MASTER ENROLLMENT AUDIT AND REPORTING SERVICES AGREEMENT

Review, complete and sign on your phone. Nothing is sent to us when you sign — you keep your signed copy and send it yourself, whichever way suits your phone.

MASTER ENROLLMENT AUDIT AND REPORTING SERVICES AGREEMENT

HOW TO COMPLETE: replace every highlighted field with your information, mark the applicable boxes in Schedule A, then sign. Delete this line before signing.

Purpose and operating boundary
This Agreement is designed for agency-facing reconciliation and reporting. VitalBot may receive Client-supplied exports and use Approved Integrations, including HealthSherpa ONE, to retrieve authorized records through Client-authorized OAuth connections. Approved access includes secure storage and permitted renewal of delegated credentials for the selected audits. VitalBot does not mutate the authoritative source records it audits; it does maintain its own operational state and send approved reports. Platform approval, Client authorization, and the non-mutating limits below apply separately.
Agreement Date
Provider
VitalBot Software Solutions, LLC, a Florida limited liability company
Provider Address
Client
Client Address

This Master Enrollment Audit and Reporting Services Agreement (the “Agreement”) is entered into as of the Agreement Date by Provider and Client. Each may be a “Party” and together the “Parties.”

RECITALS

A. Provider Technology. Provider owns and operates the VitalBot platform and related confidential, proprietary, and patent-pending technology, including technology that is the subject of pending U.S. provisional patent applications.

B. Client Purpose. Client wishes to use selected agency-facing data-ingestion, normalization, reconciliation, anomaly-detection, payroll or commission-reconciliation, and reporting services for Client's internal review and lawful remediation, using Client-supplied datasets, Approved Integrations, or both.

C. Allocation of Roles. The Parties intend to define a reports-only software relationship, preserve Client’s exclusive responsibility for insurance activity and consumer consent, protect Provider Technology, and allocate data, security, compliance, and operational risk as stated below.

D. Approved Platform Access. Provider has obtained HealthSherpa approval to use HealthSherpa ONE and Client-authorized agency OAuth credentials for agency-facing audit services, subject to the applicable platform terms and approved capabilities. That approval does not by itself authorize access to any particular Client account, constitute platform endorsement or exclusivity, or guarantee continued access. Each Client connection requires the separate authorization and launch controls in this Agreement.

1. DEFINITIONS

1.1 Applicable Law. All laws, regulations, binding governmental requirements, orders, and contractual privacy or security obligations applicable to a Party’s performance, including applicable insurance licensing and appointment rules, 45 C.F.R. §§ 155.220 and 155.260, privacy and data-security laws, breach-notification laws, communications-consent laws, and the HIPAA Rules when applicable.

1.2 Authoritative Dataset. A dataset that Client designates for a reconciliation cycle as originating from an authoritative source, including a Marketplace, carrier, enrollment platform, third-party administrator, payroll source, or other independently maintained system, whether supplied by Client or retrieved through an Approved Integration. This designation does not warrant that a received dataset is complete, current, or error-free.

1.3 Authorized User. A person Client authorizes to use the Services for Client’s internal business purposes and for whose acts and omissions Client is responsible.

1.4 Client Data. All data, records, files, instructions, identifiers, mappings, recipients, credentials, templates, and other information submitted to, made available to, or processed by the Services on Client's behalf, including data retrieved through an Approved Integration and Delegated Credentials. Client Data includes Reports after delivery and any personal or Client-provided information embedded in Operational Data; it excludes Provider Technology, the structure of Operational Data, deidentified Usage Data, and Provider's own developer API keys and application secrets. Provider's developer keys and application secrets remain Provider Confidential Information.

1.5 Client Environment. All systems, accounts, devices, networks, email addresses, cloud locations, CRMs, dialers, files, records, Reports, recipients, vendors, and transmission methods not owned and controlled by Provider.

1.6 Consumer PII. Information within Client Data that identifies, or reasonably can be used to identify, a consumer, applicant, enrollee, or a member of that person's household, including name, contact information, date of birth, Social Security or taxpayer identification number, Marketplace, Exchange, application, or policy identifier, and eligibility, subsidy, premium, financial, or health information, together with a signed consumer attestation, recording, transcript, or comparable source artifact concerning that person. Marketplace PII is Consumer PII. Consumer PII does not include Producer Data.

1.7 Designated Client System. The customer-relationship management, dialer, or document system Client identifies in the Order Form as its system of record for consent evidence, signed attestations, recordings, transcripts, and other records Client must retain and produce. Client may designate any system meeting the requirements stated in the Order Form and Section 5.10. The designated system is licensed by Client directly from its own vendor under a separate agreement to which Provider is not a party; Provider does not resell, sponsor, supervise, or guarantee it, and no fee under this Agreement includes a fee for that system. If Client designates no system, Client remains the sole custodian of those records and Provider will not transfer custody of any record to any system.

1.8 Enrollment Ledger. A ledger or other record set maintained separately from the Authoritative Dataset and independently of Provider’s reconciliation process.

1.9 Finding. A discrepancy, attribution-change indicator, match result, severity classification, coverage or completeness status, or other output generated by the Services. A Finding is an investigative aid, not a final legal, insurance, regulatory, eligibility, coverage, compensation, or disciplinary determination.

1.10 Operational Data. Provider-generated processing records used to operate and evidence the Services, including pseudonymous application identifiers, agent attribution, rule codes, severity, limited factual details, processing states, recipient send fences, source-shape baselines, export manifests, non-secret connection and authorization metadata, timestamps, and audit logs. Provider owns the record structures and non-Client elements; Client retains its rights in Client Data embedded in them. Operational Data may remain personal or regulated information under Applicable Law even when it excludes direct identifiers. Agent attribution within Operational Data is Producer Data. Reusable access tokens, refresh tokens, and other authentication secrets are not Operational Data and are governed by Section 5.11.

1.11 Order Form. A signed ordering document or service schedule identifying selected Services, Approved Integrations, linked accounts, access scopes, retrieval frequency, configuration, data categories, retention, fees, term, senders, recipients, and any additional terms.

1.12 Producer Data. Information identifying a licensed insurance producer, agency, or Authorized User in a professional capacity, including name, National Producer Number, business email address, business telephone number, agency, upline, or downline affiliation, appointment and licensing status, roster status, and agent-of-record or writing-agent attribution. Producer Data also includes an identifier of a producer who is not Client's own personnel but who appears as agent of record, writing agent, or comparable attribution within Client's own book of business. The Parties acknowledge that Producer Data is professional identifying information rather than Consumer PII, and that it is necessary to the operation of the Services, which attribute Findings, route recipient-specific Reports, enforce delivery controls, and evidence processing by named producer and National Producer Number. Producer Data may nevertheless constitute personal information under Applicable Law, and it remains Client Data and Confidential Information under this Agreement.

1.13 Provider Technology. The Services, software, code, algorithms, schemas, workflows, state controls, safety guards, report formats, Documentation, inventions, know-how, trade secrets, and all related intellectual-property rights, including improvements, configurations, and derivative works created by or for Provider.

1.14 Report. A recipient-specific report, spreadsheet, exception list, payroll or commission-reconciliation output, Finding compilation, or other output generated by the Services.

