Effective date: July 20, 2026
Last updated date: July 20, 2026
1. INTRODUCTION
1.1. Welcome to Optery for Business. This agreement (the “Agreement”), made and entered into as of the date you agree to its terms and create your Optery for Business account (“Effective Date”) between Optery, Inc., a Delaware Corporation with address 2261 Market Street STE 86983, San Francisco, CA 94114 (“Optery”) and you on behalf of your organization (“Customer”), includes and incorporates: (a) the Subscription Plan you select and pay for through the Administrator Dashboard; and (b) the Data Processing Addendum attached as Exhibit A (the “DPA”). This Agreement contains, among other things, warranty disclaimers, liability limitations and use limitations.
1.2. This Agreement constitutes the entire agreement, and supersedes and cancels all prior agreements, between Optery and Customer regarding the subject matter hereof, unless there exists a separate valid written agreement jointly signed and executed by authorized representatives of both Optery and the Customer related to the Services (as defined below). If at least one such different valid agreement exists, they(it) take(s) precedence and supersede(s), cancel(s), and render(s) this agreement invalid.
1.3. Optery may amend this Agreement from time to time, in which case the new Agreement will supersede and cancel prior versions. If we make materially significant changes to this Agreement, we will send you an email notification along with a summary of changes to the primary email address of each Administrator on your account.
1.4. This Agreement covers important information about the Services provided to you and any charges, taxes, and fees we bill you. Your use of the Services in any way means that you agree to all of this Agreement, and this Agreement will remain in effect while you use the Services. If you already created an Optery for Business account, but no longer agree to the terms of this Agreement, please contact us at support@optery.com for assistance in terminating your account. If you have any questions, comments, or concerns regarding these terms or the Services, please contact us at: Email: support@optery.com; Address: 2261 Market Street STE 86983, San Francisco, CA 94114.
2. DEFINITIONS
2.1. “Administrators” means the Customer-designated personnel who administer the Services on Customer’s behalf.
2.2. “Administrator Dashboard” means the online Administrator-facing web-platform provided by Optery to Customer for administering and managing the Services.
2.3. “AI Technology” means the artificial intelligence, machine learning, natural language processing, automated decision-making, and related algorithmic technologies that Optery develops, operates, and uses to provide the Services. AI Technology includes the automated systems, web crawlers, bots, scripts, and automated submission tools that Optery uses to locate personal information profiles, identify opt-out mechanisms, and submit removal requests on behalf of Users.
2.4. “Affiliate” means an entity that owns or controls, is owned or controlled by or is or under common control or ownership with a Party, where control is defined as the possession, direct or indirect, of the power to direct or cause the direction of the management and policies of an entity, whether through ownership of voting securities, by contract or otherwise.
2.5. “Confidential Information” means any nonpublic or proprietary information disclosed by a Party (“Discloser”) to the other Party (“Recipient”) that is in written, graphic, machine readable, oral, or other form and that (a) is marked or declared “Confidential” or “Proprietary” or in some other manner to indicate its confidential nature or (b) based upon the facts and circumstances of the disclosure, information that a reasonable person would consider confidential. For clarity, the terms of this Agreement and all pricing information under this Agreement is the Confidential Information of Optery. Confidential Information does not include any information that (i) was publicly available prior to the time of disclosure by the Discloser, (ii) becomes publicly available after disclosure by the Discloser to the Recipient through no action or inaction of the Recipient, (iii) is already in the lawful possession of the Recipient at the time of disclosure, (iv) is obtained by the Recipient from a Third Party without a breach of such Third Party’s obligations of confidentiality, or (v) is independently developed by the Recipient without use of or reference to the Discloser’s Confidential Information. For the purposes of this Agreement, “Customer Confidential Information” refers to Confidential Information for which Customer is a Discloser, and “Optery Confidential Information” refers to Confidential Information for which Optery is a Discloser.
2.6. “Customer Data” means any data, information, or material provided or submitted by Customer or its Administrators to the Services or User Platform; provided that, for clarity, Customer Data as defined herein does not include Usage Data.
2.7. “De-Identified Data” means data that has been aggregated and de-identified such that it does not identify, and cannot reasonably be used to identify, any individual User, Customer, or other natural person.
2.8. “Delegated Member” means any Administrators or other Users who create and/or use the Services or User Platform on behalf of or for the benefit of another person.
2.9. “Documentation” means Optery’s applicable official user documentation for the Services or the User Platform, as applicable.
2.10. “Party” means Customer and Optery individually; collectively, Customer and Optery are referred to as the “Parties”.
2.11. “Person” means any individual, corporation, limited liability company, partnership, joint venture, trust, business, association, or other entity.
2.12. “Personal Information” means any information that, individually or in combination, does or can identify a specific individual or by or from which a specific individual may be identified, contacted, or located, including without limitation all data considered “personal data”, “personally identifiable information”, or something similar under applicable laws, rules, or regulations relating to data privacy.
2.13. “Privacy Policy” means the Optery Privacy Policy found on Optery’s website at https://www.optery.com/privacy-policy/ as updated from time to time by Optery. Optery will provide Customer with reasonable prior notice of any material changes to the Privacy Policy that affect Customer’s obligations under this Agreement; provided that no such change will materially diminish Customer’s rights or materially expand Customer’s obligations under this Agreement during the Subscription Period without Customer’s prior written consent.
2.14. “Security Incident” means the unauthorized acquisition of, or access to, unencrypted electronic Personal Information that materially compromises its security or confidentiality such that it is reasonably likely to cause substantial harm. The determination of whether an event constitutes a Security Incident shall be made in accordance with applicable data breach notification laws.
2.15. “Service Suspension” shall have the meaning set forth in Section 3.7 of this Agreement.
2.16. “Services” means, collectively: (a) the Administrator Dashboard; and (b) the data removal services made available by Optery to Customer via the Administrator Dashboard, as may be further described in your Subscription Plan.
2.17. “Subscription Plan” means the specific Services, features, User quantity, price, and billing cadence that Customer selects and pays for online at the time of purchase, as reflected in Customer’s account.
