This Master Service Agreement ("MSA" or "Agreement") is entered into between Think Smart Group Inc., a California corporation (also referred to as "Think Smart Inc.") ("TSI"), and the customer identified on an executed Order Form ("Customer"). This Agreement establishes the general terms and conditions under which TSI will provide, and Customer will purchase, Services. Specific Services, pricing, quantities, and terms will be set forth in one or more Order Forms executed by the parties, each of which is incorporated into and governed by this Agreement.
1. Definitions
1.1 "Customer" means the entity that executes an Order Form with TSI for the provision of Services under this Agreement.
1.2 "Authorized User" means an employee, contractor, representative, or other individual authorized by Customer to access or use the Services for Customer’s internal business purposes.
1.3 "Customer Data" means data, files, records, content, or information submitted to, stored in, processed by, or transmitted through the Services by or on behalf of Customer or its Authorized Users.
1.4 "Services" means the hosted cloud services, application delivery services, professional services, support services, managed backup services, security services, and any other services identified in an Order Form, Addendum, SOW, or applicable service description.
1.5 "Order Form" means a written ordering document, quote, statement of work, or other commercial document executed by Customer and TSI that identifies the Services purchased by Customer.
1.6 "Addenda" means the addenda, policies, and service-specific terms incorporated into this Agreement or an Order Form.
1.7 "Confidential Information" means non-public information disclosed by one party to the other that is identified as confidential or that reasonably should be understood to be confidential given the nature of the information and the circumstances of disclosure.
1.8 "Professional Services" means project, migration, implementation, customization, configuration, training, data export, data import, application upgrade, vendor coordination, or other services outside the included recurring Services.
2. Scope; Structure; Orders
2.1 Purpose. This Agreement governs Customer’s purchase and use of TSI’s hosted cloud services for Customer’s internal business operations and Customer’s Authorized Users.
2.2 Covered Services. The Services include compute virtual machine instances, block and object storage, networking and secure connectivity, identity integration, nightly backups, and related support and professional services, plus any add-on services selected on an Order Form. Examples include Windows RDS Platform, Vela Cloud™ app delivery, Vela for OfficeMate, Managed Backup Service, Active Directory Platform, Managed Network Security Platform, Server Monitoring & Updates, SOC-Monitored MDR, Cloud Administration Portal, site-to-site VPNs, dedicated IPs, and related services.
2.3 Ordering. Each Order Form specifies the Services, quantities, term, start date, and pricing. Each executed Order Form is incorporated into and governed by this Agreement.
2.4 Documents. The following incorporated documents may apply depending on the Services purchased: (a) Service Level Agreement (SLA); (b) Acceptable Use Policy (AUP); (c) Security Annex; (d) Data Retention & Deletion Addendum; (e) Data Processing Addendum (GDPR) and, if applicable, HIPAA Business Associate Agreement (BAA); (f) Third-Party Access Addendum; (g) End-User Support Addendum, if help desk support is purchased or included; (h) SOC-Monitored MDR Addendum; (i) Private Pricing Addendum (PPA), if any; and (j) any Statement of Work (SOW).
2.5 Order of Precedence. If there is a conflict among documents, the following order of precedence applies for commercial terms: Order Form, PPA, applicable Addenda, SOW, this Agreement. For data protection issues, the DPA or BAA controls to the extent of a direct conflict. For security operations and maintenance practices, the Security Annex controls to the extent of a direct conflict.
3. Term; Renewal; Suspension
3.1 Term. This Agreement starts on the Effective Date identified in the first executed Order Form and continues until terminated under this Agreement. Each Order Form states its own term.
3.2 Renewal. Unless an Order Form states otherwise, each fixed-term Order Form auto-renews for one (1) year at then-current list rates, or as specified in a PPA, unless a party gives ninety (90) days’ written non-renewal notice before the end of the then-current term. Month-to-month Services may be terminated on thirty (30) days’ written notice unless the Order Form states a different notice period.
