Platform Agreement

The terms governing your use of the CrisisCommand platform.

Reference copy

This document is published for reference so prospective customers and procurement teams can review our standard terms. The operative version for any given customer is the one attached to and executed with their signed Order Form. Where the two differ, the executed version governs.

Platform Agreement

CrisisCommand, Inc.

Last updated: July 21, 2026


1. IMPORTANT TERMS

1.1 This Platform Agreement (the “Platform Agreement”) is between CrisisCommand, Inc., a Texas corporation (“CrisisCommand,” “we,” “us,” or “our”), and the entity identified on the applicable Order Form (“Customer”), and governs Customer’s use of the Service. The individual accepting these terms on behalf of Customer represents and warrants that they have the authority to bind Customer.

1.2 Structure of the Agreement. The Order Form is the operative signed document between the parties. This Platform Agreement is incorporated into the Order Form by reference, and this Platform Agreement in turn incorporates by reference: (i) the Acceptable Use Policy; (ii) the Support and Service Level Terms; (iii) the Data Processing Addendum; and (iv) where the parties execute one, any Addendum attached to the Order Form. Together, the Order Form and all documents incorporated by reference constitute the “Agreement.”

1.3 Order of Precedence. In the event of a conflict, the following order of precedence applies: (i) any Addendum executed with the Order Form; (ii) the Order Form; (iii) the Data Processing Addendum; (iv) this Platform Agreement; and (v) the Acceptable Use Policy and Support and Service Level Terms.

1.4 Amendments and Updates.

1.4.1 Negotiated Agreements. Where Customer and CrisisCommand have executed a negotiated Order Form or Agreement, no amendment is effective unless agreed in writing by both parties.

1.4.2 Updates to Standard Terms. For all other Customers, CrisisCommand may update this Platform Agreement, the Acceptable Use Policy, and the Support and Service Level Terms. CrisisCommand will provide at least thirty (30) days’ notice of any material update, and the update will take effect at the start of Customer’s next Renewal Term. Non-material updates, updates relating to new functionality, and updates required by applicable law may take effect upon posting.

1.4.3 Protective Limit. CrisisCommand may not update any term in a manner that materially reduces its obligations regarding Confidential Information, Customer Data, Customer Content, security, or the No-Training commitment, without Customer’s written consent.

1.4.4 Data Processing Addendum. The Data Processing Addendum may be amended only in accordance with its own terms.

1.5 Use of the Service is also subject to any additional terms presented for new or preview functionality at the time such functionality is made available.

1.6 Nature of the Service. The Service is a decision-support tool. Output is preliminary, pre-decisional, and deliberative in nature, and is intended to inform Customer’s independent judgment. Output does not constitute legal, medical, financial, or other professional advice, and does not constitute a final institutional record, decision, policy, or communication unless and until independently reviewed, adopted, and issued by Customer.

2. DEFINITIONS

2.1 The definitions in Section 13 (Defined Terms) apply to these Terms. All terms in quotation marks in the body of this Agreement are also defined terms.

3. USAGE

3.1 License Grant. Subject to the Terms, Customer and Customer’s Affiliates may access, and we grant Customer and Customer’s Affiliates the non-exclusive, non-transferable right to use, the Service pursuant to the Documentation during the Term. Access credentials are specific to the user to whom they are issued and may not be shared, including within the same organization. Customer will take reasonable steps to prevent unauthorized use of the Service.

3.2 Restrictions. Customer may not (i) use the Service in a way that infringes, misappropriates, or violates any person’s rights; (ii) attempt to reverse engineer, decompile, or attempt to discover the source code, algorithms, or underlying models of the Service or CrisisCommand’s subcontractors; (iii) attempt automated means to scrape content or Output from the Service; (iv) sublicense, resell, or make the Service available to third parties other than Customer’s authorized users; (v) use the Service or any Output to develop, train, or improve any AI or machine learning models (separate from authorized use of the Service under this Agreement); (vi) represent any Output as being an original work or a wholly human-generated work without disclosure of AI involvement where required by law; or (vii) use the Service for purposes that are discriminatory, harassing, harmful, or unethical.

3.3 Acceptable Use. Customer’s use of the Service is subject to the Acceptable Use Policy. CrisisCommand reserves the right to suspend access for violations of the Acceptable Use Policy after providing notice and a reasonable opportunity to cure, except where immediate suspension is necessary to prevent harm to other users, the Service, or third parties.

