SaaS Terms and Conditions
Version 1.0 — Effective January 1, 2026
This Master Software-as-a-Service Agreement (this “Agreement”) is entered into between Phoenix Consultants Group, Inc., a New Jersey corporation with offices at 9 Wilson Drive, Northfield, New Jersey 08225 (“Phoenix,” “we,” or “us”), and the entity identified on the applicable Order (“Customer” or “you”).
This Agreement governs Customer’s access to and use of FireFlight Data Systems, Phoenix’s proprietary software-as-a-service platform, and any related services identified in an Order (collectively, the “Services”). It becomes binding on the earlier of (a) the date both parties sign an Order referencing it, or (b) the date Customer first accesses the Services. By accepting this Agreement, the person doing so represents that they are authorized to bind Customer.
This Agreement, together with all Orders, is the parties’ complete agreement on this subject and supersedes all prior or contemporaneous proposals, negotiations, and understandings, whether written or oral. Capitalized terms are defined in Section 15.
1. THE SERVICES↑
1.1 Provision. Subject to Customer’s compliance with this Agreement and payment of all Fees, Phoenix will make the Services described in each Order available to Customer during the applicable Subscription Term.
1.2 Access rights. Phoenix grants Customer a non-exclusive, non-transferable, worldwide right to access and use the Services during the Subscription Term, solely for Customer’s internal business purposes and subject to the usage limits stated in the Order. The Services are made available on a subscription basis; nothing in this Agreement transfers ownership of any software, and no copy of the software underlying the Services is delivered to Customer.
1.3 Authorized Users. Customer may permit Authorized Users to access the Services. Customer is responsible for (a) each Authorized User’s compliance with this Agreement, (b) the accuracy and legality of Customer Data, and (c) all activity occurring under Customer’s accounts, other than activity caused by Phoenix’s own breach of this Agreement. Customer will maintain the confidentiality of all credentials and will notify Phoenix promptly of any suspected unauthorized access.
1.4 Affiliates. Customer may permit its Affiliates to use the Services under Customer’s subscription. Customer remains responsible for its Affiliates’ compliance and for all obligations under this Agreement, and Customer alone has the right to enforce this Agreement against Phoenix unless an Affiliate signs its own Order.
1.5 Third-party and open-source components. The Services may incorporate open-source or third-party components made available under separate license terms. Those terms apply to those components and are incorporated by reference. Where such terms conflict with this Agreement, they control solely as to the applicable component. Phoenix will make a current components list available on request.
1.6 Changes to the Services. Phoenix may improve, modify, or add to the Services from time to time. Phoenix will not materially degrade the core functionality of a Service during a paid Subscription Term. If Phoenix discontinues a Service that Customer has paid for, Phoenix will give at least ninety (90) days’ notice and refund any prepaid, unused Fees for the discontinued Service.
1.7 Beta offerings. Phoenix may offer features labeled beta, preview, or evaluation. These are optional, provided “as is” without warranty or SLA, may be discontinued at any time, and are excluded from the indemnity in Section 8.2. Customer should not use beta offerings with sensitive or regulated data.
1.8 Reservation of rights. Phoenix and its licensors retain all right, title, and interest in and to the Services, including all software, models, algorithms, interfaces, documentation, and improvements. No rights are granted except as expressly stated. No rights arise by implication, estoppel, or waiver.
2. USE RESTRICTIONS↑
2.1 Prohibited conduct. Customer will not, and will not permit any Authorized User or third party to:
a. copy, modify, translate, or create derivative works of the Services;
b. reverse engineer, decompile, or disassemble the Services, or otherwise attempt to derive their source code, structure, or underlying models, except to the extent this restriction is unenforceable under applicable law;
c. circumvent or attempt to circumvent any technical, security, usage, or rate limit, or access the Services other than through the interfaces and APIs Phoenix provides;
d. rent, lease, resell, sublicense, distribute, time-share, or operate a service bureau or hosting service using the Services for the benefit of any third party;
e. use the Services to build, train, or benchmark a competing product or service, or disclose benchmark or performance test results without Phoenix’s prior written consent;
f. upload or transmit any malicious code, or use the Services in a manner that interferes with or degrades the Services, Phoenix’s infrastructure, or any other customer’s use;
g. use the Services in violation of any applicable law, including export control, sanctions, privacy, and anti-corruption laws;
h. remove, obscure, or alter any proprietary notice or attribution; or
i. upload Regulated Data (as defined in Section 15) unless the applicable Order expressly authorizes it and the parties have executed any required supplemental terms.
