This Upright Science Master Software-as-a-Service Agreement, together with all applicable Addenda and Order Forms, as defined below, is entered into by and between Upright Science, Inc., a Delaware corporation with an address at 13421 Sabal Chase, West Palm Beach, FL 33418 (“Upright”), and the entity identified as the customer in an Order Form mutually executed by Upright and such entity("Customer"). The following Addenda (or any amendment thereof) constitute a part of, and are incorporated into, this Agreement:
Addendum A: Business Associate Agreement
This Agreement will become binding between Upright and Customer only upon the mutual execution of an Order Form that expressly references and incorporates this Agreement. Upon mutual execution, the applicable Order Form is incorporated into and forms part of this Agreement.
1. Definitions
“Affiliate” means an entity that directly or indirectly controls, is controlled by, or is under common control with, a party to this Agreement. For purposes of the foregoing and Section 2 below, “control” means ownership or the power to dispose of greater than fifty percent (50%) of any outstanding class of equity securities or interests in the subject entity.
“Agreement” means the version of this Upright Science Master Software-as-a-Service Agreement expressly referenced in a mutually executed Order Form, together with all Addenda, Order Forms, amendments, and schedules incorporated into or entered into pursuant to this Agreement.
“Customer” means the entity identified as the customer in the applicable Order Form.
“Customer Data” means all information provided to Upright by Customer via the Software, including (but not limited to) any PII (as hereinafter defined) and PHI (as defined in Addendum A) therein.
“Documentation” means any training or user manuals and other documentation for the Services normally made available electronically to Customer.
“License” means the right and license to access and use the Services in a production, testing, or development setting, for the number of Users specified in the applicable Order Form(s), and for the duration of the applicable Services Term (defined below). Licenses do not extend to any affiliate of Customer or any third party, unless expressly stated in an Order Form executed pursuant to this Agreement.
“Fee” or “Fees” shall mean fees charged for Services ordered by Customer as set forth in the applicable Order Form(s).
“PII” shall mean information that identifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular individual or household. For purposes of this Agreement, PII shall not include business contact information (e.g. name, business phone number, business email address, and business mailing address) of Customer’s personnel. PII shall not include PHI, as that term defined in Addendum A.
“Services” shall mean the hosting and provision of access to the Software to Customer via the Internet as software-as-a-service in accordance with the terms of the applicable Order Form(s) and this Agreement.
“Services Term” shall mean each term of Upright’s provision of the Services, which may be an initial Services Term or any succeeding renewal Services Term. Unless otherwise specified in an Order Form, each Services Term will be one (1) year.
“Software” means the Upright software applications (including without limitation mobile device applications) listed in an Order Form, and any and all updates, modifications, customizations, corrections or enhancements which become part of such software applications, as provided by Upright in accordance with the terms of this Agreement.
“Order Form(s)” means a written or electronic ordering document for the provision of Software and/or Services that: (a) identifies Upright and Customer; (b) expressly references and incorporates this Agreement; and (c) is mutually executed by authorized representatives of Upright and Customer, including through legally valid electronic signatures. Each Order Form will be incorporated into and form part of this Agreement upon mutual execution.
“User” means an individual under the control of Customer whom Customer has issued a personal user ID and password to access and use the Services. User does not mean a corporation, company, partnership, association, entity or organization.
2. License Grant and Restrictions
2.1 License to Services. Subject to the terms and limitations set forth in this Agreement and the applicable Documentation, and provided that Customer timely pays the applicable Fees, Upright grants to Customer a limited, worldwide, non-exclusive, non-transferable right and license (with no right to sublicense) for Users to use the Services listed on a mutually agreed upon Order Form during each Services Term in a production environment. Customer shall be responsible for all acts and omissions of persons who use the Services and Documentation and for ensuring their compliance with this Agreement. Customer shall immediately notify Upright of any loss or unauthorized access or use of a personal user ID or password.
2.2 License to Customer Data. Customer hereby grants to Upright a limited, non-exclusive, non-transferable (except in connection with a permitted assignment of this Agreement), nonsublicenseable (except to Upright’s subcontractors and agents as permitted herein) right and license to collect, process, store, generate, display, modify, transmit, and otherwise use the Customer Data as necessary for Upright to provide the Services and as otherwise authorized by the terms of this Agreement. Notwithstanding the foregoing, Upright’s obligations with respect to its collection, processing, storing, generation, display, modification, transmission, or other use of Protected Health Information subject to Health Insurance Portability and Accountability Act of 1996 under this Agreement are set forth in the Business Associate Agreement attached hereto as Addendum A. Upright shall treat Customer Data as Customer’s Confidential Information subject to the terms of Section 8, below, and maintain Customer Data in accordance with the terms of Section 9, below. Upright shall not (i) sell, rent, release, disclose, disseminate, make available, transfer, or otherwise communicate orally, in writing, or by electronic means, any Customer Data to any third-party for payment to Upright of any monetary or other valuable consideration, or (ii) retain, disclose, or use any Customer Data for any purpose (including any commercial purpose) other than the specific purpose of performing the Services specified in the Agreement and as otherwise authorized by this Agreement and permitted under applicable laws and regulations. Upright hereby certifies that it understands the restrictions described in the previous sentence, and shall comply with them.
2.3 Restrictions.
(a) No Service Bureau Use. Customer may use the Services only for its internal organizational purposes and may not provide outsourcing, service bureau, application service provider or similar services to third parties. For purposes of clarity, “internal organizational purposes” includes Customer’s use of the Services for the purposes of offering insurance quotes to Customer’s clients.
(b) Copies and Modification. Customer may make an unlimited number of copies of the Documentation solely for its internal organizational use. However, Customer may NOT (nor authorize nor permit its employees, agents, independent contractors or any other person or entity to) (A) modify or create derivative works of the Services; (B) distribute, re-sell, sublicense or publicly display or perform the Services or Documentation, any portion thereof, or any materials or information based upon the Services or Documentation; or (C) decompile, disassemble, or reverse-engineer any portion of the Services, otherwise attempt to derive their source code or protocols, or merge or bundle them with any other software, products or services.
2.4 Reservation of Rights. All rights not expressly granted to Customer are reserved by Upright. Customer shall have no rights to receive any source or object code for the Software, nor use the Services or the Software except as expressly set forth in this Agreement.
