MASTER SERVICES AGREEMENT
Mulholland, Inc.
This Master Services Agreement (this “MSA”) is entered into by and between Mulholland, Inc., a Delaware corporation (“Mulholland”) located at 3400 W Riverside Dr, Ste 250, Burbank, CA 91505, and the customer identified in the applicable Order Form (“Customer”) and governs Customer’s access to and use of the Technology and Services. The “Effective Date” of this MSA is the earlier of: (i) the effective date of the initial Order that references this MSA or (ii) the date on which Customer begins to use the Technology or Services. If the individual accepting this MSA is doing so on behalf of a company or other legal entity, such individual represents that they have authority to bind that entity, in which case “Customer” refers to that entity.
1. TECHNOLOGY, DOCUMENTATION, & SERVICES
1.1 Technology & Documentation. During the applicable Order Form Term, subject to Customer’s compliance with the terms of this Agreement and use in accordance with the Documentation for its internal business purposes, Mulholland will: (a) make available access to the Platform for Customer’s Authorized Users; (b) if applicable to Customer’s subscription, grant Customer a limited, non-exclusive, non-sublicensable, non-transferable license and right to use a single instance of the Local Software solely for the purposes of connecting or integrating with the Platform; and (c) if applicable to Customer’s subscription (or Mulholland Materials are made available through Professional Services or otherwise), grant to Customer a limited, non-exclusive, non-sublicensable, non-transferable license and right to copy and use the Mulholland Materials solely as necessary for Customer to use the Technology. Mulholland grants to Customer the right to copy and use the Documentation as necessary to use the Technology. Customer agrees Mulholland may remotely access the Local Software as necessary to perform the Services or provide the Technology. For clarity, Customer is solely responsible for updating and maintaining any Local Software unless otherwise agreed by the parties in writing. Mulholland may implement updates or changes to the Technology in its sole discretion from time-to-time.
1.2 Professional Services. If specified in an Order Form, Mulholland agrees to provide Customer with Professional Services as described in the applicable Order Form or in one or more Statements of Work (each, a “SOW”) executed by both parties. An Order Form that describes Professional Services constitutes a SOW for those services, which are governed by Mulholland's Professional Services Terms. In the event an Order Form does not specify Professional Services, Mulholland may, in its sole discretion, choose to provide Customer with Professional Services and such Professional Services are subject to the limitations of liability set forth in this Agreement for Free Services. For clarity, Mulholland’s performance of Professional Services will not impact any of its Intellectual Property Rights set forth in this Agreement.
1.3 Non-Mulholland Services. Through the Technology, Customers may be able to connect to Non-Mulholland Services. Mulholland is not responsible for the performance, functionality, or data of any Non-Mulholland Services.
1.4 Service Level Agreement. Mulholland will provide support and will make the Platform available in accordance with its standard support services offering generally available to Customers at such time, a current version of which is attached hereto as Exhibit A. For clarity, in the event Mulholland provides Customer with any Mulholland Materials while providing support, Mulholland owns any Intellectual Property Rights in such Mulholland Materials.
1.5 Security. Mulholland has in place a security program and will secure the Platform as described in its Data Processing Addendum incorporated by reference and attached hereto as Exhibit B and Trust Center, available at: https://trust.mulholland.ai/, each of which may be updated from time-to-time.
1.6 Billing and Revenue-Cycle Services. When an Order Form or SOW includes billing and revenue-cycle services, Mulholland performs them on Customer’s behalf and at Customer’s direction, using the information Customer provides, and submits claims, appeals, and statements only in Customer’s name. Customer reviews and approves those claims, appeals, and statements (individually or through written rules it sets) and remains responsible for their accuracy and completeness; for its coding and clinical documentation, fee schedules, and patient financial policies; and for its compliance with its payer contracts and applicable law. Mulholland does not provide coding, legal, or compliance advice and does not guarantee any reimbursement, payment, or collection. Unless the Order Form or SOW expressly provides otherwise, Mulholland follows up only on patient balances that are not in default and does not purchase or take assignment of any account, and payers and patients pay Customer, not Mulholland.
2. CUSTOMER RESPONSIBILITIES
2.1 General. Customer is responsible for: (a) its Authorized Users’ compliance with this Agreement and any use of the Platform and Local Software under such user’s account; (b) the accuracy, quality, and legality of Customer Data and the means by which Customer acquired it; (c) obtaining and maintaining all rights, consents, and authorizations necessary for Mulholland to access, process, and use Customer Data as contemplated by this Agreement; and (d) securing its Platform account and the Local Software, and promptly notifying Mulholland of any unauthorized use of, or access to, the Technology of which Customer becomes aware. Customer is aware security is a shared responsibility, and Mulholland will have no responsibility for securing any part of the Technology managed by Customer in its local environments, including but not limited to the Local Software or Mulholland Materials utilized by Customer.
2.2 Use Restrictions. Customer and its Authorized Users will not: (a) use the Technology and Documentation other than in accordance with the Documentation and applicable law; (b) copy, modify, reverse engineer, decompile, or attempt to discover the source code or underlying structure of the Technology and Documentation or otherwise attempt to bypass or circumvent any functionality of such, except to the extent such restriction is prohibited by law; (c) sell, resell, sublicense, rent, lease, or otherwise provide access to the Technology and Documentation to any third party except as expressly permitted in an Order; (d) include in Customer Data any data for which Customer lacks the rights, power, or authority necessary for its processing as contemplated by this Agreement; (e) unless otherwise agreed in a signed writing (including an Order Form incorporating the Business Associate Agreement), provide any highly regulated or sensitive data — including Protected Health Information, payment-card data, government-issued identification numbers, biometric identifiers, or personal data relating to children — to the Platform or to Mulholland in its provision of the Technology and Services; (f) remove any proprietary notices; (g) use the Technology and Documentation for any illegal, prohibited or high risk use cases which may impact life, lead to injury, or have a significant environmental impact (ex. In life threatening situations, such as emergency response, autonomous vehicles, nuclear operations, etc.) or for professional advice or regulated professions (ex. legal, medical, accounting, tax, financial, etc.), and Output may not be used as the sole basis for decisions with legal or similarly significant effects on individuals (including credit, housing, employment, insurance, or medical decisions) without independent human review; or (h) use the Technology, Documentation, or Services to develop a competitive service or product. For clarity, nothing in this Section 2.2 restricts Customer from using its Customer Data, Customer Ontology, Output, or its own business knowledge — or from providing them to a third party — to develop, procure, or operate another system or service, provided Customer does not use or disclose the Technology, Mulholland Materials, Documentation, or Mulholland Confidential Information in doing so; and use of the Technology, Documentation, and Output as internal operational tooling in a regulated profession or industry that an Order Form expressly permits does not breach clause (g).
3. INTELLECTUAL PROPERTY AND DATA RIGHTS
3.1 Ownership by Customer. As between the parties, Customer owns and retains all Intellectual Property Rights in its Customer Data, Customer Ontology, and Output. Mulholland’s ownership of the Technology and Mulholland Materials (including Generalized Improvements) does not give Mulholland any ownership of, or any right to use or disclose, Customer Data, Customer Ontology, or Customer Confidential Information except as expressly permitted by this Agreement. Subject to section 3.2 below, Customer understands while Output may be based on its input and Customer Data, it may have the same or similar Output as others based on the nature of generative AI technology. Mulholland’s rights in De-Identified Data and Mulholland Models are governed by Section 3.3, which controls over this Section 3.1.
3.2 Ownership by Mulholland. Mulholland owns and retains all Intellectual Property Rights in its Technology, Mulholland Materials, Documentation, Services, and any other materials or technology provided by Mulholland, including know-how, in each case excluding Customer Data, Customer Ontology, and Output. Except for the use explicitly permitted herein, and except for Customer's rights in Customer Data, Customer Ontology, and Output, Customer does not acquire any Intellectual Property Rights to the Technology, Mulholland Materials, Documentation, Services, and any other materials, products, technology, or other intellectual property provided by Mulholland through the Technology, Services or under this Agreement. Mulholland expressly reserves all of its right, title, and interest in and to the Technology, Mulholland Materials, Documentation, and the Services. For clarity, Customer’s ownership of Customer Ontology does not transfer to Customer, or grant Customer any license to, the Technology or any generic or domain-level ontology framework, template, or reusable model, or any skill, workflow, connector, evaluation material, operating parameter, methodology, or other Mulholland Materials used to create, maintain, interpret, or operate Customer Ontology; and neither the performance of Professional Services nor Customer’s payment for them transfers ownership of any Technology or Mulholland Materials to Customer unless an Order Form signed by Mulholland expressly assigns a specifically identified item to Customer.
