Terms of Service
The regulatory and contractual foundation governing clinical deployment, data architecture boundaries, and platform security.
1. Eligibility, Zero-Knowledge Key Custody, and Data Security Policies
Use of the self-serve tiers of the Platform (Lite, Pro, Elite, Research Lite, Research Pro) is fully authorized for Protected Health Information (PHI) when utilizing our standard Business Associate Agreement (BAA) executed electronically via clickwrap during onboarding.
Mandatory Account Security & Kinde MFA: To satisfy secure administrative access guidelines, every single user registration on the platform strictly requires Multi-Factor Authentication (MFA) with Time-based One-Time Password (TOTP) handled by Kinde by default. Users must access the platform exclusively through verified Single Sign-On (SSO) protocols featuring this mandatory MFA check. We strongly recommend downloading and securely storing your MFA recovery codes immediately upon registration. Your account, workspace sessions, and clinical data will be completely and permanently unrecoverable in any scenario if you lose your MFA credentials, fail to authenticate yourself, or lose your recovery codes. ConsentCollect cannot override Kinde authentication controls or recover access for you under any circumstances. Accounts lacking active MFA are subject to immediate administrative suspension without notice.
Zero-Knowledge Key Custody: Upon onboarding, the Platform generates a 256-bit AES Master Workspace Key entirely client-side via the Web Crypto API. This key is derived via PBKDF2 (100,000 iterations) from your local access code. ConsentCollect never receives, transmits, logs, or maintains access to this code or key in plaintext. The user retains sole, exclusive responsibility for preserving this access code. Loss of the access code results in the permanent, irreversible destruction of the ability to decrypt workspace data and associated logs. ConsentCollect cannot recover this data.
2. Tier Boundaries, Electronic BAA Policies, and Core System Limitations
ConsentCollect provides a standard Business Associate Agreement (BAA) for all self-serve pricing tiers (Lite, Pro, Elite, Research Lite, Research Pro), executed electronically via clickwrap during onboarding. Custom wet-signature or offline BAAs are strictly restricted to the Enterprise Tier.
Client-Side Zero-Knowledge Framework: The platform is designed to securely host Protected Health Information (PHI) on all tiers under the executed clickwrap BAA. To maintain the cryptographic integrity of the platform, clinicians must only ingest PHI within standard encrypted patient forms. Plaintext PHI is prohibited strictly within unencrypted structural metadata fields (such as clinician account names or layout template titles).
Programmatic Client-Side Defensive Infrastructure: To programmatically enforce E2EE boundaries and protect the integrity of the SaaS network infrastructure, the platform deploys autonomous client-side tools:
- Client-Side End-to-End Encryption (E2EE): Any data fields entered into the gateway are cryptographically sealed in the browser using AES-256-GCM prior to network transit. The platform's database (Convex) and object storage (Cloudflare R2) ingest and host only opaque ciphertext.
- Automated PHI Shielding: The platform utilizes a client-side NLP engine (
compromise.js) and custom regular expression matrices to intercept, tokenize, and mask potential identifiers (names, dates, locations) with deterministic placeholders before metadata optimization or subprocessor analysis occurs. - Manual Audit Pre-Clearance: Users must use the built-in manual review panels to ensure no raw plaintext PHI is embedded within structural form templates or layout designs.
3. The "Not Medical Advice" Shield
ConsentCollect is a software-as-a-service infrastructure provider. The Platform is designed to digitize and forensically verify the signature and comprehension workflow of informed consent.
4. Intellectual Property Rights
Platform Intellectual Property
ConsentCollect owns all rights, titles, and interests in the Platform software, source code, database schemas, dynamic layout logic, UI/UX systems, specialty blueprints, and automated compliance engines.
Client Consent Data Strings
The Covered Entity owns all patient consent records, signature data, custom clinical risk templates, and cryptographic consent strings created using the platform.
5. Platform Uptime, Maintenance & Disclaimers
ConsentCollect provides a target uptime of 99.9% for its cloud infrastructure. Maintenance windows are typically scheduled during off-peak hours (Eastern Time Saturday 02:00 to 06:00) and are announced 48 hours in advance.