2.2 Enforcement. Phoenix may investigate suspected violations of this Section and may take proportionate action, including suspension under Section 12.4.
3. CUSTOMER DATA↑
3.1 Ownership. As between the parties, Customer owns and retains all right, title, and interest in Customer Data. Customer grants Phoenix a non-exclusive, worldwide, royalty-free license to host, copy, transmit, process, and display Customer Data solely as necessary to provide, secure, and support the Services, and as otherwise instructed by Customer.
3.2 Customer responsibilities. Customer represents that it has all rights, consents, and lawful bases necessary for Phoenix to process Customer Data as contemplated by this Agreement, and that Customer Data does not infringe any third-party rights or violate any law.
3.3 Service Data. Phoenix may generate and use Service Data — aggregated and de-identified technical, statistical, and usage information derived from operation of the Services — to operate, secure, troubleshoot, analyze, and improve the Services and to develop new offerings. Phoenix will not disclose Service Data in any form that identifies Customer, any Authorized User, or any individual, and will not use Customer Data to train generally available machine learning models made available to other customers except with Customer’s prior written consent.
3.4 Support Data. Data Customer provides to Phoenix in connection with a support request will be used only to diagnose and resolve that request and to improve support quality, unless the parties agree otherwise in writing.
3.5 Return and deletion. During the Subscription Term, Customer may export Customer Data using the functionality of the Services. For thirty (30) days after expiration or termination, Phoenix will retain Customer Data and make it available for export in a commercially standard format. After that period, Phoenix will delete Customer Data from active systems within thirty (30) days and from backups within ninety (90) days, subject to legal retention obligations. Phoenix will certify deletion on written request.
4. PRIVACY AND DATA PROTECTION↑
4.1 Roles. Phoenix hosts and operates the Services on infrastructure that Phoenix owns and controls, and does not use a third-party public cloud provider to host Customer Data. Regardless of hosting arrangements, where Phoenix processes Personal Data on Customer’s behalf, Customer is the controller (or, where Customer is itself a processor, Phoenix is a sub-processor) and Phoenix is the processor. Phoenix will process Personal Data only on Customer’s documented instructions, which include this Agreement, each Order, and Customer’s use of the Services, unless required otherwise by law, in which case Phoenix will notify Customer unless legally prohibited.
4.2 Processing details. The parties acknowledge that: (a) the subject matter of processing is the provision of the Services; (b) the duration is the Subscription Term plus the retention periods in Section 3.5; (c) the nature and purpose is hosting, storage, analysis, and transmission of Customer Data as directed by Customer; (d) the types of Personal Data and categories of data subjects are those Customer chooses to submit, typically Customer’s personnel, contractors, customers, and end users.
4.3 Data Protection Addendum. Phoenix’s Data Protection Addendum (“DPA”), available at https://phxconsultants.com/legal/dpa and incorporated by reference, governs Phoenix’s processing of Personal Data. Where the DPA conflicts with the body of this Agreement regarding Personal Data, the DPA controls.
4.4 International transfers. Where required, transfers of Personal Data out of the European Economic Area, the United Kingdom, or Switzerland will be governed by the applicable Standard Contractual Clauses (or the UK Addendum / Swiss equivalent), which are incorporated into the DPA.
4.5 Sub-processors. Because Phoenix hosts the Services on its own infrastructure, it engages a limited number of sub-processors, listed at https://phxconsultants.com/legal/subprocessors and in Exhibit B. As of the Effective Date, Phoenix’s only sub-processor is PayPal, Inc., which processes billing and payment information; PayPal does not receive Customer Data submitted to the Services. Phoenix remains responsible for its sub-processors’ performance. Phoenix will give at least thirty (30) days’ notice before engaging a new sub-processor. If Customer reasonably objects on data protection grounds within that period, the parties will work in good faith to find an alternative; if none is available, Customer may terminate the affected subscription and receive a pro-rata refund of prepaid, unused Fees.
4.6 Data subject requests. Phoenix will provide reasonable assistance, taking into account the nature of the processing, to help Customer respond to data subject requests. If Phoenix receives such a request directly, it will redirect the individual to Customer.
4.7 Assistance and records. Phoenix will maintain records required by Article 30(2) of the GDPR to the extent applicable, and will make available information reasonably necessary to demonstrate compliance with this Section, including through a completed security questionnaire or a current third-party audit report.