2.18. “Terms” means the “Terms of Service” for the User Platform found on Optery’s website at https://www.optery.com/terms-of-service/ as updated from time to time by Optery. Optery will provide Customer with reasonable prior notice of any material changes to the Terms that affect Customer’s obligations under this Agreement; provided that no such change will materially diminish Customer’s rights or materially expand Customer’s obligations under this Agreement during the Subscription Period without Customer’s prior written consent.
2.19. “Third Party” means any Person other than Optery, Customer or any of their respective Affiliates.
2.20. “Third-Party Products” means any third-party products provided with, integrated with, or incorporated into the Services.
2.21. “Usage Data” means usage data collected and processed by Optery in connection with Customer’s and Administrators’ use of the Services, including, without limitation, data used to identify the source and destination of a communication, activity logs, and data used to optimize and maintain performance of the Services, and to investigate and prevent system abuse.
2.22. “User” means Customer’s personnel (e.g., directors, employees, contractors, consultants, interns) and applicable family members of Customer’s personnel for whose benefit use or access to the Services has been purchased.
2.23. “User Platform” means the online User-facing web-platform and data removal services made available by Optery to Users in accordance with and subject to the Terms.
3. SERVICES; USER PLATFORM
3.1. Services; User Platform. Subject to Customer’s continuing compliance with its obligations set forth in this Agreement, during the Subscription Period, Optery will make available: (a) the User Platform for use by Users pursuant to the Terms; and (b) the Services for use by Customer and its Administrators, in each case: (i) only as provided herein; (ii) only for Customer’s and its Users’ respective internal use; (iii) only in accordance with the Documentation; and (iv) on a limited, nonsublicensable, non-transferable, and nonexclusive basis.
3.2. Administrators. Customer will invite Administrators to access the Services through the Administrator Dashboard. Each Administrator must have its own unique account credentials and Administrators may not share their account credentials with one another or any third party. Customer is solely and exclusively responsible for all acts and omissions of its Administrators and for any use of Administrator accounts.
3.3. Customer Responsibility for Authorization. Customer shall obtain valid authorization to provide Users’ Personal Information to Optery prior to using the Services, including any authorizations required for Delegated Members to use the Services. Customer will maintain records of each such authorization for the duration of the Subscription Period and for one (1) year thereafter and will provide copies to Optery upon reasonable request. Customer will notify Optery promptly if any User or Delegated Member authorization becomes invalid, such as by revocation or withdrawal. Optery may suspend processing for any User or Delegated Member for whom authorization is disputed until Customer provides evidence of valid authorization satisfactory to Optery. Customer agrees to provide all necessary rights and authorizations to Optery required for Customer to use the Services.
3.4. Users. Each User’s individual access to and use of the User Platform is conditioned upon that User’s acceptance of the Terms and Privacy Policy, which establish a direct agreement between Optery and such User. Customer shall use commercially reasonable efforts to ensure that its Users comply with the Terms. As between Optery and Customer, this Agreement governs the rights and obligations of the Parties, and in the event of any conflict between this Agreement and the Terms or Privacy Policy, this Agreement will control.
3.5. Support. During the Subscription Period, Optery will use commercially reasonable efforts to provide: (a) support to Customer and its designated Administrators on weekdays during the hours of 9:00 am through 8:00 pm Eastern time, excluding U.S. Federal Holidays; and (b) an initial response to support requests within one (1) business day. Resolution times may vary based on factors such as volume of requests, peak hours, and complexity of the issue. Customer may initiate support requests via the live chat function of Optery’s Help Desk located at https://help.optery.com or by emailing support@optery.com.
3.6. Restrictions. Except as expressly set forth in this Agreement, Customer shall not, and shall not permit any User or third party (including Users and Administrators) to, directly or indirectly: (a) reverse engineer, decompile, disassemble, or otherwise attempt to discover the source code, object code, or underlying structure, ideas, or algorithms of the Services (except to the extent applicable laws specifically prohibit such restriction); (b) modify, translate, or create derivative works based on the Services; (c) copy, rent, lease, distribute, pledge, assign, or otherwise transfer or encumber rights to the Services; (d) use the Services for timesharing or service bureau purposes or otherwise for the benefit of a third party; (e) remove or otherwise alter any proprietary notices or labels from the Services or any portion thereof; (f) use the Services, in whole or in part, to build, develop, enhance, or support, directly or indirectly, any product or service that competes with any Optery product or service; (g) interfere or attempt to interfere with the proper working of the Services, including by using any automated tools to access the Services in a manner that sends more request messages to Optery servers than a human can reasonably produce in the same period; (h) bypass any measures Optery may use to prevent or restrict access to the Services (or other accounts, computer systems or networks connected to the Services); (i) permit any individual under the age of thirteen (13) to be onboarded as a User or Administrator, or to otherwise access or use the Services in any capacity; or (j) create multiple accounts, use false or misleading identifying information, or otherwise circumvent usage limits, access controls, or entitlement restrictions in order to obtain access to free or unpaid features, scans, data, or other resources beyond those to which Customer or its Users are entitled under your applicable Subscription Plan. Customer is solely responsible for all of Customer’s and its Users’ activity in connection with the Services, including, but not limited to, uploading Customer Data onto the Services, providing required notices, and obtaining required consents. Customer (x) shall use the Services in compliance with all applicable laws and (y) shall not use the Services in a manner that violates any third-party intellectual property, contractual or other proprietary rights. Furthermore, Optery for Business is for use by Administrators on behalf of their organizations (the “Permitted Use”) and not for use by individuals for any other commercial or non-commercial use. Individuals and families can sign up for an Optery personal account here: https://app.optery.com. At its sole discretion, Optery reserves the right to immediately terminate and delete Optery for Business accounts that it determines have been created for any use other than the Permitted Use. If you believe your Optery for Business account has been deleted on accident or by mistake, please contact us at support@optery.com.
