Terms
Master Service Agreement
Between: CommandKey AI, LLC, an Alabama limited liability company ("Provider," "we," "us"), and [Client Legal Name], a business entity ("Client," "you"). Each is a "Party."
Effective Date: [Date] | Version: 6.1, dated September 29, 2026
1. Services, Order Forms, and Order of Precedence
Provider supplies planning documents, self-install release packages, configuration materials, documentation, and ongoing release support for a client-controlled AI system built to run with Anthropic's Claude. Provider will not intentionally start a login to, remotely control, or open a remote-access session with Client's computers or Client-controlled accounts. Provider receives only what Client or the installed system sends through the channels this Agreement and the Client Security Disclosure describe.
Each engagement is described in an order form. An "Engagement" means an accepted order form and the services under it. An order form is accepted when Client replies by email to the message that attached it, from an email address Client has designated or has used to deal with Provider, with the words "I accept the attached order form, this Master Service Agreement, and its jury waiver" and the typed full name and title of the person accepting. The reply accepts the attached order form and the versions of this Agreement and the Client Security Disclosure identified in it. The person accepting represents that they are authorized to bind Client, and each Party represents that it has authority to enter into this Agreement.
Prices are fixed once an order form is accepted, except Care prices, which may change only as Section 2 allows. Provider's website is descriptive only and is not part of this Agreement. No purchase order, supplier portal, or other Client form adds to or changes these terms.
Order of precedence. If documents conflict: (1) an applicable open-source or third-party license controls, but only for the material it governs; (2) the order form controls on price, scope, users, computers, schedule, payment, and any provision it expressly says amends this Agreement; (3) this Agreement controls on all other terms; (4) the Client Security Disclosure controls on the technical description of the security controls and their known limits.
Engagement types:
- Fit Check (free): Provider's written opinion on whether the service fits Client's business, based only on Client's answers. It is not a survey of Client's systems and not a warranty that Client's computer meets the Minimum Requirements. The Fit Check is governed by the Fit Check terms Client accepts when requesting it.
- Blueprint (fixed fee): a written plan for Client's install, delivered by email within 5 business days after Client's intake answers are complete. The fee is credited in full toward an Install ordered within 60 days of delivery.
- Install (fixed fee): a self-install release package for Client's own computer and accounts, with written installation instructions, configuration materials, written training materials, an in-system guided tour, post-install check scripts, and 30 days of Care after go-live (the instructions, training materials, and the description of how the installed system behaves are together the "Handoff Documentation"). Client runs and supervises the installation through Client's own agent. No remote installation, onsite work, or live training is included.
- Care (monthly, optional): tested software releases with release notes and rollback instructions, a written monthly health report, corrections as described in Section 10, and email support with a target first response within two business days.
- Add-ons (fixed price, by order form): additional workflows, users, or integrations.
Work outside an order form's scope needs a new order form or a written change accepted by both Parties.
Definitions. "Business day" means Monday through Friday, excluding US federal holidays, US Central time. "Minimum Requirements" means the computer and account requirements stated in the Client Security Disclosure or the order form. "Security Layer" has the meaning in Section 12. "Release" means a versioned software package Provider distributes through its designated release channel.
2. Fees, Payment, and Taxes
- Blueprint: 100% at order.
- Install: 50% at order, 25% at go-live, and 25% at the end of the included 30-day Care period.
- Care: billed monthly in advance, once Client enrolls under Section 10, or annually in advance at the price of 10 months if the order form or enrollment offers it. If annual Care ends early for any reason other than Client's uncured breach, Provider refunds the unused whole months pro rata at the discounted monthly rate.
- Invoices are sent by email and are due within 15 days. Client may dispute an invoice in good faith by email within 30 days of the invoice date, stating the reason, and pays any undisputed part on time.
