Master Services Agreement
Version 1.2 · Effective 24 June 2026 · Customer's access to and use of the Sparrowhawk CRM platform and related Services
1. Structure and order of precedence
1.1 Orders. The specific Services, subscription plans, usage limits, fees, and other commercial terms will be set out in one or more ordering documents executed by the parties or accepted by Customer (each, an "Order"). An Order may reference this Agreement and may include attachments such as a service level agreement ("SLA") or statements of work ("SOWs").
1.2 DPA. If Customer processes personal information through the Services, Sparrowhawk's Data Processing Addendum ("DPA") available at https://www.sparrowhawklabs.com/legal/dpa, as updated from time to time, forms part of this Agreement and is incorporated by reference. In the event of any conflict between this Agreement and the DPA regarding the processing of personal information, the DPA will prevail.
1.3 Order of precedence. If there is any conflict between the terms of this Agreement, an Order, the DPA, or Sparrowhawk's online policies, the following order of precedence applies: (a) the DPA (with respect to data protection and privacy matters), (b) the Order, (c) this Agreement, and (d) Sparrowhawk's online terms and policies (including its standard Terms of Use and Privacy Policy).
2. Services and licence
2.1 Services. Sparrowhawk will provide the Services described in each Order during the applicable subscription term, subject to Customer's payment of all applicable fees and compliance with this Agreement. The Services consist of the Sparrowhawk CRM platform, related APIs, and associated documentation, hosting, and support as described in the Order and the SLA (if any).
2.2 Licence grant. Subject to the terms of this Agreement, Sparrowhawk grants Customer a non-exclusive, non-transferable (except as permitted under Section 12.3), limited licence during the applicable subscription term to access and use the Services for Customer's internal business purposes and to permit its authorized users to do the same.
2.3 Use restrictions. Customer shall not, and shall not permit any third party to: (a) use the Services for any illegal or unauthorized purpose, including any activity that violates applicable cannabis laws or regulations; (b) store or transmit any protected health information or other regulated medical records via the Services; (c) copy, modify, or create derivative works of the Services; (d) reverse engineer, decompile, or disassemble the Services, except to the extent permitted by applicable law that cannot be contractually waived; (e) circumvent or attempt to circumvent any security measures of the Services; or (f) use the Services in a way that interferes with or disrupts the integrity or performance of the Services or any third-party systems.
Prohibited Data Categories. In addition to the use restrictions above, Customer shall not submit any of the following categories of data to the Services:
- (i) Protected health information (PHI) as defined under the Health Insurance Portability and Accountability Act (HIPAA), unless Sparrowhawk and Customer have executed a separate Business Associate Agreement;
- (ii) Payment card data (PAN, CVV, expiration date), except as processed through Sparrowhawk's contracted payment providers (FluidPay / PayRio);
- (iii) Third-party personally identifiable information (names, emails, phone numbers, addresses, government ID numbers, Social Security Numbers) unless Customer has obtained informed consent from each individual or has a documented lawful basis under applicable privacy law;
- (iv) Attorney-client privileged communications, attorney work product, or confidential legal advice;
- (v) Third-party confidential information, trade secrets, or proprietary data submitted without the third party's authorization;
- (vi) Biometric data or genetic information; or
- (vii) Financial-account credentials or banking-payment information beyond what Sparrowhawk's payment processors require.
Consequences. If Customer submits Prohibited Data, Sparrowhawk may (i) quarantine the data within Customer's account, (ii) notify Customer of the violation and request remediation within fourteen (14) days, (iii) suspend Customer's access if the violation is not remediated, or (iv) delete the Prohibited Data without liability. If Prohibited Data in Customer's account creates a legal or regulatory risk for Sparrowhawk, Sparrowhawk may terminate Customer's account and any active Order on thirty (30) days' notice.
2.4 B2B and US-only focus. The Services are designed for business-to-business use by cannabis industry operators in the United States and are not intended for consumer use or for storing protected health information. Customer is responsible for ensuring that its use of the Services complies with all applicable federal, state, and local laws and regulations, including those related to cannabis and data privacy.
2.5 Cannabis Industry Disclaimers.
(a) Not legal or compliance advice. The Services are a software tool designed to support cannabis industry business operations. Nothing in the Services, documentation, or any communication from Sparrowhawk constitutes legal, regulatory, or compliance advice. Customer should consult qualified legal counsel for guidance on cannabis laws and regulations applicable to Customer's business.
