Version 1.0 — Effective Date: August 3, 2026 — Last Updated: August 3, 2026
Medicus Tiro Inc., a Colorado corporation, doing business as GME Manager
How to Read These Terms
Plain-Language Summary (provided for convenience only; it is not part of the agreement and does not modify the sections that follow; if the summary and the operative terms conflict, the operative terms control):
- GME Manager is licensed to institutions, not to individuals. A residency program, hospital, health system, or medical school signs up; its people then use the Service under that institution’s account and its policies.
- Do not put patient information in the Service. GME Manager is built as a No-PHI system. It is not an electronic health record, not a medical device, and not a clinical decision-support tool. The parties do not intend for Company to act as a HIPAA Business Associate unless they execute a Business Associate Agreement and Company expressly enables an approved PHI-capable configuration.
- AI drafts; humans decide. Every AI-assisted output is a draft. A qualified person must review, edit, and approve it before it is used for any evaluation, competency determination, attestation, promotion, remediation, or billing-related purpose.
- The Institution owns its Education Records. Residents may access and export designated portable copies through the Resident Portfolio, subject to institutional control of the underlying official records and the portfolio terms below.
- Institutions get a real exit. Export in standard formats, a defined post-termination export window, and defined deletion timelines.
- Where an Institution has signed a separate agreement, that agreement governs. These Terms fill gaps; they do not override a negotiated contract.
Structure of This Agreement: These Terms are organized in eight parts and three schedules. Part I establishes who is bound, how acceptance occurs, and which document controls when documents conflict. Part II describes the Service, accounts and roles, and acceptable use. Part III covers data ownership, the No-PHI architecture, FERPA, security, subprocessors, retention, and deletion. Part IV covers artificial intelligence: human review, accountability for consequential decisions, model training, and the documentation-support features. Part V contains commercial terms that apply only where no separate signed institutional agreement is in effect. Part VI allocates risk: warranties, disclaimers, liability limits, indemnities, and insurance. Part VII contains general legal provisions, including governing law and dispute resolution. Part VIII contains context-specific terms for the mobile applications, third-party integrations, and trademark non-affiliation. Schedules A through C contain the Acceptable Use Policy, Subprocessor Information, and Support and Service Levels.
PART I — AGREEMENT FRAMEWORK
1. Definitions
Capitalized terms have the meanings given below. Terms defined elsewhere in these Terms have the meanings given where they appear.
“ACGME” means the Accreditation Council for Graduate Medical Education.
“Affiliate” means any entity that controls, is controlled by, or is under common control with a party, where “control” means ownership of more than fifty percent (50%) of the voting interests.
“AI-Assisted Feature” means any functionality of the Service that uses artificial intelligence, machine learning, automated speech recognition, natural-language processing, large language models, or comparable automation to generate, extract, classify, summarize, route, score, flag, or draft content. AI-Assisted Features include, without limitation, the Action Rail, the Insight Rail, voice-enabled capture, structured field extraction, draft evaluation and narrative authoring, milestone and competency summarization, Clinical Competency Committee meeting support, early-warning detection, Individualized Learning Plan generation, Annual Program Evaluation preparation, attestation evidence aggregation, and the Documentation Support Features.
“Approved AI Output” means output generated by an AI-Assisted Feature that an Authorized User has reviewed, edited as appropriate, and affirmatively approved or submitted for official use in accordance with Section 9.3. Merely saving an AI-generated draft does not make it Approved AI Output.
“Authorized User” means an individual whom an Institution has provisioned and authorized to access the Service under the Institution’s account, including Program Directors, Associate Program Directors, Program Administrators and Coordinators, faculty, residents, fellows, institutional leaders, and approved technical or support personnel.
“Company,” “we,” “us,” and “our” mean Medicus Tiro Inc., a Colorado corporation, doing business as GME Manager.
“Company IP” means the Service, Documentation, software, source code, object code, models, prompts and prompt architecture, workflows, user-interface designs, curated reference data sets, templates, taxonomies, methodologies, know-how, trademarks, and other technology or materials owned or licensed by Company, excluding Institution Data.
“Consequential Decision” means a decision that has a material legal or similarly significant effect on an individual’s education, training, employment, credentialing, licensure, or professional standing. In the context of the Service, Consequential Decisions include decisions regarding milestone or competency determination, entrustment level, promotion or non-promotion, remediation, probation, extension of training, non-renewal, dismissal, graduation, board eligibility attestation, and any adverse action recorded in a trainee’s file.
“Documentation” means the user guides, implementation materials, administrator documentation, in-product help, and technical specifications that Company makes generally available for the Service, as updated from time to time.
“Documentation Support Features” means the Service functionality that prepares, checks, routes, or explains clinical and educational documentation for human confirmation, including teaching-physician attestation preparation, procedure documentation assurance, review-candidate detection, modifier and code-scenario support, and revenue outcome reconciliation.
“Education Record” means a record directly related to a Trainee and maintained by an Institution or by Company on the Institution’s behalf, including evaluations, competency and milestone assessments, entrustment observations, procedure logs, work-hour records, Clinical Competency Committee records, learning plans, remediation records, portfolio content, and related administrative records. This definition is intended to be read consistently with the Family Educational Rights and Privacy Act, 20 U.S.C. § 1232g, and its implementing regulations at 34 C.F.R. Part 99, where those authorities apply.
“FERPA” means the Family Educational Rights and Privacy Act and its implementing regulations, as amended.
“HIPAA” means the Health Insurance Portability and Accountability Act of 1996, the Health Information Technology for Economic and Clinical Health Act, and their implementing regulations at 45 C.F.R. Parts 160, 162, and 164, as amended.
“Institution” means the medical school, hospital, health system, sponsoring institution, residency program, fellowship program, or other graduate medical education organization that has contracted with Company, or that Company has approved, to access the Service, including an organization participating in a LaunchPad Pilot.
“LaunchPad Pilot” means a time-limited evaluation of the Service offered under Section 22 or under a separate written pilot agreement.
“Institution Data” means all data, content, records, files, configuration, and materials that an Institution or its Authorized Users submit to, generate within, or cause to be processed by the Service, including Education Records and Approved AI Output, but excluding Service Data and Company IP.
“Institutional Agreement” means a master services agreement, subscription agreement, order form, statement of work, pilot agreement, business associate agreement, data processing addendum, or other written agreement executed by authorized representatives of Company and an Institution that governs the Institution’s use of the Service.
“Order Form” means an ordering document executed by Company and an Institution specifying the subscribed features, user counts, term, and fees.
“PHI” means Protected Health Information as defined at 45 C.F.R. § 160.103, together with any other individually identifiable patient information, patient-identifying image, or record subject to comparable state or foreign law.
“Preview Feature” means any feature that Company designates as pilot, beta, preview, early access, limited availability, planned, vision, or by comparable words, including any feature labeled in Company marketing materials as “In Pilot,” “Planned,” or “Vision.”
“Resident Portfolio” means the component of the Service through which a Trainee may access or export designated portable copies of Education Records and other records made available to that Trainee.
“Service” means the GME Manager platform in Company’s production environment, including the web application, the mobile applications, the Data Gateway, the AI-Assisted Features, the Documentation, and any updates Company makes generally available, but excluding Preview Features except where expressly stated.
“Service Data” means data Company generates or collects in operating, securing, monitoring, supporting, and improving the Service, including telemetry, logs, diagnostics, security event data, performance metrics, and configuration metadata, in each case excluding Institution Data.
“Subprocessor” means a third party engaged by Company to process Institution Data in the course of providing the Service.
“Trainee” means a resident, fellow, or other individual whose education, training, or performance is documented in the Service.
“You” and “your” mean the person or entity accepting these Terms. Where the accepting party is an Institution, “you” means the Institution and its Authorized Users collectively. Where the accepting party is an individual Authorized User, “you” means that individual.
