Oryx Customer Agreement
Online Standard Terms and Conditions
These Standard Terms and Conditions govern Customer’s access and use of the Services identified in the applicable Order Form.
1. Definitions
- “Aggregate Data” means data derived from Customer Data, Oryx Data, or use of the Services that has been combined with other data and de-identified so that it does not identify, and cannot reasonably be used to identify, Customer or any individual.
- “Authorized User” means an employee, contractor, clinician, or other individual authorized by Customer to use the Services on Customer’s behalf..
- “Customer” means the specific legal entity on whose behalf this Agreement is accepted, as identified in the applicable Order Form.
- “Customer Data” means data, content, records, files, and information submitted to, stored in, transmitted through, or generated by Customer or its Authorized Users through the Services, including PHI, but excluding Aggregate Data, De-Identified Data, and Oryx Data.
- “De-Identified Data” means data derived from Customer Data that does not identify Customer or any individual and cannot reasonably be used to identify Customer or any individual. To the extent the source data constitutes PHI, De-Identified Data must be created in accordance with the de-identification requirements of HIPAA.
- “Documentation” means Oryx’s then-current user documentation for the Services.
- “Intellectual Property Rights” means any and all intellectual property rights throughout the world, including, without limitation, any and all patents, copyrights, trademarks, applications for any of the foregoing, trade secret rights, moral rights, unregistered design rights, rights to know-how, inventions, and algorithms, and any and all similar or equivalent rights throughout the world.
- “Oryx Data” means data and information generated, collected, or derived by or through the operation, support, security, maintenance, or use of the Services, including system logs, technical data, diagnostic data, performance data, usage data, telemetry, metadata, and statistical information. Oryx Data does not include Customer Data or PHI, except to the extent such information has been de-identified or aggregated in accordance with this Agreement, the BAA, and applicable law.
- “Order Form” means an ordering document, quote, or enrollment form executed by the Parties that identifies the Services, pricing, and applicable commercial terms.
- “Oryx Technology” means Oryx’s software, tools, systems, technology, methodologies, processes, algorithms, models, workflows, user interfaces, designs, architecture, know-how, trade secrets, inventions, techniques, templates, configurations, and other materials developed, owned, licensed, or controlled by Oryx, including: (a) all materials existing before the Effective Date or developed independently of this Agreement; (b) all modifications, improvements, enhancements, adaptations, derivative works, and extensions of the foregoing; (c) all work product and deliverables created by Oryx in connection with the Professional Services, excluding Customer Data and Customer Materials; and (d) all Intellectual Property Rights in the foregoing.
- “PHI” means Protected Health Information as defined by HIPAA, to the extent created, received, maintained, or transmitted by Oryx on behalf of Customer.
- “Professional Services” means onboarding, implementation, migration, configuration, integration, training, revenue generating, consulting, or other professional services identified in an applicable Order Form.
- “Services” means the hosted software, subscription services, and related services identified in the applicable Order Form.
- “Security Incident” means an unauthorized acquisition of, access to, use of, or disclosure of Customer Data that materially compromises the security, confidentiality, or integrity of such Customer Data.
2. Order of Precedence
- In the event of a conflict among the Agreement, the following order shall control: (a) the applicable Order Form; (b) the Startup Addendum, if applicable; (c) the Business Associate Agreement with respect to PHI; (d) these Standard Terms; and (e) the website-linked operational policies expressly incorporated by reference.
3. Subscription Grant
- Subject to this Agreement and Customer’s payment of all applicable fees, Oryx grants Customer during the Term a limited, non-exclusive, non-transferable, non-sublicensable right for Customer and its Authorized Users to access and use the Services and Documentation solely for Customer’s internal business operations.
4. Use Restrictions
- Customer shall not, and shall not authorize, permit, or enable any Authorized User or any third party not authorized by Oryx to: (a) reverse engineer, decompile, or disassemble the Services, except to the limited extent prohibited by law; (b) resell, sublicense, rent, lease, timeshare, or otherwise provide access to the Services to a third party; (c) use the Services in violation of applicable law; (d) interfere with or disrupt the integrity, availability, or performance of the Services; (e) circumvent usage limitations or security controls; or (f) use the Services to transmit malicious code or unlawful content.