5. SECURITY↑
5.1 Security program. Phoenix maintains a written information security program with administrative, physical, and technical safeguards designed to protect Customer Data against unauthorized access, disclosure, alteration, loss, or destruction, appropriate to the nature and scope of the Services. Phoenix’s then-current security documentation is available at https://phxconsultants.com/legal/security.
5.2 Technical and organizational measures. Without limiting Section 5.1, Phoenix will:
a. host the Services on infrastructure owned and operated by Phoenix at 9 Wilson Drive, Northfield, New Jersey 08225, with physical access limited to authorized personnel;
b. encrypt Customer Data in transit using TLS 1.2 or higher across all public networks;
c. encrypt Customer Data at rest, including on backup media, using AES-256 or an equivalent industry-standard algorithm;
d. restrict access to Customer Data on a least-privilege, role-based basis, require unique credentials for each individual with access, and require multi-factor authentication for administrative access;
e. maintain system and access logs sufficient to investigate a suspected Security Incident, retained for at least 60 days;
f. apply security patches to systems supporting the Services on a risk-prioritized basis, and apply patches addressing critical vulnerabilities within 30 days of availability;
g. perform regular backups of Customer Data, store backup copies in an encrypted form at a geographically separate location, and test restoration from backup at least annually; and
h. maintain a documented incident response plan, reviewed at least annually.
5.3 Compliance posture. Phoenix does not represent that it holds SOC 2 Type II, ISO 27001, or any other third-party security certification as of the Effective Date. Phoenix will complete customer security questionnaires and provide reasonable written evidence of the measures described in Section 5.2 on request. If Phoenix obtains a third-party certification or audit report during the Subscription Term, it will make the report available to Customer on request under confidentiality obligations.
5.4 Payment card data. Phoenix processes payment card transactions through a PCI DSS compliant third-party payment processor. Payment card numbers are not transmitted to, stored on, or processed by Phoenix systems. Customer must not submit cardholder data to the Services, consistent with Section 2.1(i).
5.5 Incident notification. Phoenix will notify Customer without undue delay, and in any event within seventy-two (72) hours, after confirming a Security Incident affecting Customer Data. Phoenix will provide known details, take reasonable steps to mitigate and remediate, and cooperate with Customer’s own notification obligations. Notification is not an acknowledgment of fault.
5.6 Personnel. Phoenix will conduct background screening consistent with applicable law, require written confidentiality commitments from personnel with access to Customer Data, provide periodic security and privacy training, and revoke access promptly on termination of employment or engagement.
6. SERVICE LEVELS AND SUPPORT↑
6.1 Availability. Phoenix will make the Services available in accordance with the Service Level Agreement at https://phxconsultants.com/legal/sla (“SLA”), incorporated by reference. Service credits under the SLA are Customer’s sole remedy for failure to meet the committed availability level, except as provided in Section 6.3.
6.2 Support. Phoenix will provide technical support at the tier stated in the Order, in accordance with the support policy at https://phxconsultants.com/legal/support.
6.3 Chronic failure. If monthly availability falls below ninety-five percent (95%) in each of three (3) consecutive calendar months, Customer may terminate the affected subscription on written notice given within thirty (30) days after the end of the third such month, and will receive a pro-rata refund of prepaid, unused Fees. This is Customer’s sole termination right arising from availability shortfalls.
6.4 Exclusions. The SLA does not apply to unavailability caused by scheduled maintenance announced in advance, Customer’s or an Authorized User’s acts or omissions, Customer’s equipment or networks, third-party services not under Phoenix’s control, beta offerings, or Force Majeure Events.
7. REPRESENTATIONS AND WARRANTIES↑
7.1 Mutual. Each party represents that it has full authority to enter into and perform under this Agreement, and that doing so will not breach any other agreement to which it is bound.
7.2 Phoenix warranties. Phoenix warrants, on a continuing basis during the Subscription Term, that:
a. the Services will perform materially in accordance with the Documentation;
b. Phoenix will provide the Services with reasonable skill and care, in a professional and workmanlike manner;
c. to Phoenix’s knowledge, the Services do not infringe or misappropriate any third-party intellectual property right;
d. Phoenix will not knowingly introduce viruses, worms, or other malicious code into the Services or Customer’s systems; and
e. Phoenix will comply with all laws applicable to its provision of the Services, including Data Protection Laws and Anti-Corruption Laws, and will train its personnel accordingly.
7.3 Warranty remedy. For a breach of Section 7.2(a) or 7.2(b), Phoenix will use commercially reasonable efforts to correct the non-conformity. If Phoenix has not done so within thirty (30) days of written notice, Customer may terminate the affected subscription and receive a pro-rata refund of prepaid, unused Fees. For subscriptions with annual Fees of $100,000 or more, Customer may instead elect a full refund of Fees paid for the then-current Subscription Term.
