Legal & Trust
The Paperwork, Without the Scavenger Hunt.
This is the public home for SBG's current legal, privacy, security, data-processing, and trust information. It is designed to make due diligence easier without publishing internal security playbooks that should remain internal.
Governance
Real Controls. Not the Entire Back-Office Binder.
SBG maintains written information-security, incident-response, and records-retention programs scaled to its current operations, systems, information sensitivity, and service model. SBG also maintains internal launch/readiness records used to track operational prerequisites.
Those internal procedures are not published in full. Publishing an incident playbook or detailed internal operator checklist would expose unnecessary operational detail and could turn changeable internal procedures into misleading public promises. The public Privacy, Security & Access, Terms, and source-custody pages describe the practices clients and reviewers actually need to evaluate.
SBG's ordinary business-record policy retains durable contractual, payment, acceptance, cancellation, audit, verification, security, incident, and project-provenance evidence for seven years after the latest relevant closing event, subject to any controlling legal, contractual, regulated-data, insurance, dispute, or legal-hold requirement. Sensitive working source/data does not automatically inherit that seven-year period.
Current templates
See What SBG May Ask a Client to Sign.
These are informational current templates generated from the same source text used by the SBG legal workflow where applicable. They are not an executed agreement, do not create an engagement, and do not replace the exact project-specific documents presented in an authenticated Client Portal.
Services Agreement
services-agreement-v3
+
Services Agreement
services-agreement-v3
A real engagement also includes its project-specific Statement of Work and any applicable accepted Change Orders or supplemental terms.
SBG SOFTWARE SERVICES - SERVICES AGREEMENT Version: services-agreement-v3 Here's the fun stuff. (Not really.) Legal terms probably are not why you started a software project, but they matter. We have tried to write these terms in normal human language. Please read them before signing. They explain project stages, payments, AI-assisted work, source code, intellectual property, cancellation, security, responsibilities, and what happens when software inevitably decides to behave like software. Ask before signing if something is unclear. 1. AGREEMENT AND PROJECT DOCUMENTS This Services Agreement, the applicable Statement of Work, accepted Change Orders, and expressly incorporated policies govern services provided by SBG Compliance Services, LLC, doing business as SBG Software Services (SBG), to the identified client. SBG Software Services is a trade name of SBG Compliance Services, LLC; the LLC is the contracting service provider and legal party to this Agreement. Project-specific terms in an accepted Statement of Work control a project-specific conflict unless stated otherwise. Accepted documents are versioned records and are not silently edited. Material changes require a new version and new acceptance where required. 2. PROJECT SCOPE The Statement of Work defines the project objective, included work, deliverables, exclusions, client responsibilities, stages, pricing, estimated schedule, third-party dependencies, and project-specific terms. Mentioning a request does not automatically add it to scope. Material scope changes require an approved Change Order before out-of-scope work proceeds. 3. PREPAID PROJECT STAGES Payment for a project stage authorizes only that stage. Completion of one stage does not automatically authorize or charge a later stage, and SBG is not required to begin an unpaid or unauthorized stage. Standard full Build engagements use two 50/50 stages: the first 50% authorizes Stage 1; the second 50% does not become eligible until Stage 1 is completed, presented for client review, and explicitly accepted by the client. That Stage 1 acceptance is an operational project acceptance under the existing engagement, not another contract signature and not an automatic charge. SBG Atelier uses one prepaid $299 stage. Audits, rescues, and other targeted engagements use the service-specific fixed-scope payment structure stated in the applicable Statement of Work. The applicable Statement of Work controls project-specific amounts and authorized scope. 4. FIXED PRICE AND ESTIMATES The approved fixed project price does not increase merely because agreed work takes longer than estimated. Estimated schedules and effort are good-faith planning estimates unless expressly guaranteed. If previously unknown conditions or requested changes materially alter the agreed scope, SBG will explain the issue and obtain approval of any price, scope, or schedule change before performing material out-of-scope work. 5. PAYMENTS, TAXES, AND REFUNDS Published and agreed prices are SBG service fees. If SBG is legally required to collect a sales, use, or similar transaction tax, the applicable amount will be identified before the related payment and does not silently change the agreed service fee. Each party remains responsible for taxes imposed on its own income, payroll, property, or similar obligations. A paid project stage reserves capacity and authorizes SBG to allocate scheduling and technical resources to that stage. If the client voluntarily cancels, abandons, elects not to continue, materially breaches the engagement, or requires SBG to stop because the client requests or persists in unlawful, unauthorized, infringing, fraudulent, abusive, or materially unsafe activity, payments already received for the authorized stage are non-refundable except where applicable law requires otherwise or the limited catastrophic-data-loss remedy below applies. Unauthorized future stages are not charged. If SBG elects to discontinue a paid stage for SBG's own business reason that is not caused by client breach, unlawful or unauthorized conduct, a material security/integrity risk attributable to the client, force majeure, or a third-party condition that makes performance impracticable, SBG will not simply keep payment for work it elects not to perform. SBG will, as reasonably appropriate to the circumstances, complete the agreed affected work, obtain the client's agreement to a substitute outcome, or refund the portion of fees reasonably allocable to material work SBG will not perform. Completed paid deliverables and rights already transferred are not clawed back merely because later work does not proceed. Any final legal allocation remains subject to applicable non-waivable law. CONSUMER TRANSACTIONS. If an engagement is a consumer transaction under applicable law, consumer protections that cannot lawfully be waived remain in effect. When an Ohio consumer payment is a deposit or partial payment governed by Ohio Administrative Code 109:4-3-07, SBG will provide the required dated written or properly consented electronic receipt describing the applicable services, price, payment amount, refund conditions, additional known costs, and other information required by that rule. If Ohio Administrative Code 109:4-3-09 applies and eight weeks would elapse after SBG accepted consumer money without delivery of the ordered services, SBG will use a legally permitted path before that point: delivery, a full refund, a written extended-delay notice that states the duration of the delay and offers the required refund if requested, or an agreed good-faith substitute where legally permitted. Nothing in this Agreement reduces a remedy or disclosure right that Ohio Revised Code Chapter 1345 or another applicable consumer-protection law does not permit the parties to waive. Client-provided materials remain the client's property and are handled under applicable return, retention, and security procedures. If SBG's own material error while handling client-controlled source code or data in SBG's custody directly causes catastrophic loss of that material, and the material cannot reasonably be restored from an available known-good client/SBG backup, recovery package, source repository, provider recovery method, or other reasonably available recovery source after good-faith recovery efforts, SBG may elect to re-perform the affected work, restore/reconstruct the affected material where reasonably feasible, or refund fees actually paid to SBG for the affected project stage. If SBG elects and pays that refund, the refund is the client's exclusive monetary remedy for that specific catastrophic-loss event to the maximum extent permitted by law. This limited remedy does not apply to pre-existing corruption, client or third-party modification/deletion, provider failure outside SBG's reasonable control, credentials/access withheld from SBG, unsupported environments, force-majeure events, or loss that a reasonably available client-controlled backup/repository can restore. Nothing in this paragraph limits a right or remedy that applicable law does not permit the parties to waive. 6. PAYMENT DISPUTES AND CHARGEBACKS If a payment is reversed, disputed, charged back, or withdrawn, SBG may immediately pause the affected unpaid/disputed work, future stages, or delivery obligations reasonably connected to that disputed payment while the issue is investigated. Transaction history is preserved rather than rewritten. A dispute over a later or separate amount does not by itself revoke rights already transferred in fully paid completed custom deliverables or authorize SBG to withhold an unrelated earlier completed deliverable solely as leverage. Clients are encouraged to contact SBG before initiating a payment dispute. Nothing here limits rights that cannot legally be waived. 