2. Acceptance and Who Is Bound
2.1 Acceptance. An Institution accepts these Terms only through an Order Form, Institutional Agreement, or other acceptance completed by a representative authorized to bind the Institution. An individual Authorized User accepts the provisions applicable to that individual by clicking to accept, creating or activating an account, or accessing or using the Service. An individual Authorized User does not bind an Institution merely by accessing or using the Service. If you do not agree to the provisions applicable to you, do not access or use the Service.
2.2 Authority. If you accept these Terms on behalf of an Institution, you represent and warrant that you are authorized to bind that Institution and that you have satisfied any internal approval, procurement, privacy, information security, or legal review requirement that applies. If you lack that authority, you may not accept these Terms on the Institution’s behalf.
2.3 Individual Authorized Users. Individual Authorized Users are bound by Sections 6 through 12, Section 14, Sections 15 through 19, Section 25, and Parts VII and VIII, together with Schedule A. An Authorized User’s acceptance does not create a direct commercial relationship with Company, does not entitle the Authorized User to the commercial terms in Part V, and does not displace the Institution’s control over its Institution Data.
2.4 Trainees. A Trainee’s use of the Service is a condition of participation established by the Institution, not by Company. Nothing in these Terms transfers to Company any authority over a Trainee’s education, evaluation, employment, or professional standing, and nothing in these Terms limits any right a Trainee holds under FERPA, an institutional policy, a collective bargaining agreement, a house-staff agreement, or applicable law.
2.5 No Individual Consumer Enrollment. The Service is not offered to consumers, patients, members of the general public, or individuals unaffiliated with an Institution. Company does not knowingly permit account creation by individuals under eighteen (18) years of age.
3. Order of Precedence
3.1 Precedence. Where a conflict exists, the following order controls, from highest authority to lowest: (1) a fully executed Institutional Agreement, including any negotiated data processing addendum, security exhibit, or business associate agreement; (2) an executed Order Form, as to the commercial terms it specifies; (3) these Terms; (4) Schedules A through C to these Terms; (5) the Privacy Policy; (6) the Documentation and any in-product notice.
3.2 Effect on Part V. Where an Institutional Agreement or Order Form addresses a subject covered in Part V (Commercial Terms), the Institutional Agreement or Order Form controls in full as to that subject, and the corresponding provision of Part V does not apply.
3.3 No Implied Amendment. A purchase order, vendor portal registration, procurement form, invoice, or comparable business document does not amend these Terms, and any additional or conflicting terms in such a document are rejected and have no effect, even if Company accepts payment referencing it.
3.4 Publication Consistency. Company will maintain a single authoritative version of these Terms at gmemanager.ai/legal/terms. Where any Company website, mobile application, App Store listing, marketing page, or product screen presents terms that differ from the version published at that URL, the version at that URL controls.
4. Changes to These Terms
4.1 Material Changes — Institutions. Company will provide written notice to each Institution’s designated administrative contact at least thirty (30) days before a material change to these Terms takes effect. A change is material if it materially reduces Institution rights, materially expands Institution obligations, materially changes how Institution Data is used or disclosed, or introduces a new category of Subprocessor with access to Institution Data.
4.2 Material Changes — Authorized Users. Company will provide notice of material changes to Authorized Users through an in-product notice, an email to the address associated with the account, or both, before the change takes effect.
4.3 Objection and Termination. An Institution that objects in writing to a material change before its effective date may, as its exclusive remedy, terminate the affected subscription effective as of the change date and receive a pro-rata refund of prepaid, unused fees for the terminated portion of the then-current term. The change will not apply to that Institution during the notice period.
4.4 Non-Material and Required Changes. Company may make non-material changes, and changes required to comply with law, regulation, court order, accreditation requirement, or an urgent security need, effective upon posting. Company will describe such changes in the change log referenced in Section 4.5.
4.5 Change Log and Versioning. Company will maintain a dated version history at gmemanager.ai/legal/terms identifying the effective date of each material version and summarizing what changed. Company will retain material prior versions for a commercially reasonable period and make them available to an Institution on reasonable request.
4.6 Continued Use. Continued use of the Service after a change takes effect constitutes acceptance of the changed Terms, except where applicable law, an Institutional Agreement, or an institutional policy requires affirmative written consent.
PART II — THE SERVICE
5. Service Description and Feature Availability
5.1 Description. GME Manager is a competency-based graduate medical education workflow platform for residency and fellowship programs, currently offered as GME Manager: Family Medicine Edition. The Service includes only the features expressly identified as enabled in the applicable Order Form, Institutional Agreement, subscription tier, pilot scope, or production configuration. Depending on that enabled scope, the Service may include competency-based evaluation and milestone tracking, faculty evaluation authoring with human review workflow, point-of-observation and ad hoc assessment capture, entrustable professional activity and entrustment observation support, procedure logging with supervision validation, clinical and educational work-hour tracking with compliance flags, Clinical Competency Committee meeting support with structured voting and minutes, early-warning detection and Individualized Learning Plan generation, Annual Program Evaluation preparation, board attestation evidence aggregation, continuity-of-care tracking, the Resident Portfolio, the Data Gateway for import and export, the Action Rail and Insight Rail, voice-enabled mobile capture, and the Documentation Support Features. The inclusion of a capability in this description does not represent that it is enabled, generally available, or licensed for a particular Institution.
5.2 What the Service Is Not. The Service is not, and must not be used or represented as, a patient-facing application, an electronic health record, a medical device, clinical decision support, a clinical care application, a billing or coding system of record, a claims submission system, a credentialing primary source verification service, a system of record for accreditation reporting except as expressly agreed, or a substitute for the professional judgment of faculty, program leadership, coding professionals, compliance officers, or legal counsel.
5.3 Feature Availability Varies. Enabled features vary by Institution, subscription tier, deployment, specialty edition, pilot scope, production build, and applicable Order Form. Nothing in Company marketing materials, demonstrations, prototypes, illustrative product views, roadmaps, or sales communications creates an entitlement to any feature. Only the features identified in an Order Form, or made generally available to the Institution’s subscription tier, are licensed.
5.4 Preview Features. Preview Features are provided for evaluation only, are excluded from any binding service levels established in an Order Form, Institutional Agreement, or separate service-level agreement unless that document expressly states otherwise, are provided AS IS and without warranty or indemnity of any kind, may be changed, limited, or discontinued at any time without notice, and may be subject to reduced support and additional restrictions. Institution Data submitted to a Preview Feature may be deleted when the Preview Feature ends. An Institution should not use a Preview Feature for any Consequential Decision, any regulatory or accreditation submission, or any billing-related purpose unless Company has confirmed in writing that the feature is generally available.
5.5 No Reliance on Roadmap. Company may label capabilities as available now, in pilot, planned, or vision. Labels other than “available now” describe development intent, not commitment. Purchase decisions must be based on features generally available on the Order Form effective date. Company undertakes no obligation to develop, release, or continue any planned capability.
5.6 Changes to the Service. Company may modify, update, enhance, or discontinue features of the Service. Company will not materially degrade the core functionality identified in an Institution’s Order Form during the then-current subscription term without providing a reasonably comparable replacement or the termination and refund right described in Section 4.3.
5.7 Specialty Editions and Data Sets. Company provides curated reference data sets configured for the applicable specialty edition. An Institution may customize these data sets within the Service but may not extract, redistribute, sublicense, or use them outside the Service. Company does not warrant that any curated data set reflects the current requirements of any accrediting or certifying body; the Institution remains responsible for confirming current requirements with the applicable body.
6. Accounts, Roles, and Access Control
6.1 Institutional Accounts. The Service is licensed to Institutions. Each Institution designates one or more administrators responsible for provisioning and deprovisioning Authorized Users, configuring permissions and role assignments, configuring autonomy settings for AI-Assisted Features, and ensuring that use of the Service complies with institutional policy and applicable law.