7.4 Disclaimer. EXCEPT AS EXPRESSLY STATED IN THIS AGREEMENT, THE SERVICES ARE PROVIDED “AS IS.” TO THE MAXIMUM EXTENT PERMITTED BY LAW, PHOENIX DISCLAIMS ALL OTHER WARRANTIES, EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE, INCLUDING IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, NON-INFRINGEMENT, AND ANY WARRANTIES ARISING FROM COURSE OF DEALING, USAGE, OR TRADE PRACTICE. PHOENIX DOES NOT WARRANT THAT THE SERVICES WILL BE UNINTERRUPTED OR ERROR-FREE, OR THAT ALL DEFECTS WILL BE CORRECTED.
8. INDEMNIFICATION↑
8.1 By Customer. Customer will defend Phoenix and its Affiliates against any third-party claim arising from (a) Customer Data, including any allegation that Customer Data infringes third-party rights or was collected or used unlawfully, or (b) Customer’s or an Authorized User’s use of the Services in violation of this Agreement or applicable law. Customer will indemnify Phoenix for damages and reasonable attorneys’ fees finally awarded against Phoenix, or paid in a settlement Customer approves.
8.2 By Phoenix. Phoenix will defend Customer against any third-party claim alleging that (a) Customer’s use of the Services as permitted under this Agreement infringes or misappropriates a third-party intellectual property right, or (b) Phoenix’s provision of the Services violated an applicable law, including Data Protection Laws. Phoenix will indemnify Customer for damages and reasonable attorneys’ fees finally awarded against Customer, or paid in a settlement Phoenix approves.
8.3 Exclusions. Phoenix has no obligation under Section 8.2 to the extent a claim arises from (a) Customer Data or any non-Phoenix product, service, or data; (b) modification or combination of the Services not made or authorized in writing by Phoenix; (c) use of the Services after Phoenix notified Customer to stop, where the claim would have been avoided by stopping; or (d) beta offerings.
8.4 Remedies for infringement. If the Services become, or Phoenix reasonably believes they may become, the subject of an infringement claim, Phoenix may at its option (a) procure the right for Customer to continue using them, (b) modify or replace them so they are non-infringing while materially preserving functionality, or (c) if neither is commercially reasonable, terminate the affected subscription and refund prepaid, unused Fees. Sections 8.2 through 8.4 state Phoenix’s entire liability and Customer’s exclusive remedy for intellectual property infringement.
8.5 Procedure. The indemnified party must promptly notify the indemnifying party of the claim (delay excuses the indemnifying party only to the extent it is prejudiced), give the indemnifying party sole control of the defense and settlement, and provide reasonable cooperation at the indemnifying party’s expense. The indemnified party may participate with its own counsel at its own cost.
8.6 Settlement limits. The indemnifying party may not settle a claim without the indemnified party’s written consent (not to be unreasonably withheld) if the settlement (a) involves a government agency as claimant, (b) includes any admission of fault by the indemnified party, (c) does not include a full release of the indemnified party, or (d) imposes any obligation on the indemnified party other than a full release and payment of money by the indemnifying party.
9. LIMITATION OF LIABILITY↑
9.1 General cap. Except as stated below, each party’s total aggregate liability arising out of or related to this Agreement is limited to direct damages not exceeding the Fees paid or payable by Customer for the affected Service during the twelve (12) months preceding the first incident giving rise to the claim.
9.2 Security incidents. Phoenix’s aggregate liability for a Security Incident resulting from Phoenix’s breach of Section 5 is subject to the general limitation in Section 9.1 and will not exceed the Fees paid by Customer for the affected Service during the twelve (12) months preceding the incident.
9.3 Free and evaluation offerings. For Services provided at no charge, including trials and beta offerings, Phoenix’s aggregate liability will not exceed US $5,000.
9.4 Excluded damages. NEITHER PARTY WILL BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, PUNITIVE, EXEMPLARY, OR CONSEQUENTIAL DAMAGES, OR FOR LOST PROFITS, LOST REVENUE, LOSS OF USE, LOSS OF GOODWILL, OR BUSINESS INTERRUPTION, HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, EVEN IF ADVISED OF THE POSSIBILITY.