(b) Customer compliance responsibility. Customer is solely responsible for ensuring that its business operations, including its use of the Services, comply with all applicable federal, state, and local laws and regulations, including those relating to cannabis cultivation, processing, distribution, and retail operations.
(c) Third-party data accuracy. The Services may integrate with or display data from third-party sources, including state regulatory systems (e.g., METRC), point-of-sale systems, and other cannabis industry platforms. Sparrowhawk does not guarantee the accuracy, completeness, or timeliness of any third-party data and is not liable for any errors or omissions in such data.
(d) Regulatory change risk. The cannabis industry is subject to evolving federal, state, and local regulation. Changes in applicable law or regulation may affect the availability, functionality, or legality of the Services or Customer's ability to use the Services. Sparrowhawk will use commercially reasonable efforts to adapt the Services to material regulatory changes but does not guarantee uninterrupted service in the event of regulatory action.
(e) Right to cease service. Sparrowhawk reserves the right to suspend or terminate the Services in any jurisdiction where the provision of the Services or Customer's cannabis operations become prohibited by applicable law. In such event, Sparrowhawk will provide Customer with reasonable notice and a pro-rata refund of any prepaid, unused fees.
3. Customer obligations
3.1 Accounts. Customer is responsible for maintaining the confidentiality of its account credentials and for all activities that occur under its accounts. Customer will notify Sparrowhawk promptly of any unauthorized access or use of the Services.
3.2 Customer Data. "Customer Data" means any data, content, or information (including personal information) submitted to the Services by Customer or on its behalf, including data about Customer's end-customers and users. As between the parties, Customer retains all rights, title, and interest in and to Customer Data. Customer is responsible for the accuracy, quality, legality, and means of acquiring Customer Data. Customer represents and warrants that it has all rights and consents necessary to submit Customer Data to the Services and to permit Sparrowhawk to process Customer Data as contemplated in this Agreement.
3.2A Customer Data licence to Sparrowhawk. Customer grants Sparrowhawk a worldwide, non-exclusive, royalty-free, sublicensable (only to Subprocessors as permitted under Section 7.3) licence to host, copy, store, transmit, process, and display Customer Data as reasonably necessary to: (a) provide, operate, and maintain the Services for Customer; (b) provide customer support and resolve technical issues for Customer; (c) prevent or address security threats, fraud, abuse, or violations of this Agreement; (d) comply with applicable law or valid legal process; (e) maintain, improve, and develop the Services and related features for Customer's benefit; and (f) generate Aggregated Data as defined and described in Section 9.2. This licence terminates with respect to Customer Data when Customer Data is deleted or anonymised in accordance with Section 7.4, except that Sparrowhawk may continue to use Aggregated Data already generated.
3.3 Compliance with law. Customer will use the Services in compliance with applicable laws and regulations, including those relating to cannabis, advertising, and data privacy. Sparrowhawk is not responsible for Customer's compliance with industry-specific regulations or any laws applicable to Customer's business.
4. Term and termination
4.1 Agreement term. This Agreement commences on the Effective Date (as defined in the initial Order) and continues until terminated in accordance with this Section 4.
4.2 Order term. Each Order will specify the subscription term for the Services under that Order. Unless otherwise stated in an Order, subscriptions renew automatically for successive periods equal in length to the initial term, at Sparrowhawk's then-current rates (provided that any fee increase upon renewal will not exceed ten percent (10%) of the prior term's fees without Customer's prior written consent), unless either party gives written notice of non-renewal at least sixty (60) days before the end of the then-current term.
4.3 Termination for cause. Either party may terminate this Agreement or any affected Order upon written notice if the other party materially breaches this Agreement or the Order and fails to cure such breach within thirty (30) days after receiving written notice describing the breach. Either party may terminate this Agreement immediately if the other party becomes insolvent, enters bankruptcy proceedings, or ceases business operations.
4.4 Effect of termination. Upon expiration or termination of an Order: (a) Customer's right to access and use the Services under that Order will cease; (b) any amounts owed by Customer for the period prior to termination will become immediately due and payable; and (c) Sparrowhawk will make Customer Data available for export as described in Section 7.4. Termination of this Agreement will not automatically terminate any Order then in effect; each such Order will continue for the remainder of its term, unless terminated as provided in this Section.
5. Fees and payment
5.1 Fees. Customer will pay the fees specified in each Order. Unless otherwise stated in an Order, fees are quoted and payable in US dollars and are non-refundable except as expressly provided in this Agreement or the relevant Order.