6.2 Role-Based Access. The Service supports differentiated access by role, including Program Director, Coordinator or Program Administrator, Faculty, and Resident or Fellow. Each Authorized User may access only the data and workflows made available to that user’s assigned role and permissions. An Institution is responsible for confirming that its role assignments reflect each individual’s legitimate educational or administrative need to know.
6.3 Program Director Override. Where enabled, the Program Director Override permits a Program Director to temporarily assume access to Coordinator-owned screens. Every activation is audit-logged with actor, timestamp, and scope. The Institution is responsible for governing the use of this capability under its own policy.
6.4 Individual Accounts Required. Each Authorized User must access the Service through an individual account tied to that user’s identity and role. Credential sharing, shared or generic accounts, session sharing, and token sharing are prohibited. An Authorized User is responsible for safeguarding credentials and for all activity occurring under the user’s account.
6.5 Single Sign-On and Provisioning. Where supported, the Service integrates with an Institution’s single sign-on provider. The Institution is responsible for identity provider configuration, timely provisioning, and, critically, timely deprovisioning upon role change, transfer, leave, graduation, resignation, non-renewal, or termination. Company is not responsible for access that persists because an Institution failed to deprovision an account.
6.6 Notification of Compromise. You must notify Company at [email protected] without undue delay, and in no event more than twenty-four (24) hours, after becoming aware of any actual or suspected unauthorized access to the Service or compromise of credentials.
6.7 Suspension. Company may suspend an account, a user, a feature, or an entire Institution’s access, in whole or in part, where Company reasonably determines that suspension is necessary to prevent unauthorized access, protect the security or integrity of the Service or the data of others, stop the transmission of PHI or malicious code, or comply with law. Company will limit any suspension in scope and duration to what the circumstance reasonably requires, will provide notice as soon as reasonably practicable, and will restore access promptly once the cause is resolved. Suspension for a cause attributable to the Institution does not relieve the Institution of fee obligations.
7. Acceptable Use
7.1 Permitted Purpose. You may use the Service solely for legitimate graduate medical education administrative, educational, evaluative, and program-management purposes, in accordance with these Terms, Schedule A, the Documentation, institutional policy, and applicable law.
7.2 Prohibited Conduct. The Acceptable Use Policy at Schedule A is incorporated into these Terms and forms part of them. Violation of Schedule A is a material breach.
7.3 Enforcement. Company may investigate suspected violations and may remove or disable access to content that violates these Terms. Company will notify the Institution’s designated contact of any enforcement action affecting that Institution’s Authorized Users, except where notice is prohibited by law or would compromise an active investigation.
8. Institution Responsibilities
The Institution is responsible for, and Company reasonably relies on the Institution for, each of the following:
- Determining that use of the Service is permitted under the Institution’s own privacy, information security, research, human resources, accreditation, and academic policies, and completing any internal review those policies require.
- Providing any notice to, and obtaining any consent or authorization from, Authorized Users and Trainees that applicable law, institutional policy, a house-staff or collective bargaining agreement, or an accreditation requirement may require in connection with the Service, including any notice required regarding the use of AI-Assisted Features and voice capture.
- The accuracy, legality, and completeness of Institution Data it submits, including roster, role, scheduling, rotation, and program configuration data.
- Configuring roles, permissions, and autonomy settings appropriately, and reviewing them periodically.
- Ensuring that Authorized Users are trained on the No-PHI requirement in Section 10 and on the human review requirement in Section 15 before being granted access.
- Designating and maintaining current administrative, security, and privacy contacts with Company.
- Making all Consequential Decisions through its own faculty, committees, and leadership, in accordance with its own due process requirements.
PART III — DATA, PRIVACY, AND COMPLIANCE
9. Data Ownership and License Grants
9.1 Institution Data. As between Company and the Institution, the Institution owns and retains all right, title, and interest in Institution Data, including all Education Records. Company claims no ownership in Institution Data.
9.2 License to Company. The Institution grants Company a limited, non-exclusive, worldwide, royalty-free license to host, store, transmit, display, reproduce, and process Institution Data solely to (a) provide, secure, monitor, support, and maintain the Service for the Institution; (b) prevent or address technical, security, or fraud problems; (c) comply with law; and (d) perform the specific additional purposes expressly authorized in Sections 9.5 and 17. This license terminates upon deletion of the Institution Data in accordance with Section 13, except to the extent Company must retain a copy to comply with law.
9.3 Approved AI Output. An AI-Assisted Feature’s output becomes Approved AI Output, and therefore Institution Data, when an Authorized User reviews it, edits it as appropriate, and affirmatively approves or submits it for official use. An AI-generated draft that is merely saved, autosaved, cached, or retained for later review remains a draft and is not Approved AI Output. Company asserts no ownership over Approved AI Output.
9.4 Resident Portfolio. As between Company and the Trainee, the Trainee may access and export the designated portable copies made available within the Resident Portfolio, subject to the Institution’s continuing ownership and control of the underlying Education Records. After completion, withdrawal from, or other departure from a training program, Company may provide the Trainee continued access to, or an export of, designated portable portfolio records under Company’s then-current Resident Portfolio terms. Continued hosted access is subject to reasonable authentication, security, storage, technical, and legal limitations; may be offered through a separate account or service tier; and is not guaranteed indefinitely. Company may modify or discontinue hosted portfolio access on reasonable advance notice, provided that Company offers a reasonable opportunity to export available portable records before discontinuation, except where prohibited by law or necessary to address an urgent security risk. If Company ceases operations, Company will use commercially reasonable efforts to provide an export opportunity before service wind-down. Nothing in this Section permits a Trainee to alter an Institution’s official Education Records or to extract or redistribute another individual’s records, Company IP, or curated data sets.
9.5 De-Identified and Aggregated Data. Company may create and use de-identified and aggregated data derived from Institution Data for the purposes of operating, securing, troubleshooting, benchmarking, and improving the Service, and for producing aggregate research, benchmarking, and reporting outputs, provided that Company: (a) de-identifies the data using methods reasonably designed to prevent re-identification of any individual, Institution, or program; (b) does not attempt to re-identify, and contractually prohibits recipients from attempting to re-identify, the data; (c) does not disclose data attributable to an identified or reasonably identifiable Institution, program, or individual without that party’s written consent; and (d) does not use de-identified data to train or fine-tune any third-party foundation model except as permitted by Section 17. An Institution may opt out of inclusion in benchmarking outputs by written notice to Company. This Section survives termination.
9.6 Company Intellectual Property. Company and its licensors retain all right, title, and interest in and to the Service, including its software, source code, models, prompts, prompt architecture, workflow designs, data structures, schemas, user interface designs, curated data sets, Documentation, Service Data, and trademarks, including GME MANAGER, ACTION RAIL, INSIGHT RAIL, VARIABLE AUTONOMY, PHYSICIAN AS THE SOURCE OF TRUTH, and LAUNCHPAD PILOT. Except for the limited license granted in Section 9.7, no rights are granted by implication, estoppel, or otherwise.
9.7 License to You. Subject to these Terms and payment of applicable fees, Company grants the Institution a limited, non-exclusive, non-transferable, and non-sublicensable right during the subscription term to access and use the Service, and to permit its Authorized Users to do so, for the Institution’s internal graduate medical education purposes. Suspension and termination of this right are governed by these Terms and any applicable Institutional Agreement.
9.8 Feedback. If you provide suggestions, ideas, enhancement requests, or other feedback regarding the Service, Company may use it without restriction, attribution, or obligation. This Section does not grant Company any license to Institution Data and does not permit Company to use Institution Data as feedback.
