← Back to ilumeniq.com
Legal

Master Subscription Agreement

Last updated: June 25, 2025

MASTER SUBSCRIPTION AGREEMENT AND BUSINESS ASSOCIATE AGREEMENT

PLEASE READ THIS MASTER SUBSCRIPTION AGREEMENT AND BUSINESS ASSOCIATE AGREEMENT ("AGREEMENT") CAREFULLY BEFORE CREATING AN ACCOUNT OR ACCESSING THE ILUMENIQ PLATFORM.

BY CLICKING "I AGREE," "CREATE ACCOUNT," OR ANY EQUIVALENT BUTTON DURING THE ACCOUNT CREATION PROCESS, THE INDIVIDUAL COMPLETING REGISTRATION:

  1. AGREES TO THIS AGREEMENT ON BEHALF OF THE PRACTICE OR ORGANIZATION IDENTIFIED DURING ACCOUNT CREATION ("CUSTOMER");
  2. REPRESENTS AND WARRANTS THAT THEY HAVE THE LEGAL AUTHORITY TO BIND CUSTOMER TO THIS AGREEMENT;
  3. EXECUTES THE BUSINESS ASSOCIATE AGREEMENT SET FORTH IN ARTICLE 12 ON BEHALF OF CUSTOMER AS A COVERED ENTITY UNDER HIPAA; AND
  4. ACKNOWLEDGES THAT THIS AGREEMENT CONSTITUTES A LEGALLY BINDING CONTRACT BETWEEN CUSTOMER AND ILUMENIQ LLC.

IF YOU DO NOT HAVE AUTHORITY TO BIND CUSTOMER, OR IF CUSTOMER DOES NOT AGREE TO THESE TERMS, DO NOT COMPLETE ACCOUNT CREATION.


Notice Regarding the Business Associate Agreement: Article 12 of this Agreement constitutes a Business Associate Agreement ("BAA") as required under the Health Insurance Portability and Accountability Act ("HIPAA"). By accepting this Agreement, Customer, as a Covered Entity under HIPAA, is simultaneously executing the BAA with ilumenIQ as its Business Associate. ilumenIQ will process Protected Health Information on Customer's behalf only after this Agreement — including the BAA — has been accepted.

This Agreement is entered into as of the date Customer completes account creation and accepts this Agreement (the "Effective Date"), by and between:

ilumenIQ LLC, a North Carolina limited liability company with its principal place of business at 1235 East Blvd, Suite E519, Charlotte, NC 28203 ("ilumenIQ"); and

the practice or organization identified during account creation ("Customer").

ilumenIQ and Customer are each referred to herein individually as a "Party" and collectively as the "Parties."


ARTICLE 1 — DEFINITIONS

1.1 "Authorized Users" means individuals authorized by Customer to access and use the Platform on Customer's behalf, subject to the terms of this Agreement and the End User License Agreement.

1.2 "BAA" means the Business Associate Agreement provisions set forth in Article 12 of this Agreement.

1.3 "Customer Data" means all data, content, and information submitted to or processed through the Platform by or on behalf of Customer, including PHI.

1.4 "Documentation" means any user guides, technical specifications, and other materials provided by ilumenIQ describing the functionality and use of the Platform.

1.5 "EHR System" means any third-party electronic health record, practice management, or billing system used by Customer from which data is exported or otherwise transferred into the Platform.

1.6 "HIPAA" means the Health Insurance Portability and Accountability Act of 1996, the Health Information Technology for Economic and Clinical Health Act of 2009 ("HITECH"), and all implementing regulations and guidance issued thereunder, as amended from time to time.

1.7 "Intellectual Property Rights" means all patents, copyrights, trademarks, trade secrets, and other proprietary rights recognized by applicable law.

1.8 "PHI" means Protected Health Information as defined under HIPAA at 45 C.F.R. § 160.103, as applied to information created, received, maintained, or transmitted by ilumenIQ on behalf of Customer.

1.9 "Platform" means ilumenIQ's proprietary SaaS-based software platform for data aggregation, dashboarding, reporting, and practice management, including all updates, enhancements, and modifications thereto made available to Customer under this Agreement.

1.10 "Services" means access to and use of the Platform and any related support or professional services provided by ilumenIQ under this Agreement.

1.11 "Subscription Plan" means the subscription tier, billing cycle (annual or month-to-month), and associated features selected by Customer during account creation, as displayed on the plan selection screen at signup and as may be updated from time to time in accordance with this Agreement.

1.12 "Subscription Term" means the period during which Customer is authorized to access and use the Platform under the selected Subscription Plan, commencing on the Effective Date and continuing until terminated in accordance with this Agreement.


ARTICLE 2 — ACCESS AND LICENSE

2.1 License Grant. Subject to the terms and conditions of this Agreement and payment of applicable Subscription Fees, ilumenIQ hereby grants Customer a limited, non-exclusive, non-transferable, non-sublicensable right and license to access and use the Platform during the Subscription Term solely for Customer's internal business operations and in accordance with the Documentation.

2.2 Authorized Users. Customer may permit its Authorized Users to access and use the Platform. Customer is responsible for ensuring that all Authorized Users comply with this Agreement and the End User License Agreement, which each Authorized User must accept upon first login. Customer shall promptly revoke access for any Authorized User who is no longer employed by or affiliated with Customer or who violates this Agreement or the End User License Agreement.

2.3 Restrictions. Customer shall not, and shall ensure that Authorized Users do not:

(a) sublicense, sell, resell, transfer, assign, or otherwise make the Platform available to any third party;

(b) modify, translate, adapt, or create derivative works based upon the Platform;

(c) reverse engineer, disassemble, decompile, or otherwise attempt to derive the source code of the Platform;

(d) access the Platform for purposes of building a competitive product or service or benchmarking against a competitive product;

(e) use the Platform to store or transmit infringing, defamatory, unlawful, or tortious material;

(f) use the Platform to store or transmit malicious code, viruses, or other harmful software;

(g) interfere with or disrupt the integrity or performance of the Platform or any data contained therein;

(h) attempt to gain unauthorized access to the Platform, its related systems, or networks; or

(i) use any automated script, bot, scraper, or similar tool to access or interact with the Platform in a manner not expressly authorized by ilumenIQ in writing.

2.4 EHR and Third-Party Systems. Customer is solely responsible for ensuring that its use of any EHR System or other third-party platform in connection with the Services — including any data export, integration, or transfer of data from such systems into the Platform — complies with all applicable terms of service, license agreements, and legal requirements governing such systems. ilumenIQ makes no representation that its Services are authorized under or compatible with any particular EHR System's terms of service. Customer shall indemnify and hold harmless ilumenIQ from any claim, loss, or liability arising from Customer's violation of any third-party agreement in connection with its use of the Services.

2.5 Automated Export Authorization.

(a) Scope. Where a direct API or native data connection between the Platform and an EHR System or third-party platform is not available, Customer may authorize ilumenIQ to perform automated report exports from such system on Customer's behalf (an "Automated Export"). Automated Exports are a limited fallback mechanism used solely where direct data connections are unavailable, and are performed using credentials and access rights provided by Customer.

(b) Customer Authorization. Automated Export authorization is granted by Customer on a per-system basis through a separate in-product confirmation step during connection setup. By completing that confirmation, Customer:

(i) explicitly authorizes ilumenIQ to perform Automated Exports from the identified system acting on Customer's behalf and using Customer-provided credentials or access;

(ii) represents and warrants that Customer has reviewed the terms of service and license agreement governing the identified system and has determined, in Customer's reasonable judgment, that such authorization is permitted thereunder;

(iii) acknowledges that ilumenIQ is acting solely as Customer's authorized agent in performing the Automated Export, and that all activity conducted pursuant to such authorization is deemed Customer's own activity under the applicable third-party system's terms; and

(iv) agrees to promptly revoke Automated Export authorization through the Platform if Customer's determination in clause (ii) above changes or if Customer's rights under the applicable third-party agreement are modified or terminated.

(c) ilumenIQ's Role. In performing Automated Exports, ilumenIQ acts solely at Customer's direction and on Customer's behalf. ilumenIQ does not independently assess whether Automated Export is permitted under any particular EHR System's terms of service. ilumenIQ performs Automated Exports using the minimum access and frequency necessary to deliver the Services — limited to the report types and schedules configured by Customer.

(d) Customer Responsibility. Customer bears sole responsibility for ensuring that any Automated Export authorization it grants is permitted under applicable third-party agreements and applicable law. ilumenIQ shall have no liability arising from Customer's grant of an Automated Export authorization that violates a third-party agreement, and Customer shall indemnify and hold harmless ilumenIQ from any claim, loss, or liability arising therefrom.

(e) Revocation. Customer may revoke an Automated Export authorization at any time through the Platform's connection management settings. Revocation takes effect promptly upon Customer's action and does not affect any exports already completed prior to revocation.

2.6 Reservation of Rights. ilumenIQ reserves all rights not expressly granted in this Agreement. No licenses are granted by implication.


ARTICLE 3 — SUBSCRIPTION PLAN, FEES, AND PAYMENT

3.1 Subscription Plan Selection. During account creation, Customer selects a Subscription Plan specifying the applicable features, billing cycle, and Subscription Fees. The Subscription Plan selected at signup is incorporated into and made a part of this Agreement. Customer may change its Subscription Plan subject to availability and any applicable pricing adjustments, effective at the start of the next billing cycle.

3.2 Subscription Fees. Customer agrees to pay ilumenIQ the Subscription Fees associated with Customer's selected Subscription Plan as displayed at signup and as may be adjusted in accordance with Section 3.6. All fees are stated in U.S. dollars and are non-refundable except as expressly set forth in this Agreement.

3.3 Billing and Payment.

(a) Annual Subscriptions. Subscription Fees for annual plans are billed in advance at the start of each Subscription Term and each renewal term. Payment is due upon billing.

(b) Month-to-Month Subscriptions. Subscription Fees for month-to-month plans are billed in advance at the start of each monthly billing cycle. Payment is due upon billing.

(c) Customer authorizes ilumenIQ to charge the payment method provided at account creation for all Subscription Fees as they become due. Customer is responsible for maintaining a valid payment method on file.

3.4 Taxes. Subscription Fees do not include any applicable sales, use, value-added, or other taxes. Customer is responsible for all such taxes, excluding taxes based on ilumenIQ's net income.

3.5 Late Payment. Amounts not paid when due will accrue interest at the rate of one and one-half percent (1.5%) per month (or the maximum rate permitted by applicable law, if less) from the due date until paid. ilumenIQ reserves the right to suspend access to the Platform upon thirty (30) days' written notice to Customer if any undisputed amounts remain past due.

3.6 Fee Adjustments. ilumenIQ may adjust Subscription Fees for any renewal Subscription Term upon at least sixty (60) days' prior written notice to Customer. Continued use of the Platform after the effective date of a fee adjustment constitutes Customer's acceptance of the adjusted fees.


ARTICLE 4 — SUBSCRIPTION TERM AND RENEWAL

4.1 Annual Subscriptions. Annual subscriptions automatically renew for successive one-year terms at the then-current Subscription Fees unless either Party provides written notice of non-renewal at least thirty (30) days before the end of the then-current Subscription Term.

4.2 Month-to-Month Subscriptions. Month-to-month subscriptions automatically renew on a monthly basis at the then-current Subscription Fees unless either Party provides written notice of non-renewal at least thirty (30) days before the end of the then-current monthly period.

4.3 Early Termination of Annual Subscriptions. Customer may not terminate an annual subscription for convenience prior to the end of the applicable Subscription Term. If Customer terminates an annual subscription early or if ilumenIQ terminates an annual subscription for Customer's breach, Customer shall remain liable for all Subscription Fees due through the end of the then-current Subscription Term. ilumenIQ may, at its sole discretion, elect to waive or reduce the remaining balance in exceptional circumstances.

4.4 Switching Plans. Customer may switch between annual and month-to-month billing, or between Subscription Plan tiers, at any time. Changes take effect at the start of the next billing cycle. Switching from an annual to a month-to-month plan mid-term is subject to Section 4.3.


ARTICLE 5 — CUSTOMER RESPONSIBILITIES

5.1 Account Security. Customer is responsible for maintaining the confidentiality of all account credentials and for all activities that occur under Customer's account, including activities of Authorized Users. Customer shall notify ilumenIQ promptly of any unauthorized access to or use of Customer's account.

5.2 Accuracy of Information. Customer is responsible for the accuracy, quality, and legality of all Customer Data submitted to the Platform and for the means by which Customer acquired such data.

5.3 HIPAA Compliance. Customer, as a Covered Entity under HIPAA, is solely responsible for compliance with all applicable HIPAA requirements, including obtaining all necessary patient authorizations, maintaining its own Notice of Privacy Practices, and ensuring its use of the Platform complies with the HIPAA Privacy Rule and Security Rule. ilumenIQ's status as a Business Associate does not relieve Customer of its own HIPAA obligations as a Covered Entity.

5.4 Compliance with Laws. Customer is responsible for complying with all applicable federal, state, and local laws and regulations in connection with its use of the Services, including applicable healthcare privacy and security laws.

5.5 Authority. The individual who accepted this Agreement on behalf of Customer represents and warrants on an ongoing basis that Customer is a validly existing legal entity and that Customer's acceptance and performance of this Agreement does not violate any applicable law or any agreement with a third party.


ARTICLE 6 — ILUMENIQ OBLIGATIONS

6.1 Service Availability. ilumenIQ will use commercially reasonable efforts to make the Platform available twenty-four (24) hours a day, seven (7) days a week, except for:

(a) scheduled maintenance windows, of which ilumenIQ will provide reasonable advance notice; and

(b) any unavailability caused by circumstances beyond ilumenIQ's reasonable control, including internet outages, third-party service failures, or force majeure events.

6.2 Security. ilumenIQ will implement and maintain commercially reasonable administrative, technical, and physical safeguards designed to protect Customer Data, including PHI, from unauthorized access, disclosure, or destruction. With respect to electronic PHI, ilumenIQ will comply with the HIPAA Security Rule requirements applicable to Business Associates.

6.3 Updates. ilumenIQ may update, modify, or enhance the Platform from time to time. ilumenIQ will use commercially reasonable efforts to provide advance notice of material changes that may affect Customer's use of the Platform.


ARTICLE 7 — INTELLECTUAL PROPERTY

7.1 ilumenIQ Ownership. ilumenIQ retains all right, title, and interest in and to the Platform, the Services, the Documentation, and all Intellectual Property Rights therein. Customer acquires no ownership interest in any of the foregoing under this Agreement.

7.2 Customer Data Ownership. Customer retains all right, title, and interest in and to Customer Data. Customer grants ilumenIQ a limited, non-exclusive license to access, process, and use Customer Data solely to provide the Services and as otherwise permitted under this Agreement and the BAA.

7.3 Aggregated and De-identified Data. ilumenIQ may collect and use aggregated, anonymized, and de-identified data derived from Customer's use of the Platform ("Aggregated Data") for purposes of improving the Services, conducting research, and developing new features, provided that such Aggregated Data does not identify Customer or any individual patient or client. ilumenIQ owns all Aggregated Data.

7.4 Feedback. If Customer or any Authorized User provides ilumenIQ with suggestions, ideas, or feedback regarding the Services ("Feedback"), ilumenIQ may freely use such Feedback without restriction and without any obligation to Customer.


ARTICLE 8 — CONFIDENTIALITY

8.1 Definition. "Confidential Information" means any non-public information disclosed by one Party to the other that is designated as confidential or that reasonably should be understood to be confidential given the nature of the information and circumstances of disclosure. Customer Data (including PHI) is Customer's Confidential Information. ilumenIQ's pricing, platform architecture, and technical documentation are ilumenIQ's Confidential Information.

8.2 Obligations. Each Party agrees to: (a) use the other Party's Confidential Information only as necessary to fulfill its obligations or exercise its rights under this Agreement; (b) protect the other Party's Confidential Information using at least the same degree of care it uses to protect its own confidential information, but in no event less than reasonable care; and (c) not disclose the other Party's Confidential Information to any third party without prior written consent, except to employees, contractors, and service providers who have a need to know and are bound by confidentiality obligations at least as protective as those set forth herein.

8.3 Exceptions. Confidentiality obligations do not apply to information that: (a) is or becomes publicly available through no fault of the receiving Party; (b) was already known to the receiving Party at the time of disclosure; (c) is independently developed by the receiving Party without use of or reference to the disclosing Party's Confidential Information; or (d) is required to be disclosed by law, regulation, or court order, provided the receiving Party gives the disclosing Party prompt prior written notice and cooperates in seeking a protective order.

8.4 PHI. The treatment of PHI is governed exclusively by the BAA set forth in Article 12, which controls in the event of any conflict with this Article 8.


ARTICLE 9 — REPRESENTATIONS AND WARRANTIES

9.1 Mutual Representations. Each Party represents and warrants that: (a) it has full power and authority to enter into and perform this Agreement; (b) this Agreement has been duly authorized and constitutes a binding obligation; and (c) its execution and performance of this Agreement does not violate any applicable law or any agreement with a third party.

9.2 ilumenIQ Warranties. ilumenIQ represents and warrants that: (a) the Platform will perform materially in accordance with the Documentation; and (b) ilumenIQ will comply with all applicable laws in providing the Services, including HIPAA requirements applicable to Business Associates.

9.3 Customer Warranties. Customer represents and warrants that: (a) Customer has all necessary rights and authorizations to submit Customer Data to the Platform and to permit ilumenIQ to process it as described in this Agreement; (b) Customer will comply with all applicable laws in connection with its use of the Services, including all HIPAA requirements applicable to Covered Entities; and (c) Customer's use of the Services, including any integration with EHR Systems, complies with all applicable third-party terms of service and license agreements.

9.4 Disclaimer. EXCEPT AS EXPRESSLY SET FORTH IN SECTION 9.2, THE PLATFORM AND SERVICES ARE PROVIDED "AS IS" AND "AS AVAILABLE." ILUMENIQ EXPRESSLY DISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT. ILUMENIQ DOES NOT WARRANT THAT THE SERVICES WILL BE UNINTERRUPTED, ERROR-FREE, OR COMPLETELY SECURE. ILUMENIQ DOES NOT WARRANT THAT USE OF THE SERVICES WILL RESULT IN CUSTOMER'S COMPLIANCE WITH HIPAA OR ANY OTHER APPLICABLE LAW.


ARTICLE 10 — LIMITATION OF LIABILITY

10.1 Exclusion of Consequential Damages. IN NO EVENT WILL EITHER PARTY BE LIABLE TO THE OTHER FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, INCLUDING LOSS OF PROFITS, LOSS OF DATA, LOSS OF GOODWILL, BUSINESS INTERRUPTION, OR COST OF SUBSTITUTE SERVICES, ARISING OUT OF OR RELATED TO THIS AGREEMENT OR THE SERVICES, EVEN IF SUCH PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.

10.2 Cap on Liability. EACH PARTY'S TOTAL AGGREGATE LIABILITY TO THE OTHER ARISING OUT OF OR RELATED TO THIS AGREEMENT OR THE SERVICES, WHETHER IN CONTRACT, TORT (INCLUDING NEGLIGENCE), OR OTHERWISE, SHALL NOT EXCEED THE TOTAL SUBSCRIPTION FEES PAID BY CUSTOMER TO ILUMENIQ IN THE SIX (6) MONTHS IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO THE CLAIM.

10.3 Exceptions. The limitations in Sections 10.1 and 10.2 do not apply to: (a) Customer's payment obligations under Article 3; (b) either Party's indemnification obligations under Article 11; (c) either Party's confidentiality obligations under Article 8; (d) damages arising from a Party's gross negligence or willful misconduct; or (e) liability that cannot be limited under applicable law.


ARTICLE 11 — INDEMNIFICATION

11.1 By ilumenIQ. ilumenIQ will defend, indemnify, and hold harmless Customer from and against any third-party claim alleging that the Platform, as provided by ilumenIQ and used in accordance with this Agreement, infringes any U.S. patent, copyright, trademark, or trade secret, and will pay any damages, costs, and attorneys' fees awarded or agreed in settlement. This obligation does not apply if the alleged infringement results from: (a) Customer's modification of the Platform; (b) use of the Platform in combination with third-party products not approved by ilumenIQ; or (c) Customer's use of the Platform in violation of this Agreement.

11.2 By Customer. Customer will defend, indemnify, and hold harmless ilumenIQ from and against any third-party claim arising from: (a) Customer's breach of this Agreement, including any breach of Customer's representations and warranties; (b) Customer's or any Authorized User's use of the Services in violation of applicable law; (c) Customer's violation of any third-party agreement, including any EHR System terms of service, in connection with use of the Services; or (d) Customer's failure to comply with applicable HIPAA requirements as a Covered Entity.

11.3 Process. The indemnified Party must: (a) promptly notify the indemnifying Party in writing of the claim; (b) give the indemnifying Party sole control over the defense and settlement; and (c) provide reasonable assistance at the indemnifying Party's expense. The indemnifying Party may not settle any claim in a manner that imposes obligations on the indemnified Party without prior written consent.


ARTICLE 12 — BUSINESS ASSOCIATE AGREEMENT

This Article constitutes the Business Associate Agreement between Customer (as "Covered Entity") and ilumenIQ (as "Business Associate") required under HIPAA. By accepting this Agreement, Customer simultaneously executes this BAA.

12.1 Definitions

For purposes of this Article 12, the following terms have the meanings set forth in HIPAA:

Any ambiguity in this Article 12 shall be resolved in favor of a meaning that permits compliance with HIPAA.

12.2 Permitted Uses and Disclosures of PHI

12.2.1 Business Associate may use and disclose PHI only as necessary to provide the Services as described in this Agreement and as permitted by the Privacy Rule.

12.2.2 Business Associate may use PHI for its own proper management and administration or to carry out its legal responsibilities, provided that any disclosure for such purposes is either Required by Law or made only after Business Associate obtains reasonable assurances from the recipient that the PHI will be held confidentially.

12.2.3 Business Associate may de-identify PHI in accordance with 45 C.F.R. §§ 164.502(d) and 164.514(a)–(c) and may use de-identified data for any lawful purpose.

12.2.4 Where Covered Entity has granted an Automated Export authorization under Section 2.5, Business Associate may access and process PHI contained in reports exported from an EHR System or third-party platform pursuant to such authorization. All such access and processing is performed on behalf of and at the direction of Covered Entity, constitutes an authorized function under this BAA, and shall be subject to all applicable safeguards and restrictions set forth in this Article 12. Covered Entity, as the Covered Entity under HIPAA, is responsible for ensuring that any Automated Export authorization it grants is consistent with its HIPAA obligations, including applicable minimum necessary requirements.

12.2.5 Business Associate shall not use or disclose PHI for any purpose not described in this Article 12 or otherwise required by applicable law.

12.3 Business Associate Obligations

12.3.1 Safeguards. Business Associate shall implement and maintain appropriate administrative, technical, and physical safeguards to prevent unauthorized use or disclosure of PHI, and shall comply with the Security Rule and HITECH with respect to ePHI.

12.3.2 Minimum Necessary. Business Associate shall comply with HIPAA's Minimum Necessary requirements and shall use only the minimum PHI necessary to provide the Services.

12.3.3 Subcontractors. If Business Associate engages subcontractors that create, receive, maintain, or transmit PHI on Business Associate's behalf, Business Associate shall require each such subcontractor to agree to restrictions and conditions substantially similar to those imposed on Business Associate under this Article 12 through a written agreement.

12.3.4 Breach Notification. Business Associate shall notify Covered Entity of any Breach of Unsecured PHI of which Business Associate becomes aware, without unreasonable delay and in no case later than fifteen (15) business days after discovery. Notification shall include, to the extent available: (a) identification of individuals whose PHI was involved; (b) a description of the Breach, including date of occurrence and date of discovery; (c) a description of the types of PHI involved; (d) recommended steps for affected individuals; and (e) a description of Business Associate's investigation and remediation steps. Business Associate shall supplement initial notification as additional information becomes available.

12.3.5 Individual Access. To the extent Business Associate maintains PHI in a Designated Record Set, Business Associate shall provide access to such PHI to Covered Entity or, as directed by Covered Entity, to the applicable Individual, in accordance with 45 C.F.R. § 164.524. Given that ilumenIQ processes but does not persistently store PHI, this obligation applies only to the extent PHI remains accessible within the Platform at the time of the request.

12.3.6 Amendment. To the extent Business Associate maintains PHI in a Designated Record Set, Business Associate shall make amendments to such PHI as directed by Covered Entity in accordance with 45 C.F.R. § 164.526.

12.3.7 Accounting of Disclosures. Upon written request, Business Associate shall provide Covered Entity an accounting of disclosures of PHI in the manner and within the timeframes required by 45 C.F.R. § 164.528, with a minimum of ten (10) business days to respond.

12.3.8 Governmental Access. Business Associate shall make its internal policies, practices, and records relating to PHI available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining HIPAA compliance.

12.3.9 Individual Requests. If Business Associate receives a request directly from an Individual for access, amendment, or accounting of disclosures, Business Associate shall redirect the Individual to Covered Entity.

12.4 Covered Entity Obligations

12.4.1 Covered Entity shall notify Business Associate in writing of: (a) any limitations in its Notice of Privacy Practices that may affect Business Associate's permitted uses or disclosures of PHI; (b) any changes to or revocation of an Individual's authorization; and (c) any restrictions on use or disclosure of PHI that Covered Entity has agreed to with an Individual.

12.4.2 Covered Entity shall not request that Business Associate use or disclose PHI in any manner that would not be permissible under HIPAA if done by Covered Entity.

12.4.3 Covered Entity shall comply with HIPAA's Minimum Necessary requirements and shall provide Business Associate only the minimum PHI necessary for Business Associate to provide the Services.

12.5 Term and Termination of BAA

12.5.1 This Article 12 is coterminous with this Agreement and terminates upon termination or expiration of this Agreement.

12.5.2 Upon termination of this Agreement, Business Associate shall, within thirty (30) days following the end of the data return wind-down period described in Section 13.4, return or destroy all PHI in its possession. If return or destruction is not feasible, Business Associate shall extend the protections of this Article to the retained PHI and limit further use or disclosure to those purposes that make return or destruction infeasible.

12.5.3 This Article 12 survives termination of this Agreement to the extent necessary to give effect to the obligations set forth herein.

12.6 Precedence

To the extent any provision of this Agreement conflicts with this Article 12 with respect to PHI, the terms of this Article 12 shall govern.


ARTICLE 13 — TERM AND TERMINATION

13.1 Term. This Agreement commences on the Effective Date and continues until the Subscription Term expires or is terminated in accordance with this Article.

13.2 Termination for Cause. Either Party may terminate this Agreement upon written notice if the other Party: (a) materially breaches this Agreement and fails to cure such breach within thirty (30) days after receiving written notice describing the breach in reasonable detail; or (b) becomes insolvent, makes a general assignment for the benefit of creditors, or becomes subject to bankruptcy, receivership, or similar proceedings.

13.3 Effect of Termination. Upon termination or expiration of this Agreement:

(a) All licenses granted to Customer immediately terminate;

(b) Customer shall cease all use of the Platform;

(c) Each Party shall promptly return or destroy the other Party's Confidential Information in its possession; and

(d) Accrued payment obligations and Articles 7, 8, 10, 11, 12 (as modified by Section 12.5), 13.4, and 14 survive termination.

13.4 Data Return Wind-Down. Following termination or expiration of this Agreement, Customer will have 30 days to export its Customer Data from the Platform. During this period, ilumenIQ will make the Platform available in a limited, read-only export mode for this purpose. After the wind-down period, ilumenIQ will delete or destroy Customer Data from the Platform in accordance with the BAA and ilumenIQ's data retention policies. ilumenIQ is not responsible for any Customer Data that Customer fails to export during the wind-down period.


ARTICLE 14 — GENERAL PROVISIONS

14.1 Governing Law. This Agreement is governed by and construed in accordance with the laws of the State of North Carolina, without regard to its conflict of law principles. The Parties agree to submit to the exclusive jurisdiction of the state and federal courts located in Mecklenburg County, North Carolina for any dispute arising under this Agreement.

14.2 Dispute Resolution. The Parties agree to attempt to resolve any dispute through good-faith negotiation between senior representatives before pursuing formal legal proceedings.

14.3 Notices. All legal notices required under this Agreement shall be in writing and deemed effective when: (a) delivered personally; (b) sent by certified mail, return receipt requested; or (c) sent by nationally recognized overnight courier. Operational and billing notices may be delivered by email to the address associated with Customer's account. Notices to ilumenIQ shall be addressed to:

ilumenIQ LLC Attn: Legal 1235 East Blvd, Suite E519 Charlotte, NC 28203 legal@ilumeniq.com

14.4 Updates to this Agreement. ilumenIQ may update this Agreement from time to time. If ilumenIQ makes material changes, Customer will be notified via email or through the Platform and will be required to re-accept the updated Agreement upon next login. Continued use of the Platform after acceptance of an updated Agreement constitutes Customer's agreement to the revised terms. ilumenIQ may update the BAA provisions in Article 12 as necessary to comply with changes to HIPAA upon reasonable prior notice to Customer.

14.5 Assignment. Customer may not assign this Agreement or any rights or obligations hereunder without ilumenIQ's prior written consent. ilumenIQ may assign this Agreement without consent in connection with a merger, acquisition, or sale of all or substantially all of its assets, provided ilumenIQ gives Customer reasonable prior notice. Any purported assignment in violation of this Section is void.

14.6 Amendment. Except as provided in Section 14.4, this Agreement may be amended only by a written instrument signed by authorized representatives of both Parties.

14.7 Waiver. No waiver of any right or provision will be effective unless in writing. No failure or delay by either Party in exercising any right constitutes a waiver of that right.

14.8 Severability. If any provision of this Agreement is held invalid or unenforceable, such provision will be modified to the minimum extent necessary to make it enforceable, and the remaining provisions continue in full force.

14.9 Entire Agreement. This Agreement, together with the Subscription Plan selected at account creation and the End User License Agreement, constitutes the entire agreement between the Parties with respect to its subject matter and supersedes all prior and contemporaneous agreements, negotiations, and representations. In the event of any conflict, the order of precedence is: (1) this Agreement; (2) the selected Subscription Plan terms; (3) the End User License Agreement.

14.10 Force Majeure. Neither Party will be liable for delays or failures in performance resulting from causes beyond its reasonable control, including acts of God, natural disasters, pandemics, war, terrorism, civil unrest, government actions, or internet outages.

14.11 Independent Contractors. The Parties are independent contractors. Nothing in this Agreement creates a partnership, joint venture, agency, franchise, or employment relationship between the Parties.

14.12 No Third-Party Beneficiaries. This Agreement is for the sole benefit of the Parties and their permitted successors and assigns. Nothing herein creates any third-party beneficiary rights.

14.13 Counterparts and Electronic Acceptance. This Agreement may be accepted electronically. Customer's click-to-accept during account creation constitutes a valid, binding electronic signature under applicable law, including the Electronic Signatures in Global and National Commerce Act (E-SIGN) and applicable state law. ilumenIQ maintains a record of Customer's acceptance, including the date, time, and version of the Agreement accepted.


ilumenIQ LLC | 1235 East Blvd, Suite E519 | Charlotte, NC 28203