Surgical Safety Technologies is now Aimbient.Read more

Legal

Master Subscription Services Agreement

EU, Canada

Table of Contents

Title

The entity defined on the Order Form or Statement of Work, as applicable, (“Client”) desires to purchase products and services from SST Surgical Safety Technologies Canada ULC (“SST”), as defined in the Order Form and Statement of Work submitted by Client to SST. If SST accepts such Order Form and Statement of Work, the Parties will have entered into a binding contract on terms and conditions set forth in this Master Subscription Services Agreement, including all Exhibits hereto (“Agreement”), which shall govern the Parties’ rights and obligations with regard to the applicable transaction.   SST and Client are sometimes referred to individually a “Party” and collectively “Parties”.

IN CONSIDERATION of the mutual covenants and agreements set out below, and for other good and valuable consideration, the receipt and sufficiency of which the Parties acknowledge, the Parties agrees as follows:

General Terms and Conditions
  1. Definitions.

1.1.1.     Analytics Software” means SST’s proprietary software solution and related processes for analysis of Client Data and De-Identified Data, including processing Client Data, providing analysis and generating Insights.

1.1.2.     “Anonymized Data” means De-Identified Data that has been anonymized by removing markers identifying the source of the data.

1.1.3.     “Client Data” means any data, information or materials generated by Client that are uploaded, accessed, captured, or collected by the SST System, including, without limitation, patient data, healthcare practitioner or other provider data, event data, video data, voice data, machine-operation data, imaging data, health or surgery device or system data, simulation data, metadata, and sensor data, and all intellectual property rights therein, and includes, without limitation, any of the foregoing that is Personal Data.

1.1.4.     “Client Practices” means the internal business practices, workflows, techniques, methods or processes of Client.

1.1.5.     “Client Provided Systems” means the information systems resources (e.g. network switches, servers, etc.), mechanisms of connectivity, or other infrastructure  owned, controlled, or operated by Client, that Client is required to supply in order to implement, access, and use the SST System, as set forth in the Documentation

1.1.6.     “Client User” means those individuals who are authorized, subject to the terms and conditions of this Agreement, to access and use the SST System.

1.1.7.     De-Identified Data” means Client Data that has been de-identified  in accordance with 45 CFR 164.514(b).

1.1.8.     “Documentation” means the administrative guide, specifications, and / or other policies and documents provided by SST to Client to facilitate use of the SST System, Third-Party Software, and / or Equipment, as applicable, as the same may be updated or amended by SST from time to time.

1.1.9.     “Equipment” means the hardware described in an Order Form.

1.1.10.   “Initial Subscription Term” means the period of time beginning on the Order Form Effective Date (as defined in the applicable Order Form) and continuing for the duration of the term specified in the applicable Order Form.

1.1.11.   Insights” means insights, learnings, extracted features, and analytics, and libraries or reports based on these, generated by the SST System, or otherwise by or for SST by processing Client Data, De-Identified Data or Anonymized Data, including by application of analytics, aggregation, data enrichment, data discovery, artificial intelligence or machine learning to Client Data, De-Identified Data or Anonymized Data. Insights include, but are not limited to, key (clinical) performance indicators, health outcome metrics, and procedure reports. Insights exist in a de-identified state, where the information does not identify an individual and there is no reasonable basis to believe that the information can be used to identify an individual.

1.1.12.   “Named Facility” means each healthcare facility listed on the applicable Order Form that is wholly owned or controlled by Client. For purpose of this definition, “control” means (i) the power by contract to operate or manage the day-to-day operations of a health care facility, or (ii) the power to elect a majority of the directors of a corporation or similar officers of an entity.

1.1.13.   “Order Form” means an order for the SST System, Third Party Software, and/or Equipment signed by SST and Client.

1.1.14.   “Personal Data” means any information relating to an identified or identifiable natural person that, if improperly used or disclosed, would trigger an obligation under applicable Privacy Laws.

1.1.15.   “Privacy Laws” means applicable laws relating to the access, use and disclosure of Personal Data.

1.1.16.   “Data Privacy Agreement(s)” means a Business Associate Agreement, Privacy Agreement, Data Protection Agreement, or other agreement required by law to be entered into by and between Client and SST governing the use and processing of Personal Data, as applicable.

1.1.17.   “Professional Services” means any implementation, project management, training, and/or consulting services, directly related to the SST System, provided by SST pursuant to a Statement of Work, as specified in such Statement of Work.

1.1.18.   “Room” means a clinical environment at a Named Facility where Client is licensed to access and use the SST System (e.g. operating room, trauma bay, or simulation center), as set forth in the applicable Order Form.

1.1.19.   “Services” means the SST System, Professional Services, and Support Services.

1.1.20.   “SST System” means SST’s proprietary software-as-a-service platform, inclusive of the Analytics Software and Insights.   

1.1.21.   “Statement of Work” or “SOW” means the document, signed by SST and Client, setting forth the Professional Services purchased by Client. 

1.1.22.   “Subscription Term” means, collectively, the Initial Subscription Term and any Renewal Terms, as applicable.

1.1.23.   “Third Party Software” means any third-party proprietary software specified in an Order Form.  

1.1.24.   “Work Product” means materials, deliverables, work product, or the like, produced in connection with any Professional Services provided hereunder. Work Product does not include Client Data or Client Practices.

  1. Scope of Agreement.

Client agrees to purchase from SST, and SST agrees, subject to the terms and conditions of this Agreement, to supply to Client the Services, Equipment, and/or Third Party Software, if any, as specified in each Order Form and Statement of Work, as applicable. Except as otherwise set forth herein, this Agreement does not grant any rights to Client affiliates. Each Order Form is subject to, and made part of, this Agreement.

  1. Grant of Rights.

3.1   License Grant.  Subject to the terms and conditions of the Agreement, including, without limitation, Section 3.2 below, SST hereby grants Client, during the Subscription Term set forth in the applicable Order Form, a limited, revocable, non-exclusive, non-assignable and non-transferrable right of access and license to use the SST System for the Permitted Use. The “Permitted Use” means access to and use of the applicable SST System by Client Users in the number of Rooms at the Named Facilities listed in the applicable Order Form (i) in a manner commensurate with the intended use of the SST System (as set forth in the Agreement and the Documentation), and (ii) solely in connection with Client’s internal business purposes.

3.2   Proprietary Rights; Restrictions. SST retains all ownership right, title, and interest in and to the Services and any Work Product provided hereunder, including, but not limited to all patent, copyright, trade secret, trademark and other intellectual property rights associated therewith, and any derivative works thereof. Without limiting the generality of the foregoing, Client represents and warrants that Client will not itself, directly or indirectly, and will not permit Client Users, other employees or contractors, or any third party to (i) access the SST System or Documentation other than as permitted by this Agreement, (ii) sublicense, share, assign, transfer, copy, sell, distribute, market or otherwise dispose of the SST System or Documentation, (iii) modify, port, reverse engineer, decompile, disassemble, translate, copy, record or otherwise reproduce or create derivative works of the SST System or Documentation, (iv) remove any proprietary notices, labels, or marks from the SST System or Documentation, (v) release to any third-party the results of any benchmark testing of the SST System, (vi) provide access to the SST System or Documentation to any competitor of SST, or (vii) access the SST System or Documentation in order to (a) build a competitive product or service, (b) build a product using similar ideas, features, functions or graphics of the SST System, or (c) copy any ideas, features, functions or graphics of the SST System. In no event shall anything in this Agreement or in SST’s provision of any Services convey any license under any patent, copyright, trademark, trade name, trade secret, or other intellectual property right not explicitly licensed. All rights not expressly granted to Client under this Agreement are reserved by SST. Client will not introduce any unauthorized computer program, functionality, routine, data, resources or capabilities to the SST System, or any portion thereof, and, without limiting the generality of the foregoing, Client will specifically not permit and shall prevent the entry of any computer virus program, Trojan horse program, worm program or other unauthorized computer program into the SST System, or any part thereof or into the data, databases, computer programs, computer resources or computer systems or any other technology or resource provided by SST. SST reserves the right to suspend Client and any Client User’s access to the SST System if SST believes such access may pose a reasonable threat to the security, availability, or integrity of the SST System.  

3.3   Third Party Software. Third Party Software supplied by SST is subject to the terms and conditions of this Agreement and the applicable third-party terms, including as may be set forth in an end user license agreement (“Third Party Terms”). In the event of any conflict between the terms in this Agreement and the Third-Party Terms, as they pertain to any such Third Party Software, the Third Party Terms shall govern.

