← Back to Home

Terms of Service

Master Software as a Service (SaaS) Terms of Service Agreement

Last Updated: August 9, 2026

Preamble

This Master Software as a Service Terms of Service Agreement (the "Agreement") is entered into and made legally binding by and between Zarcore Technologies LLC, a registered Arizona Limited Liability Company, along with its corporate affiliates, hosting nodes, system custodians, and developers (collectively, the "Company"), and the business entity, corporation, or partnership executing this Agreement online or activating a software subscription module (the "Client").

WHEREAS, the Company has engineered and maintains a proprietary, multi-tenant B2B business operations automation engine hosted via cloud architecture on the Base44 Developer Platform, which features modular, activatable software utilities including, but not limited to, Customer Relationship Management (CRM) tools, Double-Entry Accounting Ledgers, Human Resources (HR) and Timekeeping components, and IT Assets & Infrastructure Mapping Portals; and

WHEREAS, the Client desires to obtain a non-exclusive, non-transferable, revocable commercial subscription license to access and utilize specific modular components of this platform for its internal business operations;

NOW, THEREFORE, in consideration of the mutual covenants, representations, warranties, and financial obligations contained herein, both parties contractually agree to the following terms:

Section 1: The Definition of the Licensed Platform and System Modules

1.1 Core Platform Definition: The "Platform" or "Software" refers exclusively to the unified, all-in-one generic business operational engine owned, compiled, and hosted by Zarcore Technologies LLC. This explicitly encompasses all source code modifications, database schema designs, custom transaction processing libraries (including, but not limited to, src/lib/ledger.js and associated files), row-level security isolation filters, algorithm nodes, user interface (UI) layouts, tab navigation architectures, and visual module store presentations deployed on the web application layers.

1.2 Component Module Options: The Client may systematically customize their enterprise environment by explicitly activating distinct operational utilities within the virtual Module Store. Each activated component shall be governed entirely by this Master Agreement. These modules include:

  • The CRM Module: Processing customer pipeline paths, interaction metadata entries, lead generation matrices, and client contact profiles.
  • The Accounting Ledger Module: Processing transaction hashes, accounts payable and receivable records, automated invoice generation, and double-entry accounting ledger entries.
  • The HR & Timekeeping Module: Processing employee records, time clock entries, shifts, payroll templates, and benefit allocation parameters.
  • The IT Infrastructure Module: Processing network rack elevation schematics, port mapping vectors, server inventory tables, device topology configurations, and hardware serial logs.

Section 2: Proprietary Intellectual Property and Clean-Room Warranties

2.1 Absolute Ownership of Software Assets: The Client explicitly acknowledges and agrees that Zarcore Technologies LLC holds 100% exclusive right, title, and interest in and to the Platform, the Software, the Module Store, and all associated technical logic, trademarks, and copyrights. No ownership rights, equity units, or intellectual property shares are transferred to the Client under this Agreement. The Client is granted strictly a temporary, revocable subscription license to interact with the front-end software views.

2.2 Clean-Room Independent Origin Warranty: The Company explicitly warrants and represents that the application architecture and underlying codebase were compiled entirely independently and from scratch, out-of-office, long after any historical employment relationships with any previous entities or hospitality organizations concluded. The system contains 0% overlapping code fragments, 0% proprietary trade secrets, and 0% internal private data belonging to any third party. The historical timeline and deployment logs are natively and immutably timestamped within the version control tracking systems of the Base44 Developer Platform to provide an unassailable digital verification trail.

2.3 Restrictions on Use: The Client covenants and agrees that it shall not, and shall not permit any employee, manager, or third-party contractor to:

  • Reverse-engineer, decompile, disassemble, or attempt to extract the underlying source code, database architectures, or proprietary processing scripts of the platform.
  • Modify, copy, record, or screenshot the specific dashboard layouts, system structures, or module store workflow configurations for the purpose of creating a competing application.
  • Rent, lease, sublicense, resell, or distribute access to the platform as a standalone service bureau or white-labeled instance without explicit written corporate authorization from the Company.

Section 3: Data Containment Strategies and Security Separation

3.1 Row-Level Security Isolation (RLS): The Company utilizes advanced, multi-tenant row-level security isolation filters built natively into its database clusters. This infrastructure ensures that the Client's financial data, employee files, and operational records are completely sequestered, hidden, and partitioned from the data pools of all other subscription clients using the multi-tenant engine.

3.2 Customer Data Ownership: The Client retains 100% exclusive ownership over all raw financial metrics, employee profiles, PII data, and hardware asset vectors that it inputs, uploads, or syncs to the platform (collectively, "Customer Data"). The Company holds no claims to Customer Data and shall only access it to the minimum extent necessary to process server queues, execute automated scripts, or troubleshoot system anomalies.

3.3 Data Migration Disclaimers: If the Client utilizes the Platform's automated data ingestion gateways to migrate historical records from previous software environments (including QuickBooks, legacy real estate apps, flat-file CSV formats, or manual spreadsheets), the Client assumes absolute liability for the accuracy and formatting of those inbound files. The Company is not responsible for data distortions, broken foreign key constraints, or corrupted dashboards originating from malformed source lines.

