooperation. The Security Incident notification obligations of Section 6.3 apply to Security Incidents affecting Registrant Data. If either Party becomes aware of an event that has resulted or is reasonably likely to result in unauthorized exposure of Protected Registry Fields, Restricted Registry Data, or Sensitive Registry Data, that Party will promptly notify the other Party, and the Parties will cooperate to investigate, contain, remediate, and mitigate the event. Customer is responsible for incidents caused by Customer, Customer Personnel, Customer’s systems, configurations, or downstream recipients, including required notifications to affected Registrants and applicable authorities. Company is responsible only for Security Incidents within Company’s systems or control and breach of its express obligations under the Agreement and any applicable CJIS Security Addendum. Company will provide reasonable assistance with required notifications or remediation upon Customer’s request and at Customer’s expense. Neither Party’s obligation to notify or cooperate under this Section constitutes an admission of fault, liability, or responsibility.

‍

Article 8

Proprietary Rights

8.1 Customer Data. As between the Parties, Customer or its licensors retain all rights (including all intellectual property rights) in the Customer Data and outputs generated by the SaaS Services from Customer Data. Customer grants the Company Parties the rights as reasonably necessary or appropriate in connection with its provision of the Subscription Services, subject to the data protections in this Master Subscription Services Agreement, to receive, record, organize, store, host, combine, encrypt, use, process, transfer, disclose, delete, destroy, and dispose of Customer Data solely as necessary to (a) provide and operate the SaaS Services, (b) maintain, secure, support, troubleshoot, improve, and administer the SaaS Services, (c) perform analytics only in aggregated and deidentified form that does not identify Customer, any Registrant, or any individual, (d) comply with Law, (e) prevent or address fraud, abuse, security issues, misuse, or service-integrity issues, (f) respond to an emergency that Company believes in good faith requires it to disclose information to assist in preventing the death, harm, or bodily injury of any individual, and (g) exercise Company’s rights and remedies under the Agreement. Company may in turn grant the rights described above to a Data Center operator or other third-party service provider solely for purposes of enabling Company to perform the Services. Any processing of Sensitive Registry Data under this Section is also subject to any applicable official FBI-approved CJIS Security Addendum, as provided in Section 1.2. Customer is solely responsible for all Customer Registry Decisions, and the accuracy, quality, legality, authority, completeness, currency, classification, designation, collection, submission, use, disclosure, publication, retention, and destruction of Customer Data.

8.2 Usage Data. Company may collect, analyze, publish, disclose, and otherwise use Usage Data to provide, improve, enhance, and develop new products and services, and for other legitimate business purposes. Unless required to perform its obligations under the Agreement or Law, Company will not publish, disclose, or otherwise use Usage Data unless it is aggregated and deidentified so that Customer, any Registrant, and any individual cannot be identified. Company will own all aggregated and deidentified outputs from Usage Data and the associated intellectual property rights.

8.3 Company IP. Except for any limited rights Company expressly grants to Customer under the Agreement, as between the Parties, Company (or its suppliers as applicable) retains all right, title, and interest (including all intellectual property rights) in and to all Company IP.

Article 9

Representations & Warranties

9.1 Mutual Representations. Each Party represents that (a) it has all requisite power and authority under applicable Law to enter into, deliver, and perform its obligations under the Agreement, (b) it has duly signed the Agreement, which is valid and binding on it, and (c) its execution, delivery, and performance of the Agreement in accordance with its terms will not conflict with any agreement or instrument to which it is a party or by which it is bound, or violate any Law in effect as of the Effective Date.

9.2 SaaS Services Warranty. During the Subscription Term, Company warrants that (a) it will provide the SaaS Services in compliance with Laws applicable to Company’s provision of the SaaS Services to its customers generally, without regard to Customer’s particular use of the SaaS Services and subject to Customer’s use of the SaaS Services in accordance with the Agreement, (b) each SaaS Application will perform in substantial conformity with its Documentation, and (c) it will use commercially available industry standard software designed to detect and prevent the introduction of Malware into any Customer-hosted systems using the SaaS Services. For any breach of this warranty, Customer’s exclusive remedy and Company’s exclusive obligation will be for Company to use its reasonable efforts to correct the nonconformity, at its expense, within a reasonable time following Customer’s written notice to Company of the nonconformity; except that if Company fails within a reasonable time to correct a nonconformity material to Customer’s utilization of the SaaS Services, Customer may, on written notice to Company, terminate its subscription to the non-conforming SaaS Services and other SaaS Services rendered non-conforming, and any related Customer Support, with no obligation for payment of Subscription Fees for future Subscription Periods, and Company will refund a pro rata portion of the Subscription Fee for the Subscription Period during which the termination occurs (or in the case of consumption-based license limitation, a refund of any remaining unused portion, if applicable). This warranty does not apply to Company Extensions, which are covered by the warranty on Professional Services described in Section 9.3. This warranty also does not extend to Customer Data, Customer’s instructions, configurations, classifications, publication settings, correction instructions, third-party systems, or downstream recipients, or Customer’s legal or governmental functions.

9.3 Professional Services Warranty. Company warrants that it will perform the Professional Services (a) utilizing personnel with the requisite skills to perform those services satisfactorily, (b) in a professional and workmanlike manner, and (c) in compliance with applicable Law. With respect to particular Professional Services performed, this warranty will remain in effect for a period of ninety (90) days from the date of performance of those Professional Services. For any breach of this warranty, Customer’s exclusive remedy and Company’s exclusive obligation will be for Company to reperform those Professional Services; except that, if Company fails to reperform those Professional Services in a manner that conforms to this warranty within a reasonable time, Customer may, on written notice to Company, terminate those Professional Services and all other adversely impacted Professional Services, and Company will refund the Professional Services Fees for those and those other adversely impacted Professional Services.

9.4 Company Warranty Exclusions. Regarding all Company warranties under the Agreement, Company does not warrant against any nonconformity resulting from (a) use of the SaaS Services other than in accordance with the Agreement, the Documentation, or Law, (b) configuration or support provided by a third-party service provider not performing services on Company’s behalf, (c) Customer’s wrongful acts or omissions, including any breach of any provision of the Agreement, or (d) any Customer Data, Customer instructions, configurations, classifications, publication settings, correction instructions, integrations, or other Customer-controlled inputs.