- Late payment. Overdue undisputed amounts bear simple interest at 8% per year from the due date until paid. No other late charge applies. If any undisputed amount is more than 15 days overdue, Provider may suspend Care after 5 business days' written notice. Suspension pauses releases, reports, corrections, and support. Provider will not remotely disable, delete, or add an expiration mechanism to any installed release.
- Care price changes. Provider may change the monthly Care price by written notice at least 60 days before the change takes effect, no more than once in any 12-month period. Client may end Care before the new price takes effect, without penalty.
- Install cancellation. Client may cancel an Install by written notice before Provider delivers the first install release. Provider keeps the lesser of (a) the reasonable value of the work completed through the cancellation date, as Provider documents in writing, or (b) 20% of the Install price, and refunds the rest of the amount paid within 15 business days. After the first install release is delivered, amounts already paid are non-refundable, and no later milestone payment is due unless Client proceeds to that milestone. After go-live, Install fees are non-refundable except under the service standard in Section 3. A credited Blueprint fee is not refunded on cancellation.
- Other refunds. Blueprint refunds are stated in the Blueprint order form. Care fees for a month that has started are non-refundable.
- Taxes. Fees exclude sales, use, and similar taxes. Client pays any such taxes that apply, other than taxes on Provider's income.
3. How the Work Is Delivered
Communications, instructions, reports, approvals, notices, and support are delivered in writing by email. No calls are required. Any call is optional, informational, and does not change this Agreement. Releases are delivered through Provider's designated release channel.
Client runs and supervises the installation using Client's own Claude subscription, Client's own agent, Provider's written instructions, and the release package. Client controls every step and can stop at any time. No Engagement runs on Provider's accounts or credentials. Client's Claude subscription and other accounts, including their billing, are Client's own.
Before installation, Client confirms in writing that a current backup of the computer exists and that full-disk encryption is on (Section 7).
Go-live occurs when: (1) Client runs the supplied post-install check script on Client's computer; (2) Client sends Provider the resulting status report, and Provider replies in writing that the status report shows each check as passed (the "install report"); and (3) Client confirms in writing that the system is running, or 5 business days pass after the install report without Client reporting a reproducible failed check. The install report repeats what Client's own status report says. It is not an inspection of Client's computer and not a certification of Client's security. If Client reports a reproducible failed check in that period, Provider supplies a corrected release or written correction instructions, and the period restarts once Client reports that the checks pass. The 30 days of included Care start at go-live.
Service standard. Provider will perform the services in a professional and workmanlike manner, consistent with generally accepted industry practice for similar services. If Client tells Provider in writing within 30 days after delivery that a deliverable does not meet this standard, Provider will re-perform or correct it at no charge, and if Provider cannot do so within a reasonable time, will refund the fees paid for that deliverable. The 30-day window sets when the free re-performance is available. It does not shorten any time the law gives Client to bring a claim. Re-performance or refund is Client's exclusive remedy for breach of this service standard, and any other claim about a deliverable is subject to Section 5.
Not a security or compliance service. The services are planning, configuration, documentation, and software-release services. They are not managed security, monitoring, incident-response, legal, audit, or compliance services. Provider does not promise to find or prevent every vulnerability, malicious instruction, unauthorized action, or security incident.
Provider's tools and subcontractors. Provider uses AI tools, under human accountability, to draft, review, and deliver its work. The AI providers that may receive Client information are named in the Client Security Disclosure. Provider may use subcontractors and remains responsible for their work under this Agreement.
4. Data Handling
Client's data. Client's data, files, and business information remain Client's property. The installed system's files and memory stay on Client's computer. Provider does not host the system. In ordinary operation, Provider receives only (a) what Client sends by email, which is stored in Provider's business email account and processed with the AI providers named in the Client Security Disclosure, and (b) Care metadata, described below.
Client grants Provider a limited, non-exclusive right to receive, store, copy, and process information Client sends only as needed to perform the Engagement, administer this Agreement, secure Provider's systems, and comply with law. Provider does not sell Client information and does not itself use it to train any AI model. Provider will not send Client information to an AI provider not named in the Client Security Disclosure without first telling Client and getting Client's written consent.