3.4 Prohibited Data. The Service is not designed to process, store, or manage Protected Health Information (as defined by HIPAA), student education records protected under the Family Educational Rights and Privacy Act (FERPA), or other categories of data subject to sector-specific regulatory frameworks requiring specialized data handling certifications. For the avoidance of doubt, Prohibited Data also includes customer financial account data subject to financial-privacy or banking regulations (such as the Gramm-Leach-Bliley Act) and special categories of personal data as defined under the GDPR (including data revealing racial or ethnic origin, political opinions, religious beliefs, health data, or data concerning sex life or sexual orientation). The Service does not determine materiality, disclosure timing, or regulatory reporting obligations, and Customer retains sole responsibility for compliance with securities laws and disclosure controls. Customer agrees not to submit such data to the Service. If Customer become aware that Prohibited Data has been submitted to the Service, Customer shall promptly notify CrisisCommand, and CrisisCommand will take commercially reasonable steps to delete such data. CrisisCommand shall have no liability arising from the submission of Prohibited Data to the Service in violation of this Section.

3.5 Feedback. To the extent that Customer provides us with any Feedback, we may freely use and incorporate any Feedback into our products and services. CrisisCommand may not utilize Feedback in a way that identifies, or could be used to identify, Customer or Customer’s users, Customer Data, Content, or Customer’s Confidential Information.

3.6 Third-Party Products. Any third-party software, services, or other products Customer use in connection with the Service (for example, Customer’s internet browser) are subject to their own terms, and we are not responsible for such third-party products.

4. CONTENT

4.1 Ownership. Customer may provide Input to the Service and receive Output from the Service. As between the parties, Customer own Customer Content. CrisisCommand claims no ownership interest in Customer Content.

4.2 Similar Output. Customer may provide Input that is similar or identical to a third party’s Input, or may receive Output that is similar or identical to Output provided to other users. Output provided to other users is not Customer Content.

4.3 AI-Generated Output. Customer acknowledges that Output is generated through AI and machine learning processes. CrisisCommand does not represent or warrant that Output is accurate, complete, current, or suitable for any particular purpose. Customer is responsible for independently reviewing and verifying all Output before relying on it for any decision, communication, or action, including crisis response decisions.

4.4 Crisis Management Disclaimer. The Service is designed as a decision-support tool to augment, not replace, professional crisis management judgment. Output does not constitute legal advice, regulatory guidance, or professional crisis consulting. CrisisCommand shall not be liable for any decisions made, actions taken, or communications issued based on Output. Customer acknowledges that crisis situations involve rapidly evolving facts and circumstances, and that Output reflects information available at the time of generation.

4.5 Pre-Decisional Nature of Output. Output generated by the Service constitutes preliminary, draft, deliberative analysis designed to inform Customer’s independent judgment. Output does not represent final institutional positions, decisions, policies, or communications unless and until independently adopted, modified, and issued by Customer through Customer’s own institutional processes. Customer acknowledges that Output is a working tool intended to support, but not supplant, Customer’s organization’s decision-making authority.

5. CUSTOMER DATA

5.1 To utilize certain features, including Enterprise Intelligence, Customer may upload documents, organizational policies, governance structures, and other materials (“Customer Data”) into the Service for the purpose of enabling personalized crisis intelligence capabilities.

5.2 Ownership. As between the parties, Customer retains all right, title, and interest (including any and all intellectual property rights) in and to the Customer Data. Customer grants to CrisisCommand a non-exclusive, worldwide, royalty-free right to process the Customer Data and Customer Input solely to the extent necessary to (i) provide the Service to Customer, (ii) prevent or address service or technical problems with the Service, or (iii) comply with applicable law.

5.3 Data Handling. CrisisCommand shall handle Customer Data in accordance with its Data Management Policy and all applicable data protection laws. Customer Data is classified as Confidential and is subject to the protections set forth in Section 11.6 (Confidentiality) of this Agreement.

5.4 Customer Responsibility. Customer is solely responsible for the content and accuracy of Customer Data and for ensuring that Customer Data does not include Prohibited Data as described in Section 3.4. Customer represents and warrants that Customer has all rights necessary to provide Customer Data to CrisisCommand for processing in connection with the Service.