9.5 Exceptions. The limitations in Sections 9.1, 9.3, and 9.4 do not apply to (a) Customer’s payment obligations; (b) either party’s indemnification obligations under Section 8; (c) breach of Section 10 (Confidentiality), except that liability relating to Customer Data remains subject to Sections 9.1 and 9.2; (d) infringement or misappropriation of the other party’s intellectual property; or (e) gross negligence, willful misconduct, or fraud.
9.6 Allocation of risk. The parties agree that these limitations reflect an agreed allocation of risk and are an essential basis of the bargain, and will apply even if a limited remedy fails of its essential purpose.
10. CONFIDENTIALITY↑
10.1 Definition. “Confidential Information” means non-public information disclosed by one party to the other that is designated confidential or that a reasonable person would understand to be confidential, including Customer Data, Service security documentation, product roadmaps, pricing, and the terms of this Agreement. Confidential Information excludes information that (a) is or becomes public without breach, (b) was lawfully known to the recipient without a confidentiality obligation, (c) is independently developed without use of the discloser’s Confidential Information, or (d) is lawfully received from a third party without restriction.
10.2 Obligations. Each party will protect the other’s Confidential Information using at least reasonable care, use it only for purposes of this Agreement, and disclose it only to Representatives who need to know and are bound by obligations at least as protective as these. Each party remains responsible for its Representatives’ compliance and will promptly notify the other of any unauthorized use or disclosure.
10.3 Compelled disclosure. A party may disclose Confidential Information as required by law or valid legal process, provided it gives prompt notice where legally permitted so the other party can seek protective treatment, and discloses only what is required.
10.4 Duration. These obligations apply (a) to Customer Data, until deleted under Section 3.5, and (b) to all other Confidential Information, for five (5) years from disclosure — except trade secrets, which remain protected for as long as they qualify as trade secrets.
10.5 Equitable relief. Each party acknowledges that breach of this Section may cause irreparable harm for which damages are an inadequate remedy, and that the non-breaching party may seek injunctive relief without posting bond.
11. FEES AND PAYMENT↑
11.1 Fees. Customer will pay the fees stated in each Order (“Fees”). Except as expressly provided in this Agreement, Fees are non-refundable and Orders are non-cancelable. Subscription Fees are based on the subscription purchased, not actual usage, and quantities purchased cannot be decreased during a Subscription Term. Fees are inclusive of Phoenix’s payment processing costs; Phoenix does not impose a separate surcharge for payment by credit card.
11.2 Invoicing and payment. Unless the Order states otherwise, Phoenix will invoice Fees annually in advance, and Customer will pay within thirty (30) days of the invoice date in U.S. dollars. Usage-based Fees are invoiced monthly in arrears.
11.3 Accepted payment methods. Phoenix accepts payment by (a) credit or debit card processed through Phoenix’s third-party payment processor, (b) wire transfer or ACH to the account identified on the invoice, and (c) check payable to Phoenix Consultants Group, Inc. and mailed to the remittance address on the invoice. Phoenix may add or discontinue payment methods on notice, provided at least one method remains reasonably available to Customer.
11.4 Payment costs. Customer bears all bank, wire, intermediary, correspondent, and currency conversion charges associated with its payment, such that Phoenix receives the full invoiced amount in U.S. dollars. Any shortfall resulting from such charges remains an outstanding balance and is payable on Phoenix’s notice.
11.5 Checks and clearance. Payment by check is effective when the funds have cleared into Phoenix’s account, not on the date of mailing or receipt. If a check or electronic payment is returned, reversed, or charged back for any reason, the invoice will be treated as unpaid as of its original due date, and Customer will pay a returned-item fee of $50 in addition to any bank charges Phoenix incurs.
11.6 Overage. If Customer’s usage exceeds the limits in the Order, Phoenix will invoice the excess at the rates in the Order, or at Phoenix’s then-current list rates if none are stated.
11.7 Late payment. Undisputed amounts not paid when due accrue interest at the lesser of 1.5% per month or the maximum permitted by law. Customer must dispute an invoice in good faith and in writing within thirty (30) days of receipt; the parties will work to resolve disputes promptly and Customer will pay all undisputed amounts on time. Customer will reimburse Phoenix’s reasonable costs of collection, including attorneys’ fees, for undisputed amounts more than sixty (60) days past due.
11.8 Chargebacks. Customer will not initiate a chargeback, payment reversal, or dispute with its card issuer or bank for amounts owed under this Agreement without first raising the dispute with Phoenix under Section 11.7 and allowing thirty (30) days to resolve it. A chargeback initiated in breach of this Section is a material breach of this Agreement.