7. CLIENT RESPONSIBILITIES, AUTHORITY, AND TESTING BOUNDARY The client will provide reasonably accurate and timely information, decisions, materials, and authorized access needed for the engagement. The client represents that it owns, controls, or otherwise has sufficient authority to provide all supplied materials and to authorize SBG to access, inspect, audit, test, modify, or otherwise interact with every system, account, repository, environment, data set, and third-party resource expressly placed in scope. Authorization is limited to the accepted scope and does not extend to unrelated systems, tenants, users, accounts, or data. The client will identify material access restrictions, production-safety requirements, contractual limits, regulated environments, and systems that must not be modified. SBG may refuse or pause activity where authority is unclear or the requested activity would create an unreasonable legal, security, or integrity risk. Unless a Statement of Work expressly authorizes otherwise, an Audit is read-only wherever reasonably possible and does not authorize destructive security testing, denial-of-service activity, social engineering, credential attacks, or testing against systems outside the accepted boundary. Rescue and modification work may change in-scope systems only as authorized by the accepted Statement of Work or Change Order. Client authorization does not require SBG to violate law, third-party rights, platform terms, or reasonable security restrictions. 8. AI-ASSISTED DEVELOPMENT AI-assisted engineering is a standard and non-optional part of SBG's methodology. The incorporated AI-Assisted Development Policy applies to every engagement. A client that cannot authorize appropriate AI-assisted software development should not engage SBG. AI is used as an additional set of eyes; it does not eliminate SBG's responsibility to evaluate and verify work within the agreed scope. 9. CONFIDENTIALITY AND SOURCE MATERIALS Each party will use the other party's non-public information disclosed for the engagement only as reasonably necessary to perform, receive, administer, secure, or enforce the engagement and will apply reasonable safeguards appropriate to the information. Confidential information includes client source code, non-public project information, credentials or access details disclosed through an approved method, proprietary business information, and SBG non-public methods or materials. Confidentiality obligations do not apply to information the receiving party can reasonably demonstrate was already lawfully known without a duty of confidentiality, becomes public through no breach of this Agreement, is independently developed without use of the other party's confidential information, or is lawfully received from a third party without a confidentiality duty. A party may disclose information when required by law, subpoena, court order, or governmental demand, and where legally permitted will provide reasonable notice so the other party may seek appropriate protection. No electronic storage or transmission method can be guaranteed absolutely secure. A source archive is not authorized merely because an intake was submitted, an account or project exists, or preliminary discussions occurred. If SBG determines that an authorized Audit, Rescue, or eligible Maintenance workflow genuinely requires a client source ZIP, SBG will open a project-specific authenticated Secure Source Upload only after the applicable proposal/agreement, supplemental-data, and payment gates have cleared. Client source ZIPs are accepted only through that designated SBG project-portal workflow; ordinary email attachments and third-party file-sharing links are not approved source-archive submission methods. Repository, platform, test, or staging access may be coordinated separately through the project's approved access workflow when that is the more appropriate least-privilege method. SBG may decline to receive or use source sent outside the approved workflow, may direct the client to resubmit through the authorized channel, and may be unable to perform work that genuinely requires source if the client will not use the approved transfer process. Source material received unexpectedly outside the approved workflow does not expand project scope or authorization and may be isolated, rejected, or securely removed when appropriate, subject to incident, dispute, legal-hold, or other binding preservation requirements. 10. CREDENTIALS, CLIENT DATA, AND REGULATED INFORMATION Use least-privilege, temporary, delegated, project-specific, or revocable access where feasible. SBG's current operating policy is not to request or accept raw shared passwords, private keys, authentication tokens, MFA/recovery codes, or secret API keys through ordinary intake, email, portal messages, project notes, source ZIPs, or another improvised channel. Prefer official collaborator, team, temporary-account, provider-delegation, or equivalent least-privilege access. If a platform genuinely requires a raw shared secret and no safe delegated mechanism is available, SBG will pause the access-dependent work and may decline that portion of the engagement rather than instruct the client to send the secret through an unsafe channel. A future dedicated secret-exchange method, if SBG deliberately implements and approves one, must be separately authorized; this Agreement does not represent that such a vault exists today. If SBG discovers an exposed secret, SBG may restrict access, notify the client, recommend rotation or revocation, and securely remove unnecessary copies as appropriate. Discovery does not authorize use outside the engagement. The client is responsible for having a lawful basis and sufficient authority to provide SBG access to personal information, confidential records, and other data placed in scope. When SBG processes client-controlled data solely to perform the engagement, SBG will use it only as reasonably necessary for the agreed services, documented client instructions, security, legal obligations, or other purposes expressly permitted by this Agreement. Selecting a sensitive-data category during intake does not authorize transmission of the underlying records. Protected health information, full payment-card data, Social Security numbers, government-ID images, children's records, or other regulated/high-risk data must not be provided unless SBG has expressly accepted that handling in writing and any required addendum, Business Associate Agreement, provider capability, access controls, or other safeguards are in place. Where applicable privacy law requires a controller-processor, business-service-provider, or similar data-processing contract for client-controlled personal data, the parties will execute the required addendum before that covered processing begins. SBG does not represent that an engagement is HIPAA, PCI DSS, SOC, ISO, FedRAMP, or otherwise certified merely because a project involves regulated data or uses an underlying provider with its own certifications. 11. SECURITY, INCIDENTS, AND EMERGENCY PROTECTION SBG will use reasonable administrative and technical safeguards appropriate to the information and access within the accepted engagement, including least-privilege practices where feasible. SBG maintains written security, incident-response, and records-retention procedures scaled to its current size, activities, resources, systems, and information sensitivity and periodically reviews those procedures as its operations materially change. SBG may pause a deployment, disable an SBG-controlled transfer authorization, revoke temporary access, or take other reasonable protective action when continuing would create a material security or integrity risk. If SBG becomes aware of a confirmed security incident involving client-controlled computerized personal information in SBG's custody that triggers an applicable legal or contractual notification duty, SBG will notify the client in an expeditious manner consistent with applicable law, reasonable investigation, restoration of system integrity, and lawful law-enforcement delay. The parties will reasonably cooperate regarding information each possesses that is necessary to evaluate and respond to the incident. This provision does not shift a notification duty that applicable law places on a different party. If cancellation occurs during a technically sensitive operation, SBG may perform reasonably necessary stabilization, shutdown, backup, rollback, security, or preservation actions before stopping. 12. COMPLETION, REVIEW, AND DEFECTS A stage may be marked complete when its material deliverables have been performed in accordance with the Statement of Work. Stage completion does not mean the entire project is complete unless it is the final stage. Following server-recorded operational completion, the client has 30 calendar days to REPORT a possible reproducible material failure to conform to the original approved scope. The 30-day period is a reporting deadline, not a promise that investigation, classification, repair, or other resolution will be completed within 30 days. A case timely reported during the window remains eligible for review and, if it qualifies, resolution after the reporting window closes. New functionality, preference changes, excluded work, third-party behavior outside SBG's control, unsupported environments, misuse, or later modifications are not defects merely because the client would prefer different behavior. If no material scope-related nonconformity is reported during the review period, deliverables may be treated as accepted for project-completion purposes subject to rights that cannot legally be waived. 13. SUPPORT AFTER COMPLETION A completed SBG service engagement includes a 30-calendar-day reporting window for genuine defects in the SBG-delivered original-scope work, beginning from the server-recorded operational completion timestamp. For an Independent Audit, this support applies to a material nonconformity in SBG's Audit report or other Audit deliverable relative to the approved Audit scope; it does not include repair of defects in the audited application. For Build, Atelier, and Rescue, the support applies to qualifying defects in SBG-delivered in-scope work. A timely reported qualifying case may remain under review or resolution after the reporting window itself closes. This is defect support, not indefinite free support or a guaranteed repair-completion SLA. Maintenance, enhancements, new functionality, unrelated pre-existing defects, third-party changes, and later client or third-party modifications may require a new engagement. 14. CANCELLATION Cancellation is requested through the authenticated Client Portal where available. Submission immediately blocks new project stages and ordinary forward work while allowing reasonably necessary stabilization, shutdown, backup, rollback, security, evidence-preservation, or similar protective actions. A cancellation request is an active reconciliation state, not an indefinite holding pattern. SBG will keep the request in operational attention until it is finalized or until SBG communicates the specific reconciliation issue preventing finalization. Finalization resolves the project into its permanent cancelled state and records the final cancellation evidence. Payment/refund treatment follows Section 5 and depends on the reason work ends; the Client cancellation form does not expand or waive those terms. A finalized cancelled project cannot be reopened; future work requires a new intake, proposal, agreement, and authorization. Cancellation does not erase historical contracts, payment records, communications, security evidence, or audit records. 