Care metadata. While Care is active (including the 30 days included with an Install), the installed system emails Provider a monthly status summary: counts and categories of actions the system attempted, blocked, or held for approval; component status and release version; and whether the Security Layer is enabled. Provider uses commercially reasonable measures to design this summary to exclude Client content, prompts, command text, credentials, and file names. If Provider learns that materially different information was sent, Provider will stop or correct the transmission and handle the information under Sections 4, 8, and 11. Provider will not add any other automated communication from the installed system to Provider unless the Client Security Disclosure describes it and Client approves the change in writing.
Third parties in the data path. The system runs on Client's own Claude subscription, so the content it processes is sent to Anthropic under Client's own Anthropic account terms. If Client uses the optional texting feature, messages travel through Telegram, a third party. The Client Security Disclosure explains what data leaves Client's computer and to whom.
Data Client may not send to Provider or through Telegram: passwords, authentication tokens, or private keys; full Social Security numbers; payment card data or bank account numbers; protected health information; Federal Contract Information, Controlled Unclassified Information, export-controlled technical data, or classified information; and any other information the law or Client's contracts bar from that channel or from disclosure to Provider.
Excluded use. The standard service is not offered for, and Client will not use it with, Controlled Unclassified Information, export-controlled data, classified information, protected health information, or regulated financial-services data. Client remains responsible for access, permissions, retention, and safeguards for all information on its own systems.
Retention and deletion. While an Engagement continues, Provider purges emailed content older than 12 months that it no longer needs. When the last Engagement ends, or on Client's written request, Provider deletes the Client information it holds within 30 days, except billing records, copies the law requires Provider to keep, and copies in routine provider backups until they expire, which stay covered by Section 8.
4A. Security Disclosure
Before accepting, Client acknowledges receiving and reviewing the Client Security Disclosure. It describes the security controls in the installed system, the categories of attack they do not fully defend against, and what data leaves Client's computer. The disclosure describes the system as Provider understood it on the Effective Date. Provider prepared it with reasonable care and will tell Client without unreasonable delay if Provider learns of a material change or a material error that affects Client's installed release or Provider's handling of Client's information. The disclosure is not a warranty. No security control described in this Agreement or the disclosure is absolute or guaranteed, and Client agrees not to treat any statement in the disclosure as a promise that a listed control will catch every action it targets.
5. LIMITATION OF LIABILITY
THIS SECTION LIMITS WHAT EITHER PARTY CAN RECOVER. PLEASE READ IT.
- Cap. Except for Excluded Claims, each Party's total liability arising out of or related to a Blueprint, Install, or Add-on will not exceed the greater of the fees paid or payable under that order form and $2,500. For a claim arising from Care, the cap is the greater of the Care fees paid or payable in the 12 months before the event giving rise to the claim and $2,500. These are aggregate limits, not per claim or per legal theory.
- Indemnity and data cap. Each Party's total liability under Section 6, and for breach of Section 4, Section 8, or Section 11, will not exceed two times the applicable cap above, unless the underlying conduct is an Excluded Claim. The existence, amount, availability, or denial of insurance does not increase or decrease either Party's liability under this Agreement.
- What the caps cover. The caps and the damages exclusions apply to claims for breach of contract, breach of warranty, negligence (however labeled, including "gross negligence"), misrepresentation that is not intentional fraud, and any other claim the law allows the Parties to limit. Client acknowledges that Provider never accesses Client's systems, that Client runs the installation and supervises the system, that the fees are small relative to the value of Client's data, and that the caps are a bargained-for part of the price. Client may ask for a higher cap before ordering; if the Parties agree on one, the order form states it and the added fee.