Section 3A: White Glove Data Migration Services

3A.1 As-Directed Technical Data Extraction Only: Where the Client purchases White Glove Onboarding, the Company's data migration service consists solely of an "As-Directed Technical Data Extraction": the technical parsing, AI-assisted field mapping, and bulk ingestion of the Client's own exported source files into the corresponding module of the Platform, performed strictly as directed and instructed by the Client. The Company is a software provider only. The Company is not a Certified Public Accountant (CPA), tax preparer, tax firm, bookkeeping firm, payroll processor of record, or auditing service, and no aspect of the migration service constitutes financial auditing, tax validation, payroll compliance review, or accounting advice of any kind. The Client holds 100% of the legal responsibility for independently verifying and signing off on the accuracy, completeness, and legal sufficiency of all migrated data before relying on it for any accounting, tax, payroll, or compliance purpose.

3A.2 No Liability for Corrupted, Incomplete, or Inaccurate Source Data: The Company is not liable, in whole or in part, for any mathematical errors, broken account balances, unbalanced trial balances, missing tax records, missing employee records, or any other data defect that stems from source files, exports, or spreadsheets that were corrupted, incomplete, inaccurate, mislabeled, or otherwise deficient at the time the Client provided them for migration. The Company's mapping process reproduces the substance of the source data as directed; it does not independently audit, reconcile, or validate the correctness of that source data against any external system of record.

3A.3 Mandatory Client Reconciliation Period: Following the ingestion of each migration job into the Client's workspace, the Client is granted a strict reconciliation window of no less than seven (7) and no more than fourteen (14) calendar days (the "Client Reconciliation Period") to review all migrated balances, ledgers, employee records, and other imported data within the Platform for accuracy against the Client's own historical records. The end date of the Client Reconciliation Period for each migration job is recorded on that job's Migration Summary Report.

3A.4 Recommended Parallel Run: The Company strongly recommends, and the Client agrees to conduct, a "Parallel Run" for the first thirty (30) calendar days following migration, or for one full payroll cycle or one full monthly billing cycle, whichever is applicable, during which the Client continues operating its legacy system alongside the Platform and reconciles its accounts payable, accounts receivable, trial balance, and payroll figures between the two systems before fully transitioning ("cutover") to the Platform as its system of record.

3A.5 Cutover Sign-Off and Final Release of Liability: Before the Company completes final cutover or the Client discontinues reliance on its legacy system, the Client (or its authorized representative) shall provide a written Cutover Sign-Off, delivered digitally through the Platform's in-app confirmation tools or an equivalent signed instrument, confirming that the Client has reviewed and verified the migrated historical data, ledgers, and employee records, and that the resulting balances and figures match the Client's own records. Upon the earlier of (a) the Client providing this Cutover Sign-Off, or (b) the Client's failure to raise any objection to the migrated data before the expiration of the Client Reconciliation Period described in Section 3A.3, the Client shall be deemed to have fully and finally approved the migration and releases the Company, its managing members, developers, and contractors from any and all liability arising from data mismatches, accounting errors, broken balances, tax penalties, audit findings, or payroll disputes traceable to the migrated data.

3A.6 Interaction With General Liability Terms: This Section 3A supplements, and does not limit, the data migration disclaimer in Section 3.3 above and the indemnification and liability cap provisions of Section 5 below, all of which remain in full force and effect with respect to the White Glove data migration service.

Section 4: Financial Infrastructure and Modular Subscription Fees

4.1 Upfront Module Activation Fees: To initialize a specific operational utility within the platform, the Client must pay an upfront, non-refundable core activation fee as displayed inside the virtual Module Store interface.

4.2 Recurring Monthly Subscription Fees: In addition to the activation fee, the Client contractually agrees to pay a recurring monthly subscription fee for each active module. These fees are automatically calculated and processed via the Client's linked corporate payment method on the first business day of each billing cycle.

4.3 Stripe Gateway Integration: All financial transactions, subscription renewals, and module activation payments are processed securely through the Company's integrated Stripe payment gateway. All payouts, transaction logs, and receipts will clear directly into the Company's verified digital business checking account (Wise Business or Mercury Bank) under the federal Employer Identification Number (EIN) 42-3887449.

4.4 Non-Payment and Suspension: If a recurring monthly subscription charge is rejected by the Client's financial institution, the Company reserves the explicit right to automatically pause the Client's workspace instance, revoke API authorization tokens, and suspend access to all active modules within forty-eight (48) hours of the failed transaction. The Company shall not be liable for any operational losses or missing data metrics resulting from a non-payment suspension.