5. Customer Responsibilities
- Customer is responsible for all acts and omissions of its Authorized Users and for maintaining the confidentiality of credentials under its control.
- Customer represents that it has all rights, notices, consents, and authorizations necessary for Oryx to process Customer Data as contemplated by this Agreement, the BAA, and applicable law.
- Customer is responsible for the accuracy, quality, legality, and means of acquisition of Customer Data and for the security of Customer-controlled devices, networks, and workstations.
6. Ownership; Customer Data; Professional Services; Feedback
- Oryx Technology. As between the Parties, Oryx and its licensors retain all right, title, and interest in and to the Oryx Technology, Oryx Data, Services, Documentation, and all Intellectual Property Rights therein. Except for the limited rights expressly granted to Customer under this Agreement, Customer acquires no right, title, or interest in or to the Oryx Technology, Oryx Data, Services, Documentation, or any Intellectual Property Rights therein.
- Professional Services and Work Product. Unless otherwise expressly stated in the applicable Order Form, Oryx retains all right, title, and interest in and to all work product, deliverables, configurations, templates, processes, documentation, and other materials created, developed, or reduced to practice by Oryx in connection with the Professional Services, including all modifications, improvements, and derivative works thereof. Subject to Customer’s payment of all applicable fees, Oryx grants Customer a limited, non-exclusive, non-transferable, non-sublicensable right during the Term to use such work product solely in connection with Customer’s authorized use of the Services.
Oryx may use, without restriction, any general ideas, concepts, knowledge, skills, methodologies, processes, techniques, and experience acquired or developed in performing the Professional Services, provided that Oryx does not disclose Customer Data or Customer Confidential Information except as permitted by this Agreement.
- Customer Data and Customer Materials. As between the Parties, Customer retains all right, title, and interest in and to Customer Data. Customer grants Oryx a limited, non-exclusive right to host, process, copy, transmit, display, and otherwise use Customer Data solely as necessary to provide, secure, support, and improve the Services and as otherwise permitted by this Agreement, the BAA, and applicable law.
- Oryx Data. As between the Parties, Oryx retains all right, title, interest in and to Oryx Data. Oryx may collect and use Oryx Data for lawful business purposes, including operating, securing, supporting, monitoring, analyzing, and improving the Services, developing new products and features, capacity planning, billing, troubleshooting, and preventing fraud or misuse.
- Feedback. If Customer provides suggestions, enhancement requests, or other feedback regarding the Services, Oryx may use such feedback without restriction or obligation, provided such use does not identify Customer or disclose Customer Confidential Information.De-Identified and Aggregated Data. Oryx may create Aggregate Data and De-Identified Data from Customer Data and Oryx Data. As between the Parties, Oryx owns all right, title, and interest in and to Aggregate Data and De-Identified Data and may use and disclose such data for lawful business purposes, including analytics, benchmarking, research, product development, service improvement, security, and operations, provided that:
- the data does not identify Customer, any patient, or any other individual;
- PHI is de-identified in accordance with HIPAA;
- personal information is de-identified in accordance with applicable privacy law; and
- Oryx does not attempt to re-identify the data except as permitted by applicable law.
8. Confidentiality and Non-disparagement
- Each Party shall protect the other Party’s Confidential Information using at least reasonable care and shall not use or disclose such Confidential Information except as necessary to perform under this Agreement or as otherwise expressly permitted herein.
- “Confidential Information” includes non-public business, technical, security, financial, product, pricing, and customer information and, with respect to Customer, includes Customer Data and PHI. Confidential Information does not include information that the receiving party can demonstrate: (a) is or becomes public through no fault of the receiving party; (b) was lawfully known to the receiving party without restriction before receipt; (c) is independently developed without use of the disclosing party’s Confidential Information; or (d) is lawfully obtained from a third party without restriction.
- A receiving party may disclose Confidential Information to the extent required by law, provided it gives advance notice where legally permitted and reasonably cooperates with efforts to seek confidential treatment.
- Customer shall not permit its Authorized Users, officers, directors, employees, agents or representatives to make, publish, post or communicate to any person or entity (including through any public or private forum, social media platform, review site or other public-facing channel) of any false, defamatory, negative, adverse or derogatory statements concerning Oryx, its products, Services, or personnel (including its officers/directors).