2.5 No Medical Advice. Customer understands and agrees that Upright is not a health care provider and that the Services, are not a substitute for the advice of a physician or other qualified healthcare provider. Customer further understands and acknowledges that factors beyond the reasonable control of Upright (including without limitation the specific equipment and technology Customer uses in connection with the Software and the physical environment in which the Services are used) could result in the Services producing misleading results. Notwithstanding anything to the contrary, Customer agrees that it shall be solely responsible for any medical advice, diagnoses, treatment recommendations, or any determination related to health or physical ability arising from or related to Customer’s use of the Software or Services Upright shall have no liability whatsoever for any injuries, losses or damages arising from any medical advice, diagnoses, treatment recommendations, or any definitive determination related to health or physical ability arising from or related to Customer’s use of the Software or Services.
2.6 Availability; Support. Upright shall use commercially reasonable efforts make the Services available to Customer, provided that Customer understands and acknowledges that there may be times during which the Services are unavailable. Provided that Customer has paid all Fees then owing to Upright, Upright will provide reasonable remote technical support during its standard support hours to assist Customer in diagnosing and remediating any reported and reproducible errors or outages in the Services. Upright is not responsible for providing support with respect to Customer’s or any third party’s applications, systems or networks, unless otherwise specified in an Order Form.
3. Title
3.1 The Services and Documentation furnished under this Agreement are licensed, not sold, to Customer. Upright solely owns all right, title and interest in and to the Software, the Services, the Documentation, and any copyrights, patents, trademarks, service marks, trade names, trade dress, trade secrets and any other proprietary rights that are associated with the foregoing or otherwise associated with the Services and other related materials of Upright throughout the world, and Customer acknowledges that it receives no right, title or interest to the Services, the Software, or the Documentation, except for the limited rights provided within this Agreement. Upright also retains title to any and all copies made of any embodiments or features of the Services, the Software, and the Documentation, and upon any termination of this Agreement or the applicable Order Form, all such copies must be returned to Upright or destroyed, at Upright’s instruction.
3.2 Customer agrees not to contest Upright’s title and intellectual property rights in or to the Services, the Software, and/or the Documentation.
3.3 All Customer Data, and any other Confidential Information of Customer, together with all intellectual property rights therein, shall remain the sole and exclusive property of Customer. All discoveries, developments, techniques, advice, feedback, suggestions, improvements and similar information relating to the Services or Software or deriving from Upright’s Confidential Information, which are developed or provided in connection with this Agreement shall be the sole property of Upright. Upright shall be the sole owner of all patents, copyrights, and other rights arising therefrom or in connection therewith, and may freely use, sell and exploit the foregoing information without the consent of Customer or any obligation to render an accounting or share profits or royalties. Customer shall provide Upright with reasonable information and feedback concerning the performance and results of its use of the Services as requested by Upright. Without limiting any of the foregoing, and notwithstanding anything in this Agreement to the contrary, Upright may (i) use analytics and metrics derived from the Customer Data and Customer’s use of the Services internally to improve Upright’s products and services, and (ii) retain and use generic, aggregated data which is derived from Customer’s use of the Services, and does not identify Customer in order to provide and improve its Services.
4. Ordering Services
Customer may order Services only through an Order Form mutually executed by authorized representatives of Upright and Customer. An Order Form will be binding on both parties only when executed by authorized representatives of both parties. Each Order Form for Services shall include the following information: the Software ordered, the Fees, the initial Services Term and any renewal Services Terms. No additional or different terms in any Customer purchase order or similar document shall modify or supplement the terms of this Agreement unless such terms are specifically accepted in writing by Upright.
5. Payment
5.1 Fees. The Fees for the Services shall be set forth in the applicable Order Form(s). Software license fees are payable in advance. Fees for each renewal Services Term are due prior to the commencement of such Services Term. Except as otherwise expressly provided herein, all Fees and payments are non-refundable.
5.2 Taxes. Customer shall be responsible for any applicable sales, use, export, customs, value added or similar taxes and duties payable with respect to the provision of the Services and Documentation, or arising out of or in connection with this Agreement, unless such taxes levied or imposed are based upon Upright’s income or gross revenues. If Customer has tax-exempt status, Customer shall provide written evidence of such status to Upright.
5.3 Billing Disputes. Customer must provide Upright with written notice of any disputed charges within thirty (30) days after the invoice date or shall be deemed to have waived its right to dispute charges. If a dispute is submitted on or before the due date for the applicable invoice, Customer agrees to pay the invoiced amount minus the disputed amount on or before the due date. The dispute notice shall set forth in reasonable detail the information concerning the disputed charges and reasons for the dispute.
5.4 General. Customer shall pay all undisputed amounts due under this Agreement to Upright in U.S. dollars within thirty (30) days of receipt of invoice, unless specified otherwise in an Order Form. Upright may charge interest on overdue amounts at the rate of one and one-half percent (1.5%) per month or the highest lawful rate, whichever is greater. Upright may also temporarily suspend or terminate provision of any Services if any Fees or other amounts under this Agreement which have not been timely disputed are overdue and are not paid in full within five (5) days after Upright sends written notice (email sufficing) of the delinquency to Customer.
6. Term of Agreement
This Agreement will begin on the effective date set forth on an applicable Order Form and will continue unless terminated as described herein. The initial Services Term for the Services will begin on the effective date set forth on an applicable Order Form. At the end of the initial Services Term, each Order Form for Services shall automatically renew for successive additional one (1) year Services Terms, at Upright’s then-current pricing for such Services, unless either party notifies the other of its intent not to renew the Order Form at least sixty (60) days prior to the next renewal date. Upright shall notify Customer in writing of any pricing changes for the Services purchased under an Order Form.
7. Termination
7.1 Cause. Either party (the “Terminating Party”) may immediately terminate this Agreement upon written notice to the other in the event that: (i) the other party breaches any material term of this Agreement and such breach is not cured within thirty (30) days after written notice from the Terminating Party; or (ii) upon the other party's dissolution, liquidation, composition, financial reorganization or recapitalization with creditors, assignment for the benefit of creditors, or the appointment of a receiver, trustee, custodian, or similar agent for the party's business or property. In the event that Upright terminates this Agreement for a material breach by Customer, all amounts (with the exception of disputed amounts pursuant to Section 5.3, which may be withheld until rectified by the parties) due under this Agreement or any Order Form, shall immediately become due and payable. Upright shall also have the right to suspend or terminate the Services for non-payment as provided in Section 5.4 above. Finally, Upright may immediately suspend Customer’s access to the Services upon written notice (email sufficing) to Customer if Upright believes in its reasonable discretion that Customer is using the Services to violate applicable legal or regulatory requirements or the rights of a third party; such suspension will continue until Customer furnishes Upright with proof reasonably acceptable to Upright of Customer’s compliance with its legal and regulatory obligations.