3.3 Suspension. TSI may suspend Services immediately for: (a) security threats, AUP violations, or legal requests; (b) failure to maintain required security controls; (c) material breach; or (d) non-payment after notice. TSI will limit the scope and duration of any suspension to what is reasonably necessary.
4. Fees; Invoicing; Payment
4.1 Fees. Fees are listed in the applicable Order Form, plus taxes and pass-through third-party fees, if any.
4.2 Invoicing and Due Date. Invoices are issued on the first (1st) calendar day of each month. Unless an Order Form states otherwise, recurring fees are billed monthly in advance, and usage-based fees, overages, one-time fees, and Professional Services may be billed in arrears or upon completion. Amounts are due by the tenth (10th) calendar day of the month or the next U.S. banking day.
4.3 Auto-Payment. Customer must maintain an electronic auto-payment method with TSI unless TSI approves another payment arrangement in writing. ACH has no service fee. Credit and debit cards may be accepted and may incur a service fee identified on the Order Form or invoice. Cash and checks are not accepted unless TSI agrees in writing.
4.4 Late; Reinstatement; Collections. Past-due amounts accrue the lesser of 1.5% per month or the maximum permitted by law. TSI may suspend Services for non-payment. A $250 reinstatement fee may apply to restore suspended Services. Customer will reimburse TSI for reasonable costs of collection, including reasonable attorneys’ fees, incurred in collecting undisputed amounts more than thirty (30) days past due.
4.5 Taxes. Fees are exclusive of taxes. Customer is responsible for applicable taxes except those based on TSI’s net income.
4.6 Private Pricing Addendum. Any custom pricing, commitments, credits, renewal protections, or special commercial terms are governed by a Private Pricing Addendum, if any.
5. Use of Services; AUP; Authorized Users; Vendor Access
5.1 AUP. Customer will comply with the AUP and ensure that its Authorized Users, staff, contractors, and approved vendors do the same. TSI may suspend access for AUP violations under §3.3.
5.2 Authorized Users. Customer is responsible for all use of the Services by Customer’s Authorized Users and by anyone accessing the Services through Customer accounts, credentials, systems, networks, or vendor access.
5.3 Third-Party Access. Any access for Customer-designated vendors, including application vendors, IT providers, device vendors, consultants, or support personnel, is governed by the Third-Party Access Addendum. Customer remains responsible for vendor acts and omissions and will indemnify TSI accordingly.
5.4 Enforcement Right. TSI may suspend or restrict an Authorized User, vendor connection, account, or workload where necessary to protect the platform, comply with law, enforce the AUP, or mitigate security or stability risk, with notice to Customer where feasible.
6. Service Levels; Maintenance
6.1 SLA. The SLA defines availability targets and service credits as the sole and exclusive remedy for SLA failures, with a 100% monthly cap on the affected service. Customer must submit claims within the SLA claim window with the required evidence.
6.2 Exclusions. SLA credits are not available for, among other things, Customer connectivity or last-mile issues, third-party software failures, line-of-business application failures, quota or throttling exceedance, credential compromise, preview or beta features, scheduled maintenance, and suspensions under the AUP or this Agreement.
6.3 Maintenance and Planned Downtime. Maintenance windows and notice practices are set out in the Security Annex. Extended maintenance requiring longer downtime will be scheduled with advance notice when feasible. Time spent during announced maintenance windows does not count as Unavailability under the SLA.
7. Security; Access; Data Protection
7.1 Security Annex. TSI will implement and maintain the security controls described in the Security Annex, including network segmentation and monitoring, identity and access controls, patching baselines, logging, backup monitoring, and change management. Response targets in the Security Annex are operational SLOs and are not tied to credits unless expressly stated in the SLA.
7.2 Pen-Testing. Customer will not conduct penetration tests, vulnerability scans, port scans, load tests, or similar testing without TSI’s prior written approval and adherence to TSI’s rules of engagement. DoS and volumetric tests are prohibited.
7.3 Subprocessors. TSI may use vetted subprocessors to deliver the Services and remains responsible for their performance. For GDPR-covered data, the DPA governs subprocessor listings, notice, and any objection process.