5.2 Invoicing and payment. Unless otherwise specified in an Order, Sparrowhawk will invoice Customer in advance for subscription fees on a monthly or annual basis, as indicated in the Order. Customer will pay all undisputed amounts within thirty (30) days of the invoice date.
5.3 Taxes. Fees do not include any taxes, duties, or similar governmental assessments of any nature, including sales, use, value-added, or withholding taxes ("Taxes"). Customer is responsible for paying all Taxes associated with its purchases hereunder, excluding taxes based on Sparrowhawk's net income.
5.4 Late payments. Sparrowhawk may charge interest on overdue amounts at the lesser of 1.5% per month or the maximum rate permitted by law. Sparrowhawk may suspend Customer's access to the Services for unpaid amounts that are more than fifteen (15) days past due, provided that Sparrowhawk has given Customer at least seven (7) days' prior notice.
5.7 Not a HIPAA Business Associate. Sparrowhawk is not a Business Associate under the Health Insurance Portability and Accountability Act (HIPAA) and does not sign Business Associate Agreements as a matter of course. If Customer is a HIPAA covered entity or business associate, or processes protected health information ("PHI"), Customer may not use the Services to store, transmit, or process PHI unless Customer and Sparrowhawk have executed a separate written agreement designating Sparrowhawk as a Business Associate and establishing HIPAA-compliant safeguards. By using the Services, Customer represents and warrants that it will not submit PHI to the Services except as permitted by such a separate BAA.
6. Service levels and support
6.1 Availability target. Sparrowhawk will use commercially reasonable efforts to make the production environment of the Services available at least 99.5% of the time in each calendar month, excluding planned maintenance and excused downtime (including outages caused by force majeure events, third-party service failures, internet provider failures, or Customer's acts or omissions).
6.2 Support. Sparrowhawk will provide support as described in the applicable Order or SLA. Unless otherwise specified, Sparrowhawk will acknowledge Priority 1 (P1) support requests within two (2) hours during support hours and will use commercially reasonable efforts to provide an update within twenty-four (24) hours. For all other issues, Sparrowhawk will use commercially reasonable efforts to provide an update within forty-eight (48) hours.
6.3 Service credits. If availability falls materially below the target in a given month, Customer may request service credits as described in the applicable Order or SLA. Service credits are not granted automatically; Customer must submit a written request with reasonable supporting details within thirty (30) days after the end of the affected month. Service credits, if granted, will be applied against future fees and will be Customer's sole and exclusive remedy for failure to meet the availability target. Total service credits in any calendar month will not exceed thirty percent (30%) of that month's fees.
7. Data protection, security, and data return
7.1 Data hosting and location. Sparrowhawk hosts the Services in data centres located in the United States, primarily on Google Cloud Platform. Customer Data will be stored and processed in the United States unless otherwise agreed in writing.
7.2 Security. Sparrowhawk will maintain appropriate technical and organizational measures designed to protect the security, confidentiality, and integrity of Customer Data, including encryption of Customer Data in transit and at rest, logical separation of Customer Data between customers, network security controls, logging and monitoring, and periodic penetration testing. Further details are set out in the DPA and, where applicable, the Order.
7.3 Subprocessors. Sparrowhawk may use Subprocessors (such as cloud hosting providers, payment processors, analytics providers, logging and monitoring tools, email providers, and security tools) to provide the Services. Sparrowhawk will enter into written agreements with Subprocessors requiring them to protect Customer Data in accordance with standards substantially similar to those set out in this Agreement. Sparrowhawk will be responsible for its Subprocessors' acts and omissions to the same extent as if performed by Sparrowhawk.
7.4 Data export and deletion. During the term of the applicable Order, Customer may export certain Customer Data via the Services' standard export capabilities. Upon written request within thirty (30) days after termination or expiration of an Order, Sparrowhawk will provide Customer with a one-time export of Customer Data in a reasonable format, unless prohibited by law or this would unreasonably burden Sparrowhawk's systems. Sparrowhawk may delete or anonymize Customer Data in accordance with its data retention practices, but in any event no earlier than ninety (90) days and no later than one hundred eighty (180) days after termination, subject to applicable legal obligations.