- Customer may use Oryx’s name, logo, branding, and trademarks in a positive and professional manner, but shall not use them in any manner that negatively reflects upon Oryx or that suggests affiliation with, sponsorship by, endorsement by, or authorization from Oryx on any online forum, social media account, group, website, or similar channel.
9. Privacy and Security
- Oryx shall maintain a written information security program containing administrative, technical, and physical safeguards designed to protect the security, confidentiality, and integrity of Customer Data, including PHI, in a manner appropriate to the nature of the Services and as required by applicable law.
- Oryx may use subprocessors and subcontractors to provide the Services, provided that Oryx remains responsible for their performance and imposes written obligations on them that are materially protective of Customer Data and PHI consistent with applicable law.
- Oryx shall notify Customer without undue delay after confirming a Security Incident involving Customer Data that materially compromises the security, confidentiality, or integrity of such Customer Data. To the extent the incident involves PHI, the parties’ rights and obligations shall also be governed by the BAA.
10. Fees; Taxes; Payment Method
- Customer shall pay the fees set forth in each Order Form. Unless otherwise stated in the Order Form, the Recurring Subscription Fees are billed monthly in advance and onboarding fees are due as stated in the Order Form.
- Fees are exclusive of all sales, use, excise, VAT, GST, and similar taxes, duties, or levies, all of which shall be paid by Customer, excluding taxes based on Oryx’s net income, property, or employees. Applicable taxes may be added to invoices as separate line items.
- Customer shall maintain valid bank account information on file to facilitate payment by ACH for all onboarding fees, Recurring Subscription Fees, and other amounts due under this Agreement, and authorizes Oryx to initiate ACH transactions for amounts due in accordance with the applicable Order Form. ACH is Oryx’s preferred payment method; however, Oryx may accept payment by credit card upon request. Oryx may accept payment by credit card upon request. Payments made by credit card are subject to an additional convenience fee, not to exceed three percent (3%). Convenience fees do not apply to payments made via Oryx-initiated ACH.
11. Late Payment; Suspension for Nonpayment
- If any undisputed amount remains unpaid for more than fifteen (15) days after its due date, Oryx may provide written notice of nonpayment. If such amount remains unpaid for 15 days after such notice, Oryx may suspend access to the Services until all past due amounts are paid in full.
- Oryx may charge interest on overdue undisputed amounts at the lesser of 1.5% per month or the maximum rate permitted by law, and Customer shall reimburse Oryx for reasonable collection costs.
12. Term; Renewal; Committed Fees
- This Agreement begins on the Effective Date stated in the applicable Order Form and continues for the Initial Term stated in that Order Form. Thereafter, unless as otherwise stated in the applicable Order Form, this Agreement shall automatically renew for successive three (3) month periods. Furthermore, Customer may elect not to renew this Agreement by providing Oryx at least thirty (30) days’ prior written notification before the end of the then-current term.
- Oryx reserves the right to institute a rate increase of an amount not to exceed five percent (5%) at the time of each Renewal Term.
- All Fees as set forth in the Order Form for each committed term are non-cancelable and non-refundable, except as expressly provided in this Agreement. If this Agreement is terminated by Customer due to Oryx’s uncured material breach, Oryx shall refund any prepaid Recurring Subscription Fees on a pro rata basis for the period following the date of termination
13. Upgrades; Downgrades; Usage Verification
- Customer may purchase additional locations, modules, features, hardware, or higher service tiers during the Term at Oryx’s then-current standard pricing. Unless otherwise stated in the applicable quote or Order Form, fees for upgrades will be prorated for the remainder of the current billing month and billed thereafter at the updated recurring rate.
- Any newly added module or upgraded tier shall carry a minimum six (6) month commitment for that specific add-on. Customer may not remove or downgrade an upgraded module or tier until the applicable upgrade commitment has been completed and all associated fees have been paid.
- If fees are based on locations, active providers, active patients, transaction volume, or other usage metrics, Customer shall maintain records reasonably sufficient to verify such metrics, and upon reasonable prior notice, Oryx may verify the applicable metrics no more than once annually during normal business hours, solely to confirm billing accuracy.
14. Implementation; Support; Third-Party Services
- Any onboarding, implementation, migration, training, or other professional services purchased by Customer will be described in the applicable Order Form. Unless as otherwise stated herein, such Services are limited to the scope expressly described therein.