3.4   Client Users. Client is responsible for, and shall ensure, each Client User’s compliance with the terms of this Agreement. Any violation of this Agreement by any Client User is a violation of this Agreement by Client. Client shall ensure that (i) only Client Users who need access to the SST System to exercise Client’s rights or perform its obligations under this Agreement access the SST System, and (ii) Client Users do not share logon credentials or attempt to access the SST System without providing valid logon credentials specific to such individual. Without limiting the foregoing, once a Client User is no longer engaged by Client or is no longer assigned to activities of the Client that require use of the SST System, Client shall immediately revoke such access to the SST System. Client shall maintain reasonable and appropriate technical, physical, and administrative safeguards with respect to Client’s access to the SST System, including, without limitation, maintaining the confidentiality and security of all logon credentials.  Client shall be responsible for all access to the SST System provided by Client, directly or indirectly, and Client will promptly notify SST of any actual or suspected unauthorized access or use of the SST System provided hereunder. Client will take whatever steps are reasonably required to halt and otherwise remedy any such breach of security and will be solely responsible for any resulting loss of or unauthorized access to any Personal Data or such other information improperly disclosed or misused, and will prevent, as necessary, further disclosures or misuses.  

3.5   Updates. During the Subscription Term, SST shall provide to Client all Updates.  “Updates” means software that is an upgrade, bug fix, patch or other release for the SST System, which SST makes generally available free of incremental charge to clients purchasing a subscription for the applicable SST System. Updates shall be deemed part of the SST System.

3.6   Support Services. During the Subscription Term, SST will provide support for the SST System, Third-Party Software, and Equipment in accordance with SST’s then-current support policy:   https://www.surgicalsafety.com/support-policy (“Support Services”), which may be updated from time-to-time in SST’s sole discretion (“Support Policy”).

3.7   Client Provided Systems. Client is responsible for providing and maintaining applicable Client Provided Systems. Client Provided Systems must meet or exceed the specifications set out in the Documentation. Client acknowledges that the functionality of the SST System is dependent upon proper and functioning Client Provided Systems, and SST shall have no responsibility or liability as it relates to any Client Provided Systems or for any failure or deficiency of the SST System as a result of the Client Provided Systems.

  1. Professional Services.

4.1   Statements of Work. From time to time, SST may provide Professional Services to Client, which shall be set forth in a Statement of Work. Each Statement of Work is subject to, and made part of, this Agreement. 

4.2  On Location. If SST and Client agree that SST will perform Professional Services at a Named Facility, Client shall provide or arrange for the necessary equipment, information, and facilities required by SST to perform such Professional Services, as reasonably specified by SST.

4.3  Work Product. Subject to Client’s payment in full of applicable Professional Services fees, SST grants to Client a non-exclusive, non-transferable, non-sublicensable, revokable, limited license for Client to use the Work Product during the Term in connection with its use of the SST System as permitted hereunder. 

5.     Payment.

5.1  Fees. SST will invoice Client for, and Client shall pay to SST, all fees and other charges specified in each Order Form and/or Statement of Work.  All invoices are due and payable within thirty (30) days of the date of the invoice, in the manner and at the location set forth in the applicable invoice. Client agrees to pay interest on all past due amounts at the lower of one point five percent (1.5%) per month or the highest rate allowed by applicable law. Client will be responsible for paying any applicable duties, sales, use, transaction, excise or similar taxes and any federal, state or local fees or charges, imposed on, in respect of or otherwise associated with any Services. In addition, if payments are not received when due as described above, SST reserves the right to suspend the Services and may remove any Equipment from the Named Facilities at any time, unless and until such undisputed payment(s) are received in full, and Client agrees to hold SST harmless for such. Client must notify SST within thirty (30) days of the date of invoice if it disputes any amount contained in an invoice and shall work with SST in good faith to resolve any such disputes.  Client shall reimburse SST for all reasonable costs incurred (including reasonable attorneys’ fees) in collection past due amounts from Client.

5.2  Expenses.  Client shall be responsible for any additional out of pocket costs and expenses incurred by SST in connection with the performance of the Services under this Agreement. Such costs and expenses shall be invoiced to Client without markup and shall be payable in accordance with the terms of Section 5.1.  Any such additional costs and expenses will be supported by receipts and documentations upon Client’s reasonable request.

5.3  Purchase Orders. Client agrees to pay SST’s invoices without a purchase order reference. Without limiting the foregoing, if and only to the extent that Client provides SST with a purchase order contemporaneous with execution of an Order Form or Statement of Work, SST will use commercially reasonable efforts to include such purchase order reference in the applicable invoice. Client acknowledges and agrees that, notwithstanding anything to the contrary, Client’s failure to provide such information or SST’s failure to include a purchase order reference in any invoice, in accordance with the preceding sentence, shall not relieve Client of its obligation to pay an invoice in accordance with the terms of Section 5.1 above. Client shall appoint an individual designated by Client to serve as Client's contact with respect to all invoice and payment related matters, including purchase orders. Client shall identify this individual and provide their contact information to SST, in writing, on or before the Effective Date. Neither SST, nor this Agreement, shall be subject to provisions of any pre-printed terms on or attached to purchase orders (including, without limitation, hyperlinks to additional terms included in purchase orders) generated by Client, or any Client policies, regulations, rules, etc., including those set forth in any Client-sponsored registration system, regardless if the same requires affirmative acknowledgment from an SST representative.

5.4  Commitment. The terms and conditions of this Agreement including, without limitation, pricing terms contained in the applicable Order Form and Statement of Work, contemplate implementation of the SST System (including operationalization of applicable interfaces and installation of applicable Equipment at the Named Locations) within ninety (90) days of the applicable Order Form Effective Date (as defined in such Order Form). If the SST System is not implemented within such period, the ninety (90) day anniversary of the Order Form Effective Date shall be deemed the Go-Live Date, as that term is defined in the applicable Order Form and/or Statement of Work.

  1. Compliance with Law.

6.1 Applicable Laws; Data Privacy Agreements. Each Party will comply with all applicable laws and regulations that apply to its respective activities under this Agreement, including all applicable laws (including Privacy Laws), statutes, ordinance, codes, rules, ethical standards and other pronouncements that have the effect of law of any applicable government authority (“Applicable Laws”). 

To the extent any Client Data includes Personal Data, as defined by, and to the extent subject to, the General Data Protection Regulation (GDPR) the Data Protection Addendum set forth as Exhibit A shall apply.  

  1. Data.

7.1 Data Ownership. As between SST and Client, Client shall retain all right, title and interest in and to the Client Data and De-Identified Data; provided, however, that Client’s retention of ownership in the Client Data and De-Identified Data shall not constitute any ownership interest in the Services or Work Product. As a part of the Services, SST may  convert Client Data to De-Identified Data.  Client hereby grants to SST a worldwide, perpetual, irrevocable, royalty-free license to use the Client Data and De-Identified Data (i) to perform the Services, (ii) to develop, train, tune, enhance, and improve its software and services, and (iii) to develop, generate, or otherwise create Insights. As between Client and SST, SST will be the owner of and retain all right, title, and interest in Anonymized Data and Insights, and further shall own all intellectual property rights in all enhancements and improvements to the Services that result from use of the Client Data,  De-Identified Data, Anonymized Data and/or Insights or are otherwise developed in the course of SST’s performance of the Services. Notwithstanding the foregoing, other than for the sole use by Client, SST will not publish any Insights that identify Client, unless SST has obtained express written consent from Client.

7.3  Consents. Client is solely responsible for obtaining all necessary consents under Applicable Laws and regulations in order to allow Client to collect and provide Client Data and De-identified Data to SST hereunder, and for SST’s use of the Client Data and De-Identified Data in accordance with this Section 7.

  1. Feedback.

Client or Client Users may, from time to time, but are not obligated to, provide input, comments, suggestions, feedback or learnings regarding the Services (“Feedback”), which may include suggestions for, or feedback concerning, improvements, modifications, corrections, enhancements, derivatives or extensions, functionality, user interface, as well as branding, business or marketing ideas related to SST and/or its Services. SST acknowledges and agrees that the Feedback is provided by Client as-is, without warranties of any kind. “Feedback” does not, and shall not, include Client Practices, Client Confidential Information, or Client Data.   Client acknowledges that Feedback shall be considered SST Confidential Information and shall be protected from disclosure in accordance with the terms of this Agreement. Client hereby grants to SST a non-exclusive, perpetual, irrevocable, worldwide, royalty-free license, with the rights to sublicense through multiple tiers, to use, publish, and disclose such Feedback in any manner SST chooses and to display, perform, copy, make, have made, use, sell, and otherwise dispose of SST's products or services embodying Feedback in any manner and via any media SST chooses, without reference to the source. SST shall be entitled to use Feedback for any purpose without restriction or remuneration of any kind with respect to Client or Client Users, including but not limited to the commercialization and development of improvements and enhancements to the Services based on the Feedback, and SST will own all such improvements and any intellectual property rights therein. Client acknowledges that Feedback is only intended as possible strategies, developments, and functionalities of the Services and is not intended to be binding upon SST to any particular course of business, product strategy, and/or development. Client covenants and agrees to sign such further documents as may be reasonably required to confirm such license to SST in accordance with this Section 8.

