Fireflight SaaS Terms and Conditions – Acceptance Form
1. DEFINITIONS AND CONTRACT STRUCTURE
"Service" means the FireFlight Data Systems cloud-hosted software service, including its web interface, Company-controlled modules, Company-provided updates, and any Company-authorized integrations identified in an applicable Order Form. The Service is owned, hosted, operated, maintained, and controlled by Phoenix Consultants Group, Inc.
"Customer" means the legal entity purchasing or receiving access to the Service. "Authorized User" means an individual natural person whom Customer authorizes to use the Service for Customer's internal business purposes and for whom Customer has provisioned a valid user account.
"Order Form" means a written ordering document, proposal, subscription schedule, statement of work, or other Company-approved document identifying the subscription, fees, term, modules, usage limits, or related commercial terms. If there is a conflict, the Order Form controls only as to the specific commercial term expressly addressed; this Agreement controls all other matters unless the Order Form expressly states that it overrides a particular section of this Agreement.
2. NATURE OF SERVICE; NEW JERSEY SAAS TAX CHARACTERIZATION
The parties intend and agree that the primary object of the transaction is Customer's remote access to a software application operated by Company, and not the transfer, sale, rental, lease, sublicense, or electronic delivery of a copy of software to Customer. Company retains and operates the software at all times. Customer receives no title to, possession of, or right to download, copy, install, modify, or distribute the underlying FireFlight software.
The parties further intend that the Service operate consistently with New Jersey Division of Taxation guidance for Software as a Service, including Technical Bulletin TB-72, under which remotely accessed provider-operated software generally is treated as a service rather than a transfer of tangible personal property, subject to the rules applicable to taxable enumerated services, including information services.
FireFlight is designed as an interactive business software tool through which Customer and its Authorized Users enter, maintain, organize, process, analyze, and report on Customer Data for Customer's own operational purposes. Except for data or content expressly identified in an Order Form, Company does not sell Customer access to a general database of third-party market intelligence, public records, legal research, financial research, industry statistics, property values, leads, or similar compiled information as the true object of the subscription.
Customer-specific calculations, dashboards, summaries, analytics, alerts, and reports produced by the Service from Customer Data remain functions of the software tool. Company will not intentionally pool Customer Data into reports furnished to unrelated customers as a commercial information product unless the parties separately agree in writing and the tax treatment of that separate offering is evaluated independently.
No Contractual Tax Guarantee. Taxability is determined by applicable law, administrative guidance, the actual facts, and the manner in which the Service is sold and operated. Nothing in this Agreement is a representation that a taxing authority is legally bound by the parties' characterization. Company may collect, invoice, or remit any sales, use, excise, or similar tax that Company reasonably determines is required by law, and Customer will pay such tax unless Customer provides a valid exemption certificate.
3. SUBSCRIPTION LICENSE AND AUTHORIZED USE
Subject to timely payment and continued compliance with this Agreement, Company grants Customer a limited, non-exclusive, non-transferable, non-sublicensable, revocable right during the subscription term to permit Authorized Users to access the Service solely through Company-approved human-user interfaces and solely for Customer's internal business operations.
No rights are granted by implication. Customer may not make the Service available as a service bureau, timesharing environment, outsourced processing platform for third parties, reseller offering, or embedded component of another product without a separate written agreement signed by Company.
4. ABSOLUTE PROHIBITION ON CUSTOMER AI, BOTS, RPA, ROBOTICS, AND AUTOMATED ACCESS
Except for automation functionality that is built into FireFlight by Company or a specific integration expressly authorized in advance and in writing by Company, Customer shall not, under any circumstances, cause or permit any machine, software agent, artificial intelligence system, bot, robotic process automation tool, robotic device, script, macro, headless browser, remote-control system, crawler, scraper, computer-vision controller, or other automated mechanism to access, control, observe, operate, interrogate, enter data into, extract data from, test, monitor, or otherwise interface with the Service.
4.1 Prohibited AI and Agentic Systems
- No generative AI, AI agent, autonomous agent, copilot, coding agent, large language model, machine-learning system, or third-party AI service may be given credentials, browser access, session access, API access, remote desktop access, screenshots, DOM access, or other means to operate or interact with the Service.
- Customer may not instruct an AI system to log in, navigate forms, press controls, create or modify records, upload or download files, submit transactions, change configuration, administer users, test security, or perform repetitive work in FireFlight.