9.9 Reservation. All rights not expressly granted are reserved.
10. No-PHI Architecture and HIPAA Position
10.1 Design Commitment. The Service is architected as a No-PHI system. It is designed to process graduate medical education administrative and educational information only. It is not designed, tested, validated, or offered to receive, store, process, or transmit PHI.
10.2 Prohibition. You must not enter, upload, dictate, record, transmit, paste, or store PHI in the Service. This prohibition applies to every input surface, including free-text fields, procedure logs, evaluation narratives, voice capture, support messages, file uploads, camera and photo capture, optical character recognition, and profile images. Prohibited content includes patient names, medical record numbers, account numbers, dates of birth, dates of service, addresses, contact details, device identifiers, biometric identifiers, diagnoses tied to an identifiable patient, clinical notes, electronic health record extracts or screenshots, clinical images, patient photographs, images containing patient identifiers, and any other information that identifies a patient or provides a reasonable basis to identify a patient.
10.3 De-Identified Clinical Context Is Permitted. Nothing in this Section prevents an Authorized User from documenting educational content in a de-identified manner — for example, describing a procedure type, complexity, supervision level, or teaching point without reference to any identifiable patient. Educational documentation should describe what the Trainee did and how the Trainee performed, not who the patient was.
10.4 Not a Business Associate. Because the Service is not intended to create, receive, maintain, or transmit PHI on behalf of a covered entity, Company does not act as a Business Associate as defined at 45 C.F.R. § 160.103, and no business associate agreement is in effect unless Company and the Institution have executed one in writing. The inadvertent submission of PHI by an Authorized User does not create a business associate relationship, does not constitute Company’s agreement to act as a Business Associate, and does not cause the Service to become subject to HIPAA obligations on Company’s part. If an Institution determines that its intended use requires a business associate agreement, it must contact Company before that use begins; Company may decline, and may condition any such agreement on additional terms, fees, and technical controls.
10.5 Inadvertent Submission and Remediation. If an Authorized User submits PHI, or discovers that PHI has been submitted, the Authorized User must (a) stop, (b) report the event promptly under the Institution’s policy, and (c) notify Company at [email protected]. Company will, upon written request from the Institution and to the extent technically feasible, purge the identified content from the production environment promptly and from backups through the ordinary backup-expiration cycle, which will not exceed ninety (90) days, and will provide the Institution a written confirmation of the actions taken and a description of any system that retained a copy. The Institution remains responsible for any breach analysis, risk assessment, and notification obligation arising under HIPAA or state law from its own workforce’s submission of PHI.
10.6 Right to Reject and Suspend. Company may, without liability, block, quarantine, or delete content it reasonably believes contains PHI, and may suspend a user, a feature, or an Institution’s access under Section 6.7 where PHI submission is repeated or systemic.
10.7 Guardrails Are Not a Guarantee. Company implements design guardrails intended to reduce the risk of PHI capture, including prompt scoping, entity-extraction filtering, provider configurations designed to minimize retention, and in-product warnings at capture surfaces. These are risk-reduction measures. They are not a filter, a guarantee, or a substitute for user discipline, and Company does not warrant that they will detect or prevent every instance of PHI submission.
10.8 Allocation. Liability arising from PHI submitted in breach of this Section is allocated under Sections 26 and 27.
11. FERPA and Institutional Control of Education Records
11.1 Institution as Controller. Where FERPA applies, the Institution is the educational agency or institution that maintains and controls the Education Records. Company maintains Education Records solely on the Institution’s behalf and processes them only under the Institution’s direction and the terms of this agreement.
11.2 School Official Designation. The Institution designates Company as a “school official” with a “legitimate educational interest” in Education Records under 34 C.F.R. § 99.31(a)(1)(i)(B), for the limited purpose of performing an institutional service or function for which the Institution would otherwise use its own employees. In accepting that designation, Company: (a) performs a service the Institution would otherwise perform itself; (b) is under the Institution’s direct control with respect to the use and maintenance of Education Records; (c) uses Education Records only for the purposes authorized in this agreement; and (d) does not redisclose Education Records to any third party except as permitted by 34 C.F.R. § 99.33(a) and this agreement. The Institution is responsible for including “contractors, consultants, volunteers, and other outside service providers” in the school-official criteria stated in its FERPA annual notification.
11.3 Direct Control. The Institution may direct Company in writing to correct, restrict, disclose, export, or delete Education Records, and Company will comply within a commercially reasonable period, subject to Company’s retention obligations under law and Section 13.
11.4 Trainee Requests. A Trainee’s request to inspect, review, or seek amendment of an Education Record must be directed to the Institution. Company will not independently grant, deny, or adjudicate such a request, and will support the Institution’s response, including by producing records in a usable format at no additional charge.
11.5 Redisclosure. Company will not disclose Education Records to any third party except (a) to a Subprocessor bound by written obligations at least as protective as those in this Section and Section 12; (b) as the Institution directs in writing; (c) as required by law, subject to Section 11.6; or (d) to the Trainee, in the case of designated portable records made available to that Trainee through the Resident Portfolio. Company will maintain a record of any redisclosure required by law and make it available to the Institution where permitted.
11.6 Compelled Disclosure. If Company receives a subpoena, judicial or administrative order, civil investigative demand, or other compulsory legal process seeking Institution Data, Company will, unless legally prohibited: (a) promptly notify the Institution before disclosing, and in any event within three (3) business days of receipt; (b) provide the Institution a reasonable opportunity to seek a protective order or quash the process; (c) disclose only the narrowest set of records responsive to the process; and (d) reasonably cooperate with the Institution’s efforts at the Institution’s expense. Company will direct requesting parties to the Institution wherever it is lawful and practicable to do so.
11.7 Other Regimes. Where an Institution or its Authorized Users are subject to other privacy regimes — including state comprehensive privacy laws, state student-data-privacy laws, the General Data Protection Regulation, or the privacy requirements of a foreign jurisdiction — the parties will execute an appropriate data processing addendum, which upon execution controls over this Section as to the subject matter it addresses.
11.8 No Sale; No Advertising; No Cross-Context Tracking. Company does not sell Institution Data or personal information, does not share it for cross-context behavioral advertising, does not use it for third-party advertising, and does not use it to track users across applications or websites owned by other companies. Where applicable law so provides, Company acts as a service provider or processor and not as a business, controller, or third party with respect to Institution Data.
12. Security, Subprocessors, and Incident Response
12.1 Security Program. Company will maintain a written information security program with administrative, technical, physical, and organizational safeguards reasonably designed to protect Institution Data against unauthorized access, use, disclosure, alteration, and destruction. The program will include, at minimum: role-based access control and least-privilege provisioning; individual authenticated accounts with multi-factor authentication for administrative access; encryption of Institution Data in transit using industry-standard protocols and at rest; segregation of production from non-production environments; secure software development practices and code review; vulnerability management and periodic penetration testing; logging and monitoring of security-relevant events; audit logging of access to Education Records; documented change management; background-checked personnel with confidentiality obligations and security awareness training; a documented business continuity and disaster recovery plan; and a documented incident response plan tested at least annually.
12.2 Security Posture Disclosure. Company will make available, on reasonable request and subject to appropriate confidentiality obligations, then-current information describing its security program, Subprocessor information, available penetration-testing summary, and the status of any third-party assessment or attestation. Company will not represent that it holds a certification, assessment, or attestation unless it is then current and applicable to the Service.
12.3 Assessments. No more than once per twelve (12) months, and upon at least thirty (30) days’ written notice, an Institution may request completion of a reasonable written security questionnaire, or review Company’s then-current attestation reports and penetration test summary, in each case subject to confidentiality obligations. Company will respond within thirty (30) days. On-site or intrusive testing requires Company’s prior written consent and a separate written protocol, and may not be performed against the production environment.