11.9 Taxes. Fees exclude taxes. Customer is responsible for all sales, use, VAT, GST, and similar taxes, excluding taxes on Phoenix’s net income. If Customer is required to withhold tax, Customer will gross up the payment so Phoenix receives the full invoiced amount.
11.10 Price changes on renewal. Phoenix may change Fees effective on renewal by giving at least sixty (60) days’ written notice before the end of the then-current Subscription Term. Absent such notice, renewal Fees will be the same as the expiring term.
12. TERM AND TERMINATION↑
12.1 Term. This Agreement begins on the Effective Date and continues until all Orders have expired or been terminated, or until terminated under this Section.
12.2 Subscription Term and renewal. Each subscription runs for the Subscription Term stated in the Order and renews automatically for successive periods of equal length unless either party gives written notice of non-renewal at least thirty (30) days before the end of the then-current term.
12.3 Termination for cause. Either party may terminate this Agreement or an affected Order immediately on written notice if the other party (a) materially breaches and fails to cure within thirty (30) days after written notice describing the breach, or (b) becomes Insolvent.
12.4 Suspension. Phoenix may suspend Customer’s access, in whole or in part, if (a) Customer’s use poses a material security risk or threatens the integrity of the Services, (b) Customer’s use is materially unlawful, or (c) Fees remain unpaid more than thirty (30) days past due after written notice. Phoenix will give reasonable advance notice where practicable, limit suspension to what is reasonably necessary, and restore access promptly once the cause is resolved. Suspension does not relieve Customer of payment obligations, except where the suspension was wrongful.
12.5 Effect of termination. On expiration or termination: (a) all access rights end immediately; (b) all outstanding Fees for the period through the effective date of termination become due; (c) Customer may export Customer Data as described in Section 3.5; and (d) if Customer terminates for Phoenix’s uncured material breach, Phoenix will refund prepaid, unused Fees on a pro-rata basis.
12.6 Survival. Sections 2, 3.1, 3.5, 7.4, 8, 9, 10, 11 (as to amounts accrued), 12.5, 12.6, 13, 14, and 15 survive expiration or termination, along with any other provision that by its nature should survive.
13. COMPLIANCE AND VERIFICATION↑
13.1 Records and usage verification. Customer will maintain accurate records of its use of the Services. No more than once per twelve-month period, and on at least thirty (30) days’ written notice, Phoenix may verify Customer’s compliance with the usage limits in the Order, either by requesting a self-certification or, at Phoenix’s expense, through an independent auditor bound by confidentiality obligations. Audits will occur during business hours and will not unreasonably interfere with Customer’s operations. If verification reveals under-licensing, Customer will promptly purchase sufficient subscriptions to cover the shortfall; if the shortfall exceeds five percent (5%), Customer will also reimburse Phoenix’s reasonable audit costs.
13.2 Customer audit rights. On reasonable written notice and no more than once per twelve-month period (or more often if required by Customer’s regulator or following a Security Incident), Phoenix will provide information reasonably necessary to demonstrate compliance with Sections 4 and 5. Phoenix may satisfy this obligation by providing current third-party audit reports and completed security questionnaires. Each party bears its own costs.
13.3 Confidentiality of audit materials. All information exchanged under this Section is Confidential Information and may be used only to verify compliance.
13.4 Compliance with laws. Each party will comply with all laws applicable to its performance or use, including export control, sanctions, anti-corruption, and Data Protection Laws. Phoenix will obtain and maintain all approvals, licenses, and registrations necessary for its provision of the Services.
14. GENERAL↑
14.1 Order of precedence. If there is a conflict among the documents comprising this Agreement, the following order controls: (a) a signed amendment; (b) the applicable Order; (c) the DPA (as to Personal Data); (d) the body of this Agreement; (e) the SLA; and (f) the Documentation.
14.2 Amendments. Phoenix will not change the terms of this Agreement, including its privacy and security commitments, during an active Subscription Term except by a writing signed by both parties. Phoenix may update the SLA, support policy, and sub-processor list as provided in this Agreement, provided no update materially reduces Customer’s rights during a paid Subscription Term.
14.3 Assignment. Neither party may assign this Agreement without the other’s written consent, except that either party may assign it in full, without consent, to an Affiliate or in connection with a merger, acquisition, reorganization, or sale of all or substantially all assets, on written notice to the other party. Customer consents to Phoenix’s assignment of its right to receive payment. Assignment does not relieve the assigning party of obligations accrued before assignment. Any attempted assignment in violation of this Section is void.
14.4 Independent contractors. The parties are independent contractors. Nothing creates a partnership, joint venture, agency, or employment relationship. Each party may independently develop products without using the other’s Confidential Information.