7.2 Obligations upon Termination. On any expiration or termination under Section 7.1 or 7.3, except as otherwise expressly provided in an Order Form, all licenses granted under this Agreement shall automatically terminate, and Customer agrees to return to Upright or destroy (at Upright’s instruction) all copies of the Documentation in its possession and provide written certification from an authorized officer of Customer to that effect. Upon termination, regardless of the reason for such termination, (i) Upright shall make the Customer Data available for retrieval for a period of no more than thirty (30) days, after which Upright may delete the data; (ii) Customer shall reimburse Upright for any third party expenses that could not be cancelled and which were incurred by Upright for Customer’s benefit, and Customer shall pay such expenses within forty five (45) days of receipt of Upright’s invoice; and (iii) Upright will deliver to Customer (or, at Customer’s option, dispose of) any Customer materials and equipment in its possession or control, including any copies thereof.
7.3 Survival. In addition to those provisions which by their nature are intended to survive any termination or expiration of this Agreement or any license granted hereunder, (including this Section 7.4), Sections 2(b) (Restrictions), 3 (Title), 5 (Payment), 8 (Confidentiality), 11 (Indemnification and Infringement) and 12 (Limitation of Warranty and Liability) of this Agreement shall specifically survive such termination or expiration.
8. Confidentiality
Each party (as the “receiving party”) agrees not to permit access to or to disclose the other party’s (the “disclosing party”) Confidential Information, except to the receiving party’s authorized employees and contractors who are bound by confidentiality agreements with terms no less restrictive than those of this Section 8 and who need to use or have access to the disclosing party’s Confidential Information for the purposes contemplated by this Agreement, and to only use the other party’s Confidential Information solely to the extent necessary to fulfill its obligations under this Agreement. A receiving party shall use at least the same degree of care in protecting the disclosing party’s Confidential Information as such receiving party generally exercises in protecting its own most valuable proprietary information and shall inform its employees and contractors having access to the disclosing party’s Confidential Information of its confidential nature. In no event shall a receiving party use less than a commercially reasonable degree of care in protecting the disclosing party’s Confidential Information. “Confidential Information” includes documents, data, software and information which, when provided by the disclosing party to the receiving party: (i) are clearly identified as “Confidential” or “Proprietary” or are marked with a similar legend; (ii) are disclosed orally or visually, and identified as Confidential Information at the time of disclosure and confirmed as Confidential Information in writing within ten (10) business days; or (iii) a reasonable person would understand to be confidential or proprietary at the time of disclosure. The Software, Services and Documentation, as well as results of benchmark and other tests run by either party and resulting from use of the Software or Services, shall be deemed Upright Confidential Information without any need for any markings or legends, and in addition to the other restrictions in this Section 8, shall not be disclosed to any competitor of Upright. Customer Data shall be deemed Customer’s Confidential Information. All of the disclosing party’s Confidential Information is and will remain the sole and exclusive property of the disclosing party. Neither this Agreement nor any disclosure hereunder will be deemed, by implication or otherwise, to vest in the receiving party any license, interest, or ownership rights of any kind to or under any of the disclosing party’s Confidential Information, including, without limitation, inventions, patents, know-how, trade secrets, trademarks, copyrights, or other intellectual property rights owned or controlled by the disclosing party or its Affiliates, except as otherwise provided in this Agreement. Notwithstanding the foregoing, the receiving party shall have no obligation of confidentiality with respect to any information which the receiving party can demonstrate by written documentation: (a) is already known to the receiving party at the time of disclosure; (b) is or subsequently becomes publicly available through no wrongful act of the receiving party; (c) is disclosed or provided to the receiving party by a third party without restriction and without having violated any confidentiality agreement of any party; or (d) is developed independently by the receiving party without use of or access to the disclosing party’s Confidential Information. In addition, either party may disclose Confidential Information of the other to the extent required by law or a judicial or regulatory order; provided, however, that the party subject to the requirement furnishes the other party with as much advance written notice as possible under the circumstances and cooperates with its efforts to obtain a suitable protective order. If such an order is not obtained, or the party owning the information waives the non-disclosure obligation, the other party may disclose that portion of the Confidential Information which, based on the advice of counsel, is subject to the judicial, legal or regulatory disclosure requirement. Each party shall promptly notify the other of any suspected unauthorized access, use, disclosure, alteration or loss of the other party’s Confidential Information and shall cooperate with such other party’s reasonable requests in connection with investigating and remediating any such incident.
9. Security
9.1 Information Security. Without limiting Upright’s obligations of confidentiality as further described herein, Upright shall be responsible for establishing and maintaining a data privacy and information security program, including physical, technical, administrative, and organizational safeguards, that is designed to: (i) ensure the security and confidentiality of the Customer Data; (ii) protect against any anticipated threats or hazards to the security or integrity of the Customer Data; (iii) protect against unauthorized disclosure, access to, or use of the Customer Data; (iv) ensure the proper disposal of Customer Data; and (v) ensure that all employees, agents, and subcontractors of Upright, if any, comply with all of the foregoing.
9.2 Security Breaches. Upright shall notify Customer in writing (email sufficing) of a Security Breach within a commercially reasonable time after Upright first becomes aware of any unauthorized access to, or destruction, use or disclosure of Customer Data (except for PHI) (each such event, a “Security Breach”). For the avoidance of doubt, Upright’s obligations in the event of a Breach or Security Incident (as each is defined in Addendum A) shall be set forth in Addendum A.
10. Warranty, Remedy and Restrictions
10.1 Upright Warranties. Upright represents and warrants to Customer that:
(a) Upright has the legal power and authority to enter into this Agreement;
(b) the Services, as delivered by Upright to Customer, will substantially conform to the specifications as described in their then current Documentation during each Services Term (the “Functional Warranty”); and
(c) Upright will use commercially reasonable efforts (including industry-standard anti-malware and/or anti-virus measures) designed to ensure that the Software will be free of any viruses, Trojan horses, or other malicious code.