3.7. Suspension. Notwithstanding anything to the contrary in this Agreement, Optery may temporarily suspend Customer’s or any Administrator’s access to the Services (a “Service Suspension”) if Optery reasonably determines that: (i) there is a threat or attack on the Services or User Platform; (ii) Customer’s use of the Services disrupts or poses a security risk to the Services, User Platform, or to any other customer or vendor; (iii) Customer or an Administrator is using the Services for fraudulent, illegal, or malicious activities; (iv) Customer has made an assignment for the benefit of creditors, or become the subject of a bankruptcy or similar proceeding; (v) Optery’s provision of the Services is prohibited by applicable laws; (vi) Customer Data violates third-party intellectual property or privacy rights; or (vii) any Third-Party Products required for the Services are suspended or terminated by the provider.
3.8. Notice and Resumption of Service. Optery shall use commercially reasonable efforts to provide Customer with prior written notice of any Service Suspension, except where Optery determines in its sole discretion that immediate suspension is necessary to prevent imminent harm to the Services or other customers. Optery shall provide regular updates regarding the resumption of access and shall resume the Services promptly after the event giving rise to the Service Suspension is cured.
3.9. Liability and Fees. Optery will have no liability for any damage, liabilities, or losses (including loss of data or profits) that Customer may incur as a result of a Service Suspension arising from the circumstances described in Section 3.7(i) through (vii), except to the extent such Service Suspension is caused by Optery’s gross negligence or willful misconduct. A Service Suspension does not constitute a termination of this Agreement. Where a Service Suspension arises from Customer’s breach or security risk, Customer remains responsible for all Fees during any period of such suspension and shall not be entitled to any refund, credit, or offset of Fees paid or payable with respect to the period of suspension.
3.10. Third-Party Products. Optery may from time to time make Third-Party Products available to Customer or Optery may allow for certain Third-Party Products to be integrated with the Services to allow for the transmission of Customer Data from such Third-Party Products into the Services. For purposes of this Agreement, such Third-Party Products are subject to their own terms and conditions. Optery is not responsible for the operation of any Third-Party Products and makes no representations or warranties of any kind with respect to Third-Party Products or their respective providers. If Customer does not agree to abide by the applicable terms for any such Third-Party Products, then Customer should not install or use such Third-Party Products. By authorizing Optery to transmit Customer Data from Third-Party Products into the Services, Customer represents and warrants to Optery that it has all right, power, and authority to provide such authorization.
3.11. Artificial Intelligence and Machine Learning – AI in the Services. The Services use AI Technology to locate personal information profiles, identify opt-out mechanisms, and submit removal requests on behalf of Users. AI Technology is integral to the Services and cannot be separated from them. Optery may apply AI Technology to any aspect of the Services, and may update or replace the AI Technology from time to time to maintain and improve the Services; provided that no such change will materially diminish the overall functionality of the Services during the Subscription Period. The Parties acknowledge that AI Technology is probabilistic in nature and may produce results that are inaccurate or incomplete. Optery does not warrant that the AI Technology will successfully identify or remove any particular personal information or profile. The AI Technology is subject to the warranty disclaimers in Section 9.3 and the limitations of liability in Section 10.
3.12. Data Usage for AI. Optery will not use Customer Data or Customer Personal Information (as defined in the DPA) to train or improve the AI Technology. Optery may use Usage Data and De-Identified Data to train and improve the AI Technology. The foregoing restriction does not limit Optery’s right to process Customer Data and Customer Personal Information as necessary to provide the Services in accordance with Section 4 and the DPA.
3.13. Customer AI Obligations. Customer shall ensure that its Administrators and Users are informed of the role of AI Technology in the delivery of the Services and that Customer has obtained all authorizations from its Users and Delegated Members required under applicable laws in connection with Optery’s use of AI Technology to process their Personal Information.
4. DATA USE AND SECURITY
4.1. Data Use; Security. Optery may process Customer Data and Usage Data: (a) to provide, operate, and maintain the Services in accordance with this Agreement; (b) to manage its relationship with Customer, including billing, account management, and communications; (c) to monitor, investigate, prevent and detect fraud, security incidents and other misuse of the Services, and to prevent harm to Optery, Customer, Users and Optery’s other customers and Users; (d) for identity verification purposes; and (e) to comply with applicable laws, rules, and regulations relating to the processing and retention of Personal Information to which Optery is subject. Optery may also process Usage Data to monitor, maintain, and optimize the Services and for internal reporting purposes. Optery will maintain reasonable administrative, physical, and technical safeguards, consistent with industry standards and commensurate with the sensitivity of the data processed, designed to prevent unauthorized use or disclosure of or access to Customer Data and Usage Data.
4.2. Security Incidents. Optery will notify Customer no later than seventy-two (72) hours after confirming the actual existence of a Security Incident. Following such notification, Optery shall provide Customer with a preliminary description of the nature of the Security Incident and the categories of Personal Information affected, to the extent such information is reasonably available to Optery at that time. Optery shall supplement such description with additional details as they become reasonably available following containment. At Customer’s request, Optery will provide reasonable assistance and cooperation to help Customer fulfill its own legal notification obligations to regulators or data subjects, provided that Optery shall not draft or distribute custom notices on Customer’s behalf.
4.3. Processing of Personal Information. Personal Information processed by Optery on behalf of Customer will be governed by the terms of this Agreement and the DPA at Exhibit A according to the order of precedence described in Section 12.13.
5. INTELLECTUAL PROPERTY; FEEDBACK
5.1. Optery Intellectual Property. As between the Parties, Optery owns and retains all right, title, and interest in and to the Services, the Administrator Dashboard, the User Platform, Documentation, Optery Confidential Information, Usage Data, and all software, products, works, and other intellectual property and moral rights related thereto or created or provided by Optery in connection with this Agreement, including without limitation all patents, patent applications, trade secrets, and proprietary algorithms and methodologies, and including any copies and derivative works of the foregoing. Any software which is distributed or otherwise provided to Customer hereunder shall be deemed a part of the Services and subject to all of the terms and conditions of this Agreement. No rights or licenses are granted except as expressly and unambiguously set forth in this Agreement.