7.4 Privacy and Data Roles. For personal data, the parties’ roles and processing terms are set out in the DPA and BAA, if applicable. Customer will provide any required notices and obtain all required consents from Authorized Users, patients, employees, customers, vendors, or other data subjects.
8. Data Retention; Backups; Deletion
TSI provides managed backup and data retention services as described in the Data Retention & Deletion Addendum, which is incorporated into this Agreement. In summary, TSI performs nightly backups with defined restore points and retains data for a limited period. Upon termination, TSI will retain active copies of Customer Data for a short period to enable export, after which active copies are deleted and residual backups expire in the ordinary course. Additional details, including restore initiation targets, export and deletion procedures, and legal hold requirements, are set forth in the Data Retention & Deletion Addendum.
9. Customer Responsibilities
9.1 Core Customer Obligations. Customer is responsible for the following, regardless of any other agreement:
taking reasonable measures to prevent unauthorized access;
maintaining supported operating systems, applications, workstations, browsers, printers, scanners, peripherals, and network equipment unless expressly assumed by TSI in an Order Form or SOW;
maintaining endpoint protection and patching on Customer-owned devices and networks;
promptly implementing reasonable security or stability changes requested by TSI within a mutually agreed timeframe;
ensuring that Authorized Users and approved vendors comply with the AUP, Security Annex, and Third-Party Access Addendum;
acknowledging that upgrades are not reversible and that rollback, reconfiguration, or remediation work is out of scope and billed at Professional Services rates unless expressly included in an Order Form or SOW;
upon written request, authorizing TSI to procure third-party support or licenses on Customer’s behalf, with Customer reimbursing such costs plus a ten percent (10%) administrative fee; and
maintaining current administrative, technical, billing, and emergency contacts.
9.2 Connectivity. Customer acknowledges that adequate, reliable, and stable bandwidth and last-mile connectivity are necessary for intended use of the Services. Connectivity issues traceable to Customer networks, Authorized User networks, ISP circuits, local Wi-Fi, routers, switches, cabling, or third-party connectivity are excluded from SLA claims. TSI does not assume liability for connectivity performance outside TSI’s controlled platform.
9.3 Customer Security Responsibilities. Customer is solely responsible for configuring, securing, and managing Customer-controlled networks, systems, applications, firewall rules, vendor access, user access, and exposed services, including any TCP/UDP ports Customer elects to make publicly accessible. Customer acknowledges that insecure or unnecessary exposed services significantly increase the likelihood of compromise. Any unavailability, compromise, data loss, malicious activity, or service impact resulting from Customer’s insecure configuration or exposure of services is excluded from SLA credits, and TSI has no liability for such events except to the extent caused by TSI’s gross negligence or willful misconduct. TSI may require Customer to make reasonable configuration changes to maintain platform security or stability. If Customer fails to implement such changes within a reasonable timeframe, TSI may suspend affected Services under §3.3. If Customer exposes clearly unsafe services that create platform-wide risk, TSI may temporarily block, filter, or restrict such traffic to protect the platform, with notice to Customer where feasible.
10. Support
10.1 Included Support. Unless otherwise stated on the Order Form, TSI provides support to Customer’s designated administrative and technical contacts for platform issues. Response targets are operational SLOs only and do not give rise to credits.
10.2 Help Desk Support. If purchased or included on an Order Form, TSI may provide help desk support to Customer’s Authorized Users under the End-User Support Addendum. If help desk support is not selected, TSI will provide support only to Customer’s designated administrative or technical contacts.
10.3 Professional Services. Enhanced support tiers and Professional Services, including migration, tuning, custom integrations, training, application upgrades, data import, data export, and mass user changes, are available as priced on the Order Form, PPA, Schedule A, or SOW.
11. Software Licensing
11.1 Microsoft SPLA. Microsoft software required for the Services must be licensed through TSI under Microsoft’s SPLA program unless TSI expressly states otherwise in writing. Customer may not bring its own Microsoft licenses for use with the Services unless TSI confirms in writing that the license model is permitted and operationally supported.