7.5 Security incidents. Sparrowhawk will notify Customer without undue delay after becoming aware of a confirmed unauthorized access to Customer Data on Sparrowhawk's systems that results in loss, disclosure, or alteration of Customer Data (a "Security Incident"). The notice will include reasonably available information about the nature of the Security Incident and the measures taken or proposed to be taken by Sparrowhawk to address it.
8. Confidentiality
8.1 Definition. "Confidential Information" means non-public information disclosed by one party ("Discloser") to the other ("Recipient") that is designated as confidential or that should reasonably be understood to be confidential given the nature of the information and the circumstances of disclosure. Customer Data and Sparrowhawk's pricing and product information are Confidential Information.
8.2 Protection. Recipient will use the same degree of care that it uses to protect its own confidential information of similar nature (but not less than reasonable care) to protect Discloser's Confidential Information and will not use Discloser's Confidential Information for any purpose outside the scope of this Agreement. Recipient will not disclose Discloser's Confidential Information to any third party, except to its employees, contractors, and advisors who need to know the information for purposes of this Agreement and are bound by confidentiality obligations no less restrictive than those in this Agreement.
8.3 Exceptions. Confidential Information does not include information that: (a) is or becomes publicly available without breach of this Agreement; (b) was known to Recipient before receipt from Discloser; (c) is received from a third party without breach of any obligation of confidentiality; or (d) was independently developed by Recipient without use of Discloser's Confidential Information.
8.4 Compelled disclosure. Recipient may disclose Confidential Information to the extent required by law or court order, provided that Recipient gives Discloser reasonable prior notice (unless legally prohibited) and cooperates with Discloser's reasonable efforts to limit or protect the disclosure.
8.5 Survival. The obligations in this Section 8 will survive expiration or termination of this Agreement for three (3) years.
9. Intellectual property
9.1 Ownership of Services. As between the parties, Sparrowhawk owns all rights, title, and interest in and to the Services, including all software, technology, Content, Marks, improvements, and related intellectual property. Except for the limited licence expressly granted to Customer under this Agreement, Sparrowhawk does not grant any rights or licences to Customer (whether by implication, estoppel, or otherwise).
9.2 Ownership of Customer Data; Aggregated Data; Model Improvement.
(a) Customer Data ownership. As between the parties, Customer owns all rights, title, and interest in and to Customer Data. Sparrowhawk's rights to process Customer Data are limited to those described in Section 3.2A, this Section 9.2, the DPA, and Customer's documented instructions.
(b) Aggregated Data — definition and ownership. "Aggregated Data" means data, statistics, indicators, benchmarks, models, model parameters, embeddings, or insights derived from Customer Data and/or the operation of the Services that have been de-identified and/or aggregated such that they do not identify, and cannot reasonably be used to re-identify, Customer, any of Customer's end-customers, users, or any individual. Sparrowhawk owns all rights, title, and interest in and to Aggregated Data and may use Aggregated Data, during and after the term of this Agreement, for any lawful purpose, including: (i) operating, maintaining, securing, and improving the Services; (ii) developing new products, features, and services; (iii) producing benchmarks, market intelligence, research, and industry insights, including reports made available to other customers, partners, or the public; and (iv) training, tuning, evaluating, and improving algorithms, machine learning models, and analytical features used in the Services or otherwise.
(c) Model and feature improvement. Sparrowhawk may use Customer Data and Aggregated Data to develop, train, tune, evaluate, and improve algorithms, machine-learning models, analytical features, security and fraud-prevention systems, and operational tooling that power the Services. Sparrowhawk applies access controls and audit logging to internal use of Customer Data for these purposes. The de-identification standards referenced in DPA Section 2.4 apply when Customer Data is used for external purposes (publication of benchmarks or industry reports, or sharing with Subprocessors for purposes other than serving Customer), not to Sparrowhawk's internal model training, evaluation, and improvement.
(d) No sale; no cross-tenant disclosure of identifiable data. Sparrowhawk will not: (i) sell Customer Data (as "sale" is defined under any applicable Data Protection Law), except for disclosures of Contributory Data to Contributory Data Partners made in accordance with Section 9.3, which the parties acknowledge may constitute a "sale" or "sharing" of Personal Data under the CCPA/CPRA or similar Data Protection Law; (ii) share Customer Data for cross-context behavioural advertising; (iii) disclose Customer Data to any other Sparrowhawk customer in a form that identifies Customer or any individual; or (iv) use Customer Data for third-party advertising or any purpose unrelated to the Services, the operation of Sparrowhawk's business in providing the Services, the generation of Aggregated Data, or Contributory Data Partnerships under Section 9.3. For clarity, Aggregated Data may be disclosed and licensed to third parties because, by definition, it does not identify Customer or any individual; Contributory Data may be disclosed to Contributory Data Partners solely as, and to the extent, permitted under Section 9.3.