12.4 Subprocessors. Company may engage Subprocessors to provide the Service. Company will: (a) maintain current Subprocessor information in Schedule B or on the legal page identified there; (b) impose on each Subprocessor written data-protection and confidentiality obligations appropriate to the nature of its processing; (c) remain responsible for each Subprocessor’s performance to the extent required by applicable law and the applicable Institutional Agreement; and (d) provide Institutions reasonable advance notice of a new Subprocessor that will materially process Institution Data.
12.5 Subprocessor Change Notice and Objection. An Institution may object in writing to a new Subprocessor on reasonable data-protection grounds within thirty (30) days after notice. The parties will work in good faith to identify a commercially reasonable alternative. If no reasonable alternative is available, either party may terminate the affected Service on written notice, and Company will refund any prepaid, unused fees for the terminated portion.
12.6 Inference-Layer Retention. Company will configure AI inference and transcription providers used for production Institution Data to prohibit provider model training and to minimize provider retention consistent with the applicable service configuration and security requirements. Company will disclose any material provider retention applicable to Institution Data in Schedule B or the then-current Subprocessor information. Company will not knowingly make a material adverse change to an identified retention configuration without notice under Section 12.5.
12.7 Data Location. Company will store Institution Data at rest in the United States. Company may process Institution Data in other locations only as disclosed in Schedule B, as required to provide user-requested support, or as authorized in an Institutional Agreement. Company will provide notice under Section 12.5 before materially changing the primary region in which Institution Data is stored at rest.
12.8 Security Incident Notification. Company will notify the Institution’s designated security contact without undue delay, and in any event within seventy-two (72) hours, after confirming a Security Incident affecting that Institution’s Institution Data. “Security Incident” means a confirmed unauthorized access to, acquisition of, disclosure of, or loss of Institution Data in Company’s possession or control. Unsuccessful attempts, pings, scans, and routine blocked access attempts are not Security Incidents and do not require notice.
12.9 Contents of Notice; Cooperation. Company’s notice will describe, to the extent then known and as information becomes available: the nature and scope of the incident, the categories and approximate volume of records affected, the Authorized Users and Trainees affected, the root cause, the containment and remediation steps taken and planned, and a point of contact. Company will provide reasonable cooperation and information necessary for the Institution to meet its own notification obligations. Company will not notify an Institution’s Trainees or regulators about an incident affecting that Institution without the Institution’s prior written consent, except where Company is independently required by law to do so, in which case Company will coordinate content and timing with the Institution to the extent lawful.
12.10 Remediation Costs. To the extent a Security Incident results directly from Company’s material breach of Section 12.1, Company will bear its own reasonable investigation and remediation costs. Any obligation to reimburse an Institution for notification, credit monitoring, forensic investigation, or comparable third-party costs is subject to Sections 26 and 27 and any applicable Institutional Agreement.
12.11 Your Security Obligations. You are responsible for maintaining the security of your own systems, endpoints, networks, and identity provider; for enforcing your own password and multi-factor authentication policies; for timely deprovisioning; for restricting access to devices used to access the Service; and for promptly reporting suspected compromise under Section 6.6.
13. Export, Retention, and Deletion
13.1 Export During the Term. The Data Gateway supports export of Institution Data in CSV, Excel, PDF, and JSON formats, and supports ACGME WebADS-format export where applicable. Institutions may export at any time during the subscription term at no additional charge.
13.2 Post-Termination Export Window. For ninety (90) days after expiration or termination of a subscription, Company will maintain the Institution’s ability to export Institution Data in the formats described in Section 13.1. Company may condition access during this window on payment of undisputed amounts then due. On written request made during the window, Company will provide a one-time structured export at no charge.
13.3 Deletion. After the export window closes, Company will delete Institution Data from production systems within thirty (30) days and from backups within the ordinary backup expiration cycle, which will not exceed ninety (90) days. Company will certify deletion in writing on request. Company may retain Institution Data beyond these periods only (a) as required by law, (b) as necessary to resolve a pending dispute or legal hold, (c) in de-identified and aggregated form under Section 9.5, or (d) in immutable security and audit logs retained under Company’s log retention schedule, in each case subject to continuing confidentiality and security obligations.
13.4 Retention During the Term. Company retains Institution Data for the subscription term and as directed by the Institution. Institutions are responsible for determining the retention periods required by their accreditation, licensure, board, employment, and record-retention obligations, and for configuring the Service and their own export cadence accordingly. Company does not warrant that its default retention configuration satisfies any Institution’s regulatory retention requirement.
13.5 Voice and Transient AI Data. Company configures applicable AI inference and transcription providers to prohibit provider model training and to minimize retention consistent with the applicable service configuration and security requirements. Material provider retention is disclosed in the then-current Subprocessor information. Structured output derived from voice capture, once reviewed and approved by an Authorized User, is retained as part of the applicable workflow record.
13.6 Account Deletion. Where the Service supports account creation, an Authorized User may initiate deletion of that user’s account from within the mobile application and from account settings on the web. Because Education Records belong to the Institution, deletion of an individual account removes the individual’s access and profile but does not delete Education Records the Institution is obligated to maintain. Company will disclose this distinction to the user at the point of deletion. Where an account was created using Sign in with Apple, deletion will also revoke the associated Apple tokens.
13.7 Resident Portfolio. Section 9.4 and any applicable account terms presented to the Trainee govern any continued access to or export of designated portable portfolio records after termination of an Institution’s subscription. Institution Data that is not designated for portable portfolio access remains subject to Sections 13.2 and 13.3.
14. Confidentiality
14.1 Definition. “Confidential Information” means non-public information disclosed by one party to the other that is designated as confidential or that a reasonable person would understand to be confidential given its nature and the circumstances of disclosure. Institution Data is the Institution’s Confidential Information. The Service, Documentation, security documentation, pricing, and non-public roadmap information are Company’s Confidential Information.
14.2 Obligations. The receiving party will (a) use Confidential Information only to perform under this agreement, (b) protect it with at least the care it uses for its own confidential information and no less than reasonable care, and (c) disclose it only to personnel, Affiliates, and advisors who need it and who are bound by confidentiality obligations at least as protective.
14.3 Exclusions. Confidential Information does not include information that is or becomes public through no fault of the receiving party, was known to the receiving party without restriction before disclosure, is rightfully received from a third party without restriction, or is independently developed without use of the disclosing party’s Confidential Information.
14.4 Compelled Disclosure. A receiving party may disclose Confidential Information to the extent legally compelled, subject to the notice and cooperation obligations in Section 11.6.
14.5 User Confidentiality. Authorized Users will encounter confidential educational, evaluative, workforce, peer-review, and institutional information about identifiable individuals. Authorized Users must use such information only for authorized graduate medical education purposes and must not disclose it except as permitted by their Institution, applicable agreements, or law. Certain records accessed through the Service may be subject to peer review, quality assurance, or professional review privilege under applicable law; nothing in these Terms is intended to waive any such privilege, and the Institution remains responsible for asserting and preserving it.
14.6 Duration. Confidentiality obligations continue for three (3) years after disclosure, and indefinitely for Institution Data, Education Records, and trade secrets, in each case for so long as the information remains protectable.
PART IV — ARTIFICIAL INTELLIGENCE
15. AI-Assisted Features: Human Review Is Mandatory
15.1 Assistive Only. AI-Assisted Features produce drafts, suggestions, extractions, summaries, flags, and workflow aids. They do not produce decisions, findings, determinations, attestations, or final records. No AI-Assisted Feature output is authoritative until a qualified Authorized User has reviewed it, edited it as appropriate, and affirmatively approved it.
15.2 Mandatory Human Review. Before any AI-Assisted Feature output is submitted, finalized, exported, transmitted to an accrediting or certifying body, entered into a Trainee’s record, or relied on for any Consequential Decision or billing-related purpose, a qualified Authorized User with appropriate role authority must review it for accuracy, completeness, fairness, and appropriateness. This obligation is non-delegable to the Service and may not be satisfied by bulk approval, by approval without review, or by any configuration that approves output automatically.