- Excluded damages. Except for Excluded Claims and Client's breach of Section 9, neither Party is liable for indirect, incidental, special, consequential, exemplary, or punitive damages, or for lost profits, revenue, goodwill, or business opportunity, even if told they were possible. The reasonable cost of restoring lost or corrupted Client data from Client's backups, or of re-entering it where no backup exists because Client did not keep one as Section 7 requires, is a direct damage subject to the applicable cap, and is Client's sole measure of damages for data loss. If an exclusive remedy in this Agreement is held to have failed of its essential purpose, any other remedy remains subject to the caps and exclusions in this Section.
- Excluded Claims (not subject to the caps or the damages exclusions): a Party's intentional fraud, meaning a statement the Party knew was false when made and made to deceive the other Party; a Party's willful or wanton misconduct; Client's obligation to pay agreed fees; a Party's intentional infringement or misappropriation of the other's intellectual property; Client's breach of the restrictions in Section 9; and any liability the law does not allow the Parties to limit. A statement that turns out to be inaccurate, but that the Party did not know was false when made, is not an Excluded Claim, and Client's remedy for it is under this Agreement and subject to this Section.
- No Party may recover more than once for the same loss.
5A. AI Output; No Guaranteed Results; DISCLAIMER
The installed system and some of Provider's written deliverables use probabilistic AI models. Outputs may be inaccurate, incomplete, biased, outdated, not unique to Client, or fabricated, and factual statements that look reliable may be wrong. Outputs are not legal, tax, accounting, financial, medical, cybersecurity, or other professional advice. Unless an order form says otherwise, outputs are not reviewed by a human on Provider's behalf. Client is responsible for reviewing outputs before relying on them, making a decision with them, or sending them outside Client's organization.
Provider does not promise any particular time saved, revenue, cost reduction, or other business result.
DISCLAIMER. EXCEPT FOR THE SERVICE STANDARD IN SECTION 3 AND ANYTHING ELSE THIS AGREEMENT EXPRESSLY STATES, THE SERVICES, THE RELEASES, THE PROVIDER MATERIALS, AND THE INSTALLED SYSTEM ARE PROVIDED "AS IS" AND "WITH ALL FAULTS," WITHOUT ANY WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING ANY IMPLIED WARRANTY OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, OR NON-INFRINGEMENT. PROVIDER DOES NOT WARRANT THAT THE SYSTEM OR ANY AI OUTPUT WILL BE ACCURATE, COMPLETE, SECURE, UNINTERRUPTED, OR ERROR-FREE. Section 6 is Client's exclusive remedy for infringement claims.
5B. Third-Party Services
The installed system depends on services Client contracts for directly, including Anthropic, Telegram, and Client's email and calendar providers. Provider does not accept, negotiate, or sign any provider's terms for Client, does not control those services, and is not responsible for their availability, pricing, terms, model changes or retirements, or actions on Client's accounts.
6. Indemnification
- By Provider. Provider will defend Client against any third-party claim that Provider Materials (Section 9), as delivered and used under this Agreement, infringe a US copyright or trademark or misappropriate a trade secret, and will pay the damages and costs finally awarded or agreed in settlement. If such a claim happens or is likely, Provider may modify or replace the materials, get Client the right to keep using them, or end the license to the affected materials and refund any prepaid fees for them. This does not cover claims arising from open-source or third-party materials, AI outputs, Client's modifications, combination with things Provider did not supply, or use outside this Agreement.
- By Client. Client will defend Provider against any third-party claim arising from: Client's data, content, or instructions, to the extent the claim alleges they infringe or misappropriate rights, violate law, or were supplied without required authority or consent; Client connecting accounts or systems without authority or without notice or consent the law requires; Client's use of the system in violation of law, Section 7, or a provider's terms; Client's external use of, or decision made in reliance on, AI output; or Client's disabling or altering the Security Layer. Client's duty does not extend to the portion of any claim caused by Provider's breach of this Agreement, Provider's negligence, or Provider's willful or wanton misconduct. Client will pay the damages and costs finally awarded or agreed in settlement.