14.5 Non-exclusive. This Agreement is non-exclusive. Either party may enter into similar arrangements with others.
14.6 Feedback. If Customer provides Feedback, Customer grants Phoenix a perpetual, irrevocable, worldwide, royalty-free, non-exclusive license under Customer’s non-patent intellectual property rights to use, modify, and commercialize the Feedback in Phoenix’s products and services. Customer retains all other rights in Feedback. Neither party is obligated to provide Feedback, and Feedback is provided without any confidentiality obligation on the recipient notwithstanding Section 10.
14.7 Publicity. Neither party will use the other’s name, logo, or trademarks in publicity without prior written consent, except that Phoenix may identify Customer as a customer in its customer lists and on its website, which consent Customer may revoke on written notice.
14.8 Force majeure. Neither party is liable for failure or delay in performance (other than payment obligations) caused by a Force Majeure Event, provided the affected party gives prompt notice and uses reasonable efforts to resume performance. If a Force Majeure Event continues more than sixty (60) days, either party may terminate the affected Order without penalty.
14.9 Notices. Notices must be in writing and are effective on receipt when delivered by hand, by nationally recognized courier, or by certified mail to the address on the Order, or on transmission when sent by email to the address the recipient designates for legal notices. Legal notices to Phoenix must be sent to in**@************ts.com with a copy to the address above. Operational notices may be sent by email or through the Services.
14.10 Governing law and venue. This Agreement is governed by the laws of the State of New Jersey, without regard to conflict-of-law principles. The United Nations Convention on Contracts for the International Sale of Goods does not apply. The parties consent to the exclusive jurisdiction of the state and federal courts located in Atlantic County, New Jersey, and to the United States District Court for the District of New Jersey, and waive any objection to venue or forum non conveniens. Each party waives any right to a jury trial. Nothing prevents either party from seeking injunctive relief in any court of competent jurisdiction.
14.11 Dispute escalation. Before filing suit (other than for injunctive relief or non-payment), the parties will escalate the dispute to senior executives who will confer in good faith for thirty (30) days.
14.12 Severability. If any provision is held unenforceable, it will be modified to the minimum extent necessary to make it enforceable, and the remainder of the Agreement will remain in effect.
14.13 Waiver. No failure or delay in exercising a right waives it. Waivers must be in writing and signed by the waiving party.
14.14 No third-party beneficiaries. This Agreement creates no third-party beneficiary rights except as expressly stated.
14.15 Government customers. If Customer is a government entity, Customer represents that it has complied with all applicable procurement laws, is authorized to enter into this Agreement, and that this Agreement satisfies applicable procurement requirements. The Services are “commercial computer software” as defined in applicable federal acquisition regulations, and government rights are limited to those granted here.
14.16 Construction. This Agreement is in English; translations are for reference only. Neither party has relied on anything not stated in this Agreement. This Agreement will be interpreted according to its plain meaning, without presumption against the drafter. Unless stated otherwise: examples introduced by “including” or “e.g.” are non-exhaustive; monetary amounts are in U.S. dollars; “days” means calendar days; “may” confers a right but not a duty; “written” includes email where this Agreement authorizes email; URLs include successors and localized versions; and a document is “signed” when hand-signed or executed through an electronic signature service by an authorized representative.
14.17 Insurance. Phoenix maintains, at its own expense and with insurers of recognized standing, the commercial general liability, technology errors and omissions, and cyber liability coverage in force under its current policies, and will keep coverage of substantially the same scope in force throughout the Subscription Term. Phoenix will provide a certificate of insurance evidencing its then-current coverage and limits on Customer’s written request. Coverage limits are those stated in the certificate; nothing in this Section expands Phoenix’s liability beyond the limitations in Section 9.
14.18 Counterparts. This Agreement may be executed in counterparts, including by electronic signature, each of which is an original and all of which together constitute one instrument.
15. DEFINITIONS↑
“Affiliate” means any entity that controls, is controlled by, or is under common control with a party, where “control” means ownership of more than 50% of voting securities or the power to direct management and policies.
“Anti-Corruption Laws” means all laws prohibiting fraud, bribery, corruption, money laundering, inaccurate books and records, and inadequate internal controls, including the U.S. Foreign Corrupt Practices Act and the UK Bribery Act.
“Authorized User” means an individual whom Customer permits to access the Services, including Customer’s and its Affiliates’ employees and contractors.
“Customer Data” means all data, content, and files submitted to the Services by or on behalf of Customer or its Authorized Users. Customer Data excludes Service Data and Support Data.