  1. Equipment.

9.1  Equipment.  SST will deliver to Client Equipment for Client’s use during the Subscription Term, as set out in the applicable Order Form. Client will own all such Equipment, and SST will pass through to Client all warranties given by third-party Equipment manufacturers (if any) to the extent permitted by the terms and conditions of such warranties. The Equipment is subject to the terms and conditions of this Agreement and applicable manufacturer terms. At all times, Client shall use the Equipment in a careful and proper manner, in accordance with its Documentation. Client shall implement controls to ensure protection and security of the Equipment and to prevent theft or damage to the Equipment.  Client shall not undertake any repairs or modifications to the Equipment unless so directed by SST.  Client shall not (a) use, operate, maintain or store any Equipment improperly, carelessly, unsafely or in violation of any applicable law or regulation or for any purpose other than as set forth in this Agreement and the Documentation; (b) abandon any Equipment; (c) sublease, transfer, or assign any Equipment without the prior written consent of SST; or (d) create or allow to exist any lien, claim, security interest or encumbrance on any of its rights hereunder.  Client shall not alter any Equipment or affix any accessory or equipment to it if doing so will impair its originally intended function or use. Any alteration or addition to any Equipment shall be the responsibility of and at the sole risk of Client. Notwithstanding anything to the contrary, SST shall not be liable for any damage to property or personal injury (including death) to the extent caused by Equipment installed at a Named Facility.

9.2  Maintenance. Client shall promptly notify SST of any defective or malfunctioning Equipment. SST will provide remote Equipment fault troubleshooting and will be responsible for the return of any defective Equipment to the applicable manufacturer. Client shall be solely responsible (i) for any labor related to Equipment replacement and (ii) for the upgrade and/or replacement costs of any Equipment or part(s), including but not limited to all shipping, taxes, and duties. If Equipment is required to be upgraded or replaced, as determined by SST in its sole, reasonable discretion, Client shall (i) within one hundred twenty (120) days of receipt of notice from SST, authorize SST to upgrade or replace such Equipment (and Client will provide all assistance reasonably required by SST to complete such upgrade or replacement), and (ii) return all defective Equipment or parts within thirty (30) days of receipt of the replacement or upgraded Equipment or parts, or undertake such other action as reasonably directed by SST.  Notwithstanding anything to the contrary, Client shall be responsible for the cost of any maintenance, repair, and/or replacement of Equipment that is required due to Client’s or any Client User’s negligence, recklessness, or willful misconduct. 

9.3  Delivery. SST will cause the Equipment to be delivered to the applicable Named Facility, or such other site designated in writing by Client. Equipment will be shipped DAP Incoterms® 2020. SST is responsible for all shipping and transport of the Equipment and shall bear all risk of loss to the Equipment until such time the Equipment has been delivered to the applicable Named Facility (or other site designated in writing by Client), at which time Client assumes risk of loss and damage in accordance with DAP Incoterms® 2020. Client shall undertake all actions necessary to clear customs in a timely manner, as applicable.

9.4  Inspection Period. Upon delivery of the Equipment as set forth in Section 9.5 above, Client will have five (5) business days (each an “Inspection Period”) to inspect the Equipment to assess whether it materially complies with the Documentation. At or prior to the expiry of an Inspection Period, Client will notify SST in writing of Equipment that Client believes does not materially conform with the Documentation. SST will have ten (10) business days after the expiry of an Inspection Period to confirm and correct any such material deficiencies. If Client does not provide written notice of any material deficiencies during an Inspection Period, Client will be deemed to have accepted the Equipment. 

9.5  Treatment of Equipment Upon Termination or Expiration. Upon termination or expiration of this Agreement, Client must certify to SST in writing that it has reset the Equipment to factory settings and has erased and/or removed any Analytics Software, Insights, Documentation, trademarks, logos, or other confidential information of SST therefrom, as applicable.

  1. Confidentiality Obligations.

10.1    Confidential Information. “Confidential Information” as used in this Agreement means any information which is disclosed by either Party (including such Party’s employees or agents), directly or directly, in whatever form or medium,  during the term of this Agreement, and marked or otherwise identified as confidential or proprietary at the time of disclosure, or is of a nature that a reasonable person would, considering the circumstances and nature of disclosure, consider it to be confidential. Confidential Information may include (but is not limited to) information of the disclosing Party including, without limitation, designs, know-how, methods, processes, trade secrets, configurations, business information and plans, financial information, software, and technology. For the avoidance of doubt, all Services, Documentation, and pricing are Confidential Information of SST.

10.2   Obligations of Confidentiality. The receiving Party will not use the disclosing Party’s Confidential Information for purposes other than as provided in this Agreement. Each Party must protect the Confidential Information provided by the other Party, to prevent the unauthorized use, dissemination, disclosure, or publication of the Confidential Information, by using the same degree of care as it uses to protect its own confidential information of a like nature but exercising no less than a reasonable degree of care in any event.  Confidential Information disclosed hereunder may be disclosed to and used, in accordance with the terms of this Agreement, by the receiving Party’s employees, partners, agents, auditors, contractors, and subcontractors who (i) have a need to know such information, and (ii) are bound by the terms of an agreement protecting against unauthorized use or disclosure of Confidential Information that is at least as protective as this Agreement. The terms of this Agreement shall be considered Confidential Information; provided, however, that SST may provide a copy of this Agreement in connection with any financing transaction or due diligence inquiry. 

10.3   Exceptions. Each Party’s obligations set forth in this Section 10 shall not apply with respect to any portion of the Confidential Information of the other Party that: (i) was in that Party’s possession before receipt from the other Party as evidenced by written records; (ii) becomes a matter of public knowledge through no fault of the receiving Party; (iii) is rightfully obtained by either Party from a third party who, to the knowledge of the receiving Party, is legally free to pass on such information without the duty of confidentiality; (iv) is independently developed by either of the Parties; or (v) is Personal Data.

10.4   Judicial Order. If the receiving Party is required to disclose any Confidential Information by the requirements of law or regulations at the request of a regulatory authority, or by virtue of a summons or an order or decree of a court or tribunal, the receiving Party must, to the extent legally permitted, make commercially reasonable efforts to provide prompt written notice of such requirement to the disclosing Party prior to disclosure. If the disclosing Party is unable to obtain a protective order or arrangement preserving the confidentiality of the Confidential Information, the receiving Party subject to the disclosure requirement must limit the disclosure to only that portion of the Confidential Information which is legally required to be disclosed. 

10.5   Return of Confidential Information.  Upon termination or expiration of the Agreement, or otherwise at the disclosing Party’s written request, and at the disclosing Party’s option, the disclosing Party’s Confidential Information shall be either promptly returned to the disclosing Party or destroyed. The receiving Party may retain one (1) copy of disclosing Party’s Confidential Information in its confidential files, solely for the purpose of monitoring its continuing obligations of confidentiality under this Agreement. Notwithstanding the foregoing, electronic copies of Confidential Information stored in computer system backups maintained in accordance with the receiving Party’s systematic backup, disaster recovery, or business continuity procedures need not be returned or destroyed, provided that the receiving Party shall continue to be bound by the obligations set forth in this Agreement with respect to any of disclosing Party’s Confidential Information retained in accordance with this Section 10. 

  1. Representation and Warranties

11.1 Mutual Representation and Warranties

11.1.1 Each Party represents and warrants to the other Party that it is an entity, duly organized, validly existing and in good standing under the laws of its jurisdiction of organization.

11.1.2   Each Party represents and warrants to the other Party that it has all necessary rights, power, and authority to enter into this Agreement and to perform all of its obligations under this Agreement.

11.1.3   Each Party represents and warrants to the other Party that this Agreement has been duly and validly authorized, executed and delivered by it and constitutes a valid and binding obligation, enforceable in accordance with its terms (except as such enforceability may be limited by any applicable bankruptcy, insolvency, winding up, or other laws affecting creditors’ rights generally and by limitations on the availability of equitable remedies such as specific performance and injunction which are not in the discretion of the court from which they are sought).

11.1.4   Each Party represents and warrants to the other Party that to its knowledge, as of the Effective Date, there are no actions, suits or proceedings, existing or pending or threatened against or affecting it, before any court, arbitrator or governmental or administrative body or agency that affect the validity or enforceability of this Agreement or that would have an effect on its ability to perform its obligations hereunder.

11.2  SST Warranties

11.2.1   SST System Warranty. SST warrants that the SST System shall be made available in substantial conformity with its Documentation. Client’s sole remedy and SST’s sole liability for a breach of this warranty shall be for SST, in SST's sole discretion, to either (i) repair or replace any reported nonconformity in the SST System or, (ii) return the pro-rata fees paid for, and terminate Client’s access to, such nonconforming SST System.

11.2.2   Professional Services Warranty. SST warrants that the Professional Services provided by SST pursuant to this Agreement shall be performed in a professional manner by trained and skilled personnel. Client must notify SST of any breach of such warranty within thirty (30) days following performance of the non-conforming Professional Services giving rise to the breach of warranty claim. Client’s sole and exclusive remedy and SST’s entire liability for any breach of the warranty set forth in this Section 11.2.2 will be for SST, in SST's sole discretion, to either (i) re-perform such non-conforming Professional Services so as to comply with such warranty, or (ii) return the pro-rata fees paid for such nonconforming Professional Services.