3.3 De-Identified Data and Mulholland Models.
(a) Creation. Mulholland may create De-Identified Data from Customer Data, Customer Ontology, Output, and the other data that the Technology and Services (including any Free Services) generate for Customer, such as model inputs and outputs, workflow traces, data that Mulholland accesses or retrieves at Customer’s direction, and corrections, ratings, and labels made by Authorized Users or by Mulholland personnel (together, “Source Data”), while an Order Form is in effect. It may do so only from Source Data that it first receives or generates on or after the effective date of the Order Form or amendment by which Customer first agrees to version 1.4 or a later version of this MSA, and not from (1) Source Data received or generated before that date or under an Order Form that incorporates an earlier version, or (2) Source Data that Mulholland generates on or after that date by reprocessing Customer Data it first received before that date, or that contains such Customer Data.
(b) Use. Mulholland may use De-Identified Data and Mulholland Models for any lawful purpose, including to combine De-Identified Data with that from other customers and sources; to develop, train, fine-tune, evaluate, and improve Mulholland Models, the Technology, and its other products and services; and to license, sell, and otherwise make available Mulholland Models and the products and services that use them, without obligation to Customer except under this Section 3.3.
(c) Ownership. As between the parties, Mulholland owns all right, title, and interest, including all Intellectual Property Rights, in De-Identified Data and Mulholland Models (other than any Source Data in them that is not De-Identified Data). To the extent Customer has or acquires any such right, Customer hereby assigns it to Mulholland and, where assignment is not possible, grants Mulholland a perpetual, irrevocable, worldwide, royalty-free, transferable, and sublicensable license to it. De-Identified Data and Mulholland Models are not Customer Data, Customer Ontology, Output, or Customer Confidential Information. As between the parties, Mulholland’s rights in Mulholland Models are subject only to this Section 3.3, the Business Associate Agreement, applicable law, and the terms of any third-party model, dataset, service, or other component used to develop them. Customer’s rights in any Source Data in a Mulholland Model give it no ownership of, or lien on, the Mulholland Model as a whole.
(d) Commitments. Mulholland will:
(i) de-identify Source Data within Customer’s logically isolated environment before combining the result with any other data;
(ii) take reasonable technical and organizational measures to ensure that De-Identified Data cannot be associated with Customer or any individual or household, protect it with security measures at least as protective as those Mulholland applies to Customer Data, and, before making any Mulholland Model or aggregated statistic available to anyone other than Mulholland and its service providers, confirm that it was developed from the De-Identified Data of at least five unrelated customers or that a qualified expert has determined that it cannot reasonably be used to infer information about, or otherwise be linked to, Customer; and, on Customer’s written request no more than once in any twelve (12) months, provide a written summary of its de-identification methods and certify in writing its compliance with this Section 3.3(d);
(iii) maintain and use De-Identified Data only in de-identified form, not attempt to re-identify it, and publicly commit in its privacy policy or customer data privacy notice to do so;
(iv) not identify Customer to any third party as a source of De-Identified Data or of any Mulholland Model, except in confidence to its auditors, de-identification experts, legal and financial advisors, insurers, and actual or prospective acquirers, investors, and financing sources bound by confidentiality obligations, or as required by law (and any legally required training-data summary will describe sources by category without naming Customer unless the law requires it);
(v) not sell or license De-Identified Data itself as a dataset (including a Mulholland Model’s evaluation sets or examples), and disclose record-level De-Identified Data only as part of a Mulholland Model, to service providers acting for Mulholland, to a successor to all or substantially all of Mulholland’s business, or of the business line that uses the De-Identified Data, that agrees in writing to be bound by this Section 3.3, or as required by law;
(vi) require in writing anyone who receives De-Identified Data or a Mulholland Model from Mulholland to keep it in de-identified form, not attempt to re-identify it, not sell it, protect it, use it only as Mulholland permits, stop using it, and return or destroy it and any model that contains it, on Mulholland’s written notice, comply with Cal. Civ. Code § 1798.140(m), and impose the same terms on anyone with whom it shares it;
(vii) not use Source Data that is not De-Identified Data to train, fine-tune, or evaluate any model used for anyone other than Customer, or include it in any prompt, example, skill, or retrieval index used for anyone else (although it may run and monitor any model on Customer’s Source Data to serve Customer). Any model that Mulholland trains or fine-tunes for Customer on identifiable Source Data is used only for Customer, and Mulholland will delete it and all copies (other than routine backups, which remain protected until overwritten) within thirty (30) days after the Export Period (as defined in Section 10.5) ends;
(viii) not permit OpenAI, Google, or any other third-party model provider or Subprocessor to use Source Data or De-Identified Data to train or improve its own models;
(ix) take reasonable measures, including testing before release, designed to prevent Mulholland Models from reproducing Customer Data or information that identifies any individual; and
(x) remove authentication credentials (including passwords, one-time and two-factor codes, and access tokens), payment-card data, government-issued identification numbers (including Social Security numbers), financial-account numbers, and biometric identifiers from each record before de-identifying it. Mulholland will not create De-Identified Data from: (A) personal data relating to children (individuals under 18 years of age when the data was created), including all data in a record about a patient who was then a child, and Mulholland will remove any child listed as a dependent on another person’s record from that record before de-identifying it; (B) tax return information within the meaning of 26 C.F.R. § 301.7216-1(b)(3) or other information obtained in the business of preparing, or assisting in preparing, federal or state income tax returns (including under Cal. Bus. & Prof. Code § 17530.5); (C) confidential client information that Customer holds as a licensee of a state board of accountancy (including under Cal. Bus. & Prof. Code § 5063.3), unless Customer confirms in writing that it holds the written client permission that applicable professional rules require for that use; (D) nonpublic personal information that Customer disclosed to Mulholland under 12 C.F.R. § 1016.14 or § 1016.15; or (E) data that Mulholland or Customer obtained from a third party under terms (including an API license, payer participation agreement, or non-disclosure agreement) that do not permit that use, including any data or category of data that Customer identifies to Mulholland in writing, in good faith, as subject to such terms (identifying the terms).
(e) Failed De-identification. Information that is re-identified, or that does not meet the definition of De-Identified Data, remains Source Data (and, as applicable, Customer Personal Data or Protected Health Information). If Mulholland learns that any such information is in a dataset used to develop Mulholland Models, or can be output by a Mulholland Model, it will promptly notify Customer, remove it, and retrain, modify, or retire any Mulholland Model that can output it (and, for copies licensed or transferred to others, require their replacement or deletion under Section 3.3(d)(vi)).
(f) Liability. Any claim for breach of this Section 3.3 (including a failure of de-identification), or that Mulholland’s creation, use, or disclosure of De-Identified Data or Mulholland Models infringes or misuses Customer’s rights in Source Data, is treated as a claim for breach of the DPA (or, as to Protected Health Information, of the Business Associate Agreement) and is not a claim for infringement of Customer’s Intellectual Property Rights under Section 7.3(e). For all such claims: (1) the limitations of liability that apply to claims for breach of the DPA or the Business Associate Agreement apply to every form of monetary relief, including damages, restitution, disgorgement, unjust enrichment, and any reasonable royalty; (2) notwithstanding Sections 7.2 and 7.4 (including as they apply to Free Services and Professional Services), Mulholland’s aggregate liability will not exceed the greater of the amount those limitations would otherwise allow and US$250,000, measured without regard to whether Fees were paid or the Agreement has terminated; and (3) creating, using, or disclosing information that Mulholland reasonably and in good faith believed to be De-Identified Data, having applied the methods this Section 3.3 and the Business Associate Agreement require, is not willful misconduct for purposes of Section 7.3(b). Mulholland is responsible for complying with the law that applies to its own creation and use of De-Identified Data and Mulholland Models, and Customer’s obligations under Sections 2.1(c), 2.2(d), 5.3(a), and 6.2 do not extend to that creation or use.
(g) Precedence; Survival. This Section 3.3 is subject to the Business Associate Agreement as to Protected Health Information. Notwithstanding Sections 11.1 and 11.10, no Order Form, SOW, addendum, side letter, policy, purchase order, or other document (including the Professional Services Terms) made after Customer agrees to this version limits this Section 3.3 unless it is signed by Mulholland and expressly refers to this Section 3.3. De-Identified Data and Mulholland Models are not subject to export, return, or deletion under Section 10.5, the DPA, or the Business Associate Agreement, and this Section 3.3 survives termination or expiration of the Agreement.