- Customer may not use AI-generated scripts, macros, browser automation, or robotic process automation to interact with FireFlight, even if a human starts, supervises, reviews, or approves the automated process.
4.2 Prohibited Bots, Remote Control, and Robotics
- No bot, crawler, scraper, Puppeteer, Playwright, Selenium, browser extension, macro recorder, RPA product, remote bot, physical robot, robotic workstation, computer-vision system, or similar technology may simulate or replace human interaction with the Service.
- No remote robotic or automated system may use a keyboard, mouse, touchscreen, browser, virtual desktop, remote desktop session, accessibility layer, API, network interface, or other input/output method to control or interface with FireFlight.
4.3 No Credential Delegation to Machines
Authorized User credentials are issued for use by individual human users only. Customer shall not assign, expose, store, transmit, or make credentials, session tokens, cookies, authentication artifacts, API keys, or other access mechanisms available to any prohibited automated system.
4.4 Company-Controlled Automation Exception
This Section does not prohibit automation, AI functionality, scheduled jobs, integrations, or agents that are developed, supplied, enabled, or expressly approved in writing by Company. Any approved exception is limited to the specific system, scope, credentials, purpose, rate limits, and duration authorized by Company and may be revoked at any time.
4.5 Enforcement
Any violation or attempted violation of this Section is a material breach. Company may immediately block the automated source, revoke tokens, suspend affected users or integrations, preserve relevant logs, and, where reasonably necessary to protect the Service or other customers, suspend Customer access without advance notice. Customer is responsible for costs, damage, excess infrastructure consumption, incident response, investigation, remediation, and third-party claims caused by unauthorized automated access, subject to applicable law.
5. INTELLECTUAL PROPERTY AND RESTRICTIONS
Company and its licensors retain all right, title, and interest in and to the Service, source code, object code, database design, schemas, metadata, architecture, interfaces, workflows, forms engine, configuration methods, documentation, designs, trade secrets, know-how, improvements, and all related intellectual property. Customer receives only the access rights expressly stated in this Agreement.
- Customer shall not reverse engineer, decompile, disassemble, decode, translate, reconstruct, discover, or attempt to derive source code, algorithms, schemas, non-public APIs, security mechanisms, or underlying structure of the Service, except solely to the extent a prohibition is expressly unenforceable under applicable law.
- Customer shall not copy, clone, mirror, frame, modify, reproduce, distribute, sell, sublicense, publish, create derivative works from, or commercially exploit any portion of the Service or Company documentation.
- Customer shall not conduct or publish competitive benchmarking, feature mapping, load testing, vulnerability scanning, penetration testing, response-time testing, or comparative product analysis without Company's prior written consent.
- Customer shall not remove or obscure proprietary notices or use Company trademarks except as expressly authorized.
6. CUSTOMER DATA; OWNERSHIP; PROCESSING
As between the parties, Customer retains ownership of data, records, files, text, images, and other content submitted to the Service by or for Customer ("Customer Data"). Customer grants Company a non-exclusive right to host, copy, process, transmit, display, back up, restore, and otherwise use Customer Data only as reasonably necessary to provide, secure, support, maintain, and improve the Service and to comply with law.
Customer represents that it has all rights, notices, consents, permissions, and lawful bases required to submit and process Customer Data. Customer is responsible for the legality, accuracy, quality, and integrity of Customer Data and for determining whether the Service is appropriate for Customer's regulatory obligations.
Company will not sell Customer Data as a data product. Company may use de-identified operational and telemetry information that does not identify Customer or any individual to secure, maintain, measure, and improve the Service, provided such use does not convert the subscription into the sale of a general information service.
7. ACCOUNT ADMINISTRATION AND SECURITY
Customer is responsible for designating administrators, approving Authorized Users, assigning permissions, maintaining current contact information, enforcing appropriate password and authentication practices, and promptly disabling access for persons who no longer require it. Customer is responsible for activity occurring through Customer accounts to the extent caused by Customer, its Authorized Users, or compromised credentials under Customer's control.
Customer shall promptly notify Company of suspected unauthorized access, credential compromise, security incidents affecting the Service, or misuse of Customer accounts. Company may require password resets, multi-factor authentication, access restrictions, or other reasonable protective measures.
8. ACCEPTABLE USE AND PROHIBITED CONDUCT
- No unlawful, fraudulent, deceptive, defamatory, infringing, harassing, or malicious use.