- If the Services provide links or integrations to third-party services, such third-party services are governed by the terms and policies of the applicable third party, and Oryx is not responsible for such third-party services except to the extent expressly stated in this Agreement.
15. Warranties; Disclaimer
- Oryx warrants that during the Term, the Services will perform in all material respects in accordance with the Documentation and that any implementation or support services purchased under an Order Form will be performed in a professional and workmanlike manner.
- EXCEPT AS EXPRESSLY PROVIDED IN THIS AGREEMENT, THE SERVICES ARE PROVIDED “AS IS,” AND ORYX DISCLAIMS ALL OTHER WARRANTIES, WHETHER EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE, INCLUDING IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT.
16. Indemnification
- Oryx shall defend Customer against any third-party claim alleging that the unmodified Services, when used in accordance with this Agreement, infringe or misappropriate such third party’s U.S. intellectual property rights, and Oryx shall indemnify Customer against damages, costs, and reasonable attorneys’ fees finally awarded or paid in settlement of such claim, provided Customer promptly notifies Oryx, gives Oryx sole control of the defense and settlement, and provides reasonable cooperation.
- Customer shall defend Oryx against any third-party claim arising from: (a) Customer Data infringing, violating, or misappropriating such third party’s rights; (b) Customer’s or its Authorized Users’ unlawful or unauthorized use of the Services; or (c) Customer’s breach of applicable law or required patient consents in connection with Customer Data. Customer shall indemnify Oryx against damages, costs, and reasonable attorneys’ fees finally awarded or paid in settlement of such claim, subject to the same notice, control, cooperation, and settlement-consent rules.
- The indemnifying party may not settle any covered claim in a manner that admits fault or imposes non-monetary obligations on the indemnified party without the indemnified party’s prior written consent, not to be unreasonably withheld.
17. Limitation of Liability
- Except for Excluded Claims, neither Party shall be liable for any indirect, incidental, special, consequential, exemplary, or punitive damages, or for any loss of profits, revenues, goodwill, use, or data, even if advised of the possibility of such damages.
- Except for Excluded Claims, each Party’s total aggregate liability arising out of or relating to this Agreement shall not exceed the fees paid or payable by Customer to Oryx under this Agreement during the twelve (12) months preceding the event giving rise to the claim.
- “Excluded Claims” means: (a) Customer’s payment obligations; (b) either Party’s gross negligence, willful misconduct, or fraud; and (c) either Party’s indemnification obligations and breaches of confidentiality or privacy/security obligations, but only to the extent expressly stated in the applicable Order Form or a negotiated amendment.
18. Suspension; Termination
- Oryx may suspend Customer’s access to the Services upon notice if: (a) Customer materially breaches this Agreement and fails to cure within the applicable cure period; (b) Customer’s use poses a material security risk to the Services or other customers; (c) suspension is required by law or governmental order; or (d) Customer fails to pay undisputed fees as provided in this Agreement.
- Either Party may terminate this Agreement upon written notice if the other Party materially breaches this Agreement and fails to cure such breach within thirty (30) days after receipt of notice, except that nonpayment and certain security-related breaches may have shorter cure periods as expressly stated herein.
- Upon expiration or termination, Customer shall cease use of the Services and pay all amounts due, including any committed fees that become due under this Agreement.
19. Data Export and Deletion
- For up to thirty (30) days following expiration or termination, Customer may request one export of Customer Data in a commercially reasonable format. Thereafter, subject to the BAA and applicable law, Oryx may delete Customer Data in accordance with its standard retention policies.
20. Website-Linked Policies
- Oryx’s then-current Support Policy, Service Level Addendum, Privacy Policy, Cookie Notice, Acceptable Use Policy, Security Overview, and Subprocessor List are incorporated by reference into this Agreement. Oryx may update those policies from time to time, provided that no such update will materially diminish Customer’s rights or Oryx’s material obligations during the then-current committed term.
- Core pricing, term and renewal, license grant, confidentiality, indemnity, limitation of liability, data ownership, and BAA obligations may not be modified solely by website posting.
21. Miscellaneous
- This Agreement is governed by the laws of the State of Delaware, without regard to its conflict of laws principles. The state and federal courts located in Delaware shall have exclusive jurisdiction and venue over any action arising out of or relating to this Agreement, and each party consents to such jurisdiction and venue.