10.2 Customer Warranty. Customer represents and warrants to Upright that: (i) it has the legal power and authority to enter into this Agreement; (ii) the provision of all Customer Data to Upright hereunder is in compliance with Customer’s privacy policies and all applicable legal and regulatory requirements; (iii) the Customer Data, and the use thereof by Upright in accordance with this Agreement, does not infringe upon or violate the rights of any third party; (iii) Customer has obtained all permissions and consents from Users as may be required for Customer’s usage of the Services, and Customer will provide Upright with evidence of any such required permissions or consents upon Upright’s reasonable written request, (iv), to the extent that Customer is a healthcare provider or is otherwise providing medical advice, it (and its employees and agents) has all appropriate and necessary licenses, permits, and other applicable rights and permissions to do so, and (v) to the extent patient consent with respect to the Services should be obtained pursuant to best practices, ethical obligations, or legal requirement, Customer has obtained such patient consents, and Customer will provide Upright with evidence of any such required patient consents upon Upright’s reasonable written request.
10.3 Functional Warranty Remedy. As Upright’s sole liability and Customer’s sole and exclusive remedy for any breach of the Functional Warranty, upon receipt of Customer’s written notice specifying the non-conformity, Upright shall use diligent efforts to remediate any material non-conformities in the Services within a commercially reasonable time period. Notwithstanding the foregoing, Upright shall not be responsible for any defects or non-conformities of the Services that arise from (i) Customer’s misuse of Services or breach of this Agreement, (ii) any modification of Services by a person or entity other than Upright or its authorized subcontractors, (iii) Customer’s failure to maintain minimum technology standards for use of the Services as specified by Upright from time to time, or (iv) an event of Force Majeure as provided in Section 13.5 below. Additionally, Upright shall not be obligated to remedy any failure or defect in the Services that cannot be adequately repeated.
11. Indemnification and Infringement
11.1 Indemnification.
(a) Upright Indemnity. Upright shall defend, indemnify, and hold harmless Customer and its Affiliates from and against any out-of-pocket costs, damages, losses, or penalties (including reasonable attorney’s fees) (collectively, “Losses”) incurred in connection with any third party claim, demand, or proceeding (a “Claim”) arising from any infringement by the Software of any United States patent, copyright, trademark, or other United States intellectual property right of a third party.
(b) Customer Indemnity. Customer shall defend, indemnify, and hold harmless Upright and its Affiliates from and against any Losses incurred in connection with any Claim arising from (i) a breach of Customer’s representations and warranties in this Agreement; (ii) the Customer Data, (iii) any Claim(s) related to Customer’s use of the Software or Services, or (iv) Customer’s gross negligence or willful misconduct.
(c) Mutual Indemnity. Each party (the “indemnifying party”) shall defend, indemnify, and hold harmless the other party and its Affiliates (the “indemnified party”) from and against any Losses incurred in connection with any Claim arising from the indemnifying party’s violations of law or regulation applicable to the indemnifying party’s business.
(d) Further Infringement Obligations. Should the Software become, or in Upright's opinion likely to become, the subject of a claim of infringement or trade secret misappropriation, Upright shall, at its option and expense, either: (i) procure for Customer the right to continue to use the allegedly infringing Software (or portion thereof), or (ii) replace or modify the infringing Software (or portion thereof) to make its use non-infringing without loss of substantial functionality. Notwithstanding the foregoing, if Upright, in its sole discretion, determines that neither of the said options is reasonably available to it, Upright, at its option, may terminate Customer’s license for the allegedly-infringing Software (or portion thereof), in which event Upright shall refund to Customer a prorated portion of the annual Fee paid by Customer for the applicable Software (or portion thereof) during the then-current Services Term. The infringement indemnification remedies provided herein shall be Upright’s sole liability, and Customer’s sole and exclusive remedy, for any claims or allegations relating to intellectual property infringement or misappropriation.
(e) Infringement Exclusions. Notwithstanding the foregoing, Upright shall have no liability or obligation to Customer with respect to any Claim based on (i) use of the Software by Customer in combination with other business processes, products, devices, software, services or components which were not furnished to Customer by Upright or included with the Software, or which were not explicitly approved in writing by Upright, if the infringement would not have occurred but for the combination; (ii) modification or alteration of the Software by Customer or its agents, if the infringement would not have occurred but for the modification or alteration; (iii) use of the Software after Upright notifies Customer, pursuant to Section 11.1(c) above, to discontinue use of the Software due to a claim, allegation or proceeding; (iv) use of the Software by other than authorized Users; or (v) use of the Software for a purpose other than that for which they were designed or in violation of this Agreement.
11.2 Indemnification Process. An indemnified party shall promptly provide the indemnifying party with written notice of any claim for which it seeks indemnification hereunder, and the indemnifying party shall have the right to assume the defense thereof; provided, however, that failure of the indemnified party to provide such notice will not release the indemnifying party from any of its indemnity obligations except to the extent that the indemnifying party’s ability to defend such claim is materially prejudiced by such delay. The indemnifying party shall not settle or compromise any such claim without the full release of the indemnified party from all liabilities and obligations (except for any obligations that the indemnified party has consented to in writing), and such settlement shall not impose any obligation on the indemnified party (including the payment of any amount) without the prior written consent of the indemnified party. The indemnifying party shall also not admit liability or wrongdoing on behalf of an indemnified party without the indemnified party’s prior written consent. Each party shall have the right to participate, at its expense, in the defense of any claim covered hereunder with counsel of its own choosing.
12. Limitation of Warranty and Liability
12.1 Warranty Limitations. EXCEPT FOR THE EXPRESS WARRANTIES SET FORTH IN SECTION 10 OR AN ADDENDUM, NEITHER PARTY MAKES ANY OTHER EXPRESS OR IMPLIED WARRANTIES OF ANY KIND AND EACH PARTY HERETO SPECIFICALLY DISCLAIMS AND EXCLUDES ALL OTHER REPRESENTATIONS OR WARRANTIES, EXPRESS OR IMPLIED, STATUTORY OR OTHERWISE, INCLUDING WITHOUT LIMITATION, ANY WARRANTY RELATING TO MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, NON-INFRINGEMENT, SECURITY, FREEDOM FROM VIRUSES OR OTHER HARMFUL CODE, UPTIME, OR UNINTERRUPTED OR ERROR-FREE OPERATION; ANY IMPLIED WARRANTY ARISING FROM COURSE OF PERFORMANCE, COURSE OF DEALING, OR USAGE OF TRADE; OR ANY STATUTORY REMEDY. NO STATEMENT WHETHER MADE BY EITHER PARTY HERETO OR ITS EMPLOYEES, AGENTS OR OTHERWISE SHALL BE DEEMED TO BE A WARRANTY BY SUCH PARTY FOR ANY PURPOSE OR TO GIVE RISE TO ANY LIABILITY ON THE PART OF SUCH PARTY.