- Process. The Party seeking defense notifies the other promptly in writing, gives it control of the defense and settlement (no settlement may admit fault for, or impose obligations on, the protected Party without its consent), and gives reasonable help at the defending Party's cost.
- Both indemnities are subject to the indemnity and data cap in Section 5.
7. Client Responsibilities
Client is responsible for:
- (a) Backups. Before installation changes anything, Client confirms in writing that a current backup of the computer exists. If none exists, Provider's instructions direct Client to create one before continuing. Provider does not take, hold, or verify Client's backups.
- (b) Encryption. Full-disk encryption must be on for the computer running the system and on any backup of it. Client sends confirmation and will not begin installation without it.
- (c) Claude plan and settings. Client uses a Claude offering whose terms permit Client's intended business use and data, and follows Provider's instructions to use the most privacy-protective settings reasonably available.
- (d) Accounts. Client keeps its own Claude subscription and connected accounts active and paid, and gives each Authorized User the separate subscription its plan requires.
- (e) Authority to connect. Client has the authority to connect each account it connects, and has given any notice its own people or the law require.
- (f) Accurate information. Client gives accurate answers about its systems and data, including written confirmation that the excluded use in Section 4 does not apply.
- (g) Responsiveness. Client answers Provider's emails in a reasonable time. Timelines pause while Provider waits on Client.
- (h) Security Layer. Client does not disable, bypass, or modify the Security Layer, its configuration, or its log, and does not run the system in a mode that skips its checks. Provider is not responsible for actions the system takes after Client alters or disables the Security Layer.
- (i) Incident reporting. Client tells Provider promptly about any suspected security incident or malfunction.
- (j) Lawful use. Client uses the system only for lawful business purposes and in line with the usage policies of Anthropic and the other providers Client connects.
- (k) AI-use restrictions. Before ordering, Client tells Provider in writing about any contract, policy, or regulation that restricts Client's use of AI tools, cloud processing, or third-party messaging on its data. Provider may decline or re-scope an Engagement based on that information. Client is responsible for restrictions it did not disclose.
Authorized Users are the people named in the order form. An approval given by any Authorized User is Client's approval. Client is responsible for its Authorized Users' use of the system.
Always-on work. Scheduled and after-hours agent work runs on Client's own computer and happens only while that computer meets the Minimum Requirements and is powered on, awake, and connected to the internet.
8. Confidentiality
- Confidential Information means non-public information one Party (the "Discloser") gives the other (the "Recipient") in connection with this Agreement that is marked confidential or that a reasonable person would understand to be confidential, including Client's intake answers, workflow examples, incident details, and Care metadata, and Provider's non-public runbooks, methods, templates, pricing, and release notes.
- Exclusions. It does not include information that is or becomes public through no fault of the Recipient, that the Recipient already knew without a duty of confidence, that the Recipient gets from a third party free to share it, or that the Recipient develops independently.
- Duties. The Recipient uses Confidential Information only to perform or receive the services, shares it only with its own people, contractors, and the service providers named in the Client Security Disclosure who need it and are bound by written protections appropriate to the information, and protects it with at least reasonable care.
- Compelled disclosure. If the law or a court requires disclosure, the Recipient may disclose what is required after giving the Discloser prompt notice where legally allowed.
- Return and deletion. When this Agreement ends, or on written request, the Recipient returns or deletes the Discloser's Confidential Information, subject to Section 4's retention terms and Client's license under Section 9.
- Duration. These duties last during this Agreement and for 3 years after it ends, and for trade secrets as long as they remain trade secrets.
- Remedies. The Discloser may seek an injunction in addition to other remedies.
9. Intellectual Property, License, and Attribution
- Client materials and outputs. Client keeps ownership of material Client supplies. As between the Parties, Client may use outputs generated through Client's own account for any lawful purpose, subject to the law and the relevant provider's terms. Provider does not represent that an AI-generated output is copyrightable, unique, or free of third-party rights.