- Neither Party may assign this Agreement without the other Party’s prior written consent, except that either Party may assign this Agreement without consent in connection with a merger, acquisition, corporate reorganization, or sale of substantially all of its assets, provided the assignee agrees in writing to be bound by this Agreement.
- Neither Party shall be liable for delay or failure to perform due to causes beyond its reasonable control, including natural disasters, acts of government, labor disputes, internet or telecommunications failures, denial-of-service attacks, civil unrest, war, or other force majeure events, except that this section does not excuse Customer’s payment obligations for Services already provided.
- All legal notices under this Agreement must be in writing and will be deemed given when delivered personally, sent by nationally recognized overnight courier, or sent by email to the designated legal notice address with confirmation of transmission. Operational notices, including service notices and billing notices, may be given by email or through the Services.
- If any provision of this Agreement is held unenforceable, the remaining provisions will remain in effect. Failure to enforce any provision is not a waiver. This Agreement, together with the applicable Order Form, exhibits, and incorporated policies, constitutes the entire agreement between the parties with respect to its subject matter.
_______________________________________________________________
Exhibit A – Business Associate Agreement
1. Purpose and Scope
- This Business Associate Agreement (“BAA”) applies to PHI created, received, maintained, or transmitted by Oryx Dental Software, LLC (“Business Associate”) on behalf of Customer (“Covered Entity”) in connection with the Services.
- Capitalized terms not defined in this BAA have the meanings given in HIPAA and the HITECH Act.
2. Permitted Uses and Disclosures
- Business Associate may use and disclose PHI only: (a) to perform the Services and other obligations under the Agreement; (b) for the proper management and administration of Business Associate or to carry out its legal responsibilities, to the extent permitted by HIPAA; (c) as required by law; and (d) to de-identify PHI in accordance with HIPAA.
- Business Associate may use de-identified information resulting from PHI for lawful business purposes, provided Business Associate does not attempt to re-identify such information except as permitted by law.
3. Safeguards and Compliance
- Business Associate shall implement appropriate administrative, physical, and technical safeguards and shall comply with the applicable requirements of the HIPAA Security Rule with respect to electronic PHI.
- Business Associate shall report to Covered Entity any use or disclosure of PHI not permitted by this BAA of which Business Associate becomes aware.
4. Subcontractors
- Business Associate shall ensure that any subcontractor that creates, receives, maintains, or transmits PHI on behalf of Business Associate agrees in writing to the same restrictions, conditions, and requirements that apply to Business Associate with respect to such information.
5. Breach Notification
- Business Associate shall report any Breach of Unsecured PHI to Covered Entity without unreasonable delay and in no event later than thirty (30) calendar days after discovery, subject to delays permitted by law or requested by law enforcement.
- Business Associate shall provide information reasonably available to it concerning the nature of the Breach and the remediation steps being taken.
6. Individual Rights Assistance
- To the extent applicable to the Services, Business Associate shall make PHI available to Covered Entity as necessary for Covered Entity to fulfill its obligations under 45 C.F.R. § 164.524.
- To the extent applicable to the Services, Business Associate shall make PHI available for amendment and shall provide information necessary for an accounting of disclosures, in each case as required by HIPAA and to the extent maintained by Business Associate in a designated record set.
7. Access by Secretary
- Business Associate shall make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining compliance with HIPAA.
8. Term and Termination
- This BAA commences on the effective date of the Agreement and terminates upon termination or expiration of the Agreement, unless earlier terminated for material breach.
- Covered Entity may terminate this BAA if Business Associate materially breaches this BAA and fails to cure such breach within fifteen (15) business days after written notice, provided that if cure reasonably requires more time and Business Associate promptly commences and diligently pursues cure, the cure period shall be extended for a commercially reasonable period.
9. Return or Destruction of PHI
- For up to thirty (30) days following expiration or termination, Customer may request one export of Customer Data in a commercially reasonable format. Thereafter, subject to the BAA and applicable law, Oryx may delete Customer Data in accordance with its standard retention policies.
- If return or destruction is infeasible, Business Associate shall continue to protect such PHI and limit further uses and disclosures to those purposes that make return or destruction infeasible for so long as Business Associate retains such PHI.