15. CLIENT PORTAL AND RECORD RETENTION Cancellation does not immediately eliminate portal access. Appropriate historical agreements, project records, receipts, and cancellation records may remain available. Clients are encouraged to download and retain copies of documents they wish to preserve. Before routine closure of an inactive portal account, SBG should provide reasonable advance notice when practical so the client has an opportunity to retain available records. Advance notice may be shortened or omitted where prompt restriction or closure is reasonably required for security, fraud, legal, provider, or similar protective reasons. Closure of account access does not necessarily require deletion of contractual, payment, security, audit, dispute-resolution, accounting, or other records SBG reasonably retains for legitimate business or legal purposes. SBG applies a purpose-based retention framework. As its ordinary business-record standard, SBG retains durable contractual, payment, acceptance, cancellation, audit, verification, security, incident, and project-provenance evidence for seven years after the latest relevant project-closing event, such as operational completion, final cancellation/termination, final payment or payment-dispute resolution, final Maintenance term closure, or related incident/dispute closure. The seven-year period is an SBG business-record policy, not a representation that every record is legally required to be retained for seven years, and a longer or shorter binding legal, tax, contractual, regulated-data, insurance, or legal-hold requirement controls where applicable. Working source-transfer copies, credentials, regulated data, and other sensitive working material do not automatically inherit the seven-year period and should be deleted, returned, or de-identified when their legitimate operational purpose ends, subject to active support/recovery needs, disputes, incidents, legal holds, Maintenance baseline requirements, or separately agreed retention terms. Non-secret source-release hashes and custody/provenance evidence may be retained with the durable project record after underlying archive bytes are deleted. The posted Privacy Policy provides additional information. 16. INTELLECTUAL PROPERTY AND DELIVERABLE RIGHTS The client retains ownership of materials and intellectual-property rights it owned before the engagement or validly provides for use in the engagement. Subject to full payment of amounts applicable to the completed custom deliverables, SBG hereby assigns to the client all right, title, and interest that SBG owns and is legally able to transfer in the custom source code, custom documentation, and other custom deliverables specifically identified in the applicable Statement of Work, including assignable copyrights in those custom deliverables. In a staged engagement, a fully paid completed stage may contain completed custom deliverables whose transferable rights pass even if a later stage never proceeds. A paid but unfinished stage does not automatically convert incomplete internal working material, experiments, drafts, or uncompleted items into completed deliverables unless the applicable Statement of Work or a written termination/cancellation resolution expressly identifies them as deliverables. This assignment does not include SBG background technology, reusable tools, methodologies, generic components, templates, know-how, pre-existing materials, open-source software, third-party technology, or rights SBG does not own. To the extent SBG-owned background material is embedded in a paid custom deliverable and is necessary to use that deliverable, SBG grants the client a perpetual, worldwide, non-exclusive, royalty-free license to use, execute, reproduce, modify, and distribute that embedded background material solely as part of or as reasonably necessary to use, maintain, or further develop the paid deliverable. Open-source and third-party components remain subject to their applicable licenses and terms. AI-assisted development does not expand the rights SBG can transfer; to the extent any element is not protectable by copyright or is subject to third-party rights, SBG transfers only the rights it actually owns or can grant. The client represents that materials it supplies may be used for the engagement and remains responsible for third-party rights in client-supplied content, code, data, branding, and other materials. The client grants SBG a limited, non-exclusive license during the engagement and any reasonably necessary support or handoff period to access, reproduce, modify, test, and otherwise use client-supplied materials solely as reasonably necessary to perform, verify, secure, support, document, or hand off the agreed services. 17. THIRD-PARTY SERVICES, OPEN-SOURCE SOFTWARE, AND ACCOUNTS Projects may depend on hosting providers, development platforms, repositories, APIs, AI services, libraries, frameworks, storage providers, email systems, payment providers, domains, open-source software, or other third parties governed by their own terms, licenses, pricing, and availability. SBG may use commercially reasonable standard libraries, frameworks, and open-source components where appropriate to the scope. Applicable third-party and open-source license obligations pass through and are not overridden by this Agreement. Where practical, production resources intended to belong to the client should ultimately be held in or transferred to client-controlled accounts. SBG cannot transfer ownership of technology or accounts it does not own. The current SBG project portal does not collect full payment-card numbers; payment may occur through an external method or provider, while SBG may preserve limited payment metadata and administrative authorization evidence in the project record. 18. HANDOFF Final handoff is an SBG-recorded project event identifying what SBG prepared, made available, delivered, or deployed, when, by whom, how, and relevant version or commit references where applicable. An SBG administrative handoff record does not by itself prove client receipt, completed download, successful deployment, or client acceptance; separate evidence controls those claims when applicable. After handoff, SBG is not responsible for defects or security conditions introduced by client or third-party modifications unless SBG later agrees to review those modifications. 19. AUDITS, RESCUE, AND EXISTING SYSTEMS An Audit is a scoped, point-in-time independent evaluation of an existing application relative to the original builder or implementation being examined, based on the systems, versions, environments, access, evidence, and test methods reasonably available during the engagement. An Audit may identify defects, risks, weaknesses, inconsistencies, evidence, severity, confidence, and recommended outcomes, but cannot prove that no undiscovered defect, vulnerability, malicious code, data-quality problem, or future failure exists. Unless the Statement of Work expressly says otherwise, an Audit is not a penetration test, regulatory certification, legal opinion, formal compliance attestation, or repair engagement and does not provide implementation-ready replacement code or step-by-step remediation instructions. The Audit service's included defect-support window applies to SBG's Audit/report deliverable, not free repair of the audited application's defects. Rescue or repair work is separately scoped and does not make SBG responsible for defects, vulnerabilities, architecture, data corruption, technical debt, or other conditions that existed before SBG's work or outside the accepted repair boundary. SBG may require a recoverability baseline, backup, staging environment, or other protective measure before changing an existing system. Verification performed by SBG after SBG's own Rescue work is a post-repair verification step, not an organizationally independent third-party audit. The client may use Audit findings independently, hire another provider, or separately engage SBG for remediation. 20. THIRD-PARTY CHANGES AND OUTAGES SBG is not responsible for failures caused solely by subsequent third-party API, platform, dependency, browser, operating-system, hosting, provider, policy, or service changes outside SBG's reasonable control. Cloud or provider outages and other events outside reasonable control may affect schedules without automatically constituting breach. 21. PROFESSIONAL SERVICES; NO ERROR-FREE GUARANTEE SBG will perform agreed services with reasonable professional care. Software can contain defects, dependencies, platform limitations, security risks, and conditions not reasonably discoverable during an engagement. Unless expressly stated, SBG does not warrant that software will be completely error-free, uninterrupted, immune from future vulnerabilities, or compatible with every future technology change. 22. REFUSAL OR DISCONTINUATION OF WORK The client represents that the intended use and instructions supplied to SBG are lawful and that the client has the rights and authority described in Section 7. SBG may decline, pause, or discontinue work involving unauthorized access, malicious software, fraud, unlawful activity, intellectual-property infringement, abusive conduct, material security threats, material breach, or requests SBG reasonably believes should not be performed. When the concern is reasonably capable of clarification or cure, SBG may pause and ask for clarification, corrected authorization, or a safer/lawful instruction before deciding whether work can continue. Urgent security, fraud, unlawful-activity, or integrity concerns may require immediate suspension. If the concern remains unresolved, SBG may discontinue the affected work. Financial treatment when work ends follows Section 5 and distinguishes client-caused/breach or prohibited-work situations from an SBG business decision to stop work for reasons not caused by the client. 23. NO UNSTATED CERTIFICATION Unless expressly identified as a deliverable, SBG does not provide legal, accounting, regulatory certification, attestation, or formal compliance certification services. Certifications or controls held by an underlying platform do not automatically certify a client's application. 