3.4 Feedback. If Customer provides Feedback regarding the Technology and Services, Customer agrees Mulholland has an irrevocable, worldwide, perpetual, royalty-free license and may use it without restriction or obligation for any reason, including incorporating it within its technology, products, and services.
3.5 License to Mulholland. Customer grants Mulholland a non-exclusive, worldwide, royalty-free license during the Term and any Export Period to access, use, copy, process, store, transmit, and display Customer Data, Customer Ontology, and Output solely to provide, secure, support, maintain, and improve the Technology and Services for Customer, to comply with applicable law, and as otherwise expressly permitted by this Agreement. Mulholland’s creation and use of De-Identified Data and Mulholland Models are governed by Section 3.3.
3.6 Business Continuity. The parties may agree in an Order Form or executed addendum to a source-code escrow or other business-continuity arrangement under which Customer receives a limited, internal-use continuity license to specified materials upon narrowly defined release events (such as Mulholland’s cessation of business without a successor). Absent such an executed Order Form or addendum, no continuity license, and no right to receive source code, is granted under this Agreement.
4. CONFIDENTIALITY
Each party retains all ownership rights in and to its Confidential Information. A receiving party will not use the disclosing party’s Confidential Information except as permitted under this Agreement and will not disclose it to any third party except to its Representatives who have a bona fide need to know and are bound by confidentiality obligations at least as protective as those herein. Each party will protect the other’s Confidential Information using the same degree of care it uses to protect its own confidential information (at least reasonable care). A party may disclose Confidential Information to the extent required by law or binding court order, provided it gives prior written notice where legally permitted. Each party acknowledges that breach of this Section may cause irreparable harm for which monetary damages would be an inadequate remedy, and that the non-breaching party is entitled to seek equitable relief in addition to other available remedies.
5. WARRANTIES; DISCLAIMER
5.1 Mutual. Each party warrants that it has the valid legal authority to enter into and perform this Agreement.
5.2 Mulholland Warranties. Mulholland warrants during the term of an Order for the Platform, (a) the Platform will perform materially in accordance with the Documentation, and (b) Professional Services will be performed in a professional and workmanlike manner consistent with industry standards. For Professional Services, this warranty applies only if Customer provides written notice of a claim within forty-five (45) days after performance of the deficient Professional Services and is subject to the warranty remedies set forth in the SOW and any terms incorporated within. For breach of any other warranties, Customer may provide Mulholland with thirty (30) days written notice of breach (effective on Mulholland’s receipt) and Mulholland will have 30 days to cure such breach. In the event Mulholland does not cure such breach, then Customer will have a right to receive a refund of any prorated, pre-paid fees for the impacted Order Form after the effective date of termination. Mulholland shall not be liable for any such cure or remedies to the extent such breach is caused by Customer. For any breach of a warranty above, Customer’s exclusive remedies are described in this section.
5.3 Customer Warranties. Customer warrants: (a) it has all legally required and otherwise necessary rights and consents for Mulholland to process Customer Data, including personal data within; (b) it will comply with all applicable laws and regulations in its use of the Technology and Services; and (c) it will not use the Technology and Services for any illegal or otherwise unauthorized purposes.
5.4. Disclaimer. EXCEPT AS EXPRESSLY SET FORTH IN THIS AGREEMENT, AND TO THE MAXIMUM EXTENT PERMITTED BY LAW, MULHOLLAND DISCLAIMS ALL WARRANTIES, WHETHER EXPRESS OR IMPLIED, ORAL OR WRITTEN, STATUTORY, OR OTHERWISE, RELATING TO THE TECHNOLOGY AND SERVICES PROVIDED (INCLUDING BUT NOT LIMITED TO THE PLATFORM, LOCAL SOFTWARE, MULHOLLAND MATERIALS, DOCUMENTATION, AND SERVICES OR OTHER WORK) INCLUDING WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT, AND ANY WARRANTY THAT THE TECHNOLOGY, MULHOLLAND MATERIALS, DOCUMENTATION, AND SERVICES WILL BE ERROR-FREE OR UNINTERRUPTED. TO THE MAXIMUM EXTENT PERMITTED UNDER LAW, MULHOLLAND MAKES NO WARRANTY REGARDING, AND WILL HAVE NO LIABILITY FOR, ANY DECISIONS, OUTPUT, ANALYSES, OR RESULTS DERIVED FROM CUSTOMER DATA OR OTHER CONCLUSIONS OR ACTIONS TAKEN BY CUSTOMER BASED ON ITS USE OF THE TECHNOLOGY, MULHOLLAND MATERIALS, DOCUMENTATION, AND SERVICES. FURTHERMORE, MULHOLLAND MAKES NO WARRANTIES FOR ANY INACCURATE, INCORRECT, QUALITY, OR LEGALITY OF ANY OUTPUT GENERATED BY GENERATIVE AI COMPONENTS OF THE TECHNOLOGY AND SERVICES, WHICH ARE BASED ON THE INPUT PROVIDED BY CUSTOMER AND DISCLAIMS ALL LIABILITY RELATED TO THE OUTPUT AND ANY USE OR RELIANCE BY CUSTOMER OF OUTPUT. ANY FREE SERVICES ARE PROVIDED “AS-IS” AND AS AVAILABLE EXCLUSIVE OF ANY WARRANTIES OR GUARANTEES OF ANY KIND.
6. INDEMNIFICATION
6.1 By Mulholland. Mulholland will defend Customer against any third-party claim alleging Customer’s authorized use of the Platform infringes or misappropriates such third party’s Intellectual Property Rights (an “IP Claim”), and will indemnify Customer for damages, attorneys’ fees, and costs finally awarded against Customer, or amounts paid in settlement approved by Mulholland. Notwithstanding the foregoing, Mulholland has no liability for any claim arising from: (a) any open-source software component, unless the claim specifically alleges that the infringement arises from the Platform as distinct from such component; (b) the combination or use of the Platform with services, software, equipment, or data not supplied by Mulholland, where the claim would not have arisen but for such combination or use; or (c) Customer’s use of the Platform other than in accordance with the Documentation and this Agreement, including use of Customer Data that Customer lacked the rights to process. If the Platform becomes, or Mulholland believes it may become, the subject of an IP Claim, Mulholland may at its option and expense (a) procure the right for Customer to continue using the affected Platform, (b) modify or replace it to be non-infringing while substantially equivalent, or (c) terminate the affected Order Form for the Platform and refund any unused, prepaid Fees for the affected aspect.
6.2 By Customer. Customer will defend Mulholland against any third-party claim arising from (a) Customer’s use of the Technology and Services in violation of law or the rights of a third party, (b) Customer Data or the use of Customer Data with the Technology and Services, or (c) Customer’s breach of sections 2.2 (Use Restrictions) or section 5.3 (Customer Warranties), including but not limited to any resulting regulatory fines or penalties (a “Data Claim”), and will indemnify Mulholland for damages, attorneys’ fees, and costs finally awarded, or amounts paid in settlement approved by Customer; except, in each case, to the extent the claim arises from Mulholland’s breach of this Agreement or its gross negligence or willful misconduct.
6.3 Procedure. The indemnified party will (a) promptly notify the indemnifying party of the claim (late notice excuses the indemnifying party only to the extent it is prejudiced), (b) give the indemnifying party sole control of the defense and settlement (provided no settlement imposing liability or admission on the indemnified party may be made without its consent), and (c) provide reasonable cooperation at the indemnifying party’s expense.
6.4 Sole Remedy. This Section states each party’s entire liability and exclusive remedy for third-party claims of infringement or misappropriation of Intellectual Property Rights.
7. LIMITATION OF LIABILITY
7.1 Exclusion of Damages. TO THE FULLEST EXTENT PERMITTED BY LAW, NEITHER PARTY WILL BE LIABLE FOR ANY (a) LOST PROFITS OR REVENUE, (b) LOSS OF GOODWILL, (c) LOSS OR CORRUPTION OF DATA, (d) LOSS ARISING FROM INACCURATE OR UNEXPECTED RESULTS FROM USE OF THE TECHNOLOGY AND SERVICES, INCLUDING BUT NOT LIMITED TO ANY UNEXPECTED OUTPUT FROM THE TECHNOLOGY AND SERVICES, OR (e) INDIRECT, INCIDENTAL, SPECIAL, PUNITIVE, COVER, BUSINESS INTERRUPTION, OR CONSEQUENTIAL DAMAGES, REGARDLESS OF WHETHER ADVISED OF THE POSSIBILITY OF SUCH DAMAGES OR IF A PARTY’S REMEDY OTHERWISE FAILS ITS ESSENTIAL PURPOSE.