11.2.3   Limitation of Warranties. The warranties set forth in this Section 11.2  shall not apply, and SST shall have no warranty obligation or liability with respect to, (a) any SST System that (i) are damaged through no fault of SST, (ii) are modified by anyone other than SST or SST’s designee, (iii) are used for any purpose other than its intended purpose (as specified in the Documentation), (iv) are used with equipment not specified as compatible in the Documentation, (v) are used with software not specified as compatible in the Documentation, (vi) Client fails to properly install or maintain, (b) any computer malfunction not attributable to the Services (c) any incorrect use of the Services, or (d) any willful misconduct or negligent action or omission of Client.

11.2.4 DISCLAIMER. TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, THE WARRANTIES CONTAINED IN THIS SECTION 11 ARE THE ONLY WARRANTIES AND THERE ARE NO OTHER WARRANTIES OR CONDITIONS, EXPRESS OR IMPLIED, INCLUDING IMPLIED WARRANTIES OR CONDITIONS OF MERCHANTABLE QUALITY, FITNESS FOR A PARTICULAR PURPOSE,  NON-INFRINGEMENT AND TITLE, AND/OR THOSE ARISING BY STATUTE OR OTHERWISE IN LAW OR FROM A COURSE OF DEALING OR USAGE OF TRADE, ALL OF WHICH ARE EXPRESSLY DISCLAIMED. FOR THE AVOIDANCE OF DOUBT, SST DOES NOT WARRANT, IN ANY WAY WHATSOEVER, THAT ANY USE OF THE SERVICES WILL RESULT IN ANY BENEFIT, ADVANTAGE OR IMPROVEMENT TO CLIENT, NAMED FACILITIES, OR ANY CLIENT USERS, OR THAT THE SERVICES WILL BE PERFORMED WITHOUT ERROR OR INTERRUPTION. CLIENT UNDERSTANDS THAT SST IS NOT THE MANUFACTURER OF ANY THIRD PARTY SOFTWARE OR EQUIPMENT, AND SST MAKES NO REPRESENTATION OR WARRANTY WITH RESPECT TO ANY THIRD-PARTY SOFTWARE OR EQUIPMENT. UNDER NO CIRCUMSTANCES SHALL SST'S THIRD-PARTY SUPPLIERS OF ANY COMPONENT OF THE SERVICES OR EQUIPMENT BE RESPONSIBLE OR LIABLE TO CLIENT OR ITS AFFILIATES FOR ANY DAMAGES, DIRECT OR OTHERWISE, ARISING UNDER THIS AGREEMENT OR OTHERWISE ARISING FROM THE TRANSACTIONS CONTEMPLATED HEREIN. SUCH THIRD-PARTY SUPPLIERS ARE THIRD PARTY BENEFICIARIES OF THE FOREGOING SENTENCE.

12. Indemnification

12.1 SST Indemnification.  SST will indemnify and hold harmless Client and its officers, directors, employees, agents, successors, heirs and assigns (“Client Indemnitees”) from any losses, liabilities, damages, and expenses (including reasonable legal fees) (“Losses”) arising out of any third-party claims, suits, demand, and causes of action (“Claims”) brought during the Term based on:

a.     any gross negligence or wilful misconduct of SST in the performance of its obligations hereunder;

b.     any damage to property or personal injury (including death) to the extent caused by the gross negligence of SST while performing Professional Services at a Named Facility; or

c.     the infringement of any United States or Canadian patent, copy right or trademark, or misappropriation of a trade secret of such third party, by the SST System.

12.2  Infringement Remedy.  In the event of infringement as described in Section 12.1 c. above, or if SST reasonably believes that such infringement is likely, SST may, at its option: (i) procure for Client the right to continue using the infringing SST System; (ii) modify the SST System to make its use non-infringing; (iii) replace the SST System with a product having materially equivalent functionality; or (iv) if, in SST’s reasonable opinion, neither (i) (ii) or (iii) above are commercially reasonable, terminate Client’s right to use such SST System and refund any prepaid and unused fees paid by Client for the infringing SST System. SST will have no obligation or liability under this Section 12 for any claim or action resulting from any of the following: (a) any claim or action that would have arisen due to Client’s business activities without use of the particular technology employed by the SST System, or (b) any claim or action resulting from any of the following: (i) modifications to the SST System by Client or a party other than SST, (ii) the combination of the SST System with other products, processes, or materials not provided by SST if the SST System itself would not infringe, (iii) specifications or requirements supplied by Client that were used for the configuration of the SST System, or (iv) where Client continues allegedly infringing activities after being provided with modifications that would have avoided the alleged infringement. This Section 12 states the sole obligation and exclusive liability of SST (express, implied, statutory or otherwise), and the sole remedy of Client, for any third-party claims or actions of infringement of any intellectual property or other proprietary right. 

12.3  Client Indemnification. Client will indemnify and hold harmless SST and its trustees, directors, officers, employees, agents, third party service providers, successors, heirs, and assigns from any Losses arising out of or relating to any Claims for:

a.     any gross negligence or wilful misconduct of Client and/or any Client Indemnitee;

b.     failure of Client and/or any Client Indemnitee to comply with applicable Privacy Laws; or

c.     damage to property or personal injury (including death) to the extent caused by (i) any acts or omissions of Client and/or Client Indemnitees, or (ii) Equipment installed at a Named Facility.

12.4  Indemnification Process. The indemnifying Party shall bear the expense of defending the Claims and shall pay any Losses attributed to a Claim.   The indemnified Party will provide all reasonably requested cooperation and assistance to the indemnifying Party (at the indemnifying Party’s expense) and provide the indemnifying Party with full authority to defend, settle or otherwise dispose of a Claim in accordance with this Section 12; provided that the indemnified Party may elect to participate in such a defense at its sole option and expense.   The obligations of the indemnifying Party are conditioned on the indemnified Party’s prompt written notification of a Claim that is subject to the indemnification obligations under this Section 12.  Notwithstanding the foregoing, the indemnifying Party may not enter into any settlement that (i) requires the indemnified Party to admit fault, (ii) that imposes any obligation on the indemnified party, or (iii) that does not contain a release of the indemnified Party, without the prior written consent of the indemnified Party, which consent shall not be unreasonably withheld or delayed.

13. Limitations of Liability

13.1 SST’s liability to the Client for any expense, damage, loss, injury, or liability of any kind, regardless of the form of action or theory of liability (including for breach of contract, tort, negligence, by statute or otherwise) arising out of or related to this Agreement (including, without limitation, any Data Privacy Agreement/s) will be limited to the actual direct damages suffered by such Party and such liability will not exceed the fees paid by Client in the twelve-month period immediately preceding the first claim for which SST is liable, for any and all claims arising in any connection with this Agreement.

13.2 IN NO EVENT WILL SST BE LIABLE TO CLIENT FOR ANY LOSS OF PROFITS OR REVENUES, LOSS OF ANTICIPATED SAVINGS, LOSS OF CUSTOMERS, OR LOSS OF USE OF ANY SOFTWARE OR DATA, NOR FOR ANY SPECIAL, INDIRECT, INCIDENTAL OR CONSEQUENTIAL DAMAGES SUFFERED BY CLIENT, HOWSOEVER CAUSED AND REGARDLESS OF THE FORM OR CAUSE OF ACTION, EVEN IF SUCH DAMAGES ARE FORESEEABLE OR SST HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. 

13.3 CLIENT ACKNOWLEDGES THAT SOFTWARE AND SERVICES ARE NOT ERROR FREE. FURTHERMORE, DATA ANALYSIS IS A PROCESS THAT IS INHERENTLY INACCURATE AND ERRORS OCCUR IN THE CONTENT, OUTPUT AND RESULTS OF SUCH PROCESSES THAT SST IS NOT RESPONSIBLE FOR. CLIENT AGREES THAT IT IS THE SOLE RESPONSIBILITY OF CLIENT AND EACH CLIENT USER TO IDENTIFY AND CORRECT ANY SUCH ERRORS AND INACCURACIES BEFORE USING AND/OR RELYING ON THE CONTENT, RESULTS OR OUTPUT OF ANY SOFTWARE AND/OR SERVICES PROVIDED UNDER THIS AGREEMENT. CLIENT UNDERSTANDS THAT SST IS NOT RESPONSIBLE FOR THE ACCURACY OF ANY CLIENT DATA, CLIENT’S CONFIDENTIAL INFORMATION, OR OTHER INFORMATION PROVIDED BY CLIENT. CLIENT FURTHER UNDERSTANDS THAT CLIENT SHALL NOT HOLD SST LIABLE OR PURSUE ANY CLAIMS AGAINST SST ARISING AS A RESULT OF ANY ERROR, MISREPRESENTATION, OR INACCURACY IN THE CLIENT DATA OR CLIENT’S CONFIDENTIAL INFORMATION FURNISHED TO SST OR UPLOADED INTO THE SST SYSTEM BY CLIENT HEREUNDER. SST SHALL HAVE NO LIABILITY FOR ANY LOSS, DAMAGE TO, OR CORRUPTION OF ANY CLIENT DATA. CLIENT AGREES THAT SST IS NOT PROVIDING MEDICAL PRACTICE ADVICE, AND THAT CLIENT AND EACH CLIENT USER WILL CONSULT WITH AND RELY EXCLUSIVELY ON ITS OWN PHYSICIANS OR OTHER MEDICAL DIRECTION FOR REVIEW, NECESSARY REVISIONS AND APPROVAL OF ANY AND ALL SUCH MEDICAL-PRACTICE-RELATED CONTENT, RESULTS OR OUTPUT. CLIENT UNDERSTANDS AND ACKNOWLEDGES THAT THE SST SYSTEM USES ARTIFICIAL INTELLIGENCE, WHICH MAY NOT BE ERROR FREE AND MAY NOT BE ACCURATE, RELIABLE, OR NON-INFRINGING. SST ASSUMES NO RESPONSIBILITY FOR ANY OF THE FOREGOING.

