# MASTER SERVICES AGREEMENT

**CUSTOMER AGREEMENT TEMPLATE - COMPLETE ALL BRACKETED FIELDS BEFORE SIGNATURE**

This Master Services Agreement (“MSA”) is entered into as of **[[MSA EFFECTIVE DATE]]** by and between **RSBB Group LLC**, an Ohio limited liability company doing business as **MyJourney** (“Provider”), and **[[CUSTOMER LEGAL NAME]]** (“Customer”).

Provider and Customer may each be referred to as a “Party” and together as the “Parties.”

---

## 1. Agreement Structure & Order of Precedence

This MSA governs Customer’s purchase and use of the MyJourney multi-tenant health engagement SaaS platform and related services (“Services”).

The complete agreement between the Parties consists of:
1. This MSA;
2. Each mutually executed Order Form;
3. The Business Associate Agreement (“BAA”), when applicable;
4. Any mutually executed addendum or Statement of Work (SOW); and
5. Documents expressly incorporated by reference.

If documents conflict, the following order of precedence applies unless an Order Form expressly states otherwise:
1. **Business Associate Agreement (BAA)**, solely with respect to Protected Health Information (PHI) and HIPAA matters;
2. **Order Form**;
3. **This MSA**;
4. **Incorporated Policies or Technical Documentation**.

---

## 2. Services & Scope

Provider will make the Services identified in each Order Form available to Customer during the applicable Subscription Term.

MyJourney includes SaaS functionality for multi-tenant organization administration, patient/client health engagement, GLP-1 weight analytics, progress photo storage, body composition tracking, medication logging, symptom logger check-ins, automated messaging, and related clinical workflow features.

Production features and service tiers are determined by the applicable Order Form and then-current technical documentation.

---

## 3. Customer Accounts and Authorized Users

Customer controls which individuals (attending physicians, clinicians, med spa staff, patients) are authorized to access its tenant environment (“Authorized Users”), subject to Provider’s platform access controls and role-based access control (RBAC) hierarchy.

Customer is responsible for:
- Determining appropriate user roles (e.g., Patient, Clinician, Med Spa Admin) and permission grants;
- Maintaining accurate organization membership and account data;
- Promptly disabling access for workforce members whose authorization is revoked or terminated;
- Ensuring Authorized Users comply with this Agreement and end-user Terms of Use; and
- Maintaining appropriate internal administrative, physical, and technical safeguards for its workforce devices and access credentials.

Provider may suspend access when reasonably necessary to prevent material security harm, protect PHI, or respond to unauthorized access threats.

---

## 4. Customer Data & De-Identified Analytics

### Customer Data Ownership & License
“Customer Data” means information submitted to, stored in, transmitted through, or otherwise processed by the Services on behalf of Customer, excluding Provider technology and de-identified aggregated analytics. As between the Parties, Customer retains all right, title, and interest in Customer Data.

Customer grants Provider a limited, non-exclusive right to host, process, transmit, back up, and display Customer Data solely to provide, secure, maintain, and support the Services; comply with applicable law; and enforce this Agreement.

### De-Identified Data and Aggregated Analytics Rights
Provider may create and use aggregated or de-identified information derived from Customer Data only as permitted by applicable law, the BAA when applicable, the applicable Order Form, and Customer’s written instructions.

For PHI, de-identification shall use a method recognized under HIPAA, such as Safe Harbor or Expert Determination, as applicable, and Provider shall document the method used. Provider may use aggregated or de-identified information for internal service operation, security, quality, performance, product improvement, and Customer reporting.

Provider will not externally publish, license, sell, commercialize, or disclose PHI-derived de-identified data to third parties, or use such data for external AI model training or evaluation, unless expressly authorized in writing by Customer and permitted by applicable law.

---

## 5. Protected Health Information (PHI) & HIPAA BAA

If Provider creates, receives, maintains, or transmits PHI on Customer’s behalf and HIPAA applies to the relationship, the Parties shall execute Provider’s **Business Associate Agreement (BAA)**.

Provider will not sell Customer PHI, nor will Provider use Customer PHI for third-party advertising or independent commercial profiling.

