Kanza AI Business Terms — Multi-Clinic Partner

1. Who These Terms Apply To

1.1 These Kanza AI Business Terms — Multi-Clinic Partner (“Business Terms”) govern the standard Kanza service provided to a multi-clinic partner organization (“Partner,” “you”) and the clinics, practices, or facilities it designates (each a “Clinic Organization” — meaning a separate organization for which Partner acts as a Business Associate, and not a location, department, or affiliate within a single covered entity). These Business Terms apply to the standard service; where Kanza develops a specialized or dedicated model for Partner or deploys on Partner’s premises, the Business Terms Agreement — Enterprise and the Business Associate Agreement — Enterprise apply instead.


1.2 These Business Terms are an agreement between Kanza AI, Inc. (“Kanza,” “we,” or “us”) and you, and incorporate the guidelines and policies we make available in writing (the “Kanza AI Policies”), the Business Associate Agreement — Multi-Clinic Partner (the “BAA”), and any ordering document (an “Order Form”), together the “Agreement.” They take effect on execution by an authorized representative of Partner, who represents that Partner has authority to bind itself and accepts with the authority represented in the BAA. “Kanza Content” means the service and all software, models, content, and materials we make available, excluding Partner Content.


1.3 Order Forms and Negotiated Terms. Negotiated terms take precedence over these Business Terms. Where Kanza and Partner sign an Order Form, addendum, or other negotiated agreement covering the service, that document controls over these Business Terms and the Kanza AI Policies, and — where it expressly states that it amends the BAA — over the BAA, to the extent of any conflict, for the subject matter it addresses. A pre-existing signed agreement between the parties remains in effect on its own terms.

2. Access and the Services

2.1 Access. We grant Partner and its designated Clinic Organizations and users a non-exclusive, non-transferable right to access and use the Kanza service during the Term for use in their clinical practice. Partner is responsible for its Clinic Organizations’ and users’ access and for their compliance with this Agreement, and will ensure each user uses a separate account. Individual credentials may not be shared.


2.2 Fees. Fees for the service, if any, are as set out in an Order Form, which governs pricing, payment terms, and any applicable taxes. Where no Order Form applies, access may be provided at no charge or through Service Credits we issue, and we are not obligated to continue providing access at no charge.


2.3 Intended Use; Clinical Judgment. The service is clinician-facing clinical decision support intended to support, and not replace or direct, the independent professional judgment of a qualified healthcare professional. Partner and its clinicians are solely responsible for all clinical decisions, must independently review the basis for the information presented, and must evaluate all Output for accuracy and appropriateness in each case, and will not use the service for autonomous diagnosis or treatment without clinician review or in any manner inconsistent with its intended use as non-device clinical decision support.


2.4 Data You May Submit. Partner represents that it and its Clinic Organizations will provide only the minimum necessary Protected Health Information (“PHI”) for use of the service, and will not submit data they lack authority or the necessary consents to share, or categories of data prohibited by the Kanza AI Policies.

3. Restrictions

3.1 We own all right, title, and interest in the service and Kanza Content, and you receive only the rights expressly granted. You will not, and will ensure your Clinic Organizations and users do not:

  1. (a) use the service or Partner Content in violation of applicable law or the Kanza AI Policies;
  2. (b) use them in a way that infringes a third party’s rights;
  3. (c) reverse assemble, decompile, or engage in model extraction, or otherwise attempt to discover the source code or underlying components of the service;
  4. (d) use output to develop artificial-intelligence models or applications that compete with our products and services;
  5. (e) extract data from the service other than as permitted; or
  6. (f) transfer access or credentials to a third party.

4. Content

4.1 Partner Content. Partner and its Clinic Organizations may provide input to the service (“Input”) and receive output based on it (“Output”), together “Partner Content.” As between the parties, Partner and its Clinic Organizations retain all ownership of Input, and we assign to Partner our right, title, and interest, if any, in Output generated for Partner. Partner grants Kanza a non-exclusive, royalty-free, worldwide license to use Partner Content to host, operate, and provide the service during the Term.


4.2 Our Use of Partner Content. We use identifiable Partner Content only to provide the service to you and your Clinic Organizations, including features such as case matching that operate on your data for your benefit, and we will not use identifiable Partner Content to train, develop, or improve our models except with permission as provided in the BAA. To the extent Partner Content constitutes PHI, our use and disclosure of it is governed by the BAA, which controls over this Section with respect to that information. As permitted by the BAA, we may de-identify PHI and use and disclose the resulting de-identified data, including to develop, provide, and improve our products and services.


