Master Service Agreement
Last Updated: June 25, 2026
This Master Service Agreement ("Agreement") is entered into between Complya, Inc., a Delaware corporation ("Provider"), and the customer identified in the applicable Order Form ("Customer"). This Agreement governs Customer's access to and use of the platform and services provided by Provider.
1. Definitions
- "Authorized Users" means Customer's employees, contractors, and agents who are authorized to access the Services. Each Authorized User must have unique credentials; account sharing is strictly prohibited.
- "BAA" means the Business Associate Agreement located at complya.com/baa, which is incorporated herein by reference.
- "Customer Data" means all data, content, and information submitted by or on behalf of Customer through the Services, including Protected Health Information ("PHI").
- "Order Form" means the document executed by the parties specifying the Services, fees, and term.
- "Platform" means Provider's proprietary software-as-a-service platform.
- "Services" means the subscription-based access to the Platform and any associated professional services.
- "Terms of Service" means the terms governing use of the Site and Services located at complya.com/terms.
2. Services and Support
2.1 Billing and Reimbursement Disclaimer
The Platform is designed for complex practice management. While Provider provides tools aligned with standard billing codes (CPT/H-codes), Provider does not guarantee reimbursement or compliance with specific payer contracts. Customer retains sole responsibility for the accuracy of clinical documentation and billing submissions.
2.2 Beta Features
From time to time, Provider may make "beta" or early-access features available. These features are provided "AS IS" and "AS AVAILABLE" without any warranty. Provider shall have no liability for any harm or damage arising out of or in connection with a Beta Feature.
2.3 Support and Service Levels
(a) Support: Technical support is available via email at support@complya.com during standard business hours, excluding public holidays.
- Support Inquiries: Technical support is available via email at support@complya.com during standard business hours, excluding standard public holidays.
- Response Times: Provider will make commercially reasonable efforts to respond to support inquiries and resolve technical issues in a timely manner. Issue resolution will be prioritized based on the severity and overall impact of the problem.
(b) Platform Uptime: "Monthly Uptime Percentage" means (total minutes in the month minus Downtime minutes) divided by total minutes in the month. "Downtime" means a period during which the Platform is unavailable to Customer, excluding: (i) scheduled maintenance communicated with at least 48 hours' advance notice; (ii) unavailability caused by force majeure events under Section 12.9; and (iii) unavailability caused by Customer's acts or omissions. Provider commits to a Monthly Uptime Percentage of at least 99%.
(c) Service Credits: If Monthly Uptime falls below 99.0% in a given calendar month, Customer shall be entitled to a service credit equal to one (1) day of the monthly fee for each full percentage point below 99.0%, up to a maximum of seven (7) days of the monthly fee per month. Credits must be requested in writing within thirty (30) days of the affected month and shall be applied to the next invoice. Credits are Customer's sole and exclusive financial remedy for Platform unavailability. Provider makes real-time platform availability visible at https://status.complya.com.
3. Restrictions and Responsibilities
3.1 Use Restrictions
Customer shall not, and shall not permit others to: (i) reverse engineer or decompile the Platform; (ii) build a competitive product or use the Services for competitive benchmarking; (iii) provide access to Provider's direct competitors; or (iv) use the Services for any fraudulent or unlawful purpose. Any violation of clauses (ii) or (iii) constitutes a material breach and may result in immediate termination and legal action.
3.2 Equipment and Security
Customer is responsible for obtaining and maintaining all equipment and connectivity needed to access the Services. Customer shall maintain the security of all account credentials and is liable for all activities occurring under Customer's account.
4. Data Privacy and HIPAA
4.1 Business Associate Agreement
The parties shall comply with the BAA regarding the handling of PHI. In the event of a conflict between this Agreement and the BAA regarding PHI, the BAA shall control.
4.2 Security Standards
Provider shall implement administrative, physical, and technical safeguards, including AES-256 encryption at rest and TLS 1.2 or higher in transit. Provider shall conduct annual vulnerability assessments and maintain comprehensive audit logs.