14. Term and Termination

14.1. Term. This Agreement will commence on the Effective Date and, unless terminated earlier in accordance with the terms hereof, shall remain in effect until the last to expire of any Subscription Term.  Each Order Form shall be effective for the Initial Subscription Term set forth in such Order Form and thereafter shall subsequently automatically renew at SST’s then-current rates for the same term length as the Initial Subscription Term (each a “Renewal Term”), unless either Party gives one hundred and eighty (180) days’ advance notice prior to the expiration of the Order Form’s Initial Subscription Term or applicable Renewal Term of a decision to terminate or not renew the Order Form.    

14.2 Termination for Cause. Either Party may terminate this Agreement, and/or any Order Form or Statement of Work, upon written notice if the other Party commits a material breach of this Agreement or such Order Form or Statement of Work and fails to cure such breach within thirty (30) days of receipt of written notice describing such breach. Notwithstanding the foregoing, SST may terminate this Agreement, and/or any Order or Statement of Work, immediately upon written notice to Client if Client (a) infringes SST’s intellectual property rights, (b) commits, or permits any third party to commit, any breach of confidentiality obligations, or (c) Client has a receiver appointed to handle its assets or affairs, admits that it is insolvent, or is otherwise unable to pay its debts as they mature, or ceases to do business in the ordinary course.

14.3 Effects of Termination. In the event of termination of this Agreement: (i) Client will promptly pay all amounts owing and payable to SST up to and including the effective date of termination, and (ii) all licenses and rights granted by SST to Client under this Agreement will terminate.

14.4 Survival.  The provisions of Sections 1, 3.2, 3.4, 5, 7, 8, 9, 10, 11, 12, 13, 14.3, 14.4, and 15 and such other terms and conditions that, by their nature and context, survive expiration or termination of this Agreement, will survive termination or expiration of this Agreement.

15. General Provisions; Miscellaneous.

15.1 Independent Contractors.  SST and Client acknowledge and agree that SST is an independent contractor and is not an employee, agent or partner of Client.  Neither Client or SST will have the authority to enter into any contract on behalf of the other or make any representation or incur any obligation in the name of or on behalf of the other.

15.2   Entire Agreement.   This Agreement, including all Exhibits, Order Forms, and Statements of Work hereto, constitutes the entire agreement between the Parties pertaining to all matters herein and terminates and supersedes all prior agreements, understandings, letter of intent, negotiations and discussions between the Parties, whether oral or written.  This Agreement may only be amended by written agreement executed by the authorized representative of the Parties.

15.3  Order of Precedence. In the event of a conflict between the terms or provisions of this Agreement, the order of precedence shall be as follows: (i) any Data Privacy Agreement entered into by the Parties which incorporates this Agreement by reference, solely with respect to the privacy and security of Personal Data, (ii) this Agreement, and (iii) each Order Form or Statement of Work, unless Order Form or Statement of Work states that a specific provision of this Agreement will be superseded by a specific provision therein.   

15.4  No Third-Party Beneficiaries. Except as expressly stated otherwise in this Agreement, nothing in this Agreement is intended to create any rights in, or confer any benefits upon, any person or entity other than the Parties to this Agreement.

15.5  Dispute Resolution.  If a dispute arises out of, or in connection with this Agreement, the Parties agree to use good faith efforts to pursue a resolution through negotiation before resorting to litigation.  All information exchanged during any such negotiation, shall be regarded as “without prejudice” communications for the purpose of settlement negotiations and shall be treated as confidential by the Parties and their representatives, unless otherwise required by law. However, evidence that is independently admissible or discoverable shall not be rendered inadmissible or non-discoverable by virtue of its use during such negotiations. All disputes hereunder shall be brought within a period of one (1) year from the later of (i) the date the dispute arose, or (ii) the date the applicable Party learned of, or, by exercising a reasonable degree of care, should have learned of, the circumstances from which the dispute arose.

15.6  Publicity.  SST may use in its advertising, publicity, websites, press releases, marketing materials, or otherwise the name, logo and trademarks of Client, and Client hereby expressly grants SST a fully paid up, non-exclusive, irrevocable license to use any such materials of Client to do so, or to perform any of SST’s obligations under this Agreement. Without limiting the foregoing, SST may refer to the existence of this Agreement or the relationship of the Parties in connection with a press release. SST will not use any trademarks of Client for any other purpose.  The Client shall not use the name, business, name, trademarks or logos of SST in any advertising, publicity or marketing other materials intended for public release, whether in hard copy or electronic format, without the express written permission of SST.

15.7  Subcontracting. SST reserves the right to subcontract the performance of its obligations under this Agreement to third-party subcontractors. Without limiting the foregoing, Client acknowledges and agrees that SST’s rights and obligations hereunder may be exercised, performed, or otherwise carried out by an SST affiliate.

15.8  Assignment.  Neither Party may assign this Agreement without the prior written consent of the other Party. Notwithstanding the foregoing, either Party may assign this Agreement to a successor of all or substantially all of such Party’s business or assets to which this Agreement relates, whether by merger, consolidation, sale of assets or otherwise, upon written notice to the other Party.  Any purported assignment in contravention of the foregoing will be null and void.  The rights and obligations of the Parties under this Agreement will be binding upon and inure to the benefit of the successors and permitted assigns of the Parties.

15.9  Injunctive Relief. Each Party acknowledges that any use or disclosure of Confidential Information in breach of this Agreement or any violation of SST’s intellectual property rights may cause irreparable damage to the non-breaching Party, for which remedies other than injunctive relief may be inadequate, and the breaching Party agrees that it shall not object to the non-breaching Party seeking injunctive or other equitable relief to restrain the alleged breach or violation. The Parties further agree that in the event such equitable relief is granted in the United States, they will not object to courts in other jurisdictions granting provisional remedies enforcing such United States judgments. 

15.10 Counterparts.  This Agreement may be executed in any number of counterparts, each of which shall be deemed an original.   Facsimile or electronic copies hereof shall be deemed to be originals.

15.11   Governing Law.  This Agreement shall be construed and enforced in accordance with the laws of theProvince of Ontario , without regard to conflict of law rules.  All disputes arising from this Agreement will be subject to the exclusive jurisdiction of the courts of competent jurisdiction located in Ontario. EACH OF THE PARTIES HERETO HEREBY IRREVOCABLY WAIVES ANY AND ALL RIGHT TO TRIAL BY JURY IN ANY LEGAL PROCEEDING ARISING OUT OF OR RELATED TO THIS AGREEMENT OR THE TRANSACTIONS CONTEMPLATED HEREBY. This Agreement was prepared in the English language, which language shall govern the interpretation of, and any dispute regarding, the terms of this Agreement. All information to be provided by the Parties to each other shall be in English, and Client shall be responsible for all necessary translation. Unless stated otherwise, all currency references herein are to United States Dollars.

15.12   Notices.   Any notices or communication required or permitted to be given under this Agreement shall be served personally, sent by mail, sent by overnight delivery or courier, or sent by email to the following address:

If to SST:           SST Surgical Safety Technologies Canada ULC
Attn: Dr. Teodor Grantcharov; Sr. Director Contracts + Compliance
                           20 Queen St. W Suite 3501, 35th Floor
                           Toronto, Ontario M5H 3R3.
                          Email: contracts@surgicalsafety.com 

If to Client:       Address indicated on the applicable Order Form or Statement of Work

15.13   Force Majeure. Except for payment obligations, neither Party will be liable for any failure or delay in performing an obligation under this Agreement that is due to any of the following causes, to the extent beyond its reasonable control: acts of God , accident, riots, terrorist act, epidemic, pandemic, quarantine, civil commotion, breakdown of communication facilities, breakdown of web host, breakdown of internet service provider, natural catastrophes, governmental acts or omissions, changes in laws or regulations, national strikes, fire, explosion, generalized lack of availability of raw materials or energy. 