24. ELECTRONIC TRANSACTIONS, SIGNATURES, AND RECORDS The parties agree to conduct the engagement and related notices electronically unless applicable law, a valid withdrawal of electronic-record consent, or a later written agreement requires another method. When SBG's authorized Admin uses the authenticated legal workflow and expressly confirms EXECUTE AND PRESENT, SBG intends that act, the authenticated Admin identity, and the resulting execution record to serve as SBG's electronic execution/signature of the exact document versions and hashes presented. Client electronic acceptance requires the signer's full legal name, a fresh Opportunity to Review acknowledgement for the exact document/package, electronic-signature intent, a fresh Electronic Records Disclosure acknowledgement, and acceptance of the incorporated AI policy where applicable. For a business, professional, or organizational engagement, the signing record also requires the Client / Organization identity and the signer's title or authority. For an engagement classified as primarily personal, family, or household use, the authenticated individual signs as the Individual Client and is not required to invent a business name or business title. The engagement's primary-use classification must be resolved before a new legal package can be accepted; a checkbox or signer label does not override facts that reasonably show a different primary purpose or waive non-waivable law. Those acknowledgements and classifications are recorded with the execution-package evidence; a prefilled identity or direct request cannot bypass them. The client signer intends the electronic acceptance action and typed name to serve as the client's electronic signature. SBG records server timestamps, authenticated identity information, review/consent evidence, document versions, cryptographic content hashes, and relevant audit evidence. ELECTRONIC RECORDS DISCLOSURE. Before consenting, the client is informed that: (a) electronic-record consent applies to the current SBG engagement and related records that SBG is legally permitted to provide electronically; (b) the client may withdraw consent for future legally required electronic records through the authenticated Legal & Documents control, without affecting records validly provided before withdrawal or obligations already incurred; (c) withdrawal may require SBG to use a paper/manual process or pause a future transaction until an available lawful delivery method is arranged; (d) the client may update electronic contact information in Account and may request a reasonable paper copy through the Client Portal or SBG legal contact; SBG currently charges no separate SBG fee for a reasonable paper copy; and (e) access requires an internet-connected device, a reasonably current web browser, a working email address, and the ability to view, save, print, or otherwise retain ordinary web/PDF records. The electronic consent action requires the client to confirm that the client can view and download the records presented in the SBG portal. If those technical requirements materially change in a way that creates a material risk that a consumer cannot access later records for which consent is required, SBG will provide the updated requirements and obtain renewed consent where applicable law requires it. Accepted documents are made available in a form the client can view and download for later reference, subject to portal and retention policies. SBG will not intentionally inhibit a recipient's ability to print or store a legally required electronic record. Nothing in this section waives a required disclosure's content, timing, delivery method, verification requirement, retention right, or other consumer protection that applicable law does not permit the parties to waive. 25. INDEPENDENT CONTRACTOR SBG is an independent contractor. This Agreement does not create employment, partnership, franchise, fiduciary, agency, or joint-venture status except as expressly agreed in writing. 26. PUBLICITY SBG will not publicly identify the client, publish confidential project materials, or use client trademarks as portfolio material without permission. 27. LIMITATION OF LIABILITY; ALLOCATION OF RISK To the maximum extent permitted by applicable law, neither party is liable to the other for indirect, incidental, special, exemplary, punitive, or consequential damages arising from the engagement, including lost profits or lost business opportunities, regardless of the legal theory asserted, except to the extent applicable law does not permit that category of damages to be excluded. To the maximum extent permitted by law, SBG's aggregate monetary liability for claims arising out of or relating to a Statement of Work will not exceed the fees actually paid to SBG under the Statement of Work giving rise to those claims. The limited catastrophic-data-loss remedy in Section 5 is part of, and does not increase, that aggregate monetary cap unless applicable law requires otherwise. The exclusions and SBG liability cap in this Section do not apply to the extent a final judgment determines liability that applicable law prohibits the parties from limiting, including liability arising from SBG's fraud, willful misconduct, or gross negligence where such a limitation is not enforceable. This Section does not erase the client's obligation to pay undisputed amounts properly due, does not claw back rights already transferred under Section 16, and does not limit the client's separate obligations for a covered third-party claim under Section 28. No amount stated here is intended as liquidated damages or a penalty. 28. CLIENT-SUPPLIED MATERIALS; THIRD-PARTY CLAIMS The client represents that it has sufficient rights and authority to provide the content, code, data, branding, materials, systems, access, and instructions it places within the engagement and to authorize the uses SBG is asked to make of them. If a third party brings a claim against SBG arising directly from (a) client-supplied materials that infringe, misappropriate, or violate that third party's intellectual-property, privacy, publicity, confidentiality, or other rights; (b) a client instruction, access authorization, or requested use for which the client lacked required authority or that was unlawful; or (c) the client's unlawful or unauthorized use, modification, publication, or distribution of a deliverable after delivery, the client will defend and indemnify SBG against the portion of final damages, judgments, approved settlements, and reasonable outside attorneys' fees and litigation costs actually resulting from that covered third-party claim, but only to the extent caused by those client-controlled matters. SBG will provide reasonably prompt notice of a covered claim after becoming aware of it. Delay in notice reduces the client's obligation only to the extent the delay materially prejudices the defense. The client may control the defense using qualified counsel reasonably acceptable to SBG, and SBG will provide reasonable cooperation at the client's expense for material out-of-pocket costs. SBG may participate through its own counsel at its own expense. The client may not settle a covered claim without SBG's prior written consent if the settlement admits wrongdoing by SBG, imposes a non-monetary obligation or restriction on SBG, requires SBG to pay an amount not covered by the settlement, or fails to provide SBG a full release from the covered claim; SBG will not unreasonably withhold consent to an otherwise reasonable settlement. The client has no duty under this Section to the extent a claim is caused by SBG's breach of the governing agreement, SBG's negligence or other legally actionable conduct, SBG's unauthorized use of client materials, SBG activity outside the client-authorized scope, or SBG-supplied/background material that the client neither supplied nor specifically required SBG to use. This Section addresses third-party claims only. Direct disputes between SBG and the client remain governed by the other provisions of the Agreement. Nothing in this Section requires the client to indemnify SBG for SBG's own negligence or misconduct. 29. GOVERNING LAW AND VENUE This Agreement is governed by the laws of the State of Ohio, without regard to conflict-of-law principles, except where applicable law requires otherwise. To the maximum extent permitted by applicable law, the parties consent to exclusive jurisdiction and venue for a dispute arising from this Agreement or an applicable Statement of Work in the state courts located in Franklin County, Ohio, or, when federal subject-matter jurisdiction exists, the United States District Court for the Southern District of Ohio. This venue agreement does not override a non-waivable right to another forum that applicable law grants to a consumer or other protected party. 30. GENERAL TERMS Formal legal notices to SBG may be sent to legal@sbgcompliance.com or to SBG Compliance Services, LLC, 2606 Hilliard Rome Rd, Unit #V257, Hilliard, OH 43026. General support correspondence should use info@sbgcompliance.com or the authenticated Client Portal where available. The parties may establish additional project-specific notice procedures in an accepted Statement of Work or Change Order. If a provision is unenforceable, the remainder survives to the extent permitted by law, and an unenforceable provision is applied only to the maximum lawful extent rather than rewritten to create a materially different bargain. Failure to enforce a term once does not waive future enforcement. Headings are for readability and do not change substantive meaning. Except for persons expressly receiving enforceable rights under an accepted project document, this Agreement does not create third-party beneficiary rights. Provisions that logically survive termination, including confidentiality, ownership, incurred payment obligations, third-party-claim obligations, liability limitations, dispute terms, retention obligations, and document integrity, continue as appropriate. 31. ENTIRE AGREEMENT AND ORDER OF PRECEDENCE The accepted Services Agreement, applicable Statement of Work, accepted Change Orders, and expressly incorporated policies constitute the agreement for the engagement and supersede prior discussions on the same subject. For project-specific conflicts, an accepted Change Order controls the Statement of Work, which controls this Services Agreement, subject to applicable law.