7.2 General Cap. EXCEPT FOR THE UNCAPPED MATTERS IN SECTION 7.3, EACH PARTY’S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATED TO THIS AGREEMENT WILL NOT EXCEED THE TOTAL FEES PAID OR PAYABLE BY CUSTOMER UNDER THE APPLICABLE ORDER DURING THE TWELVE (12) MONTHS PRECEDING THE FIRST INCIDENT GIVING RISE TO THE LIABILITY (THE “GENERAL CAP”). WHERE A CLAIM ARISES FROM OR RELATES TO MORE THAN ONE ORDER, THE GENERAL CAP IS CALCULATED BY REFERENCE TO THE FEES PAID OR PAYABLE UNDER ALL SUCH ORDERS DURING THAT PERIOD. EACH PARTY’S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATED TO PROFESSIONAL SERVICES (INCLUDING ANY DELIVERABLES OR OTHER WORK PRODUCT) WILL NOT EXCEED THE TOTAL FEES PAID OR PAYABLE BY CUSTOMER UNDER THE APPLICABLE ORDER FORM REFERENCING THE APPLICABLE SOW.
7.3 Uncapped Matters. NOTHING IN THIS AGREEMENT LIMITS LIABILITY FOR (a) FRAUD OR FRAUDULENT MISREPRESENTATION; (b) WILLFUL MISCONDUCT; (c) CUSTOMER’S PAYMENT OBLIGATIONS; (d) FINES OR PENALTIES IMPOSED BY A GOVERNMENTAL OR REGULATORY AUTHORITY, AND THE REASONABLE COSTS OF RESPONDING TO THE PROCEEDING THAT IMPOSES THEM, IN EACH CASE TO THE EXTENT ARISING DIRECTLY FROM CUSTOMER’S OWN VIOLATION OF APPLICABLE DATA PROTECTION, PRIVACY, OR OTHER LAWS GOVERNING CUSTOMER DATA (INCLUDING A BREACH OF SECTION 2.2(d), SECTION 2.2(e), OR SECTION 5.3(a)), WHICH REMAIN UNCAPPED WITHIN CUSTOMER’S INDEMNIFICATION FOR A DATA CLAIM; ALL OTHER LIABILITY UNDER CUSTOMER’S INDEMNIFICATION FOR A DATA CLAIM IS SUBJECT TO THE GENERAL CAP; (e) A PARTY’S INFRINGEMENT OF THE OTHER’S INTELLECTUAL PROPERTY RIGHTS (OTHER THAN ANY CLAIM THAT SECTION 3.3(f) GOVERNS); OR (f) LIABILITY THAT CANNOT BE LIMITED BY LAW.
7.4 Free Services. TO THE MAXIMUM EXTENT PERMITTED UNDER LAW, MULHOLLAND PROVIDES THE FREE SERVICES “AS-IS” WITHOUT ANY WARRANTY OR GUARANTY OF ANY KIND AND SHALL NOT HAVE ANY INDEMNIFICATION OBLIGATIONS OR LIABILITY FOR ANY FREE SERVICES. IN THE EVENT MULHOLLAND CANNOT EXCLUDE LIABILITY FOR FREE SERVICES UNDER APPLICABLE LAW, THEN ITS MAXIMUM LIABILITY FOR THE FREE SERVICES SHALL NOT EXCEED $500. MULHOLLAND DOES NOT REPRESENT OR WARRANT CUSTOMER’S USE OF THE FREE SERVICES WILL BE UNINTERRUPTED, TIMELY, SECURE FROM ERROR, ACCURATE, OR MEET CUSTOMER’S REQUIREMENTS. CUSTOMER IS SOLELY RESPONSIBLE FOR ANY DAMAGES ARISING OUT OF ITS USE OF THE FREE SERVICES.
8. FEES
8.1 Fees. Customer will pay all Fees set forth in the applicable Order. Except as otherwise specified in an Order, Fees are stated and payable in U.S. Dollars, are non-cancelable and non-refundable except as expressly provided herein, and invoices are due within thirty (30) days of the invoice date. All amounts due under an Order will be paid in full without set-off, counterclaim, deduction, or withholding, except as required by law.
8.2 Late Payment. Undisputed amounts not paid when due accrue interest at the lesser of one and one-half percent (1.5%) per month or the maximum rate permitted by law. Customer is responsible for applicable sales, use, or value-added taxes, excluding taxes on Mulholland’s net income.
8.3 Invoice Disputes. If Customer reasonably and in good faith disputes any portion of an invoice, Customer must provide written notice to Mulholland within thirty (30) days of the invoice date, detailing the nature of the dispute. If Customer fails to notify Mulholland within this period, the invoice will be deemed accurate and undisputed. The parties will work together in good faith to resolve any timely disputed amounts. Customer must pay all undisputed portions of the invoice in accordance with Section 8.1 (Fees).
9. SUSPENSION
Mulholland may suspend Customer’s access to the Platform (a) immediately if Mulholland reasonably believes Customer’s use violates Section 2.2 (Use Restrictions) in a manner that may cause material harm to Mulholland or a third party, or (b) following five (5) business days’ written notice of failure to pay undisputed, delinquent Fees. For purposes of clause (b), amounts that Customer has disputed in good faith and in accordance with Section 8.3 (Invoice Disputes) are not “undisputed” and may not serve as a basis for suspension while the dispute remains pending; this does not affect Mulholland’s right to suspend for failure to pay undisputed amounts or otherwise impact applicable cure period and termination rights.
10. TERM AND TERMINATION
10.1 Term. This Agreement begins on the Effective Date and continues until terminated in accordance with this Section (the “Term”). Each Order Form has the applicable Order Form term stated in it.
10.2 Termination for Convenience. Either party may terminate the Agreement on fifteen (15) days written notice if there are no active Order Forms outstanding.
10.3 Termination for Cause. Either party may terminate the Agreement if the other party materially breaches it and fails to cure within thirty (30) days after written notice. Either party may terminate immediately if the other becomes insolvent, makes an assignment for the benefit of creditors, or becomes subject to bankruptcy or similar proceedings not dismissed within thirty (30) days. Upon a termination resulting from Mulholland’s insolvency or cessation of business operations, Customer’s rights under Section 10.5 (Post-Termination Obligations) survive for a period of sixty (60) days.
10.4 Effect of Termination. Upon termination of this Agreement, all Orders terminate. Upon termination or expiration of an Order, Customer’s right to access the Platform under that Order ceases. If an Order is terminated by Customer for Mulholland’s uncured material breach, Mulholland will refund any unused, prepaid Fees for that Order.
10.5 Export; Post-Termination Obligations. The “Export Period” is the sixty (60) days that begin on the earlier of (1) the first date on which no Order Form or SOW is in effect and Mulholland is not providing Free Services to Customer, and (2) termination of the Agreement. If, after an Export Period begins, an Order Form or SOW takes effect or Mulholland begins or resumes providing Free Services, a new Export Period begins when clause (1) or (2) next applies, and, if that happens during the earlier Export Period or the thirty (30) days after it, the earlier Export Period is cancelled. While an Order Form or SOW is in effect or Mulholland is providing Free Services to Customer and, upon Customer’s written request, during the Export Period, Mulholland will make Customer Data, Customer Ontology, and Output available to Customer for export in commercially reasonable, machine-readable formats as described in its Documentation (for example, SQL or CSV exports of Customer Data and Output, and a schema export, data dictionary, and machine-readable ontology manifest for Customer Ontology). Export deliverables consist of the Customer-specific instance of such materials; any generic or domain-level Mulholland template, framework, or model that Customer Ontology references or was derived from is identified by name or version only and is not reproduced. The export right does not include, and nothing in this Agreement requires Mulholland to deliver, the Technology or Mulholland Materials or any information that would disclose Mulholland source code, prompts or system instructions, security architecture, or trade secrets. Customer may use exported materials itself and may provide them to a third-party service provider for Customer’s internal business purposes, without further obligation to Mulholland. While an Order Form or SOW is in effect, Mulholland may limit exports that require manual assistance to one per calendar quarter, in addition to any self-service export functionality the Platform provides. Where an export requires custom support or manual assistance beyond Mulholland’s standard export functionality, Mulholland will provide such services at its then-current professional services rates under a separate SOW executed by the parties. Within thirty (30) days after the Export Period ends, Mulholland will delete or return Customer Personal Data as Section 8.2 of the DPA provides and, as to Protected Health Information, subject to Section 5.3 of the Business Associate Agreement.