5.2. Customer Data. As between the Parties, Customer owns all right, title, and interest, including all intellectual property rights, in and to the Customer Data and Customer Confidential Information. Customer hereby grants to Optery a non-exclusive, royalty-free, worldwide license to reproduce, distribute, and otherwise use, perform, and display the Customer Data solely as necessary for Optery to provide the Services to Customer in accordance with this Agreement. Customer may not upload to the Services or otherwise provide to Optery any Customer Data it does not have sufficient rights to upload.
5.3. Feedback. Customer hereby grants to Optery a nonexclusive, worldwide, perpetual, irrevocable, transferable, sublicensable, royalty-free, fully paid-up license to use and otherwise practice any suggestions, ideas, enhancement requests, feedback, or recommendations that Customer provides to Optery relating to the Services.
6. FEES; PAYMENT
6.1. Fees. Customer shall pay Optery all costs, fees, expenses, and other charges (collectively, the “Fees”) identified in your Subscription Plan without offset or deduction and at the cadence identified in your Subscription Plan (e.g., monthly or yearly). Customer will pay all Fees immediately at the time of purchase. If a new User is added during the Subscription Period, the Fees for the new User shall be prorated to the end of the Subscription Period and due immediately at the time the User is added. Payment obligations are non-cancelable, and Fees paid to Optery are nonrefundable, except as expressly provided in Section 11.1. Optery may increase the Fees upon notice to Customer. The Fees do not include taxes; Customer will pay all taxes, levies, and duties associated with this Agreement, other than taxes based on Optery’s income.
6.2. Late Payment. Non-payment after thirty (30) days may result in suspension or termination of Customer’s access to all or any part of the Services and Users’ access to all or any part of the User Platform at Optery’s discretion. Customer will pay Optery all costs and expenses of collection (including attorneys’ fees) incurred by Optery for collecting any such past due amounts.
7. TERM; TERMINATION
7.1. Term. The initial term of this Agreement begins on the day you first purchase a paid Subscription Plan and, unless terminated earlier in accordance with this Section 7, will continue in effect for the period identified in your Subscription Plan (the “Initial Subscription Period”). This Agreement will automatically renew for additional successive terms equal to the length of the Initial Subscription Period unless earlier terminated pursuant to this Agreement’s express provisions or until either Party cancels the then-current Subscription Plan prior to the expiration of the then-current term (each a “Renewal Subscription Period”, and together with the Initial Subscription Period, the “Subscription Period”). You can cancel at any time by logging into your Optery for Business Administrator account at https://business.optery.com and downgrading your Member(s) to Free Basic, or emailing us at support@optery.com.
7.2. Termination. In the event of a material breach of this Agreement by either party, the non-breaching party may terminate this Agreement by providing written notice to the breaching party, provided that the breaching party does not materially cure such breach within thirty (30) days of receipt of such notice.
7.3. Effects of Expiration or Termination of the Subscription Period. Upon expiration or termination of the Subscription Period, Customer’s and its Users’ access to Services and User Platform (respectively) will end, and the Subscription Period will not auto-renew. No expiration or termination will affect Customer’s obligation to pay all Fees that may have become due before such expiration or termination or entitle Customer to any refund. The following Sections survive the expiration or termination of this Agreement: 2, 3.3, 3.6, 3.7, 3.8, 3.9, 3.10, 3.11, 3.12, 3.13, 4, 5, 6 (with respect to amounts accrued prior to expiration or termination), 8, 9, 10, 11, and 12, together with Exhibit A.
8. CONFIDENTIAL INFORMATION
8.1. Nonuse and Nondisclosure. Recipient will use Discloser’s Confidential Information only to exercise rights and fulfill obligations under this Agreement. Recipient will use reasonable care to protect the Discloser’s Confidential Information from being disclosed to Persons other than the Recipient’s employees, Affiliates, contractors, agents, or professional advisors who need to know it and who have a legal obligation to keep it confidential. Recipient’s disclosure of Confidential Information pursuant to law or a judicial or administrative order will not be deemed to be a breach of this Agreement, if Recipient (a) provides timely written notice of such disclosure requirement to the Discloser (if permitted to do so under applicable laws), and (b) reasonably cooperates, at Discloser’s expense, with the Discloser’s efforts to limit the scope of such disclosure.
8.2. Return of Materials; Effects of Termination/Expiration. On the expiration or termination of the Agreement, the Recipient shall promptly return to Discloser all copies, whether in written, electronic, or other form or media, of Discloser’s Confidential Information, or destroy all such copies and certify in writing to Discloser that such Confidential Information has been destroyed. Each Party’s obligations of non-use and non-disclosure with regard to Confidential Information are effective as of the Effective Date and will expire five (5) years from the date of termination or expiration of this Agreement; provided, however, with respect to any Confidential Information that constitutes a trade secret (as determined under applicable law), such obligations of non-disclosure will survive the termination or expiration of this Agreement until such Confidential Information is no longer considered a trade secret under applicable law through no wrongful act or omission of Recipient. This Section 8 supersedes and replaces any prior non-disclosure agreement between the Parties to the extent such agreement relates to the Services or the evaluation or procurement thereof; provided that any non-disclosure agreement governing Customer’s access to Optery’s security documentation, audit reports, or trust center materials shall remain in full force and effect in accordance with its terms, regardless of whether such access occurred during the evaluation or procurement of the Services.
9. REPRESENTATIONS AND WARRANTIES; WARRANTY DISCLAIMER
9.1. Mutual Representations and Warranties. Each Party represents and warrants that (a) it has full power and authority to enter into this Agreement; and (b) the person entering into this Agreement on its behalf has the authority to do so.
9.2. Compliance. In the performance of this Agreement, each Party will comply with all applicable laws and regulations, including state and federal laws and regulations, orders, ordinances, and laws governing such party’s data privacy practices (including all required notices and consents necessary for the data processing activities described in this Agreement).