15.14   Severability.   The invalidity or unenforceability of one or more provisions of this Agreement shall not affect the validity or enforceability of any of the other provisions hereof and this Agreement shall be construed in all respects as if such invalid or unenforceable provisions are omitted. 

Exhibit A

DATA PROTECTION ADDENDUM 

This Data Protection Addendum (“DPA”) is subject to, and made part of, the Master Subscription Services Agreement to which this DPA is attached (“Agreement”). This DPA only applies to the Processing by SST of Personal Data collected from the EEA to provide, support, or improve the Services . 

The Parties agree that, for the purposes of this DPA, Client is a Data Controller as defined in the GDPR (“Controller”) and SST is a Data Processor as defined in the GDPR (“Processor”). 

1. Definitions.

Capitalized terms used, but not otherwise defined, in this DPA or the Agreement shall have the meaning given to them in GDPR. The following terms have the following meanings when used in this DPA: 

1.1  “EEA” means Member States of the European Economic Area, Switzerland, United Kingdom, Canada, Brazil, and any country that has implemented data privacy laws and regulations substantially similar to GDPR.  

1.2EEA Data Protection Laws” means GDPR (and as applied in the UK), the UK Data Protection Act of 2018, the Switzerland Federal Data Protection Act of 2023, Brazilian Data Protection Law (General Law for the Protection of Privacy), Canada’s Personal Information Protection and Electronic Documents Act, and Canada’s Personal Health Information Protection Act (2004) (Ontario), as applicable. 

1.3  “GDPR” means the General Data Protection Regulation 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons regarding the processing of personal data and on the free movement of such data, as amended. 

1.4Personal Data Breach” means a breach of security by Processor or its Sub-processors, leading to the unauthorized or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data. 

1.5  “Processing” means any operation or set of operations that is performed on Personal Data whether or not by automated means such as collection, recording, organization, structuring, storage, adaption or alteration, retrieval, consultation, use, disclosure by transmission, dissemination, or otherwise making available, alignment or combination, restriction, erasure, or destruction. “Process,” “Processed” and the like will have a corresponding meaning. 

2. Compliance with Applicable Law.

Processor will comply with all applicable provisions of applicable EEA Data Protection Laws in respect of Personal Data. 

3. Processing of Personal Data.

Processor will only Process Personal Data in accordance with Controller’s instructions or as required by law. Controller instructs Processor to Process Personal Data to perform the Services and as described in the DPA and the Agreement. The Agreement, including this DPA, are Controller’s complete and final instructions to Processor for the Processing of Personal Data. Processor will not be bound by additional or alternative instructions except pursuant to the Parties mutual written agreement. Processor will inform Controller if, in its reasonable opinion, its instructions to Process Personal Data pursuant to the Agreement, including this DPA, infringes Privacy Laws and shall without liability, be entitled to stop Processing Personal Data in accordance with such infringing instruction. The Parties acknowledge and agree that a failure or delay by Processor to identify that an instruction infringes Privacy Laws will not cause Processor to be in breach of the Agreement or this DPA nor relieve Controller of its liability under the Agreement. 

4. Data Transfers Outside of the EEA.

Personal Data may be transferred to any country in which SST, or its Sub-processors maintain facilities. This Section 4 only applies to the transfer of Personal Data from the EEA to a third country that has not been deemed adequate by the applicable data protection authority. For each applicable version of the European Union Standard Contractual Clauses (“SCCs”) between SST and Client: (a) such SCCs are incorporated by reference herein, and Client and SST are deemed to have executed the SCCs upon execution of the Order Form or Statement of Work, as applicable; and (b) Client is the “data exporter” and SST is the “data importer. SST will conduct the transfers of Personal Data from the EEA pursuant to the SCCs or any other data transfer mechanism permitted under EEA Data Protection Laws of each applicable jurisdiction. With respect to the SCCs the following apply if SST (including via a Sub-processor) Processes Personal Data outside the EEA: (i) Module Two (controller to processor); (ii) Annexes I and II attached hereto, attached as Appendix 2 and 3 respectively; (iii) “Member State” refers to the country from which the Personal Data originates (irrespective of whether the country is a member state of the European Union); (iv) “jurisdiction” and “supervisory authority” refer to the respective data protection authority that enforces applicable EEA Data Protection Law/s; (v) Clause 7; (vi) in Clause 9, option 2 for general written authorization with a time period of ten days; (vii) in Clause 11, the optional text is not included; (viii) in Clauses 17 and 18, selecting option 2 and specifying Denmark, unless the applicable EEA Data Protection Law/s require a different jurisdiction, in which case such jurisdiction shall be specified, and (ix) for Personal Data subject to the Switzerland Federal Data Protection Act of 2023 (“Swiss DPA”) or the Brazilian General Data Protection Law (“LGPD”), references to the GDPR and “that Regulation” will be read as references to the relevant provisions of the Swiss DPA or the LGPD. With respect to a transfer from SST to a Sub-processor pursuant to the SCCs, SST will conduct the transfer under Module Three (processor to processor) and SST shall be the “data exporter” and the Sub-processor shall be the “data importer.”  

5. Confidentiality.

Processor will restrict access to Personal Data to those authorized persons who need such information to provide the Services. Processor will ensure such authorized persons are obligated to maintain the confidentiality of any Personal Data. 

6. Security.

In accordance with Article 32 of GDPR, Processor will implement technical and organizational measures designed to protect Personal Data against a Personal Data Breach. A description of such technical and organizational measures is attached as Appendix 3.  

7. Sub-processors.

Controller agrees that Processor may engage other processors to assist in fulfilling its obligations with respect to providing, supporting, and improving the Services pursuant to the Agreement or this DPA, where such entity processes Controller Personal Data (“Sub-processor(s)”).  Where Processor engages a Sub-processor for carrying out specific Processing activities on behalf of Controller, substantially similar data protection obligations as set out in this DPA will be imposed on the Sub-processor by way of a contract or other legal mechanism, in particular providing sufficient guarantees to implement appropriate technical and organizational measures in such a manner that the Processing will meet the requirements of  applicable EEA Data Protection Laws. As set forth in Article 28 of GDPR, where that Sub-processor fails to fulfill its data protection obligations, Processor will remain fully liable to Controller for the performance of that Sub-processor’s obligations. Controller’s current Sub-processors, as of the Effective Date, are set forth on Appendix 1 to this DPA. Processor will (i) provide an up-to-date list of the Sub-processors it has appointed upon written request from Controller; and (ii) notify Controller if it adds or replaces a Sub-processor at least ten (10) days prior to any such changes in accordance with the notice provision set forth in the Agreement. Processor may update the process for notification upon ten (10) days’ advance written notice to Controller, via email to the email address identified in the preceding sentence. If Controller reasonably objects to a Sub-processor, Controller must inform Processor in writing within five (5) days. Absent such a written communication from Controller within the defined time period, Controller will be deemed to have accepted Processor’s use of such Sub-processor. If Processor is unable to resolve Controller’s objection, either party may, upon notice and without liability, terminate the portion of the services provided under the Agreement that use the objected-to Sub-processor. 

  1. Data Subject’s Requests.

Processor has implemented and will maintain appropriate technical and organizational measures needed to enable Controller to respond to requests from data subjects to exercise their rights set forth in Chapter III of GDPR, including, without limitation, rights to access, correct, transmit, limit Processing of, or delete (erasure) any relevant Personal Data held by the Processor. If Processor receives the aforementioned request(s) from a data subject directly, Processor will notify Controller within ten (10) calendar days of receiving the request, and, except as otherwise required by applicable EEA Data Protection Laws, Controller shall be responsible for handling the response to the request with the reasonable coordination and assistance of Processor as necessary.  

9. Security Breach and Management.

Processor shall promptly notify Controller upon becoming aware of the occurrence of a Personal Data Breach and provide Controller with the following information as it becomes available: 

  • a description of the nature of the Personal Data Breach, including where possible the categories and approximate number of data subjects concerned; 

  • the name and contact details of Processor contact from whom more information can be obtained; and 

  • a description of the measures taken or proposed to be taken by Processor and/or Controller to address the Personal Data Breach, including, where appropriate, measures to mitigate its possible adverse effects. 

The parties agree to coordinate in good faith on developing the content of any related public statements and any required notices to the affected data subjects and/or the relevant regulators in connection with a Personal Data Breach. For clarity, Controller, and not the Processor, shall be responsible for providing any required notices to individuals and/or regulators.  

