Legal
Business Associate Agreement and Non-Disclosure Agreement
This Agreement is both a HIPAA Business Associate Agreement ("BAA") and a Non-Disclosure Agreement ("NDA"), and also covers data use and intellectual property. It applies to every client of Strategic AI Architects, LLC d/b/a Strategic AI Architects ("Provider," "we," "us"). "Client" means you — the person or organization that engages Provider or pays a Provider invoice. If you are acting on behalf of an organization, you represent that you have authority to bind that organization, and "Client" includes that organization.
Provider builds and connects websites, tools, and systems for Client. Everything else is in the parties' separate services agreement, statement of work, or invoice (the "Services Agreement").
Payment of any Strategic AI Architects invoice constitutes agreement to this Agreement. This is a fixed document that applies equally to every client at our standard project pricing. We do not negotiate or customize it on a per-project basis. No signature is required.
This agreement represents the parties' complete understanding of the obligations described herein. Each party is responsible for obtaining independent counsel prior to execution if desired.
1. Access to Client's Systems
Client grants Provider's team login access to Client's systems as needed to do the work, and removes that access when the work is done. Client owns all of its accounts, systems, and data at all times. Provider does not store or keep Client's customer data on its own systems.
2. Confidentiality (Non-Disclosure)
Each party will keep the other's non-public business information confidential and will use it only to perform or receive the services. This does not apply to information that is public, was already known, is received from someone else without restriction, or is independently developed.
3. Provider's Promises About Client's Data
Provider will never:
- sell, rent, license, share, or monetize Client's data to anyone;
- use Client's customer lists, leads, or contact data for its own marketing or for any other client;
- market or sell to Client's customers; or
- use Client's data to train any AI model.
Client's customer data belongs to Client. Provider's only use of it is to do the work Client hired it to do. These promises are permanent and survive the end of this Agreement.
4. HIPAA Business Associate Agreement
These terms apply only if and to the extent Provider handles protected health information ("PHI") for Client. Client is the custodian of all PHI.
- Provider will use and disclose PHI only to perform the services or as required by law, and will use reasonable and appropriate safeguards.
- Provider will not sell PHI or use it for marketing.
- Provider will report to Client any breach of unsecured PHI, or any use or disclosure not permitted by this Agreement, within fifteen (15) days of discovering it.
- Provider will require any subcontractor that handles PHI to agree to these same terms. Provider chooses its own subcontractors and vendors.
- Provider will make PHI it holds available to Client so Client can meet its obligations to individuals, and will make its records available to the Secretary of HHS as required by law.
- On termination, Provider will return or destroy any PHI it holds, to the extent feasible.
- Either party may terminate this Agreement if the other materially breaches these HIPAA terms and does not cure within thirty (30) days.
Client is responsible for obtaining all consents and authorizations for the information it collects, for the security of its own systems and staff, and for issuing any breach notifications to individuals, regulators, or the media.
5. Intellectual Property
5.1 What Client gets
When Client has paid in full, Client owns the copy of the files, code, content, and assets Provider delivers, and may use, host, change, and keep them for its own business, forever.
5.2 What Provider keeps
Provider owns its software, engines, generators, templates, components, layouts, code, designs, prompts, processes, and methods, including any improvements made while working for Client. None of this is transferred to Client, and the work is not a "work made for hire."
5.3 Provider builds the same thing for everyone
Client understands that Provider is a high-volume service that builds for hundreds or thousands of insurance agencies using the same processes, methods, templates, and code. What Client receives will be substantially similar, and may be nearly identical, to what Provider delivers to other clients, including Client's direct competitors, in Client's own market. What is unique to Client is Client's own name, logo, photos, and copy, not the underlying build. Client is getting Provider's standard pricing precisely because Provider reuses this work.
5.4 No exclusivity
Provider may reuse everything, its methods and any code, layout, or structure in the deliverables, for any other client at any time, including Client's competitors, with no notice, payment, or permission. Client gets no exclusivity of any kind, and none will be implied from any invoice, proposal, or conversation.