15.3 No Autonomous Decisions. Company does not, and the Service is not designed to, make autonomous determinations about a Trainee’s competence, entrustment, milestone level, promotion, remediation, probation, extension, graduation, board eligibility, employment, or professional standing, or about patient care, diagnosis, treatment, or clinical judgment. Every such determination is made by the Institution’s faculty, committees, and leadership.
15.4 Variable Autonomy. Where the Service offers configurable autonomy levels for AI agents, the Institution’s Program Director or designated administrator selects the level for each agent. Higher autonomy levels reduce the number of human checkpoints in a workflow. The Institution is responsible for selecting a level appropriate to the workflow, for documenting that selection, for reviewing it periodically, and for the consequences of the level selected. Company will document the behavior of each autonomy level in the Documentation and will not silently change the behavior of a configured level.
15.5 Accuracy Not Warranted. AI-Assisted Feature outputs may contain errors, omissions, fabrications, outdated information, and biases, including biases that could disadvantage individuals by race, ethnicity, national origin, sex, gender identity, sexual orientation, disability, age, religion, English-language proficiency, medical school of origin, or other protected or sensitive characteristic. Bias-mitigation features, including structured voting and bias prompts in Clinical Competency Committee workflows, are aids to human deliberation. They are not a validation of fairness, are not an audit, and do not establish that any output or decision is unbiased or lawful.
15.6 Attribution and Disclosure. An Authorized User must not present AI-drafted content as independently authored where institutional policy, professional standards, or applicable law requires disclosure of AI assistance. The Institution is responsible for establishing its attribution and disclosure policy. Where the Service records that an output originated from an AI-Assisted Feature, the Institution should retain that metadata as part of its record.
15.7 Audit Trail. The Service records, for AI-assisted workflows, the fact of AI involvement, the reviewing user, the approval or rejection action, the timestamp, and material edits made before approval. Company will retain this audit trail for the subscription term and will make it available to the Institution on request and in the export under Section 13.
16. Consequential Decisions and Human Accountability
16.1 Institution Is the Decision-Maker. The Institution, and not Company, makes every Consequential Decision affecting a Trainee. Company provides workflow tooling and drafts; the Institution provides judgment, process, and due process.
16.2 Adverse Action Requirements. Before taking any adverse action against a Trainee — including a finding of unsatisfactory milestone attainment, non-promotion, remediation, probation, extension of training, non-renewal, or dismissal — where an AI-Assisted Feature output, early-warning flag, or automated score materially informed the action, the Institution will: (a) ensure the underlying output has been reviewed and approved by a qualified human under Section 15.2; (b) ensure the action is supported by evidence independent of the AI-Assisted Feature output; (c) follow its own due process, grievance, and appeal procedures; and (d) preserve the record, including the audit trail described in Section 15.7.
16.3 Notice and Appeal. The Institution is responsible for providing Trainees any notice regarding the use of automated or AI-assisted tools in their evaluation, and any right to review, correct, contest, or appeal, that applicable law or institutional policy requires. Company will provide the Institution reasonable assistance, including plain-language descriptions of what each AI-Assisted Feature does, what inputs it uses, and what its known limitations are.
16.4 Evolving AI Regulation. The parties acknowledge that laws governing automated decision-making in education, credentialing, and employment continue to develop. Company will, on reasonable request, provide available documentation reasonably necessary for an Institution to understand the intended purpose, inputs, known limitations, and human-review controls of the applicable AI-Assisted Features. Each party remains responsible for determining and meeting the legal obligations applicable to its own role and use of the Service, and the parties will negotiate in good faith any amendment reasonably required for compliance.
16.5 Employment-Related Use. Where an Institution uses the Service, or output generated in it, in connection with hiring, retention, compensation, credentialing, or other employment decisions regarding faculty, staff, or Trainees, the Institution is solely responsible for compliance with employment, anti-discrimination, and automated-decision laws applicable to that use, including any bias audit, notice, or accommodation requirement. Company does not offer the Service as an employment selection or screening tool.
17. Model Training and Provider Use
17.1 No Training on Institution Data. Company will not use Institution Data, and will not permit any Subprocessor to use Institution Data, to train, fine-tune, evaluate, or improve any third-party foundation model or any model made available to other customers, except with the Institution’s separate prior written authorization. Authorization by acceptance of these Terms alone does not constitute such authorization.
17.2 Service Improvement. Company may use Service Data and de-identified, aggregated data under Section 9.5 to improve the Service, including to evaluate prompt performance, measure quality, and tune retrieval and routing logic that does not require model training on identifiable Institution Data.
17.3 Provider Configuration. Company will contract with its AI, transcription, and image-processing providers on terms that prohibit use of Company’s or Institutions’ data for provider model training and that support the retention-minimization and disclosure commitments described in Section 12.6.
17.4 Human Review of Training Decisions. Any change to Company’s practice under this Section is a material change requiring notice under Section 4.1.
18. Documentation Support and Revenue Assurance Features
18.1 Scope. Where enabled, the Documentation Support Features prepare, check, route, and explain clinical and educational documentation for human confirmation. They may include teaching-physician attestation preparation, procedure documentation assurance, detection of records that are candidates for human review, support for modifier and code-scenario evaluation, and reconciliation reporting.
18.2 What These Features Do Not Do. The Documentation Support Features do not select final billing codes, do not assign final modifiers, do not generate or submit claims, do not certify medical necessity, do not attest to the accuracy or completeness of any record, do not replace an Institution’s coding, compliance, revenue-cycle, or electronic health record systems, and do not constitute coding advice, billing advice, compliance advice, legal advice, or an opinion on the correctness of any claim.
18.3 Human Confirmation Required. Every output of a Documentation Support Feature requires confirmation by a qualified human — a treating or teaching physician for an attestation, and a qualified coding or compliance professional for any coding-related determination — before it is used, submitted, or relied upon. The Institution and the individual clinician remain solely responsible for the accuracy and truthfulness of any attestation, documentation, or certification, and for every claim submitted to any federal health care program, state program, or commercial payer.
18.4 Regulatory Responsibility. The Institution acknowledges that the submission of claims implicates the False Claims Act, 31 U.S.C. §§ 3729–3733, the Civil Monetary Penalties Law, Medicare teaching physician documentation requirements at 42 C.F.R. § 415.172 and applicable manual provisions, and comparable state law, and that responsibility for compliance with those authorities rests with the Institution and its clinicians. Company’s outputs are inputs to the Institution’s own compliance process and do not create, satisfy, or evidence compliance with any such authority.
18.5 No Payment Guarantee. Company does not guarantee that any documentation prepared or checked with these features will result in payment, will survive audit, or will be accepted by any payer, contractor, or auditor.
18.6 Institution Compliance Program. The Institution will subject its use of the Documentation Support Features to its own compliance program oversight, including auditing and monitoring, and will not use the features to increase documentation or coding intensity absent independent clinical justification.
18.7 Separate Enablement Required. Documentation Support Features are not enabled under these Terms alone. They may be enabled only if identified in an Order Form and governed by a separate Documentation Support Addendum or comparable written terms executed by authorized representatives of Company and the Institution. Company may require acknowledgment or approval by the Institution’s compliance, coding, or revenue-cycle leadership before enablement. If no such addendum is in effect, the Institution is not licensed to use Documentation Support Features.
19. No Clinical Use
19.1 Prohibition. The Service must not be used for diagnosis, treatment, triage, clinical decision-making, patient safety decisions, prescribing, care planning, or any other clinical purpose, and must not be relied on in the delivery of patient care.
