1. PARTIES AND DEFINITIONS
- 1.1 This Master Service Agreement ("MSA") is entered into between SecureHive Inc., a Delaware corporation ("Provider"), and the subscribing entity ("Customer").
- 1.2 "Services" means the comprehensive security and compliance management platform provided by Provider, including all software, applications, APIs, and related services.
- 1.3 "Service Schedule" means the specific terms governing individual service offerings, pricing, and service levels.
2. SCOPE OF SERVICES AND DELIVERY
- 2.1 Provider shall deliver enterprise-grade security and compliance management services as detailed in the applicable Service Schedules.
- 2.2 Services include but are not limited to: security framework management, compliance monitoring, risk assessment, policy management, and audit support.
- 2.3 Provider maintains 99.95% service availability with comprehensive monitoring and incident response capabilities.
- 2.4 Provider shall provide priority support for all customers.
3. DATA PROCESSING AND PRIVACY COMPLIANCE
- 3.1 Provider processes Customer data in accordance with applicable Data Protection Laws, including GDPR, CCPA, PIPEDA, and emerging 2026-2027 privacy regulations.
- 3.2 Provider implements comprehensive data governance frameworks, including data minimization, purpose limitation, retention policies, and cross-border transfer safeguards.
- 3.3 Customer retains full ownership and control of their data, with Provider acting as a data processor under applicable Data Protection Laws.
- 3.4 Provider maintains comprehensive data processing records and conducts regular privacy impact assessments.
4. ARTIFICIAL INTELLIGENCE AND AUTOMATION
- 4.1 Provider may utilize AI and machine learning technologies to enhance service delivery, subject to Customer's explicit consent and applicable AI governance requirements.
- 4.2 AI processing activities comply with emerging AI governance frameworks, including algorithmic transparency and bias mitigation measures.
- 4.3 Customer has granular control over AI features and may opt-out of non-essential AI processing activities.
5. SECURITY AND COMPLIANCE OBLIGATIONS
- 5.1 Provider maintains a comprehensive information security program aligned with ISO/IEC 27001 and is currently in preparation for ISO/IEC 27001 certification. Provider undergoes periodic third-party security assessments and will provide available security documentation upon request
- 5.2 Provider implements defense-in-depth security measures, including multi-factor authentication, encryption, network segmentation, and continuous monitoring.
- 5.3 Provider maintains comprehensive incident response procedures and will notify Customer of security incidents within 24 hours of discovery.
- 5.4 Customer is responsible for maintaining appropriate access controls, security practices, and compliance with their own regulatory requirements.
6. INTELLECTUAL PROPERTY RIGHTS
- 6.1 Provider retains all rights, title, and interest in the Services, including all intellectual property rights, trade secrets, and proprietary methodologies.
- 6.2 Customer grants Provider a limited, non-exclusive license to use Customer data solely for providing the Services and improving service quality.
- 6.3 Customer retains all rights to their proprietary data, intellectual property, and business processes.
- 6.4 Any improvements or modifications to the Services developed during the engagement remain the property of Provider.
7. LIABILITY, INDEMNIFICATION, AND INSURANCE
- 7.1 Provider's total liability is limited to the amount paid by Customer in the 12 months preceding the claim, with no liability for indirect or consequential damages.
- 7.2 Customer agrees to indemnify Provider against claims arising from Customer's use of the Services in violation of this MSA or applicable law.
8. TERM, RENEWAL, AND TERMINATION
- 8.1 This MSA remains in effect for the duration of the service relationship and automatically renews unless terminated with 30 days' written notice.
- 8.2 Either party may terminate this MSA for material breach with 30 days' notice and opportunity to cure.
- 8.3 Provider may suspend services immediately for violations of this MSA, non-payment, or security concerns.
- 8.4 Upon termination, Customer data will be available for export for 90 days, after which it will be securely deleted in accordance with applicable law.
9. GOVERNING LAW AND DISPUTE RESOLUTION
- 9.1 This MSA is governed by the laws of Delaware, United States, without regard to conflict of law principles.
- 9.2 Disputes shall be resolved through binding arbitration in accordance with the rules of the American Arbitration Association.
- 9.3 Either party may seek injunctive relief in any court of competent jurisdiction to prevent irreparable harm.
10. GENERAL PROVISIONS
- 10.1 This MSA constitutes the entire agreement between the parties and supersedes all prior agreements and understandings.
- 10.2 Modifications must be in writing and signed by authorized representatives of both parties.
- 10.3 If any provision is found unenforceable, the remaining provisions shall remain in full force and effect.
- 10.4 Provider may assign this MSA; Customer may not assign without Provider's written consent.