Except for SLAs explicitly negotiated under custom Enterprise contracts, the service is provided on an "AS IS" and "AS AVAILABLE" basis. We disclaim all warranties of fitness for a particular clinical study or trial purpose.
6. Hyper-Strict Limitation of Liability and Multi-Layered Indemnification
Consequential Damages Waiver: TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT SHALL CONSENTCOLLECT, ITS DIRECTORS, OR ITS INFRASTRUCTURE SUBPROCESSORS (INCLUDING CONVEX INC., KINDE PTY LTD., CLOUDFLARE INC., RESEND INC., AND OPENAI) BE LIABLE FOR ANY INDIRECT, SPECIAL, INCIDENTAL, CONSEQUENTIAL, PUNITIVE, OR EXEMPLARY DAMAGES. THIS INCLUDES, BUT IS NOT LIMITED TO, LOSS OF REVENUE, DATA ERASURE CRON TIMEOUTS, DEFECTIVE AUDIT EVENT TRAILS, MEDICAL MALPRACTICE CLAIMS, OR REGULATORY FINES RESULTING FROM THE USER'S FAILURE TO VALIDATE THE CLINICAL LEGITIMACY OF FORM LAYOUTS.
Liability Cap: THE TOTAL AGGREGATE LIABILITY OF CONSENTCOLLECT FOR ANY CLAIM ARISING OUT OF OR RELATING TO THESE TERMS OR THE USE OF THE PLATFORM, WHETHER IN CONTRACT, TORT, OR OTHERWISE, SHALL BE STRICTLY LIMITED TO THE ACTUAL FEES PAID BY THE USER TO CONSENTCOLLECT IN THE THREE (3) MONTHS IMMEDIATELY PRECEDING THE INCIDENT GIVING RISE TO LIABILITY.
Strict Multi-Layered Indemnification: You agree to fully indemnify, defend, and hold harmless ConsentCollect, its officers, directors, employees, and cloud infrastructure vendors from and against any and all third-party claims, liabilities, regulatory enforcement actions, losses, costs, or expenses (including reasonable attorneys' fees and Office for Civil Rights (OCR) penalties) arising out of or resulting from:
- (a) Your upload, storage, or transmission of Protected Health Information (PHI) without executing the standard online clickwrap BAA or a custom offline BAA;
- (b) Any clinical or operational disputes regarding patient comprehension, informed consent validity, or eIDAS/Part 11 compliance;
- (c) Any unauthorized data exposure or system lockouts resulting from the loss, compromise, or theft of local clinician workspace access codes or derived keys;
- (d) DPDP Act Penalty Indemnification: For accounts subject to Indian jurisdiction, the user (Data Fiduciary) acknowledges that they hold exclusive custody of the client-side decryption keys. If a data breach or unauthorized data exposure occurs due to the loss, theft, or compromise of the user's local access codes or multi-factor authentication tokens, the user assumes 100% liability for any statutory penalties, compliance violations, or fines levied by the Data Protection Board of India (DPBI) under the DPDP Act, 2023. The user agrees to fully indemnify and hold harmless ConsentCollect from any such enforcement actions.
7. Termination & Consent Archive Preservation
Upon account closure or contract termination, the platform initiates a strict decommission phase:
- 30-Day Export Window: The Covered Entity has thirty (30) days from the date of termination to export all patient consent logs, signature records, and HMAC chains in standard CSV/JSON format.
- Terminal Erasure Job: Following the expiration of the 30-day export window, an automated terminal erasure mutation (
executeTerminalErasure) is executed. The system permanently purges all encrypted database documents, executes cryptographic erasure of related datasets, and systematically purges all associated objects, signatures, and identity proof artifacts from Cloudflare R2 object storage. - Audit Trail Retention: Standard HMAC audit chain events (action types, timestamps, hashed identifiers) are preserved for up to six (6) years to satisfy regulatory record retention standards (45 CFR § 164.530(j)), after which they are systematically deleted.
8. Governing Law & Binding Arbitration
These Terms shall be governed by, and construed in accordance with, the laws of the State of Delaware, without regard to conflict of law principles. Any dispute arising out of or relating to these Terms or the Platform shall be resolved exclusively through mandatory, binding arbitration administered by the American Arbitration Association (AAA) under its Commercial Arbitration Rules. You waive any right to participate in class actions or jury trials.