10.6 Survival. Sections 3 (Intellectual Property and Data Rights), 4 (Confidentiality), 5.4 (Disclaimer), 6 (Indemnification), 7 (Limitation of Liability), 8 (Fees and Payment, as to amounts accrued), 10 (Term and Termination), 11 (General), and 12 (Definitions), and any other provision that by its nature should survive, will survive termination.
11. GENERAL
11.1 Order of Precedence. This Agreement comprises this MSA, including any exhibits attached hereto, the DPA, any executed addenda, each SOW, and each Order Form. In the event of conflict, the order of precedence is: (a) the applicable Order or SOW (solely as to its subject matter), (b) any executed addendum (solely as to its subject matter), (c) the DPA (with regards to personal data), and (d) this MSA.
11.2 Dispute Resolution.
11.2.1 Governing Law. This Agreement is governed by the laws of the State of California, without regard to conflict-of-laws principles, and the United Nations Convention on Contracts for the International Sale of Goods does not apply.
11.2.2 Good Faith Resolution. The parties shall attempt in good faith to resolve any dispute arising out of or relating to this Agreement promptly by negotiation between executives who have authority to settle the controversy and who are at a higher level of management than the persons with direct responsibility for administration of this Agreement. Any party may give the other party written notice of any dispute not resolved in the normal course of business. Within 15 days after delivery of the notice, the receiving party shall submit to the other a written response. The notice and response shall include with reasonable particularity (a) a statement of each party's position and a summary of arguments supporting that position, and (b) the name and title of the executive who will represent that party and of any other person who will accompany the executive. Within 30 days after delivery of the notice, the executives of both parties shall meet at a mutually acceptable time and place. Unless otherwise agreed in writing by the negotiating parties, the above-described negotiation shall end at the close of the first meeting of executives described above ("First Meeting"). Such closure shall not preclude continuing or later negotiations, if desired. At no time prior to the First Meeting shall either side initiate an arbitration or litigation related to this Agreement except to pursue a provisional remedy that is authorized by law or by JAMS Rules or by agreement of the parties. However, this limitation is inapplicable to a party if the other party refuses to comply with the requirements of this section.
11.2.3 Arbitration. If the matter is not resolved by negotiation pursuant to the paragraphs above, then the matter will proceed to arbitration as set forth below. Any dispute, claim or controversy arising out of or relating to this Agreement or the breach, termination, enforcement, interpretation or validity thereof, including the determination of the scope or applicability of this agreement to arbitrate, shall be determined by arbitration in Los Angeles, California before one arbitrator. The arbitration shall be administered by JAMS pursuant to its Comprehensive Arbitration Rules and Procedures and in accordance with the Expedited Procedures in those Rules. Judgment on the Award may be entered in any court having jurisdiction. This clause shall not preclude parties from seeking provisional remedies in aid of arbitration from a court of appropriate jurisdiction. The parties shall maintain the confidential nature of the arbitration proceeding and the Award, including the Hearing, except as may be necessary to prepare for or conduct the arbitration hearing on the merits, or except as may be necessary in connection with a court application for a preliminary remedy, a judicial challenge to an Award or its enforcement, or unless otherwise required by law or judicial decision.
11.3 Assignment. Neither party may assign this Agreement without the other’s prior written consent, not to be unreasonably withheld, except that either party may assign it to a successor in connection with a merger, acquisition, or sale of substantially all assets upon written notice; provided that if such assignment is to a direct competitor of the non-assigning party, the non-assigning party may terminate this Agreement on written notice.
11.4 Publicity. Neither party will use the other’s name, logo, or marks in any publicly available publicity, press release, or customer reference without the other party’s prior written consent.
11.5 Independent Contractors. The parties are independent contractors. This Agreement creates no partnership, joint venture, agency, or employment relationship.
11.6 No Third-Party Beneficiaries. This Agreement is for the sole benefit of the parties and their permitted successors and assigns. Nothing in this Agreement, express or implied, confers any rights, remedies, or benefits on any other person, including any Authorized User or Affiliate, except as expressly provided herein.
11.7 Subcontractors and Subprocessors. Mulholland may engage third parties (including cloud infrastructure providers and model providers) to perform or support the Platform or Services. Mulholland remains responsible for the performance of its subcontractors and for ensuring they are bound by obligations consistent with this Agreement. The processing of Personal Data by Subprocessors, whether through the Platform or in performing Professional Services, is governed by the DPA.
11.8 Notices. Notices must be in writing and are effective when delivered to the email or address identified in the applicable Order, or, for legal notices to Mulholland, to the address above and a copy to legal@mulholland.ai.
11.9 Force Majeure. Neither party is liable for any delay or failure to perform (other than payment obligations) due to causes beyond its reasonable control, including acts of God, natural disasters, epidemics or pandemics, war, terrorism, civil unrest, labor disputes, governmental action, failures or outages of the internet or of third-party telecommunications, hosting, cloud-infrastructure, or model providers, and cyber events such as denial-of-service attacks (“Force Majeure Event”). The affected party will use commercially reasonable efforts to mitigate the effects of the event and resume performance.
11.10 Entire Agreement; Amendment. This Agreement is the complete and exclusive agreement between the parties regarding its subject matter and supersedes all prior or contemporaneous agreements. Any amendment or waiver must be in a writing signed by both parties. Customer has not relied on any promise regarding future functionality.
11.11 Severability; Waiver; Counterparts. If any provision is held unenforceable, it will be enforced to the maximum extent permissible, and the remainder will continue in effect. Failure to enforce a right is not a waiver. This Agreement may be executed in counterparts, including by electronic signature, each of which is deemed an original.
11.12 Export Control. Customer acknowledges that the Technology and Services acquired hereunder are subject to the export control laws and regulations of the United States, and any amendments thereof. Customer confirms that with respect to the Technology or Services, it will not export or re-export them, directly or indirectly, either to any countries or individuals that are subject to U.S. export restrictions or otherwise in violation of applicable law. Customer shall at its own expense obtain and maintain any governmental approval, consent, license or other authorization necessary for the performance of this Agreement.
11.13 Versions. Each Order Form is governed by the version of this MSA that it incorporates. This version governs an Order Form that incorporates an earlier version, or data received or generated under one, only if an amendment signed by both parties expressly so provides.
12. DEFINITIONS
12.1 “Affiliate” means any entity that controls, is controlled by, or is under common control with a party.
12.2 “Authorized User” means personnel of Customer or its Affiliates authorized by Customer to use the Platform.
12.3 “Confidential Information” means all information disclosed by a party that is marked confidential or that a reasonable person would understand to be confidential. For clarity, (i) Mulholland Confidential Information includes but is not limited to the Mulholland Materials, the Platform, Local Software, source code, prompts and system instructions, non-public technical, security, and performance information, and the terms of this Agreement, including any Order Form; and (ii) Customer Confidential Information includes but is not limited to Customer Data, Customer Ontology, and Output. Confidential Information does not include information that the receiving party can demonstrate (a) is or becomes public through no fault of the receiving party, (b) was rightfully known to it without confidentiality obligations before disclosure, (c) is rightfully received from a third party without confidentiality obligations, or (d) is independently developed without use of the disclosing party’s Confidential Information.
12.4 “Customer Data” means data, content, documents, policies, procedures, business rules, and other materials that Customer or its Authorized Users submit to or make available to the Platform or to Mulholland in connection with the Services (including data Input into any generative AI features, and data Mulholland accesses from Customer’s systems at Customer’s direction).
12.5 “Documentation” means Mulholland’s then-current user documentation for the Platform.
12.6 “DPA” means the Data Processing Addendum incorporated into this Agreement, attached hereto as Exhibit B.
12.7 “Feedback” means suggestions or feedback regarding the Technology and Services that Customer chooses to provide. Corrections, ratings, edits, and labels that Authorized Users make to Output or other Source Data, and any Customer Data, Customer Ontology, or Output included in Feedback, are not Feedback; Mulholland may use them only as Sections 3.3 and 3.5 permit.
12.8 “Fees” means all amounts payable for the Technology and Services as set forth in an Order.
12.9 “Free Services” means any free trial, beta, preview or any other services provided to Customer free of charge.
12.10 “Intellectual Property Rights” means all worldwide intellectual property rights, including rights in patents, copyrights, trademarks, trade secrets, know-how, and databases.
12.11 “Local Software” means the Mulholland software provided to Customer for local installation to link Customer Data to the Platform.