- No malware, ransomware, destructive code, denial-of-service activity, excessive traffic, or attempts to impair availability or circumvent usage controls.
- No unauthorized access to other tenants, accounts, data, networks, servers, or administrative functions.
- No security testing, enumeration, credential stuffing, interception, packet manipulation, or circumvention of technical restrictions without prior written authorization.
- No use that violates export controls, sanctions laws, privacy laws, intellectual-property rights, or applicable contractual obligations.
9. THIRD-PARTY SERVICES AND INTEGRATIONS
The Service may interoperate with third-party products or services. Unless expressly stated otherwise in an Order Form, third-party products are not part of the Service and are governed by their own terms. Company is not responsible for changes, outages, acts, omissions, security, data practices, or continued availability of third-party products. Customer authorizes Company to exchange Customer Data with an approved third-party integration only to the extent required to perform the requested integration.
A third-party integration does not create an exception to Section 4. Any third-party automation, AI system, bot, RPA tool, or robotic interface requires Company's separate prior written authorization even if Customer is otherwise licensed to use that third-party product.
10. COMPANY AI FEATURES AND GENERATED OUTPUT
If Company elects to provide an AI-assisted feature within FireFlight, that feature is Company-controlled functionality and does not authorize Customer to attach external AI systems to the Service. AI-assisted output may be probabilistic, incomplete, or incorrect. Customer remains responsible for human review of material business decisions and for determining whether generated output is suitable for Customer's intended use. Company may identify additional terms or usage limits for particular AI features.
11. FEES, PAYMENT, TAXES, AND CHANGES
Customer will pay the fees stated in the applicable Order Form. Unless otherwise stated, fees are due without setoff or deduction and are non-refundable except where this Agreement expressly provides otherwise. Overdue amounts may accrue lawful interest and collection costs.
Customer is responsible for applicable taxes, assessments, or governmental charges imposed on Customer's purchase or use of the Service, excluding taxes based on Company's net income. If Company is required to collect tax, Company may add the tax to the invoice. Any claimed exemption must be supported by a valid exemption certificate acceptable to Company.
Company may revise subscription pricing upon renewal or as otherwise permitted by the Order Form by providing reasonable advance notice. Usage beyond contracted limits may be billed at then-current rates or restricted until the parties amend the subscription.
12. SUSPENSION
Company may suspend some or all access if: (a) fees remain unpaid after any applicable cure period; (b) Customer violates Sections 4, 5, 7, or 8; (c) continued access presents a security, legal, operational, or third-party risk; (d) suspension is required by law or governmental order; or (e) Customer's use threatens the integrity or availability of the Service. Where circumstances reasonably permit, Company will provide notice and an opportunity to cure before suspension. Emergency security suspensions may be immediate.
13. TERM; RENEWAL; TERMINATION; DATA EXPORT
The subscription term is stated in the Order Form. Unless the Order Form states otherwise, renewal, cancellation notice, and any minimum commitment are governed by the Order Form. Either party may terminate for a material breach not cured within thirty (30) days after written notice, except that breaches involving unauthorized automation, security attacks, intellectual-property misuse, unlawful activity, or conduct creating immediate material risk may permit immediate suspension or termination.
Upon termination or expiration, Customer's right to access the Service ends. If Customer is in good standing and requests export before termination or within a reasonable post-termination period designated by Company, Company will make Customer Data available in a commercially reasonable format supported by the Service. Custom conversion, migration, restoration, consulting, or extraordinary extraction work may be charged separately. Thereafter, Company may delete Customer Data in accordance with its retention and backup practices, subject to legal obligations.
14. SERVICE AVAILABILITY, MAINTENANCE, BACKUPS, AND CHANGES
Company will use commercially reasonable efforts to operate and maintain the Service. The Service may be unavailable due to maintenance, upgrades, emergencies, internet or telecommunications failures, third-party infrastructure, cybersecurity events, force majeure, or other causes. Unless a separate written service-level agreement applies, no specific uptime percentage is guaranteed.
Company may modify, update, replace, or discontinue features when reasonably necessary for security, performance, legal compliance, product improvement, or third-party dependencies. Company will use reasonable efforts to avoid materially reducing core paid functionality during a current subscription term without a legitimate operational or legal reason.
Backups are maintained for disaster recovery and operational continuity and are not a substitute for Customer's own legally required retention, archival, or records-management obligations. Recovery of specific historical data may not always be possible.