1.15 Security Incident. A confirmed unauthorized acquisition of, access to, use of, alteration of, or disclosure of Client Data in a Provider-controlled system. Unsuccessful attempts and events confined to the Client Environment are not Security Incidents under this Agreement.

1.16 Services. The agency-facing software and data services selected in an Order Form. Services may include the technical authentication, authorized retrieval, and credential-management operations expressly permitted by Section 2.3. Services do not include insurance sales, solicitation, advice, administration, consumer outreach, substantive carrier or regulator communications, or other excluded regulated activity unless a later signed amendment expressly states otherwise after legal review.

1.17 Successful Completion. A reconciliation cycle has reached Successful Completion when it has not entered or remained in a held or error state, every intended recipient delivery has completed successfully, the applicable processing state has been committed, and no legal, preservation, or retention hold applies.

1.18 Ultra-Authorized Sender. An email address or other identity designated in the Order Form as authorized to trigger agency-wide processing, approve a protected action, or issue another high-impact instruction.

1.19 Usage Data. Technical and statistical information concerning Service use and performance that does not identify Client, an Authorized User, or an individual and cannot reasonably be used by Provider to reidentify an individual.

1.20 Source System. An externally maintained system of record or data service designated in the Order Form, including a Marketplace, Exchange, carrier, enrollment platform, or other authoritative source. HealthSherpa records accessed through HealthSherpa ONE may be a designated Source System.

1.21 Approved Integration. A Source System API or other platform-approved connection expressly selected in the Order Form, with its permitted capabilities, account population, fields, scopes, retrieval schedule, and safeguards identified. An integration is approved for use only while required platform permissions, Client authority, and Delegated Authorization remain effective.

1.22 Delegated Authorization. Client's documented, revocable authorization, given by a person with authority over the designated account, for Provider to use an Approved Integration on Client's behalf within the Order Form and the Source System's permitted scope. Required platform account-linking or consent steps are part of this authorization; Client authorization does not enlarge platform permissions.

1.23 Delegated Credentials. OAuth access tokens, refresh tokens, approved connection references, or other delegated authentication material issued or made available through a Source System's approved authorization process for a Client connection. Delegated Credentials do not include a user's account password, multifactor-authentication code, recovery code, or an unrelated agency's credentials.

2. AGREEMENT STRUCTURE AND SERVICES

2.1 Agreement Components and Priority. This Agreement governs every Order Form. If documents conflict, a signed Business Associate Addendum controls only for PHI; the Data Processing and Security Schedule controls only for Client Data; the applicable Order Form controls for the selected commercial configuration; and this Agreement otherwise controls. An Order Form overrides a numbered provision only if it expressly identifies that provision.

2.2 Selected Services Only. Provider will perform only the modules, sources, Approved Integrations, frequencies, destinations, volumes, retention settings, and support commitments selected in an Order Form. Code that exists but is not selected or enabled is not part of the Services. Platform approval for a broader capability does not make that capability part of the Services.

2.3 Approved API Access and Delegated Authorization. For an Approved Integration selected in a signed Order Form, Client authorizes Provider to connect to and authenticate against the designated Source System and retrieve Client-authorized records for the selected audit, reconciliation, and reporting Services. HealthSherpa ONE may be selected for approved on-exchange or off-exchange read access, as applicable; each capability must be separately identified. A separate amendment is not required solely to enable a conforming read-only Approved Integration under this Section. Export-based and hybrid intake remain available when selected.

2.3(a) Connection Approval. Before access begins, Provider will confirm its required platform-level permission for the selected capability, and Client will complete the approved account-linking process and identify the agency or agent accounts it is authorized to connect. The Order Form will record non-secret approval and connection references. Client will not send passwords, multifactor codes, recovery codes, or raw tokens by ordinary email, spreadsheet, or this Agreement. Credentials may be supplied only through the approved authorization process or an expressly approved secure credential-transfer mechanism.

2.3(b) Permitted Credential Operations. While the applicable Services and Delegated Authorization remain active, Client authorizes Provider to receive, securely store, use, renew, refresh, rotate, and, where supported, revoke Delegated Credentials, or to use a platform-managed connection performing those functions. These operations are limited to maintaining the approved connection and are subject to Section 5.11 and platform terms. Refresh does not authorize an increased scope or a new account. Recurring retrievals within the approved schedule are standing Client instructions and do not require a new email for each audit.

2.3(c) Client-Specific Scope. Provider may serve multiple agency clients through its approved developer integration, but each connection must have its own valid authorization for the designated account population. Provider will associate each connection and its credentials with the correct Client and use them only for that Client's selected Services. Provider will not use one Client's authorization to access another agency's records or to provide another client with that data. Technical visibility beyond the selected population is not permission to collect, retain, or disclose that additional data.

2.3(d) Access Restrictions and Changes. Both Parties will comply with the Source System's applicable access terms, purpose restrictions, rate limits, and approval conditions. Provider will not scrape a user interface, automate a user's login, bypass access controls, or access an unapproved Source System under this authorization. A new account, increased scope, or materially expanded purpose requires documented Client approval, any required platform consent or re-linking, and an updated Order Form before use. Source-record writes require the separate signed amendment described in Section 2.4.

2.4 Non-Mutating Source Relationship. Provider will not create, alter, submit, cancel, terminate, or delete enrollment, policy, attribution, payment, or other business records in a Source System, Enrollment Ledger, CRM, dialer, consent repository, or other Client system of record unless a later signed amendment expressly authorizes a reviewed write integration and all necessary permissions are obtained. Audit-only or read-scoped credentials will be used where the Source System supports them. If its available grant necessarily includes broader capabilities, the Order Form must disclose those capabilities and the application restrictions that prevent their use; the broader grant does not authorize writes. A production credential used solely to obtain an Enrollment Ledger will be read-scoped unless a later signed amendment expressly authorizes a reviewed write integration. Provider does write its own Operational Data, mailbox labels, processing states, and approved outbound communications. Permitted OAuth connection, refresh, rotation, and revocation operations are credential-management operations, not authorization to change source business records.

2.5 Safety Controls. Provider may hold, delay, suppress, withhold, reroute, retry, supersede, or refuse processing when a completeness, coverage, schema, date-window, quota, authorization, security, duplicate-delivery, pagination, credential-expiration, scope-change, or other safety control is triggered. A safety control's operation is not a Service failure. Release may require Client correction, reauthorization, a new dataset, or a cause-specific Provider action. Provider may change thresholds and guard logic to improve reliability, security, or compliance. Automated access does not require Provider to proceed when access authority or available source data is insufficient for the selected comparison.

2.6 Duplicate and Repeated Inputs. Client will not assume that a repeated or byte-identical input will be ignored. Re-submission may be part of a recovery workflow and may initiate a new processing attempt. Provider’s processing-state and recipient-specific controls are designed to reduce unintended repetition but do not guarantee that every duplicate input, Finding, Report, or communication will be detected or suppressed. Repeated or unchanged API responses may also be processed as part of scheduled, recovery, or verification workflows; polling does not itself guarantee that every repeated output is suppressed.