9.3. Disclaimer. THE SERVICES AND ANY OTHER INFORMATION AND MATERIALS (INCLUDING THE DOCUMENTATION) ARE PROVIDED BY OPTERY “AS IS” AND ON AN “AS AVAILABLE” BASIS WITHOUT WARRANTY OF ANY KIND, AND OPTERY HEREBY EXPRESSLY DISCLAIMS ALL OTHER WARRANTIES, EXPRESS, IMPLIED (EITHER IN FACT OR BY OPERATION OF LAW), OR STATUTORY, AS TO ANY MATTER WHATSOEVER (INCLUDING WITH RESPECT TO THE USE OF, OR THE RESULTS FROM THE USE OF, THE SERVICES), INCLUDING, WITHOUT LIMITATION, THE IMPLIED WARRANTIES OF MERCHANTABILITY, TITLE, NONINFRINGEMENT, FITNESS FOR A PARTICULAR PURPOSE OR USE, WARRANTIES IMPLIED FROM A COURSE OF DEALING OR COURSE OF PERFORMANCE OR USAGE OF TRADE, OR THAT THE SERVICES AND ANY OTHER INFORMATION AND MATERIALS (INCLUDING THE DOCUMENTATION) PROVIDED BY OPTERY ARE OR WILL BE SECURE, ERROR-FREE, OR UNINTERRUPTED. CUSTOMER HAS NO RIGHT TO MAKE OR PASS ON ANY REPRESENTATION OR WARRANTY ON BEHALF OF OPTERY TO ANY PERSON. OPTERY DOES NOT WARRANT, AND SHALL HAVE NO LIABILITY FOR, ANY THIRD-PARTY PRODUCTS. THE EFFECTIVENESS OF THE SERVICES DEPENDS ON OPTERY’S ABILITY TO ACCESS THIRD-PARTY WEBSITES AND SYSTEMS AND TO COMMUNICATE WITH THOSE THIRD PARTIES, AND SUCH ACCESS MAY BE LIMITED BY FACTORS OUTSIDE OPTERY’S CONTROL. OPTERY SHALL HAVE NO LIABILITY FOR ANY INABILITY TO COMPLETE REMOVAL REQUESTS RESULTING FROM SUCH LIMITATIONS.
10. LIMITATION OF LIABILITY
10.1. Exclusion of Consequential Damages. To the extent permitted by applicable law, and regardless of legal theory, in no event will either Party be liable for damages for loss of profit or revenue, data that is lost or corrupted, loss of goodwill, or any other special, incidental, indirect, punitive, or consequential damages arising out of or related to this Agreement, even if such damages could have been foreseen or if a Party has been advised of the possibility of such damages.
10.2. General Cap. Subject to Section 10.3, a Party’s total and cumulative liability for all claims of any nature arising out of this Agreement will not exceed the total Fees paid or payable by Customer in the twelve (12) months immediately preceding the occurrence of the first event giving rise to a claim under this Agreement.
10.3. Exceptions. The limitations set forth in Sections 10.1 and 10.2 do not apply to: (a) a Party’s intellectual property indemnification obligations specified in Section 11; (b) payment obligations; (c) damages arising from the unauthorized use of the other Party’s intellectual property; or (d) a Party’s gross negligence or willful misconduct.
11. INDEMNIFICATION
11.1. Optery Indemnity. Optery agrees to indemnify, defend and hold harmless Customer from and against any unaffiliated third party claims (“Claims”) asserted against Customer, its employees, contractors, officers, directors, and affiliates and any judgment, expenses (including reasonable attorneys’ fees), costs or liability (“Losses”) imposed against Customer pursuant to such Claims, to the extent such Claims allege that the Services or User Platform infringe, misappropriate, or violate any third party’s intellectual property rights; provided that the obligations of Optery do not apply to the extent such claims arise from (a) materials not created or provided by Optery (including without limitation any Customer Data); (b) materials made in whole or in part in accordance to Customer specifications; (c) materials modified after delivery by Optery; (d) materials combined with other products, processes or materials not provided by Optery (where the alleged claim arises from or relates to such combination); (e) Customer continuing allegedly infringing activity after being notified thereof or after being informed of modifications that would have avoided the alleged infringement; or (f) Customer’s use of the Services or User Platform not strictly in accordance herewith. If the Services or User Platform become, or in Optery’s reasonable opinion are likely to become, the subject of an infringement claim, Optery may, at its option and expense: (i) procure the right for Customer to continue using the affected Services or User Platform; (ii) modify or replace the infringing component to make it non-infringing without materially diminishing functionality; or (iii) if neither (i) nor (ii) is commercially practicable, terminate the affected Subscription Plan and refund any prepaid Fees covering the remainder of the Subscription Period following the effective date of termination.
11.2. Customer Indemnity. Customer agrees to indemnify, defend and hold harmless Optery, its employees, contractors, officers, directors, and affiliates from and against Claims asserted against Optery, and any resulting Losses, to the extent such Claims allege: (a) that the Customer Data or Customer’s use of the Services or User Platform infringes, misappropriates, or violates any third party’s intellectual property or privacy rights; (b) a breach by Customer of Section 3.3 (Customer Responsibility for Authorization), including any failure to obtain required authorizations from individual Users; or (c) Customer’s violation of the restrictions in Section 3.6 or breach of its representations under Section 9. Notwithstanding the foregoing, Customer shall not indemnify, defend or hold harmless Optery to the extent that a court of competent jurisdiction determines that any such Losses are caused by the gross negligence or willful misconduct of Optery.
11.3. Procedures. The indemnifying Party’s (the “Indemnitor”) obligations under this Section 11 are conditioned upon the Person(s) seeking indemnification under this Section 11 (the “Indemnitee(s)”): (a) promptly notifying the Indemnitor in writing of the Claim; provided that any failure or delay in providing such notice shall not relieve the Indemnitor of its obligations except to the extent the Indemnitor is materially prejudiced by such failure or delay; (b) granting the Indemnitor sole control of the defense and settlement of the Claim provided that any such settlement does not bind any Indemnitee to pay any monetary amounts or admit to any wrongdoing; and (c) providing the Indemnitor, at the Indemnitor’s expense, with all assistance, information, and authority reasonably required for the defense and settlement of the Claim.