4.3 Your Obligations. Partner is responsible for all Input and represents that it and its Clinic Organizations have all rights, licenses, and permissions required to provide it, including any authorization or consent required by law, and are solely responsible for use of Output, including through human review.


4.4 Similarity of Output. Due to the nature of the service, Output may not be unique, and our assignment of Output does not extend to other customers’ output.


4.5 Service Data. Kanza may collect and use technical and operational data generated through the use, operation, support, or performance of the service, including usage statistics, diagnostic information, system and device information, logs, telemetry, and support metadata (“Service Data”), to operate, secure, support, analyze, and improve the service. Service Data does not include PHI or the substantive content of Input or Output, and Kanza will not use Service Data to disclose Partner’s or any Clinic Organization’s Confidential Information. Service Data is not Partner Content and may be retained after termination.

5. Privacy and HIPAA

5.1 Before Partner or any Clinic Organization uses the service to create, receive, maintain, or transmit PHI, Partner must accept the BAA, which is incorporated into and forms part of this Agreement and is accepted by an authorized representative of Partner with the authority represented in the BAA.

6. Confidentiality

6.1 “Confidential Information” means non-public business, technical, or financial information disclosed by one party to the other that is identified as confidential or should reasonably be understood to be confidential, and includes Partner Content. The recipient will use it only to exercise its rights and perform its obligations under this Agreement, protect it with reasonable care, and not disclose it except to those with a need to know who are bound by comparable obligations or as required by law. These obligations do not apply to information that is public through no fault of the recipient, already known, rightfully received without restriction, or independently developed. The obligations in this Section survive expiration or termination of this Agreement for three years; provided that obligations concerning trade secrets continue for so long as the information qualifies as a trade secret under applicable law, and obligations concerning PHI are governed by the BAA, including any provisions of the BAA that survive termination.

7. Security

7.1 We will maintain an information security program that uses commercially reasonable technical, administrative, and organizational measures consistent with industry standards to protect the service and Partner Content against unauthorized access, use, or disclosure. These measures include, as then-current elements of our program, encryption in transit and at rest, access controls and authentication, network security and monitoring, logging and incident response, and periodic review. We may update the specific measures over time so long as the protection is not materially reduced.

8. Term; Termination

8.1 Term; Termination. This Agreement begins on execution or the effective date of an Order Form and continues until terminated (the “Term”). Either party may terminate for the other’s uncured material breach after thirty (30) days’ written notice, or if the other becomes insolvent. We may also suspend or terminate access if required by law or to address a security risk or credible risk of harm, with notice where practicable.


8.2 Effect of Termination; Deletion. For thirty (30) days following termination, we will, on Partner’s written request, make Partner Content available for export in a commonly used, machine-readable format. Following that period, or earlier at Partner’s written direction, we will delete Partner Content from our active production systems within thirty (30) days; residual copies in backups and disaster-recovery systems are deleted in the ordinary course and remain protected under this Agreement and the BAA until deleted. De-identified data derived from Partner Content is not Partner Content and survives termination. Provisions intended to survive will survive.

9. Warranties; Disclaimer

9.1 We warrant that during the Term the service will conform in all material respects to the documentation we provide. Except for the warranty in the first sentence of this Section, the service is provided “as is,” and we and our affiliates and licensors disclaim all other warranties, express or implied, including merchantability, fitness for a particular purpose, title, and non-infringement. We do not warrant that the service will be uninterrupted, error free, or secure. We do not warrant that Output will be accurate, complete, or suitable for any particular patient or clinical circumstance. The service does not provide medical advice and does not constitute the practice of medicine or any other licensed profession; Kanza is not a healthcare provider, and nothing in the service creates a provider-patient relationship.

10. Indemnification

10.1 By Us. We will defend and indemnify you against third-party claims that the service infringes a third party’s intellectual-property right, including claims arising from training data we use to train a model that powers the service. This does not apply to claims arising from combination with non-Kanza products, modification by anyone other than us, your Input, or use in violation of this Agreement or applicable law.


10.2 By You. You will indemnify us and our affiliates and licensors against third-party claims arising from Input or from use of the service by you, your Clinic Organizations, or your users in violation of this Agreement.


10.3 These remedies are the sole and exclusive remedies for any third-party claim that the service infringes intellectual-property rights. The indemnifying party controls the defense; neither party may settle in a way that imposes liability or an admission on the other without consent.