- Paid written deliverables. Provider keeps ownership of Blueprints, reports, training materials, and other written deliverables, excluding Client material in them. On full payment, Provider grants Client a perpetual, non-exclusive license to use, copy, modify, and share those deliverables for Client's internal business purposes, including with Client's employees, advisers, and vendors acting for Client. Client may not sell, publish, or distribute them as a standalone product or service.
- Open-source and third-party materials. Each release may contain materials governed by separate licenses, including AGPL v3 and CC BY-SA 4.0. Provider supplies with each release a manifest identifying those materials, their licenses, required notices, and where to get their source code. Those licenses control for the materials they cover, and nothing in this Agreement limits any right Client has under them. Open-source and third-party materials come with no Provider warranty or indemnity. Provider will preserve required notices and make source available as those licenses require.
- Provider Materials means only material that Provider owns or has the right to license, that no open-source license prevents Provider from restricting, and that the release manifest identifies as Provider Material. An item not so identified is not Provider Material.
- License. Provider grants Client a non-exclusive, non-transferable, non-sublicensable, perpetual license to install and use each release of the Provider Materials for which Client has paid, on the number of computers and for the number of users in its order form, for Client's own internal business purposes. The license to a release ends only if Client materially breaches the Restrictions below and does not cure within 30 days of written notice.
- Restrictions. Client will not: (i) sell, resell, rent, lease, sublicense, distribute, publish, or otherwise make the Provider Materials available to a third party; (ii) use them to provide installation, setup, configuration, training, or managed services to anyone other than Client; (iii) modify or create derivative works of them, except configuration the Handoff Documentation describes as Client-adjustable; (iv) reverse engineer any part delivered in non-source form; or (v) remove or obscure Provider's notices or marks. These restrictions do not apply to open-source materials, which Client may use as their own licenses allow.
- Feedback. Provider may use suggestions Client gives about the services, but never Client's Confidential Information.
9A. Case Study and Publicity
Provider will not publish a case study, Client's name or logo, or anything that reasonably identifies Client without Client's written approval of the final version. Any case-study commitment tied to founding pricing is stated in the order form.
10. Care, Corrections, Term, and Termination
Optional paid Care. The included 30-day Care period ends automatically unless Client affirmatively enrolls in paid Care in writing. At least 15 days before it ends, Provider will email the available plan, monthly price, start date, and cancellation terms. Paid Care begins only after Client replies that it accepts the identified plan and price. Continued use of the installed release does not by itself enroll Client. Either Party may end paid Care with 30 days' written notice.
What Care corrects. Care includes commercially reasonable correction of reproducible failures of the installed release to perform materially as described in the Handoff Documentation, up to the number of correction requests per month stated in the order form. Corrections for a material security vulnerability in Provider Materials, or for a defect Provider's own release introduced, are free and do not count toward that number. Care does not include new functionality, changed requirements, or restoring functionality a third-party provider discontinued, and does not cover problems caused by Client's changes, Client's hardware, operating system, network, or internet, Client's third-party accounts and their outages or terms, or data Client put into the system. Work outside Care needs a fixed-price order form.
Upstream changes. If Anthropic or another upstream provider makes a change that materially affects installs, Provider will assess it promptly and give Care clients a written status and plan, and a tested release or documented workaround when one is reasonably available.
Term. This Agreement starts on the Effective Date and continues until every Engagement has ended and, after that, until either Party ends it by written notice. A Blueprint is complete on delivery. An Install is complete at go-live plus the 30 days of included Care.
Inactive Engagements. If Client does not respond to Provider's written requests for 60 days during an Install, Provider may close the Engagement by written notice. Amounts paid are kept for work performed, no further milestone payments are due, and Client may restart within 6 months under a new order form at then-current pricing, with the amount paid credited in full.
Termination for cause. Either Party may end this Agreement or any Engagement by written notice if the other materially breaches it and does not cure the breach within 30 days after written notice describing it (10 days for non-payment). Either Party may end it immediately if the other stops doing business in the ordinary course.