AI-Assisted Development Policy
ai-assisted-development-v2
+
AI-Assisted Development Policy
ai-assisted-development-v2
This policy is incorporated into SBG engagements and AI-assisted engineering is a standard condition of service.
AI-Assisted Development Policy SBG Software Services uses artificial intelligence and automated development tools as part of its normal software engineering, analysis, testing, debugging, security review, documentation, and quality-assurance processes. Modern applications can contain thousands of interconnected files, functions, dependencies, permissions, and application states. AI-assisted tools provide an additional layer of analysis and help SBG investigate complex systems efficiently. AI assistance does not replace SBG's responsibility for the services it agrees to perform. SBG remains responsible for engineering decisions and for the review, testing, evaluation, and verification included in the engagement. AI-generated output is not treated as inherently correct. Use of appropriate AI-assisted development tools is a condition of working with SBG Software Services and cannot be disabled on a project-by-project basis. If a client or organization prohibits AI-assisted software development or cannot authorize its use, SBG will not accept that engagement. Some development platforms and services selected for a project may incorporate AI-assisted functionality as part of their normal operation. SBG may use those integrated capabilities and other appropriate AI-assisted tools. SBG will not knowingly provide passwords, private keys, authentication tokens, payment credentials, or similar authentication secrets to an external AI service merely for convenience. SBG does not intentionally use client confidential information to train a general-purpose model for SBG or another client. External AI and development providers remain subject to their own terms, security practices, and data-handling controls, which may change over time. A project involving regulated or unusually sensitive data may require provider review, data minimization, de-identification, an additional agreement, or a decision not to process that data through a particular AI-assisted tool. Confidential project information remains subject to the confidentiality and security obligations of the Services Agreement.
Data Processing Addendum
Conditional DPA · data-processing-addendum-v2
+
Data Processing Addendum
Conditional DPA · data-processing-addendum-v2
Used only when applicable privacy law or the approved project facts require a controller/processor, business/service-provider, or similar processing addendum.
SBG SOFTWARE SERVICES - DATA PROCESSING ADDENDUM Version: data-processing-addendum-v2 Project / SOW: Project-specific reference appears in an executed engagement Client: SAMPLE CLIENT — informational template Service Provider / Processor: SBG Compliance Services, LLC d/b/a SBG Software Services Address: 2606 Hilliard Rome Rd, Unit #V257, Hilliard, OH 43026 Legal and privacy notices: legal@sbgcompliance.com USE CONDITION This Data Processing Addendum (“DPA”) supplements the parties' Services Agreement and applicable Statement of Work only when SBG's review, applicable privacy law, or the client's documented legal obligations require a controller-processor, business-service-provider, contractor, or similar data-processing agreement for client-controlled personal information. It does not mean that every privacy statute applies to the client, SBG, or the project. If a mandatory privacy-law requirement applies and conflicts with this DPA, the parties will apply the mandatory requirement to the extent required by law. 1. RELATIONSHIP TO THE SERVICES AGREEMENT This DPA is incorporated into the parties' governing Services Agreement for the identified project when electronically executed. The Services Agreement remains in effect except where this DPA imposes a more specific requirement for covered personal information. This DPA does not expand project scope, authorize new data collection, or authorize SBG to receive regulated/high-risk information that remains blocked by another SBG data-handling gate. 2. DEFINITIONS AND ROLES “Client Personal Data” means personal information, personal data, or a similar protected category that the client controls and makes available to SBG solely so SBG can perform the agreed services. “Applicable Privacy Law” means a privacy or data-protection law that actually applies to the relevant processing and requires contractual obligations addressed by this DPA. For covered Client Personal Data, the client generally acts as the controller, business, or equivalent party determining the purpose and means of processing, and SBG acts as the processor, service provider, contractor, or equivalent party processing the data on the client's behalf. The parties acknowledge that SBG separately acts for its own legitimate business purposes with respect to its own account, contracting, security, billing, legal, and operational records as described in the Services Agreement and Privacy Policy. 3. CLIENT INSTRUCTIONS AND AUTHORITY The client represents that it has the authority, notices, consents, contracts, or other lawful basis required to provide SBG access to Client Personal Data and instruct SBG to process it for the engagement. The Services Agreement, Statement of Work, accepted Change Orders, this DPA, and documented lawful project instructions constitute the client's instructions to SBG. SBG may decline or pause an instruction that exceeds scope, conflicts with law or a third-party restriction, or creates an unreasonable security, privacy, or integrity risk. 4. PURPOSE LIMITATION SBG will process Client Personal Data only as reasonably necessary to perform, secure, verify, support, document, or hand off the agreed services; comply with documented client instructions; comply with applicable law; or protect legal rights, security, and system integrity as permitted by the governing agreement. To the extent Applicable Privacy Law requires these restrictions, SBG will not: - sell Client Personal Data; - retain, use, or disclose Client Personal Data outside the direct business relationship except as permitted by Applicable Privacy Law and the governing agreement; - use Client Personal Data for cross-context behavioral advertising or targeted advertising on SBG's own behalf; - combine Client Personal Data with personal data received from another person or collected from SBG's own consumer interactions except where Applicable Privacy Law permits the combination for a business/service-provider purpose; - intentionally use Client Personal Data to train a general-purpose AI model for SBG or another client. 5. DATA MINIMIZATION The parties will seek to limit Client Personal Data to what is reasonably necessary for the project. Synthetic, masked, redacted, or de-identified data should be used for development and testing when it is reasonably sufficient. Selecting a data category during intake or review does not itself authorize transmission of the underlying records. 6. CONFIDENTIALITY AND PERSONNEL SBG will limit access to Client Personal Data to persons who reasonably need access for the engagement and who are subject to appropriate confidentiality obligations. SBG will use least-privilege, project-specific, temporary, delegated, or revocable access where feasible. Authentication secrets must not be placed in ordinary intake, messages, or email merely for convenience. 7. SECURITY SBG will maintain reasonable administrative and technical safeguards appropriate to the nature of the Client Personal Data, the project, and SBG's role. SBG's current security program is governed internally by its Written Information Security Program and includes, as applicable, authenticated role-separated portals, server-side authorization, least-privilege practices, secure source-transfer controls, audit evidence, session protection, data minimization, incident response, and retention controls. No security program can guarantee that an incident will never occur. This DPA is not a representation that SBG or the client application has a certification unless a specific certification is expressly identified in writing. 