10. Miscellaneous
- This BAA is governed by federal law and, to the extent not preempted, the laws of the State of Delaware.
- In the event of a conflict between this BAA and the Agreement with respect to PHI, this BAA controls.
_______________________________________________________________
Exhibit B – Startup Addendum
1. Applicability
- This Startup Addendum applies only if the Order Form expressly identifies Customer as a Startup Customer.
2. Startup Initial Period
- For Startup Customers only, the discounted initial period begins on the Effective Date and ends on the earlier of: (a) the date Customer has two hundred (200) Active Patients; or (b) twelve (12) months after the Effective Date.
- “Active Patients” means unique patient records associated with Customer’s practice that have had at least one scheduled appointment, billable encounter, or completed chart entry in the preceding 12months.
3. Paid Commitment After Startup Period
- Upon expiration of the Startup Initial Period, the standard 12-month paid commitment stated in the Order Form shall begin automatically.
- If Customer terminates during the Startup Initial Period or the ensuing paid commitment other than for Oryx’s uncured material breach, Customer remains liable for the committed fees identified in the Order Form.
_______________________________________________________________
Exhibit C – California Privacy and Supplemental Data Processing Terms
1. California Service Provider / Contractor Restrictions
- To the extent Oryx processes personal information subject to the California Consumer Privacy Act, as amended, on behalf of Customer, Oryx shall act as a service provider or contractor, as applicable, and shall not: (a) sell or share such personal information; (b) retain, use, or disclose such personal information for any purpose other than performing the Services, the business purposes specified in the Agreement, or as otherwise permitted by applicable law; (c) retain, use, or disclose such personal information outside the direct business relationship between Customer and Oryx; or (d) combine such personal information with personal information received from another source except as permitted by applicable law.
2. Subprocessors
- Oryx shall require subprocessors that receive such personal information to be bound by materially equivalent obligations.
3. Customer Cooperation
- Each Party shall reasonably cooperate with the other in responding to verified data subject requests and regulatory inquiries to the extent required by applicable law and appropriate in light of the Party’s role in the processing activity.
_______________________________________________________________
EXHIBIT D
CANADIAN PRIVACY AND HEALTH INFORMATION ADDENDUM
(PIPEDA-COMPLIANT FORM FOR CANADIAN CUSTOMERS)
This Canadian Privacy and Health Information Addendum (the “Canadian Addendum”) is entered into between Oryx Dental Software (“Oryx”) and the customer identified in the applicable Order Form (“Customer”). This Canadian Addendum supplements the Order Form and the Standard Terms and Conditions (together, the “Agreement”) for Canadian customers and is intended to address the collection, use, disclosure, storage, safeguarding, and handling of Personal Information and Personal Health Information in connection with the Services.
This Canadian Addendum is intended to serve as the Canadian equivalent of a business associate / health information handling addendum. It is drafted primarily to support compliance with the Personal Information Protection and Electronic Documents Act (“PIPEDA”), while also recognizing that substantially similar or more specific obligations may arise under applicable provincial privacy and health-information laws, including laws governing personal health information, custodians, trustees, affiliates, information managers, or service providers.
1. Definitions
- “Applicable Privacy Law” means PIPEDA and any other applicable Canadian federal or provincial privacy, health-information, breach-notification, or data-protection law, regulation, order, or guidance applicable to the parties’ handling of Personal Information or Personal Health Information in connection with the Services.
- “Customer Personal Information” means Personal Information processed by Oryx on behalf of Customer in connection with the Services.
- “Personal Information” has the meaning given under Applicable Privacy Law and generally includes information about an identifiable individual.
- “Personal Health Information” means personal information about an individual’s physical or mental health, health history, provision of health care, payments for health care, or other health-related information that is subject to Applicable Privacy Law.
- “Privacy Incident” means any loss of, unauthorized access to, unauthorized use of, unauthorized disclosure of, or other breach of security safeguards involving Customer Personal Information.
- “Subprocessor” means any third party engaged by Oryx to process Customer Personal Information in connection with providing the Services.
- “Services” means the software, hosting, support, implementation, migration, analytics, and related services provided by Oryx under the Agreement.
2. Scope and Roles
2.1 Customer remains responsible for its compliance with Applicable Privacy Law as the organization, health information custodian, trustee, affiliate, clinic, practice, or other entity that determines the purposes for which Customer Personal Information is collected, used, and disclosed.