9.5 Customer Representations and Warranties. Customer represents and warrants that (a) Customer is and will remain a Governmental Entity and Registry Authority, or is an authorized governmental agency acting for a Registry Authority, with all authority required under Applicable Registry Laws and other applicable Laws to collect, obtain, compile, receive, use, process, submit, transmit, disclose, publish, and make available to Company for processing all Customer Data that Customer or a person or system acting on Customer’s behalf or under Customer’s authority provides to Company, (b) Customer’s instructions, configurations, classifications, publication settings, correction instructions, and use of the SaaS Services and Customer Data will comply with Applicable Registry Laws, applicable privacy Laws, applicable public-records Laws, CJIS Requirements (to the extent applicable), constitutional requirements, and Customer’s Mandatory Government Requirements, (c) Customer will not instruct or direct Company to disclose Protected Registry Fields or Sensitive Registry Data in violation of Applicable Registry Laws, (d) Customer has obtained and will maintain all notices, consents, approvals, and authorizations required under Applicable Registry Laws and other applicable Laws for its collection, use, disclosure, publication, and submission of Customer Data to Company, (e) Customer will maintain correction, due-process, public-warning, notice, hearing, appeal, and registrant-notification procedures required by Applicable Registry Laws, (f) Customer is solely responsible for the accuracy, quality, legality, authority, completeness, currency, classification, public or nonpublic designation, collection, compilation, submission, use, disclosure, publication, retention, and destruction of Customer Data and for all Customer Registry Decisions, and (g) Customer’s documented lawful instructions will not cause Company to violate applicable Law. Customer will identify or promptly provide to Company any agency-specific legal requirements, CJIS Requirements, or other compliance obligations applicable to the SaaS Services or Customer Data. Company has no obligation to obtain or source data from Registrants, other agencies, public registries, data brokers, third-party databases, or any other source on Customer’s behalf.

9.6 DISCLAIMER. EXCEPT AS EXPRESSLY SET OUT IN THE AGREEMENT, AND TO THE MAXIMUM EXTENT PERMITTED BY LAW, (a) THE SAAS SERVICES ARE PROVIDED “AS-IS” AND “AS AVAILABLE,” (b) USE OF THE SAAS SERVICES IS AT CUSTOMER’S SOLE RISK, (c) COMPANY DISCLAIMS ALL REPRESENTATIONS AND WARRANTIES WITH RESPECT TO ANY SUBJECT MATTER OF THE AGREEMENT, WHETHER EXPRESS, IMPLIED, OR STATUTORY, INCLUDING ANY IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, ACCURACY, AND NON-INFRINGEMENT, AND ANY WARRANTIES ARISING OUT OF COURSE OF DEALING, COURSE OF PERFORMANCE, OR USAGE OF TRADE, and (d) COMPANY DOES NOT WARRANT THAT THE SAAS SERVICES WILL BE SECURE OR OPERATE ERROR-FREE, OR OPERATE WITHOUT INTERRUPTION, OR MEET CUSTOMER’S SPECIFIC REQUIREMENTS. COMPANY DOES NOT WARRANT THE ACCURACY, COMPLETENESS, TIMELINESS, CURRENCY, LEGALITY, OR FITNESS OF CUSTOMER DATA OR ANY CONFIGURATION, CLASSIFICATION, PUBLICATION SETTING, CORRECTION INSTRUCTION, OR OUTPUT GENERATED FROM CUSTOMER DATA. COMPANY DOES NOT INDEPENDENTLY VERIFY, SOURCE, COLLECT, ADJUDICATE, CLASSIFY, PUBLISH, OR DETERMINE THE LEGAL SUFFICIENCY OF CUSTOMER DATA OR CUSTOMER REGISTRY DECISIONS. COMPANY DOES NOT WARRANT THAT CUSTOMER’S REGISTRY PROGRAM, PUBLIC WEBSITE, NOTIFICATIONS, WARNINGS, CORRECTION PROCESS, DUE-PROCESS MECHANISMS, PUBLICATION RULES, TIER CLASSIFICATIONS, FIELD CLASSIFICATIONS, OR OTHER CUSTOMER-CONTROLLED CONFIGURATIONS ARE CONSTITUTIONALLY SUFFICIENT, LEGALLY COMPLIANT, OR APPROPRIATE FOR CUSTOMER’S JURISDICTION, OR THAT CUSTOMER’S USE OF THE SAAS SERVICES WILL PRODUCE A PARTICULAR LEGAL OR GOVERNMENTAL RESULT. CUSTOMER ACKNOWLEDGES THAT THESE DISCLAIMERS ARE A FUNDAMENTAL PART OF THE AGREEMENT AND THAT COMPANY WOULD NOT AGREE TO ENTER INTO THE AGREEMENT WITHOUT THEM.

Article 10

Indemnification

10.1 Indemnification by Company for Infringement.

(a) Subject to the conditions set out in Section 10.4, and the exclusions set out in subsection (b) of this Section, Company will, at its expense, defend and hold harmless the Customer Indemnitees from and against any third-party claim that the Customer’s (or other Customer Parties’) use of one or more of the SaaS Services directly infringes a third party’s intellectual property rights. Further, Company will indemnify the Customer Indemnitees with respect to any damages, costs, and expenses finally awarded to the claimant by a court of competent jurisdiction attributable to that claim; provided that with respect to the indemnification of each affected Customer Indemnitee, they must take reasonable steps to mitigate their damages arising from that claim.

(b) Company’s indemnification obligations under subsection (a) of this Section will not apply to the extent the claim results from any of the following:

  • (i) Use of a SaaS Service in breach of the Agreement or the Documentation or Customer’s other breach of the Agreement;‍
  • ‍(ii) Modifications or enhancements to a SaaS Service other than by or at the direction of Company;
  • (iii) Any Third-Party Application, any service provided by any third-party in connection with any SaaS Services, or any use of, exchange of data with or other interaction between Customer and a Third-Party Application;
  • (iv) Except for a copyright infringement claim, a Company Extension developed to meet Customer’s requirements not contained in the Documentation or in compliance with a method or process provided by Customer for implementing those requirements; or
  • (v) Customer’s bundling, combining, integrating, or interfacing a SaaS Service with any non-Company products, processes, software, hardware, or materials, if the claim would have been avoided absent that bundling, combination, or integration, except to the extent those products, processes, software, hardware, or materials are designated in the Documentation as appropriate for bundling, combining, integrating, or interfacing with that SaaS Service.

(c) If any of the SaaS Services becomes, or Company determines is likely to become, the subject of any claim, suit, or proceeding arising from or alleging infringement of any third party’s intellectual property rights, then Company will have the right, at its expense and as its entire obligation to the Customer Indemnitees with respect to that claim, suit, or proceeding (other than any applicable indemnification obligations under subsection (a) of this Section), to (i) procure for Customer the right to continue to access those SaaS Services, (ii) replace or modify those SaaS Services so that they are not infringing, or (iii) if Company reasonably determines that neither action described in clause (i) or (ii) of this subsection is reasonably feasible, discontinue providing access to those SaaS Services and refund a portion of the Subscription Fees paid for those SaaS Services based on a reasonable allocation of the Subscription Fees for those SaaS Services to that portion of the SaaS Services not received. In the case of clause (iii) of this subsection, if Company reasonably determines that further infringement can be avoided by removing a Company Extension from a SaaS Service, or a change described in Section 10.1(b)(ii), it may do so rather than discontinuing the associated SaaS Services.