4.3 Breach Notification
Provider shall notify Customer of any confirmed Breach of PHI or unauthorized access to Customer Data as follows, consistent with the BAA: (i) a preliminary notification without unreasonable delay and in no event later than seventy-two (72) hours after Provider's reasonable confirmation that a Breach has occurred, including the nature of the incident, categories of data involved, and approximate number of individuals affected to the extent then known; and (ii) a final written report no later than sixty (60) calendar days after discovery, covering the full scope of the Breach, affected individuals, and remediation steps taken. Customer's regulatory notification obligations to affected individuals and HHS begin upon the date of discovery of the Breach, which may precede Customer's receipt of the preliminary notification; Provider's seventy-two (72) hour notification obligation is designed to provide Customer maximum advance notice within that regulatory window. Provider shall cooperate with Customer in any required notifications. This section summarizes Provider's notification obligations under the BAA; in the event of any inconsistency between this section and the BAA, the BAA governs.
4.4 Geolocation Consent
If the Services include geolocation-based features (e.g., visit verification), Customer represents and warrants that it has obtained all necessary consents from Authorized Users and patients for the collection and processing of location data.
4.5 Non-PHI Personal Data Processing
To the extent Provider processes personal data not governed by the BAA (e.g., Authorized User account credentials, contact information, and usage analytics), such processing is governed by Provider's Privacy Policy at complya.com/privacy. For Customers subject to state comprehensive privacy laws (including CCPA/CPRA), Complya acts as a Service Provider as defined therein, processing such data solely for the business purposes described in the Privacy Policy.
4.6 Business Continuity and Disaster Recovery
Provider maintains a documented Business Continuity Plan ("BCP") and Disaster Recovery Plan ("DRP") reviewed and tested at least annually. Provider's infrastructure is deployed across geographically redundant cloud availability zones. In the event of a declared disaster materially affecting the Services, Provider will: (i) notify Customer within twenty-four (24) hours of declaring a disaster; and (ii) use commercially reasonable efforts to restore Platform availability in accordance with its then-current DRP.
4.7 Subprocessor Changes
Provider shall maintain and publish a current list of subprocessors at complya.com/privacy. Provider shall give Customer at least thirty (30) days' prior written notice before adding or replacing any subprocessor that will process Customer Data containing PHI. If Customer reasonably objects in writing within fourteen (14) days that the new subprocessor would cause Provider to breach its HIPAA or BAA obligations, the parties shall negotiate in good faith to resolve the objection.
5. Confidentiality and Proprietary Rights
5.1 Confidentiality
"Proprietary Information" means any non-public technical, business, financial, or operational information disclosed by one party to the other that is identified as confidential or should reasonably be understood to be confidential given the nature of the disclosure. Each party shall take reasonable precautions to protect the other party's Proprietary Information. This obligation survives for five (5) years post-termination, except for PHI, which is governed indefinitely by the BAA.
5.2 Ownership
Customer owns all right, title, and interest in Customer Data. Provider owns and retains all rights in the Platform, Software, and any improvements or modifications thereto.
5.3 AI Processing
AI-powered features within the Services may process Customer Data, including PHI, through Provider's AI infrastructure and third-party AI subprocessors, solely to provide the Services to Customer. Provider does not use Customer Data or PHI to develop, train, or improve AI or machine learning models. All subprocessors that process PHI in connection with AI features have executed BAAs with Provider, as listed at complya.com/privacy. Ownership of Customer Data remains with Customer at all times.
5.4 Feedback Ownership
"Feedback" means conceptual suggestions or comments regarding the Services provided by Customer's authorized personnel, and expressly excludes any Customer Data, PHI, or Authorized User personal information. Customer may provide Feedback to Provider, and hereby grants Provider a royalty-free, worldwide, perpetual, irrevocable license to use and incorporate such Feedback into the Services without any obligation or compensation to Customer.
6. Fees and Payment
6.1 Payment Terms
Customer shall pay the fees specified in the Order Form. Payments are due Net 30 from the invoice date. Provider may increase fees for Renewal Terms by providing notice at least sixty (60) days prior to the end of the current term.
