Customer agreements

All five agreements keep their own dated history.

Every Order Form incorporates these master terms, which carry the SLA and DPA as exhibits.

  1. 2026-06-28Initial published Master Services Agreement, under California law, with the SLA and DPA as its exhibitsv1.0
  2. 2026-07-02Customer Data is not used to train foundation models; Output is never the sole basis for a consequential decision without human reviewv1.1
  3. 2026-09-03The customer owns its Customer Ontology alongside its data and output, and may export all three during the term and for 60 days afterv1.2
  4. 2026-09-03Data Processing Addendum only: the two service-provider terms California’s privacy regulations requirev1.3
  5. 2026-10-01For customers who sign on v1.4, Mulholland may de-identify data it receives from then on and use the De-Identified Data to build its own models, which it owns, under the safeguards in §3.3v1.4
  6. 2026-10-01Billing and revenue-cycle services are Professional Services, done in the customer’s name with the customer responsible for its claims (§1.6); export and deletion run on one clock, with personal data deleted within 30 days after the 60-day export periodv1.5
  7. 2026-10-01Data Processing Addendum only: every new subprocessor company gets thirty days’ notice, and an unresolved objection can end the affected Order Form or SOW with a refundv1.6

This addendum sets out how we process and protect customer data.

  1. 2026-09-03Describes the platform as operated: tenant isolation is logical, enforced by forced row-level security in a multi-tenant database; TLS 1.2 is the floor in transitv1.2
  2. 2026-09-03The subprocessor list lives on the trust center, with thirty days’ notice and an objection right before a new one processes personal datav1.2
  3. 2026-09-03§9 adds the service-provider terms the CCPA regulations requirev1.3
  4. 2026-10-01De-identification under MSA §3.3 as a documented instruction and specified business purpose; subprocessor categories and security wording updatedv1.4
  5. 2026-10-01§8.2 makes deletion a firm obligation on the MSA §10.5 clock, with subprocessors deleting too; Annex C adds revenue-cycle support contractors in the Philippines for customers who buy billing servicesv1.5
  6. 2026-10-01§4.3: revenue-cycle contractors are listed as one category, with an update before each new individual starts and names on request; an objection to a new subprocessor can end the affected SOW, with prepaid, unused billing fees refundedv1.6

This exhibit holds our uptime commitment and our support response targets.

  1. 2026-06-28Published with the first Master Services Agreement as its Exhibit Av1.0

These terms cover implementation, deliverables and intellectual property.

  1. 2026-06-28Initial published Professional Services Terms; an Order Form may serve as the statement of workv1.0
  2. 2026-07-02Counsel-approved hardening: remedies, a deliverables non-infringement warranty and a bridge to the BAA for services workv1.1
  3. 2026-07-02§10 restructured after outside review: no hiring restraintv1.2
  4. 2026-10-01Clarity fixes for Free Services, directed data sources and Pilot remedies; nothing in these terms limits MSA §3.3v1.3
  5. 2026-10-01Billing and revenue-cycle work is a Professional Service and its records are the customer’s; only a refundable Pilot’s refund is its exclusive remedy, and customer-caused delay extends the 90-day long-stopv1.4
  6. 2026-10-01Billing errors can be raised within 45 days of discovery, up to 12 months after the service; Mulholland pays reimbursement lost when it misses a filing deadline through its own fault, capped at three months of billing fees per yearv1.5

This agreement adds the HIPAA terms for healthcare clients who handle PHI.

  1. 2026-06-28Initial published Business Associate Agreement, incorporated by reference into the healthcare Order Formv1.0
  2. 2026-10-01§3.4 lets Mulholland de-identify PHI to HIPAA’s standard for its own purposes, with safeguards; the BAA covers all PHI Mulholland handles, including services workv1.1

Old versions
stay put.

Policies

Security

Trust center