12.2 Exclusion of Consequential and Related Damages. EXCEPT FOR THE PARTIES’ INDEMNIFICATION OBLIGATIONS IN THIS AGREEMENT, A PARTY’S INTENTIONAL BREACH OF ITS CONFIDENTIALITY OBLIGATIONS UNDER SECTION 8, A PARTY’S WILLFUL MISCONDUCT OR A BREACH BY CUSTOMER OF ANY LICENSE RESTRICTIONS IN THIS AGREEMENT, IN NO EVENT WILL EITHER PARTY BE LIABLE TO THE OTHER UNDER THIS AGREEMENT OR OTHERWISE FOR ANY INCIDENTAL, SPECIAL, PUNITIVE OR CONSEQUENTIAL DAMAGES, LOSS OF PROFITS, LOSS OF DATA OR USE OF DATA, OR INTERRUPTION OF BUSINESS OR OPERATIONS, EVEN IF SUCH PARTY OR ITS REPRESENTATIVE HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH LOSS.
12.3 Limitation of Liability. EXCEPT AS OTHERWISE SET FORTH IN SECTION 12.4, BELOW, REGARDING LIABILITY ARISING UNDER SECTION 9, AND EXCEPT FOR THE PARTIES’ INDEMNIFICATION OBLIGATIONS IN THIS AGREEMENT, CUSTOMER’S PAYMENT OBLIGATIONS UNDER THIS AGREEMENT, A PARTY’S INTENTIONAL BREACH OF ITS CONFIDENTIALITY OBLIGATIONS UNDER SECTION 8, A PARTY’S WILLFUL MISCONDUCT OR A BREACH BY CUSTOMER OF ANY LICENSE RESTRICTIONS IN THIS AGREEMENT, IN NO EVENT WILL THE AGGREGATE LIABILITY OF EITHER PARTY ARISING OUT OF OR RELATED TO THIS AGREEMENT, FOR ANY AND ALL CLAIMS, AND WHETHER IN CONTRACT, TORT OR UNDER ANY OTHER THEORY OF LIABILITY, EXCEED THE FEES PAID UNDER THE APPLICABLE ORDER FORM FOR THE SERVICES TO WHICH THE CLAIM(S) RELATE DURING THE TWELVE (12) MONTH PERIOD PRECEDING THE LATEST EVENT(S) GIVING RISE TO SUCH CLAIM(S).
12.4 Special Limitation of Liability. NOTWITHSTANDING ANY OTHER PROVISION OF THIS AGREEMENT TO THE CONTRARY, IN NO EVENT SHALL UPRIGHT’S TOTAL AGGREGATE LIABILITY ARISING FROM OR RELATED TO (i) SECURITY BREACHES OR OTHER INFORMATION SECURITY-RELATED ISSUES, OR (ii) ANY LIABILITY ARISING UNDER THE BUSINESS ASSOCIATE AGREEMENT ATTACHED HERETO AS ADDENDUM A, WHETHER IN CONTRACT, TORT OR UNDER ANY OTHER THEORY OF LIABILITY, EXCEED A TOTAL OF $250,000. IF SUCH DAMAGES INCLUDE THE COST OF CONSUMER NOTIFICATION OR CREDIT MONITORING, UPRIGHT SHALL BE LIABLE FOR SUCH DAMAGES (SUBJECT TO THE FOREGOING LIMITATION) ONLY IF SUCH NOTICE OR CREDIT MONITORING IS REQUIRED BY APPLICABLE LAW OR REGULATION. FOR THE AVOIDANCE OF DOUBT, THIS SECTION 12.4 ESTABLISHES UPRIGHT’S MAXIMUM AGGREGATE LIABILITY IN THE EVENT OF A SECURITY BREACH.
12.5 Material Part of Agreement. Customer agrees that the disclaimer of warranties and limitations of liability in this Section 12 are a material inducement and consideration for Upright to enter into this Agreement and provide the Services and related materials at their current pricing. Accordingly, such provisions shall be enforced as written even if a remedy fails of its essential purpose.
13. General
13.1 Governing Law. This Agreement and any claim, controversy or dispute arising under or related to this Agreement shall be governed in all respects by the laws of the State of Delaware, without giving effect to principles of conflicts of laws. The United Nations Convention for the International Sale of Goods shall not apply to this Agreement. Any controversy or dispute arising under or related to this Agreement shall be adjudicated in the state and federal courts in and for New Castle County, Delaware (including their applicable appellate courts), and each party consents to the exercise of jurisdiction and venue by such courts; provided, however, that either party may seek temporary or emergency injunctive relief in any court of competent jurisdiction to protect and preserve its rights in its intellectual property and Confidential Information.
13.2 Notices. All notices or reports shall be in writing and shall be delivered by personal delivery, facsimile transmission, e-mail (when explicitly permitted by this Agreement), overnight mail or by certified or registered mail, return receipt requested, and shall be deemed given upon personal delivery, five days after deposit in the mail, or upon acknowledgment of receipt of electronic transmission. Notices shall be sent to the respective addresses set forth in the applicable Order Form or to such other address as a party may subsequently designate by notice in accordance with this Section 13.2.
13.3 No Agency. The parties to this Agreement are independent contractors and nothing in this Agreement shall be deemed to create a joint venture, partnership, or agency relationship between the parties in this Agreement.
13.4 Injunctive Relief. Each party acknowledges that its breach of Sections 2, 3 or 8 of this Agreement will cause the other party immediate and irreparable damage for which recovery of money damages would be inadequate. Therefore, each party agrees that the other party shall be entitled to seek injunctive relief to protect its rights under Sections 2, 3 and 8 of this Agreement (in addition to any other remedies available to said party) without the necessity of posting bond.