2.7 Third-Party Dependencies. The Services may depend on email, cloud, network, spreadsheet, storage, carrier, Marketplace, API, OAuth, and other third-party systems outside Provider's control. Provider is not responsible for their acts, omissions, outages, delays, schema changes, rate limits, data coverage, token-refresh failures, access restrictions, data quality, or discontinuation, but will use commercially reasonable efforts to mitigate material effects within Provider's control. Platform approval is not a warranty of future access, unchanged capabilities, or complete account coverage. This provision does not excuse Provider's breach of its express access or security obligations.

2.8 Service Changes. Provider may modify the Services for security, reliability, functionality, legal compliance, or product development. Provider will not materially reduce purchased core functionality during a paid term without reasonable notice and either a commercially reasonable substitute or a right to terminate the affected Service with a prorated refund of prepaid unused fees.

3. ACCESS, INSTRUCTIONS, AND PERMITTED USE

3.1 Limited Right. During the applicable Order Form term, Provider grants Client a limited, nonexclusive, nontransferable, nonsublicensable right for Authorized Users to use the Services and Documentation solely for Client’s internal enrollment-audit, payroll or commission-reconciliation, review, and Client-controlled remediation operations.

3.2 Authorized Electronic Instructions. Client designates its Ultra-Authorized Senders, administrators, approval-token recipients, and Report recipients in the Order Form. Client agrees that a message from a designated address, or use of a Provider-issued action token sent to a designated recipient, is an agreed security procedure and may be treated by Provider as Client’s authenticated instruction until Provider receives effective notice of compromise. Client is responsible for protecting those accounts and for instructions attributable to them, except to the extent directly caused by Provider’s breach of an express obligation. Approved configuration and an authenticated account-linking or reauthorization action by Client's designated administrator may also constitute Client instructions, but do not expand the Order Form or authorize excluded activities. Provider will retain non-secret evidence of the authorized connection and selected scope.

3.3 Accounts and Access. Client will use reasonable access controls, maintain accurate contact and recipient information, restrict credentials to assigned persons, promptly disable departed or unauthorized users, and notify Provider immediately of suspected compromise or unauthorized activity. Client is responsible for source accounts it controls; Provider is responsible for Delegated Credentials in Provider-controlled systems under Section 5.11. Each Party will promptly notify the other of a known revocation, compromise, or material permission change affecting an Approved Integration.

3.4 Restrictions. Client will not, and will not permit another person to: reverse engineer, decompile, disassemble, copy, derive, or attempt to discover Provider Technology; circumvent a safety, security, licensing, or usage control; use the Services to build, train, benchmark, validate, or improve a competing product; scrape or bulk extract Provider Technology; resell, sublicense, time-share, or expose the Services to a third party; remove proprietary notices; introduce malicious code; or use the Services unlawfully or outside an Order Form.

3.5 Suspension and Refusal. Provider may immediately suspend or refuse affected access, processing, output, or delivery when reasonably necessary to address suspected unlawful use, unlicensed activity, lack of consent or authority, inaccurate configuration, account compromise, security risk, expired or revoked Delegated Authorization, reduced access scope, third-party restriction, nonpayment, breach, risk to another customer, or material regulatory exposure. Provider will limit suspension to the extent practicable and restore Service when the risk is reasonably resolved.

3.6 Disconnection and Reauthorization. Client may withdraw Delegated Authorization at any time through available Source System revocation controls or by an authenticated instruction to Provider's designated administrator. Upon receiving that instruction or learning that authorization is no longer valid, Provider will cease initiating new retrievals and token refreshes under the affected grant, disable the affected connection, and apply Section 5.11. Provider may hold pending processing or delivery until the remaining authority is established and will not bypass revocation through another credential. Restoration requires valid authorization and any required platform approval or re-linking. Disconnection does not itself delete previously obtained data; its further processing and disposition remain subject to this Agreement, lawful Client instructions, Applicable Law, and applicable source-use restrictions. Withdrawal does not by itself cancel an Order Form or eliminate fees otherwise due.

4. CLIENT RESPONSIBILITIES AND REGULATED-ACTIVITY BOUNDARY

4.1 Licensing and Authority. Client represents, warrants, and covenants that Client and each Authorized User will obtain and continuously maintain every producer, agency, appointment, Marketplace, certification, registration, and other authority required for the jurisdictions and activities supported by the Services. Provider does not verify, supervise, sponsor, or guarantee Client’s licensing or compliance. Each use of the Services is Client’s continuing representation that required authority remains current.

4.2 Lawful Data and Marketplace Authority. Client represents, warrants, and covenants that it has every right, notice, consent, agreement, and lawful purpose required to collect, access, transmit, disclose, and instruct Provider to process Client Data. When Client Data includes Marketplace PII, Client will identify the governing Marketplace agreement and authorized purpose, ensure the governing agreement permits the processing, execute any required downstream terms with Provider before processing, and provide only data necessary for the selected Services. For an Approved Integration, Client also represents that the person granting access has authority over each linked agency or agent account and may authorize Provider's retrieval and processing for the selected purpose. Client will promptly report changes in account ownership, producer affiliation, appointments, permissions, or consumer authority that affect that access. Platform approval and Delegated Authorization do not replace required consumer consent, Marketplace downstream agreements, or other lawful authority.

4.3 Consumer Consent and Recordkeeping. Client alone will obtain, document, maintain, and produce all consumer consent, application-review confirmation, authorization to act, call recordings, transcripts, signed forms, and other records required by Applicable Law. When 45 C.F.R. § 155.220 applies, Client will preserve required consent and application-review documentation for at least ten years and produce it upon request. Provider is not Client’s consent system of record and may not be the sole custodian of any required record. Client will maintain an authoritative copy in its CRM, dialer, document system, or other controlled repository. An OAuth grant is not consumer-contact consent or authority for Provider to perform insurance activity.

4.4 Configuration and Recipient Accuracy. Client is responsible for the completeness, accuracy, timeliness, legality, and format of Client Data and for designating source ownership, population completeness, reporting period, field mappings, identifiers, thresholds, jurisdictions, recipients, and workflow rules. Client will verify every destination and recipient before launch and promptly correct known errors. For API access, Client will also identify and approve linked accounts, permitted record populations, relevant plan years, requested fields, retrieval frequency, and the persons authorized to grant or revoke access. Client is not responsible for defects in Provider's implementation merely because Client approved configuration.

4.5 Human Review and Decisions. Client will assign appropriately licensed and qualified personnel to review ambiguous matches and Findings, verify material results against source records, determine meaning and causation, and make every insurance, eligibility, coverage, licensing, compensation, employment, discipline, remediation, and consumer-impacting decision. Client will not take an adverse action solely on an automated Finding or treat a Finding as proof of fraud, wrongdoing, liability, or entitlement.

4.6 Reports-Only Role. Provider is a software and data-services company and does not act as an insurer, agency, producer, broker, consultant, counselor, administrator, adjuster, Marketplace, Exchange, regulator, attorney, accountant, payroll processor, fiduciary, or Client representative in insurance activity. Except for technical API and credential-management requests expressly permitted by Section 2.3, Client's licensed personnel alone will communicate with consumers, carriers, Marketplaces, Exchanges, regulators, competitors, and other third parties; correct records; obtain consent; file reports; and perform remediation. Delegated Authorization is limited technical access and is not a power of attorney or an appointment to conduct insurance activity.