6.2 Non-Refundable; Early Termination
All fees are non-refundable. If Customer terminates early or Provider terminates for Customer's material breach, all fees for the remainder of the then-current term become immediately due and payable as liquidated damages and not as a penalty, reflecting the difficulty of calculating Provider's actual damages from early termination. For the avoidance of doubt, this liquidated damages provision shall not apply if Customer terminates this Agreement pursuant to Section 8.2 due to Provider's uncured material breach.
6.3 Invoice Disputes
Customer may dispute any invoice in good faith by providing written notice to Provider within fifteen (15) days of the invoice date, identifying the specific amount disputed and the basis for the dispute. Undisputed amounts remain due by the original due date. Provider shall not suspend Service on disputed amounts while a good-faith dispute is pending resolution.
7. Suspension of Service
Provider reserves the right to suspend access if: (i) an invoice is more than forty-five (45) days past due; (ii) Provider determines, in its reasonable judgment, that Customer's use poses a material threat to the security, integrity, or availability of the Platform; or (iii) Customer violates any material provision of the Terms of Service or the BAA.
8. Term and Termination
8.1 Auto-Renewal
This Agreement shall automatically renew for successive one (1) year periods unless either party provides written notice of non-renewal at least sixty (60) days prior to the end of the current term.
8.2 Termination for Cause
Either party may terminate upon thirty (30) days' written notice of an uncured material breach. Provider may terminate immediately for Customer's non-payment or for a material and willful HIPAA violation caused solely by Customer's acts or omissions, provided that such termination right does not apply to HIPAA violations caused or contributed to by Provider's own act or omission. Customer may terminate this Agreement prior to the expiration of the then-current term upon ninety (90) days' written notice; such early termination requires payment of all fees for the remainder of the then-current term as described in Section 6.2.
8.3 Data Retention and Export Responsibility
Customer is solely responsible for exporting Customer Data prior to termination. Upon termination, Provider shall retain Customer Data for a period of sixty (60) days to allow for final export. After this period, Provider shall destroy PHI in accordance with the BAA. Notwithstanding any suspension of Customer's access to the Services, Provider shall maintain Customer's ability to export Customer Data in CSV format during the sixty (60) day Data Retention Period. If access is suspended pursuant to Section 7, Provider shall restore read-only data export functionality within forty-eight (48) hours of Customer's written request.
9. Warranty Disclaimer
THE SERVICES ARE PROVIDED "AS IS." PROVIDER DISCLAIMS ALL IMPLIED WARRANTIES. PROVIDER DOES NOT WARRANT THAT THE SERVICES WILL BE ERROR-FREE OR THAT USE WILL RESULT IN SUCCESSFUL REIMBURSEMENT.
10. Indemnification
10.1 Indemnification by Customer
Customer shall indemnify and hold harmless Provider against any claims arising from: (i) Customer's breach of this Agreement; (ii) Customer's clinical or billing practices; or (iii) unauthorized disclosure of PHI caused by Customer's Authorized Users or equipment. Provider shall: (a) promptly notify Customer in writing of any indemnifiable claim; (b) give Customer sole control of the defense and settlement, provided that Customer shall not settle any claim in a manner that imposes obligations on Provider without Provider's consent; and (c) provide Customer with reasonable cooperation and assistance.
10.2 Indemnification by Provider
Provider shall defend, indemnify, and hold harmless Customer from and against any third-party claims alleging that the Platform infringes a U.S. patent, copyright, or trademark. This obligation is contingent upon Customer providing prompt notice of the claim and granting Provider sole control of the defense. Provider's indemnification obligations under this Section shall not apply to any claim arising from: (i) modification of the Platform by Customer or any third party not authorized by Provider; (ii) combination of the Platform with products, services, or software not provided or approved by Provider; (iii) Customer's failure to implement an update that would have avoided the claim; or (iv) use of the Platform outside the scope of the license granted herein.