19.2 Not a Medical Device. The Service is not intended to be, and has not been evaluated or cleared as, a medical device under the Federal Food, Drug, and Cosmetic Act or any comparable authority. Company does not claim any exemption or classification under 21 U.S.C. § 360j(o) and does not offer the Service as clinical decision support.
19.3 Supervision Determinations. Where the Service records supervision levels, entrustment observations, or procedure approvals, those records document educational assessment after the fact. They do not authorize, direct, or substitute for real-time clinical supervision decisions, which remain the responsibility of the supervising physician and the Institution.
PART V — COMMERCIAL TERMS
The provisions of this Part apply only where no executed Institutional Agreement or Order Form addresses the subject, in accordance with Section 3.2.
20. Fees, Invoicing, and Taxes
20.1 Fees. Subscription fees are set out in the applicable Order Form. Fees are based on the features, user tiers, program counts, and term specified there.
20.2 Invoicing and Payment. Unless the Order Form states otherwise, fees are invoiced annually in advance and are due within thirty (30) days of the invoice date. Fees are non-refundable except as expressly provided in Sections 4.3, 12.5, 21.4, and 24.3.
20.3 Late Payment. Undisputed amounts more than thirty (30) days overdue may accrue interest at the lesser of one percent (1%) per month or the maximum permitted by law. Company will provide at least ten (10) business days’ written notice before suspending the Service for non-payment. Company will not suspend access to a Resident Portfolio for the Institution’s non-payment.
20.4 Disputed Amounts. An Institution may withhold a disputed amount if it notifies Company in writing within twenty (20) days of the invoice date, identifies the basis for the dispute, and pays all undisputed amounts. The parties will resolve the dispute in good faith. Company will not suspend the Service or charge interest on a properly disputed amount while the dispute is pending.
20.5 Mid-Term Increases. Company will not increase fees during a subscription term. Company may adjust renewal pricing on at least sixty (60) days’ written notice before the renewal date.
20.6 Overages. If usage materially exceeds the tiers in the Order Form, Company will notify the Institution and the parties will agree in good faith on an adjustment for the following term. Company will not assess retroactive overage charges without prior written notice and an opportunity to reduce usage.
20.7 Taxes. Fees exclude sales, use, VAT, GST, and comparable transaction taxes, which are the Institution’s responsibility, excluding taxes on Company’s net income. An Institution claiming exemption must provide a valid exemption certificate.
20.8 Purchase Orders. Where an Institution requires a purchase order, it will provide one before the invoice date. Section 3.3 governs any terms printed on it.
21. Term, Renewal, Termination, and Effects
21.1 Term. The subscription term is stated in the Order Form. If no term is stated, the term is twelve (12) months from the effective date.
21.2 Renewal. Subscriptions renew for successive terms of equal length unless either party gives written notice of non-renewal at least sixty (60) days before the end of the then-current term. Company will send a renewal reminder at least ninety (90) days before the renewal date, identifying the renewal date, the non-renewal deadline, and any pricing change.
21.3 Termination for Convenience. Either party may terminate effective at the end of the then-current term by the notice described in Section 21.2. Termination for convenience mid-term does not entitle the Institution to a refund unless the Order Form provides otherwise.
21.4 Termination for Cause. Either party may terminate for the other’s material breach if the breach is not cured within thirty (30) days after written notice describing it. Either party may terminate immediately on written notice if the other becomes insolvent, makes an assignment for the benefit of creditors, or becomes subject to a bankruptcy proceeding not dismissed within sixty (60) days. If the Institution terminates for Company’s uncured material breach, Company will refund prepaid, unused fees for the remainder of the term.
21.5 Termination for Regulatory or Accreditation Cause. An Institution may terminate on thirty (30) days’ written notice if a change in law, regulation, accreditation requirement, or institutional governance determination makes continued use of the Service materially unlawful or non-compliant and the parties cannot agree on a commercially reasonable modification within that period. Company will refund prepaid, unused fees.
21.6 Effect of Termination. Upon expiration or termination: the license in Section 9.7 ends and Authorized Users must stop accessing the Service; all accrued and unpaid amounts become due; Section 13 governs export, retention, and deletion; and Sections 9.1, 9.4, 9.5, 9.6, 9.8, 10.4, 10.8, 11.5, 11.6, 13, 14, 17.1, 18.3, 18.4, 24, 25, 26, 27, 28, 30, and 34 survive, together with any other provision that by its nature should survive.
21.7 Transition Assistance. On written request made before the end of the export window in Section 13.2, Company will provide reasonable transition assistance, including export-format documentation and commercially reasonable technical support, at Company’s then-current professional-services rates or at no charge where the Institution terminated under Section 21.4 or 21.5.
22. LaunchPad Pilot and Evaluation Use
22.1 Pilot Terms. An Institution may participate in a LaunchPad Pilot for thirty (30) days at no charge, or for such other period as Company specifies in writing. All provisions of these Terms apply during a pilot except as modified in this Section.
22.2 Pilot Service Levels. Pilot access is provided AS IS. Any binding service levels established in an Order Form, Institutional Agreement, or separate service-level agreement do not apply to pilot use unless that document expressly states otherwise. Section 24.2 warranty and Section 27.1 indemnity do not apply to pilot use. Company may modify or terminate a pilot at any time on notice.
22.3 Pilot Data. If the Institution does not convert to a paid subscription within thirty (30) days after the pilot period ends, Company will retain pilot data for an additional sixty (60) days to allow export and will then delete it in accordance with Section 13.3. Company will send a written reminder at least fifteen (15) days before deletion.
22.4 Pilot Liability. For pilot use where no fees are paid, Company’s aggregate liability is limited as provided in Section 26.3.
22.5 Real Data in Pilots. If an Institution submits real Education Records during a pilot, all obligations in Part III apply to that data in full, including the FERPA, security, incident notification, export, and deletion obligations. The reduced warranty and service level position in Section 22.2 does not reduce Company’s data protection obligations.
23. Support and Service Levels
23.1 Support. Company provides support through the channels and during the hours described in Schedule C.
23.2 Availability. Unless an Order Form or Institutional Agreement expressly states a binding service level and remedy, any availability percentage described in Schedule C or Company materials is a non-binding operational target and not a warranty or service-level commitment.
23.3 Maintenance. Company will use reasonable efforts to perform scheduled maintenance outside peak usage windows and to provide advance notice of maintenance expected to cause material unavailability. Emergency maintenance may be performed without advance notice.
PART VI — WARRANTIES, DISCLAIMERS, AND RISK ALLOCATION
24. Representations and Warranties
24.1 Mutual. Each party represents and warrants that it has the power and authority to enter into this agreement and that its performance will comply with applicable law.
24.2 Company Service Warranty. Company warrants that, during the subscription term: (a) the Service will perform materially in accordance with the Documentation; (b) Company will provide the Service in a professional and workmanlike manner consistent with generally accepted industry standards; (c) Company will maintain the security program described in Section 12.1; and (d) Company will not materially decrease the overall security or functionality of the Service during the term.
24.3 Warranty Remedy. For a breach of Section 24.2(a), Company will use commercially reasonable efforts to correct the non-conformity. If Company cannot correct it within thirty (30) days after written notice, the Institution may terminate the affected subscription and receive a pro-rata refund of prepaid, unused fees. This is the Institution’s exclusive remedy for breach of Section 24.2(a) and does not limit remedies for breach of Sections 24.2(b) through (d) or for any matter excluded from the liability cap under Section 26.4.
24.4 Malicious Code. Company warrants that it will use industry-standard measures to ensure the Service does not contain viruses, worms, or other malicious code introduced by Company.
24.5 Institution Warranties. The Institution represents and warrants that: it has the right to submit Institution Data to the Service; it has provided all notices and obtained all consents required under Section 8; it will not submit PHI in breach of Section 10; and its use of the Service complies with its own policies, applicable law, and applicable accreditation requirements.
