Terms of Service
The regulatory and contractual foundation governing clinical deployment, data architecture boundaries, and platform security.
1. Eligibility, Zero-Knowledge Key Custody, and Data Security Policies
Use of the self-serve tiers of the Platform (Lite, Pro, Elite, Research Lite, Research Pro) is fully authorized for Protected Health Information (PHI) when utilizing our standard Business Associate Agreement (BAA) executed electronically via clickwrap during onboarding.
Zero-Knowledge Key Custody & Intentional Architecture: Upon onboarding, the Platform generates a 256-bit AES Master Workspace Key entirely client-side via the Web Crypto API. This key is derived via PBKDF2 (100,000 iterations) from your local access code. ConsentCollect never receives, transmits, logs, or maintains access to this code or key in plaintext. The user retains sole, exclusive responsibility for preserving this access code. Loss of the access code results in the permanent, irreversible destruction of the ability to decrypt workspace data and associated logs. The permanent unrecoverability of data resulting from the User's failure to maintain their local cryptographic keys or MFA tokens is the intended architectural design of the Platform's zero-knowledge security model and shall not constitute a breach of service, data loss incident, negligent act, or grounds for any liability claim.
2. Tier Boundaries, Electronic BAA Policies, and Core System Limitations
ConsentCollect provides a standard Business Associate Agreement (BAA) for all self-serve pricing tiers, executed electronically via clickwrap during onboarding. Custom wet-signature or offline BAAs are strictly restricted to the Enterprise Tier.
Client-Side Zero-Knowledge Framework: The platform is designed to securely host PHI on all tiers under the executed clickwrap BAA. To maintain the cryptographic integrity of the platform, clinicians must only ingest PHI within standard encrypted patient forms. Plaintext PHI is prohibited strictly within unencrypted structural metadata fields.
Programmatic Client-Side Defensive Infrastructure: To programmatically enforce E2EE boundaries and protect the integrity of the SaaS network infrastructure, the platform deploys autonomous client-side tools:
- Client-Side End-to-End Encryption (E2EE): Any data fields entered into the gateway are cryptographically sealed in the browser using AES-256-GCM prior to network transit. The platform's database and object storage ingest and host only opaque ciphertext.
- Automated PHI Shielding: The platform utilizes a client-side NLP engine and custom regular expression matrices to intercept, tokenize, and mask potential identifiers with deterministic placeholders before metadata optimization or subprocessor analysis occurs.
- Manual Audit Pre-Clearance: Users must use the built-in manual review panels to ensure no raw plaintext PHI is embedded within structural form templates or layout designs.
3. The "Not Medical Advice" Shield
ConsentCollect is a software-as-a-service infrastructure provider. The Platform is designed to digitize and forensically verify the signature and comprehension workflow of informed consent.
4. Intellectual Property Rights
Platform Intellectual Property
ConsentCollect owns all rights, titles, and interests in the Platform software, source code, database schemas, dynamic layout logic, UI/UX systems, specialty blueprints, and automated compliance engines.
Client Consent Data Strings
The Covered Entity owns all patient consent records, signature data, custom clinical risk templates, and cryptographic consent strings created using the platform.
5. Platform Uptime, Maintenance & Disclaimers
ConsentCollect provides a target uptime of 99.9% for its cloud infrastructure. Maintenance windows are typically scheduled during off-peak hours (Eastern Time Saturday 02:00 to 06:00) and are announced 48 hours in advance.
Except for SLAs explicitly negotiated under custom Enterprise contracts, the service is provided on an "AS IS" and "AS AVAILABLE" basis. We disclaim all warranties of fitness for a particular clinical study or trial purpose.
6. Hyper-Strict Limitation of Liability and Multi-Layered Indemnification
Consequential Damages Waiver: TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT SHALL CONSENTCOLLECT, ITS DIRECTORS, OR ITS INFRASTRUCTURE SUBPROCESSORS BE LIABLE FOR ANY INDIRECT, SPECIAL, INCIDENTAL, CONSEQUENTIAL, PUNITIVE, OR EXEMPLARY DAMAGES. THIS INCLUDES, BUT IS NOT LIMITED TO, LOSS OF REVENUE, DATA ERASURE CRON TIMEOUTS, DEFECTIVE AUDIT EVENT TRAILS, MEDICAL MALPRACTICE CLAIMS, OR REGULATORY FINES RESULTING FROM THE USER'S FAILURE TO VALIDATE THE CLINICAL LEGITIMACY OF FORM LAYOUTS.