11. Limitation of Liability

11.1 Exclusion of Indirect Damages. Except for a party’s gross negligence or willful misconduct, your breach of Section 3 (Restrictions), either party’s breach of Section 6 (Confidentiality), our breach of Section 7 (Security), or a party’s indemnification obligations, neither party nor its affiliates or licensors will be liable for any indirect, incidental, special, consequential, punitive, or exemplary damages (including lost profits), even if advised of the possibility.


11.2 Liability Cap. Except for a party’s gross negligence or willful misconduct, a party’s indemnification obligations, your breach of Section 3 (Restrictions) or Section 6 (Confidentiality), or your misappropriation of our intellectual property, each party’s total liability under this Agreement will not exceed the greater of the total amount paid to us in the twelve (12) months before the event giving rise to liability or one thousand U.S. dollars (US$1,000). The excepted matters in this Section are not subject to that cap.


11.3 Data Protection Cap. Notwithstanding Section 11.2, Kanza’s total aggregate liability for Data Protection Claims — meaning our breach of Section 6 (Confidentiality), our breach of Section 7 (Security), and our breach of the BAA — will not exceed the greater of two (2) times the fees paid or payable to Kanza in the twelve (12) months preceding the event and fifty thousand U.S. dollars ($50,000). This cap sits above and outside the general cap; the matters excepted in Section 11.2 remain uncapped.

12. Trade Controls

12.1 You must comply with all applicable trade, sanctions, and export-control laws, and may not use the service in or for any embargoed country or restricted party or for any prohibited end use.

13. Dispute Resolution

YOU AGREE TO THE FOLLOWING MANDATORY ARBITRATION AND CLASS ACTION WAIVER PROVISIONS.


13.1 You and Kanza will resolve any claim arising out of or relating to this Agreement through final and binding arbitration administered by National Arbitration and Mediation (NAM) before a sole arbitrator, after a sixty (60) day informal-resolution period, in San Francisco, California, or another agreed location. Claims for injunctive relief to stop infringement or unauthorized use may be brought in court. Nothing in this Section requires arbitration of individual actions properly brought in small-claims court.


13.2 No Class Actions. Disputes must be brought individually and not as a class or representative proceeding. If a dispute proceeds in court, each party waives any right to a jury trial.

14. Modifications

14.1 We may update these Business Terms or the Kanza AI Policies with reasonable notice, including by posting the update. If an update materially affects your rights or obligations, we will provide at least thirty (30) days’ notice, and material changes to the arbitration or liability terms require your renewed acceptance. Updates do not apply to disputes arising before they take effect.

15. Miscellaneous

  1. 15.1 Feedback; Publicity. If you provide feedback, you grant us the right to use it without restriction. We will not use your name or marks publicly without your approval or as agreed in an Order Form.
  2. 15.2 Entire Agreement; Relationship. This Agreement is the entire agreement between the parties on its subject matter and supersedes prior understandings. Neither party is liable for any delay or failure to perform (other than payment obligations) caused by events beyond its reasonable control. The parties are independent contractors. There are no third-party beneficiaries. You may not assign this Agreement without our consent; we may assign to an affiliate or successor. If any provision is unenforceable, the remainder stays in effect.
  3. 15.3 Notices. Notices will be in writing. We may provide notice to the email or registration information on your account. We accept service of process at: Kanza AI, Inc., 2995 Woodside Road, Suite 400, Woodside, California 94062, Attention: Legal, contract-notices@kanza.ai.
  4. 15.4 Governing Law; Venue. This Agreement is governed by the laws of the State of California, excluding its conflicts-of-law rules. Except as provided in Section 13, claims will be brought exclusively in the state or federal courts located in San Francisco County, California.

Business Associate Agreement — Multi-Clinic Partner


How This Agreement Is Entered Into

This Business Associate Agreement (this “BAA”) is entered into between Kanza AI, Inc. (“Kanza,” as “Business Associate”) and the multi-clinic partner organization identified on the applicable Order Form or onboarding record (“Partner”), a Business Associate of the participating clinics, practices, or facilities it designates (each a “Clinic Organization”). Partner enters this BAA for itself; no Clinic Organization is a party. It is incorporated into and forms part of the Business Terms between Kanza and Partner. It takes effect on execution by an authorized representative of Partner. This BAA governs Kanza’s provision of the standard Kanza service to Partner and its Clinic Organizations; it does not apply where Kanza develops a specialized or dedicated model for Partner or deploys on Partner’s premises, which are governed by the Business Terms Agreement — Enterprise and the Business Associate Agreement — Enterprise. References to sections of the Business Terms are to those sections as renumbered from time to time.