(d) Regarding infringement, or alleged infringement, by the SaaS Services of third-party intellectual property rights, this Section sets out the Customer Indemnitees’ exclusive remedy and Company’s exclusive obligations.

10.2 Indemnification by Company for Data Breach. Subject to the conditions set out in Section 10.4, Company will, at its expense, defend and hold harmless the Customer Indemnitees from and against any third-party claim that the claimant has been damaged because of a Data Breach. Further, Company will indemnify the Customer Indemnitees with respect to any damages, costs, and expenses finally awarded to the claimant by a court of competent jurisdiction, and attributable to that claim; provided that with respect to the indemnification of each affected Customer Indemnitee, they must take reasonable steps to mitigate their damages arising from that claim.

10.3 Indemnification by Customer. Subject to the conditions set out in Section 10.4, Customer will, at its expense, defend and hold harmless the Company Indemnitees from and against any third-party claim or investigation, resulting from, arising out of, or in connection with any of the following:

(a) Customer’s use of the SaaS Services in a manner not authorized or contemplated under the Agreement or the Documentation;

(b) the actual or alleged infringement of any intellectual property rights or any other proprietary or other rights of a third party in any data, information, or any other materials provided by or on behalf of the Customer Parties to Company in connection with the Agreement;

(c) where a SaaS Service operates as intended, the Customer Parties’ or any third party’s use of or reliance on any information generated by that SaaS Service;

(d) Customer’s failure to obtain or maintain any licenses, authorizations or approvals necessary to access and use any Third-Party Application, or Customer’s violation of any of the terms or conditions governing any Third-Party Application;

(e) Customer Data, including its accuracy, quality, completeness, currency, legality, authority, classification, public or nonpublic designation, collection, compilation, submission, provision, use, disclosure, publication, retention, or destruction;

(f) Customer Registry Decisions or any Customer instruction, configuration, classification, publication setting, correction, removal, takedown, warning, notice, legal determination, or other Customer-controlled input under the Agreement;

(g) Customer’s noncompliant use, disclosure, publication, dissemination, or onward transfer of Customer Data;

(h) Customer’s failure to comply with Applicable Registry Laws, applicable privacy Laws, public-records Laws, constitutional requirements, or CJIS Requirements;

(i) public-records disputes, privacy claims, defamation or false-light claims, wrongful-publication claims, due-process or correction claims, and CHRI or CJIS claims to the extent involving Customer Data;

(j) Customer’s failure to maintain security measures, correction procedures, public warnings, notices, or due-process procedures required by the Agreement or Applicable Registry Laws; or

(k) any claim by a Registrant, law-enforcement agency, regulatory authority, governmental entity, or other third party arising from Customer’s governmental functions or handling of Customer Data.

Further, Customer will indemnify the Company Indemnitees with respect to any damages, costs, and expenses finally awarded to the claimant by a court of competent jurisdiction or fines levied by the investigative body, in each case attributable to that claim; provided that with respect to the indemnification of each affected Company Indemnitee, they must take reasonable steps to mitigate their damages arising from that claim.

10.4 Conditions to Indemnification. An Indemnifying Party’s indemnification obligation under Section 10.1, 10.2, or 10.3 will be subject to the following conditions:

(a) An affected Indemnitee will give written notice to the Indemnifying Party of the claim promptly, and not later than twenty (20) days, following the date they first receive notice of the claim; except that an Indemnifying Party is relieved of its obligation to provide indemnification only to the extent it is materially prejudiced by the delay;

(b) The Indemnifying Party will have sole control of the defense and any settlement of the claim; except that the Indemnifying Party may not settle any claim without the affected Indemnitee’s prior consent to the settlement unless the settlement unconditionally releases the affected Indemnitee of all liability and (subject to Company’s rights under Section 10.1(c) in connection with its indemnification for intellectual property infringement) does not restrict the Indemnitee’s rights under the Agreement, and the affected Indemnitee will have the right to retain legal counsel at their own expense to monitor the proceedings relating to the Indemnifying Party’s defense and settlement of the claim; and

(c) The affected Indemnitee reasonably will cooperate with the Indemnifying Party’s defense (with the Indemnifying Party responsible for paying or reimbursing their reasonable out-of-pocket expenses for their cooperation), including by providing the Indemnifying Party with that information, assistance, and authority to enable it reasonably to perform its obligations under this Article.

Article 11

Limitations on Liability

11.1 General Acknowledgement. In agreeing to the limitations set out below, the Parties have considered the allocation of risks between them and the pricing and other considerations set out in the Agreement. The limitations set out below will apply even if one or more of the remedies available to the Party seeking relief fail of their essential purpose. References in this Article to the term “PARTY” or “COMPANY” or “CUSTOMER” will be deemed to include that Party’s related parties who may have claims or who may have claims asserted against them.

11.2 EXCLUSION OF DAMAGES. EXCEPT AS PROVIDED IN SECTION 11.5, To the maximum extent permitted by Law NEITHER PARTY, NOR ANY THIRD-PARTY SUPPLIER OF SOFTWARE, DATA SERVICES, OR HARDWARE PROVIDED BY OR THROUGH COMPANY, WILL BE LIABLE TO THE OTHER PARTY (WHETHER UNDER CONTRACT, TORT, WARRANTY, STRICT LIABILITY, OR OTHERWISE) FOR LOST SALES OR PROFITS, OR CONSEQUENTIAL, INDIRECT, SPECIAL, INCIDENTAL OR PUNITIVE DAMAGES, RESULTING FROM, ARISING OUT OF, OR IN CONNECTION WITH THE AGREEMENT, OR OTHERWISE RELATED TO ITS SUBJECT MATTER (INCLUDING ANY OF THOSE TYPES OF DAMAGES DESCRIBED ABOVE RELATING TO CUSTOMER’S OR THE OTHER CUSTOMER PARTIES’ (A) USE OF OR INABILITY TO USE THE SUBSCRIPTION SERVICES, OR THIRD-PARTY APPLICATIONS, THIRD-PARTY SERVICES, OR HARDWARE, (B) LOSS OF DATA OR DAMAGE TO HARDWARE OR SOFTWARE, (C) FAILURE TO REALIZE SAVINGS OR OTHER BENEFITS FROM THE SAAS SERVICES, AND (D) CLAIMS BY THIRD PARTIES), EVEN IF THE OTHER PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF THOSE DAMAGES OR THOSE DAMAGES WERE FORESEEABLE.

11.3 DAMAGES FOR DATA BREACH. NOTWITHSTANDING ANYTHING IN SECTION 11.2 TO THE CONTRARY, COMPANY’S LIABILITY FOR DIRECT DAMAGES ARISING OUT OF, RESULTING FROM, OR IN CONNECTION WITH A DATA BREACH WILL BE DEEMED TO INCLUDE (BUT NOT BE LIMITED TO) (A) DEFENSE AND INDEMNIFICATION PURSUANT TO SECTION 10.2, (B) REASONABLE COSTS FOR MAILING LEGALLY REQUIRED BREACH NOTIFICATION TO AFFECTED INDIVIDUALS, AND (C) LEGALLY REQUIRED CREDIT MONITORING SERVICES FOR UP TO 12 MONTHS TO AFFECTED INDIVIDUALS. COMPANY WILL HAVE NO LIABILITY FOR A SECURITY INCIDENT EXCEPT TO THE EXTENT IT CONSTITUTES A DATA BREACH.