10. Audits.

On Controller’s request, and subject to the confidentiality provisions of the Agreement, Processor will make available to Controller copies of, or extracts from, Processor’s audit reports designated for distribution to its client base related to the security of the Services. Controller may request (directly or through a third-party auditor subject to written confidentiality obligations) an audit of Processor to verify Processor’s compliance with the terms of this DPA if such an audit is required by EEA Data Protection Laws and Processor’s compliance cannot be demonstrated by means that are less burdensome on Processor (including as set forth in the preceding sentence). Any audit under this section must meet the following requirements: (a) Controller must provide Processor at least 30 days’ prior written notice of a proposed audit unless otherwise required by a competent supervisory authority or EEA Data Protection Laws; (b) Controller may not perform more than one audit in any 12-month period, except where required by a competent supervisory authority; (c) Controller and Processor must mutually agree on the time, scope, and duration of the audit in advance; (d) Controller must ensure that its representatives performing an audit protect the confidentiality of all information obtained through the audit in accordance with the Agreement, execute an enhanced mutually agreeable nondisclosure agreement if requested by Processor, and abide by Processor’s security policies while on Processor’s premises; and (e) Controller must promptly disclose to Processor any written audit report created, and any findings of noncompliance discovered, as a result of the audit.  

11. Return or Disposal.

Processor will delete all Personal Data upon termination of the Agreement and cessation of Processing, unless applicable EEA Data Protection Laws or Processor’s internal data retention policies (provided they are in compliance with the applicable EEA Data Protection Laws) requires Processor to maintain and store any Personal Data, in which case Processor will continue to protect the Personal Data in accordance with the terms of this DPA. 

12. Controller Obligations.

Subject to the cooperation of Processor as specified in this DPA, Controller will be solely responsible for safeguarding the rights of any data subjects, including determining the adequacy of the security measures in relation to Personal Data which Controller provides to Processor. Controller agrees that: (i) it will comply with its obligations as a Controller under applicable EEA Data Protection Laws in respect of its processing of Personal Data and any processing instructions it issues to Processor; (ii) it will not instruct Processor to perform any Processing of Personal Data that violates applicable EEA Data Protection Laws or any other applicable data protection law; and (iii) it has provided notice and obtained (or will obtain) all consents and rights necessary under applicable EEA Data Protection Laws  for Processor to process Personal Data and perform its obligations pursuant to the Agreement and this DPA. Notwithstanding anything to the contrary herein, Controller agrees that except to the extent expressly provided in this DPA, Controller is responsible for its secure use of the Processor’s services pursuant to the Agreement, including securing its account authentication credentials, protecting the security of Personal Data when in transit to and from Processor and taking any appropriate steps to securely encrypt or backup any Personal Data provided to the Processor. 

13. Amendment to Comply with Law.

The Parties acknowledge that laws relating to data security and privacy are rapidly evolving and that amendment of this DPA may be required to provide for procedures to ensure compliance with such developments. The Parties specifically agree to take such action as is necessary to implement the standards and requirements of applicable EEA Data Protection Laws, and other applicable laws relating to the security or confidentiality of Personal Data. The Parties understand and agree that Controller must receive satisfactory written assurance from Processor that Processor will adequately safeguard all Personal Data. Upon request of either Party, the other Party agrees to promptly enter into negotiations concerning the terms of an amendment to this DPA embodying written assurances consistent with the standards and requirements of the applicable EEA Data Protection Laws, or other applicable laws. This DPA may only be amended by written agreement executed by the authorized representative of the Parties. 

14. Interpretation.

This DPA shall be interpreted as broadly as necessary to implement and comply with applicable EEA Data Protection Laws. The Parties agree that any ambiguity in this DPA shall be resolved in favor of a meaning that complies and is consistent with applicable EEA Data Protection Laws. 

15. Termination.

This DPA will terminate when the Processor ceases to Process Personal Data under the Agreement, unless otherwise agreed in writing between the Parties; provided, Processor’s obligations to protect the privacy and security of Personal Data in Processor’s possession, in accordance with the terms of this Agreement is continuous and survives any termination, cancellation, expiration, or other conclusions of this DPA. 

16. Governing Law.

This DPA shall be governed by the applicable EEA Data Protection Laws, as defined herein.  

17. Limits of Liability.

For clarity, any claims brought under or in connection with this DPA, by and between Controller and Processor will be subject to the terms and conditions, including but not limited to, the exclusions and limitations on liability, set forth in the Agreement. No one other than a party to this DPA, its successors and permitted assignees will have any right to enforce any of its terms, except as specifically provided under applicable EEA Data Protection Laws.  

18. Conflict.

If there is a conflict between the terms of this DPA and the Agreement, this DPA will prevail with respect to the privacy and security of Personal Data. Except for the matters covered by this DPA, all terms of the Agreement, remain in effect.

Appendix 1

SST Affiliate Sub-processor: 

Surgical Safety Technologies, Inc. (US)  

SST Third-Party Sub-processors


Vendor

Type of Service

Amazon Web Services, Inc.

Infrastructure

Atlassian Pty Ltd (Jira)

Internal support collaboration

Google LLC

Email and office applications

Salesforce.com, Inc.

Customer relationship management services

HubSpot, Inc.

Customer relationship management services

Slack Technologies, Inc.

Communication services

Microsoft Corporation

Office applications

Elastic NV

Log management tool

Sage Software, Inc.

Billing and invoicing software

Adobe Inc.

Office application (eSignature tool)

Datadog, Inc.

Database and infrastructure monitoring


Appendix 2

(Annex 1) 

A. LIST OF PARTIES

Data exporter(s): 

Name: Client 

Address: The address for Client associated with its SST account or as otherwise stated in the Agreement. 

Contact person’s name, position, and contact details: The contact details for Client associated with its SST account or as otherwise stated in the Agreement. 

Activities relevant to the data transferred under these Clauses: SST provides a proprietary software-as-a-service platform designed to assist in the monitoring of clinical procedures and environments by capturing data on-site at Client’s locations and providing analysis of such data. SST Processes Personal Data for the purpose of providing, supporting, and improving the Services.

Signature and date: The parties agree that Order Form or Statement of Work signature, as applicable, constitutes execution of this Annex 1 by both parties. 

Role (controller/processor): Controller. 

Data importer(s)

Name: SST Surgical Safety Technologies Canada ULC

Address: 20 Queen St. W Suite 3501, 35th Floor. Toronto, Ontario M5H 3R4

Contact person’s name, position, and contact details: The contact details for SST as stated in the Agreement. SST’s privacy team can be contacted at contracts@surgicalsafety.com

Activities relevant to the data transferred under these Clauses: SST provides a proprietary software-as-a-service platform designed to assist in the monitoring of clinical procedures and environments by capturing data on-site at Client’s locations and providing analysis of such data. SST Processes Personal Data for the purpose of providing, supporting, and improving the Services.

Signature and date: The parties agree that execution of the Order Form or Statement of Work, as applicable, constitutes execution of this Annex 1 by both parties. 

Role (controller/processor): Processor. 

B. DESCRIPTION OF TRANSFER 

Categories of data subjects whose personal data is transferred 

The data subjects may include Client’s employees, contractors and other hospital personnel, patients, and end users, and any such Data Subjects that Personal Data is collected about to the extent collected by SST in the performance of the Services.  

Categories of personal data transferred 

The Personal Data that is sent to SST by, or on behalf of, Client in connection with the Services . 

Sensitive data transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as for instance strict purpose limitation, access restrictions (including access only for staff having followed specialized training), keeping a record of access to the data, restrictions for onward transfers or additional security measures. 

The categories of Personal Data involved and transferred may include sensitive personal data. Refer to Appendix 3 for SST’s description of technical and organizational measures.  

The frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis). 

Personal Data is transferred on a continuous basis. 

Nature of the processing 

Analysis, storage, and other Services as described in the Agreement, Order (s), Statement(s) of Work, DPA, and Documentation. 

Purpose(s) of the data transfer and further processing 

For SST to provide, support, and improve the Services. 

The period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period 

Personal Data collected in the course of performance of the Services  is retained for thirty (30) days, unless otherwise specified by Client (and agreed to by SST) in writing. Personal Data used to support the Services(e.g. Client contact information) is retained in accordance with SST’s data retention policies.  

For transfers to (sub-) processors, also specify subject matter, nature, and duration of the processing 

The subject matter of Personal Data transferred to Subprocessors is Client Personal Data, which is transferred to Subprocessors to provide, support, and improve the Services, as set forth in the Agreement and this DPA. 

C. COMPETENT SUPERVISORY AUTHORITY 

Identify the competent supervisory authority/ies in accordance with Clause 13 

The competent supervisory authority shall be Denmark, unless the applicable EEA Data Protection Law/s require a different jurisdiction, in which case such jurisdiction shall be specified. 

Appendix 3

(Annex 2)

TECHNICAL AND ORGANISATIONAL MEASURES INCLUDING TECHNICAL AND ORGANISATIONAL MEASURES DESIGNED TO ENSURE THE SECURITY OF THE DATA

Encryption of Data at Rest 

The following table describes the data that is encrypted at rest within products that exist within SST Systems. 