11.4. Sole Remedy. Section 11 (including the remedial options set forth in Section 11.1) sets forth Customer’s sole remedies and Optery’s sole liability and obligation for any actual, threatened, or alleged claims that the Services infringe, misappropriate, or otherwise violate any intellectual property rights of any third party; provided that this Section 11.4 shall not (a) apply to claims arising from Optery’s willful or knowing infringement, or (b) limit Customer’s right to terminate this Agreement under Section 7.2 for an uncured material breach.
12. GENERAL
12.1. Independent Contractors. The Parties are independent contractors and nothing contained in this Agreement gives either Party the power to act as an agent of the other or to direct or control the day-to-day activities of the other.
12.2. Assignment. Customer may not assign this Agreement or its rights or obligations hereunder without the prior written consent of Optery. Optery may assign this Agreement and its rights and obligations hereunder freely without Customer’s consent. Nonpermitted assignments are void. Subject to the foregoing, this Agreement will be binding upon and inure to the benefit of the Parties and their successors and permitted assigns. Notwithstanding the foregoing, Optery may fulfill some of its duties under this Agreement through Affiliates or other Persons that provide services, supplies, equipment, or staffing at the request of, under the supervision, or at the place of business of Optery (collectively “Subcontractors”). Optery will be liable to Customer for the acts and omissions of its Subcontractors to the same extent Optery would be liable to Customer had Optery committed such acts or omissions.
12.3. Notices. Any notice must be in writing and will be effective upon delivery as follows: (a) if to Customer, (i) when delivered via registered mail, return receipt requested, or overnight delivery service to Customer’s address on record; or (ii) when sent via email to the email address on record for Customer; and (b) if to Optery, when sent via email to support@optery.com. Either Party may change its address for receipt of notices by providing notice to the other Party in accordance with this Section.
12.4. Force Majeure. Neither Party will be liable, nor be deemed to have breached this Agreement for any failure or delay in fulfilling or performing any obligation of this Agreement (excluding any delay in the payment of any Fees that are due and payable) to the extent such failure or delay is caused by or results from acts or circumstances beyond the reasonable control of such Party including, without limitation, any act of God, flood, fire, earthquake, explosion, governmental action, war, invasion or hostilities (whether war is declared or not), terrorist threats or acts, riot, or other civil unrest, national emergency, revolution, insurrection, epidemic, pandemic, lock-out, strike, or other labor disputes (whether or not relating to either Party’s workforce), or restraints or delays affecting carriers or inability or delay in obtaining supplies of adequate or suitable materials, or telecommunication breakdown or power outage.
12.5. Governing Law; Jurisdiction; Venue. This Agreement and all proceedings arising hereunder will be governed by and construed in accordance with the laws of the state of California without reference to its principles of conflicts of law. Any legal suit, action, or proceeding arising out of or related to this Agreement or the licenses granted hereunder will be instituted exclusively in the United States District Court for the Northern District of California or the courts of the State of California in each case located in San Francisco County, California and each Party irrevocably submits to the exclusive jurisdiction of such courts in any such suit, action, or proceeding.
12.6. Remedies Cumulative. Except as explicitly provided in this Agreement, the remedies provided to the Parties under this Agreement are cumulative and will not exclude any other remedies to which a Party may be lawfully entitled.
12.7. Severability. Each provision of this Agreement is separate and distinct and severable from all other provisions. If any provision (or any part thereof) is unenforceable under or prohibited by any present or future law, then such provision (or part thereof) will be amended, and is hereby amended, so as to be in compliance with such law, while preserving to the maximum extent possible the intent of the original provision. Any provision (or part thereof) that cannot be so amended will be severed from this Agreement; and all remaining provisions of this Agreement will remain unimpaired.
12.8. No Third-Party Beneficiaries. Nothing set forth in this Agreement is intended to or will be construed to confer any rights or remedies upon any Person that is not a Party to this Agreement.
12.9. U.S. Government Customers. The Services comprise a “commercial item”, as that term is defined in 48 C.F.R. 2.101, consisting of “commercial computer software” and “commercial computer software documentation,” as such terms are used in 48 C.F.R. 12.212. Consistent with 48 C.F.R. 12.212 and 48 C.F.R. 227.7202-1 through 227.7202-4, all U.S. Government Customers acquire such software and documentation with only those rights set forth herein. If a government agency has a need for rights not conveyed under these terms, it must negotiate with Optery to determine if there are acceptable terms for transferring such rights, and a mutually acceptable written addendum specifically conveying such rights must be included in any applicable contract or agreement.
12.10. Export. Customer represents and covenants that Customer is not named on any U.S. government agency’s sanctioned or denied-party list. Customer will not, and will not permit any Person to, access or use the Services in violation of any applicable export law or regulation. Notwithstanding any other provision of this Agreement, Optery reserves the right to limit or deny access to the Services to anyone who is named on or subject to any U.S. government agency’s sanctioned or denied-party list.
12.11. Amendment and Waiver. Except as otherwise provided herein, any provision of this Agreement may be amended or waived only by a writing executed by both Parties. The failure of either Party to act with respect to a breach of this Agreement by the other Party shall not constitute a waiver and shall not limit such Party’s rights with respect to such breach or any subsequent breaches.
12.12. Entire Agreement. Subject to Section 1.2, this Agreement constitutes the complete and exclusive statement of all mutual understandings between Optery and Customer with respect to the subject matter hereof, superseding all prior or contemporaneous proposals, communications and understandings, oral or written. Nothing contained in any purchase order, acknowledgment or invoice will in any way modify or add to the terms or conditions of this Agreement.