4.7 Prohibited Client Use. Client will not use the Services or Reports to: conduct unlicensed insurance activity; contact a consumer without required consent; make deceptive, coercive, discriminatory, retaliatory, harassing, or threatening communications; demand records or payment under threat of reporting; coordinate exclusion or boycott of another person; access or alter a consumer application without authorization; auto-enroll a person into a suppression or other registry without that person’s documented choice; or violate antitrust, extortion, unfair-trade, privacy, communications, insurance, or consumer-protection law.

4.8 Immediate Compliance Remedies. Provider may immediately suspend any Client, user, module, destination, or workflow reasonably suspected of a prohibited use. Provider may terminate immediately for a willful, fraudulent, repeated, noncurable, or legally required compliance breach, or for conduct creating material risk to a consumer, Provider, a third party, or the Services. Other curable material breaches are governed by Section 7.4.

4.9 Client Environment. Client has sole responsibility for the lawful receipt, security, access, storage, transmission, disclosure, retention, and disposal of Client Data and Reports in the Client Environment. Client will limit access to persons with a need to know, maintain reasonable safeguards, preserve required records, revoke access promptly, and comply with applicable privacy, cybersecurity, breach-notification, insurance, Marketplace, and record-retention duties.

4.10 Evidence of Compliance. On reasonable request, Client will provide non-sensitive evidence of current licenses, authority, consent and application-review procedures, system-of-record custody, approved recipients, authority over linked accounts, non-secret connection approvals, and corrective action. Provider has no duty to monitor Client continuously and may suspend affected Services if requested evidence is not provided or reveals material risk.

5. DATA RIGHTS, RETENTION, AND SECURITY

5.1 Ownership and Processing License. As between the Parties, Client retains its rights in Client Data. Client grants Provider and approved subprocessors a limited right to retrieve through Approved Integrations, receive, host, copy, transmit, normalize, match, compare, analyze, display, report, retain, back up, and otherwise process Client Data to provide, secure, support, and document the Services; improve them only through deidentified Usage Data or as specifically authorized in the Order Form; comply with Client’s lawful instructions; prevent misuse; establish or defend legal claims; and comply with Applicable Law. Notwithstanding these general processing purposes, Delegated Credentials may be processed only as permitted by Sections 2.3 and 5.11.

5.2 Operational Data and Source-Export Disposal. Client authorizes Provider to create, retain, and back up Operational Data as described in this Agreement and the Order Form. For a source export received by email, after a reconciliation cycle reaches Successful Completion, Provider will submit the source export message to the receiving mail system's permanent-delete operation and will record that the mail system accepted the deletion request. A message the mail system deletes by that operation is not user-recoverable from the receiving mailbox. Where the mail system does not accept the deletion request, the message remains subject to disposal on a subsequent cycle, and Provider may retain it until that disposal occurs. A cycle that is held, terminates in error, or has an unsuccessful intended-recipient delivery does not reach Successful Completion, and its source message may be retained pending resolution so that processing or delivery can resume. A legal, preservation, or retention hold suspends disposal. Provider does not intentionally include source export messages or their attachments in its managed off-box backup archives. Deletion of a source message does not delete Operational Data derived from it, or copies retained by Client, the sender, a recipient, or a third-party service outside Provider's control. Provider does not warrant that a third-party email provider, legal-preservation system, sender, recipient, or other person has not retained a separate copy outside Provider's control. This source-message rule does not govern API response retention or the credential lifecycle; those are addressed in Sections 5.11 and 5.12.

5.3 Data Minimization. Client will not submit passwords, full Social Security numbers, payment-card data, or data not reasonably necessary for the selected Services unless the Order Form expressly identifies the data and safeguards. Provider may reject or delete unnecessary data and may require Client to provide a reduced field set. This restriction applies to Consumer PII and to data outside the selected Services. It does not restrict Producer Data, which is necessary to the Services. Client will provide accurate and current producer names, National Producer Numbers, business email addresses, and roster status for each Authorized User and for each producer whose business is within the selected scope, and Client acknowledges that an incomplete or inaccurate producer roster degrades attribution accuracy and may cause Findings to be raised against business the producer in fact holds. Delegated Credentials received through the approved process are permitted subject to Section 5.11; this does not permit sharing Source System account passwords. Provider will limit API requests and retained fields to those needed and authorized for the selected Services, subject to the platform's available controls.

5.4 Usage Data. Provider may create and use Usage Data for security, capacity planning, support, analytics, and service improvement. Provider will not sell Client Data, use Client Data for targeted advertising, or attempt to reidentify deidentified Usage Data.

5.5 Safeguards. Each Party will maintain reasonable administrative, technical, and physical safeguards appropriate to its role and the sensitivity of data in its possession or control. Provider’s commitments are limited to those stated in this Agreement, the Data Processing and Security Schedule, and the applicable Order Form; no marketing statement or questionnaire response expands them unless signed by an authorized Provider representative.

5.6 Security Incident Notice. Provider will notify Client without unreasonable delay and, where Florida law governing a third-party agent applies, no later than ten days after Provider determines that a Security Incident occurred. Provider will provide information reasonably available for Client’s legal assessment and cooperate reasonably at Client’s expense except to the extent the incident was caused by Provider’s breach. Notice is not an admission of fault.

5.7 HIPAA. The Parties do not assume that HIPAA applies merely because data concerns insurance or health coverage. Client will not submit, or authorize Provider to retrieve, PHI for which Provider would be a business associate or subcontractor business associate unless the Parties first sign a separate Business Associate Addendum and activate it in the Order Form. If no BAA is signed, Client represents that Provider is not acting in that role for the submitted or retrieved data.

5.8 Legal Requests and Preservation. Provider may preserve or disclose Client Data when required by law, legal process, litigation hold, or a reasonable need to establish or defend legal claims. Unless prohibited, Provider will give Client reasonable notice and disclose only what Provider reasonably believes is required.

5.9 Return and Deletion. After termination and payment of all undisputed amounts, Provider will make a commercially reasonable export of available Client Data if Client requests it within thirty days. Provider may thereafter delete or deidentify Client Data from active systems under its retention practices, while retaining protected copies in backups, security records, legal holds, Operational Data, and compliance archives for the purposes stated in this Agreement. Return or deletion of Consumer PII does not require deletion of Producer Data, or of the Operational Data in which producer attribution is embedded, which Provider may retain for the purposes stated in this Agreement. Credential disablement and disposition under Section 5.11 are not conditioned on payment, an export request, or expiration of this thirty-day period; reusable credentials are not retained as Operational Data.

5.10 Custody Transfer to the Designated Client System. Where the Order Form enables custody transfer, Provider will transmit a signed consumer attestation or comparable consent record to the Designated Client System and will treat custody as transferred only upon a confirmed accepted result from that system. Provider will not delete its copy of such a record before that confirmation. Client is responsible for retaining the record in the Designated Client System for the period required by Applicable Law, including the ten-year period under 45 C.F.R. § 155.220(j)(2)(ii) where it applies, and for producing it on request. Provider is not the system of record for those materials and may not be the sole custodian of any record Client must produce. If custody transfer is not enabled in the Order Form, or the Designated Client System does not confirm acceptance, Provider will retain the record and Client remains responsible for maintaining an authoritative copy.

