DOMx Canada Software Subscription and
Information Management Agreement

Canadian clinics and healthcare practices

Version: August 5, 2026

Contracting provider: Specialized Office Systems Inc., a British Columbia corporation

Applies to: DOMx Legacy, DOMxOnline, mobile features, AI Scribe, support, backup and related subscribed services

Electronic Acceptance Notice

This Agreement governs the Customer’s access to and use of DOMx Software and Services. The Customer accepts and agrees to be bound by this Agreement by signing it, clicking an electronic acceptance button, or accessing or using the Services after this Agreement has been conspicuously presented or made available.

The individual accepting this Agreement confirms that they are authorized to bind the Customer. If the Customer does not agree to this Agreement, it must not access or use the Services.

1. Parties, Acceptance and Scope

1.1 Parties. This Agreement is between the clinic or other legal entity identified in an order, invoice, account or signature record (the “Customer”) and Specialized Office Systems Inc., a British Columbia corporation (the “Canadian Provider”). The similarly named British Columbia and Oregon corporations are separate legal persons. Only the entity identified here is the contracting provider.

1.2 Acceptance. The Customer accepts this Agreement by signing it, electronically accepting it, or accessing or using the Services after it is presented. The person accepting represents that they are authorized to bind the Customer. If the Customer does not agree, it must not use the Services.

1.3 Agreement documents. This Agreement, each accepted order or quote, each applicable privacy or security schedule, and any signed statement of work form the complete agreement. A purchase order or other Customer form does not add terms unless the Service Provider expressly accepts those terms in writing.

2. Services, Access and Customer Responsibilities

2.1 Services. The Service Provider grants the Customer a limited, non-exclusive, non-transferable right during the subscription term to use its subscribed DOMx services for the Customer’s internal clinical and administrative operations. Subscriptions are not contingent on delivery of future functionality unless an accepted order expressly states otherwise.

2.2 Users and systems. The Customer controls authorized users, roles and permissions and is responsible for credential protection, secure devices and networks, timely removal of former users, and the accuracy and legality of Customer Data. Where DOMx operates on Customer-controlled computers or servers, the Customer is responsible for the environment and for any independent backup expressly assigned to it.

2.3 Support and remote access. Support may require call-back service, remote connection, diagnostic information and authorized access to Customer systems. The Service Provider will access Customer Data only as reasonably necessary for support and will apply the privacy obligations in this Agreement. Support telephone messages may be converted to text by an approved telecommunications provider for routing and response.

2.4 Restrictions. The Customer must not copy or resell the Services; reverse engineer them except where law cannot prohibit it; circumvent security or usage controls; introduce malicious code; access another customer’s data; or use the Services unlawfully or to infringe another person’s rights.

2.5 Third-party services and integrations. A third-party product selected or independently contracted by the Customer is governed by that third party’s terms. If the Customer directs DOMx to exchange data with it, the Customer authorizes the necessary exchange and remains responsible for evaluating that third party. This does not reduce the Service Provider’s responsibility for subprocessors it selects to perform the Services.

2.6 Suspension. The Service Provider may suspend affected access where reasonably necessary for non-payment, unlawful use, a material breach, a serious security threat, vendor service interruption, or a legal requirement. Where practicable, it will give notice and work to restore access after the cause is resolved.

3. Term, Variable Fees and Payment

3.1 Term. This Agreement begins on acceptance and continues month-to-month unless an accepted order specifies another term. Either party may give notice of non-renewal. Unless the order states otherwise, cancellation is effective at the end of the current monthly billing period and does not affect amounts already due.

3.2 Pricing records. Fees are not fixed or published by this Agreement. The Customer will pay the amounts separately agreed for its selected Services, users, locations, equipment, usage and clinic-specific arrangements. An accepted order, quote, invoice, account statement, directly provided fee schedule or other written pricing record is a “Pricing Record.” Different customers may have legacy, promotional or negotiated arrangements. The most recent mutually applicable Pricing Record controls.