Encryption of Data in Transit 

The transmission of data from one machine to another can occur: 

1.     within the Hospital’s data center infrastructure 

2.     over the Internet to SST’s cloud infrastructure

3.     within SST’s cloud infrastructure 

4.     to user clients (i.e. browsers) consuming data on Black Box Platform (BBP)

Within the Hospital’s data center infrastructure 

OR Black Box data is transmitted within the Hospitals data center infrastructure (and only between dedicated OR Black Box servers provided by the Hospital) over a private VLAN (Virtual Local Area Network), configured and administered by the Hospital. This private OR Black Box VLAN ensures isolation of OR Black Box network traffic from other Hospital network traffic. 

Data captured by OR Black Box is encrypted at rest, on disk that is provided and administered by the Hospital. Decryption of newly created OR Black Box data at the Hospital’s premise is neither permitted nor possible. Encrypted Captured Data is only transmitted between authorized servers within the private OR Black Box VLAN network. 

Over the Internet 

Encrypted Captured Data that is securely transmitted from the Hospital’s servers to SST’s servers is protected using enterprise grade Managed File Transfer (MFT) solutions. Encrypted data is securely transmitted over the internet using one of the following configurations: 

1) SFTP 

2) HTTPS with TLS 1.2+ 

Within SST’s data center infrastructure 

Data is transmitted within SST’s AWS infrastructure using encrypted protocols.  Furthermore, data can be transmitted between machines that reside within the same data center infrastructure. In this case, internal network transmission of data is also encrypted. 

Encryption Protocols and Ciphers supported by OR Black Box Platform and Black Box Explorer

Security Controls 

SST has adopted, implemented, and maintains the security controls as described below, to:  

1.   ensure the confidentiality, integrity, and availability of all Confidential Information that SST accesses, creates, receives, processes, maintains, or transmits on Client’s behalf;  

2.   protect against any reasonably anticipated threats or hazards to the security or integrity of such information;  

3.   protect against any reasonably anticipated uses or disclosures of such information that are not permitted by applicable law and the Agreement; and  

4.   ensure compliance by its workforce, including SSTs and agents. 

Maintain a formal information security program, with a named individual responsible for its overall execution. SST’s information security program has executive support, and is defined based on the characteristics of its business. It includes documented security plans, policies, and procedures designed to protect the confidentiality, integrity, and availability of its information assets. SST maintains staffing and technical resources at an appropriate level to ensure the information security program’s plans, policies, procedures, ongoing operations, monitoring, and continuous improvement. 

Maintain formal documented instructions for reporting security breaches. SST maintains documentation for reporting security breaches, and SST staff are trained on the process. In the event of a security breach involving client data, SST will notify the client manager in writing with a detailed description of the breach, actions taken and an action plan to prevent future incidents.

Assess and manage security risks associated with vendors and sub-contractors of SST. SST maintains a program for assessing and managing information security risks associated with its vendors and sub-contractors that have physical or logical access to SST’s IT systems and networks. As appropriate, required security requirements are incorporated into contracts between SST and its vendors and sub-contractors. Contracts between SST and its vendors and sub-contractors will flow down requirements for maintaining any applicable regulatory requirements. 

Maintain employee on-boarding and off-boarding policies and procedures. SST ensures that new employees receive a level of screening appropriate for their roles, that may include, but not necessarily be limited to, professional reference checks and criminal background checks. Upon employee termination, access to SST’s systems and networks (including remote access via VPN) is discontinued in a timely fashion, and any SST-issued IT assets (e.g. laptops, mobile phones, or portable storage media) are collected prior to the employee’s separation from the company.  

Ensure continuing employee awareness of and education on security policies, standards, and procedures. SST will provide security training to all employees and contract staff. Formal procedures and scope of administrator’s roles and security procedures are specified. SST maintains security policies, rules, procedures and instructions for continued security awareness and education. 

Maintain policies and procedures that establish the rules for granting and modifying access, documentation of changes to access rights, and account termination procedures. All SST user accounts are set up based on their role and are restricted to privileges based on job duties, project responsibilities, and other relevant business activities. SST user accounts are removed from all systems immediately upon termination of employment or contractual relationship with SST.   

Prevent access to information and resources unless authorized. SST has policies, procedures, and technical controls in place to ensure that access to SST’s systems and applications will be denied unless the user has entered a valid user ID and password.  Only authorized networks and users are allowed access to SST’s servers and applications. 

Limit the time that an unattended, logged-in system is vulnerable to unauthorized use. Workstations, laptops, and mobile devices used or managed by SST’s personnel will be configured to launch a password-protected screen lock after a maximum of 45 minutes of inactivity. 

Maintain password management policies and procedures, including personal accountability for user accounts and limited exposure from password disclosures. SST policies, procedures and security features require a unique user ID and password for each user. Any party, including SST personnel or system administrators, cannot discover passwords. SST enforces password expiration in line with industry standard guidelines (e.g. NIST). Where possible, multi-factor authentication is used to supplement password security for access into critical systems. 

Protect systems and networks with firewalls and intrusion detection/prevention systems (IDS/IPS). SST uses firewalls and IDS/IPS to protect its servers, workstations, laptops mobile devices, and other network devices. A combination of network- and host-based firewalls and IDS/IPS may be used to address different risk profiles as determined by SST’s risk assessment. SST regularly reviews firewall and IDS/IPS rules to ensure that they are still applicable. Firewalls and IDS/IPS are configured to generate automated alerts based on matching signatures of malicious network activity, and management consoles are routinely monitored by SST personnel.  

Evaluate and install security patches in a timely fashion. SST maintains formally documented security patch management procedures. SST will evaluate, test, and install security patches based on a risk-based schedule prioritized by the Common Vulnerability Scoring System (CVSS) score, or a functionally equivalent approach. Security patches identified as a high priority, generally those that address vulnerabilities with a CVSS base score of 7.0 to 10.0, should be installed with 30 calendar days of release, including any system reboots that may be necessary to fully install the patch. SST will maintain a formal exception management process to review and address risks associated with high priority patches that cannot be installed during this window.  

Encrypt sensitive information. SST encrypts all sensitive information in transit (e.g. through SSL/TLS, SSH, or site-to-site VPNs). A minimum level of 128-bit AES encryption will be employed. Administrative access to the production network is performed over an encrypted channel. Passwords are encrypted during transit and at rest. Full-disk encryption software (e.g. PGP, BitLocker, FileVault, or equivalent) is used to protect any of SST’s workstations and laptops that may be used for either temporary or long-term storage of confidential information. 

Protect systems against self-propagating malware. Endpoint security software is installed and maintained on all SST workstations and servers, properly configured and maintained with an up-to-date scan engine and anti-virus definition files. Endpoint security software will be configured to periodically perform an automated full scan of the system, as well as to actively scan incoming and outgoing network traffic (e.g. through email or web browsing) for viruses. Endpoint security software may be omitted from systems that are not commonly affected by malware (e.g. mainframes) based on the SST’s formal, documented risk assessment of those system. 

Routinely review and archive operating system and application server logs. Operating system and application server (e.g. web server, database server, middleware server) logs are regularly reviewed for account creation or modification, unusual account login activity, system restarts, unusual network events, and other hardware or software alarms that may indicate a system fault or malicious activity. All operating system and application logs are archived in accordance with a documented log retention policy. 

Use standardized secure build processes to harden servers, workstations, laptops, and other network devices against attack. SST has policies and procedures in place for building all systems, including servers, workstations, laptops, mobile devices, and network devices, in a manner that hardens them against attacks. Secure build procedures should disable or remove unnecessary network services, applications, and data from systems before placing them into production use. 

Maintain data backup plans to ensure that the data necessary for service delivery can be recovered in the event of a hardware, software, or facilities failure. SST maintains policies, procedures, and systems for data backup and restoration, including routine testing of recovery processes to ensure that systems and data can be properly restored. 

Maintain disaster recovery plan, emergency mode operation plan (down-time operation plan) and testing of disaster recovery plan requirements. To the extent applicable, SST will maintain a documented disaster recovery plan, including emergency mode operation or down time operation plan in place and testing of the plan has been implemented. Testing of disaster recovery plans is performed periodically to ensure their effectiveness, with the interval of testing determined through a risk assessment. 

Access client network using client approved secure remote access. SST agrees to only access the client’s network using client provided solutions. Access should occur on an as needed basis. Remote and onsite access should have access to minimum necessary information. All SST activities while accessing client systems may be monitored by client as decided by the client. 

A world where every procedure advances the next.

One World Trade Center,
New York, NY 10007, USA

20 Queen St W, Toronto,
ON M5H 3R3, Canada

© 2026 Aimbient. All Rights Reserved.

A world where every procedure advances the next.

One World Trade Center,
New York, NY 10007, USA

20 Queen St W, Toronto,
ON M5H 3R3, Canada

© 2026 Aimbient. All Rights Reserved.

A world where every procedure advances the next.

One World Trade Center,
New York, NY 10007, USA

20 Queen St W, Toronto,
ON M5H 3R3, Canada

© 2026 Aimbient. All Rights Reserved.