11.2 Bring Your Own License (Third-Party Software). Bring Your Own License (BYOL) applies only to third-party software vendors other than Microsoft, and only where BYOL is permitted and available. Customer is responsible for obtaining and maintaining all third-party application licenses not provided by TSI, including line-of-business applications such as OfficeMate, Crystal Practice Management, and related vendor software.
11.3 Termination of SPLA. All SPLA licenses provisioned by TSI automatically terminate upon termination or expiration of the applicable Services, and Customer shall immediately cease use of such licenses.
12. Intellectual Property; Suggestions
12.1 Ownership. Each party retains ownership of its pre-existing Intellectual Property. TSI retains all rights in the Services, documentation, configurations, platform designs, templates, automation, and any deliverables not expressly transferred by SOW.
12.2 Suggestions. If Customer or its Affiliates provide suggestions, ideas, feedback, recommendations, or proposed improvements, TSI and its Affiliates may use them without restriction. Customer hereby irrevocably assigns to TSI all right, title, and interest in and to those suggestions and will provide reasonable assistance to document, perfect, and maintain TSI’s rights.
13. Termination
13.1 For Cause. Either party may terminate this Agreement or an Order Form for material breach not cured within thirty (30) days after written notice. For payment breaches, the cure period is ten (10) days after written notice.
13.2 Fixed-Term Orders. Fixed-term purchases are non-cancellable for convenience unless the applicable Order Form expressly states otherwise. If Customer nevertheless terminates a fixed-term Order Form for convenience before the end of its term, Customer will pay the early termination fee stated in the Order Form. If no early termination fee is stated, Customer will pay an early termination fee equal to fifty percent (50%) of the remaining recurring fees for the terminated Services, due upon termination, as a reasonable estimate of damages and not as a penalty.
13.3 Month-to-Month Orders. Month-to-month Services may be terminated on thirty (30) days’ written notice unless the Order Form states a different notice period. Customer remains responsible for all fees through the effective termination date.
13.4 Effect of Termination. Upon termination, all unpaid fees become due, access ceases, and data handling follows §8 and the Data Retention & Deletion Addendum. Outstanding Addenda that by their nature should survive will survive, including payment, IP, confidentiality, disclaimers, limitations, indemnities, and governing law and venue.
14. Warranties; Disclaimers
14.1 Limited Warranty. TSI will provide the Services in a professional and workmanlike manner.
14.2 Disclaimers. THE SERVICES AND CONTENT ARE PROVIDED "AS IS." Except to the extent prohibited by law, or to the extent any non-waivable statutory rights apply, TSI and its licensors: (a) make no representations or warranties of any kind, whether express, implied, statutory, or otherwise, regarding the Services or third-party content; (b) disclaim all warranties, including implied warranties of merchantability, satisfactory quality, fitness for a particular purpose, non-infringement, quiet enjoyment, and any arising out of course of dealing or usage of trade; and (c) do not warrant that the Services or content will be uninterrupted, error-free, or free of harmful components, or that any content will be secure or not otherwise lost or altered.
15. Indemnities
15.1 TSI IP Indemnity. TSI will defend Customer against third-party claims alleging that the TSI-provided platform, excluding Customer Data, Customer content, Customer software, and third-party software, infringes a U.S. patent, copyright, or trademark, and will pay resulting damages finally awarded, provided Customer: (a) promptly notifies TSI; (b) grants TSI sole control; and (c) provides reasonable assistance. As a remedy, TSI may procure rights, modify, or replace the Services. If not feasible, TSI may suspend or terminate the affected Services with a pro-rata refund of prepaid fees.
15.2 Customer Indemnity. Customer will defend and indemnify TSI from claims arising out of: (a) Customer Data or content; (b) Customer, Authorized User, or vendor use in violation of the AUP or law; (c) Customer’s third-party software, including licensing; and (d) any vendor access under the Third-Party Access Addendum.