8. SUBPROCESSORS AND SERVICE PROVIDERS The client authorizes SBG to use service providers reasonably necessary to operate SBG or perform the engagement, subject to the Services Agreement, this DPA, and Applicable Privacy Law. SBG will require a service provider that processes covered Client Personal Data on SBG's behalf to protect that data through contractual or other legally required obligations appropriate to the provider's role. Current categories may include application/hosting infrastructure, authentication, object storage/source transfer, repository/development platforms, transactional email, AI-assisted development tools, and other providers reasonably necessary for the engagement. Provider availability, terms, subprocessors, and architecture may change. A material provider/data-path change involving unusually sensitive or regulated data may require renewed review before covered processing continues. 9. SECURITY INCIDENTS SBG will investigate suspected unauthorized access to, acquisition of, use of, disclosure of, alteration of, or destruction of Client Personal Data in SBG's custody. If SBG becomes aware of a confirmed incident that triggers an applicable legal or contractual notice obligation to the client, SBG will notify the client without unreasonable delay and in an expeditious manner consistent with applicable law, reasonable investigation, restoration of system integrity, and lawful law-enforcement delay. SBG will provide reasonably available information necessary for the client to evaluate and respond to the incident and will reasonably cooperate regarding containment, investigation, and legally required notices. This DPA does not silently transfer a statutory notification duty from the party on whom applicable law places it. 10. INDIVIDUAL / CONSUMER REQUESTS If SBG receives a request from an individual concerning Client Personal Data controlled by the client, SBG may direct the requester to the client unless Applicable Privacy Law requires SBG to act directly. Taking into account the nature of the processing and information available to SBG, SBG will provide reasonable assistance required by Applicable Privacy Law and the governing agreement when the client needs SBG's help responding to an applicable request to access, correct, delete, obtain, or restrict covered Client Personal Data. 11. COMPLIANCE ASSISTANCE Taking into account the nature of processing and information available to SBG, SBG will provide reasonable cooperation required by Applicable Privacy Law concerning security obligations, data-protection assessments, incident response, or regulator inquiries that relate directly to SBG's processing of Client Personal Data for the project. Work materially outside the accepted service scope may require separate scoping unless Applicable Privacy Law requires SBG to provide it without additional charge. 12. COMPLIANCE INFORMATION; AUDITS Upon reasonable request where required by Applicable Privacy Law or a binding client obligation disclosed before acceptance, SBG will make available information reasonably necessary to demonstrate compliance with this DPA for SBG's covered processing. The parties will first use documentation, questionnaires, existing evidence, and remote review where reasonably sufficient. Any additional audit right required by Applicable Privacy Law will be exercised on reasonable notice, during normal business operations, subject to confidentiality/security restrictions, without access to unrelated client information, and in a manner designed to avoid unreasonable disruption. This section does not create an unlimited right to penetration testing, source-code access, production access, or inspection of unrelated SBG/client systems. 13. RETURN, DELETION, AND RETENTION SBG will retain underlying Client Personal Data only for as long as reasonably necessary for the approved engagement, support/recovery/security needs, documented client instructions, or a binding legal/contractual requirement. At completion or termination, SBG will return, delete, or de-identify Client Personal Data in SBG-controlled working systems as reasonably appropriate to the engagement and Applicable Privacy Law, subject to legal holds, security investigations, backup/provider limitations, and records SBG is legally permitted or required to retain. SBG's ordinary seven-year business-record standard applies to durable contractual, execution, payment, security, and project-provenance evidence; it does not automatically require SBG to retain the underlying Client Personal Data or source archives for seven years. SBG's internal Records Retention Schedule governs ordinary operational defaults. 14. DE-IDENTIFIED DATA If SBG receives or creates data that Applicable Privacy Law treats as de-identified and relies on that status, SBG will take reasonable measures required by Applicable Privacy Law to maintain the information in de-identified form and will not attempt to re-identify it except where law permits re-identification for testing whether de-identification processes satisfy legal requirements or another expressly permitted purpose. 15. SENSITIVE / REGULATED INFORMATION This DPA does not by itself authorize SBG to receive protected health information, full payment-card data, Social Security numbers, government-ID images, children's records, or other regulated/high-risk data. Those categories may require a separate Addendum, BAA, provider review, architecture change, or additional safeguards before access is allowed. 16. CROSS-BORDER DATA TRANSFERS If a project actually requires a legally mandated cross-border transfer mechanism, localization commitment, standard contractual clauses, or similar transfer instrument not already satisfied by the approved architecture, the parties will identify and execute the required mechanism before the affected transfer begins. This DPA does not silently represent that a particular international transfer mechanism applies. 17. CHANGES IN LAW OR PROJECT FACTS The client will notify SBG when a material change in the project's data categories, data subjects, purposes, geography, client regulatory role, or provider architecture changes the privacy requirements disclosed to SBG. SBG may reopen review, require a revised DPA/addendum, change the provider/data path, or pause affected processing until the requirement is resolved. 18. STATE-SPECIFIC MANDATORY TERMS To the extent an Applicable Privacy Law requires a processor/service-provider contract to contain a particular mandatory restriction, cooperation duty, assessment provision, audit right, deletion obligation, confidentiality requirement, or subprocessor flow-down not fully stated above, that mandatory requirement is incorporated only to the extent legally required for the covered processing. The parties will execute a reasonable amendment if a separate written form is necessary to document the requirement. 19. NO UNSTATED CERTIFICATION OR LEGAL OPINION This DPA is a contractual processing instrument. It is not a certification, attestation, legal opinion, or representation that every privacy law applies to or is satisfied by the client's application. Each party remains responsible for obligations applicable to its own role, business, notices, collection practices, and instructions. 20. TERM AND SURVIVAL This DPA becomes effective when electronically executed and continues for as long as SBG processes Client Personal Data covered by it. Purpose limitation, confidentiality, security, incident cooperation, return/deletion, and applicable audit/compliance obligations survive termination for as long as SBG retains covered Client Personal Data or the obligation otherwise survives by law. 21. ELECTRONIC EXECUTION AND RECORD INTEGRITY The parties may execute this DPA through SBG's authenticated electronic-signature workflow. Each signer's typed legal name, authenticated account, client/organization identity and title, authority attestation, electronic-signature consent, fresh Electronic Records Disclosure acknowledgement, deliberate execution action, server timestamp, and the exact version and SHA-256 content hash of this DPA are intended to evidence the signer's electronic signature and intent to be bound. A later DPA template revision does not silently alter an earlier executed DPA.
Health Data Handling Addendum
Conditional regulated-data addendum · health-data-addendum-v2
+
Health Data Handling Addendum
Conditional regulated-data addendum · health-data-addendum-v2
Screening for health or other sensitive data does not itself authorize sending those records to SBG.