2.2 Oryx will process Customer Personal Information only for the purposes of providing, maintaining, securing, supporting, improving, and administering the Services, and for such other limited purposes as are expressly permitted by the Agreement, this Canadian Addendum, or Applicable Privacy Law.
2.3 Except to the extent Applicable Privacy Law expressly permits or requires otherwise, Oryx shall not sell Customer Personal Information, use Customer Personal Information for its own unrelated marketing purposes, or disclose Customer Personal Information to a third party except as authorized by Customer, required to provide the Services, or required by law.
3. Accountability and Privacy Management
3.1 Oryx shall maintain a privacy management program reasonably designed to support compliance with Applicable Privacy Law, including policies and practices governing the handling of Customer Personal Information.
3.2 Oryx shall designate one or more individuals responsible for privacy and security matters relating to the Services.
3.3 Oryx remains responsible for Customer Personal Information in its custody or control, including information transferred to a Subprocessor for processing on Oryx’s behalf.
4. Permitted Use and Disclosure
4.1 Oryx may use and disclose Customer Personal Information only to the extent reasonably necessary to provide the Services, perform its obligations under the Agreement, comply with documented instructions from Customer, protect the security and integrity of the Services, meet legal obligations, or otherwise as permitted or required by Applicable Privacy Law.
4.2 Oryx shall limit access to Customer Personal Information to personnel and Subprocessors who have a need to know such information for the permitted purposes and who are bound by confidentiality obligations no less protective than those set out in the Agreement and this Canadian Addendum.
4.3 Oryx shall not collect, use, or disclose Customer Personal Information in a manner that would cause Customer to violate Applicable Privacy Law, to the extent Oryx is aware of Customer’s documented restrictions or instructions.
5. Safeguards
5.1 Oryx shall protect Customer Personal Information by security safeguards appropriate to the sensitivity of the information, including administrative, technical, and physical measures designed to protect against loss, theft, unauthorized access, unauthorized use, unauthorized disclosure, copying, modification, or disposal.
5.2 Without limiting the foregoing, Oryx shall maintain reasonable controls relating to access management, authentication, logging, vulnerability management, backup, incident response, workforce training, and secure disposal.
5.3 Oryx shall use reasonable measures to ensure that Customer Personal Information retained in connection with the Services is as accurate, complete, and up to date as is reasonably necessary for the purposes for which it is to be used by Oryx.
6. Confidentiality and Workforce Obligations
6.1 Oryx shall ensure that employees, contractors, and agents with access to Customer Personal Information are subject to written confidentiality obligations and receive privacy and security training appropriate to their roles.
6.2 Oryx shall implement and enforce role-based access restrictions and shall promptly revoke access when no longer required.
7. Privacy Incidents and Breach Notification
7.1 Oryx shall notify Customer without undue delay after confirming a Privacy Incident involving Customer Personal Information under Oryx’s custody or control.
7.2 Such notice shall include, to the extent known at the time: (a) a description of the nature of the Privacy Incident; (b) the date or estimated date of the Privacy Incident; (c) the categories of Customer Personal Information affected; (d) the steps Oryx has taken or plans to take to contain, investigate, mitigate, and remediate the Privacy Incident; and (e) contact information for a person able to provide additional information.
7.3 Oryx shall reasonably cooperate with Customer in investigating the Privacy Incident and in enabling Customer to assess whether notice to affected individuals, regulators, commissioners, custodians, or other third parties is required under Applicable Privacy Law.
7.4 Unless Applicable Privacy Law requires Oryx to provide notice directly, Customer shall be responsible for determining whether notice must be provided to affected individuals or regulators. Oryx shall not notify affected individuals on Customer’s behalf without Customer’s approval, except where required by law.
7.5 Oryx shall maintain records of Privacy Incidents relating to Customer Personal Information to the extent required by Applicable Privacy Law.
8. Assistance with Access, Correction, and Inquiries
8.1 To the extent Customer cannot reasonably access or correct Customer Personal Information through the Services, Oryx shall provide reasonable assistance to enable Customer to respond to requests for access to, correction of, or information about Customer Personal Information, as required by Applicable Privacy Law.