5.11 Delegated Credential Security and Lifecycle. Provider will use Delegated Credentials only to establish, maintain, secure, or end the Approved Integration while the applicable authority remains effective. Provider will protect tokens, refresh tokens, and developer secrets in transit and at rest using encryption and restrict access to authorized personnel, processes, and approved subprocessors with a need to perform those functions. Provider will not expose reusable secrets in Reports, routine logs, source code, client-facing pages, ordinary email, or AI-tool prompts. Non-secret account identifiers, grant scope, timestamps, and connection-status evidence may be retained as Operational Data.

5.11(a) Revocation and Removal. Following revocation, termination, or loss of authority, Provider will promptly remove usable Delegated Credentials from active stores and request revocation or invalidation through available Source System mechanisms. If remote revocation is unavailable to Provider, it will stop local use and inform Client of any Client action needed at the Source System. Protected backup copies may remain only for the documented backup cycle or a legally required preservation period; they must not be used to restore access without new valid authorization. Retention for evidence or preservation does not authorize further API access. Provider will retain a non-secret record of the disconnection action.

5.12 API-Retrieved Data. Before an Approved Integration is enabled, the Order Form will identify the selected data categories, permitted fields, processing frequency, and retention for raw API responses and any normalized or historical records, including whether raw responses are processed transiently or retained for a stated period. Those settings remain subject to applicable platform retention and use restrictions. API approval is not permission to warehouse all accessible records. Source-message deletion under Section 5.2 does not delete the Source System's records, terminate a valid OAuth connection, or erase Operational Data. Preservation requirements and lawful deletion instructions remain applicable to API-derived Client Data. A valid token or successful API response does not itself establish a complete population or make Provider the Client's system of record.

6. CONFIDENTIALITY AND INTELLECTUAL PROPERTY

6.1 Confidential Information. Each Party will use the other Party’s nonpublic information only for this relationship, protect it with at least reasonable care, and disclose it only to persons who need to know and are bound by protective obligations. Provider’s Confidential Information includes Provider Technology, patent materials, source code, algorithms, schemas, security information, pricing, product plans, and technical demonstrations. Client’s Confidential Information includes Client Data and nonpublic business records.

6.2 Exclusions and Required Disclosure. Confidential Information excludes information the receiving Party can document was lawfully known without restriction, became public without breach, was lawfully received without duty, or was independently developed without use of the disclosure. A compelled receiving Party will, if legally permitted, provide prompt notice, disclose only what is required, and assist in seeking protection at the disclosing Party’s expense.

6.3 Duration and Disposition. Confidentiality obligations continue during the Agreement and for five years afterward; trade secrets remain protected while they qualify as trade secrets, and personal or regulated data remains protected for the period required by law. Return or destruction is subject to legal retention, backups, security records, and archives that remain protected.

6.4 Provider Ownership and Custom Work. Provider and its licensors retain all rights in Provider Technology. Any configuration, integration, report format, improvement, custom development, or derivative work created by or for Provider in connection with the Services is Provider Technology, excluding Client’s preexisting materials and Client Data. Client receives only the limited use right expressly stated in this Agreement.

6.5 Feedback. Client grants Provider a perpetual, irrevocable, worldwide, royalty-free right to use and incorporate voluntary feedback without identifying Client or disclosing Client Data. Client is not required to provide feedback.

6.6 Equitable Relief and Publicity. Unauthorized use or disclosure of Confidential Information or Provider Technology may cause irreparable harm; the injured Party may seek appropriate equitable relief without waiving other remedies. Neither Party may publicly identify the relationship or use the other Party’s name, marks, or logo without prior written consent, except as required by law.

7. FEES, TERM, SUSPENSION, AND TERMINATION

7.1 Fees and Taxes. Client will pay the fees, overages, expenses, and taxes stated in each Order Form. Fees are noncancelable and nonrefundable except as expressly stated. Client is responsible for transaction taxes other than taxes based on Provider’s net income.

7.2 Invoices. Undisputed amounts are due within thirty days after invoice. Client must provide good-faith written detail of an invoice dispute within fifteen days and timely pay the undisputed portion. Overdue amounts may accrue interest at 1.5% per month or the maximum lawful rate, whichever is lower, plus reasonable collection costs.

7.3 Term and Renewal. This Agreement begins on the Agreement Date and continues while an Order Form remains active. Each Order Form states its term and renewal. Provider may update renewal pricing on at least thirty days’ notice before a renewal term unless the Order Form states otherwise.

7.4 Termination for Cause. Either Party may terminate an affected Order Form for a material breach not cured within thirty days after written notice. Provider may use a ten-day cure period for nonpayment. A Party may terminate immediately for a breach incapable of cure, insolvency, cessation of business, or when continued performance would violate law. Provider’s additional immediate compliance rights are in Section 4.8.

7.5 Effect of Termination. On termination, Client’s access ends; Provider may disable instructions and delivery; accrued fees become due; and Sections intended by their nature to survive will survive. Except for a Provider breach giving rise to an express refund remedy, termination does not relieve Client of committed fees. Termination of an Approved Integration also ends its standing retrieval instructions; Provider will disable that connection, cease token refreshes, and handle its Delegated Credentials under Section 5.11.

8. WARRANTIES, DISCLAIMERS, AND OPERATIONAL LIMITATIONS

8.1 Authority. Each Party represents that it has authority to enter into this Agreement and that its signer may bind it.

8.2 Limited Provider Warranty. Provider warrants that it will perform the Services in a professional and workmanlike manner. Client’s exclusive remedy is re-performance; if Provider cannot cure a material nonconformity within a reasonable time, Client may terminate the affected Service and receive a prorated refund of prepaid fees for the unused period.

8.3 Decision Support; Errors. Findings may include false positives, false negatives, incomplete or delayed data, ambiguous matches, stale information, and errors caused by source systems, configuration, timing, schema changes, incomplete populations, or third parties. Provider does not guarantee detection of every discrepancy, attribution change, commission event, compliance issue, unauthorized action, or missing record. API data may be partial, delayed, unavailable for some records, limited to the linked account's visibility, or affected by changed scopes and carrier coverage. A failed request, empty response, or missing field does not, by itself, establish coverage termination, lost attribution, or wrongdoing.

8.4 No Professional or Regulatory Advice. The Services do not provide legal, regulatory, tax, accounting, payroll, eligibility, coverage, licensing, employment, cybersecurity, privacy, or insurance advice and do not ensure compliance with a law, license, appointment, carrier rule, Marketplace agreement, privacy duty, or security standard.

8.5 No Outcome or Availability Guarantee. Provider does not guarantee recovery of commissions, restoration of agent-of-record status, correction by a carrier or Marketplace, consumer response, remediation completion, uninterrupted operation, data availability, delivery, acceptance by a regulator, or any financial or business outcome. Safety holds, withheld routing, planned maintenance, third-party outages, and recovery processing are not breaches. Unless an Order Form expressly provides otherwise, scheduled or repeated API retrieval is not a warranty of continuous monitoring, real-time updates, or access to every record or field.