13.5 Force Majeure. Neither party shall be liable to the other, following notice thereof, for any failure or delay in the performance of its obligations (except for Customer’s payment obligations hereunder) for any cause that is beyond the reasonable control of such party, including, without limitation, acts of God, shortages of supplies, labor or materials, strikes and other labor disputes, storms, floods, acts of war or terrorism, third-party hacking and other criminal or malicious activities, failures of third-party hardware, software or networks, utility brown-outs, failures of telecommunications or the Internet, quarantine or stay-at-home or shelter-in-place orders, pandemics, epidemics, outbreak of disease (including, but not limited to, COVID-19) or public health crises, and actions by a governmental authority (such as changes in government codes, ordinances, laws, rules, regulations, or restrictions).
13.6 Waiver. If one party fails to enforce a provision of this Agreement, it shall not be precluded from enforcing the same provision at another time.
13.7 Severability. If any provision of this Agreement is deemed unenforceable or invalid by law or by a court decision, the provision shall be changed and interpreted if possible to accomplish the intent of the provision within the constraints of the law. Only that provision that is deemed unenforceable or invalid, and not the entire Agreement, shall be invalidated.
13.8 Assignment. Neither party may assign this Agreement or its rights hereunder without the prior written consent of the other party; provided, however, that each party may assign this Agreement without consent to (i) an Affiliate, or (ii) a successor (by merger, consolidation, purchase of assets or otherwise) to substantially all of the assigning party’s assets or business. Upright may also, without notice, utilize subcontractors and agents to perform aspects of the Services, provided, however, that Upright shall remain primarily responsible for compliance with its obligations under this Agreement. Upright shall obtain and maintain in effect a written agreement with the subcontractor/agent which agreement shall contain sufficient terms for Upright to comply with all provisions of this Agreement; however, nothing contained in any such agreement shall create, nor represent to create, a contractual relationship between Customer and any subcontractor/agent. Upright’s agreements with its subcontractor/agent must impose an obligation of confidentiality (consistent with the terms of this Agreement) on the subcontractor/agent with respect to Customer’s Confidential Information. Upright shall be fully responsible for the acts of all subcontractors and agents to the same extent it is responsible for the acts of its own employees.
13.9 No Conflicting Terms. Upright shall not accept, and this Agreement does not operate as an acceptance of, any different or additional terms and conditions, and this Agreement shall prevail over any such different or additional provisions of any Customer order or any other Customer originated instruments.
13.10 Entire Agreement. This Agreement supersedes all previous agreements, whether oral or written, with respect to its subject matter.
13.11 Order of Precedence. In the event of any inconsistencies between the main body of this Agreement and any Addendum or Order Form, the conflict shall be resolved in the following order of priority (in order of most to least precedential): (i) Order Form, (ii) the main body of this Agreement, and (iii) an Addendum.
13.12 Export Compliance. Regardless of whether Customer is a US-based entity, Customer shall not export or re-export any of the Services or Documentation (in whole or in part) to any country without ensuring that such export complies with the Export Administration Regulations of the U.S. Department of Commerce, or any other agency of the U.S. Government, or similar laws governing the export of software or products of any other government having jurisdiction over such export, re-export, or use, pursuant to any applicable statute, regulation, or governmental order. Customer agrees to remain at all times and to its knowledge in full compliance with U.S. Government export policy and regulations and failure of such compliance shall constitute a material breach of this Agreement.
13.13 Press Release. Neither party may use the other party’s name or company artwork (for example, logo) on a website or in any form of advertising, promotion or publicity, including press releases, without the prior written consent of the other party.
13.14 Modifications. Upright reserves the right to modify this Agreement for any reason. Customer should look at this Agreement regularly and the “Last Updated” date at the beginning of the document and applicable addenda thereto. Upright will use reasonable efforts to give Customer notice of modifications, such as posting notice of modifications on this web page. By continuing to use the Services and/or Software after Upright makes these modifications, Customer agrees that it will be subject to the Agreement as modified with respect to Order Forms entered into on or after the date of the modification; however, Upright will not apply modifications to the Agreement retroactively to Order Forms entered into before the date of the modification unless Customer affirmatively consents. Except as otherwise expressly provided in this Section 13.14, no modifications to the Agreement shall be valid unless made in writing and signed by a duly authorized representative of Customer and by Upright, and neither the acquiescence in any performance at variance to the provisions of this Agreement nor the failure to exercise any right or enforce any obligation hereunder shall be deemed a modification of this Agreement.
Addendum A. Business Associate Agreement
This Addendum A (the “BAA”), along with the terms of this Agreement into which it is incorporated by reference, will govern the use and safeguarding by Upright of any PHI (as defined below) provided by Upright to Customer.
1. Definitions
1.A For the purposes of this BAA, all capitalized terms not defined herein shall have the meanings defined in the Agreement or the HIPAA Rules (as may be amended from time to time), as applicable.
1.B “Business Associate” shall generally have the same meaning as the term “business associate” at 45 C.F.R. § 160.103, and in reference to this BAA, shall mean Upright.
1.C “Breach” shall mean the unauthorized acquisition, access, use, or disclosure of Unsecured PHI that compromises the security or privacy of such information. A Breach shall not include: (1) any unintentional acquisition, access, or use of PHI by a
1.D Workforce member or person acting under the authority of Covered Entity, Business Associate, or Subcontractor if such acquisition, access, or use was made in good faith and within the scope of authority, and the PHI was not further acquired, accessed, used, or disclosed; (2) any inadvertent disclosure by a person who is authorized to access PHI at Covered Entity, Business Associate, or Subcontractor to another person authorized to access PHI at the same entity, or at an organized health care arrangement in which Covered Entity participates, and the information received as a result of such disclosure is not further acquired, accessed, used, or disclosed; or (3) a disclosure of PHI where Covered Entity or Business Associate has a good faith belief that an unauthorized person to whom the disclosure was made would not reasonably have been able to retain such information.
1.E “Covered Entity” shall mean Customer.
1.F “Electronic Protected Health Information” (“EPHI”) is PHI that is maintained in electronic media or transmitted by electronic media. EPHI is a subset of PHI.
1.G “HIPAA” shall mean, collectively, the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), as amended by the Health Information Technology for Economic and Clinical Health Act of 2009 (the “HITECH Act”), and their associated regulations, specifically, 45 CFR §§ 160, 162 and 164, Standards for Privacy of Individually Identifiable Health Information, Final Rule (the “Privacy Rule”) and Health Insurance Reform: Security Standards, Final Rule (the “Security Rule”).