After termination. Client pays fees for work delivered through the end date and keeps its license under Section 9. Nothing in this Agreement gives Provider any ongoing access or control. When Care ends, Provider stops release notices, reports, corrections, and support, and Client may keep using the last installed release. Provider is not responsible for changes Client or a third party makes after Care ends.
11. Security Incidents
A "Security Incident" means (1) confirmed unauthorized access to or disclosure of Client information held in Provider's own systems, or (2) Provider's confirmation that malicious or unauthorized code was introduced into a release Provider delivered to Client. Provider will notify Client within 3 business days after confirming a Security Incident, unless the law requires earlier notice, with the information reasonably available to it, written containment or remediation instructions or a corrected release where available, and reasonable cooperation with Client's own legally required notifications. Provider does not monitor Client's computer or accounts and may not detect an incident occurring there. Client handles containment and investigation on its own systems, following Provider's written instructions where they apply.
12. Approval for High-Risk Actions
The installed release is designed so that the system drafts by default and asks an Authorized User for approval before taking the high-risk actions listed in the Client Security Disclosure. The Disclosure states which of those actions are enforced by the Security Layer (a code-level check that runs before the AI model's own judgment and outside the customizable persona configuration) and which depend on configuration that Client controls and Section 7(h) protects. Client acknowledges that configuration-based controls are less reliable than code-enforced controls. A reply to an Authorized User through the channel that user used to make a request counts as approved by that request. Model-processing calls, read-only retrieval, and the Care metadata email are not communications for this section. Approving a workflow in advance does not approve each action in it, unless the order form and release documentation expressly identify a specific recurring action as approved in advance.
The Security Layer reduces risk but can be bypassed by defects, unsupported tools, Client modifications, malicious instructions or code, third-party changes, or the other limits described in the Client Security Disclosure. It is not a guarantee that every covered action will be caught. Approvals are given on Client's computer unless the release documentation states that another channel is supported.
13. No Compliance or Certification Claims
Provider does not certify, and does not represent, that Client is compliant with any law, regulation, or framework, including CMMC, FAR 52.204-21, HIPAA, or GLBA. Any mapping of system controls to a framework is supporting evidence only. Compliance remains Client's responsibility. The services are commercial services and the Provider Materials are commercial computer software and documentation. If Client intends to use any deliverable in performing a Government contract or subcontract, Client will say so before ordering, and no Government contract clause applies to Provider unless Provider expressly accepts it in a signed addendum.
14. Insurance
During each paid Engagement, Provider intends to carry professional liability and cyber liability insurance and will give Client a certificate of insurance on reasonable written request. The certificate, not this Agreement, states the coverage in force.
15. Governing Law, Courts, and Disputes
This Agreement is governed by the laws of the State of Alabama, without regard to its conflict-of-laws rules. Client is a business and enters this Agreement for business purposes, not for personal, family, or household use.
Before filing any claim, the Parties will try in good faith to resolve the dispute by email between their decision-makers for 30 days. After that, any suit must be brought exclusively in the state courts located in Coffee County, Alabama, Enterprise Division, or, if federal subject-matter jurisdiction independently exists, the United States District Court for the Middle District of Alabama. Each Party consents to personal jurisdiction and venue in those courts and waives any objection based on inconvenient forum. This does not prevent either Party from filing an eligible claim in the small-claims division of the Coffee County District Court, or from seeking an injunction in any court to protect its Confidential Information or intellectual property without waiting out the negotiation period. In any suit to collect fees or to enforce Section 8 or Section 9, the prevailing Party may recover its reasonable attorneys' fees and costs.