5.5 Customer Data Practices. The Service is designed to operate effectively with summarized situational information, organizational context, and scenario descriptions. The Service does not require, and Customer should avoid submitting, raw sensitive source documents, personally identifiable information, unredacted internal investigation files, or other confidential materials beyond what is necessary for the Service to generate useful Output. Customer is responsible for determining what information to submit in accordance with Customer’s own organization’s data handling, information governance, and records management policies. CrisisCommand recommends the use of role descriptions, code names, and summarized facts rather than raw source materials when providing situational context to the Service.

5.6 No Training. CrisisCommand will not train any AI or machine learning models using Customer Content or Customer Data. CrisisCommand contractually requires its Subprocessors not to train any AI or machine learning models using Customer Content or Customer Data.

5.7 De-Identified and Aggregated Data. CrisisCommand may use de-identified and aggregated data (from which Customer, Customer’s users, and any individual cannot be identified) to improve the reliability, performance, and security of the Service.

5.8 Usage Data. CrisisCommand may collect and use Usage Data to develop, improve, support, and operate the Service. CrisisCommand may not share Usage Data that includes Customer’s Confidential Information with a third party except (i) in accordance with Section 11.6 (Confidentiality) of this Agreement, or (ii) to the extent the Usage Data is aggregated and anonymized such that Customer cannot be identified.

6. FEES AND PAYMENTS

6.1 Fees. Fees payable by Customer (“Fees”) are as set forth in the Order Form. CrisisCommand may correct invoicing errors within forty-five (45) days of the relevant invoice being received by Customer.

6.1.1 Standard Invoicing and Payment Terms. Unless the Order Form specifies different terms, the following standard terms apply: (i) Fees are invoiced annually in advance; (ii) the first invoice is issued on the Effective Date and each subsequent invoice is issued at least thirty (30) days before the start of the applicable Renewal Term; (iii) payment is due within thirty (30) days of the invoice date (net 30); (iv) Fees are stated and payable in U.S. dollars; and (v) Fees are non-refundable except as expressly provided in this Agreement.

6.2 Fees are exclusive of any taxes or other governmental assessments, including but not limited to sales, use, value-added, and withholding taxes (“Taxes”). Customer is responsible for all Taxes on the Fees, except Taxes on CrisisCommand’s net income. CrisisCommand will add Taxes to Customer’s invoice if required by law.

6.3 If Customer wisheses to dispute any Fees or Taxes, please contact billing@crisiscommand.ai within thirty (30) days of the date of the disputed invoice. Undisputed amounts past due may be subject to a finance charge of 1.5% per month on the unpaid balance. If any undisputed amount of Customer’s Fees is past due, we may suspend Customer’s access to the Service after we provide Customer with fifteen (15) days’ written notice of late payment.

7. TERM AND TERMINATION

7.1 Term.

7.1.1 Initial Term. The “Initial Term” begins on the Effective Date set forth in the Order Form and continues for the Service Period specified in the Order Form.

7.1.2 Renewal Term. Unless the Order Form states otherwise, the Agreement automatically renews for successive one-year periods (each, a “Renewal Term”) unless either party gives written notice of non-renewal at least thirty (30) days before the end of the then-current term. The Initial Term together with all Renewal Terms constitute the “Term.”

7.1.3 Renewal Pricing. Unless the Order Form states otherwise, Fees for each Renewal Term will increase by five percent (5%) over the Fees for the immediately preceding term. CrisisCommand will notify Customer of Renewal Term Fees at least thirty (30) days before the start of the Renewal Term.

7.1.4 Public Entities. Where Customer is a public entity prohibited by applicable law or procurement rules from agreeing to automatic renewal, the Agreement will not automatically renew, and any Renewal Term requires Customer’s affirmative written agreement before the end of the then-current term.

7.2 Termination for Cause. Either party may terminate any operative order form if the other party fails to cure any material breach of such order form or the Agreement within thirty (30) days after receipt of written notice from the terminating party of the material breach.

7.3 Refund on Termination. In the event an order form is terminated pursuant to Section 7.2 by Customer due to CrisisCommand’s uncured material breach, Customer will be refunded a pro rata amount of any prepaid unused Fees inclusive of the day of termination.

7.4 Data Deletion. Within ninety (90) days of termination, CrisisCommand will securely delete any remaining Customer Data and Content unless (i) otherwise instructed by Customer in writing (provided that any Customer-directed retention beyond ninety (90) days is subject to CrisisCommand’s written agreement and may be subject to additional fees), (ii) retention is required by applicable law, or (iii) de-identified or aggregated data is retained in accordance with Section 5.7.