Authority; Applicability

Partner is a Business Associate of each participating Clinic Organization, and Kanza is Partner’s Subcontractor under 45 C.F.R. § 160.103. Partner represents and warrants that its business associate agreement with each Clinic Organization permits Partner to engage Kanza as a Subcontractor and to authorize the uses of PHI set out in this BAA — including the de-identification and improvement rights in Section 3.2 — and that Partner will maintain those agreements for the term. Kanza’s rights extend only as far as those agreements permit, and Kanza’s reporting under Section 2.3 runs to Partner for relay to the affected Clinic Organization. Partner is responsible for identifying its participating Clinic Organizations and for the accuracy of these representations. This BAA applies only to the extent PHI is created, received, maintained, or transmitted via the Kanza service; it does not apply to use of the service that does not involve PHI.

1. Definitions

Capitalized terms not defined here have the meaning given in 45 C.F.R. Parts 160 and 164 (the “HIPAA Rules”). “PHI” means Protected Health Information that Kanza creates, receives, maintains, or transmits for or on behalf of Partner and its Clinic Organizations via the service, and includes electronic PHI. “Unsuccessful Security Incident” means pings, port scans, unsuccessful log-on attempts, denials of service, and similar attempted but unsuccessful incidents that do not result in unauthorized access, use, or disclosure of PHI.

2. Obligations of Business Associate

2.1 Kanza will not use or disclose PHI other than as permitted by this BAA or the Business Terms, or as Required by Law, and will not use or disclose PHI in any manner that would violate the HIPAA Privacy Rule if done by Covered Entity. Kanza will use or disclose PHI consistent with the minimum necessary requirements of the HIPAA Rules.


2.2 Kanza will use appropriate safeguards and comply with Subpart C of 45 C.F.R. Part 164 with respect to electronic PHI, consistent with its information security program under the Business Terms.


2.3 Kanza will report to Partner, without unreasonable delay and in no event later than the timeframe required by 45 C.F.R. § 164.410, any use or disclosure of PHI not permitted by this BAA, any Breach of Unsecured PHI under 45 C.F.R. § 164.410, and any Security Incident. This Section constitutes notice of the ongoing occurrence of Unsuccessful Security Incidents, for which no further report is required. A Breach does not include an event Kanza determines under 45 C.F.R. § 164.402 to carry a low probability that PHI has been compromised; Kanza will make its written risk assessment available to Partner on request. Kanza will provide the identification of affected Individuals and the other information required by 45 C.F.R. § 164.410(c) to the extent available to it, and Partner is responsible for determinations Kanza cannot make from the information it holds and for relay to the affected Clinic Organization.


2.4 Kanza will ensure that each Subcontractor that creates, receives, maintains, or transmits PHI on Kanza’s behalf is bound by a written agreement satisfying the applicable subcontractor business-associate requirements of HIPAA, including 45 C.F.R. §§ 164.308(b), 164.314(a), 164.502(e), and 164.504(e).


2.5 Designated Record Set. The service is not intended to serve as a medical record or a Designated Record Set, and Partner and its Clinic Organizations are responsible for maintaining their own records of care. To the extent Kanza maintains PHI in a Designated Record Set on a Clinic Organization’s behalf, Kanza will, upon Partner’s written request and within the time reasonably necessary to meet the applicable obligations under 45 C.F.R. §§ 164.524, 164.526, and 164.528, make such PHI available. Partner or the Clinic Organization makes all determinations regarding an Individual’s request.


2.6 Delegated Privacy Rule Obligations. To the extent Kanza is delegated responsibility for an obligation of a Covered Entity under Subpart E of 45 C.F.R. Part 164, Kanza will comply with the requirements of Subpart E that apply to that obligation.


2.7 Kanza will make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of the U.S. Department of Health and Human Services as required to determine compliance with the HIPAA Rules, subject to applicable legal privileges.


2.8 Kanza will mitigate, to the extent practicable, any harmful effect known to Kanza resulting from a use or disclosure of PHI by Kanza or its subcontractors in violation of this BAA, and will reasonably cooperate with Partner’s mitigation efforts.


2.9 Encryption. Kanza will encrypt PHI in transit and at rest using encryption that renders PHI unusable, unreadable, or indecipherable to unauthorized persons, consistent with the standards specified by the U.S. Department of Health and Human Services under 45 C.F.R. § 164.402 and the NIST guidance referenced therein.

3. Permitted Uses and Disclosures by Kanza

3.1 Kanza may use or disclose PHI as necessary to perform the service, as otherwise permitted by this Section 3, and as Required by Law.