1.H “HIPAA Rules” shall mean the Privacy, Security, Breach Notification, and Enforcement Rules at 45 CFR §§ 160, 162 and 164.
1.I “Information System” shall mean an interconnected set of information resources under the same direct management control that shares common functionality. A system normally includes hardware, software, information, data, applications, communications, and people.
1.J “Protected Health Information” (“PHI”) shall have the meaning given to such term in 45 C.F.R. § 160.103, limited to the information created or received by Business Associate from or on behalf of Covered Entity.
1.K “Security Incident” shall mean the attempted or successful unauthorized access, use, disclosure, modification, or destruction of information or interference with system operations in an information system.
1.L “Unsecured PHI” means PHI that is not rendered unusable, unreadable, or indecipherable to unauthorized individuals through the use of a technology or methodology specified by the Secretary of the U.S. Department of Health and Human Services (“Secretary”) in the guidance issued under section 13402(h)(2) of the HITECH Act.
1.M “Workforce” shall mean employees, volunteers, trainees, and other persons whose conduct, in the performance of work for Covered Entity, Business Associate or Subcontractor, is under the direct control of such entity, whether or not they are paid by Covered Entity, Business Associate or Subcontractor.
2. Term and Termination
2.A Term. The Term of this BAA shall be effective as of the effective date set forth on an applicable Order Form and shall terminate when all of the PHI provided by Covered Entity to Business Associate, or created or received by Business Associate on behalf of Covered Entity, is destroyed or returned to Covered Entity, or, if it is infeasible to return or destroy PHI, protections are extended to such information, in accordance with the termination provisions of this Section 2.
2.B Termination. Business Associate authorizes termination of this BAA by Covered Entity upon Covered Entity’s knowledge of a material breach by Business Associate. Upon violation of a material term of this BAA by Business Associate, Covered Entity may either:
2.B.1 Provide a fifteen (15) day opportunity for Business Associate to cure the material breach or end the violation and, if Business Associate does not cure the material breach or end the violation within the fifteen (15) day period, Covered Entity may terminate this BAA and the Agreement;
2.B.2 If Business Associate has breached a material term of this BAA and cure is not, in Covered Entity’s reasonable determination, possible, Covered Entity may immediately terminate this BAA and the Agreement; or
2.B.3 If neither termination nor cure are, in Covered Entity’s sole determination, feasible, Covered Entity shall report the violation to the Secretary.
2.C Except as provided in paragraph 2.C.1 below of this Section, upon termination of this BAA for any reason, Business Associate shall return or destroy all PHI received from Covered Entity, or created or received by Business Associate on behalf of Covered Entity. This provision shall also apply to PHI that is in the possession of subcontractors or agents of Business Associate. Neither Business Associate nor any subcontractor or agent of Business Associate shall retain copies of the PHI.
2.C.1 If Business Associate reasonably determines that returning or destroying the PHI is infeasible (such as in the event that retention of PHI is required for archival purposes to evidence the Services provided), Business Associate may retain the PHI that is not feasible to return for so long as it remains infeasible to return such PHI. In such event, Business Associate shall extend the protections of this BAA to such PHI and limit further uses and disclosures of such PHI to those purposes that make the return or destruction infeasible, for so long as Business Associate maintains such PHI.
2.C.2 The provisions of this Section 2.C shall survive termination of this BAA.
3. Obligations of Business Associate
3.A Business Associate shall comply with the use and disclosure provisions of the Privacy Rule in performing its obligations under any agreement for services with Covered Entity and to not use or disclose Covered Entity’s PHI other than as permitted or required under this BAA or as Required by Law.
3.B Business Associate shall implement and use appropriate safeguards to prevent use or disclosure of Covered Entity’s PHI other than as provided for by this BAA.
3.C Business Associate shall implement administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of EPHI that it creates, receives, maintains, or transmits on behalf of Covered Entity, and to otherwise comply with the Security Rule in performing Business Associate’s obligations under this BAA.
3.D Business Associate shall mitigate, to the extent practicable, any harmful effect that is known to Business Associate of a use or disclosure of Covered Entity’s PHI by Business Associate in violation of the requirements of this BAA.
3.E Business Associate shall, as soon as reasonably practicable and in no event later than fifteen (15) days of discovery of the same, report to Covered Entity any use or disclosure of Covered Entity’s PHI not provided for by this BAA of which it becomes aware, including, but not limited to, any Security Incident (not including unsuccessful Security Incidents such as general “pinging” or “denial of service attacks” that are not determined to have been directed at Covered Entity’s EPHI) and any unauthorized acquisition, access, use, or disclosure of Covered Entity’s PHI.
3.F Business Associate shall, following the discovery of a Breach of Covered Entity’s PHI, notify Covered Entity of such Breach.
3.F.1 Business Associate shall provide initial notice of the Breach as soon as reasonably practicable and in no event later than ten (10) days after the discovery of the Breach. A Breach shall be treated as discovered as of the first day on which the Breach is known to the Business Associate.
3.F.2 The initial notice shall include, to the extent possible, the identification of each individual whose PHI has been, or is reasonably believed by the Business Associate to have been, accessed, acquired, or disclosed during such Breach. Business Associate shall make best efforts to collect and provide to Covered Entity as soon as possible any such information that Business Associate is unable to provide in the initial notice.
3.G Business Associate shall, following notification to Covered Entity of a Breach of PHI, cooperate with Covered Entity in providing any and all information required for Covered Entity to comply with the breach notification provisions of section 13402 of the HITECH Act and the implementing regulations set forth in Subpart D of the Privacy Rule (45 C.F.R. § 164.400 et seq.) and any other applicable breach notification laws and regulations of which Business Associate is informed of by Covered Entity.
3.H Business Associate shall enter into legally binding agreements with each of its subcontractors and agents to ensure that any subcontractor agent to whom Business Associate provides PHI received from, or created or received by, Business Associate on behalf of Covered Entity agrees to the same restrictions and conditions that apply through this BAA to Business Associate with respect to such information.
3.I For purposes of the Secretary determining Covered Entity's compliance with the Privacy Rule and Security Rule, Business Associate shall make available to the Secretary, in a time and manner designated by the Secretary, its internal practices, books, and records (including policies and procedures), relating to the use and disclosure of PHI received from, or created or received by, Business Associate on behalf of Covered Entity.