7.5 Survival. The sections of these Terms that by their nature should survive termination will survive, including provisions regarding confidentiality, limitation of liability, indemnification, intellectual property, data deletion, and the obligation to pay unpaid fees.

8. INDEMNIFICATION

8.1 CrisisCommand Indemnification. CrisisCommand will indemnify Customer against any damages, costs, and attorneys’ fees finally awarded against Customer, or agreed in settlement by CrisisCommand, resulting from any claim by a third party alleging that the Service (excluding Output), when used in accordance with these Terms and the Documentation, infringes any United States intellectual property right of such third party, subject to the Liability Cap set forth in Section 10.2. CrisisCommand’s obligations under this Section 8.1 do not extend to claims arising from or attributable to: (i) Customer Input or Customer Data; (ii) Output generated by the Service (which relies in part on third-party AI models not developed or controlled by CrisisCommand); (iii) modifications to the Service made by Customer; or (iv) use of the Service in combination with products or services not provided by CrisisCommand. This Section 8.1 states CrisisCommand’s entire liability, and Customer’s sole and exclusive remedy, for any claim of intellectual property infringement. If Customer’s use of the Service results (or in CrisisCommand’s opinion is likely to result) in an infringement claim, CrisisCommand may either: (a) substitute functionally similar products or services, (b) procure for Customer the right to continue using the Service, or if (a) and (b) are not commercially reasonable, (c) terminate this Agreement and the applicable order form and refund to Customer any prepaid unused Fees.

8.2 Customer’s Indemnification. Customer will indemnify CrisisCommand against any damages, costs, and attorneys’ fees finally awarded against CrisisCommand, or agreed in settlement by Customer, resulting from any claim by a third party arising from or relating to: (i) Customer Input, (ii) Customer Data, (iii) Customer’s submission of Prohibited Data in violation of Section 3.4, or (iv) Customer’s use of the Service in violation of these Terms.

8.3 Indemnification Procedure. In the event of a potential indemnity obligation under this section, the Indemnified Party will: (i) promptly notify the Indemnifying Party in writing of the claim; (ii) provide the Indemnifying Party with reasonable cooperation in connection with the claim at the Indemnifying Party’s expense; and (iii) give the Indemnifying Party the opportunity to participate in the defense or settlement of such claim. Failure to notify will not relieve the Indemnifying Party of its obligations, but the Indemnifying Party will not be liable for damages resulting from material prejudice caused by the delay. Neither party may settle any claim that would bind the other party to any obligation (other than payment covered by the Indemnifying Party) or require any admission of fault, without the other party’s prior written consent.

9. WARRANTY AND DISCLAIMER

9.1 Customer’s Warranty. Customer warrants that (i) Customer has the necessary rights in Customer Data and Input to use them with the Service; (ii) Customer’s use of the Service will comply with all applicable laws and regulations; and (iii) Customer will not submit Prohibited Data (as defined in Section 3.4) to the Service.

9.2 CrisisCommand Warranty. CrisisCommand warrants that (i) the Service will conform in all material respects with the specifications provided in our Documentation; (ii) it will provide the Service in a professional and workmanlike manner with personnel having a level of skill commensurate with the requirements of this Agreement; (iii) the Service does not, to our knowledge, infringe any third-party intellectual property right; and (iv) its provision of the Service will comply with all applicable laws and regulations.

9.3 Warranty Remedy. If the Service fails to conform to the warranties set forth in Section 9.2, Customer’s sole and exclusive remedy, and CrisisCommand’s sole and exclusive liability, shall be for CrisisCommand to use commercially reasonable efforts to correct the non-conformity within thirty (30) days of receiving written notice from Customer describing the non-conformity in reasonable detail. If CrisisCommand fails to correct the non-conformity within such thirty (30) day period, Customer may terminate the applicable Order Form upon written notice, and CrisisCommand will refund to Customer a pro rata amount of any prepaid unused Fees.