(e) Re-identification prohibited. Sparrowhawk will not attempt to re-identify any Aggregated Data, will not combine Aggregated Data with other data sets in a manner intended to enable re-identification, and will contractually prohibit its Subprocessors and recipients of Aggregated Data from doing so.
(f) Non-Essential Analytics Opt-Out. Customer may, by written notice to privacy@sparrowhawklabs.com, opt out of being included in (i) publishable benchmarks and external industry insights reports, and (ii) Aggregated Data made available to other Sparrowhawk customers, partners, or the public. The opt-out does not apply to: internal model training, tuning, evaluation, or improvement; operating, securing, or supporting the Services; fraud prevention; compliance with applicable law; or Aggregated Data already generated prior to the opt-out. Sparrowhawk will implement an accepted opt-out within thirty (30) days of receipt.
9.3 Contributory Data Partnerships.
(a) Definitions. "Contributory Data" means a minimized subset of Customer Data consisting of (i) accounts-receivable and payment-performance fields (invoice amounts, aging buckets, payment timeliness, and credit-utilization metrics) and (ii) the identity of the retailer or other business debtor to which those receivables relate (its legal and DBA business name, cannabis licence number, and business location), which constitutes commercial information about a business and not personal information about an individual. Contributory Data is stripped of all individual Third-Party PII (the names, email addresses, and telephone numbers of natural persons), free-text fields, pricing terms, and any deal records other than the accounts-receivable fields and business-debtor identity described above. "Contributory Data Partner" means a third party listed on Sparrowhawk's published Data Partner registry that receives Contributory Data in order to generate and provide credit scores, risk signals, suggested credit limits, or similar reports. A Contributory Data Partner is not a Subprocessor (it does not process data on Customer's behalf to deliver the Services) and its receipt of Contributory Data is not Aggregated Data (it is not de-identified/aggregated to the standard in Section 9.2(b)).
(b) Permitted disclosure. Notwithstanding Section 9.2(d), Sparrowhawk may disclose Contributory Data to a Contributory Data Partner solely for that partner's generation of credit scores, risk signals, suggested credit limits, or similar reports, which may be provided back to Sparrowhawk and/or Customer, and in connection with which Sparrowhawk may receive fees (including a margin on report resale). This disclosure may constitute a "sale" or "sharing" of Personal Data under the CCPA/CPRA or other applicable Data Protection Law. Sparrowhawk does not represent or characterise this disclosure as being outside the scope of "sale" or "sharing" under such laws; instead, Sparrowhawk provides the opt-out rights in Section 9.3(f) as its mechanism for honouring any such law's opt-out-of-sale/sharing requirement, in addition to the mechanisms described in Sparrowhawk's Privacy Policy.
(c) Minimization. Contributory Data is limited to the fields defined in Section 9.3(a). Sparrowhawk will not include individual Third-Party PII (the names, email addresses, or telephone numbers of natural persons), free-text notes, pricing terms, or deal records beyond the accounts-receivable fields and business-debtor identity defined in Section 9.3(a) in any disclosure to a Contributory Data Partner.
(d) Partner flow-down obligations. Sparrowhawk will require each Contributory Data Partner, by written agreement, to: (i) use Contributory Data solely for the purpose described in Section 9.3(b); (ii) not resell, license, or further disclose Contributory Data itself (as distinct from scores, signals, or reports the partner derives from it); (iii) not re-identify or attempt to re-identify any individual from Contributory Data; (iv) maintain security measures substantially similar to those required of Subprocessors under Section 7.3; and (v) delete or return Contributory Data upon termination of the applicable Data Partner agreement or Customer's opt-out under Section 9.3(f), whichever is earlier, subject to a reasonable wind-down period.
(e) Advance notice; published registry. Sparrowhawk will maintain a published registry of current Contributory Data Partners at https://www.sparrowhawklabs.com/legal/data-partners and will provide Customer at least thirty (30) days' advance notice (via the registry and email or in-product notice) before including Customer's Contributory Data with a new Contributory Data Partner or a new category of Contributory Data Partner.