3.3 Variable monthly authorization. The Customer authorizes the Service Provider and its payment processor to charge or debit its approved payment method each month for the amount then due under the applicable Pricing Record, including recurring charges, usage-based charges, Customer-approved additions, adjustments and taxes. The amount may vary when Services or usage change. Cancelling a payment method does not cancel the subscription or release amounts owing.

3.4 Canadian Business PAD authorization. If the Customer supplies business banking information, it authorizes the Canadian Provider, its financial institution and payment processor to issue recurring Business Pre-Authorized Debits (“PADs”) against that account, normally monthly on or about the first day of the month. The amount is variable and determined under Sections 3.2 and 3.3. Each person authorizing the PAD represents that they have authority over the account. The banking authorization or void cheque supplied by the Customer identifies the account to be debited.

VARIABLE PAD PRE-NOTIFICATION WAIVER. THE CUSTOMER EXPRESSLY WAIVES SEPARATE 10-CALENDAR-DAY PRE-NOTIFICATION OF EACH VARIABLE BUSINESS PAD AND AUTHORIZES THE AMOUNT SHOWN ON THE APPLICABLE INVOICE OR ACCOUNT STATEMENT TO BE DEBITED ON OR ABOUT THE STATED DATE.

3.5 Revocation and recourse. The Customer may revoke the PAD authorization by giving at least 10 calendar days’ written notice to [email protected] or by another method permitted by Payments Canada Rule H1. The Customer has recourse rights if a debit is unauthorized or inconsistent with this authorization; details are available from its financial institution or payments.ca. A copy or confirmation of the authorization will be provided. Revoking PAD does not terminate the Services or release amounts owing.

3.6 Fee changes. The Service Provider may change recurring fees on at least 30 days’ written notice. The Customer may terminate the affected Service before the increase takes effect. Usage charges and external pass-through costs may vary as described in the applicable Pricing Record.

3.7 Taxes and overdue amounts. Fees exclude taxes the Service Provider is legally required to collect. Undisputed overdue amounts may accrue the lesser of 1.5% per month and the maximum lawful rate after written notice. The Customer must promptly identify any good-faith invoice dispute.

4. Confidentiality, Data and Intellectual Property

4.1 Confidentiality. Each party will protect the other party’s non-public business, technical, personal and health information using at least reasonable safeguards and will use it only to perform or receive the Services, exercise rights under this Agreement, or comply with law. These duties do not apply to information lawfully public, already known without restriction, independently developed, or lawfully received without confidentiality duty.

4.2 Customer Data. As between the parties, the Customer retains ownership and lawful custody or control of Customer Data. The Service Provider receives no ownership interest in identifiable patient information and may process it only as permitted by this Agreement.

4.3 De-identified service analytics. The Service Provider may create and use statistics that have been aggregated or de-identified using reasonable methods so they do not identify a patient, authorized user or Customer. They may be used to operate, secure, measure and improve DOMx, including evaluating AI performance. The Service Provider will not attempt to re-identify them or disclose them in a manner that reasonably permits re-identification.

4.4 DOMx materials. DOMx software, documentation, designs, methods, templates, know-how, improvements and other pre-existing or independently developed materials remain the Service Provider’s property. Feedback may be used without restriction if it contains no Customer Confidential Information or patient information.

5. AI Scribe and AI-Assisted Features

5.1 Purpose and limitations. AI Scribe and other AI features may capture audio, transcribe speech and generate draft clinical documentation or suggestions. Output may contain errors, omissions or inaccuracies. It is assistive only and is not an independent clinical decision, diagnosis, final health record or substitute for professional judgment.

5.2 Human review. The treating professional must review, correct and approve each AI-generated note or suggestion before relying on it for patient care, billing or recordkeeping. The Customer remains responsible for clinical decisions and the accuracy and completeness of the patient record.