15. CONFIDENTIALITY
Each party may receive non-public business, technical, security, financial, or operational information of the other ("Confidential Information"). The receiving party will use reasonable care to protect Confidential Information and will use it only to perform or exercise rights under the parties' relationship. Confidential Information does not include information that the receiving party can demonstrate is publicly available without breach, already lawfully known without restriction, independently developed without use of the other party's Confidential Information, or lawfully received from a third party without confidentiality duty.
A party may disclose Confidential Information when required by law, subpoena, or court order, subject to legally permitted notice and reasonable cooperation. Trade-secret obligations survive for so long as the information remains a trade secret under applicable law.
16. PRIVACY AND REGULATED DATA
Customer is responsible for determining whether Customer Data is subject to sector-specific laws or contractual restrictions. Unless Company expressly agrees in a separate written addendum, Customer shall not use the Service to store or process data that legally requires Company to execute a specialized regulatory agreement or to implement controls beyond the Service's contracted security scope. Examples may include protected health information subject to HIPAA, payment-card data outside approved payment integrations, or other specially regulated data categories.
Where applicable, the parties will comply with privacy and security laws governing their respective roles. Nothing in this Agreement makes Company a fiduciary, records custodian, regulated professional, or compliance officer for Customer unless a separate signed agreement expressly creates that role.
17. WARRANTIES AND DISCLAIMERS
Company warrants that it has authority to provide the Service and will perform any contracted professional services in a professional and workmanlike manner. Customer's exclusive remedy for a breach of this warranty is re-performance of the affected service or, if Company cannot reasonably cure the breach, termination of the affected service and refund of prepaid fees for the unused portion of the terminated period.
EXCEPT FOR EXPRESS WARRANTIES IN THIS AGREEMENT, THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE" TO THE MAXIMUM EXTENT PERMITTED BY LAW. COMPANY DISCLAIMS IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, NON-INFRINGEMENT, AND ANY WARRANTY THAT THE SERVICE WILL BE UNINTERRUPTED, ERROR-FREE, OR SUITABLE FOR EVERY LEGAL OR REGULATORY REQUIREMENT. COMPANY DOES NOT WARRANT CUSTOMER DATA, THIRD-PARTY SERVICES, INTERNET CONNECTIVITY, OR RESULTS PRODUCED FROM INACCURATE OR INCOMPLETE CUSTOMER INPUTS.
18. INDEMNIFICATION
Customer will defend, indemnify, and hold harmless Company and its officers, directors, employees, and agents from third-party claims, damages, penalties, judgments, and reasonable attorneys' fees arising from: (a) Customer Data that violates law or third-party rights; (b) Customer's or an Authorized User's unlawful use of the Service; (c) Customer's unauthorized AI, bot, RPA, robotic, scripted, or automated access; (d) Customer's breach of Sections 4, 5, 7, 8, or 16; or (e) Customer's instructions to Company that violate third-party rights or law.
Company will defend Customer against a third-party claim that Customer's authorized use of the unmodified Service infringes a United States patent, copyright, or trademark, and will pay damages finally awarded or agreed in settlement, provided Customer promptly notifies Company and gives Company control of the defense. Company may modify or replace the Service, obtain rights for continued use, or terminate the affected Service and refund prepaid unused fees. This obligation does not apply to claims caused by Customer Data, combinations not supplied by Company, unauthorized modifications, continued use after notice, or use outside this Agreement.
19. LIMITATION OF LIABILITY
TO THE MAXIMUM EXTENT PERMITTED BY LAW, NEITHER PARTY WILL BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, PUNITIVE, OR CONSEQUENTIAL DAMAGES, OR FOR LOST PROFITS, LOST REVENUE, LOST BUSINESS, LOSS OF GOODWILL, OR LOSS OF DATA, ARISING OUT OF OR RELATING TO THIS AGREEMENT, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
EXCEPT FOR EXCLUDED CLAIMS BELOW, EACH PARTY'S AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO THIS AGREEMENT WILL NOT EXCEED THE FEES PAID OR PAYABLE BY CUSTOMER TO COMPANY FOR THE SERVICE DURING THE TWELVE (12) MONTHS IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO THE CLAIM.
The foregoing cap does not limit Customer's payment obligations, Customer's infringement or misappropriation of Company intellectual property, unauthorized automated access under Section 4, either party's indemnification obligations, fraud, willful misconduct, or liability that cannot lawfully be limited. Nothing in this Agreement excludes rights or remedies that applicable law prohibits the parties from waiving.