JURY WAIVER. EACH PARTY KNOWINGLY, VOLUNTARILY, AND INTENTIONALLY WAIVES ANY RIGHT TO A TRIAL BY JURY IN ANY ACTION, PROCEEDING, OR COUNTERCLAIM ARISING OUT OF, RELATING TO, OR IN ANY WAY CONNECTED WITH THIS AGREEMENT, ANY ORDER FORM, ANY ENGAGEMENT OR DELIVERABLE, THE CLIENT SECURITY DISCLOSURE, OR THE RELATIONSHIP BETWEEN THE PARTIES, WHETHER THE CLAIM SOUNDS IN CONTRACT, TORT, FRAUD, OR STATUTE, AND INCLUDING CLAIMS ABOUT HOW THIS AGREEMENT OR ANY ORDER FORM WAS FORMED OR INDUCED. EACH PARTY CONFIRMS THAT IT HAS READ THIS WAIVER, HAS HAD THE OPPORTUNITY TO REVIEW IT WITH A LAWYER OF ITS CHOICE, AND IS A BUSINESS ENTERING THIS AGREEMENT FOR BUSINESS PURPOSES.
16. General Terms
- Independent contractors. Nothing here creates a partnership, joint venture, employment, or agency relationship.
- Compliance with laws. Each Party will comply with the laws that apply to its performance under this Agreement.
- Electronic dealings. The Parties agree to conduct this Agreement, every order form, every notice, and every amendment by electronic means. Each acceptance or typed name sent as this Agreement describes is that Party's electronic signature under the Alabama Uniform Electronic Transactions Act.
- Notices. Notices are sent by email to the notice addresses in the order form. A notice is effective on the next business day after it is sent, unless the sender gets a delivery-failure message. A notice of breach, termination, indemnity claim, or legal proceeding must say it is a formal notice under this Agreement. Either Party may change its notice address by notice.
- Assignment; name changes. Neither Party may assign this Agreement without the other's written consent, except to a successor to all or substantially all of its related business. Provider may change its trade name by written notice without affecting this Agreement or any order form. Any other attempted assignment is void.
- Force majeure. Neither Party is liable for delay or failure caused by events beyond its reasonable control. This does not excuse payment obligations.
- Export and sanctions. Client will not use or export the deliverables in violation of US export control or sanctions laws.
- No outside promises. In deciding to enter into this Agreement, Client is not relying on any promise or statement that the services will produce a particular financial result, save a particular amount of time, prevent every unauthorized action, or be error-free, except a statement contained in this Agreement, the applicable order form, or the Client Security Disclosure. This does not limit liability for intentional fraud.
- Severability. If a provision is unenforceable, it is changed to the minimum extent needed, and the rest stays in effect.
- Waiver. A waiver counts only if written, and one waiver does not waive anything else.
- Entire agreement; amendments. This Agreement, its order forms, and the Client Security Disclosure are the entire agreement on this subject and replace prior discussions. Each Party has read this Agreement, has had the opportunity to negotiate it and to have a lawyer review it, and enters it as a business for business purposes. Amendments must be in writing and accepted by both Parties; an email exchange expressly agreeing to the change counts.
- No third-party beneficiaries. No one other than the Parties has rights under this Agreement.
- Survival. Payment obligations, Sections 4 (while Provider holds Client information), 4A, 5, 5A, 5B, 6, 8, 9, 13, 15, and 16, and any other provision that by its nature should survive, survive the end of this Agreement.
ACCEPTANCE. Accepted as described in Section 1, by email reply stating: "I accept the attached order form, this Master Service Agreement, and its jury waiver," with the typed full name and title of the person accepting.
Every order form carries, directly above its acceptance line: "This order form is governed by the Master Service Agreement, version 6.1, dated September 29, 2026, including its limitation of liability in Section 5, its disclaimer in Section 5A, and its jury waiver in Section 15, which apply to this order form."
Fit Check terms (placed on the Fit Check request form and at the top of every Fit Check): "This Fit Check is a free written opinion based only on the answers you gave us. We have not seen your systems. It is not a warranty and not advice on security, legal, or compliance matters. By requesting it, you agree that our total liability for it will not exceed $100, and that it is otherwise governed by our Master Service Agreement, which you can read at https://commandkey.ai/terms.html before requesting it."