9.4 Disclaimer. EXCEPT FOR THE WARRANTIES IN THIS SECTION, THE PARTIES DISCLAIM ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND TITLE. CRISISCOMMAND DOES NOT REPRESENT OR WARRANT THAT THE USE OF THE SERVICE WILL BE UNINTERRUPTED OR ERROR-FREE. WITHOUT LIMITING THE FOREGOING, CRISISCOMMAND MAKES NO WARRANTY REGARDING THE ACCURACY, RELIABILITY, COMPLETENESS, OR TIMELINESS OF ANY OUTPUT, INCLUDING ANY CRISIS MANAGEMENT STRATEGIES, STAKEHOLDER ANALYSES, COMMUNICATIONS DRAFTS, OR ACTION PLANS GENERATED BY THE SERVICE. THE SERVICE IS NOT DESIGNED TO PROCESS PROTECTED HEALTH INFORMATION, STUDENT EDUCATION RECORDS, OR OTHER DATA SUBJECT TO SECTOR-SPECIFIC REGULATORY REQUIREMENTS.

10. LIMITATIONS ON LIABILITY

10.1 Exclusion of Consequential Damages. IN NO EVENT WILL EITHER PARTY BE LIABLE TO THE OTHER PARTY OR ANY THIRD PARTY FOR ANY INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, PUNITIVE, OR CONSEQUENTIAL DAMAGES, INCLUDING LOSS OF INCOME, PROFITS, REVENUE, OR BUSINESS INTERRUPTION, OR THE COST OF SUBSTITUTE SERVICES OR OTHER ECONOMIC LOSS, ARISING OUT OF OR IN CONNECTION WITH THESE TERMS, WHETHER SUCH LIABILITY ARISES FROM ANY CLAIM BASED ON CONTRACT, WARRANTY, TORT (INCLUDING NEGLIGENCE), STRICT LIABILITY, OR OTHERWISE, AND WHETHER OR NOT SUCH PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH LOSS OR DAMAGE.

10.2 Liability Cap. EXCEPT AS SET FORTH IN SECTIONS 10.3 AND 10.4, EACH PARTY’S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO THIS AGREEMENT WILL NOT EXCEED THE AMOUNT ACTUALLY PAID OR PAYABLE TO CRISISCOMMAND BY CUSTOMER IN THE TWELVE (12) MONTHS PRECEDING THE EVENT GIVING RISE TO THE CLAIM (THE “LIABILITY CAP”). CRISISCOMMAND’S INDEMNIFICATION OBLIGATIONS UNDER SECTION 8.1 ARE SUBJECT TO THE LIABILITY CAP.

10.3 Super Cap. NOTWITHSTANDING SECTION 10.2, EACH PARTY’S TOTAL AGGREGATE LIABILITY FOR CLAIMS ARISING FROM ITS OWN BREACH OF SECTION 11.6 (CONFIDENTIALITY), AND CRISISCOMMAND’S TOTAL AGGREGATE LIABILITY FOR CLAIMS ARISING FROM BREACH OF SECTION 5.6 (NO TRAINING), WILL NOT EXCEED TWO (2) TIMES THE AMOUNT ACTUALLY PAID OR PAYABLE TO CRISISCOMMAND BY CUSTOMER IN THE TWELVE (12) MONTHS PRECEDING THE EVENT GIVING RISE TO THE CLAIM (THE “SUPER CAP”). CRISISCOMMAND’S LIABILITY FOR ANY SUBPROCESSOR’S BREACH OF A NO-TRAINING OBLIGATION IS SUBJECT TO THE SUPER CAP.

10.4 Exclusions from the Caps. THE LIABILITY CAP AND THE SUPER CAP DO NOT APPLY TO: (i) EITHER PARTY’S PAYMENT OBLIGATIONS UNDER THIS AGREEMENT; (ii) CUSTOMER’S INDEMNIFICATION OBLIGATIONS UNDER SECTION 8.2, WHICH ARE UNCAPPED; OR (iii) LIABILITY THAT BY LAW CANNOT BE LIMITED, INCLUDING GROSS NEGLIGENCE AND WILLFUL MISCONDUCT.

11. GENERAL TERMS

11.1 Assignment. Neither party may assign these Terms without the advance written consent of the other party, except that CrisisCommand may (i) assign these Terms in their entirety to any Affiliate, or (ii) assign these Terms in connection with a consolidation, merger, or sale of all or substantially all of CrisisCommand’s assets.

11.2 Subcontracting. CrisisCommand may use subcontractors and other third-party providers in connection with the performance of its activities under these Terms, provided that it remains responsible for the performance of any such subcontractors or third-party providers. Any Subprocessor brought on after the Effective Date that would have access to Customer Data or Content must be brought on in accordance with the Data Processing Addendum.