(f) Opt-out. Customer may opt out of some or all Contributory Data Partnerships at any time, with prospective effect, by written notice to privacy@sparrowhawklabs.com or via in-product settings. Sparrowhawk will implement an accepted opt-out within fifteen (15) business days and will exclude Customer's data from Contributory Data disclosures from that point forward. Opt-out does not require retroactive recall of Contributory Data already disclosed to a Contributory Data Partner before the opt-out's effective date, except that Sparrowhawk will use commercially reasonable efforts to request deletion from the affected partner. Unless and until Customer exercises this opt-out, Customer is enrolled in Contributory Data Partnerships as a default feature of the Services, consistent with the Non-Essential Analytics Opt-Out model in Section 9.2(f).
9.4 Feedback. If Customer or its users provide Sparrowhawk with suggestions, comments, or other feedback regarding the Services ("Feedback"), Customer hereby grants Sparrowhawk a perpetual, irrevocable, worldwide, royalty-free licence to use, modify, and incorporate such Feedback into the Services or Sparrowhawk's other products and services without restriction or compensation to Customer.
10. Warranties and disclaimers
10.1 Mutual warranties. Each party represents and warrants that it has the legal authority and power to enter into this Agreement and that its performance under this Agreement will comply with applicable laws.
10.2 Sparrowhawk warranties. Sparrowhawk warrants that: (a) during the applicable subscription term, the Services will substantially conform in all material respects to the documentation made available by Sparrowhawk; and (b) Sparrowhawk will not materially reduce the overall security of the Services during the term of this Agreement. Customer's exclusive remedy for breach of this warranty is the re-performance of the Services or, if Sparrowhawk cannot substantially correct the non-conformity within a reasonable time, termination of the affected Order with a pro-rata refund of any prepaid, unused fees.
10.3 Customer warranties. Customer represents and warrants that it has all necessary rights and consents to submit Customer Data to the Services and to permit Sparrowhawk to process Customer Data as contemplated by this Agreement, and that Customer's use of the Services will comply with this Agreement and applicable laws.
10.4 Disclaimers. EXCEPT AS EXPRESSLY PROVIDED IN THIS AGREEMENT, THE SERVICES ARE PROVIDED "AS IS" AND "AS AVAILABLE" AND SPARROWHAWK DISCLAIMS ALL OTHER WARRANTIES, EXPRESS, IMPLIED, OR STATUTORY, INCLUDING ANY IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT. SPARROWHAWK DOES NOT WARRANT THAT THE SERVICES WILL BE ERROR-FREE, UNINTERRUPTED, OR MEET CUSTOMER'S REQUIREMENTS.
11. Indemnity
11.1 Sparrowhawk indemnity. Sparrowhawk will defend Customer against any third-party claim alleging that Customer's authorized use of the Services infringes a valid US patent, copyright, or registered trademark, and will pay any damages and reasonable attorneys' fees finally awarded against Customer (or any settlement approved by Sparrowhawk) arising out of such claim. Sparrowhawk's obligations do not apply to claims arising from: (a) Customer Data; (b) Customer's use of the Services in violation of this Agreement; (c) combinations of the Services with other products, services, or technology not provided by Sparrowhawk; or (d) Customer's modification of the Services.
If Sparrowhawk believes the Services may infringe, Sparrowhawk may: (i) modify the Services to make them non-infringing; (ii) replace the Services with a non-infringing alternative with substantially similar functionality; or (iii) terminate the affected Order and provide a pro-rata refund of any prepaid, unused fees.
11.2 Customer indemnity. Customer will defend Sparrowhawk and its affiliates, and their respective officers, directors, and employees, against any third-party claim arising out of or related to: (a) Customer Data; (b) Customer's use of the Services in violation of this Agreement or applicable law; or (c) any dispute between Customer and its customers, partners, or users relating to Customer's use of the Services. Customer will pay any damages and reasonable attorneys' fees finally awarded against Sparrowhawk (or any settlement approved by Customer) arising out of such claims; except to the extent the claim arises from Sparrowhawk's material breach of this Agreement or the DPA, or from Sparrowhawk's negligence or wilful misconduct, in which case Sparrowhawk shall defend itself against such claims and Customer's indemnity shall not apply.
11.3 Procedures. The indemnified party will: (a) promptly notify the indemnifying party of any claim; (b) give the indemnifying party sole control of the defence and settlement of the claim (except that the indemnifying party may not settle any claim that imposes any non-monetary obligation on the indemnified party without its consent); and (c) provide the indemnifying party with reasonable cooperation at the indemnifying party's expense.