11.4 AMOUNT OF LIABILITY. OTHER THAN WITH RESPECT TO CLAIMS FOR WHICH THE AGREEMENT PROVIDES FOR EXCLUSIVE REMEDIES, AND SUBJECT TO THE EXCEPTIONS SET OUT IN SECTION 11.5, TO THE MAXIMUM EXTENT PERMITTED BY LAW A PARTY’S LIABILITY FOR ALL CLAIMS UNDER THE AGREEMENT OR OTHERWISE RELATED TO ITS SUBJECT MATTER (WHETHER IN CONTRACT, TORT, INDEMNIFICATION, WARRANTY, OR OTHER LAW) ARISING IN A GIVEN SUBSCRIPTION PERIOD WILL NOT EXCEED AN AMOUNT EQUAL TO THE SUBSCRIPTION FEES PAID BY CUSTOMER FOR THOSE SPECIFIC SUBSCRIPTION SERVICES ACQUIRED DURING THAT SUBSCRIPTION PERIOD TO WHICH THOSE CLAIMS RELATE; PROVIDED, HOWEVER, THAT (A) TO THE EXTENT THOSE CLAIMS ARE FOR DATA BREACH OR BREACH OF CONFIDENTIALITY, A PARTY’S LIABILITY WILL NOT EXCEED TWO (2) TIMES THOSE FEES, OR (B) IF THE CLAIMS DO NOT RELATE TO SPECIFIC SUBSCRIPTION SERVICES, THEN A PARTY’S LIABILITY WILL NOT EXCEED THE AGGREGATE SUBSCRIPTION FEES (OR TWO (2) TIMES THAT TOTAL, AS APPLICABLE) PAID FOR ALL SUBSCRIPTION SERVICES ACQUIRED DURING THE APPLICABLE SUBSCRIPTION PERIOD.

11.5 Exceptions to Limitations. To the maximum extent permitted by Law, the limitations set out in Sections 11.2 and 11.4 will not apply to (a) Customer’s failure to pay any Fees owed pursuant to the Agreement (including payments in accordance with Section 12.3 for Premature Termination), (b) the Parties’ indemnification and defense obligations under Sections 10.1 and 10.3, (c) Customer’s obligations and liabilities arising from Customer Data, Customer Registry Decisions, or Customer’s instructions, provision, use, publication, disclosure, retention, or destruction of Customer Data, and (d) claims for a Party’s gross negligence or willful misconduct. Where applicable Law prohibits or limits Customer’s obligations under this Section, Section 14.5 will govern. Any prohibited portion will be severed or reformed to the maximum lawful equivalent, and Company will have no liability for the portion of any loss attributable to Customer’s misuse, unauthorized disclosure, publication, export, onward transfer, regulatory non-compliance, due-process failure, or security failure. Nothing in this Section expands any Company liability cap or creates uncapped Company liability.

Article 12

Term and termination

12.1 Term. This Master Subscription Services Agreement will remain in effect until terminated in accordance with the remaining provisions of the Agreement or until all Subscription Terms for the SaaS Services have expired or otherwise terminated.

12.2 Termination. In addition to Customer’s rights to terminate set out elsewhere in the Agreement, either Party may terminate the Agreement or Customer’s subscription to an affected SaaS Service on written notice to the other (a) if the other has failed to cure a material breach of the Agreement within thirty (30) days following receipt of written notice from the terminating Party specifying the nature of the breach; except that, if the material breach is incapable of cure, the terminating Party may terminate the Agreement or Customer’s subscription to that affected SaaS Service on written notice of the material breach, or (b) if (i) in the case of Company, Company fails to function as a going concern, has a receiver, trustee, or other custodian appointed for substantially all its assets, becomes insolvent or unable to pay its debts as they mature, makes a general assignment for the benefit of creditors, is liquidated or dissolved, or has any proceeding commenced against it under any bankruptcy, insolvency, or debtor’s relief Law that is not dismissed within thirty (30) days, (ii) in the case of Customer, Customer ceases to be a Governmental Entity, loses the governmental authority required to perform its material obligations, or is prohibited by applicable Law from continuing the Agreement, or (iii) a proceeding involving the other Party legally requires termination. In addition, Company may terminate the Agreement or Customer’s subscription to an affected SaaS Service on written notice to Customer if termination is required due to changes in any licensing requirements with respect to any Third-Party Application. Regarding a Customer breach, during any applicable thirty (30)-day cure period, Company may suspend any or all Services to Customer without liability or penalty if Company reasonably determines that suspending those Services is necessary to protect Company from potential loss or liability or to protect the security, integrity, or availability of the SaaS Services; provided that prior to that suspension, Company must give Customer written notice and the ability promptly to respond to that notice unless Company determines in good faith that to do so would jeopardize the protections sought by the suspension. No designation of a remedy as exclusive under any provision of the Agreement limits or waives Customer’s right to terminate the Agreement for material breach in accordance with this Section.

12.3 Effect of Expiration or Termination. On termination of the Agreement, all Subscription Forms and Customer’s subscriptions to all SaaS Services covered by those forms will terminate concurrently. On termination of Customer’s subscription to a SaaS Service, all SOWs, to the extent related to that SaaS Service, will terminate concurrently. On expiration or termination of the Agreement or Customer’s subscription to a SaaS Service, Customer will, as of the date of that expiration or termination, immediately cease accessing and otherwise utilizing the affected SaaS Services. Expiration or termination for any reason will not relieve Customer of its obligation to pay any Fees accrued or due prior to the effective date of that expiration or termination. On expiration or a termination of the Agreement or Customer’s subscription to a SaaS Service other than a Premature Termination, Customer will be relieved of any further obligation to pay Subscription Fees, and within thirty (30) days following that expiration or termination Company will reimburse Customer a pro rata portion of any prepaid Subscription Fees for the affected SaaS Services based on that portion of the Subscription Period remaining, if any, following the termination (or in the case of consumption-based license limitation, a refund of any remaining unused portion, if applicable). Customer acknowledges that, in exchange for Company’s commitment to provide the SaaS Services for the full agreed-to Subscription Terms, Customer commits to pay the applicable Subscription Fees for those SaaS Services. Therefore, if there is a Premature Termination, Customer will pay Company, as damages, and not as a penalty, within thirty (30) days following the termination, the present value of the remaining Subscription Fees that would have become due under the Subscription Forms related to the affected SaaS Services, minus the present value of the marginal cost savings Company should achieve from the Premature Termination.