5.3 Audio and records. Audio submitted to AI Scribe is transient and is not retained after processing, unless the Customer deliberately enables a separately documented retention feature or temporary retention is necessary to investigate an incident as permitted by law. Transcripts and approved notes may be retained as part of Customer Data according to the Customer’s settings and legal obligations.

5.4 Notice and consent. The Customer must provide notices and obtain and document consent required when a patient conversation is recorded or listened to by AI Scribe. Provider-only dictation must still comply with the Customer’s privacy policies and applicable law.

5.5 Model training. Customer prompts, audio, transcripts and outputs are not used by the Service Provider or its model providers to train public or foundation AI models. The Service Provider will not submit identifiable patient information through public consumer AI accounts.

5.6 Deployment statements. Residency and retention statements apply to the production services and deployment types described in current DOMx security and subprocessor documentation. Optional or future features with materially different processing will be described before use.

6. Security, Subprocessors and Incidents

6.1 Safeguards. The Service Provider will maintain reasonable and appropriate administrative, technical and physical safeguards based on the sensitivity of Customer Data, including access control, authentication, encryption in transit and at rest where supported, logging, workforce confidentiality, vulnerability and patch management, backup controls, and incident response.

6.2 Personnel and subprocessors. Access is limited to authorized personnel and subprocessors with a need to know. The Service Provider will require personnel confidentiality and require subprocessors handling patient information to provide protections consistent with applicable law and this Agreement. The Service Provider remains responsible for its subcontracting obligations.

6.3 Subprocessor information. The Service Provider will maintain current information identifying material subprocessors, including Microsoft Azure, and will provide notice of a material new subprocessor handling identifiable patient information where required by law or an accepted order.

6.4 Incident notice. The Service Provider will notify the Customer without unreasonable delay after discovering a confirmed unauthorized access, use, disclosure, loss, alteration or destruction of Customer Data for which notice is required. It will provide available information reasonably needed for assessment, containment, mitigation and legally required notification, and will supplement the notice as material information becomes available.

6.5 Security and compliance information. On reasonable request, the Service Provider will provide information reasonably necessary for the Customer’s privacy impact assessment, risk analysis, insurer review or vendor questionnaire, subject to confidentiality, proportionality and the security of other customers and systems.

7. Data Access, Return and Deletion

7.1 Access and export. During the subscription, the Customer may access Customer Data through available functions. On termination, it may request an export in a standard format reasonably supported by DOMx and Microsoft SQL Server. The Customer should make the request before termination or within 30 days afterward. Custom conversion or professional services may be separately charged if disclosed in advance.

7.2 Return and deletion. After the export period, the Service Provider may securely delete Customer Data in its possession or control, except where retention is required by law, directed by the Customer, or technically unavoidable in protected backup cycles. Retained information remains protected, is isolated from routine use and will be deleted under the applicable retention cycle when feasible.

7.3 Customer recordkeeping. The Customer is responsible for retaining patient records for legally required periods and for maintaining access independent of the Services after termination. Ending a licence may require uninstalling or permitting removal of licensed software.

8. Warranty, Indemnity and Liability

8.1 Service standard. The Service Provider will perform the Services with reasonable care. Except as expressly stated and to the maximum extent permitted by law, the Services are provided “as is” and “as available,” without implied warranties of merchantability, fitness for a particular purpose, error-free output or uninterrupted operation.

8.2 Intellectual-property claims. The Service Provider will defend the Customer against a third-party claim that the unmodified DOMx Services, when used as authorized, infringe that third party’s intellectual-property rights, and will pay finally awarded damages or an approved settlement. It may obtain continued use rights, modify or replace the affected Service, or terminate it and refund prepaid unused fees. This does not apply to Customer Data, unauthorized combinations or modifications, or continued use after notice of an available remedy.

8.3 Customer responsibility. The Customer is responsible for claims arising from unlawful Customer Data, Customer instructions, unauthorized use, or the Customer’s breach of messaging, consent or privacy obligations, except to the extent caused by the Service Provider’s breach, negligence or wilful misconduct.