4.5 Absolute Right to Terminate for Non-Payment: TIME IS OF THE ESSENCE with respect to every payment obligation under this Agreement. In the event any invoiced fee, activation fee, recurring subscription charge, or reinstatement charge remains unpaid for a period of ten (10) calendar days following its stated invoice due date, the Client shall be deemed to be in material breach of this Agreement, without any requirement of further notice, demand, or grace period beyond that stated herein. Upon such material breach, the Company may, at its sole and absolute discretion and without incurring any liability whatsoever: (a) immediately suspend the Client's workspace instance, user credentials, API keys, and webhook endpoints; (b) disable all module functionality, automated jobs, scheduled reports, and integrations; (c) declare this Agreement terminated for cause effective immediately; and (d) commence the irreversible data destruction sequence described in Section 6 of this Agreement, culminating in the permanent, unrecoverable overwrite of all Customer Data. The Client expressly acknowledges that suspension, termination for cause, and the resulting destruction of Customer Data are agreed-upon, bargained-for contractual remedies, are not penalties, and shall not be construed as a forfeiture.

4.6 Reinstatement, Interest, and Collection Costs: Any past-due balance shall accrue interest at the lesser of one and one-half percent (1.5%) per month or the maximum rate permitted by Arizona law, calculated from the original due date until paid in full. The Client shall additionally reimburse the Company for all costs of collection, including collection agency commissions, arbitration filing fees, court costs, and reasonable attorneys' fees. Reinstatement of a suspended workspace is offered solely at the Company's discretion and, where offered, is conditioned upon payment in full of all arrears, accrued interest, collection costs, and a non-refundable administrative reinstatement fee. The Company is under no obligation to reinstate any workspace whose data destruction window has expired, and reinstatement after destruction shall consist solely of a new, empty workspace instance.

4.7 No Refunds and No Set-Off: All activation fees, setup fees, migration fees, and recurring subscription fees are fully earned upon receipt and are strictly non-refundable in whole or in part, including in the event of suspension, termination for cause, voluntary cancellation mid-cycle, non-use of the Platform, or destruction of Customer Data. The Client waives any right of set-off, deduction, chargeback, or withholding against amounts owed to the Company, and agrees that the initiation of a payment-card chargeback or payment-processor dispute in respect of validly rendered services shall itself constitute an independent material breach of this Agreement.

Section 5: System Availability, Compliance, and Technical Limitation of Liability

5.1 As-Is Service Provision: The Platform, its user views, processing nodes, and reporting dashboards are provided entirely on an "As-Is" and "As-Available" basis, with all technical faults. To the maximum extent permitted by applicable law, the Company disclaims all warranties, whether express, implied, or statutory, including any implied warranties of merchantability, fitness for a particular purpose, or uninterrupted uptime.

5.2 Upstream Hosting Failures: The Client explicitly acknowledges that the platform is deployed via remote cloud servers. The Company shall not be held legally or financially liable for systemic downtime, packet losses, corrupted table files, or processing drops caused directly by third-party hosting pipeline adjustments, internet backbone blackouts, or server-side API rate-limiting crashes.

5.3 Absolute Indemnification: The Client agrees to fully defend, indemnify, and hold completely harmless Zarcore Technologies LLC, its managing members, directors, and developers from and against any and all civil claims, lawsuits, administrative tax audits, regulatory fines, or operational losses arising out of or resulting from:

  • The Client's utilization of the platform to process inaccurate, fraudulent, or non-compliant financial bookkeeping, HR payroll records, or corporate tax filings.
  • Systemic data distortions that manifest because Client administrative managers failed to audit or verify inbound files during automated CSV migration loops.

5.4 The Ultimate Financial Liability Cap: In the highly unlikely event that a court of competent jurisdiction rules that the Company is legally liable for an operational software bug, system glitch, or data loss event, both parties contractually agree that the Company's absolute maximum aggregate financial liability under any circumstances shall be strictly capped at the exact dollar amount the Client paid to the Company for software subscription services during the immediate twelve (12) months preceding the claim, or a maximum flat sum of one hundred US dollars ($100.00), whichever is lower. Under no circumstances shall the Company be held liable for any indirect, incidental, consequential, special, or punitive damages, including lost business profits, loss of corporate goodwill, or business interruption liabilities.

Section 6: Termination Protocols and Data Retrieval Lifelines

6.1 Client Cancellation: The Client may deactivate any active module or terminate their entire enterprise workspace at any time by navigating to the billing preferences tab inside the interface. Upon cancellation, the current subscription license will remain active until the conclusion of the paid billing cycle, after which all automated module tools will lock automatically.

6.2 Post-Termination Data Lifeline: Following the formal termination of a subscription instance, whether by voluntary cancellation, written or verbal notice of termination, abandonment of the workspace, or termination for cause arising out of non-payment under Section 4.5, the Company will hold the Client's underlying database containment records in an isolated, read-only, non-production cache status for a strict, non-extendable window of thirty (30) calendar days (the "Data Retrieval Window"). The Data Retrieval Window commences on the earlier of: (a) the effective date of termination; (b) the date the Company suspends the workspace for non-payment; or (c) the date the Client communicates an intent to terminate by any means, including verbally, by email, by support ticket, or by written notice. The Data Retrieval Window does not renew, toll, pause, or extend for any reason, including Client vacation, personnel turnover, illness, disputed invoices, pending arbitration, ongoing negotiations, or lack of internal awareness of this provision.