11. Limitation of Liability
11.1 Exclusion of Damages
NEITHER PARTY SHALL BE LIABLE FOR INDIRECT, INCIDENTAL, OR CONSEQUENTIAL DAMAGES, INCLUDING LOSS OF PROFITS, DATA, OR GOODWILL, ARISING OUT OF OR IN CONNECTION WITH THIS AGREEMENT.
11.2 Liability Cap
IN NO EVENT SHALL PROVIDER'S TOTAL CUMULATIVE LIABILITY EXCEED THE FEES PAID BY CUSTOMER IN THE TWELVE (12) MONTHS PRIOR TO THE ACCRUAL OF THE CLAIM, UNLESS A DIFFERENT AMOUNT IS EXPRESSLY SPECIFIED IN THE ORDER FORM. Provider's pricing reflects, in part, this allocation of risk.
11.3 Exceptions to Liability Cap
The limitations set forth in Section 11.2 shall not apply to: (i) a party's willful or intentional disclosure of the other party's Proprietary Information to a third party for commercial benefit or competitive advantage; (ii) Provider's breach of its data security obligations under Section 4 resulting from gross negligence or willful misconduct; (iii) a party's indemnification obligations under Section 10; or (iv) any liability that cannot be limited by applicable law.
12. Miscellaneous
12.1 Governing Law and Arbitration
This Agreement shall be governed by the laws of the State of Delaware without regard to its conflict of laws provisions. Any dispute, claim, or controversy arising out of or relating to this Agreement or the breach, termination, enforcement, interpretation, or validity thereof, shall be determined by binding arbitration in Wilmington, Delaware. The arbitration shall be administered by JAMS pursuant to its Comprehensive Arbitration Rules and Procedures. Judgment on the Award may be entered in any court having jurisdiction.
EACH PARTY MAY BRING CLAIMS AGAINST THE OTHER ONLY ON AN INDIVIDUAL BASIS AND NOT AS A PLAINTIFF OR CLASS MEMBER IN ANY PURPORTED CLASS, CONSOLIDATED, OR REPRESENTATIVE ACTION OR PROCEEDING. THE ARBITRATOR MAY NOT CONSOLIDATE OR JOIN MORE THAN ONE PARTY'S CLAIMS AND MAY NOT OTHERWISE PRESIDE OVER ANY FORM OF A CONSOLIDATED, CLASS, OR REPRESENTATIVE PROCEEDING.
Notwithstanding the foregoing, Provider reserves the right to seek injunctive or equitable relief in any court of competent jurisdiction to protect its intellectual property or confidential information.
12.2 Order of Precedence
In the event of any direct conflict, the following order of precedence shall govern: (1) Business Associate Agreement (complya.com/baa); (2) Executed Order Form; (3) This Master Service Agreement (complya.com/msa); (4) Product Privacy Policy (complya.com/privacy); (5) Terms of Service (complya.com/terms).
12.3 Non-Solicitation
During the term and for one (1) year thereafter, neither party shall directly solicit or recruit for employment any employee of the other party who was materially involved in the performance of this Agreement. This Section shall not prohibit either party from hiring any person who responds to a general public advertisement not targeted at the other party's employees.
12.4 Logo Rights
Customer grants Provider a non-exclusive, royalty-free license to use Customer's name and logo in Provider's customer lists and marketing materials during the term. Customer may revoke this license upon thirty (30) days' written notice, after which Provider shall remove Customer's marks from new materials but shall have no obligation to recall materials already in circulation. This license automatically terminates upon expiration or termination of this Agreement.
12.5 Anti-Corruption
Customer represents that it has not received or been offered any bribe, kickback, or thing of value from any Provider employee or agent in connection with this Agreement.
12.6 Copyright/DMCA Policy
Provider respects intellectual property rights and will respond to notices of alleged infringement in accordance with the Digital Millennium Copyright Act. Notices should be sent to support@complya.com.
12.7 Amendments
Provider may update this Agreement upon thirty (30) days' prior written notice. Material amendments (including changes to fees, data rights, or limitation of liability) shall require Customer's affirmative written consent or a thirty (30) day period during which Customer may terminate without early termination fees. For non-material updates (e.g., clarifications or legal hygiene), Customer's continued use after the effective date constitutes acceptance.