11.3 Severability. If a court of competent jurisdiction holds any provision of these Terms to be unenforceable or invalid, that provision will be limited to the minimum extent necessary so that these Terms will otherwise remain in effect.

11.4 Affiliate Usage. Customer may grant Customer’s Affiliates access to and use of the Service under Customer’s account, provided that Customer ensures such Affiliates are aware of, and Customer is responsible for their compliance with, the Terms. Actions taken or omissions made by Customer’s Affiliates in connection with their access or use of the Service are deemed as if taken or made by Customer.

11.5 Intellectual Property. Neither party grants the other any rights or licenses not expressly set out in this Agreement. Except for CrisisCommand’s express rights in this Agreement, as between the parties, Customer retains all intellectual property and other rights in Customer Data. Except for Customer’s express rights in this Agreement, as between the parties, CrisisCommand and its licensors retain all intellectual property and other rights in the Service, including the crisis case library, analytical frameworks, workflow methodologies, and related proprietary technology.

11.6 Confidentiality. Each party (as the “Receiving Party”) will use the same degree of care that it uses to protect the confidentiality of its own confidential information of like kind (but not less than reasonable care) to: (i) not use any Confidential Information of the other party (the “Disclosing Party”) for any purpose outside the scope of these Terms; and (ii) except as otherwise authorized by the Disclosing Party in writing, limit access to Confidential Information to those of its and its Affiliates’ employees and contractors who need that access for purposes consistent with these Terms and who are bound by confidentiality obligations containing protections not materially less protective than this section. If the Receiving Party is required by applicable law or court order to disclose Confidential Information, the Receiving Party will, to the extent legally permitted, provide the Disclosing Party with advance written notification and cooperate in any effort to obtain confidential treatment of the Confidential Information.

11.7 Security. CrisisCommand will maintain commercially reasonable administrative, technical, and physical safeguards designed to protect Customer Data and Content from unauthorized access, destruction, loss, alteration, or disclosure. Such safeguards include industry-standard encryption of data at rest and in transit, access controls based on least-privilege principles, and a program of regular security assessments that CrisisCommand is implementing. CrisisCommand’s security practices are further described in its Security Documentation, which will be made available to Customer upon request. CrisisCommand has engaged to undergo a SOC 2 Type II examination and will make its SOC 2 report available to Customer upon completion, subject to a non-disclosure agreement.

11.8 Incident Response and Breach Notification. CrisisCommand maintains an Incident Response Plan for managing information security incidents. In the event of a confirmed security breach involving Customer Data or Content, CrisisCommand will (i) notify Customer without undue delay following confirmation of the breach, (ii) take reasonable steps to contain and remediate the breach, (iii) provide Customer with reasonably available information regarding the nature of the breach and the data affected, and (iv) cooperate with Customer in connection with any notification obligations Customer may have under applicable law.

11.9 Subprocessors. A current list of CrisisCommand’s Subprocessors is maintained at https://trust.crisiscommand.ai. CrisisCommand will provide at least thirty (30) days’ advance notice before engaging any new Subprocessor that will have access to Customer Data or Content, by updating the Subprocessor list and notifying Customer via email. If Customer has a reasonable objection to a new Subprocessor, Customer may notify CrisisCommand in writing within fifteen (15) days of receiving notice. CrisisCommand will make commercially reasonable efforts to address Customer’s concerns. If CrisisCommand is unable to resolve Customer’s objection, Customer may terminate the affected order form upon written notice, and CrisisCommand will refund any prepaid unused Fees. Notwithstanding the foregoing notice period, where a Subprocessor must be added or replaced on an urgent basis for security, legal-compliance, business-continuity, or breach-related reasons (including a Subprocessor’s failure to honor its no-training or data-protection obligations), CrisisCommand may make the change immediately and will provide notice to Customer promptly thereafter, together with Customer’s objection and termination rights described above applied on a post-change basis. CrisisCommand’s ability to substitute Subprocessors rapidly is a resilience feature of the Service and does not diminish the protections of this Section.

11.10 Use of Name. CrisisCommand will not use Customer’s name, logo, or identity to reference Customer as a customer of the Service in any marketing or promotional materials without Customer’s prior written consent, which may be given or withheld in Customer’s sole discretion.

11.11 Governing Law. These Terms will be governed by the laws of the State of Texas, without regard to its conflicts of laws provisions and without regard to the United Nations Convention on the International Sale of Goods.