6.3 Client's Sole and Exclusive Responsibility to Export Data: THE CLIENT IS SOLELY, EXCLUSIVELY, AND ENTIRELY RESPONSIBLE FOR EXPORTING, DOWNLOADING, VERIFYING, AND INDEPENDENTLY ARCHIVING ALL CUSTOMER DATA PRIOR TO THE EFFECTIVE DATE OF TERMINATION AND, IN ALL EVENTS, PRIOR TO THE EXPIRATION OF THE DATA RETRIEVAL WINDOW. The Company has no obligation whatsoever to remind, notify, warn, prompt, telephone, or otherwise contact the Client regarding an approaching destruction deadline, and any courtesy notice the Company elects to send in a given instance creates no duty, custom, course of dealing, or expectation of future notice. The Client is further solely responsible for maintaining a current, accurate account-owner email address of record; the Company's transmission of any notice or secure download link to the email address then on file shall constitute complete and conclusive delivery, irrespective of whether the message is actually received, opened, filtered, quarantined, or read.

6.4 Data Retrieval Request Protocol: Data retrieval is available exclusively through the following controlled protocols, and by no other means: (a) Accounts in Good Standing. A Client whose account is current and free of arrears may, at any time during an active subscription or during the Data Retrieval Window, submit a support ticket through the in-Platform support interface requesting an export of its Customer Data. Upon verification of account standing and of the requester's identity as the account owner of record, the Company will generate and transmit a time-limited, single-tenant, cryptographically signed secure download link to the account owner's email address of record. (b) Accounts Suspended or Terminated for Non-Payment. Where the workspace has been disconnected for non-payment and the Client has not cured the payment default, the Company retains sole discretion over the manner and timing of any export. Where the Company elects to honor such a request, a time-limited secure download link will be generated and transmitted by email to the account owner of record. The Company may, as a precondition to release, require satisfaction of all outstanding arrears, verified identity documentation, and a signed acknowledgment of final termination. (c) Common Terms. All secure download links expire automatically, are non-transferable, are issued to the account owner of record only, and may be regenerated at the Company's discretion subject to an administrative processing fee. The Company reserves the right to refuse any export request it reasonably believes to be fraudulent, made by an unauthorized party, subject to a legal hold, or in furtherance of a breach of Section 2 of this Agreement.

6.5 Automatic, Irreversible Data Deletion Schedule: The Client expressly acknowledges and agrees to the following destruction schedule, which executes automatically and without human intervention: (a) Day 0. Termination, suspension for non-payment, or receipt of verbal or written notice of termination; workspace transitions to read-only isolation and the Data Retrieval Window opens. (b) Days 1 through 30. Customer Data remains available for export solely by the protocols set forth in Section 6.4; no new records may be created and all automations, scheduled jobs, and integrations remain disabled. (c) Day 30. The Data Retrieval Window closes permanently at 11:59 p.m. Mountain Standard Time (America/Phoenix) on the thirtieth (30th) calendar day. All outstanding secure download links are revoked. (d) Day 31. All production tenant records, database rows, uploaded documents, receipts, payroll files, employee records, and object-storage assets are purged from the live production clusters by automated cryptographic overwrite. (e) Days 31 through 60. All encrypted rolling backups, point-in-time recovery snapshots, replicas, and disaster-recovery archives containing the Client's tenant fragments are rotated out and cryptographically overwritten or key-destroyed in the ordinary course, such that no later than the sixtieth (60th) calendar day following termination NO copy of the Customer Data remains in any form under the Company's custody or control. THE CLIENT UNDERSTANDS THAT THIS PROCESS IS FINAL, ABSOLUTE, AND TECHNICALLY IRREVERSIBLE. Following execution, the Customer Data cannot be recovered, reconstructed, restored, undeleted, or reproduced by the Company, by the Client, by the Company's hosting providers, or by any forensic means, and the Company shall have no obligation to attempt any such recovery. Where the Client fails to pay and fails to communicate with the Company at any point prior to the expiration of the thirty (30) day Data Retrieval Window, deletion proceeds automatically and the Customer Data is permanently and unrecoverably destroyed without further notice of any kind.