12.12 “Mulholland Materials” means software, sample code, templates, tools, know-how, processes, methodologies, configurations, performance evaluation materials and methodologies, templates, ontology frameworks, generic and domain-level ontologies, schemas, models, skills, workflows, agents, connectors, prompts and system instructions, evaluation materials, Generalized Improvements, and other materials used, created, or delivered by Mulholland in connection with the Technology and Services, including but not limited to any information, tools, materials, or intellectual property that Mulholland developed or owned before the Effective Date or developed after the Effective Date. For clarity, Mulholland Materials exclude Customer Data, Customer Ontology, Output, and Customer Confidential Information (including the values, parameters, and business inputs a Customer supplies).
12.13 “Non-Mulholland Services” means third party services and technology which may connect to the Local Software or Platform.
12.14 “Order Form” means an order form or similar ordering document setting forth the Technology and Services subscribed to by Customer.
12.15 “Output” means the business results, content, records, reports, analyses, determinations, communications, and other information generated by the Platform for Customer using Customer Data or Customer Ontology in response to Authorized User inputs or Customer-configured workflows. Output does not include the Technology or Mulholland Materials — including any source code, object code, agents, skills, workflows, connectors, models, prompts or system instructions, evaluation materials, platform configurations, or technical specifications — even where generated or produced by the Platform in the course of operating it for Customer.
12.16 “Personal Data” has the meaning given in the DPA.
12.17 “Platform” means Mulholland’s proprietary software as a service platform and services as described in an Order Form.
12.18 “Professional Services” means the configuration, integration, and onboarding services, and the billing and revenue-cycle services (such as eligibility and benefits verification, claims preparation and submission, payment posting, denial and appeal follow-up, and payer and patient balance follow-up), agreed to in an Order Form or SOW.
12.19 “Representatives” means a party’s employees, Affiliates, agents, advisors, and subcontractors.
12.20 “Services” means the Professional Services and support services by Mulholland under an Order or SOW, excluding Free Services.
12.21 “Technology” means the Platform and Local Software, including but not limited to application programming interfaces (APIs), software development kits (SDKs), integrations, software, and other technology provided by Mulholland to Customer, including any updates to the same.
12.22 “Customer Ontology” means the Customer-specific representation of Customer’s business, operations, and Customer Data as modeled or configured within the Platform for Customer, consisting of Customer’s instance-specific database schemas, tables, object and relationship definitions, properties and field definitions, identifiers, taxonomies, mappings, data dictionaries, and the business rules, policies, values, parameters, and other business inputs supplied or stated by Customer, in each case as they relate to Customer. Customer Ontology does not include (i) the Technology; (ii) Mulholland’s generic or domain-level ontology frameworks, templates, schemas, object or relationship models, or other structures that do not contain Customer Data or Customer Confidential Information and are capable of use independently of Customer, whether developed before or during the Term; or (iii) other Mulholland Materials, including skills, workflows, agents, connectors, prompts and system instructions, evaluation materials, and the operating parameters, thresholds, and configurations that Mulholland derives or calibrates in operating the Platform (as distinct from the business rules and inputs Customer supplies).
12.23 “Generalized Improvements” means improvements, enhancements, modifications, abstractions, techniques, methods, tools, templates, and other reusable technology or know-how that Mulholland develops or learns in the course of providing the Technology or Services, to the extent they do not contain or disclose Customer Data, Customer Ontology, Output, or Customer Confidential Information. Generalized Improvements are Mulholland Materials. Generalized Improvements do not include any model weight, adapter, head, embedding, example, evaluation set, label or answer vocabulary, or statistical rule, parameter, or threshold that is trained, fine-tuned, or calibrated on, or computed from, Source Data that is not De-Identified Data, or any artifact that contains values copied from that Source Data; Section 3.3(d)(vii) governs their use.
12.24 “De-Identified Data” means information derived from Source Data (as defined in Section 3.3) that does not identify, and cannot reasonably be used to infer information about or otherwise be linked to, Customer, any Authorized User, any client or patient of Customer (whether an individual or a business), or any other individual or household, and that meets, as applicable: (a) for Protected Health Information, the standard in 45 C.F.R. § 164.514(a)–(c), as Section 3.4 of the Business Associate Agreement provides; (b) for personal information subject to the California Consumer Privacy Act, the requirements of Cal. Civ. Code § 1798.140(m) (or, for aggregated information, the definition of aggregate consumer information in § 1798.140(b)); and (c) for other personal data, the de-identification requirements of applicable data protection law. De-Identified Data includes aggregated and statistical information that meets this definition. Records of dataset sources that Mulholland keeps separately and under restricted access, as described in Annex B of the DPA, do not cause information to fail this definition. Information ceases to be De-Identified Data if it is re-identified.
12.25 “Mulholland Models” means machine-learning and other artificial-intelligence models that Mulholland develops, trains, fine-tunes, or evaluates, in whole or in part, using De-Identified Data, including their weights, adapters, classifier heads, embeddings, prompts, examples, skills, calibration parameters and thresholds, learned rules and statistics, and evaluation sets, and all improvements and derivatives of them. Mulholland Models are Mulholland Materials. They do not include any third-party model except to the extent of Mulholland’s modifications to it, or any model described in the last sentence of Section 3.3(d)(vii). No model, and no weight, adapter, head, example, vocabulary, rule, statistic, threshold, or other component, that was trained, fine-tuned, or calibrated on Source Data that was not De-Identified Data when used (including Source Data that Mulholland first received before the date Section 3.3(a) specifies) is, or becomes through later evaluation, improvement, or combination with De-Identified Data, a Mulholland Model; each is a model described in the last sentence of Section 3.3(d)(vii). This sentence does not apply to records that Section 3.3(e) requires Mulholland to remove, and a Customer-only adapter, calibration, or threshold that Mulholland derives from Customer’s Source Data to serve Customer does not change the status of any Mulholland Model it adapts.
12.26 “Business Associate Agreement” means the business associate agreement between the parties that an Order Form incorporates, in the version it incorporates.
12.27 “Protected Health Information” has the meaning given in 45 C.F.R. § 160.103.
12.28 “Professional Services Terms” means Mulholland’s Professional Services Terms in the version an Order Form incorporates.
By signing below, each party agrees to the terms of this Master Services Agreement:
|
MULHOLLAND, INC. Signature Name Title Date |
CUSTOMER [official company name] Signature Name Title Date |
EXHIBIT A – STANDARD SUPPORT SERVICES
This Service Level Agreement (the “SLA”) describes Mulholland’s availability and support commitments for the Platform applicable to Customer’s use of the Service in accordance with the Agreement. It applies to the production Platform and does not apply to non-production environments, Free Services, Local Software, or Professional Services.
1. Definitions
1.1 “Available” means the production Platform is materially accessible and operational for Customer’s Authorized Users.
1.2 “Downtime” means a period during which the production Platform is not Available, measured in minutes, excluding Excluded Events.
2. Availability Commitment. Mulholland will use commercially reasonable efforts to make the production Platform Available with a monthly uptime percentage of at least 99.5% during each calendar month (the “Uptime Commitment”). Availability and Monthly Uptime Percentage are measured on a per-Customer tenant basis.
3. Excluded Events The Availability Commitment does not apply to, and Downtime does not include, unavailability caused by: (a) scheduled maintenance for which Mulholland provides reasonable advance notice and emergency maintenance reasonably required to protect the security or integrity of the Platform; (b) factors outside Mulholland’s reasonable control, including a Force Majeure Event and failures or outages of third-party telecommunications, hosting, cloud-infrastructure, or model providers; (c) Customer’s or its Authorized Users’ acts or omissions, equipment, software, or network connections, or use of the Platform other than in accordance with the Documentation; (d) suspension or termination of Customer’s access in accordance with the Agreement; or (e) usage of Free Services.
4. Support. Mulholland will provide technical support for the production Platform. Customer may submit support requests by email to the address designated by Mulholland. Mulholland will use commercially reasonable efforts to promptly respond during Mulholland’s normal business hours.
EXHIBIT B – DATA PROCESSING ADDENDUM
This Data Processing Addendum, including its Annexes (this “DPA”), is incorporated into and forms part of the agreement between the parties set forth in the Order Form incorporating the MSA (the “Agreement”) between Mulholland, Inc. (“Mulholland”) and the Customer identified in the Order Form (“Customer”), and applies to the extent Mulholland processes Customer Personal Data in connection with the Technology and Services. Capitalized terms not defined here have the meaning given in the Agreement. For purposes of this DPA, “Customer” includes Customer and its Authorized Affiliates.
1. Definitions
1.1 “Authorized Affiliate” means a Customer Affiliate authorized to use the Platform under the Agreement that has not signed its own separate agreement with Mulholland.
1.2 “CCPA” means the California Consumer Privacy Act of 2018, as amended (including by the California Privacy Rights Act), Cal. Civ. Code § 1798.100 et seq.