16. Limitation of Liability
16.1 Cap. Except for Excluded Claims below, each party’s aggregate liability arising out of or relating to this Agreement will not exceed: (a) for Services provided under a fixed-term Order Form, the fees paid or payable by Customer to TSI for the six (6) months preceding the event giving rise to the claim for the affected Services; and (b) for Services provided on a month-to-month basis, the fees paid or payable by Customer to TSI for the one (1) month preceding the event giving rise to the claim for the affected Services, provided that such liability cap shall not be less than five thousand dollars (US $5,000).
16.2 Excluded Damages. In no event will either party be liable for indirect, incidental, special, consequential, exemplary, punitive, or lost profits, revenue, goodwill, or data, even if advised of the possibility of such damages.
16.3 Excluded Claims; Carve-Out Cap. The foregoing cap in §16.1 does not apply to: (a) a party’s willful misconduct or gross negligence; (b) breach of confidentiality; or (c) TSI’s IP indemnity under §15.1. For those categories, liability will be capped at twelve (12) months of fees paid or payable for the affected Services.
16.4 Exclusive Remedy for Downtime. SLA credits are the sole and exclusive remedy for any failure to meet service levels.
16.5 Limitations Period. Any claim must be filed within one (1) year after it accrues. This does not limit TSI’s actions to collect unpaid fees.
17. Insurance
Each party will maintain, with insurers rated A- or better, at minimum: Commercial General Liability $1M per occurrence / $2M aggregate; Technology E&O or Professional Liability $2M; Cyber Liability $2M; and Workers’ Compensation as required by law. Each party will annually provide certificates of insurance upon request, and upon renewal, replacement, material change, or lapse.
18. Confidentiality
Each party will protect the other’s Confidential Information with at least reasonable care and use it only to perform under this Agreement. Exclusions and compelled disclosure rights apply. Upon termination, each party will return or destroy Confidential Information, except as required by law or retained in archival backups in the ordinary course.
19. Branding; Publicity
TSI will not publicly use Customer’s name, trademarks, or logos for marketing, publicity, or reference purposes without Customer’s prior written consent. Notwithstanding the foregoing, TSI may use Customer’s name or marks as required by law or regulation, or as reasonably necessary to provide support, billing, operational, or security notifications.
20. Miscellaneous
20.1 Governing Law; Venue. This Agreement is governed by the laws of the State of California, without regard to conflict-of-laws rules. The parties consent to exclusive jurisdiction and venue in the state and federal courts located in Sacramento County, California.
20.2 Changes to Policies and SLA. TSI may update referenced policies and the SLA from time to time. Materially adverse changes will apply upon renewal of the then-current term, unless earlier application is required by law or to address security, legal, or system-integrity risks. Updates will not modify commercial pricing or payment terms unless agreed in writing or stated in an Order Form, PPA, or SOW.
20.3 Assignment. Neither party may assign this Agreement without the other’s consent, except to an Affiliate or in connection with a merger, acquisition, or sale of substantially all assets, provided the assignee is not a direct competitor and assumes all obligations.
20.4 Notices. Notices must be in writing and delivered by email with confirmation, recognized courier, or certified mail. Notice email addresses for each party will be as specified in the applicable Order Form or as updated by written notice from one party to the other.
20.5 Entire Agreement; Amendments. This Agreement, together with incorporated Order Forms and Addenda, is the parties’ entire agreement and supersedes prior or contemporaneous agreements on the subject. Amendments must be in writing and signed by both parties, except for policy updates permitted under §20.2 and the applicable Addenda.
20.6 Severability; Waiver. If any provision is unenforceable, the remainder remains in effect. Failure to enforce is not a waiver.
20.7 Force Majeure. Neither party is liable for delays or failures due to events beyond its reasonable control, excluding payment obligations.
Acceptance
By executing an Order Form that references this Master Service Agreement (MSA-CUST), Customer agrees to be bound by the terms of this Agreement and all incorporated Addenda, policies, and SOWs applicable to the Services purchased by Customer.
Customer: ____________________________ Think Smart Group, Inc.
By: ____________________________________ By: ____________________________________
Name: _________________________________ Name: _________________________________
Title: ___________________________________ Title: __________________________________
Date: ___________________________________ Date: __________________________________