6.6 Limitation of Liability for Data Loss Arising From Termination: TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, THE COMPANY, ITS MANAGING MEMBERS, OFFICERS, DEVELOPERS, CONTRACTORS, HOSTING PROVIDERS, AND SYSTEM CUSTODIANS SHALL BE HELD FOREVER HARMLESS FROM, AND SHALL BEAR NO LIABILITY WHATSOEVER FOR, ANY LOSS, DESTRUCTION, INACCESSIBILITY, OR NON-RECOVERABILITY OF CUSTOMER DATA, NOR FOR ANY LOSS OF BUSINESS, LOSS OF PROFITS, LOSS OF REVENUE, LOSS OF ANTICIPATED SAVINGS, LOSS OF CORPORATE GOODWILL, BUSINESS INTERRUPTION, REGULATORY PENALTY, TAX ASSESSMENT, AUDIT FAILURE, PAYROLL DISRUPTION, LITIGATION EXPOSURE, OR CONSEQUENTIAL, INCIDENTAL, INDIRECT, SPECIAL, EXEMPLARY, OR PUNITIVE DAMAGE OF ANY NATURE, ARISING OUT OF OR RELATING TO THE SUSPENSION OR TERMINATION OF THE CLIENT'S ACCOUNT OR THE DELETION OF CUSTOMER DATA, WHERE SUCH SUSPENSION, TERMINATION, OR DELETION RESULTS FROM THE CLIENT'S NON-PAYMENT, THE CLIENT'S MATERIAL BREACH OF THIS AGREEMENT, THE CLIENT'S OWN NOTICE OF TERMINATION, OR THE CLIENT'S FAILURE TO EXPORT ITS DATA WITHIN THE DATA RETRIEVAL WINDOW. This allocation of risk is a material, bargained-for inducement without which the Company would not provide the Platform at the stated subscription rates, applies regardless of the legal theory asserted (contract, tort, negligence, strict liability, statute, or otherwise), and survives any failure of any limited remedy of its essential purpose. All liability, if any, remains subject in all events to the aggregate financial liability cap set forth in Section 5.4.

6.7 Client Duty of Independent Backup: The Platform is not, and shall not be represented or relied upon as, a system of record of last resort, an archival repository, or a substitute for the Client's own backup regime. The Client covenants to maintain its own independent, off-platform backups of all business-critical records, including all financial, payroll, tax, employment, and asset records required to be retained under applicable federal, state, or local law, at a frequency appropriate to its own legal and regulatory retention obligations. The Client's failure to maintain such independent backups is an assumption of risk by the Client, and the Company shall bear no responsibility for the Client's resulting inability to satisfy any statutory retention, audit, or discovery obligation.

6.8 Termination by the Company for Cause; Survival: The Company may terminate this Agreement and the Client's workspace immediately, for cause and without refund, upon: non-payment as described in Section 4.5; breach of the intellectual property restrictions in Section 2.3; unlawful, fraudulent, or abusive use of the Platform; initiation of a chargeback in respect of validly rendered services; or any conduct that threatens the security, integrity, or lawful operation of the multi-tenant environment. Sections 2, 4.6, 4.7, 5, 6, and 7 shall survive any expiration or termination of this Agreement in full force and effect.

Section 6A: SMS / Text Messaging Consent and Terms

6A.1 Opt-In: By submitting your mobile phone number through the Company's website inquiry form and checking the accompanying consent box, you expressly consent to receive text messages (SMS) from Zarcore Technologies LLC and its authorized CRM agents, at the number provided, for purposes including scheduling, account notifications, customer support, and permitted service updates. Consent is not required as a condition of purchasing any goods or services.

6A.2 Message Frequency and Rates: Message frequency varies; you should expect no more than a few messages per month. Message and data rates may apply based on your mobile carrier plan.

6A.3 Opt-Out and Help: You may opt out of text messages at any time by replying STOP to any message received. For help, reply HELP or contact privacy@zarcore.com. Carriers are not liable for delayed or undelivered messages.

6A.4 No Sharing for Marketing Purposes: Mobile opt-in information and phone numbers collected for SMS purposes will not be shared with any third party for marketing or promotional purposes.

6A.5 Supported Carriers: Zarcore's text messaging service is offered on major US mobile carriers. Carriers are not liable for delayed or undelivered messages.

Section 7: Arbitration, Severability, and Arizona Governing Law

7.1 Substantive Arizona Governing Law: This Master Agreement, its execution paths, and all legal relationships arising out of the deployment of this B2B SaaS platform shall be governed by, structured under, and enforced exclusively in accordance with the substantive laws of the State of Arizona, completely bypassing any conflict of law principles.

7.2 Private Binding Arbitration Shield: To eliminate the stress, high costs, and public exposure of traditional courtroom litigation, both parties contractually agree that any and all disputes, breaches, or interpretations of this contract shall be resolved exclusively through final, binding arbitration administered by the American Arbitration Association (AAA) sitting within Maricopa County, Arizona, rather than a public trial. Both parties explicitly waive their constitutional right to a jury trial or to participate in a class-action lawsuit against each other.

7.3 Strategic Anti-SLAPP Protections: If an outside third party or the Client files a groundless, frivolous, or predatory civil lawsuit against Zarcore Technologies LLC in an attempt to harass the developer, disrupt operations, or interfere with corporate expansion, the Company shall immediately deploy Arizona's ironclad Anti-SLAPP statutory protections. The Company will seek immediate dismissal of the groundless action and a mandatory court order forcing the opposing party to pay 100% of the Company's legal and attorney fees.