8.6 General Disclaimer. EXCEPT FOR THE EXPRESS WARRANTY IN SECTION 8.2, THE SERVICES, DOCUMENTATION, REPORTS, AND FINDINGS ARE PROVIDED “AS IS” AND “AS AVAILABLE.” TO THE MAXIMUM EXTENT PERMITTED BY LAW, PROVIDER DISCLAIMS IMPLIED WARRANTIES, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, NON-INFRINGEMENT, ACCURACY, AND WARRANTIES ARISING FROM COURSE OF DEALING OR USAGE OF TRADE.

9. INDEMNIFICATIONimportant

9.1 Client Indemnity. Client will defend, indemnify, and hold harmless Provider, its affiliates, licensors, subprocessors, members, managers, officers, employees, and personnel from third-party claims, investigations, demands, losses, liabilities, judgments, settlements, penalties to the extent legally indemnifiable, and reasonable attorneys’ fees arising from: Client Data or instructions; lack of authority or consent; Client’s licensing, insurance activity, consumer contact, communications, payroll or employment decisions, remediation, or regulatory duties; Client’s breach of Sections 3, 4, 5, or 6; an adverse action based on a Finding; prohibited or unauthorized use; or an event in the Client Environment.

9.2 Provider IP Indemnity. Provider will defend Client against a third-party claim that Client’s authorized use of the unmodified Services directly infringes a United States patent, copyright, or trade secret and will pay finally awarded damages or a settlement approved by Provider. Provider has no obligation for claims caused by Client Data, instructions, combination with unapproved items, unauthorized use, modification by another person, continued use after notice, or compliance with Client specifications.

9.3 IP Remedies. If an IP claim is likely, Provider may procure continued use, modify or replace the affected Service with materially equivalent functionality, or terminate the affected Service and refund prepaid fees for its unused period. Sections 9.2 and 9.3 state Client’s exclusive IP-infringement remedy and remain subject to Section 10.

9.4 Procedure. The indemnified Party will promptly notify the indemnifying Party, provide reasonable cooperation at the indemnifying Party’s expense, and allow control of the defense and settlement. Delay relieves obligations only to the extent materially prejudicial. No settlement may admit fault by, impose nonmonetary obligations on, or fail to fully release the indemnified Party without its written consent.

10. LIMITATION OF LIABILITYimportant

10.1 Excluded Damages. TO THE MAXIMUM EXTENT PERMITTED BY LAW, PROVIDER AND ITS PERSONNEL WILL NOT BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, PUNITIVE, OR CONSEQUENTIAL DAMAGES; LOST PROFITS, REVENUE, GOODWILL, BUSINESS OPPORTUNITY, COMMISSIONS, OR DATA; OR THE COST OF SUBSTITUTE SERVICES, EVEN IF ADVISED OF THE POSSIBILITY.

10.2 Provider Cap. EXCEPT FOR LIABILITY THAT LAW PROHIBITS FROM LIMITING, PROVIDER’S TOTAL AGGREGATE LIABILITY ARISING OUT OF THIS AGREEMENT WILL NOT EXCEED THE FEES PAID OR PAYABLE FOR THE AFFECTED SERVICES DURING THE TWELVE MONTHS BEFORE THE EVENT FIRST GIVING RISE TO LIABILITY. PROVIDER’S AGGREGATE LIABILITY FOR ITS BREACH OF CONFIDENTIALITY, A PROVIDER-CONTROLLED SECURITY INCIDENT CAUSED BY BREACH OF AN EXPRESS SECURITY OBLIGATION, OR A SIGNED BAA WILL NOT EXCEED TWO TIMES THAT AMOUNT. PROVIDER’S IP INDEMNITY IS SUBJECT TO THE GENERAL CAP.

10.3 Client Exclusions from Cap. Any cap otherwise applicable to Client does not limit Client’s payment obligations; breach of Sections 3.4, 4.2, 4.3, 4.7, 5.3, or 6; infringement or misappropriation of Provider Technology; Client’s indemnity obligations; fraud, gross negligence, or willful misconduct; or liability that law prohibits from limiting.

10.4 No Personal Liability. Client’s sole recourse for a Provider obligation is against Provider as an entity. No member, manager, officer, employee, contractor, inventor, or affiliate of Provider has personal liability arising from the Services or this Agreement, except for that person’s own fraud or willful misconduct to the extent liability cannot lawfully be disclaimed.

10.5 Allocation of Risk. The fees and remedies reflect this allocation of risk. The exclusions and limits apply regardless of legal theory, to the maximum lawful extent, and even if a limited remedy fails of its essential purpose.

11. DISPUTE RESOLUTION; FLORIDA LAW AND FORUMimportant

11.1 Good-Faith Resolution. Before filing suit, a Party will provide written notice describing the dispute and requested relief. Authorized representatives will confer in good faith. This requirement does not prevent urgent equitable relief, preserve a limitations period, collect undisputed amounts, or respond to an active Security Incident.

11.2 Mediation. If negotiation fails, either Party may demand confidential, nonbinding mediation in Broward County, Florida before a mutually selected Florida Supreme Court certified circuit mediator. The Parties will share mediator fees equally and bear their own other costs.

11.3 Florida Law and Exclusive Forum. Florida substantive law governs without regard to conflicts principles. Every action arising from this Agreement or the Services must be brought exclusively in the state courts in Broward County, Florida or, if federal jurisdiction exists, the United States District Court for the Southern District of Florida. Each Party submits to those courts and waives objections based on venue or inconvenient forum.

11.4 Jury-Trial Waiver. TO THE MAXIMUM EXTENT PERMITTED BY LAW, EACH PARTY KNOWINGLY, VOLUNTARILY, AND IRREVOCABLY WAIVES TRIAL BY JURY IN EVERY ACTION ARISING OUT OF OR RELATING TO THIS AGREEMENT, THE SERVICES, OR THE PARTIES’ RELATIONSHIP. EACH PARTY ACKNOWLEDGES THE OPPORTUNITY TO CONSULT INDEPENDENT COUNSEL.

11.5 Time to Bring Claims. Except for payment, indemnity, confidentiality, intellectual-property, fraud, or claims that cannot lawfully be shortened, no action may be brought more than one year after the claimant knew or reasonably should have known of the facts giving rise to it.

11.6 Fees and Equitable Relief. The substantially prevailing Party in an action to enforce this Agreement may recover reasonable attorneys’ fees and taxable costs, including on appeal. Either Party may seek equitable relief for misuse of Confidential Information, Provider Technology, security credentials, or access controls.

12. GENERAL TERMS

12.1 Independent Contractors. The Parties are independent contractors. This Agreement creates no partnership, joint venture, agency, fiduciary, employment, franchise, insurance, or exclusivity relationship, and neither Party may bind the other.

12.2 Assignment. Client may not assign this Agreement without Provider’s prior written consent. Provider may assign it to an affiliate or in connection with a merger, financing, reorganization, sale of equity, assets, business, or control, provided the assignee assumes Provider’s obligations. An impermissible assignment is void.

12.3 Subprocessors. Provider may use subprocessors and remains responsible for their performance to the extent stated in this Agreement. Client authorizes subprocessors used for email, infrastructure, backup, support, and other Service functions, subject to appropriate confidentiality and data-protection obligations.