“Data Protection Laws” means all laws applicable to either party governing privacy, data protection, or data security, including the EU General Data Protection Regulation (“GDPR”), the UK GDPR, the California Consumer Privacy Act as amended, and their implementing and successor legislation.
“Documentation” means the user guides, technical specifications, and other materials Phoenix makes generally available describing the Services, as updated from time to time.
“Feedback” means suggestions, ideas, comments, or know-how a party provides about the other’s products or services. Feedback excludes sales forecasts, release schedules, marketing plans, financial results, and roadmaps.
“Force Majeure Event” means an event beyond a party’s reasonable control, including acts of God, natural disaster, war, terrorism, civil unrest, labor action, epidemic, government action, widespread internet or utility failure, and denial-of-service attacks.
“Insolvent” means admitting in writing an inability to pay debts as they mature; making a general assignment for the benefit of creditors; having a trustee or receiver appointed over substantially all assets (not vacated within sixty (60) days); filing or having filed against it a bankruptcy petition (not dismissed within sixty (60) days); being adjudicated bankrupt; being wound up or liquidated; or ceasing to carry on business.
“Order” means an ordering document, order form, or online purchase flow executed by or on behalf of the parties that references this Agreement and identifies the Services, quantities, Fees, and Subscription Term.
“Personal Data” means information relating to an identified or identifiable natural person, as further defined under applicable Data Protection Laws.
“Regulated Data” means data subject to heightened legal requirements, including protected health information under HIPAA, cardholder data under PCI DSS, biometric identifiers, government classified information, and data subject to ITAR or EAR controls.
“Representatives” means a party’s employees, Affiliates, contractors, advisors, and consultants.
“Security Incident” means a confirmed breach of Phoenix’s security leading to accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Customer Data in Phoenix’s possession or control. Unsuccessful attempts and routine events such as pings, port scans, and failed login attempts are not Security Incidents.
“Service Data” means aggregated, de-identified technical, operational, and statistical data derived from the operation and use of the Services, from which all identifiers of Customer, Authorized Users, and individuals have been removed.
“Services” means the FireFlight Data Systems platform and any other Phoenix software-as-a-service offerings, APIs, and related support identified in an Order, together with the Documentation. “FireFlight Data Systems,” “FireFlight,” and associated logos are trademarks of Phoenix; no rights in those marks are granted under this Agreement except as expressly stated.
“Standard Contractual Clauses” means the standard data protection clauses adopted by the European Commission under Article 46 of the GDPR, and the equivalent UK and Swiss transfer mechanisms.
“Subscription Term” means the period stated in an Order during which Customer is authorized to access the Services.
“Support Data” means data Customer provides to Phoenix, or authorizes Phoenix to obtain from the Services, in connection with a technical support request.
SIGNATURES↑
PHOENIX CONSULTANTS GROUP, INC. 9 Wilson Drive, Northfield, New Jersey 08225
By: _______________________________
Name: _____________________________
Title: ____________________________
Date: _____________________________
CUSTOMER: _______________________
By: _______________________________
Name: _____________________________
Title: ____________________________
Date: _____________________________
EXHIBIT A — ORDER FORM↑
| Field | Detail |
|---|---|
| Customer legal entity | |
| Billing contact / address | |
| Notices contact | |
| Services ordered | FireFlight Data Systems — [modules / editions] |
| Usage limits (users, volume, environments) | |
| Subscription Term (start / end) | |
| Fees and billing frequency | |
| Overage rates | |
| Payment terms (if other than Net 30) | |
| Support tier | |
| Regulated Data authorized? | Yes / No — if yes, specify type and supplemental terms |
| Special terms |
This Order incorporates the Phoenix Consultants Group, Inc. Master Software-as-a-Service Agreement dated January 1, 2026 governing the FireFlight Data Systems platform.
EXHIBIT B — SUB-PROCESSORS↑
Current as of January 1, 2026. The authoritative list is maintained at https://phxconsultants.com/legal/subprocessors.
| Sub-processor | Purpose | Data processed | Location |
|---|---|---|---|
| PayPal, Inc. | Payment processing | Billing contact name, email, billing address, transaction amounts. Payment card numbers are collected and stored by PayPal, not by Phoenix. | United States |
Phoenix hosts the Services on infrastructure it owns and operates and does not use a third-party cloud hosting provider to store or process Customer Data. Phoenix will provide at least thirty (30) days’ notice before engaging any additional sub-processor, in accordance with Section 4.5.