7.4 Structural Severability: If any single clause, sentence, or sub-provision of this Agreement is held to be invalid, illegal, or contractually unenforceable by an authorized arbitrator or court, that specific element shall be minimized or severed to the minimum extent necessary, and all remaining sections shall continue in full force and effect to maintain maximum legal insulation for the Company.

IN WITNESS WHEREOF, the parties hereto have accepted, ratified, and digitally executed this Master Software as a Service Terms of Service Agreement as of the date of electronic account registration or module activation.

Schedule A: Data Processing Addendum

This Schedule A ("DPA") is incorporated into, and forms an integral and legally binding part of, this Agreement. It governs the processing of personal data contained within Customer Data across the CRM, Accounting, HR & Payroll, Inventory, IT Assets, and Business Analytics modules. Where this Schedule conflicts with the preceding Sections of this Agreement on matters of data protection, this Schedule controls.

A.1 Roles of the Parties

With respect to the processing of personal data submitted to, or generated within, a Client workspace:

  • Client as Controller: The Client determines the purposes and means of processing its own Customer Data, including employee records (HR module), customer and lead records (CRM module), vendor and financial records (Accounting module), and network/asset inventories (IT Assets module).
  • Company as Processor: The Company processes Customer Data solely as necessary to provide the Platform, strictly on the documented instructions of the Client as set out in this Agreement and the Client's own configuration of its workspace (e.g., which modules are activated, which fields are populated, which team members are invited).

A.2 Subject Matter, Nature, and Duration of Processing

Subject Matter: The Company's hosting, storage, computation, and transmission of Customer Data as needed to operate the modular business system the Client has subscribed to.

Nature and Purpose: Provisioning the Client's isolated workspace; running CRM pipeline, accounting ledger, payroll, inventory, and IT asset logic against Customer Data; generating reports, invoices, and notifications; and providing customer support.

Categories of Data Subjects: The Client's employees and contractors (HR/Payroll module), the Client's customers and leads (CRM module), the Client's vendors and business contacts (Accounting module), and, incidentally, individuals associated with IT/network assets (IT Assets module).

Categories of Personal Data: Contact details (name, email, phone, address); employment data (job title, compensation, benefit elections, timesheets); payroll data (bank account details, tax withholding elections, and, where the Client opts to store them, Social Security Numbers, which are encrypted at rest using a dedicated encryption key and are only ever decrypted on an authorized, logged, on-demand basis); financial data (invoices, ledger entries, bank feed transactions); and CRM data (deal values, communications, marketing consent status).

Duration: For the term of this Agreement, plus the thirty (30) day Data Retrieval Window and the subsequent automated purge schedule described in Section 6 above.

A.3 The Company's Obligations as Processor

The Company shall:

  • Process Customer Data only on the Client's documented instructions (including as expressed through the Client's own module configuration and user actions), unless required to do otherwise by law, in which case the Company will inform the Client of that legal requirement first, unless legally prohibited from doing so.
  • Ensure that personnel authorized to process Customer Data are bound by confidentiality obligations.
  • Implement appropriate technical and organizational security measures, including: TLS encryption in transit; encryption at rest for sensitive fields such as SSNs and bank account details; strict row-level security (RLS) so each tenant's data is logically isolated from every other tenant; role-based access control (RBAC) within each workspace; and automated, encrypted backup snapshots.
  • Engage sub-processors only as disclosed in Section A.5 below, and remain fully liable for their acts and omissions in relation to Customer Data.
  • Notify the Client without undue delay, and in any event within forty-eight (48) hours of becoming aware, of any confirmed unauthorized access to, or disclosure of, Customer Data ("Security Incident"), and provide reasonably available information to help the Client meet any of its own breach-notification obligations.
  • Assist the Client, insofar as reasonably possible given the nature of the Platform, in responding to requests from data subjects seeking to exercise their rights under applicable data protection law, where such requests are directed to the Company in error and identify the relevant Client workspace.
  • Delete or return Customer Data in accordance with Section 6 above (the Data Retrieval Window and automated purge schedule) upon termination of the Client's subscription, except to the extent retention of specific records (e.g., Stripe invoice history, tax-relevant transaction logs) is required by law.

A.4 The Client's Obligations as Controller

The Client shall:

  • Ensure it has a valid legal basis for all personal data it inputs, uploads, or syncs into its workspace, including employee data entered into the HR module and lead/customer data entered into the CRM module.
  • Ensure any privacy notices required to be given to its own employees, customers, or leads (as applicable) adequately disclose the Client's use of the Company as a processing platform.
  • Be solely responsible for the accuracy, quality, and lawfulness of Customer Data, and for configuring role-based access within its own workspace (e.g., who on the Client's team can view SSNs or bank details via the HR module's reveal-on-demand controls).
  • Where the Client uses the Marketing add-on to send outreach campaigns, ensure it has appropriate consent or legal basis to contact those recipients, and honor opt-outs (which the Marketing module tracks and enforces automatically).