11.12 Dispute Resolution. Any dispute, claim, or controversy arising out of or relating to this Agreement will first be subject to good-faith negotiation between the parties for a period of thirty (30) days following written notice of the dispute. If the dispute is not resolved through negotiation, either party may bring a claim in the state or federal courts located in Travis County, Texas, and each party consents to the exclusive jurisdiction and venue of such courts.

11.13 Notice. All notices must be in writing (in English) and addressed to the parties via email: (i) for CrisisCommand, notice must be sent to legal@crisiscommand.ai; and (ii) for Customer, to the email address set forth in Customer’s operative order form. Either party may update its email address for notices by providing written notice to the other party. For notices of termination or material breach, the sending party will additionally provide a copy by nationally recognized overnight courier or certified mail to the other party’s last-known business address, provided that email notice governs the effective date and the physical copy is a courtesy backstop.

11.14 No Waiver. No waiver will be implied from conduct or failure to enforce or exercise rights under these Terms, nor will any waiver be effective unless in a writing signed by the waiving party.

11.15 Entire Agreement. These Terms are the complete and exclusive statement of the mutual understanding of the parties in connection with Customer’s use of the Service and supersede and cancel all previous written and oral agreements, understandings, and communications relating to the subject matter in these Terms.

11.16 Force Majeure. Neither party will be liable to the other for any delay or failure to perform any obligation under these Terms (except for failure to pay applicable Fees) if the delay or failure results from any cause beyond such party’s reasonable control that could not have been prevented through the use of commercially reasonable safeguards, including acts of God, labor disputes, systemic electrical or telecommunications failures, earthquake, storms, public health emergencies, acts or orders of government, acts of terrorism, or war.

12. DATA PROCESSING

12.1 CrisisCommand will at all times abide by the Terms as well as the Data Processing Addendum with respect to the handling and processing of Customer Data and Content. To the extent of any conflict between the Terms and the Data Processing Addendum, as to the subject matter covered by the Data Processing Addendum, the Data Processing Addendum controls.

12.2 Privacy Policy. Customer’s users will be subject to our Privacy Policy to the extent not in conflict with the Terms in using the Service.

12.3 Regulatory Data Exclusion. The Service is not designed, intended, or authorized for use with Protected Health Information (PHI) as defined by HIPAA, student education records as defined by FERPA, customer financial account data subject to financial-privacy or banking regulations (such as the Gramm-Leach-Bliley Act), or other data subject to sector-specific regulatory frameworks that require specialized data handling certifications or agreements (such as Business Associate Agreements). CrisisCommand does not represent that the Service is compliant with HIPAA, FERPA, the Gramm-Leach-Bliley Act, or similar regulatory frameworks. CrisisCommand does not determine materiality, disclosure timing, or regulatory reporting obligations, and Customer retains sole responsibility for compliance with securities laws and disclosure controls. Customer is solely responsible for ensuring that data submitted to the Service does not include such regulated data. CrisisCommand may implement technical measures to detect and prevent submission of such data, but shall have no obligation to do so and shall have no liability for any regulated data submitted to the Service in violation of this Section or Section 3.4.

13. DEFINED TERMS

13.1 “Acceptable Use Policy” means CrisisCommand’s policy governing the use of its Service as located at https://crisiscommand.ai/legal/aup.

13.2 “Affiliate” means any entity that directly or indirectly controls, is controlled by, or is under common control with the subject entity, where “control” means direct or indirect ownership or control of more than 50% of the voting interests in the subject entity.

13.3 “Confidential Information” means all information that is identified as confidential at the time of disclosure by the Disclosing Party or reasonably should be known by the Receiving Party to be confidential or proprietary due to the nature of the information disclosed and the circumstances surrounding the disclosure. Content specific to Customer and Customer Data are Customer’s Confidential Information. CrisisCommand’s crisis case library, analytical frameworks, workflow methodologies, and proprietary technology are CrisisCommand’s Confidential Information.

13.4 “Content” means Input and Output collectively.

13.5 “Customer Data” has the meaning set forth in Section 5.1.

13.6 “Data Processing Addendum” or “DPA” means the Data Processing Addendum governing CrisisCommand’s processing of Content and Customer Data as located at https://crisiscommand.ai/legal/dpa.