---

## 6. Security & Technical Safeguards

Provider will maintain administrative, physical, and technical safeguards designed to protect the security, confidentiality, and integrity of Customer Data and PHI, including controls for:
- Encryption of data in transit and at rest, as appropriate;
- Multi-tenant access control and tenant isolation;
- Security and audit logging;
- Secrets and key management;
- Backup, monitoring, vulnerability management, and incident response.

Customer acknowledges that security is a shared responsibility and shall maintain appropriate security controls for its workforce devices, networks, passwords, and multi-factor authentication (MFA/TOTP) keys.

---

## 7. Privacy & Regulatory Compliance

Each Party is responsible for its own compliance with applicable laws.

Customer is responsible for:
- Ensuring its collection, transmission, and use of Customer Data through the Services complies with all privacy and health-privacy laws;
- Providing required privacy notices (including HIPAA Notice of Privacy Practices) to patients and end users;
- Obtaining any required patient consents, authorizations, or disclosures;
- Responding to patient medical-record requests, access requests, or HIPAA individual-rights requests.

Provider is responsible for technical and administrative compliance applicable to Provider as a SaaS provider and Business Associate.

---

## 8. Restrictions

Customer shall not, and shall not permit any third party to:
- Reverse engineer, decompile, or disassemble the Services except as permitted by non-waivable applicable law;
- Bypass, disable, or circumvent authentication, tenant isolation controls, rate limits, or platform access controls;
- Probe, scan, or conduct unauthorized penetration testing or vulnerability assessments against Provider infrastructure;
- Introduce malware, viruses, or destructive code into the platform;
- Use automated scraping, bots, or unauthorized extraction mechanisms;
- Resell, sublicense, or rent access to the Services except as expressly authorized in an Order Form; or
- Use the Services in violation of applicable law.

---

## 9. Fees and Payment

Customer (the Organization / Med Spa) shall pay Provider the software subscription fees set forth in each Order Form.

### Organization-Paid Billing Structure & Active-Client Pricing
MyJourney is billed directly to Customer as an Organization-paid B2B SaaS subscription. Unless an Order Form specifies a custom pricing tier, subscription fees are calculated as follows:
- **Base Monthly Fee**: **$250.00 / month**, which includes access for up to **10 active clients/patients** per billing cycle;
- **Additional Active Client Expansion Rate**: **$25.00 / month** for each additional active client beyond the 10 included base clients;
- **High-Water Mark Calculation**: Active client volume is measured during each billing period using Provider’s high-water mark active-client calculation methodology (any patient account active, provisioned, or engaging with the platform during the billing cycle).

### Customer Resale Rights & Patient Billing Autonomy
Customer maintains sole and exclusive discretion over whether, how, and at what rate Customer charges its end-user patients/clients for access to Customer’s health programs, clinical services, or MyJourney platform access. Provider has no direct billing relationship with end-user patients/clients and does not collect platform subscription fees directly from Customer's end users.

### Setup & Onboarding Fees
If specified in an Order Form, Customer shall pay a one-time Setup and Onboarding Fee covering initial tenant environment provisioning, staff technical onboarding, domain setup, and workflow configuration. Setup fees are due upon Order Form execution (or as invoiced) and are non-refundable once setup services commence.

### Payment Terms
Unless an Order Form states otherwise:
- Invoices are due within **30 days** of invoice date (or processed automatically via ACH / credit card);
- Fees are non-refundable except as explicitly provided in this Agreement;
- Customer is responsible for applicable sales, use, and transaction taxes (excluding taxes based on Provider’s net income);
- Provider may suspend Services for undisputed past-due balances after 10 days' written notice and opportunity to cure.

---

## 10. Subscription Term and Renewal

The initial Subscription Term is specified in each Order Form.

Unless otherwise stated in an Order Form, subscriptions automatically renew for successive 12-month terms unless either Party provides written notice of non-renewal at least **30 days** prior to the expiration of the then-current term.

---

## 11. Support, SLA, Maintenance & Audit Assistance

### Support & Platform Maintenance
Provider will provide technical support as set forth in the applicable Order Form or standard Support SLA. Provider performs routine maintenance, patches, security updates, and feature upgrades. Service availability commitments, if any, are set forth in the applicable Order Form or Support SLA.

### Compliance Audit & Security Questionnaire Assistance
Provider will make available standard platform compliance documentation, HIPAA posture summaries, and standard audit log exports or summaries at no additional charge.