12. Limitation of liability
12.1 Exclusion of certain damages. TO THE MAXIMUM EXTENT PERMITTED BY LAW, NEITHER PARTY WILL BE LIABLE FOR ANY INDIRECT, INCIDENTAL, CONSEQUENTIAL, SPECIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR FOR ANY LOSS OF PROFITS, REVENUE, OR DATA, ARISING OUT OF OR RELATED TO THIS AGREEMENT, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
12.2 Cap on liability. EXCEPT FOR (A) CUSTOMER'S PAYMENT OBLIGATIONS AND (B) CUSTOMER'S BREACH OF SPARROWHAWK'S INTELLECTUAL PROPERTY RIGHTS, EACH PARTY'S AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO THIS AGREEMENT WILL NOT EXCEED THE FEES PAID OR PAYABLE BY CUSTOMER TO SPARROWHAWK UNDER THE APPLICABLE ORDER DURING THE TWELVE (12) MONTH PERIOD IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO THE CLAIM.
For claims arising from each party's indemnification obligations under Section 11, each party's aggregate liability will not exceed two (2) times the fees paid or payable by Customer under the applicable Order during the twelve (12) month period immediately preceding the event giving rise to the claim.
For claims arising solely from Sparrowhawk's infringement of third-party intellectual property rights in the Services (excluding Customer Data and third-party materials), Sparrowhawk's aggregate liability will not exceed two (2) times the amount of fees paid or payable by Customer under the applicable Order during the same twelve (12) month period.
12.3 Unlimited liability carve-outs. Nothing in this Agreement limits or excludes either party's liability for willful misconduct or fraud.
13. Governing law and dispute resolution
13.1 Governing law. This Agreement is governed by and construed in accordance with the laws of the State of Oregon and the federal laws of the United States applicable therein, without regard to its conflict of law rules.
13.2 Informal resolution and arbitration. Before initiating formal legal proceedings, the parties will attempt in good faith to resolve any dispute by informal negotiations for at least thirty (30) days after written notice of the dispute. Any dispute not resolved by negotiation will be finally determined by binding arbitration administered by the American Arbitration Association under its Commercial Arbitration Rules. The seat and place of arbitration will be Deschutes County, Oregon, USA, the language will be English, and the tribunal will consist of one (1) arbitrator.
13.3 Courts and injunctive relief. Nothing in this Agreement prevents either party from seeking temporary or preliminary injunctive relief from a court of competent jurisdiction, including the courts located in Deschutes County, Oregon, to protect its rights pending final resolution of a dispute.
14. Miscellaneous
14.1 Entire agreement. This Agreement, together with all Orders and the DPA, constitutes the entire agreement between the parties relating to the subject matter hereof and supersedes all prior and contemporaneous understandings, agreements, negotiations, and communications, both written and oral.
14.2 Amendments. Any amendment or modification of this Agreement must be in writing and signed by both parties, except that Sparrowhawk may update the DPA or online policies in accordance with their terms.
14.3 Assignment. Neither party may assign this Agreement without the prior written consent of the other party, except that either party may assign this Agreement in connection with a merger, acquisition, or sale of substantially all of its assets. Any attempted assignment in violation of this Section is void. This Agreement will bind and inure to the benefit of the parties and their respective permitted successors and assigns.
14.4 Force majeure. Neither party will be liable for any delay or failure to perform its obligations under this Agreement due to events beyond its reasonable control, including acts of God, natural disasters, war, terrorism, labour disputes, governmental actions, changes in applicable law or regulation (including cannabis-related regulatory actions), internet or telecommunication failures, or third-party service failures.
14.5 Independent contractors. The parties are independent contractors, and nothing in this Agreement will be construed as creating a partnership, joint venture, agency, or employment relationship between the parties.
14.6 Severability. If any provision of this Agreement is held invalid or unenforceable by a court of competent jurisdiction, that provision will be enforced to the maximum extent permissible and the remaining provisions of this Agreement will remain in full force and effect.
14.7 Waiver. No waiver by either party of any breach or default under this Agreement will be deemed a waiver of any preceding or subsequent breach or default.
15. Contact information
If you have any questions about this Agreement, please contact:
Sparrowhawk Labs, Inc.
1605 NW Galveston Ave
Bend, OR 97703
United States
Email: help@sparrowhawklabs.com