8.4 Excluded loss and cap. To the maximum extent permitted by law, neither party is liable for indirect, incidental, special, exemplary, punitive or consequential damages or lost profits. Except for liability that cannot legally be limited, fraud, wilful misconduct, infringement, payment obligations, or a party’s breach of confidentiality or data-protection obligations, the Service Provider’s aggregate liability will not exceed fees paid for the affected Services during the 12 months before the event giving rise to the claim.

9. General

9.1 Governing law. This Agreement is governed by British Columbia law and applicable Canadian federal law; exclusive venue is in British Columbia courts. Mandatory health-information, privacy and other laws applicable in the Customer’s jurisdiction continue to apply despite this clause.

9.2 Notices. Legal notices must be sent to the addresses or email contacts shown in the applicable order, invoice or signature record. Operational, billing, security and amendment notices may be delivered by email, in-product notice or another reasonable electronic method.

9.3 Assignment. Neither party may assign this Agreement without the other’s consent, not to be unreasonably withheld, except to an affiliate or in connection with a merger, reorganization or sale of substantially all relevant assets if the assignee assumes the obligations.

9.4 Force majeure. Neither party is liable for delay caused by events beyond reasonable control. This does not excuse payment, confidentiality, security, incident response or data return duties to the extent performance remains reasonably possible.

9.5 Changes. Material changes will be identified by version date and given reasonable advance notice. Continued use after the effective date constitutes acceptance where legally permitted. A material reduction in privacy or security protection will not apply retroactively without legally sufficient notice and consent. Changes required by law or that strengthen protection may take effect on notice.

9.6 Order of precedence. In the event of a conflict concerning the same subject matter, the following order of precedence applies: (a) a clinic-specific privacy addendum, Business Associate Agreement, order, quotation, pricing arrangement or other document signed or electronically accepted by both parties; (b) this Agreement; and (c) other policies incorporated into this Agreement. A clinic-specific document prevails only to the extent of the conflict and only for the subject matter it addresses. A later version of this Agreement accepted by the Customer replaces earlier versions of this Agreement but does not amend or replace a clinic-specific document unless the later Agreement expressly identifies the clinic-specific document or provision being changed.

9.7 Severability, waiver and survival. Invalid provisions will be limited to the minimum extent necessary without affecting the remainder. A waiver must be in writing and does not waive later breaches. Provisions concerning payment, confidentiality, ownership, privacy, security, data return, liability and interpretation survive as necessary to give them effect.

 

Schedule A – Canadian Information Management and Privacy Terms

This Schedule forms part of the Agreement and applies whenever the Canadian Provider handles Personal Information or Personal Health Information for the Customer. For an Alberta Customer, it is intended to be the written Information Manager Agreement required under the Health Information Act and Health Information Regulation.

A1. Definitions and Roles

A1.1 Applicable Privacy Law. “Applicable Privacy Law” means Canadian federal, provincial and territorial privacy and health-information law applicable to the Customer Data or Services, including successor legislation. “Personal Information” includes Personal Health Information and other information about an identifiable individual.

A1.2 Customer role. The Customer remains the custodian, trustee, organization or controller recognized by Applicable Privacy Law. It determines purposes, authorizes users, supplies lawful instructions, provides required notices, obtains required consent, maintains record-retention compliance and responds to individual rights requests.

A1.3 Information Manager role. The Canadian Provider acts as an information manager, information management service provider, electronic service provider, agent and/or service provider as applicable. It will comply with duties directly imposed on it and with the Customer’s lawful documented instructions.

A2. Information and Authorized Services

A2.1 Information covered. The information covered includes patient and clinic demographic, contact, appointment, billing, insurance, clinical, image, document, communication, audit, transcription, audio-in-processing and other information entered into, collected through or generated by DOMx.

A2.2 Authorized services. The authorized purposes are operating, hosting, transmitting, synchronizing, backing up, securing, supporting, maintaining and troubleshooting DOMx; processing payments and communications; transcribing audio; generating draft clinical documentation; and performing other subscribed practice-management functions described in an accepted order.