If Customer requests custom compliance audit assistance, manual forensic log compilation, specialized security questionnaire completions, or direct participation in Customer third-party or regulatory audits beyond standard platform documentation, Provider will support Customer in good faith. Provider reserves the right to bill Customer for custom audit assistance and specialized technical support at Provider’s standard professional services hourly rate (or as mutually agreed in an Order Form / SOW).

---

## 12. Intellectual Property Rights

Provider and its licensors retain all right, title, and interest (including all patent, copyright, trademark, trade secret, and intellectual property rights) in and to:
- The MyJourney platform, source code, and backend services;
- Application Programming Interfaces (APIs), schema designs, and database structures;
- Mobile applications (iOS/Android Flutter clients) and web user interfaces;
- System documentation, branding, and derivative works;
- Aggregated or de-identified analytical datasets derived under Section 4, to the extent permitted by that section.

No intellectual property ownership is transferred to Customer under this Agreement.

---

## 13. Feedback

Customer or its Authorized Users may provide suggestions or feedback regarding the Services. Provider may freely use, implement, and commercialize such feedback without restriction or financial obligation to Customer, provided no Customer PHI or Customer Confidential Information is disclosed.

---

## 14. Confidentiality

“Confidential Information” means non-public business, technical, financial, product roadmap, or pricing information disclosed by one Party (“Discloser”) to the other (“Recipient”) that reasonably should be understood to be confidential.

Recipient shall:
- Protect Discloser’s Confidential Information using at least a reasonable standard of care;
- Use Confidential Information solely to exercise rights or perform obligations under this Agreement;
- Disclose Confidential Information only to employees, contractors, and legal/financial advisers with a need to know and subject to confidentiality obligations.

Confidential Information excludes information that: (a) is or becomes publicly known through no breach by Recipient; (b) was known to Recipient prior to disclosure; (c) is independently developed without reference to Discloser’s Confidential Information; or (d) is lawfully received from a third party without restriction.

Handling of Protected Health Information (PHI) is additionally governed by the BAA.

---

## 15. Compelled Legal Disclosure

If Recipient is legally required by subpoena, court order, or law to disclose Discloser’s Confidential Information, Recipient will provide prompt written notice to Discloser (where legally permissible) to enable Discloser to seek a protective order or limit disclosure.

---

## 16. Warranties & Disclaimers

### Mutual Warranties
Each Party warrants that it has full corporate power and legal authority to enter into and perform under this Agreement.

### Provider Performance Warranty
Provider warrants that the Services will function materially in accordance with published product documentation and will be performed in a professional manner consistent with industry standards.

### Disclaimer
EXCEPT AS EXPRESSLY PROVIDED HEREIN, THE SERVICES ARE PROVIDED “AS IS” AND “AS AVAILABLE.” PROVIDER DISCLAIMS ALL OTHER WARRANTIES, EXPRESS, IMPLIED, OR STATUTORY, INCLUDING IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT.

---

## 17. No Medical Services

Provider is a SaaS software provider and does not practice medicine or deliver healthcare services. Customer and its clinical staff are solely responsible for medical treatment, clinical advice, diagnostic decisions, prescriptions, and all patient care.

---

## 18. Indemnification

### 18.1 Customer Indemnity
Customer shall defend, indemnify, and hold harmless Provider from third-party claims, damages, or liabilities arising from: (a) Customer’s unlawful use of the Services; (b) Customer’s medical, clinical, or health care services; (c) Customer’s violation of applicable law or patient rights; or (d) Customer Data uploaded without lawful authority.

### 18.2 Provider IP Indemnity
Provider shall defend and indemnify Customer from third-party claims alleging that Customer’s authorized use of the unmodified MyJourney platform infringes any valid United States patent, copyright, or trademark. Provider’s obligations under this section do not apply to claims resulting from Customer Data, unauthorized modifications, or combinations with third-party software.

---

## 19. Limitation of Liability

EXCEPT FOR EXCLUDED CLAIMS, TO THE MAXIMUM EXTENT PERMITTED BY LAW:
1. **INDIRECT DAMAGES**: NEITHER PARTY SHALL BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, PUNITIVE, OR COVER DAMAGES, OR FOR LOSS OF PROFITS, REVENUE, OR DATA.
2. **AGGREGATE LIABILITY CAP**: EACH PARTY’S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO THIS AGREEMENT SHALL NOT EXCEED THE TOTAL FEES PAID OR PAYABLE BY CUSTOMER TO PROVIDER IN THE **TWELVE (12) MONTHS** PRECEDING THE EVENT GIVING RISE TO LIABILITY.