12.4 Transition Services. On Customer’s request in connection with Customer’s termination of the Agreement prior to its expiration or of a SaaS Service prior to expiration of the applicable Subscription Term (except where that termination is a Premature Termination), Company will, to assist Customer with its transition off of the impacted SaaS Services, (a) continue to provide one or more of the terminated SaaS Services, on a month-to-month basis, as requested, for up to six (6) months, and (b) provide reasonable additional services of the type customarily offered by Company to transitioning SaaS Services Customers during that transition period as requested. The continued provision of the SaaS Services will be for monthly Subscription Fees at rates comparable to those in effect for Customer immediately prior to the termination and any additional services will be at Company’s then-current hourly rates. The terms of the Agreement or the applicable Subscription Forms will continue in effect as reasonably applicable to the transition services provided.

12.5 Return of Data and Materials. Within thirty (30) days following the expiration or termination of Customer’s subscription to a SaaS Service, Company will return to Customer a single copy of any Customer Data remaining in the applicable cloud environment as of the expiration or termination date through Company’s standard export functionality or another format mutually agreed by the Parties. Any request that Customer Data be returned in a specific format, or that Company provide transition or export assistance beyond the standard functionality, will be subject to mutual agreement between the Parties and any additional fees to be paid by Customer. Customer is responsible for timely exporting and preserving Customer Data needed for its operations, records-retention obligations, legal holds, and Applicable Registry Laws. After that thirty (30)-day period, Company will have no obligation to maintain or provide any Customer Data and may delete it in accordance with the Agreement, the Security Program, Company’s standard retention policies, and applicable Law. Promptly following expiration or termination of Customer’s subscription to a SaaS Service, Customer will return or destroy all copies of the Documentation and other Company-proprietary materials relating to that SaaS Service in its possession or control and provide Company with a certification from an authorized representative of Customer confirming that action.

12.6 After Expiration or Termination. Termination of the Agreement will not relieve either Party of any obligations arising under the Agreement prior to the date of termination. The Parties’ rights and obligations under the terms of the Agreement that by their nature extend beyond the termination of the Agreement, including specifically the terms of this Section, and Articles 5 (subject to Section 5.3), 10, 11, 13, and 15, will survive the expiration or any termination of the Agreement.

Article 13

Applicable Laws and Disputes

13.1 Applicable Law. The Laws of the State of Louisiana (without giving effect to the principles thereof or of any other jurisdiction relating to the conflicts of Laws) govern all matters arising out of or relating to the Agreement and the transactions contemplated hereby, including the validity, interpretation, construction, performance and enforcement of the Agreement. The Uniform Computer Information Transactions Act, however adopted in any form in any jurisdiction, does not apply to the Agreement.

13.2 Dispute Conference. If there is a dispute between the Parties resulting from, arising out of, or in connection with the Agreement or related to its subject matter, either Party may notify the other of its desire that the Parties engage in executive-level discussions to resolve the dispute. Within five (5) business days following that notice, each Party will designate an executive of that Party with the authority to make commitments that would resolve the dispute. Those executives will meet in person or telephonically within ten (10) business days of the date on which the last of the two executive designations are made, and they will negotiate in good faith to resolve the dispute. Except to the extent necessary to prevent irreparable harm or to preserve rights or remedies, neither Party will initiate litigation with the other until ten (10) days following the meeting of the designated executives. The dispute resolution procedures in this Section will not apply to claims subject to indemnification under Article 10 or to a Party’s request for a provisional remedy relating to claims of misappropriation or ownership of intellectual property rights or Confidential Information.

13.3 Jurisdiction and Venue for Dispute Resolution; Attorneys’ Fees. Each Party knowingly, voluntarily, unconditionally and irrevocably (a) agrees that any claim brought by it that arises out of or relates to the Agreement must be brought solely and exclusively in the United States District Court for the Eastern District of Louisiana or in the courts of the State of Louisiana located and having within their jurisdiction the Parish of St. Tammany, Louisiana, (b) accepts and submits to the sole and exclusive jurisdiction of such courts in personam with respect to all claims arising out of or related to the Agreement, and (c) waives any objection which it may now or later have to the laying of venue of any claim arising out of or related to the Agreement that is brought in any such court, including that any claim brought in any such court has been brought in an inconvenient forum. The prevailing Party in any dispute between the Parties arising from or related to the Agreement will be entitled to recover from the other Party its attorneys’ fees and costs incurred in pursuing or defending such dispute.

13.4 Judicial Interpretation. The Parties acknowledge that both Parties have participated in the preparation of the Agreement and its various provisions, and they intend that the Agreement will not be construed more strictly against either Party under the contra proferentem rule or any similar rule of construction.

13.5 Equitable Relief. Each Party acknowledges that a breach of the confidentiality or intellectual property provisions of the Agreement may cause irreparable harm for which monetary damages are inadequate. Accordingly, the non-breaching Party may seek injunctive and other equitable relief.

Article 14

Governmental Entity Provisions

14.1 Government Customer; Eligibility and Applicability. Customer must be a Governmental Entity throughout the term of the Agreement. Customer represents and warrants that it is a Governmental Entity acting in its governmental capacity. No nongovernmental entity may execute as Customer or obtain access under the Agreement. Authorized contractors, agents, and service providers may access the SaaS Services only as Customer Personnel and subject to the restrictions in Article 1 and Article 7. If Company reasonably determines that Customer does not satisfy or has ceased to satisfy these eligibility requirements, Company may decline to provide or continue the affected Services and may suspend or terminate the Agreement or affected Subscription Services on written notice, without liability for the suspension or termination. The Agreement constitutes the complete and exclusive agreement governing Customer’s access to and use of the Services, subject only to Mandatory Government Requirements that cannot lawfully be waived or modified by contract.

14.2 Mandatory Government Requirements. The Parties acknowledge that Customer may be subject to Laws and other requirements applicable specifically to it as a Governmental Entity (collectively, “Mandatory Government Requirements”). To the extent a Mandatory Government Requirement is legally required to apply to this Agreement and cannot lawfully be waived, such requirement will apply notwithstanding any contrary provision of the Agreement. Customer will identify to Company, in writing and before execution of the Agreement to the extent reasonably practicable, any Mandatory Government Requirements that Customer contends must be incorporated into the Agreement. Except to the extent required by applicable Law, Customer will not interpret or apply any Mandatory Government Requirement to impose obligations on Company that are materially broader than those expressly required by such Law or to create contractual rights or remedies in favor of Customer beyond those expressly set forth in the Agreement. If a Mandatory Government Requirement conflicts with a provision of the Agreement, the Parties will cooperate in good faith to modify the affected provision only to the minimum extent necessary to comply with such requirement while preserving, to the maximum extent permitted by Law, the Parties’ original allocation of rights, responsibilities, risks and remedies. The provisions of Article 7 and Customer’s obligations under Article 10 are integral to the Agreement and will not be overridden by Mandatory Government Requirements except to the minimum extent mandatory nonwaivable Law expressly requires. Customer will identify to Company in writing any registry-specific, public-records-specific, or CJIS-specific requirements applicable to Customer’s use of the SaaS Services and will cooperate with Company in protecting Company’s Confidential Information and Protected Registry Fields in any public-records response to the maximum extent permitted by Law.