13.7 “Documentation” means the controlled product help documentation for the Service that CrisisCommand makes available to Customer through its designated help center or trust portal, as updated by CrisisCommand from time to time. Documentation does not include CrisisCommand’s public marketing website, sales or promotional materials, or any performance metrics, benchmarks, or comparative claims contained therein, none of which form part of the Documentation or the warranty in Section 9.2.

13.8 “Effective Date” means the date which is the earlier of (i) when Customer first use the Service or (ii) the effective date of the first Order Form referencing this Agreement.

13.9 “Feedback” means any suggestions, enhancement requests, recommendations, corrections, or other feedback provided to CrisisCommand by Customer relating to our offerings. Feedback excludes Customer Data and Content.

13.10 “Fees” has the meaning set forth in Section 6.1.

13.11 “Input” means the query, prompt, scenario description, or other information provided by a user to the Service.

13.12 “Liability Cap” has the meaning set forth in Section 10.2.

13.13 “Output” means the crisis assessments, stakeholder analyses, communications drafts, action plans, and other output provided by the Service to a user in response to such user’s Input.

13.14 “Privacy Policy” means CrisisCommand’s policy governing the privacy provisions related to its Service as located at https://crisiscommand.ai/legal/privacy.

13.15 “Public Entity Terms” means the terms set forth in Section 14 of this Agreement, which apply automatically to customers that are public entities or are otherwise subject to public records, freedom of information, open records, or similar disclosure requirements.

13.16 “Prohibited Data” means Protected Health Information as defined by HIPAA, student education records as defined by FERPA, customer financial account data subject to financial-privacy or banking regulations (such as the Gramm-Leach-Bliley Act), and any other data subject to sector-specific regulatory frameworks requiring specialized data handling certifications, as further described in Section 3.4.

13.17 “Service” means the CrisisCommand Crisis Intelligence Platform, a software-as-a-service offering made available by CrisisCommand, including through its web application, and any related features, functionalities, and components as described in the Documentation or as otherwise made available by CrisisCommand from time to time. The Service includes Live Crisis Mode, Plan Mode, Simulate Mode, and Enterprise Intelligence features.

13.18 “Subprocessor” means any subcontractor or vendor of CrisisCommand that has access to or otherwise processes Customer Data or Content.

13.19 “Usage Data” means information reflecting the access, interaction, or use of the Service by or on behalf of Customer, including frequency, duration, volume, features used, session data, and statistical or other analysis, information, or data based on or derivative of the foregoing. Usage Data does not include any Customer Data or Content.

13.20 “Customer” or “Customer’s” means the entity identified on the applicable Order Form that is contracting for the use of the Service, including its respective authorized users, as appropriate.

14. CONFIDENTIALITY AND DISCLOSURE PROTECTION

14.1 Trade Secret Designation. The parties acknowledge and agree that the Service, the crisis case library, analytical frameworks, workflow methodologies, proprietary technology, algorithms, and all related Documentation constitute trade secrets and confidential proprietary business information of CrisisCommand within the meaning of applicable state trade secret statutes (including the Uniform Trade Secrets Act as adopted in applicable jurisdictions) and federal law (including the Defend Trade Secrets Act of 2016).

14.2 Deliberative Character of Output. Consistent with Section 1.6, the parties acknowledge and agree that Output constitutes preliminary, pre-decisional, and deliberative material generated to inform Customer’s independent decision-making, and does not constitute a final institutional record, decision, policy, or communication unless and until independently reviewed, adopted, and issued by Customer through Customer’s own governance processes.

14.3 Notice of Compelled Disclosure. Customer will promptly notify CrisisCommand in writing at legal@crisiscommand.ai upon receiving any subpoena, court order, civil discovery demand, regulatory demand, public records or freedom of information request, or other compelled disclosure demand that would require disclosure of CrisisCommand’s Confidential Information, Output, or information about the Service, its architecture, or its methodology, to the extent Customer is legally permitted to provide such notice.

14.4 CrisisCommand’s Rights Are Discretionary. CrisisCommand may, at its sole discretion and at its own expense, seek a protective order or other appropriate remedy in response to any demand described in Section 14.3. CrisisCommand has no obligation to intervene, object, or defend against any such demand, and any decision by CrisisCommand not to intervene in a particular instance does not waive, limit, or diminish the designations in Sections 14.1 and 14.2 or CrisisCommand’s rights in any other instance. Nothing in this Section 14 requires Customer to act in violation of applicable law or a valid court order.