5.5 No claims over similarity
Client will not bring, and gives up, any claim against Provider or any other Provider client based on the deliverables being similar to other work Provider has done. This is permanent.
5.6 Client's own material
Client keeps ownership of its name, logo, photos, and any copy it supplies, and grants Provider permission to use them to do the work and to show the work in Provider's portfolio.
6. Portfolio
Provider may name Client as a client, use Client's logo, and show screenshots of the sites it built in its portfolio, website, and sales materials. Provider will not publish Client's private business information, customer identities, or PHI.
7. Limits on Liability and Costs
7.1 Cap
The most either party can ever owe the other under this Agreement, for everything combined, no matter what happens, including any attorneys' fees, costs, and expenses, is the total amount Client has actually paid Provider. Client's sole and exclusive remedy for any claim is a refund of that amount. This cap applies no matter how a claim is framed, contract, negligence, statute, or otherwise. It does not apply to fraud or intentional misconduct, which the law does not allow either party to disclaim.
7.2 No indirect damages
Neither party is liable for lost profits, lost revenue, or indirect, special, or consequential damages.
7.3 No insurance requirement
Provider is not required to carry cyber liability, errors and omissions, or any other insurance, and Client is not relying on Provider having any. Client maintains its own coverage.
7.4 No added costs or programs
Provider is not required to buy, fund, or undergo any security certification (SOC 2, HITRUST, ISO), audit, penetration test, compliance platform, security staff, outside counsel, or formal written security, training, or business-continuity program. If Client or its carriers require any of these, Client pays for it in advance.
7.5 Client's responsibility
Client is responsible for its own systems, staff, vendors, carriers, and for anything Client or a third party adds to Client's sites or systems. Client will indemnify Provider for claims arising from those, from instructions Client gave Provider, and from Client's use or modification of the deliverables after delivery.
7.6 As is
Except as stated in the Services Agreement, deliverables are provided "as is," with no warranty as to rankings, traffic, leads, or business results.
8. Nothing Here Limits Provider's Other Work
This Agreement contains no non-compete, no exclusivity, and no restriction on whom Provider may work for, in any market, at any time, including Client's direct competitors. Provider's staff are free to work on any future project or client. Provider may use the general skills and knowledge it gains, including what its people simply remember. The only limit is that Provider will not use Client's confidential information or customer data to do it.
For two (2) years after this Agreement ends, Provider will not use Client's customer or lead data to sell insurance to Client's customers. That limit is about Client's data only, it does not stop Provider from working with other agencies.
9. General
- Term. Starts when Client engages Provider or submits payment, whichever comes first, and runs until the Services Agreement ends. Sections 3, 5, 6, 7, and 8 survive.
- Confidentiality period. Section 2 lasts five (5) years after termination; trade secrets last as long as they remain trade secrets. Sections 3 and 5 are permanent.
- Return of information. On written request, each party will return or destroy the other's confidential information within thirty (30) days. This does not require Provider to give up its own software, methods, templates, or general knowledge.
- Governing law and disputes. Michigan law governs. Before filing suit, the parties will give written notice and try to resolve the dispute in good faith for thirty (30) days. Any lawsuit will be filed where the defendant is located. Both parties waive trial by jury. Claims must be brought within two (2) years.
- Other. This Agreement is the entire agreement on confidentiality, data, and intellectual property, and replaces any prior non-disclosure agreement. It controls over any conflicting term in the Services Agreement, any purchase order, or any Client form, including any term claiming the work is a work made for hire or assigning intellectual property to Client, which is void. If any part is unenforceable, the rest stands. Neither party may assign without consent, except to a successor. Signatures may be electronic and in counterparts.
10. Extended Engagements
Clients who require custom contract terms, extended liability discussion, or exclusivity provisions should contact us to discuss our enterprise level clients, which includes dedicated legal and contract time.