14.3 Appropriations and Funding. To the extent applicable to Customer under applicable Law, Customer’s payment obligations under the Agreement are subject to the availability and lawful appropriation of funds and to any applicable debt-limitation, Anti-Deficiency Act, or similar restriction. Customer will promptly notify Company if Customer reasonably determines that applicable Law prevents or materially limits Customer’s ability to perform its payment obligations. Customer will not invoke an appropriations or funding limitation to avoid payment of Fees for Services already provided under the Agreement, and any lawful funding limitation will not affect Company’s right to suspend or terminate Services for nonpayment or to recover amounts lawfully due.

14.4 Public Records and Disclosure Laws. The Parties acknowledge that Customer may be subject to applicable public-records, freedom-of-information, or similar Laws. Nothing in the Agreement will prohibit Customer from making a disclosure that Customer is legally required to make under such Law. Before making a disclosure of Company’s Confidential Information to the extent permitted by applicable Law, Customer will, to the extent legally permissible and reasonably practicable, provide Company with prompt written notice and a reasonable opportunity to seek a protective order or other appropriate remedy. Customer will disclose only the portion of Company’s Confidential Information that Customer reasonably determines is legally required to be disclosed.

14.5 Governmental Immunity. Nothing in the Agreement will be construed as a waiver of any sovereign, governmental, tribal, judicial, prosecutorial, statutory, treaty-based, or other immunity, defense, limitation, or protection available to Customer under applicable federal, state, local, territorial, or tribal Law, and nothing in the Agreement will require Customer to indemnify Company or pay damages to the extent prohibited by applicable Law. No waiver of immunity is made unless expressly authorized by applicable Law. Nothing in the Agreement overrides applicable appropriations, debt-limitation, Anti-Deficiency Act, procurement-law, or other mandatory restrictions applicable to Customer. Except as otherwise expressly required by applicable Law, Customer’s preservation of governmental immunity will not affect Company’s rights and remedies expressly provided under the Agreement, including rights relating to payment of Fees for Services properly provided to Customer, suspension, termination, equitable relief, and enforcement of Customer’s direct contractual and reimbursement obligations to the maximum extent permitted by Law. Where Customer is prohibited by Law from providing indemnification, uncapped damages, or a particular remedy under the Agreement, including under Article 10 or Article 11, the affected obligation will apply to the maximum extent permitted by Law and will be treated and enforced as a direct contractual obligation, reimbursement obligation, payment adjustment, recoupment or setoff right where lawful, defense and cooperation obligation, equitable remedy, basis for suspension or termination, or other lawful risk allocation. Customer’s preservation of governmental or sovereign immunity will not relieve Customer of its substantive obligations under Article 7, including compliance with Applicable Registry Laws, proper handling of Registrant Data, and cooperation with Company in the investigation and remediation of Security Incidents and misconfigurations.

14.6 No Additional Terms Through Electronic Systems. Customer will not impose additional or conflicting contractual terms through any electronic procurement, registration, or invoicing system or similar mechanism. Any such terms will be ineffective unless expressly accepted by Company in a writing executed by an authorized representative of Company. The Parties’ use of electronic systems for administrative, procurement, invoicing, security or operational purposes will not modify the substantive terms of the Agreement unless the Parties expressly agree in accordance with Section 15.7.

14.7 Subcontractor and Flow-Down Requirements. Customer will not impose on Company any governmental flow-down, subcontracting, cybersecurity, privacy, accessibility, audit, insurance, reporting, records-retention or other requirement applicable to Company solely by virtue of Customer’s governmental status unless such requirement is (a) expressly identified in the Agreement or an applicable Subscription Form, (b) expressly required by applicable Law to be imposed on Company, or (c) subsequently accepted in writing by Company. Where a governmental requirement is legally required to be flowed down to Company, Customer will provide Company with the applicable requirement in sufficient detail to permit Company to comply with it, and the Parties will cooperate in good faith to implement such requirement in a manner consistent with the SaaS delivery model and the terms of the Agreement. Company will not be deemed to have accepted any governmental flow-down or regulatory requirement by virtue of its commencement or continuation of performance unless Company expressly agrees in writing. Any governmental flow-down requirement applicable to Registrant Data or the SaaS Services will be subject to the provisions of Article 7 and this Article.

14.8 Changes Required by Law. If, after the Effective Date, a change in applicable Law or a governmental directive imposes a new or materially increased obligation on Company in connection with the Services, the Parties will negotiate in good faith an equitable adjustment to the affected Fees, implementation schedule, scope, security requirements or other affected terms to the extent the additional obligation results in a material increase in Company’s cost or burden. If the Parties cannot agree upon a commercially reasonable adjustment within thirty (30) days after Company provides written notice of the applicable change, either Party may terminate the Agreement or Customer’s subscription to the affected SaaS Service(s) on written notice.

14.9 Exclusive Contractual Terms. Except for Mandatory Government Requirements that cannot lawfully be waived or modified, the rights and obligations of the Parties with respect to the Services will be governed exclusively by the Agreement and the documents expressly incorporated into the Agreement. No governmental statute, regulation, policy, or other requirement will be deemed incorporated into the Agreement solely by reference or implication unless expressly required by applicable Law or expressly agreed to by the Parties in writing. Any provision that is required by applicable Law to be incorporated into the Agreement will be interpreted, to the maximum extent permitted by Law, consistently with the remaining provisions of this Agreement. If any such provision is inconsistent with another provision of the Agreement, it will control only to the extent of the legally required inconsistency.

14.10 Government Customer Severability. If any provision of the Agreement is unenforceable against Customer because of its governmental status or a Mandatory Government Requirement, that provision will be modified to the minimum extent necessary for enforceability, and the remaining provisions will remain in full force and effect. The Parties will cooperate in good faith to replace the unenforceable provision with one that most closely preserves their original intent and risk allocation. This Section supplements Section 15.9.

Article 15

General Terms

15.1 Nature of Relationship. The Parties’ relationship will be that of independent contractors, and nothing in the Agreement creates a joint venture, partnership, principal‑agent, or mutual agency relationship between them. Neither Party has any right or power under the Agreement to create any obligation, expressed or implied, on behalf of the other. Employees of Company will not be considered employees of Customer, and Customer will be responsible for all applicable compensation and benefits for Customer’s employees.

15.2 Assignment. The Agreement will be binding on and inure to the benefit of the Parties and their successors and permitted assigns; provided, however, that Customer will not assign the Agreement or any part of the Agreement without the prior written approval of Company. Any assignment by Customer without Company’s prior written approval, whether by contract, merger, change in control, or otherwise, will be void ab initio.