12.4 Force Majeure. Neither Party is liable for delay or failure caused by events beyond its reasonable control, including outages, cyberattacks, disasters, governmental action, labor events, telecommunications failure, or third-party platform restrictions, excluding payment obligations. The affected Party will use reasonable efforts to mitigate.

12.5 Notices. Legal notices must be in writing and delivered by personal delivery, nationally recognized overnight courier, certified U.S. mail, or email with confirmed receipt to the contacts in the Order Form. Operational notices may be sent to designated administrators through email or the Services.

12.6 Severability; Waiver. An invalid provision will be enforced to the maximum lawful extent or severed, and the remainder will continue. A waiver must be written and signed; delay or a waiver on one occasion is not a continuing waiver.

12.7 No Third-Party Beneficiaries. Except for indemnified persons expressly identified in Section 9.1, this Agreement benefits only the Parties and permitted successors and assigns.

12.8 Entire Agreement; Amendments. This Agreement, signed Order Forms, and incorporated schedules are the entire agreement concerning the Services and supersede prior proposals, demonstrations, statements, and understandings. An amendment must be a writing signed by authorized representatives of both Parties. Client purchase orders, portals, policies, or questionnaires do not modify this Agreement.

12.9 Electronic Signatures and Counterparts. The Parties agree to conduct this transaction electronically. Electronic records, signatures, and counterparts have the same effect as originals, and a reproducible electronic copy is an original for evidentiary purposes.

SIGNATURES

IN WITNESS WHEREOF, the Parties have executed this Agreement through authorized representatives.

PROVIDER
CLIENT
VitalBot Software Solutions, LLC
By:
By:
Name: Alec Kruki Title: Chief Executive Officer
Name: Title:
Date:
Date:

SCHEDULE A - ORDER FORM AND LAUNCH AUTHORIZATION

Complete and sign before production launch

Order Form Date
Initial Term
Renewal
Target Launch
Client Administrator
Provider Administrator

A-1. Selected Services

Select
Module
Included scope / configuration
Dataset intake
Approved API audit integration
Ledger interface
Normalization and matching
Enrollment discrepancy audit
Attribution analysis
Completeness and coverage controls
Recipient-specific reports
Payroll or commission reconciliation
Custom implementation

A-2. Data Sources, Senders, and Recipients

Authoritative source(s)
Enrollment Ledger
Ultra-Authorized Senders
Regular Authorized Senders
Approval-token recipients
Agent Report recipients
Administrator recipients
Acquisition mode
[Exports only / Approved Integration / hybrid. For API access, complete A-2.1; no account passwords or raw tokens in this form.]

A-2.1. Approved Integration Record

Complete one record for each Approved Integration; omit if exports-only. Identify account and approval references, never secret token values. This record authorizes only the read/reconcile/report scope stated below, not enrollment, payment, attribution changes, or other source-record writes.

Integration / capability
[HealthSherpa ONE / other source; on-exchange policy-status readback / off-exchange read access / other approved audit capability. Identify approved API/interface.]
Platform permission
[Approval date/reference, approved audit purpose, applicable terms and version, restrictions on delegated agency access and credential storage. Confirm each selected capability.]
Client accounts and linking authority
[Agency/account identifiers and relevant NPNs; Client administrator; authorized account-linking person and basis of authority. No raw credentials.]
Permitted access scope
[OAuth scopes, allowed read operations, record population, plan years, fields, and filters. Identify any necessarily broader grant and the application controls preventing write use.]
Linking and credential management
[Source-approved linking/secure transfer method, connection reference, token custodian, refresh/rotation method, and re-linking requirements. No token or key values.]
Retrieval schedule and limits
[Standing retrieval frequency, operating window/time zone, request limits, retry/backoff behavior, and any Client-triggered routes. No real-time guarantee unless expressly stated.]
Revocation and access changes
[Client and Provider contacts; source-side revocation or disconnect method; local disablement test; procedure for account, producer, or scope changes.]
Launch verification
[Date and approving representatives; verified account scope, permitted data, secure token handling, non-mutating behavior, failure handling, retention settings, and disconnect test. A-6 governs activation.]

A-3. Data Categories, Retention, and Security

Data categories
Prohibited data
[Account passwords, multifactor/recovery codes, full SSNs, payment cards, other. Delegated Credentials only through the approved secure process.]
Source-message retention
Email source exports only: Permanent deletion after Successful Completion (as defined in § 1.17) — Provider uses the mail system's permanent-delete operation and records that the mail system accepted the deletion request. Retained pending resolution where a cycle is held, errors, or any recipient delivery fails, or where the mail system does not accept the deletion request. Legal/preservation hold suspends disposal. Operational Data derived from the export is retained separately per Schedule B. API responses and Delegated Credentials follow Sections 5.11 and 5.12.
API response and derived-record retention
[Raw responses: transient processing or stated retention period; normalized/history records: fields and period; backup period and legal-hold handling. Subject to source-use restrictions; Section 5.12.]
Delegated Credential safeguards and lifecycle
[Approved secret-storage service/location, authorized access roles, encryption, rotation/revocation process, and backup expiry. No secret values. Section 5.11 applies regardless of general data-retention periods.]
Operational Data retention
Report retention
Client system of record
Designated Client System — vendor
— product / module
— Client administrator for that system
— custody transfer enabled
— transfer method
[Approved endpoint, secure file transfer, or other method, identified and tested before launch. Provider transfers custody only on a confirmed accepted result — Section 5.10.]
— Client retention period in that system
— separate contract confirmed
[Confirm Client licenses this system directly from its vendor. Provider does not resell, sponsor, or guarantee it, and no fee here includes a fee for it. If left blank, Client remains sole custodian — Section 5.10.]
HIPAA status
Marketplace agreement

A-4. Required Client Attestations

Select
Attestation
Client confirmation
LICENSING
Client and all Authorized Users maintain every required license, appointment, certification, registration, and authority.
DATA AUTHORITY
Client has lawful authority, notices, agreements, and consent for every selected data category and purpose, including Provider retrieval through each approved linked account.
DELEGATED AUTHORIZATION
Client authorizes approved token storage, refresh, and scheduled retrieval; confirms the linking person's account authority; and understands that OAuth access does not authorize source-record writes, consumer contact, or access to another agency's records.
CONSENT RECORDS
Client will obtain, maintain, and produce required consumer consent and application-review records, including ten-year retention where 45 C.F.R. § 155.220 applies.
SYSTEM OF RECORD
Client will keep authoritative copies of signed forms, recordings, transcripts, and attestations; Provider will not be the sole custodian.
REPORTS-ONLY MODEL
Client accepts the regulated-activity boundary and will not represent that Provider performs insurance or governmental functions.
HUMAN REVIEW
Licensed personnel will verify Findings and make every insurance, employment, compensation, remediation, and consumer-impacting decision.
AUTHORIZED SENDERS
Client accepts responsibility for the designated sender accounts, action tokens, recipients, and destinations.
PROHIBITED USE
Client will not use the Services for unlicensed, deceptive, coercive, discriminatory, threatening, unauthorized, or otherwise unlawful conduct.
CLIENT ENVIRONMENT
Client accepts responsibility for Client Data and Reports after delivery to Client-controlled systems or recipients.

