Master Services Agreement

This Master Services Agreement (“MSA”) governs subscriptions to the InvoToday service purchased under a signed order form, quote, or similar ordering document that references this MSA (each, an “Order”) between InvoToday, a business operated from British Columbia, Canada (“Provider”), and the customer identified in the Order (“Customer”). Customers who subscribe self-serve without an Order are governed by the Terms of Service instead. In case of conflict, the order of precedence is: the Order, this MSA, the Data Processing Addendum, then the policies incorporated by reference.

1. The service; access

Provider will make the InvoToday service described in the Order (the “Service”) available to Customer during each subscription term, and grants Customer a non-exclusive, non-transferable right for its authorized users (up to the seat count in the Order) to access and use the Service for Customer’s internal business purposes. Seats are named users and may be reassigned to replacement personnel but not shared. Provider may update the Service from time to time, provided updates do not materially reduce its core functionality during a paid term.

2. Orders, term and renewal

Each Order commences on its start date and runs for the initial term stated in it. Unless the Order says otherwise, subscriptions renew automatically for successive periods equal to the initial term at the then-current rates, unless either party gives notice of non-renewal at least 30 days before renewal. This MSA remains in effect while any Order is active.

3. Fees, payment and taxes

4. Customer obligations

Customer is responsible for: its users’ compliance with this MSA; the accuracy and legality of Customer Data; obtaining all consents needed to submit personal data; its own tax, accounting, e-invoicing, and regulatory compliance (the Service is a software tool and provides no professional advice); credentials and API keys it supplies (including e-invoicing certificates and AI-provider keys); maintaining exports of records it is legally required to keep; and using the Service in accordance with the acceptable-use provisions of the Terms of Service, which are incorporated by reference.

5. Customer Data; data protection

As between the parties, Customer owns Customer Data. Customer grants Provider a license to host, process, transmit, display, and back up Customer Data solely to provide, secure, support, and improve the Service. The parties will comply with the Data Processing Addendum, which is incorporated into this MSA. Provider will maintain the security measures described in the DPA and the Security & Cyber Liability Statement. Following termination, Provider will make Customer Data available for export for at least 30 days, then delete it as described in the DPA.

6. Confidentiality

Each party (as receiver) will protect the other party’s non-public information disclosed in connection with this MSA (“Confidential Information”) using at least reasonable care, use it only to perform under this MSA, and disclose it only to personnel and advisers bound by confidentiality obligations. Confidential Information excludes information that is or becomes public without breach, was lawfully known before disclosure, is independently developed, or is rightfully received from a third party. A receiver may disclose Confidential Information where legally compelled, with prompt notice to the discloser where lawful. These obligations survive for 5 years after termination (indefinitely for trade secrets and Customer Data).

7. Intellectual property

Provider and its licensors retain all rights in the Service, its software, templates, and documentation, and in all improvements, usage data in aggregate or de-identified form, and feedback (which Customer licenses to Provider perpetually and royalty-free). No rights are granted except as expressly stated. Neither party may use the other’s names or marks without prior written consent, except that Provider may identify Customer as a customer in factual lists unless the Order says otherwise.

8. Warranties

Each party warrants that it has the authority to enter into this MSA. Provider warrants that during a paid term the Service will perform materially in accordance with its documentation and that Provider will not materially degrade its core functionality. Customer’s exclusive remedy for breach of this warranty is that Provider will use commercially reasonable efforts to correct the non-conformity, and if Provider cannot do so within 30 days of notice, Customer may terminate the affected Order and receive a pro-rata refund of prepaid, unused fees. EXCEPT AS EXPRESSLY STATED IN THIS SECTION, THE SERVICE IS PROVIDED “AS IS” AND PROVIDER DISCLAIMS ALL OTHER WARRANTIES AND CONDITIONS, EXPRESS, IMPLIED, OR STATUTORY, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT, AND DOES NOT WARRANT THAT THE SERVICE WILL BE UNINTERRUPTED OR ERROR-FREE OR THAT OUTPUTS WILL SATISFY ANY LEGAL, TAX, OR REGULATORY REQUIREMENT.

9. Indemnification

By Provider. Provider will defend Customer against third-party claims alleging that the Service, as provided by Provider and used as permitted, infringes a third party’s copyright or trademark, and will pay damages finally awarded or agreed in settlement. If such a claim arises, Provider may procure the right to continue, modify the Service to be non-infringing, or terminate the affected Order with a pro-rata refund of prepaid, unused fees. Provider has no obligation for claims arising from Customer Data, combinations with items not provided by Provider, modifications not made by Provider, or use in breach of this MSA. This section states Customer’s exclusive remedy for infringement claims.

By Customer. Customer will defend Provider against third-party claims arising from Customer Data, Customer’s documents, filings, or e-invoice submissions, Customer’s use of the Service in breach of this MSA or law, or disputes with Customer’s own customers, vendors, employees, or authorities, and will pay damages finally awarded or agreed in settlement.

The indemnified party must give prompt notice, sole control of the defense to the indemnifying party (which may not settle in a way that imposes liability on the indemnified party without consent), and reasonable cooperation.

10. Limitation of liability

TO THE MAXIMUM EXTENT PERMITTED BY LAW: (a) NEITHER PARTY IS LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR FOR LOSS OF PROFITS, REVENUE, DATA, GOODWILL, OR BUSINESS OPPORTUNITY; AND (b) EACH PARTY’S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO THIS MSA WILL NOT EXCEED THE FEES PAID OR PAYABLE BY CUSTOMER FOR THE SERVICE IN THE TWELVE (12) MONTHS BEFORE THE FIRST EVENT GIVING RISE TO LIABILITY. THESE LIMITS DO NOT APPLY TO CUSTOMER’S PAYMENT OBLIGATIONS, A PARTY’S INDEMNIFICATION OBLIGATIONS, A PARTY’S BREACH OF SECTION 6 (CONFIDENTIALITY), OR LIABILITY THAT CANNOT BE LIMITED UNDER APPLICABLE LAW (INCLUDING FRAUD OR WILFUL MISCONDUCT).

11. Insurance

Each party will maintain, at its own cost, insurance coverage as required by applicable law and as commercially reasonable for a business of its size and risk profile. On written request, a party will provide a summary of its relevant coverage. Neither party’s insurance limits expand its liability under this MSA.

12. Termination

Either party may terminate this MSA or an affected Order: (a) for material breach not cured within 30 days of written notice; or (b) immediately if the other party becomes insolvent or subject to bankruptcy or similar proceedings. On termination for Provider’s uncured breach, Provider will refund prepaid fees for the unused remainder of the term; on termination for Customer’s uncured breach, all unpaid fees for the remainder of the term become due. Sections that by their nature should survive (including fees owed, confidentiality, IP, indemnities, limitations of liability, and governing law) survive termination.

13. General