15.3 Third Party Beneficiaries. The Agreement is for the sole benefit of the Parties and their successors and permitted assigns, and each Party intends that the Agreement will not benefit, or create any right or cause of action in or on behalf of, any person or entity other than the Parties and their successors and permitted assigns; provided, however, that Company and Customer acknowledge and agree that: (a) the Company Parties are beneficiaries of the Agreement; and (b) to the extent necessary to enforce their indemnification rights under the Agreement, an Indemnitee will be deemed a beneficiary of the Agreement.

15.4 Export Control Law. Company’s provision of the SaaS Services may be subject to U.S. or non-U.S. export control Laws. Customer will comply fully with, and will not take or permit any action that will cause Company to be in violation of, U.S. and non-U.S. export control Laws with respect to the transactions contemplated under the Agreement. Customer will not export, reexport, transfer, or transmit the SaaS Services or Registrant Data across any national boundary except in compliance with all applicable Laws and Article 7, and will ensure that Customer Personnel and any authorized recipient comply with those requirements. Customer promptly will notify Company if it becomes aware of a material change affecting the legality of Customer’s access to or use of the SaaS Services or Registrant Data. Company may, from time to time deny Customer the right to purchase or access one or more SaaS Services to the extent Company deems it reasonably necessary to comply with, or otherwise protect its interests regarding, U.S. or non-U.S. export control Law.

15.5 Effect of Force Majeure. Except for Customer’s payment obligations under the Agreement, or either Party’s confidentiality or nonuse obligations under the Agreement, neither Party will be liable to the other for any delay or interruption in performance of any obligation under the Agreement resulting from Force Majeure. Force Majeure will not excuse Company from failure to implement its standard internal business continuity plans except to the extent Force Majeure reasonably prevents it. If Force Majeure prevents Company from providing a SaaS Service to Customer for more than thirty (30) days, then Customer may terminate its subscription to that SaaS Service on written notice to Company without any liability for that termination.

15.6 Notices. Whenever one Party is required to give notice to the other under the Agreement, such notice will be deemed given when delivered to the address specified below.

In the case of Company:

Watch Systems, LLC4 Sanctuary Blvd.Mandeville, LA 70471

With a copy to:

In the case of Customer:

Either Party may modify its contact or address for notification purposes by giving the other Party notice of the new contact or address and the date upon which it will become effective.

15.7 Amendment and Waiver. No amendment, modification or supplement to the Agreement will be valid unless made in writing and signed by duly authorized representatives of each of Company and Customer. Neither the course of dealings between the Parties nor any trade practices will act to modify, vary, supplement, explain or amend the Agreement. No waiver, modification or amendment of the Agreement will be binding upon either Party unless made in writing and signed by duly authorized representatives of each of Company and Customer, and no failure or delay in enforcing any right will be deemed a waiver of that right.

15.8 Consents and Approvals. Except as specifically set forth in the Agreement, (a) all consents and approvals to be given by either Party under the Agreement will not be unreasonably withheld, conditioned or delayed, and (b) in order to be binding, all notices, requests, consents, approvals, agreements, authorizations, acknowledgments, waivers and other communications required or permitted under the Agreement must be provided by a Party’s authorized representative, and must be provided expressly in writing and manually signed by, or directly transmitted by electronic mail from, a Party’s authorized representative.

15.9 Savings Clause. If any term of the Agreement conflicts with the Law under which the Agreement is to be construed, or if any such term is held invalid or unenforceable by a court with jurisdiction over the Parties, such term will be deemed to be modified or restated to reflect as nearly as possible the original intentions of the Parties in accordance with applicable Law, or if and to the extent such modification or restatement is not permitted under applicable Law, such term will be severed from the Agreement. The remaining terms of the Agreement and the application of the challenged term to persons, entities or circumstances other than those as to which it is invalid or unenforceable will not be affected, and each such term will be valid and enforceable to the greatest extent permitted by applicable Law.

15.10 Counterparts. This Master Subscription Services Agreement may be executed in any number of counterparts, each of which will be deemed an original and all of which will constitute one and the same instrument. This Master Subscription Services Agreement, each Subscription Form, and each SOW may be executed by electronic signature in accordance with the Electronic Signatures in Global and National Commerce Act, the Uniform Electronic Transaction Act, and any other applicable Law, and any document so executed will be binding on both Company and Customer with the same legal effect as a manually executed original.

15.11 Entire Agreement. The Agreement constitutes the entire agreement and understanding between the Parties with respect to its subject matter and supersedes all prior agreements and understandings relating to such subject matter (including any non-disclosure or confidentiality agreement(s) executed by the Parties prior to the Effective Date, and any information shared under those agreements will be governed by the terms of Article 5), and there are no other representations, warranties, promises, covenants, commitments, understandings or agreements between the Parties relative to such subject matter; provided that the foregoing will not limit the applicability of Mandatory Government Requirements to the extent required by Section 14.2. Except as expressly provided in this Master Subscription Services Agreement, no purchase order, purchase requisition, procurement document, solicitation, bid specification, statement of work, task order, portal terms, click-through terms, online terms of use, standard terms and conditions or other document issued or presented by Customer (collectively, “Customer Terms”) will amend, supplement, supersede or otherwise modify the Agreement, regardless of whether such Customer Terms are issued before or after the Effective Date, and regardless of whether such Customer Terms are referenced in or attached to a Subscription Form, SOW or invoice. No provision contained in Customer Terms will apply merely because such document is incorporated by reference, referenced in a purchase order, made available through a procurement portal or otherwise provided to Company, unless Company expressly agrees in writing that the particular provision will apply. Company’s commencement or continuation of performance, delivery of SaaS Services, provision of Professional Services, submission of an invoice, receipt of payment or acknowledgment of a purchase order will not constitute acceptance of, or agreement to be bound by, any Customer Terms that are inconsistent with or additional to the Agreement. If Customer’s purchasing system requires Company to submit or accept a purchase order containing Customer Terms, such submission or acceptance will be deemed solely an administrative accommodation for Customer’s internal purchasing processes and will not modify the Agreement or constitute Company’s acceptance of any conflicting or additional terms.

Exhibit 1

Subscription Service Unique Terms

The following terms and conditions are applicable to any subscription for the SaaS Service known as “Remote Express” and supplement the terms of the Master Subscription Services Agreement:

1. Product Description. Remote Express is a mobile application that enables eligible registered offenders to submit sex-offender registration updates (including address, vehicle, contact information, physical descriptors, and photographs) remotely via smartphone. Submissions are subject to identity verification (including facial-recognition match against the mugshot on file), geolocation capture, digital attestation, and mandatory review and approval by an authorized officer of Customer prior to any update to Customer’s registration records.