12.8 Limitation on Claims
Any claim or cause of action arising out of or related to use of the Services or this Agreement must be filed within one (1) year after such claim or cause of action arose, or within one (1) year of when the claiming party first knew or reasonably should have known of the basis for the claim, whichever is later, or be forever barred; except that claims arising out of or relating to the BAA or the handling of PHI shall be governed by applicable law.
12.9 Force Majeure
Neither party shall be liable for any failure or delay in performance (other than payment obligations) due to causes beyond its reasonable control, including acts of God, war, terrorism, power outages, or internet service provider failures, provided the affected party provides prompt notice and uses reasonable efforts to mitigate the impact.
12.10 Severability
If any provision of this Agreement is found to be unenforceable or invalid, that provision will be limited or eliminated to the minimum extent necessary so that this Agreement will otherwise remain in full force and effect.
12.11 Assignment
Customer may not assign this Agreement or any of its rights or obligations hereunder without Provider's prior written consent. Provider may assign this Agreement in connection with a merger, acquisition, or sale of all or substantially all of its assets. Any Change of Control of Customer shall be deemed an assignment requiring Provider's prior written consent, not to be unreasonably withheld for non-competitive transactions. "Change of Control" means the acquisition of more than fifty percent (50%) of Customer's voting control or substantially all of its assets. Provider reserves the right to terminate with sixty (60) days' notice if Customer undergoes a Change of Control in favor of a direct competitor of Provider.
12.12 Relationship of the Parties
The parties are independent contractors. This Agreement does not create a partnership, franchise, joint venture, agency, fiduciary, or employment relationship between the parties.
12.13 No Third-Party Beneficiaries
There are no third-party beneficiaries to this Agreement. A person who is not a party to this Agreement has no right to enforce any of its terms.
12.14 Survival
The following Sections shall survive any termination or expiration of this Agreement: 1 (Definitions), 3 (Restrictions), 5 (Confidentiality/IP), 6 (Fees), 8.3 (Data Retention), 9 (Disclaimer), 10 (Indemnification), 11 (Liability), and 12 (Miscellaneous).
12.15 Notices
Legal notices required under this Agreement shall be delivered via email with a confirming copy sent via nationally recognized overnight courier or certified mail, return receipt requested. Notice shall be deemed given upon the earlier of (i) confirmed electronic receipt or (ii) one (1) business day after delivery by overnight courier. Notices to Provider shall be sent to support@complya.com with copy to the address on Provider's Order Form. Notices to Customer shall be sent to the address specified in the Order Form.
13. Provider Insurance
During the Term, Provider shall maintain at its own expense: (i) Commercial General Liability insurance; (ii) Professional Liability (Errors & Omissions) insurance; and (iii) Cyber Liability insurance, each with limits reasonable for the industry. Provider shall, upon written request, furnish Customer with certificates of insurance evidencing such coverage.
14. Usage Audit Rights
Provider shall have the right to monitor Customer's usage of the Services to ensure compliance with the Service Capacity and Authorized User limits. Once per year, Provider may audit Customer's user lists. If an audit reveals that Customer has exceeded its licensed capacity, Customer shall be invoiced for such excess usage at Provider's then-current rates. Customer shall also have the right, no more than once per calendar year, to submit a written security questionnaire of reasonable scope to Provider. Provider shall respond in good faith within thirty (30) business days. Provider will notify Customer within thirty (30) days of any material adverse change to its security program or insurance coverage.
15. Professional Services
Any professional services, including custom software development or bespoke data analysis, must be agreed upon in a separate Statement of Work (SOW) executed by both parties. Such services are governed by this Agreement unless the SOW explicitly states otherwise. Unless otherwise expressly stated in an applicable SOW, all work product developed by Provider under a SOW, including any modifications or enhancements to the Platform, shall be owned exclusively by Provider. Customer shall receive a limited license to use such work product as part of the Services during the term of this Agreement.