1.3 “Customer Personal Data” means any personal data or personal information contained within Customer Data that Mulholland processes on Customer’s behalf in providing the Platform.
1.4 “Data Protection Laws” means all data protection and privacy laws applicable to a party in its role in processing Customer Personal Data under the Agreement, which may include the CCPA.
1.5 “Security Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of, or access to, Customer Personal Data.
1.6 “Subprocessor” means any processor engaged by Mulholland to process Customer Personal Data.
1.7 “Trust Center” means Mulholland’s Trust Center available at: https://trust.mulholland.ai/.
The terms “controller,” “processor,” “data subject,” “process,” “processing,” “personal data,” and “supervisory authority” have the meanings given under Data Protection Laws. For the CCPA, “controller” includes “business,” “processor” includes “service provider,” “personal information” refers to such within “Customer Personal Data”, and “data subject” includes “consumer.”
2. Processing of Personal Data
2.1 Roles. This DPA applies where Mulholland processes Customer Personal Data as a processor (or service provider) in providing the Platform, as applicable. Customer acts as a controller (or business) or, where applicable, as a processor on behalf of a third-party controller.
2.2 Customer Obligations. Customer will (a) comply with Data Protection Laws in its processing of Customer Personal Data and in any instructions it issues to Mulholland, and (b) ensure it has provided all notices and obtained all consents and rights necessary for Mulholland to process Customer Personal Data in accordance with the Agreement.
2.3 Mulholland Obligations. When processing Customer Personal Data as a processor, Mulholland will (a) comply with Data Protection Laws applicable to its provision of the Platform, (b) process Customer Personal Data only to provide the Platform, to create De-Identified Data under Section 2.5, and otherwise in accordance with Customer’s documented instructions (including as set out in the Agreement, this DPA, or as directed through the Platform), and (c) notify Customer if, in its reasonable opinion, an instruction infringes Applicable Data Protection Laws. Mulholland is not responsible for determining whether Customer’s instructions are lawful.
2.4 Details of Processing. The subject matter, nature, purpose, duration, categories of data subjects, and categories of personal data are described in Annex A.
2.5 De-identification. Customer instructs Mulholland to create De-Identified Data (as defined in the MSA) from Customer Personal Data, in the manner Section 3.3 of the MSA requires, for the specific business purposes of (i) undertaking internal research for technological development and demonstration (Cal. Civ. Code § 1798.140(e)(7)) and (ii) building and improving the quality of the Platform and Services, in each case by developing, training, and evaluating machine-learning models using only the resulting De-Identified Data. Mulholland’s later use and disclosure of De-Identified Data, including in Mulholland Models made available to others, relies on Cal. Civ. Code § 1798.145(a)(1)(F) and 11 C.C.R. § 7050(a)(5). Customer discloses Customer Personal Data to Mulholland only for the limited and specified business purposes in Section 2.3(b), this Section 2.5, and Annex A. Mulholland creates De-Identified Data as Customer’s processor (or service provider). Section 2.2 and the last sentence of Section 2.3 do not apply to this de-identification, and Mulholland is responsible for its lawfulness, including any consent that applicable law requires for it. For purposes of this DPA, Customer Personal Data includes personal data in any Source Data (as defined in the MSA). De-Identified Data is not Customer Personal Data, and Sections 2.3(b), 8, and 9 do not restrict Mulholland’s retention, use, or disclosure of it under Section 3.3 of the MSA. Working copies made to create De-Identified Data, and any code or key that could re-identify it, remain Customer Personal Data. This instruction is a term of the Agreement for as long as Section 3.3(a) of the MSA permits Mulholland to create De-Identified Data; it may be withdrawn or changed only by a written amendment signed by both parties that expressly refers to Section 3.3 of the MSA, and not by any instruction given through the Platform or otherwise. De-identification in accordance with this Section 2.5 and Section 3.3 of the MSA is an authorized use for purposes of Section 9.
3. Confidentiality of Processing. Mulholland will ensure that personnel authorized to process Customer Personal Data are bound by an appropriate duty of confidentiality.
4. Sub-processors.
4.1 Authorization. Customer provides a general authorization for Mulholland to engage Subprocessors to process Customer Personal Data, including those identified in Mulholland’s then-current subprocessor list (the “Subprocessor List”), made available through the Trust Center.
4.2 Subprocessor Obligations. Mulholland will (a) impose written data protection obligations on each Subprocessor that are no less protective than those in this DPA, and (b) subject to the limitations of liability in the MSA, remain liable for each Subprocessor’s acts and omissions to the same extent Mulholland would be liable if performing the services itself.
4.3 Changes to Subprocessors. Mulholland will publish any addition to the Subprocessor List on the Trust Center and will give Customer at least thirty (30) days’ prior notice — by email to Customer’s notice contact or through the Trust Center’s subscription mechanism — before a new Subprocessor processes Customer Personal Data. Customer may object in writing within that period on reasonable, documented data-protection grounds. The parties will work in good faith to resolve the objection; if they cannot within thirty (30) days, Customer may terminate the affected Order Form on written notice and receive a refund of any prepaid, unused Fees for the affected Platform, as its sole remedy. A change to a Subprocessor’s own infrastructure, or a change that does not alter the categories of Customer Personal Data processed or the processing location, is not an addition for this purpose.
5. Assistance to Customer
5.1 Data Subject Requests. Taking into account the nature of the processing and to the extent legally required by Mulholland, Mulholland will provide reasonable assistance (including through Service functionality) to enable Customer to respond to a legally required request. If a request is made directly to Mulholland, Mulholland will forward it to Customer and will not respond directly except to refer the individual to Customer, unless legally required.
5.2 DPIAs. Mulholland will provide reasonably requested information to assist Customer with data protection impact assessments and related consultations with regulatory authorities, to the extent Customer does not otherwise have access to the relevant information.
5.3 Legal Requests. If Mulholland receives a legal demand from a public authority seeking Customer Personal Data, Mulholland will make reasonable efforts to redirect the authority to Customer and, if compelled to disclose, will give Customer reasonable prior notice unless legally prohibited.
6. Security
6.1 Security Measures. Mulholland will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data, as described in Annex B and its Trust Center. Mulholland may update these measures in its sole discretion provided the updates do not materially diminish the overall security of Customer Personal Data.
6.2 Breach Notification. Mulholland will notify Customer in writing without undue delay, and in any event within the shorter of seventy-two (72) hours after confirming a Security Breach and any shorter period that applicable law requires of Mulholland, and will take reasonable steps to contain, investigate, and mitigate it. Mulholland will reasonably cooperate with Customer regarding any legally required notifications to authorities or data subjects.
7. Audits and Records
7.1 Audit Materials. Upon written request and subject to confidentiality terms, Mulholland will provide documentation reasonably evidencing its compliance with this DPA, in the form of the certifications or audit reports identified in Annex B.
7.2 Audit. Only to the extent Customer cannot reasonably verify compliance through such materials, or where otherwise required by Applicable Data Protection Laws, Customer (or its qualified third-party auditor bound by confidentiality) may audit Mulholland’s relevant controls through written documentation requests no more than once annually, on reasonable prior notice and at a mutually agreed scope, time, and duration. Customer will promptly notify Mulholland of any audit results. Audit results are Mulholland’s Confidential Information.
8. Return and Deletion
8.1 During Term. Customer may retrieve or delete Customer Personal Data using any Platform functionality Mulholland may make available for this purpose during the term. Mulholland will delete Customer Personal Data from the Platform upon Customer’s instruction through such functionality.
8.2 On Termination. Within thirty (30) days after the Export Period (as defined in Section 10.5 of the MSA) ends, Mulholland will delete Customer Personal Data (or, if Customer so requests in writing during the Export Period, return it to Customer and then delete it) and require its Subprocessors to delete it, except for copies that applicable law requires Mulholland or a Subprocessor to retain and copies held in routine backups, which remain protected under this DPA until deleted and which Mulholland will use only for the purpose for which they are retained.
9. CCPA
With respect to Customer Personal Data subject to the CCPA, Mulholland acts as a service provider. To the extent required of Mulholland under the CCPA, Mulholland will not (a) “sell” or “share” “personal information” (as such terms are defined under the CCPA); (b) retain, use, or disclose personal information for any purpose other than the business purposes specified in Sections 2.3(b) and 2.5 and Annex A, or as otherwise permitted by the CCPA; (c) retain, use, or disclose personal information outside the direct business relationship between the parties; or (d) combine personal information with personal information from other sources except as permitted by the CCPA. Mulholland certifies that it understands and will comply with these restrictions. Mulholland will provide the same level of privacy protection as is required of Customer by the CCPA and its implementing regulations, and will notify Customer without undue delay if Mulholland determines that it can no longer meet its obligations under the CCPA or this DPA. Customer has the right, upon notice, to take reasonable and appropriate steps to help ensure that Mulholland uses Customer Personal Data in a manner consistent with Mulholland’s obligations under the CCPA, and to stop and remediate any unauthorized use of personal information within Customer Personal Data.