2. Third-Party Facial-Recognition Component. Company licenses facial-recognition technology from Paravision, Inc. The Paravision software is deployed and operated entirely within Company’s security-controlled internal infrastructure. All selfies, mugshots, and biometric templates are processed on servers owned and controlled by Company and are never transmitted to, or received by, Paravision or any other third party; Paravision does not access, receive, retain, or use any biometric template or image generated in connection with Remote Express, and the arrangement is a software license, not a data-sharing or subprocessor relationship. Company will use commercially reasonable efforts to notify Customer of any material change in the facial-recognition component at least sixty (60) days in advance.

3. Payment Processing.

  • All payment card transactions initiated through Remote Express are processed by LexisNexis VitalChek, which maintains PCI-DSS validation as a merchant service provider and provides Company and Customer with PCI compliance materials as applicable.
  • Company’s integration with VitalChek uses an inline iframe hosted by VitalChek and served within the Remote Express client experience; cardholder data is entered by the offender-user directly into the VitalChek-hosted iframe and is not received, transmitted, or stored by Company. The applicable PCI-DSS self-assessment is SAQ A-EP, and Company will maintain the applicable SAQ A-EP attestation, quarterly ASV scans, and the technical and organizational safeguards required for that scope.
  • The offender-user pays a fixed Agency Fee of $60.00 for a twelve (12)-month access period, which expires and does not automatically renew and for which no payment card is stored for automatic recharge. The Agency Fee is collected by VitalChek under Company’s merchant account and remitted to Company; it is not a “subscription.”
  • Any separate fee that Customer elects to charge offender-users for remote registration (a “Customer Convenience Fee,” if any) is collected by VitalChek under Customer’s own direct merchant relationship with VitalChek and deposited directly into Customer’s designated bank account; Company does not receive, hold, or pass through any Customer Convenience Fee, and Customer is responsible for establishing and maintaining its VitalChek merchant relationship and for any PCI-DSS attestation applicable to it.
  • Company shall make available to Customer, through the Remote Express agency portal, a report of transactions initiated through Remote Express to support Customer’s reconciliation; Company does not provide financial accounting, reconciliation, or tax-reporting services.
  • Company is not a money services business, payment aggregator, or money transmitter with respect to any fee described in this Section.
  • Customer’s use of VitalChek is governed by VitalChek’s own agreements with Customer, and the Agreement does not modify those terms.

4. Officer Review and Human-in-the-Loop Requirements.

  • All offender-user submissions must be reviewed by an authorized officer of Customer prior to acceptance.All offender-user submissions must be reviewed by an authorized officer of Customer prior to acceptance.
  • Customer shall not enable any auto-approval configuration that bypasses individual officer review.
  • The Remote Express review interface will present to the reviewing officer, at minimum, (i) the offender’s photograph on file, (ii) the offender’s submitted selfie, (iii) the facial-recognition match score, (iv) the submitted location, and (v) a side-by-side comparison view.
  • Customer shall document initial officer training on Remote Express review and maintain records of any refresher training.

5. Biometric Templates and Facial Imagery.

  • Company shall obtain, through the Remote Express end-user flow, informed written (electronic) consent from each offender-user prior to any biometric capture, disclosing the purpose of collection, the no-retention posture for biometric templates, and the retention posture for facial imagery, in a form intended to comply with applicable Law.
  • Biometric templates (mathematical face-geometry templates generated for identity comparison) are generated in volatile memory within Company’s security-controlled internal infrastructure for the specific comparison event only, are not written to persistent storage, and are destroyed immediately upon completion of the comparison. Company does not maintain any database of biometric templates, and no biometric template or image is transmitted to or received by Paravision or any other third party.
  • Facial imagery (selfies and mugshots), including selfies retained for audit purposes and any selfie promoted by an authorized officer of Customer to serve as the current mugshot of record, is Customer Information and shall be retained in accordance with Customer’s statutory records-retention obligations, which may require or permit indefinite retention.
  • Remote Express shall provide reviewing officers with a “Promote to Mugshot” function that allows a properly-verified offender-submitted selfie to replace the mugshot of record for the offender in Customer’s registry, and the audit log shall record the identity of the reviewing officer, the date and time, and the prior mugshot for reference.
  • Company shall not sell, lease, trade, or otherwise profit from biometric templates or facial imagery.
  • Company shall publish and maintain a written biometric information policy at a stable public URL and shall link to it from the Remote Express end-user terms of use and privacy policy.
  • Company’s license with Paravision is consistent with subsections (b) and (e) of this Section (on-premises operation; Paravision receives no data), and Company shall provide Customer with a summary of that arrangement upon request.

6. Geolocation Data. Location data collected via Remote Express shall be used solely to verify submission origin and detect location spoofing. Location data shall not be used for continuous surveillance or for any purpose beyond verification of the specific submission. Retention of location data shall be limited to the period necessary to demonstrate compliance and in no event longer than five (5) years from the date the end-user consent was given.

7. End-User Agreement. Offender-users of Remote Express are subject to a separate Company-published terms of use and privacy policy, including, where legally enforceable, consent to arbitration. Customer is not a party to and is not responsible for enforcement of those terms.

8. Automated Record Updates. Following officer approval, Remote Express will automatically update Customer’s registration records with the approved changes. Customer acknowledges that Customer bears ultimate responsibility for the accuracy of records maintained in Customer’s custody and shall periodically audit records updated through Remote Express. Company shall provide an audit-log export of all Remote Express-driven record changes upon Customer’s reasonable request.

9. Reporting. Company shall provide Customer with quarterly reports summarizing (a) submission volume, (b) approval and rejection rates, (c) facial-recognition match-score distributions, and (d) anomalies flagged by anti-spoofing controls. Reports will be made available through the Remote Express agency portal or via email.

10. Fees for Liability-Cap Purposes. For clarity, the offender-paid fees collected by Company from each end-user of Remote Express do not constitute Subscription Fees for purposes of Article 11 of the Master Subscription Services Agreement. Instead, for purposes of calculating the limitations on liability provided for in Section 11.4 of the Master Subscription Services Agreement, the “THE SUBSCRIPTION FEES PAID BY CUSTOMER FOR THOSE SPECIFIC SUBSCRIPTION SERVICES ACQUIRED DURING THAT SUBSCRIPTION PERIOD TO WHICH THOSE CLAIMS RELATE” shall equal Two Million Dollars ($2,000,000.00).

11. Offender-User Wind-Down. Upon any termination of Customer’s subscription to Remote Express, Company shall (a) continue to service existing offender-user access periods through the end of the then-current access period or the offender-user’s next registration verification date, whichever is earlier, and (b) coordinate with Customer on transition to in-person registration processes for affected offender-users.

12. Facial-Recognition Match Scores; No Warranty. Company does not warrant the accuracy of any facial-recognition match score, which is provided as decision-support only. All approval decisions affecting an offender-user’s registration record must be made by a qualified officer of Customer following the review described in Section 4 of this Exhibit. Customer is solely responsible for training its officers on interpretation of match scores and side-by-side photographic comparison, and shall not configure Remote Express to approve submissions without such human review.