3.2 De-identified Data. As authorized under Partner’s business associate agreements with the applicable Covered Entity(ies), Kanza may de-identify PHI consistent with 45 C.F.R. § 164.514 and may use and disclose the resulting de-identified data for any purpose, including to develop, provide, and improve its products and services, subject to Section 3.6. Kanza will not attempt to re-identify de-identified data and will require any third party to which it discloses such data to agree not to do so. De-identified data is not PHI and is not subject to the return-or-destruction obligations of this BAA. This right is granted by Partner in reliance on the authority represented in the Authority; Applicability section above. Where the PHI includes free-text narrative, dates of service, or longitudinal linkage, Kanza will de-identify by expert determination under § 164.514(b)(1); otherwise Safe Harbor under § 164.514(b)(2) may be used.


3.2A Identified Training. Kanza may use identifiable PHI to train, develop, or improve models, or for research, only where an Order Form signed by both parties authorizes that specific use, and only for records for which Partner represents that the applicable Covered Entity has obtained all required patient authorizations under 45 C.F.R. § 164.508 or other permissions required by law. Partner is responsible for obtaining and maintaining those authorizations and permissions, and Kanza’s rights under this Section extend only as far as they permit. On Partner’s notice that an authorization has been revoked, Kanza will cease using that Individual’s identifiable PHI for that purpose promptly and no later than ten (10) business days, and will delete identifiable copies in the ordinary course and no later than thirty (30) days. Kanza will use commercially reasonable measures designed so that deployed models do not output identifiable PHI.


3.3 Kanza may use PHI for its proper management and administration and to carry out its legal responsibilities.


3.4 Kanza may disclose PHI for its proper management and administration or to carry out its legal responsibilities only where Required by Law, or where Kanza obtains reasonable written assurances from the recipient that the PHI will be held confidentially, used or further disclosed only as Required by Law or for the purpose disclosed, and that the recipient will notify Kanza of any breach of confidentiality.


3.5 Data Aggregation. Kanza may use PHI to provide Data Aggregation services relating to the health care operations of Partner and its Clinic Organizations, as permitted by 45 C.F.R. § 164.504(e)(2)(i)(B), and may develop aggregate statistics through de-identification or Data Aggregation.


3.6 No Monetization of Data. Except as expressly agreed in an Order Form signed by both parties, Kanza will not sell, license, rent, or otherwise receive remuneration for PHI, Partner Content (as defined in the Business Terms), de-identified data, or any dataset derived from them, and will not use PHI for marketing. Any sale of PHI within the meaning of 45 C.F.R. § 164.502(a)(5)(ii) is permitted only where an Order Form so provides and the applicable patient authorizations satisfy § 164.508(a)(4); absent such an Order Form, the data rights granted under this BAA are not granted in exchange for remuneration, and no sale of PHI occurs. Model weights, parameters, and architectures resulting from permitted use are Kanza’s, and Kanza may commercialize its models and the service.

4. Obligations of Partner

4.1 Partner will obtain, and will ensure each Clinic Organization obtains, any authorization or consent Required by Law before PHI is provided to the service, and is responsible for its and its Clinic Organizations’ inputs as set out in the Business Terms.


4.2 Partner will notify Kanza of any limitation in a Clinic Organization’s notice of privacy practices, any change in or revocation of permission to use or disclose PHI, and any restriction agreed under 45 C.F.R. § 164.522, to the extent it may affect Kanza’s use or disclosure of PHI.


4.3 Partner will not, and will ensure its Clinic Organizations do not, request Kanza to use or disclose PHI in any manner that would not be permissible under the HIPAA Rules if done by a Covered Entity, except as permitted under Section 3.

5. Term and Termination

5.1 This BAA takes effect on execution, continues while the Business Terms remain in effect, and terminates when all PHI has been returned or destroyed.


5.2 Either party may terminate this BAA for the other party’s material breach that remains uncured following the cure process in the Business Terms.


5.3 Upon termination or expiration, Kanza will return or destroy all PHI it maintains, consistent with the deletion terms of the Business Terms. Where return or destruction of particular PHI is infeasible — including residual copies in backup or disaster-recovery systems — Kanza will extend the protections of this BAA to that PHI and limit further use or disclosure to the purposes that make return or destruction infeasible, for as long as it maintains the PHI. De-identified data is not PHI and is not subject to this Section. This Section survives termination.

6. General

6.1 With respect to PHI, this BAA governs over any conflicting term of the Business Terms, except that an Order Form or negotiated agreement that expressly states it amends this BAA controls to the extent it so states. In all other respects the Business Terms control. The parties will amend this BAA as necessary for compliance with the HIPAA Rules, and any ambiguity will be resolved to permit compliance. This BAA confers no rights on any third party.