10. General
10.1 Precedence. This DPA supersedes any prior data processing terms between the parties for the Platform. In the event of conflict between this DPA and the MSA regarding the processing of Customer Personal Data, this DPA controls.
10.2 Affiliates. Mulholland’s obligations extend to Authorized Affiliates, provided that (a) Customer is responsible for communicating instructions on their behalf, (b) Customer is responsible for their compliance, and (c) any claim by an Authorized Affiliate must be brought by Customer on its behalf and is subject to the liability limitations in the Agreement.
10.3 Liability. Each party’s aggregate liability arising out of or related to this DPA is subject to the limitations of liability in the MSA.
10.4 Governing Law; Survival. This DPA is governed by the law and jurisdiction stated in the Agreement, unless Applicable Data Protection Laws require otherwise. This DPA survives for as long as Mulholland processes Customer Personal Data.
10.5 Amendments. The parties agree Mulholland may update this DPA from time-to-time as required to comply with Applicable Data Protection Laws.
Annex A. Description of Processing
|
Controller |
Customer, as identified in the Agreement. Role: controller or processor |
|
Processor |
Mulholland, Inc. Role: processor. Contacts: privacy@mulholland.ai; security@mulholland.ai |
|
Data subjects |
Individuals whose personal data is included in Customer Data, which may include Customer’s contacts, customers, prospects, vendors, business partners, and the employees or representatives of any of them, and Customer’s Authorized Users. |
|
Categories of data |
Determined and controlled by Customer, which may include name, contact details, business role, and any other personal data Customer includes in Customer Data. |
|
Sensitive data |
To be specified by Customer if applicable. |
|
Nature & purpose |
Provision of Mulholland’s hosted applied-AI platform and related services, including ingestion, structuring against the ontology, generation of Output, and any billing and revenue-cycle services, as described in the Agreement and applicable Orders/SOWs; and creation of De-Identified Data as instructed in Section 2.5. |
|
Duration |
The term of the Agreement and any post-termination period during which Mulholland processes Customer Personal Data in accordance with the Agreement. |
|
Frequency |
Continuous or one-off, depending on Customer’s use and subscription. |
Annex B. Security Schedule (Technical and Organizational Measures)
Mulholland maintains an information security program that includes the following measures designed to protect Customer Personal Data. Mulholland may update these measures provided they do not materially diminish the overall level of security.
|
Access control |
Role-based access controls with least-privilege provisioning; unique credentials for each user; prompt deprovisioning upon role change or departure; quarterly access reviews. |
|
Authentication |
Multi-factor authentication required for all administrative accounts and for remote access to systems processing Customer Personal Data; enforced use of a password manager for personnel. |
|
Encryption |
Encryption of Customer Personal Data at rest using AES-256 (or equivalent) and in transit using TLS 1.2 or higher. |
|
Tenant isolation |
Logical isolation of each Customer’s data within a multi-tenant environment: every Customer record carries an immutable tenant identifier and is protected by forced row-level security enforced by the database, so a Customer’s sessions may read and write only that Customer’s data. Named Mulholland engineering personnel may access data across tenants for support, operations, and security; that access is not used to export, combine, or de-identify Source Data, which only service identities bound to a single Customer do. Access is further separated by per-service database identities and least-privilege roles. Mulholland offers single-tenant or Customer-hosted deployment only where an Order Form or addendum expressly provides for it. |
|
Network security |
Firewalling, network segmentation, and monitoring of the production environment; restriction of administrative access to authorized personnel. |
|
Logging & monitoring |
Audit logging of access to systems processing Customer Personal Data; monitoring for anomalous or unauthorized activity. |
|
Vulnerability management |
Regular vulnerability scanning and patching; remediation of identified vulnerabilities prioritized by severity, with critical vulnerabilities targeted for remediation promptly upon validation. |
|
Personnel security |
Confidentiality obligations for all personnel with access to Customer Personal Data; security awareness training; background checks where permitted by law. |
|
Incident response |
A documented incident-response process supporting the breach-notification obligations in Section 6.2, including defined roles, escalation, and post-incident review. |
|
Secure development |
Change-management and code-review practices for changes to the Platform; separation of development and production environments. |
|
De-identification |
Mulholland does not create De-Identified Data from Customer’s Source Data until it has implemented, and then does so only through, a process that includes: de-identification performed as Section 3.3 of the MSA requires; removal or exclusion, before de-identification, of the data that Section 3.3(d)(x) of the MSA lists, including a check of each third-party source’s terms (such as a practice-management system’s API terms); for Protected Health Information, the method, minimum-necessary, and record-code rules in Section 3.4 of the Business Associate Agreement; records identifying, for each dataset used to develop Mulholland Models, the contributing customers and the agreement version and start date that governed their data, kept separately from De-Identified Data and accessible only to compliance personnel and, in confidence, Mulholland’s auditors and de-identification experts; access to De-Identified Data and model-training environments limited to authorized personnel; and deletion of working copies once the De-Identified Data is validated. |
Business Continuity and Recovery
|
Backups |
Regular encrypted backups of the production environment. |
|
Recovery Point Objective (RPO) |
Target: 24 hours. |
|
Recovery Time Objective (RTO) |
Target: 48 hours. |
|
Point In Time Recovery (PITR) |
7 Day retention of data for instant recovery |
Certifications and Audits
Mulholland maintains a HIPAA compliance program, with its administrative, physical, and technical safeguards monitored continuously through Vanta, and will enter into a Business Associate Agreement with Customer before it processes Customer’s Protected Health Information. Mulholland’s SOC 2 Type II examination is underway with an independent auditor, with its controls monitored continuously through Vanta; the current status of that examination, and of any additional framework Mulholland pursues, is published on the Trust Center. Pending issuance, Mulholland will make its security documentation, control descriptions, and completed security questionnaires available to Customer upon request, subject to confidentiality obligations. Upon issuance, Mulholland will make the resulting SOC 2 report (and any later certification) available to Customer upon request, subject to confidentiality obligations. Mulholland's HIPAA program documentation is available to Customer upon request, subject to confidentiality obligations.
Annex C. Subprocessors
Mulholland’s authoritative list of Subprocessors — each provider’s name, purpose, and processing location — is the Subprocessor List published on the Trust Center (Section 4.1), which is incorporated into this DPA by reference and kept current as providers change. As of the date this version was published, the Subprocessor List comprises Google Cloud Platform, OpenAI, TypeSafe, Cloudflare, Oxylabs, and Vanta, in the categories below. The revenue-cycle support contractor category below applies only where Customer’s Order Form or SOW includes billing and revenue-cycle services, and Mulholland will add each such contractor to the Subprocessor List before the contractor processes Customer Personal Data. Additions are subject to the notice and objection process in Section 4.3.
|
Category (current provider) |
Purpose |
Location |
|
Cloud infrastructure and model hosting (currently Google Cloud Platform) |
Compute, managed database, storage, key management, and secrets; Vertex AI as an alternate model provider |
United States |
|
Model providers (currently OpenAI as the default agent model; Google Vertex AI as alternate) |
Large-language-model inference over Customer Data, under contractual terms that prohibit training on it and limit retention |
United States |
|
Structured-judgment inference (currently TypeSafe) |
Classification and scoring over Customer Data, under contractual terms that prohibit training on it |
United States |
|
Serving edge (currently Cloudflare) |
DNS, web application firewall, and edge routing of application traffic, encrypted in transit |
Global |
|
Network egress for connector sessions (currently Oxylabs) |
Routing of encrypted sessions to third-party portals Customer directs Mulholland to access; the provider does not decrypt them |
United States |
|
Security and compliance monitoring (currently Vanta) |
Continuous control monitoring and audit evidence; receives system metadata, not Customer Data |
United States |
|
Revenue-cycle support contractors (individuals engaged by Mulholland under written confidentiality and, for Protected Health Information, subcontractor business associate terms) |
Billing and revenue-cycle services included in Customer’s Order Form or SOW |
Philippines |
Integrity hash (SHA-256 of source text): 1fac64813c180b37065b7e5893f508d4656572425bd9448ac49b7938ac3797cf