A.5 Sub-processors

The Client provides general written authorization for the Company to engage the following categories and named sub-processors, each engaged for a specific, limited purpose. The Company remains responsible for each sub-processor's compliance with data protection obligations equivalent to those in this Schedule.

  • Stripe, Inc. — Payment processing: Subscription billing, invoice payment collection, and card/bank payment method storage. Stripe is PCI DSS Level 1 certified. The Company does not store full card numbers on its own servers.
  • Google LLC (Google Workspace / Gmail / Google Calendar) — Where the Client or Company connects a Google account: transactional and lead email sending/receiving (Gmail), meeting scheduling and calendar sync (Google Calendar), and associated data retention within Google's infrastructure for accounts so connected.
  • Microsoft Corporation (Microsoft 365 / Outlook / SharePoint / OneDrive) — Where the Client or Company connects a Microsoft account: email sending/receiving (Outlook), meeting scheduling and calendar sync, and document/file storage and retention (SharePoint / OneDrive), functionally equivalent to the Google integrations above.
  • Cloud Hosting & Database Infrastructure (Base44 Platform) — Multi-tenant application hosting, database storage with row-level security isolation, encrypted object storage for uploaded files, and automated backup infrastructure underlying the entire Platform.

The Company will notify Client account owners of any new material sub-processor category via the standard system notification channel described in this Agreement. Continued use of the Platform following such notice constitutes acceptance of the updated sub-processor list.

A.6 International Data Transfers

The Company and its sub-processors (including Stripe, Google, Microsoft, and the underlying cloud hosting infrastructure) may process Customer Data in the United States and other jurisdictions in which those providers operate. Where such processing involves a transfer of personal data out of a jurisdiction with data localization or adequacy requirements (e.g., the European Economic Area or United Kingdom), the Company relies on the sub-processor's own certified transfer mechanisms (such as Standard Contractual Clauses) as made available by Stripe, Google, and Microsoft respectively.

A.7 Security Measures Specific to Sensitive Modules

In recognition of the sensitivity of the data flowing through certain modules, the Company applies the following module-specific safeguards:

  • HR & Payroll Module: Employee Social Security Numbers and bank account details are encrypted at rest with a dedicated encryption key, are never displayed in plaintext by default, and are only decrypted through an explicit, individually-logged "reveal" action taken by an authorized Client user.
  • Accounting Module: Ledger entries, bank feed data, and reconciliation records are isolated per tenant via row-level security and are never aggregated or compared across different Client workspaces.
  • IT Assets Module: Network topology, port maps, and device credentials entered by the Client are stored within that Client's isolated workspace and are not accessible to, or scanned by, any other tenant.

A.8 Audit Rights

Upon reasonable prior written request, no more than once per twelve (12) month period (absent a suspected Security Incident), the Company will make available to the Client information reasonably necessary to demonstrate compliance with this Schedule, such as a summary of its technical and organizational security measures. Any on-site or infrastructure-level audit request must be conducted in a manner, and at a time, that does not disrupt the shared multi-tenant environment serving other Company clients, and may be satisfied through a written questionnaire response at the Company's discretion.

A.9 Deletion on Termination

Upon termination of the Client's subscription, the Company will handle Customer Data strictly in accordance with the Data Retrieval Window and automated destruction schedule described in Section 6 above: a thirty (30) day read-only retrieval window, followed by permanent deletion from production systems, followed by rotation out of encrypted backup snapshots. The Company has no obligation to retain Customer Data beyond that schedule, and the Client is solely responsible for exporting its data before the window closes.

A.10 Precedence and Term

This Schedule takes effect automatically upon the Client's execution of this Agreement (including via online account registration or module activation) and remains in effect for as long as the Company processes Customer Data on the Client's behalf. In the event of any conflict between this Schedule and the body of this Agreement regarding the processing of personal data, this Schedule shall govern.

Schedule B: Acceptable Use Policy

This Schedule B ("AUP") is incorporated into, and forms an integral and legally binding part of, this Agreement. It sets out specific, module-by-module rules governing the Client's, and the Client's authorized users', use of the Platform and its connected third-party services. Violation of this Schedule constitutes a material breach of this Agreement and may result in immediate suspension of the offending module or the entire workspace under Section 4.5 and Section 6.8 above, without the ten (10) day cure period otherwise applicable to non-payment breaches.

B.1 General Prohibited Conduct

Across every module of the Platform, the Client shall not, and shall not permit any user of its workspace to:

  • Upload, transmit, or store any content that is unlawful, defamatory, fraudulent, or infringes the intellectual property, privacy, or publicity rights of any third party.
  • Upload or attempt to upload malicious code, malware, ransomware, or any file designed to disrupt, disable, or gain unauthorized access to the Platform, other tenants' workspaces, or the Company's underlying infrastructure.
  • Attempt to probe, scan, or test the vulnerability of the Platform or its network, or attempt to breach the row-level security isolation separating the Client's workspace from any other tenant.
  • Use automated means (bots, scrapers, or scripts) to extract data from the Platform beyond the Client's own workspace, or to circumvent rate limits, usage caps, or seat/module licensing restrictions.
  • Impersonate any person or entity, or misrepresent an affiliation with any person or entity, when using the CRM, HR, or Support modules.
  • Use the Platform to violate any applicable federal, state, or local law, including tax law, labor law, wage-and-hour law, or data protection law.