Liability Cap: THE TOTAL AGGREGATE LIABILITY OF CONSENTCOLLECT FOR ANY CLAIM ARISING OUT OF OR RELATING TO THESE TERMS OR THE USE OF THE PLATFORM, WHETHER IN CONTRACT, TORT, OR OTHERWISE, SHALL BE STRICTLY LIMITED TO THE ACTUAL FEES PAID BY THE USER TO CONSENTCOLLECT IN THE THREE (3) MONTHS IMMEDIATELY PRECEDING THE INCIDENT GIVING RISE TO LIABILITY.
Strict Multi-Layered Indemnification: You agree to fully indemnify, defend, and hold harmless ConsentCollect, its officers, directors, employees, and cloud infrastructure vendors from and against any and all third-party claims, liabilities, regulatory enforcement actions, losses, costs, or expenses (including reasonable attorneys' fees and Office for Civil Rights (OCR) penalties) arising out of or resulting from:
- (a) Your upload, storage, or transmission of PHI without executing the standard BAA;
- (b) Any clinical or operational disputes regarding patient comprehension, informed consent validity, or eIDAS/Part 11 compliance;
- (c) Any unauthorized data exposure or system lockouts resulting from the loss, compromise, or theft of local clinician workspace access codes;
- (d) DPDP Act Penalty Indemnification: For accounts subject to Indian jurisdiction, the user (Data Fiduciary) acknowledges that they hold exclusive custody of the client-side decryption keys. If a data breach occurs due to the loss of the user's local access codes, the user assumes 100% liability for any statutory penalties levied by the Data Protection Board of India (DPBI) under the DPDP Act, 2023.
7. Termination & Consent Archive Preservation
- 30-Day Export Window: The Covered Entity has thirty (30) days from the date of termination to export all patient consent logs, signature records, and HMAC chains in standard CSV/JSON format.
- Terminal Erasure Job: Following the expiration of the 30-day export window, an automated terminal erasure mutation (
executeTerminalErasure) is executed. The system permanently purges all encrypted database documents and systematically purges all associated objects, signatures, and identity proof artifacts. - Audit Trail Retention: Standard HMAC audit chain events are preserved for up to six (6) years to satisfy regulatory record retention standards (45 CFR § 164.530(j)), after which they are systematically deleted.
8. Mandatory Dispute Resolution, Jurisdiction, and Arbitration
Notice and Cure Period: Prior to initiating any legal action or arbitration against ConsentCollect, the User must provide written notice of the alleged breach or dispute and grant ConsentCollect a period of sixty (60) days to cure the alleged issue. Failure to provide such notice and cure period strictly prohibits the initiation of any proceedings.
Statute of Limitations: Any claim or cause of action arising out of or related to the use of the Services or these Terms must be filed within one (1) year after such claim or cause of action arose, or it is forever barred, notwithstanding any statute or law to the contrary.
Prevailing Party Fees: In any legal action or arbitration to enforce or interpret these Terms, the prevailing party shall be entitled to recover its reasonable attorneys' fees, costs, and necessary disbursements from the non-prevailing party.
Governing Law and Exclusive Venue (Split Jurisdiction):
- For Self-Serve Tiers (Lite, Pro, Elite, Research Lite, Research Pro): These Terms shall be governed strictly by the laws of India. Any dispute, claim, or controversy arising out of or relating to these Terms or the breach thereof shall be resolved exclusively by mandatory, binding arbitration seated in New Delhi, India, in accordance with the Indian Arbitration and Conciliation Act, 1996. You expressly waive any right to litigate in a foreign jurisdiction or participate in class actions.
- For Custom Enterprise Contracts: If the User has executed a custom, offline Enterprise Service Agreement, these Terms shall be governed by the laws of the jurisdiction where the User's company is formally registered and headquartered. Any dispute shall be resolved through binding arbitration in that specific geographic jurisdiction, pursuant to the rules of the internationally recognized arbitration body governing that region (e.g., AAA for the United States).
9. Anonymous Telemetry & Analytical Tracking Boundaries
ConsentCollect utilizes privacy-first web telemetry utilities (specifically Umami Cloud) to evaluate landing page conversion paths, calculate time milestones on free builders, and analyze marketing effectiveness. By using the Platform, you acknowledge and agree that: (a) this tracking is cookie-free, anonymized, and strictly limited to public-facing routes; (b) **under no circumstances does telemetry tracking execute or log actions within the secure authenticated workspaces (`/app` and `/admin` sub-paths)**; and (c) ConsentCollect is not liable for any platform layout deviations or loading failures caused by your local use of browser extensions or firewalls that block standard web script execution.