A-5. Fees and Service Levels

Implementation fee
$
Recurring fee
$
Included volume
Overage fees
$
Support hours
Availability commitment
Special terms

A-6. Launch Approval and Acceptance

The Parties will attach or approve the field map, identifier rules, completeness and coverage rules, thresholds, jurisdiction list, recipient matrix, retention settings, and escalation contacts before production launch. Client confirms that all selected addresses and high-impact authorities are accurate. Before enabling any Approved Integration, the Parties will also complete its A-2.1 record, confirm platform permission and Client account authority, approve the data and credential retention settings, and test account scoping, non-mutating access, error handling, secure credential handling, and disconnection. Platform approval alone does not activate a Service. No Approved Integration will be enabled until these controls and launch authorization are complete.

PROVIDER
CLIENT
VitalBot Software Solutions, LLC
By:
By:
Name: Alec Kruki Title: Chief Executive Officer
Name: Title:
Date:
Date:

SCHEDULE B - DATA PROCESSING AND SECURITY

Applies whenever Provider processes Client Data

B-1. Processing Instructions and Roles

B-1.1 Instructions. Provider will process Client Data only to perform, secure, support, and document the Services; improve them only through deidentified Usage Data or as specifically authorized in the Order Form; follow Client’s lawful documented instructions; prevent misuse; establish or defend claims; or comply with law. This Agreement, the Order Form, approved configuration, support requests, and authenticated Authorized User actions are documented instructions. For an Approved Integration, the completed A-2.1 record and authenticated account-linking or reauthorization actions document the approved retrieval and credential-management instructions, subject to Sections 2.3, 3.6, and 5.11.

B-1.2 Purpose and Duration. The Order Form will identify the data categories, purpose, systems, and operational retention. Client determines the lawful basis and required record-retention period. Provider is a processor or service provider only to the extent Applicable Law assigns that role; Client remains responsible for controller or business obligations.

B-1.3 Confidentiality. Provider will limit Client Data access to persons and subprocessors with a legitimate need and subject them to appropriate confidentiality obligations.

B-2. Provider Safeguards and Data Boundaries

• Provider will maintain commercially reasonable access control, authentication, logging, backup, recovery, change-management, incident-response, and secure-disposal practices appropriate to Provider’s size, role, and the data identified in the Order Form.

• When configured for a Google Sheets ledger, Provider will use a production credential that is not authorized to write to that ledger unless a later signed amendment expressly changes the integration.

• Provider may connect to a designated Source System only through an Approved Integration under Section 2.3, within platform permission and valid Client-specific Delegated Authorization. Provider will associate each grant with the correct Client account and will not use it to access or disclose another agency's records. Non-mutating access restrictions in Section 2.4 remain in effect.

• Provider may parse source attachments and API responses in memory without creating a local working copy. Email source-message retention and disposal are governed by Section 5.2, including its Successful Completion, failed-delivery, safety-control, error, and preservation exceptions. API-derived data retention and credential handling are governed by Sections 5.11 and 5.12 and the completed Order Form.

• Provider may retain pseudonymous Operational Data that excludes specified direct identifiers but may remain personal or regulated information when linkable to other records.

• Provider will protect reusable Delegated Credentials and its developer API secrets with encryption in transit and at rest, need-to-know access, and exclusion from routine logs, Reports, source code, client-facing pages, ordinary email, and AI-tool prompts. Credential backups, revocation, removal, and restoration are subject to Section 5.11; general Operational Data retention does not authorize continued use of a revoked grant.

• Provider may maintain encrypted off-box backups of selected configuration, databases, and records. A backup or retention setting is not a warranty of uninterrupted availability or immutability unless expressly stated in the Order Form.

• Provider may replace a safeguard with a materially equivalent or stronger control and may withhold sensitive architecture details that would create security or trade-secret risk.

B-3. Client Security and Cooperation

B-3.1 Client Controls. Client will secure the Client Environment, sender accounts, recipients, devices, exports, credentials, records, backups, and vendors; use least privilege; promptly revoke access; and notify Provider immediately of compromise or material change affecting processing. Client will complete the approved linking process, promptly notify Provider of revoked or changed permissions, and use available source-side disconnect controls when authority ends. Provider remains responsible for credentials in Provider-controlled systems under Section 5.11.

B-3.2 Data Reduction. Client will provide only fields reasonably necessary for the selected Services and will not submit prohibited data. Provider may require a revised export or mapping before processing. For API sources, the Parties will approve necessary request fields, response-field handling, and retention before launch; technical availability does not expand the permitted data purpose.

B-3.3 Incidents and Notices. The Parties will coordinate legally required notices. Client is responsible for notices arising from the Client Environment. Provider is responsible for notices expressly assigned to it by law or this Agreement. Neither Party will name the other publicly without prior consultation unless law requires otherwise.

B-4. Subprocessors, Requests, and Audits

B-4.1 Subprocessors. Client authorizes Provider’s use of subprocessors for email, infrastructure, storage, approved credential management, backup, support, and related Service functions. Provider will impose appropriate confidentiality and data-protection obligations. On reasonable request, Provider will identify material subprocessors used for Client Data. Delegated Credentials may be provided to a subprocessor only as necessary for the Approved Integration and only where the Source System permits that use. Provider remains responsible for its express credential-protection obligations.

B-4.2 Rights Requests. Taking into account the nature of processing and information available, Provider will reasonably assist Client with legally required data-subject requests at Client’s expense. Client is responsible for verifying identity, determining applicability, and responding.

B-4.3 Review. No more than once annually and additionally after a material Security Incident, Provider will reasonably answer a proportionate written security questionnaire or provide current documentation, subject to confidentiality and protection of other customers and security-sensitive information. Client may not scan, penetrate, load test, or test Provider systems without a separate signed test plan.

B-5.1 Disposition. Following termination and the export period, Provider may delete or deidentify Client Data from active systems under its documented retention practices. Provider may retain protected copies in backups, Operational Data, security records, legal holds, and compliance archives for the limited purposes stated in the Agreement. Delegated Credential disablement and disposition are governed by Section 5.11, not the general export period or Operational Data retention rules. A preserved or restored backup may not reactivate a revoked connection without new valid authorization.

B-5.2 No Sole Custody. Client will not rely on Provider as the sole custodian of consent evidence, signed attestations, recordings, transcripts, source exports, or records Client must produce to a regulator, carrier, Marketplace, consumer, employee, or court.

HIPAA condition
If Provider will create, receive, maintain, or transmit PHI as Client’s business associate or subcontractor business associate, the Parties must sign a separate Business Associate Addendum before that processing begins. The Agreement and this Schedule do not activate a BAA by themselves.

Sign

Before you sign. This is the whole agreement, including both schedules. You can save or print it and review it on a computer first, and you can come back — anything you have typed is kept on this device until you clear it.

Typing your name and selecting Sign applies your electronic signature to this completed agreement. This page does not verify your identity, notarize your signature, or apply a cryptographic seal. Selecting Sign does not send anything to us.

If a button below does nothing, it is this preview blocking it — not your phone, and nothing you have typed is lost. Some mail apps open an attachment in a viewer that cannot save files. Any one of these still works: