Think Smart Inc.

Flow-Through Addendum

Third-party terms that flow through to the Services.

Last updated: December 9, 2025

← All agreements
Draft — pending review. This document is a working draft adapted for Think Smart Group Inc. and should be confirmed by legal counsel before launch.

This Flow-Through Terms Addendum (“Addendum”) supplements and is incorporated into the Master Service Agreement (“MSA”) between Think Smart Group, Inc. (“TSI”) and the Customer. Where the Customer is an Independent Software Vendor (“ISV”), this Addendum requires ISV to bind its End-Users by written contract to terms no less protective of TSI than those contained in the MSA and incorporated policies (including the AUP, Security Annex, Data Retention & Deletion Addendum, DPA/BAA, SLA, and Third-Party Access Addendum). Capitalized terms used but not defined in this Addendum have the meanings given in the Master Service Agreement (MSA).

1. Required End-User Terms

ISV will include in each End-User agreement:

  • an Acceptable Use Policy substantially equivalent to TSI’s AUP;
  • security obligations (MFA when available; supported OS; endpoint protection; lawful use);
  • bandwidth/last-mile responsibility and warranty of adequate, reliable, stable connectivity;
  • Third-Party Access controls (authorization, MFA, bastion/jump, logging, time-boxed credentials);
  • consent/notice that TSI acts as a service provider/processor for hosting and support; and
  • acknowledgment that downtime remedies are credits only as defined by ISV’s SLA with its End-Users (no liability for TSI beyond credits owed to ISV under the TSI SLA).

2. Enforcement & Suspension

ISV is the primary enforcer of End-User obligations. TSI may, in emergencies or for repeated violations, directly suspend an End-User account or connection to protect the platform, with prompt notice to ISV.

3. Data Processing & Privacy

ISV will ensure End-User contracts authorize processing by TSI as a "service provider" (CCPA/CPRA) and/or "processor" (GDPR) where applicable, and reference ISV’s privacy notices. The DPA between ISV and TSI governs GDPR specifics, including subprocessors and cross-border transfers.

4. Third-Party Vendors of End-Users

End-User vendors must meet the Third-Party Access Addendum controls. ISV remains responsible for vendors engaged by End-Users and will indemnify TSI for resulting claims as provided in the ISV MSA.

5. Changes to this Addendum

TSI may update this Addendum from time to time and will provide notice of material changes. Materially adverse changes will not take effect during a then-current Order Form term; they apply upon renewal, unless earlier required by law or to address security, legal, or system‑integrity risks. Updates will not modify commercial pricing or payment terms.

Acceptance. This Flow-Through Terms Addendum is accepted and agreed to by ISV as of the Effective Date of the Master Services Agreement into which it is incorporated.

Questions?

Prefer to ask a person?

For questions about this document or about Think Smart, reach out and we will help.