8.2 Oryx shall promptly refer to Customer any complaint, inquiry, request, or demand from an individual, regulator, commissioner, or other governmental authority relating specifically to Customer Personal Information, unless Oryx is legally required to respond directly.
9. Retention, Return, and Secure Disposal
9.1 Oryx shall retain Customer Personal Information only for as long as reasonably necessary to provide the Services, comply with the Agreement, meet legal requirements, resolve disputes, enforce rights, or as otherwise permitted or required by Applicable Privacy Law.
9.2 Upon expiration or termination of the Agreement, Customer may request one export of Customer Personal Information in a commercially reasonable format within thirty (30) days after termination, unless a different period is stated in the Agreement.
9.3 Following the applicable export period, Oryx shall securely delete or anonymize Customer Personal Information in accordance with its retention schedule and Applicable Privacy Law, except to the extent retention is required by law or reasonably necessary for backup restoration cycles, dispute resolution, or enforcement of the Agreement.
10. Subprocessors and Service Providers
10.1 Oryx may engage Subprocessors to provide the Services, provided that Oryx remains responsible for their compliance with obligations applicable to Customer Personal Information under this Canadian Addendum.
10.2 Oryx shall impose written privacy, confidentiality, and security obligations on each Subprocessor that are no less protective than the obligations imposed on Oryx by this Canadian Addendum, taking into account the nature of the Services performed by the Subprocessor.
10.3 Upon Customer’s written request, Oryx shall make available a current list of material Subprocessors that process Customer Personal Information in connection with the Services.
11. Cross-Border Processing
11.1 Customer acknowledges that Oryx and its Subprocessors may process, host, or access Customer Personal Information outside the province or country in which it was originally collected, subject to the safeguards and obligations in this Canadian Addendum and Applicable Privacy Law.
11.2 Oryx shall, upon request, provide general information regarding the jurisdictions in which Customer Personal Information is stored or from which it may be accessed in connection with the Services, subject to reasonable confidentiality, security, and competitive-sensitivity limitations.
12. De-Identification and Analytics
12.1 Oryx may create and use de-identified, aggregated, and statistical information derived from Customer Personal Information for lawful business purposes, including analytics, benchmarking, service improvement, security, quality assurance, and product development, provided that such information does not identify Customer or any individual.
12.2 Oryx shall not attempt to re-identify de-identified information except to test or validate the de-identification process, to the extent permitted by Applicable Privacy Law, or with Customer’s written authorization.
13. Audit Cooperation and Evidence of Compliance
13.1 Upon reasonable written request and no more than once annually, Oryx shall provide Customer with commercially reasonable information regarding Oryx’s privacy and security program relevant to the Services, which may include policies summaries, security questionnaires, certifications, or similar materials.
13.2 Any audit or assessment rights shall be exercised in a manner that does not unreasonably interfere with Oryx’s operations, compromise the confidentiality of other customers, or create security risk, and may be satisfied through third-party reports or certifications where appropriate.
14. Provincial Law Savings and Health Information Terms
14.1 The parties acknowledge that certain Canadian provinces impose additional or different obligations concerning Personal Health Information, custodians, trustees, affiliates, agents, information managers, electronic service providers, or health information network providers. To the extent such provincial laws apply, this Canadian Addendum shall be interpreted and, where necessary, supplemented to meet those requirements.
14.2 If Applicable Privacy Law requires additional contractual language for a particular province, the parties shall cooperate in good faith to execute a supplementary provincial schedule, information manager agreement, or similar addendum reasonably required for compliance.
14.3 Without limiting the foregoing, Customer is responsible for identifying to Oryx any provincial requirements that are specifically applicable to Customer’s operations and that materially differ from the baseline requirements addressed in this Canadian Addendum.
15. Precedence
In the event of a conflict between this Canadian Addendum and the Standard Terms and Conditions, this Canadian Addendum shall control with respect to Customer Personal Information of Canadian customers. In the event of a conflict between this Canadian Addendum and the Order Form, the Order Form shall control only to the extent it expressly states an intent to override this Canadian Addendum.
16. Termination
This Canadian Addendum remains in effect for so long as Oryx processes Customer Personal Information on behalf of Customer in connection with the Services. Sections that by their nature should survive termination, including those relating to confidentiality, safeguards, incident response, retention, de-identification, and return or deletion of Customer Personal Information, shall survive.