“Excluded Claims” means: (a) Customer’s payment obligations; (b) breach of Section 8 (Restrictions); (c) indemnification obligations under Section 18; or (d) gross negligence, fraud, or willful misconduct.

---

## 20. Insurance

Provider will maintain commercial insurance coverage appropriate to its operations, including Commercial General Liability, Technology Errors & Omissions, and Cyber / Privacy Liability coverage. Certificates of insurance available upon request.

---

## 21. Term & Termination

Either Party may terminate this MSA or any Order Form:
1. For cause upon **30 days' written notice** of a material breach, if such breach remains uncured at the end of the notice period; or
2. Immediately if the other Party becomes insolvent, enters receivership, or makes an assignment for the benefit of creditors.

Provider may temporarily suspend access immediately if necessary to prevent ongoing security harm, active cyberattacks, or severe legal exposure.

---

## 22. Effect of Termination & Data Export

Upon expiration or termination:
- Customer’s license and access rights end;
- Accrued, undisputed payment obligations remain payable;
- **Data Export Period**: Provider will make Customer Data available for export via standard platform export features for **30 days** post-termination;
- Following the export period, Provider will securely purge or delete Customer Data in accordance with its retention policies, BAA requirements, and applicable law.

---

## 23. Governing Law & Dispute Resolution

This Agreement is governed by the laws of the State of Ohio, United States, without regard to conflict-of-law rules. Any legal dispute arising under this Agreement shall be brought exclusively in the state or federal courts located in Franklin County or Fairfield County, Ohio, and each Party consents to personal jurisdiction therein.

---

## 24. General Provisions

- **Entire Agreement**: This Agreement (with Order Forms and BAA) constitutes the entire agreement between the Parties and supersedes all prior communications.
- **Amendments**: Amendments must be in writing and executed by authorized representatives of both Parties.
- **Assignment**: Neither Party may assign this Agreement without prior written consent, except in connection with a merger, acquisition, or sale of substantially all assets.
- **Severability**: If any provision is held unenforceable, remaining provisions stay in full force.
- **Force Majeure**: Neither Party is liable for delays caused by acts of God, war, cyber warfare, power outages, or events beyond reasonable control (excluding payment obligations).

---

# SIGNATURES

## PROVIDER

**RSBB Group LLC d/b/a MyJourney**

By: ______________________________________

Name: Ronald S. Baer

Title: Sole Member / Authorized Representative

Date: _____________________________________

## CUSTOMER

**[[CUSTOMER LEGAL NAME]]**

By: ______________________________________

Name: ____________________________________

Title: _____________________________________

Date: _____________________________________

---

# MUTUAL ORDER FORM TEMPLATE

**Order Form Number:** [[ORDER-FORM-001]]  
**Customer Legal Name:** [[CUSTOMER LEGAL NAME]]  
**Effective Date:** [[START DATE]]  
**Initial Subscription Term:** [[12 MONTHS / 24 MONTHS / OTHER]]  
**Subscription Model:** Organization-Paid (B2B) Active-Client SaaS Subscription  

| Product / Module Description | Measurement Unit | Monthly Rate | Billing Frequency |
|---|---|---|---|
| MyJourney Base Platform Access (Includes 10 Active Clients) | Base Organization License | $250.00 / mo | Monthly / Annual |
| Additional Active Client License Expansion Tier | Per Additional Active Client (High-Water Mark) | $25.00 / client / mo | Monthly |
| Dedicated Onboarding & Technical Setup | One-time Setup | $[[SETUP-FEE]] | One-Time |

**Billing & Payment Terms:** Net 30 days via Automated Invoice / ACH / Credit Card  
**Patient Billing Rights:** Customer retains sole discretion to bundle, re-sell, or charge end-user patients for program access. MyJourney does not bill end-user patients directly.  
**Auto-Renewal:** Renewed for successive 12-month terms unless written non-renewal notice is provided 30 days prior.

This Order Form is governed by the Master Services Agreement between RSBB Group LLC d/b/a MyJourney and Customer.