3.J Business Associate agrees to provide access to Covered Entity, in the time and manner designated by the Covered Entity, to Covered Entity’s PHI in a Designated Record Set, or, as directed by Covered Entity, to an Individual in order to meet the requirements of 45 C.F.R. § 164.524.
3.K Business Associate agrees to make any amendment(s) to Covered Entity’s PHI in a Designated Record Set that the Covered Entity directs or agrees to pursuant to 45 C.F.R. § 164.526 at the request of Covered Entity or an Individual, and in the time and manner designated by the Covered Entity.
3.L Business Associate shall document such disclosures of Covered Entity’s PHI and information related to such disclosures as would be required for Covered Entity to respond to a request by an Individual for an accounting of disclosures of PHI in accordance with the Individual’s right to receive such accounting under 45 C.F.R. § 164.528.
3.M Business Associate shall provide to Covered Entity or an Individual, information collected in accordance with Section 3.L of this BAA, to permit Covered Entity to respond to a request by an Individual for an accounting of disclosures of PHI in accordance with the Individual’s right to receive such accounting under 45 C.F.R. § 164.528.
3.N Business Associate is required to comply with an Individual’s restriction request, except as otherwise required by law, if it is to a health plan for payment or health care operations and pertains to a health care item or service for which the health care provider was paid in full “out of pocket” by the Individual.
3.O Business Associate and its agent(s) and subcontractor(s) are prohibited from directly or indirectly receiving any remuneration in exchange for an individual’s PHI unless the Individual provides a valid authorization.
4. Obligations of Covered Entity
4.A In addition to any other obligation set forth in this BAA, Covered Entity agrees that it will: (i) not make any disclosure of PHI to Business Associate if such disclosure would violate HIPAA, the HITECH Act or any applicable federal or state law or regulation; and (ii) not request Business Associate to use or make any disclosure of PHI in any manner that would not be permissible under HIPAA, the HITECH Act or any applicable federal or state law or regulation if such use or disclosure were done by Covered Entity.
4.B Covered Entity shall notify Business Associate of any limitation(s) in Covered Entity’s notice of privacy practices, to the extent that such limitation may affect Business Associate’s use or disclosure of PHI.
4.C Covered Entity shall notify Business Associate of any changes in, or revocation of, permission by an individual to use or disclose PHI, to the extent that such changes may affect Business Associate’s use or disclosure of such PHI.
4.D Covered Entity shall notify Business Associate of any restriction to the use or disclosure of PHI to which Covered Entity has agreed and thus Business Associate is bound, to the extent that such restriction may affect Business Associate’s use or disclosure of PHI.
5. Permitted Uses and Disclosures by Business Associate
5.A Except as otherwise limited by this BAA, Business Associate may use PHI for the proper management and administration of the Business Associate or to carry out the legal responsibilities of the Business Associate.
5.B Except as otherwise limited by this BAA, Business Associate may disclose PHI for the proper management and administration of the Business Associate, provided that disclosures are Required By Law, or Business Associate obtains reasonable assurances from the person to whom the information is disclosed that it will remain confidential and be used or further disclosed only as Required By Law or for the purpose for which it was disclosed to the person, and the person notifies the Business Associate of any instances of which it is aware in which the confidentiality of the information has been breached.
5.C Except as otherwise limited by this BAA, Business Associate may use PHI to provide Data Aggregation services to Covered Entity as permitted by 45 C.F.R. § 164.504(e)(2)(i)(B).
5.D Business Associate may use PHI to report violations of law to appropriate Federal and State authorities, consistent with 45 C.F.R. § 164.502(j)(1).
6. Notice
Whenever, under the terms of this BAA, written notice is required or permitted to be given by one Party to the other Party, such notice shall be governed by the Agreement with the exception of Notice required under Sections 3.E and 3.F of this BAA regarding unauthorized disclosure of PHI or a Breach. Such notice shall initially be given via electronic mail to Covered Entity at the email address identified Customer in the applicable Order Form. Such Notice shall also be followed by overnight delivery of written Notice.
7. Miscellaneous
7.A This BAA sets forth the entire understanding and agreement between the parties relating to the use and disclosure of PHI and shall be binding upon the parties and their respective successors, heirs and assigns. All prior negotiations, agreements, and understandings regarding the use and disclosure of PHI are superseded hereby.
7.B The parties agree to take such action as is necessary to amend this BAA from time to time as is necessary for the parties to comply with the requirements of HIPAA/HITECH, as may be amended from time to time.
7.C This BAA shall be automatically assigned to and assumed by any legal successor or affiliate of the assignor who or which assumes responsibility for assignor’s obligations under any agreement between the parties concerning the services provided by Business Associate for or on behalf of Covered Entity.
7.D This BAA shall be construed and enforced pursuant to the laws of the Delaware.
7.E The invalidity or unenforceability of any particular provision or part thereof of this BAA shall not affect the remainder of this BAA, and this BAA shall be construed in all respects as if such invalid or unenforceable provision or part thereof had been omitted.
7.F This BAA shall not create nor be deemed to create any relationship between Covered Entity and Business Associate other than that of independent contractors contracting with each other solely for the purpose of performing the agreement pursuant to which Business Associate provides the Services to Covered Entity. Neither Covered Entity nor Business Associate shall assume or be responsible for the acts, omissions, liabilities, debts, or other obligations of the other party, other than as specifically set forth in this BAA and the agreement pursuant to which Business Associate provides the Services to Covered Entity.
7.G Any failure or delay by either party in exercising any right under this BAA shall not operate as a waiver of such party’s rights, nor shall any single or partial exercise of any right serve to preclude a subsequent exercise of such right.
7.H Any ambiguity in this BAA shall be resolved to permit Covered Entity and Business Associate to comply with the HIPAA/HITECH.
7.I Notwithstanding anything to the contrary in this BAA, nothing herein shall be construed to require Business Associate to take any action, the consequence of which could reasonably be foreseen to result in the waiver or loss of any legal right or ethical obligation of either Covered Entity or Business Associate to keep any information confidential.
7.J This BAA is incorporated into and accepted together with the Agreement and does not require a separate signature. Electronic acceptance of the Agreement or an applicable Order Form that identifies or incorporates this BAA constitutes execution and acceptance of this BAA by Customer and Upright.