12.13. Order of Precedence. In the event of any conflict among the terms of this Agreement, the order of precedence shall be: (i) the DPA (solely as it relates to the Processing of Customer Personal Information); (ii) this Agreement; (iii) the Subscription Plan (solely with respect to the specific products, pricing, quantities, and Subscription Period purchased); and (iv) any other Exhibit or additional terms. Notwithstanding the foregoing, no Exhibit, Subscription Plan, or additional terms shall supersede or modify this Agreement with respect to Section 5 (Intellectual Property; Feedback), Section 8 (Confidential Information), Section 10 (Limitation of Liability), Section 11 (Indemnification), or Section 12.5 (Governing Law; Jurisdiction; Venue) unless such document specifically references the Section it intends to override and is signed by authorized legal representatives of both Parties. The Terms and Privacy Policy are not part of this Agreement and do not modify the rights or obligations of the Parties under this Agreement; in the event of any conflict between this Agreement and the Terms or Privacy Policy, this Agreement will control as between Optery and Customer.
12.14. Interpretation. In this Agreement: (a) the headings are for convenience only and will not affect the meaning or interpretation of this Agreement; (b) the words “herein,” “hereunder,” “hereby” and similar words refer to this Agreement as a whole (and not to the particular sentence, paragraph, or Section where they appear); (c) terms used in the plural include the singular, and vice versa, unless the context clearly requires otherwise; and (d) “or” is used in the sense of “and/or”; “any” is used in the sense of “any or all”. If an ambiguity or question of intent or interpretation arises, then this Agreement will be construed as if drafted jointly by the Parties and no presumption or burden of proof will arise favoring or disfavoring any Party by virtue of the authorship of any of the terms hereof or thereof.
Exhibit A
DATA PROCESSING ADDENDUM
This Data Processing Addendum (“DPA”) supplements the Service Agreement for Optery for Business (the “Agreement”) entered into by and between Customer and Optery, Inc. (“Optery” or “Company”). This DPA incorporates the terms of the Agreement, and any terms not defined in this DPA shall have the meaning set forth in the Agreement.
A1. DEFINITIONS
A1.1. “CCPA” means the California Consumer Privacy Act, as amended by the California Privacy Rights Act.
A1.2. “Controller” means the entity that, alone or jointly with others, determines the purposes and means of Processing Personal Information.
A1.3. “Customer Personal Information” means Personal Information that Customer provides to Company, or that Company Processes on Customer’s behalf, in connection with the Services. All references to “Customer Personal Data” in this DPA shall be deemed to be references to Customer Personal Information.
A1.4. “Data Protection Laws” means all applicable laws and regulations applicable to the Processing of Personal Information under the Agreement, including, as applicable: (a) the CCPA and all other applicable U.S. state privacy laws; (b) the Canadian Personal Information Protection and Electronic Documents Act (PIPEDA) and any substantially similar provincial legislation; (c) the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles; (d) the New Zealand Privacy Act 2020; and (e) the South African Protection of Personal Information Act, 2013 (POPIA); in each case as may be amended, superseded, or replaced from time to time. Notwithstanding the foregoing, Data Protection Laws shall specifically exclude the Health Insurance Portability and Accountability Act (HIPAA), the Gramm-Leach-Bliley Act (GLBA), the Family Educational Rights and Privacy Act (FERPA), and the Children’s Online Privacy Protection Act (COPPA), and Customer represents and warrants that it shall not provide to Company any “protected health information” as defined by HIPAA, “nonpublic personal information” as defined by GLBA, “education records” as defined by FERPA, or personal information of children under the age of 13 that would be subject to COPPA.
A1.5. “Data Subject” (or “Consumer” under U.S. state privacy laws) means the identified or identifiable natural person to whom the Personal Information relates. Under this DPA, Data Subjects are limited to Customer’s Users (as defined in the Agreement).
A1.6. “Personal Information” shall have the meaning set forth in the Agreement. All references to “Personal Data” in this DPA shall be deemed to be references to Personal Information.
A1.7. “Process” or “Processing” means any operation or set of operations performed on Personal Information or on sets of Personal Information, whether or not by automated means. This includes, but is not limited to, the collection, use, storage, disclosure, analysis, deletion, or modification of Personal Information.
A1.8. “Processor” (or “Service Provider” under the CCPA) means the entity that Processes Personal Information on behalf of a Controller. Under this DPA, Company is the Processor.
A1.9. “Subprocessor” means any person or third-party service provider appointed by or on behalf of Processor to Process Personal Data on behalf of Controller.
A2. ROLES OF THE PARTIES
The Parties agree that Customer acts as a Controller and Company acts as a Processor. For the purposes of global compliance: (a) “Controller” includes a “Business” (CCPA) and a “Responsible Party” (POPIA); (b) “Processor” includes a “Service Provider” (CCPA) and an “Operator” (POPIA); and (c) “Data Subject” includes a “Consumer” (U.S.) and an “Individual” (PIPEDA/AU/NZ).
A3. PERSONAL INFORMATION PROCESSING
A3.1. Customer Instructions. Customer shall provide Company with Personal Information Processing instructions in compliance with Data Protection Laws. Company shall notify Customer if, in its opinion, an instruction from Customer infringes Data Protection Laws. Company’s fulfillment of an instruction shall not be construed as legal advice or a guarantee of Customer’s compliance with law.
A3.2. Customer Responsibilities. Customer is solely responsible for ensuring the accuracy, quality, and legality of the Customer Personal Information and the means by which it was acquired. Customer acknowledges and agrees that Customer Personal Information may be stored and processed in the United States or other jurisdictions where Company or its Subprocessors maintain facilities. Customer is responsible for notifying its Data Subjects that their Personal Information may be subject to the laws of the jurisdictions in which it is processed.
A3.3. Purpose Limitation. Company shall process Personal Information only for the limited and specified business purposes described in the Agreement. Company is prohibited from: (a) “selling” or “sharing” Customer Personal Information as defined by Data Protection Laws; (b) retaining, using, or disclosing Customer Personal Information outside of the direct business relationship between Company and Customer; or (c) combining Customer Personal Data with personal information received from other sources, except as strictly necessary to provide the Services.