A2.3 Limits. The Canadian Provider will collect, access, use, disclose, retain, modify and destroy Personal Information only as necessary for authorized services, the Customer’s lawful instructions, security, or legal requirements. It will not sell Personal Information, use it for targeted advertising, or use identifiable patient information to train public or foundation AI models.

A3. Location, Personnel, Subprocessors and Legal Demands

A3.1 Canadian production environment. The production environment for identifiable Canadian patient information is designed to use Microsoft Azure services deployed in Canada. This commitment is subject to the documented architecture, necessary network transmission, disaster recovery, security operations and legally compelled access. The Canadian Provider will not describe a Global AI deployment as Canada-only processing.

A3.2 Material location changes. The Canadian Provider will provide advance notice, where required by law or contract, before a material change that would routinely process identifiable Canadian patient information outside Canada. The Customer is responsible for any clinic-specific approval or PIA amendment required before enabling an optional feature with different processing.

A3.3 Personnel and subprocessors. Personnel must be authorized, trained as appropriate and bound by confidentiality. Subprocessors must be contractually bound to privacy and security obligations appropriate to the information and services. Access will be limited to the minimum reasonably necessary.

A3.4 Demands for disclosure. Unless prohibited by law, the Canadian Provider will notify the Customer of a legally compelled demand for identifiable patient information, disclose only what is legally required, and reasonably assist the Customer in seeking protective treatment or challenging an invalid demand.

A4. Individual Rights, Accuracy and Cooperation

A4.1 Requests. If the Canadian Provider receives an access, correction, complaint or other privacy request relating to Customer Data, it will promptly refer the requester to the Customer and notify the Customer. It will locate and supply relevant information within a reasonable time that permits the Customer to meet its legal deadline.

A4.2 Accuracy and amendment. Where the Canadian Provider maintains or updates Personal Information for the Customer, it will take reasonable steps appropriate to its role to preserve accuracy and will implement authorized corrections without altering the integrity of required audit information.

A4.3 PIA and regulatory cooperation. The Canadian Provider will reasonably cooperate with the Customer’s privacy impact assessment, Commissioner inquiry, complaint, audit or investigation. A direct audit must be proportionate, coordinated in advance, protect other customers and system security, and ordinarily rely first on available documentation and independent assurance reports.

A5. Incidents, Retention and Termination

A5.1 Privacy incident. In addition to Section 6.4, notice will include known categories of information and individuals affected, timing, likely consequences, containment and mitigation measures, and a contact for follow-up, to the extent available. The parties will cooperate on legally required notification; the Customer controls patient and regulator notices unless law requires the Canadian Provider to notify directly.

A5.2 Return and destruction. On termination or lawful written instruction, the Canadian Provider will return or make available Customer Data and securely destroy remaining copies after the transition period, subject to legal retention and protected backup cycles. If immediate destruction is infeasible, protections continue and use is limited to the reason retention is necessary.

A5.3 Privacy representatives. Each party will maintain a privacy contact with authority appropriate to administer this Schedule. The Customer’s contact is identified in its account or signature record. The Canadian Provider may be contacted at [email protected] unless a dedicated privacy address is later provided by notice.

A6. Jurisdiction-Specific Application

Applicable laws may include Alberta HIA/HIR; British Columbia PIPA; Manitoba PHIA; New Brunswick PHIPAA; Newfoundland and Labrador PHIA; Nova Scotia PHIA; Ontario PHIPA; Prince Edward Island HIA; Quebec private-sector privacy legislation; Saskatchewan HIPA; Northwest Territories HIA; Yukon HIPMA; PIPEDA where applicable; and successor legislation. This list does not replace a jurisdiction-specific assessment. A signed or electronically accepted clinic-specific addendum may supplement this Schedule where a regulator, PIA or mandatory law requires additional terms.