B.2 CRM & Marketing Module — Acceptable Use

The CRM module, including its Marketing add-on, may not be used to:

  • Send unsolicited bulk commercial email ("spam") in violation of the CAN-SPAM Act, CASL, or equivalent anti-spam law, or to any contact who has not been lawfully added to the Client's CRM.
  • Send marketing communications to any contact after that contact has opted out through the Platform's unsubscribe mechanism; the Client is responsible for honoring all opt-outs recorded by the Marketing Compliance tools.
  • Harvest, purchase, or import third-party contact lists obtained without a lawful basis for outreach (e.g., scraped lead lists with no prior relationship or consent).
  • Post social content through the Social Studio tools that is deceptive, infringing, or violates the terms of service of the underlying social platform (Facebook, Instagram, etc.) to which it is pushed.

B.3 Accounting Module — Acceptable Use

The Accounting module, invoicing tools, and Stripe-powered payment features may not be used to:

  • Process, invoice for, or accept payment for illegal goods or services, or for any transaction prohibited under Stripe's own Restricted Businesses terms.
  • Knowingly enter false, fraudulent, or materially misleading ledger entries, expense categorizations, or financial statements for the purpose of tax evasion, financial statement fraud, or misleading a lender, investor, or auditor.
  • Initiate a payment-card chargeback or Stripe dispute against a validly rendered charge in bad faith, or use the invoicing tools to bill customers for amounts not actually owed.
  • Circumvent Stripe's payment processing by directing customers to pay through unauthorized, undisclosed channels in a manner that violates Stripe's terms or applicable payment-processing law.

B.4 HR & Payroll Module — Acceptable Use

The HR & Payroll module, including its Social Security Number and bank-detail storage features, may not be used to:

  • Store, process, or run payroll for any worker in a manner that violates federal or state wage-and-hour law, minimum wage law, or worker classification rules (e.g., knowingly misclassifying employees as independent contractors to avoid payroll tax obligations).
  • Grant "reveal SSN" or "reveal bank info" access to any user who is not authorized by the Client to view that specific employee's sensitive data; the Client is solely responsible for its own internal role assignments.
  • Use the recruiting/talent acquisition tools to solicit, screen, or reject candidates on any basis prohibited by federal or state anti-discrimination law.
  • Upload employee documents (offer letters, disciplinary records, benefit elections) that the Client does not have the right to store or that were obtained unlawfully.

B.5 Inventory & IT Assets Modules — Acceptable Use

The Inventory and IT Assets modules may not be used to:

  • Track, list, or manage inventory of any goods that are stolen, counterfeit, or illegal to possess or sell in the Client's jurisdiction.
  • Use the network topology, port mapping, or device credential storage features of the IT Assets module to plan, document, or facilitate unauthorized access to any network or system that is not owned or lawfully operated by the Client.
  • Store live production credentials (e.g., unencrypted administrator passwords) in a manner inconsistent with reasonable security hygiene; the Client is responsible for its own credential rotation practices.

B.6 Use of Connected Third-Party Services (Stripe, Google, Microsoft)

The Platform integrates with the following third-party services, each of which imposes its own acceptable use terms that the Client must also independently comply with when connecting an account:

  • Stripe (Payments): The Client must comply with Stripe's Services Agreement and Restricted Businesses policy for all invoicing, subscription billing, and checkout activity processed through the Platform.
  • Google (Gmail & Google Calendar): Where the Client connects a Google account for lead email or calendar sync, the Client must comply with Google's Acceptable Use Policy and Gmail's bulk-sender guidelines, including maintaining low spam-complaint rates and honoring unsubscribe requests.
  • Microsoft (Outlook, SharePoint & OneDrive): Where the Client connects a Microsoft account for email, calendar sync, or document storage/retention, the Client must comply with the Microsoft Services Agreement and Microsoft's own acceptable use terms, in the same manner as required for Google above.

The Company is not responsible for, and bears no liability arising from, a Client's violation of a connected third-party provider's own terms of service. The Company reserves the right to disconnect any integration that it reasonably believes is being used in a manner that violates the applicable provider's terms, in order to protect the Company's own standing with that provider.

B.7 Enforcement

The Company may, in its sole discretion and without prior notice, disable a specific module, integration, or feature (rather than the entire workspace) where it reasonably believes a violation of this Schedule is confined to that module or feature. Where the violation is severe, ongoing, or threatens the security or integrity of the multi-tenant Platform, the Company may suspend or terminate the Client's entire workspace under Section 4.5 and Section 6.8 above. The Client remains liable for all fees accrued prior to any such suspension or termination, consistent with Section 4.7 above.