A3.4. Company Personnel. Company will limit access to Customer Personal Data to authorized personnel and Subprocessors who need it to fulfill their duties under the Agreement. Company shall: (a) vet personnel for reliability; (b) apply the principle of “least privilege” by restricting access to the minimum Personal Data required for a specific role; and (c) ensure all such individuals are bound by confidentiality obligations no less restrictive than those set forth in Section 8 of the Agreement.
A3.5. Company Accountability. Company shall appoint a designated individual to oversee compliance with Data Protection Laws where applicable law requires such designation or appointment.
A3.6. Return or Deletion. Upon termination of the Services, Company shall delete or return all Personal Information within a reasonable period of time, unless retention is required by law.
A4. SUBPROCESSORS
A4.1. Authorization and Flow-Down. Customer provides a general authorization for Company to engage Subprocessors that are reasonably necessary to provide the Services. Company shall notify Customer in writing (including by email or by updating the Subprocessor list at the URL below) at least ten (10) days before engaging any new Subprocessor to Process Customer Personal Information. Company shall ensure that any such Subprocessor is bound by a written agreement that provides at least the same level of data protection as set forth in this DPA. Company shall remain liable for the acts and omissions of its Subprocessors to the same extent Company would be liable if performing the Services directly under the terms of this DPA, subject always to the aggregate limitations of liability set forth in the Agreement. In no event shall Company’s liability for Subprocessor actions exceed the liability caps agreed upon by the Parties in the Agreement. A list of Company’s current Subprocessors is maintained at https://www.optery.com/subprocessors.
A4.2. Objections and Alternatives. Customer may object to a new Subprocessor on reasonable grounds related to data protection within ten (10) days of notice. In the event of a reasonable objection, Company will use commercially reasonable efforts to provide an alternative Subprocessor. If no such alternative Subprocessor is available within a reasonable period, Customer’s sole remedy is to discontinue use of the affected Service by providing written notice. Any such discontinuation shall not relieve Customer of any fees owed under the Agreement for services already rendered or for unaffected portions of the Services. If Customer does not provide a written objection within the ten (10) day notice period, the new Subprocessor shall be deemed authorized.
A5. DATA SUBJECT RIGHTS
A5.1. Cooperation. To the extent Customer receives a request from a Data Subject to exercise rights under Data Protection Laws (such as access, deletion, portability, or correction), and Customer is unable to fulfill such request through its own use of the Services, Company shall provide reasonable assistance to Customer to fulfill the request. Customer shall be responsible for all costs associated with such assistance, including a reimbursement to Company for any time expended by Company personnel during the process at Company’s then-current professional services rates.
A5.2. Verification. Customer is solely responsible for verifying the identity of the Data Subject before requesting assistance from Company to fulfill the request.
A5.3. Direct Requests. If a Data Subject contacts Company directly to exercise their rights, Company shall promptly notify Customer and advise the Data Subject to submit the request to Customer without responding to the substance of the request, unless required by law.
A6. DATA SECURITY
Company shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing. Company shall conduct regular risk assessments of its Processing activities and implement appropriate technical and organizational measures to ensure a level of security commensurate with the risk. These measures shall be designed to protect Customer Personal Data against Security Incidents, in alignment with internationally-recognized security standards and best practices. Any obligations regarding the notification and management of Security Incidents are governed exclusively by the terms set forth in the Agreement.
A7. EVIDENCE OF COMPLIANCE; AUDITS
A7.1. Evidence of Compliance. Company shall maintain records sufficient to demonstrate its compliance with this DPA and shall provide prompt notice to Customer if it determines it can no longer meet its obligations under this DPA. Upon Customer’s reasonable written request, and subject to reasonable confidentiality controls, Company shall make available for Customer’s review copies of its then-current SOC 2 report or comparable third-party security assessments demonstrating Company’s compliance with prevailing data security standards. The Parties agree that such reports and assessments are intended to satisfy Customer’s audit and inspection interests under this DPA to the maximum extent permitted by Data Protection Laws.
A7.2. Further Audit. Only if the evidence made available under Section A7.1 is reasonably insufficient to demonstrate compliance as required by Data Protection Laws, Company shall make available information reasonably necessary to demonstrate compliance with this DPA and allow for one reasonable inspection or audit conducted by Customer no more than once per twelve (12) month period, provided that any such audit is subject to the following conditions: (a) Customer must provide at least thirty (30) days’ prior written notice; (b) the audit must be conducted virtually and during regular business hours and in a manner that is not unreasonably disruptive to Company’s business; (c) the auditor must be subject to a non-disclosure agreement acceptable to Company; and (d) the scope of the audit is restricted to data and systems relevant to evaluating Company’s compliance with this DPA. Customer shall be responsible for all costs associated with any such audit, including a reimbursement to Company for any time expended by Company personnel during the audit process at Company’s then-current professional services rates.
A8. JURISDICTION-SPECIFIC TERMS
A8.1. United States. For purposes of the CCPA, Customer is a Business, and Company is a Service Provider. Company shall not “Sell” or “Share” Personal Information and will not combine Customer Personal Data with other sources, except as permitted by CCPA and as strictly necessary to provide the Services. This DPA automatically applies to any new U.S. state privacy laws that become effective during the term of the Agreement, provided they impose obligations substantially similar to those herein.
A8.2. Australia. Company shall take reasonable steps to ensure that any Subprocessor does not breach the Australian Privacy Principles in relation to the Customer Personal Information.
A8.3. New Zealand. Company acknowledges that, for the purposes of IPP 12 of the New Zealand Privacy Act 2020, it is required to protect Customer Personal Information subject to the Agreement in a way that provides comparable safeguards to those in that Act.
A8.4. UK, EEA, and Switzerland. At this time, the Parties do not contemplate inclusion of Customer Personal Information that is subject to the Data Protection Laws of the UK, EEA, or Switzerland. For any future data transfers from the EEA, UK, or Switzerland to the United States, the Parties shall rely on the then-current Standard Contractual Clauses (SCCs) to ensure an adequate level of protection.