SBG SOFTWARE SERVICES - HEALTH DATA HANDLING ADDENDUM Version: health-data-addendum-v2 Service Provider: SBG Compliance Services, LLC d/b/a SBG Software Services Address: 2606 Hilliard Rome Rd, Unit #V257, Hilliard, OH 43026 Legal notices: legal@sbgcompliance.com IMPORTANT USE BOUNDARY This Addendum is used only when SBG's regulated-data review determines that a project involves identifiable or otherwise sensitive health information but a HIPAA Business Associate Agreement is not the applicable agreement for the relationship. It is not a representation that HIPAA, the FTC Health Breach Notification Rule, or any particular state health-privacy law applies or does not apply. If the facts change, SBG may require a different agreement, additional safeguards, provider changes, or renewed review before covered processing continues. 1. RELATIONSHIP TO THE SERVICES AGREEMENT This Health Data Handling Addendum supplements the accepted Services Agreement, Statement of Work, and any accepted Change Orders for the identified project. The Services Agreement remains in effect except where this Addendum expressly imposes a more specific requirement for health information. This Addendum does not expand the project scope or authorize SBG to access information that has not been approved through the regulated-data review. 2. HEALTH INFORMATION COVERED BY THIS ADDENDUM For this Addendum, “Health Data” means information within the approved project scope that identifies or can reasonably be linked to an individual and relates to health, wellness, symptoms, diagnoses, treatment, medications, tests, measurements, fitness, reproductive or sexual health, health-care services, or similar health-related characteristics or activity. Health Data does not include information that has been de-identified so that it is no longer reasonably linkable to an individual under the standard applicable to the project. 3. CLIENT AUTHORITY AND INSTRUCTIONS The client represents that it has the legal authority and appropriate notices, consents, contracts, or other lawful basis required to provide SBG access to Health Data and to instruct SBG to process it for the project. The client will identify material legal, contractual, geographic, platform, or internal-policy restrictions before SBG receives the affected information. SBG may refuse an instruction that would exceed the agreed scope, conflict with applicable law, violate a third-party restriction, or create an unreasonable security or privacy risk. 4. PURPOSE LIMITATION AND DATA MINIMIZATION SBG will access, use, disclose, or otherwise process Health Data only as reasonably necessary to perform, secure, verify, support, document, or hand off the agreed services; follow documented client instructions; comply with applicable law; or protect legal rights and system integrity as permitted by the governing agreement. SBG will seek to minimize the Health Data used for development and testing. Synthetic, masked, or de-identified information should be used instead of identifiable production Health Data when reasonably sufficient for the task. 5. NO SALE, ADVERTISING USE, OR GENERAL-PURPOSE MODEL TRAINING SBG will not sell Health Data, use it for cross-context behavioral advertising, or intentionally use client Health Data to train a general-purpose AI model for SBG or another client. AI-assisted tools may be used only when the regulated-data review has approved the relevant data path and provider controls. If an approved provider cannot support the required handling, the affected Health Data must be excluded from that provider or the architecture must change before processing continues. 6. ACCESS AND SECURITY SBG will use reasonable administrative and technical safeguards appropriate to the approved Health Data and project risk. Access should be least-privilege, project-specific, temporary, delegated, or revocable where feasible. Authentication secrets must use an approved secure method and must not be placed in ordinary intake, project notes, or email. SBG may suspend access or processing when continuing would create a material security, privacy, legal, or integrity risk. 7. SERVICE PROVIDERS AND SUBPROCESSING SBG will not intentionally provide Health Data to a service provider that has not been reviewed for the approved use. Where applicable law or the governing client relationship requires contractual privacy, security, confidentiality, or breach obligations for a service provider, SBG will require the necessary arrangement before that provider receives the covered Health Data. Provider availability, certifications, and contractual programs can change; approval of a project is therefore tied to the reviewed architecture and does not permanently approve every future provider or feature. 8. SECURITY EVENTS AND BREACH COOPERATION SBG will investigate suspected unauthorized access to, acquisition of, use of, or disclosure of Health Data in its custody. If SBG becomes aware of a confirmed event that creates an applicable legal or contractual notification duty, SBG will notify the client without unreasonable delay and provide information reasonably available to support the client's response. The parties will cooperate regarding containment, investigation, legally required notices, and preservation of relevant evidence. Responsibility for notice to individuals, regulators, or other parties follows applicable law and any more specific written allocation between the parties; this Addendum does not silently transfer a statutory duty from the party on whom the law places it. 9. INDIVIDUAL REQUESTS If SBG receives a request from an individual concerning Health Data controlled by the client, SBG may direct the requester to the client unless applicable law requires SBG to respond directly. SBG will provide reasonable assistance required by the governing agreement or applicable law when the client needs SBG's help locating, correcting, exporting, restricting, or deleting Health Data within SBG-controlled project systems. 10. RETENTION, RETURN, AND DELETION SBG will retain identifiable Health Data only for as long as reasonably necessary for the approved engagement, security and recovery needs, legal obligations, or a separately agreed retention requirement. At project completion or termination, SBG will return, transfer, delete, or de-identify Health Data in SBG-controlled project systems as reasonably appropriate to the engagement and applicable law, subject to legal holds, security investigations, immutable audit evidence that does not itself contain the underlying Health Data, and other records SBG is legally permitted or required to retain. 11. CHANGES IN FACTS OR SCOPE The client must promptly tell SBG if the project begins collecting new categories of Health Data, changes from synthetic/de-identified information to identifiable production data, adds a new health-data source or provider, changes the client's regulatory role, or otherwise materially changes the facts used for the regulated-data review. SBG may pause affected work and reopen the review. No prior clearance is a permanent waiver for materially changed processing. 12. NO UNSTATED COMPLIANCE CERTIFICATION This Addendum is a contractual data-handling instrument. It is not a legal opinion, regulatory certification, HIPAA certification, SOC report, PCI certification, or representation that the client application complies with every law applicable to the client's business. Each party remains responsible for obligations applicable to its own role. 13. TERM AND SURVIVAL This Addendum begins when electronically executed by the parties and continues for as long as SBG processes Health Data covered by it. Purpose limitation, confidentiality, security, incident cooperation, and return/deletion obligations survive termination for as long as SBG retains covered Health Data. 14. ELECTRONIC EXECUTION This Addendum may be executed through SBG's authenticated electronic-signature workflow. A typed legal name combined with the signer's authenticated account, authority attestation, electronic-signature consent, fresh Electronic Records Disclosure acknowledgement, deliberate execution action, server timestamp, and the exact version and cryptographic hash of this Addendum is intended to constitute the signer's electronic signature. The retained execution package identifies the exact document executed by each party.
HIPAA Business Associate Agreement
Conditional BAA template · hipaa-baa-v2
+
HIPAA Business Associate Agreement
Conditional BAA template · hipaa-baa-v2
A BAA is project- and role-specific. This sample does not mean SBG has accepted PHI for a project or that every provider path is HIPAA-ready.
SBG SOFTWARE SERVICES - BUSINESS ASSOCIATE AGREEMENT Version: hipaa-baa-v2 Project / SOW: Project-specific reference appears in an executed engagement Regulated Client: SAMPLE REGULATED CLIENT — informational template Regulated Client role: Covered Entity or Business Associate, as determined for the actual engagement Business Associate / Subcontractor Business Associate: SBG Compliance Services, LLC d/b/a SBG Software Services Address: 2606 Hilliard Rome Rd, Unit #V257, Hilliard, OH 43026 Legal notices: legal@sbgcompliance.com USE CONDITION This Business Associate Agreement (“BAA”) is presented only after SBG's regulated-data review determines that SBG will act as a “business associate” or business-associate subcontractor under the HIPAA Rules for the identified engagement. It does not authorize PHI access by itself. SBG may receive or access PHI only after this BAA is fully executed and SBG has confirmed that the approved architecture, service providers, access method, and project scope are compatible with the required handling. 1. INCORPORATION AND DEFINITIONS This BAA supplements the parties' Services Agreement and applicable Statement of Work. “HIPAA Rules” means the Privacy, Security, Breach Notification, and Enforcement Rules at 45 C.F.R. Parts 160 and 164, as amended. Terms including Breach, Designated Record Set, Disclosure, Electronic Protected Health Information, Individual, Minimum Necessary, Protected Health Information (“PHI”), Required by Law, Secretary, Security Incident, Subcontractor, Unsecured Protected Health Information, and Use have the meanings assigned by the HIPAA Rules. “Regulated Client” means the client identified above in its applicable role as a Covered Entity or Business Associate. “SBG” means SBG Compliance Services, LLC, doing business as SBG Software Services. 