20. EQUITABLE RELIEF
Customer acknowledges that unauthorized access, reverse engineering, disclosure of proprietary technology, credential delegation to automated systems, or misuse of Company intellectual property may cause harm that is difficult to measure solely in money damages. In addition to other remedies, Company may seek temporary, preliminary, or permanent injunctive or equitable relief without waiving any claim for damages, subject to applicable procedural law.
21. COMPLIANCE WITH LAW; EXPORT; GOVERNMENT REQUESTS
Each party will comply with laws applicable to its own performance under this Agreement. Customer shall not use the Service in violation of export controls, sanctions, anti-corruption laws, or other applicable restrictions. Company may comply with lawful governmental requests and may preserve or disclose information when legally required.
22. NOTICES
Operational notices may be delivered through the Service, account email, invoice email, or other electronic means reasonably calculated to reach Customer. Formal notices of breach, indemnification claims, or termination must be delivered to the legal or business contact identified in the applicable Order Form, unless a party has provided an updated notice address in writing.
23. GOVERNING LAW; VENUE; JURY TRIAL WAIVER
This Agreement is governed by the laws of the State of New Jersey, without regard to conflict-of-laws principles. Any action arising out of or relating to this Agreement shall be brought in a state or federal court of competent jurisdiction located in New Jersey, and each party consents to personal jurisdiction and venue there. To the extent enforceable under applicable law, each party knowingly and voluntarily waives trial by jury in any action arising out of or relating to this Agreement. Nothing prevents either party from seeking temporary or emergency equitable relief in a court of competent jurisdiction.
24. CHANGES TO TERMS
Company may update these Terms to address changes in law, security requirements, technology, Service functionality, or business practices. For material changes affecting an active paid subscription, Company will provide reasonable notice. Unless a change is legally required sooner, a material change will apply no earlier than the stated effective date. Continued use after the effective date constitutes acceptance where permitted by law; if an Order Form requires signed amendments, that requirement controls for provisions specifically covered by the Order Form.
25. GENERAL PROVISIONS
Neither party may assign this Agreement without the other party's prior written consent, except that Company may assign it in connection with a merger, reorganization, sale of substantially all assets, or transfer of the FireFlight business. Customer may not assign accounts or credentials separately from an authorized assignment of the Agreement.
The parties are independent contractors. This Agreement does not create a partnership, joint venture, fiduciary relationship, franchise, employment relationship, or agency. Neither party has authority to bind the other except as expressly stated.
If a provision is held unenforceable, it will be enforced to the maximum extent permitted and the remaining provisions will remain in effect. A waiver must be in writing and is limited to the specific instance. Headings are for convenience only. "Including" means "including without limitation." Electronic signatures and electronic acceptance are effective to the extent permitted by law.
This Agreement, together with applicable Order Forms and expressly incorporated addenda, is the entire agreement regarding the Service and supersedes prior or contemporaneous proposals, representations, or agreements concerning the same subject matter. Provisions that by their nature should survive termination will survive, including intellectual property, confidentiality, payment obligations, indemnification, liability limitations, governing law, and restrictions concerning unauthorized automated access.
APPENDIX A
NEW JERSEY SAAS TAX-CHARACTERIZATION OPERATING COVENANTS
This Appendix states the commercial and operational characteristics that the parties intend to maintain for the standard FireFlight SaaS subscription. It does not override applicable tax law or a binding determination of the New Jersey Division of Taxation.
New Jersey Authorities Referenced
- N.J.S.A. 54:32B-1 et seq. (New Jersey Sales and Use Tax Act).
- N.J.S.A. 54:32B-2(yy) and 54:32B-3(b)(12) (information services).
- N.J.S.A. 54:32B-2(g), 54:32B-3(a), and 54:32B-8.56 (prewritten software and electronically delivered software concepts).
- New Jersey Division of Taxation Technical Bulletin TB-72, Cloud Computing (SaaS, PaaS, IaaS).
- New Jersey Division of Taxation Publication ANJ-29, Information Services & New Jersey Sales Tax.
A. CUSTOMER ACKNOWLEDGMENT (OPTIONAL SIGNATURE PAGE)
The undersigned represents that he or she is authorized to bind Customer and acknowledges acceptance of the FireFlight Data Systems SaaS Terms and Conditions.