2. PERMITTED AND REQUIRED USES AND DISCLOSURES SBG may Use or Disclose PHI only as necessary to perform the services expressly described in the applicable Statement of Work and documented client instructions, as permitted by this BAA, or as Required by Law. SBG will not Use or Disclose PHI in a manner that would violate Subpart E of 45 C.F.R. Part 164 if done by the Regulated Client, except to the extent a use or disclosure is expressly permitted for a business associate by the HIPAA Rules and this BAA. SBG will apply the Minimum Necessary standard to Uses, Disclosures, and requests for PHI as required by the HIPAA Rules and the Regulated Client's communicated minimum-necessary requirements. 3. MANAGEMENT, ADMINISTRATION, AND LEGAL RESPONSIBILITIES SBG may Use PHI for its proper management and administration or to carry out its legal responsibilities only to the extent permitted by the HIPAA Rules. SBG may Disclose PHI for those purposes only if the Disclosure is Required by Law or SBG obtains reasonable assurances that the recipient will hold the information confidentially, use or further disclose it only as Required by Law or for the purpose for which it was disclosed, and notify SBG of any breach of confidentiality of which the recipient becomes aware. SBG is not authorized to use PHI for unrelated marketing, sale, general product development, or general-purpose AI model training. 4. SAFEGUARDS AND SECURITY RULE SBG will use appropriate safeguards to prevent Use or Disclosure of PHI other than as provided by this BAA and will comply with the applicable requirements of Subpart C of 45 C.F.R. Part 164 with respect to Electronic Protected Health Information. SBG will use reasonable administrative, physical, and technical safeguards appropriate to its role and the approved environment. SBG may immediately pause PHI processing or access when necessary to address a material security, privacy, legal, or integrity risk. 5. REPORTING IMPERMISSIBLE USES, DISCLOSURES, BREACHES, AND SECURITY INCIDENTS SBG will report to the Regulated Client any Use or Disclosure of PHI not provided for by this BAA of which SBG becomes aware, including a Breach of Unsecured Protected Health Information as required by 45 C.F.R. § 164.410, and any Security Incident of which SBG becomes aware. Breach notice will be provided without unreasonable delay and in no case later than the period required by 45 C.F.R. § 164.410 after discovery. SBG will provide the information required by that rule to the extent known and will supplement information as it becomes available. Routine unsuccessful Security Incidents, such as blocked scans, unsuccessful connection attempts, or failed authentication attempts that do not result in unauthorized access, Use, Disclosure, modification, or destruction of PHI or interference with system operations, are deemed reported on an ongoing basis unless the parties agree otherwise in writing. 6. SUBCONTRACTORS SBG will ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on SBG's behalf agrees in writing to restrictions, conditions, and requirements that are at least as protective as those applicable to SBG with respect to that PHI, including applicable Security Rule obligations for Electronic Protected Health Information. SBG will not intentionally route PHI through a provider that has not been approved for the regulated data path. If a required provider arrangement is unavailable, the affected PHI processing will remain blocked until the architecture or provider arrangement is changed. 7. ACCESS TO PHI AND DESIGNATED RECORD SETS To the extent SBG maintains PHI in a Designated Record Set for the Regulated Client, SBG will make that PHI available to the Regulated Client, or to an Individual if expressly directed by the Regulated Client and permitted by law, as necessary for the Regulated Client to satisfy its obligations under 45 C.F.R. § 164.524. The parties may document reasonable technical procedures and response times consistent with the Regulated Client's legal obligations. 8. AMENDMENT To the extent SBG maintains PHI in a Designated Record Set, SBG will make PHI available for amendment and incorporate amendments as directed by the Regulated Client as necessary for the Regulated Client to satisfy 45 C.F.R. § 164.526. 9. ACCOUNTING OF DISCLOSURES SBG will document Disclosures and make information available to the Regulated Client as necessary for the Regulated Client to satisfy its obligations under 45 C.F.R. § 164.528, to the extent those obligations apply to the PHI and activity within SBG's control. 10. PERFORMANCE OF REGULATED CLIENT OBLIGATIONS To the extent SBG is expressly engaged to carry out one or more obligations of the Regulated Client under Subpart E of 45 C.F.R. Part 164, SBG will comply with the requirements of Subpart E that apply to the Regulated Client in performing those specific obligations. 11. ACCESS BY THE SECRETARY SBG will make its internal practices, books, and records relating to the Use and Disclosure of PHI received from, or created or received by SBG on behalf of, the Regulated Client available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining compliance with the HIPAA Rules, in the time and manner required by law. 12. REGULATED CLIENT RESPONSIBILITIES The Regulated Client will notify SBG of limitations in its Notice of Privacy Practices, changes in or revocation of an Individual's permission, and restrictions on the Use or Disclosure of PHI to the extent any such limitation, change, revocation, or restriction may affect SBG's permitted or required Uses or Disclosures. The Regulated Client will not request SBG to Use or Disclose PHI in a manner that would violate the HIPAA Rules if performed by the Regulated Client, except to the extent the HIPAA Rules permit a business associate to perform the requested activity. The Regulated Client is responsible for identifying the systems, data sets, and instructions that are within the approved PHI boundary. 13. RETURN OR DESTRUCTION AT TERMINATION At termination of this BAA, SBG will, if feasible, return or destroy PHI received from the Regulated Client or created, maintained, or received by SBG on the Regulated Client's behalf that SBG still maintains in any form, and will retain no copies except as permitted by the HIPAA Rules or agreed for a lawful purpose. If return or destruction is infeasible, SBG will extend the protections of this BAA to the retained PHI, limit further Uses and Disclosures to the purposes that make return or destruction infeasible, and return or destroy the PHI when it is no longer needed for that purpose. Audit evidence should retain only non-PHI integrity and execution metadata whenever reasonably possible. 14. TERM; TERMINATION FOR MATERIAL BREACH This BAA becomes effective when fully electronically executed and continues while SBG creates, receives, maintains, or transmits PHI subject to this BAA. If the Regulated Client determines that SBG has violated a material term of this BAA, the Regulated Client may terminate the affected engagement or BAA as permitted by the HIPAA Rules and governing Services Agreement. Where cure is legally permitted and appropriate, the parties may attempt cure before termination; urgent privacy or security risk may require immediate suspension of PHI processing. 15. INTERPRETATION; CHANGES IN LAW This BAA will be interpreted to permit compliance with the HIPAA Rules. A reference to a HIPAA provision means that provision as amended from time to time. If a legal change makes a term materially incomplete or inconsistent with applicable requirements, the parties will cooperate in good faith to amend the BAA. A public-policy update or template revision does not silently amend an already executed BAA; a material amendment requires a new version and execution. 16. NO BROADER CERTIFICATION Execution of this BAA establishes contractual obligations for the specific relationship; it is not a certification that SBG, the Regulated Client, the client application, or every underlying provider is “HIPAA certified.” SBG will not accept PHI into a provider path until the required provider capability and contractual safeguards for that path have been reviewed. 17. ELECTRONIC EXECUTION AND RECORD INTEGRITY The parties may execute this BAA through SBG's authenticated electronic-signature workflow. Each signer's typed legal name, authenticated account, client/organization identity and title, authority attestation, electronic-signature consent, fresh Electronic Records Disclosure acknowledgement, deliberate execution action, server timestamp, and the exact version and SHA-256 content hash of this BAA are intended to evidence that signer's electronic signature and intent to be bound. The retained execution package will identify both parties' execution evidence and the exact document version executed. A later template revision does not alter an earlier executed BAA.
Maintenance
Annual Maintenance Is Its Own Deliberate Agreement.
Current annual Maintenance is $299 per eligible completed SBG project, includes four documented reviews and a defined minor corrective/compatibility boundary, and does not auto-renew. It is separate from the applicable 30-day post-completion defect-reporting window and is not unlimited tickets, feature development, redesign, emergency/SLA service, or a promise that every concern is an included repair. SBG must first mark the completed project eligible for Maintenance. The term-specific agreement is then presented in the authenticated Client Portal with exact term dates and fresh electronic acceptance, and any active term is tied to the Maintenance Source Baseline SBG accepts for that term.
Read Maintenance details →Contact
Need the Boring Official Details?
SBG Compliance Services, LLC d/b/a SBG Software Services
2606 Hilliard Rome Rd, Unit #V257, Hilliard, OH 43026
legal@sbgcompliance.com · legal/privacy notices
info@sbgcompliance.com · general business/support
Active clients should use the authenticated Client Portal for project-specific legal, privacy, security, and document questions when practical so the communication can remain tied to the project record.