24.6 Anti-Corruption and Sanctions. Each party represents that it will comply with applicable anti-corruption, export control, and economic sanctions laws, and that it is not a person or entity with whom the other is prohibited from dealing under those laws.
25. Disclaimers
25.1 Exclusion. EXCEPT AS EXPRESSLY SET OUT IN SECTION 24, THE SERVICE IS PROVIDED “AS IS” AND “AS AVAILABLE.” TO THE MAXIMUM EXTENT PERMITTED BY LAW, COMPANY DISCLAIMS ALL OTHER WARRANTIES, EXPRESS, IMPLIED, STATUTORY, AND OTHERWISE, INCLUDING ANY IMPLIED WARRANTY OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, NON-INFRINGEMENT, ACCURACY, AND ANY WARRANTY ARISING FROM COURSE OF DEALING OR USAGE OF TRADE.
25.2 No Warranty of Outcome. COMPANY DOES NOT WARRANT THAT THE SERVICE WILL BE UNINTERRUPTED OR ERROR-FREE, THAT DEFECTS WILL BE CORRECTED, THAT AI-ASSISTED FEATURE OUTPUTS WILL BE ACCURATE, COMPLETE, CURRENT, OR UNBIASED, THAT USE OF THE SERVICE WILL RESULT IN ACCREDITATION, CONTINUED ACCREDITATION, A FAVORABLE SITE VISIT OUTCOME, BOARD ELIGIBILITY, ATTESTATION ACCEPTANCE, COMPLIANCE WITH ANY ACGME, ABFM, OR OTHER REQUIREMENT, PAYMENT OF ANY CLAIM, OR ANY PARTICULAR EDUCATIONAL, ADMINISTRATIVE, OR FINANCIAL OUTCOME.
25.3 Not Professional Advice. THE SERVICE AND ITS OUTPUTS DO NOT CONSTITUTE MEDICAL, CLINICAL, LEGAL, COMPLIANCE, CODING, BILLING, ACCREDITATION, EMPLOYMENT, OR HUMAN RESOURCES ADVICE. THE SERVICE IS NOT A SUBSTITUTE FOR PROFESSIONAL JUDGMENT, FACULTY REVIEW, PROGRAM DIRECTOR AUTHORITY, INSTITUTIONAL OVERSIGHT, COMMITTEE DELIBERATION, COMPLIANCE REVIEW, OR LEGAL COUNSEL.
25.4 User Conduct. COMPANY IS NOT RESPONSIBLE FOR PHI OR OTHER PROHIBITED CONTENT SUBMITTED IN BREACH OF SECTION 10, FOR AN INSTITUTION’S FAILURE TO DEPROVISION ACCESS, FOR FAILURE TO PERFORM THE HUMAN REVIEW REQUIRED BY SECTION 15.2, FOR AUTONOMY LEVELS SELECTED BY AN INSTITUTION UNDER SECTION 15.4, FOR CONSEQUENTIAL DECISIONS MADE BY AN INSTITUTION, OR FOR USE OF THE SERVICE OUTSIDE THE PERMITTED PURPOSE.
25.5 Preview Features. PREVIEW FEATURES ARE EXCLUDED FROM SECTION 24 IN THEIR ENTIRETY AND ARE PROVIDED WITHOUT WARRANTY OF ANY KIND.
25.6 Jurisdictional Limits. Some jurisdictions do not allow the exclusion of certain warranties. Where a disclaimer is prohibited, it applies to the maximum extent permitted and the remaining disclaimers remain in effect.
26. Limitation of Liability
26.1 Exclusion of Indirect Damages. TO THE MAXIMUM EXTENT PERMITTED BY LAW, NEITHER PARTY WILL BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR FOR LOST PROFITS, LOST REVENUE, LOST GOODWILL, LOSS OF BUSINESS OPPORTUNITY, OR THE COST OF SUBSTITUTE SERVICES, WHETHER IN CONTRACT, TORT, STRICT LIABILITY, OR OTHERWISE, AND WHETHER OR NOT THE PARTY WAS ADVISED OF THE POSSIBILITY.
26.2 General Cap. EXCEPT AS PROVIDED IN SECTIONS 26.3 AND 26.4, EACH PARTY’S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATED TO THIS AGREEMENT WILL NOT EXCEED THE AMOUNTS PAID OR PAYABLE BY THE INSTITUTION TO COMPANY UNDER THE APPLICABLE ORDER FORM IN THE TWELVE (12) MONTHS PRECEDING THE FIRST EVENT GIVING RISE TO THE CLAIM.
26.3 No-Fee and Individual User Cap. For Preview Features and any evaluation, trial, or other use for which no fees are paid, and for any claim by an individual Authorized User in that individual’s own capacity, Company’s total aggregate liability will not exceed one thousand United States dollars (US$1,000). A paid pilot is subject to Section 26.2 unless the applicable Institutional Agreement expressly provides otherwise.
26.4 Special Rules and Enhanced Cap. (a) Company’s obligations under Section 27.1 are subject to the General Cap in Section 26.2. (b) Company’s aggregate liability arising from its material breach of Section 12.1, Section 14, or Section 17.1 that results in a Security Incident, unauthorized disclosure of Institution Data, or unauthorized model training, including any obligation under Section 27.3, will not exceed three (3) times the amounts paid or payable by the Institution to Company under the applicable Order Form in the twelve (12) months preceding the first event giving rise to the claim. (c) The limitations in Sections 26.1 and 26.2 do not apply to the Institution’s payment obligations; either party’s gross negligence, willful misconduct, or fraud; or liability that cannot be limited under applicable law. (d) The Institution’s indemnity obligations arising from its intentional submission of PHI, willful violation of law, or willful misuse of the Service are not subject to the General Cap; all other Institution indemnity obligations are subject to the General Cap.
26.5 Public Institutions. Where the Institution is a public or state entity that cannot lawfully agree to a limitation of liability, indemnity, or arbitration provision, that provision applies only to the extent permitted by the law governing that entity, and the remainder of this agreement remains in effect. Nothing in this agreement waives any governmental or sovereign immunity.
26.6 Allocation. The parties acknowledge that these limitations are an essential basis of the bargain and reflect the allocation of risk that determined the fees. They apply even if a limited remedy fails of its essential purpose.
26.7 Claim Period. No claim arising out of this agreement may be brought more than two (2) years after the claiming party knew or reasonably should have known of the facts giving rise to it, except for claims for non-payment or where a longer period is required by law.
27. Indemnification
27.1 Company Indemnity — Intellectual Property. Company will defend the Institution and its trustees, officers, employees, and agents against any third-party claim alleging that the Service, as provided by Company and used in accordance with this agreement, infringes a United States patent, copyright, trademark, or trade secret, and will indemnify them against damages, costs, and reasonable attorneys’ fees finally awarded or agreed in settlement. This obligation does not apply to a claim arising from Institution Data, from use in combination with materials not supplied by Company where the claim would not have arisen absent the combination, from modification of the Service by anyone other than Company, or from continued use after Company has provided a non-infringing alternative.
27.2 Remedies for Infringement. If the Service is, or in Company’s reasonable opinion may become, subject to a claim under Section 27.1, Company may at its option and expense procure the right to continue use, replace or modify the Service to make it non-infringing while preserving materially equivalent functionality, or, if neither is commercially reasonable, terminate the affected subscription and refund prepaid, unused fees. This Section states Company’s entire liability for intellectual property infringement.
27.3 Company Indemnity — Data Protection. Company will defend the Institution and its trustees, officers, employees, and agents against a third-party claim to the extent arising directly from Company’s confirmed material breach of Section 12.1, Section 14, or Section 17.1 that results in a Security Incident, unauthorized disclosure of Institution Data, or unauthorized use of Institution Data for model training, and will indemnify them against damages, costs, and reasonable attorneys’ fees finally awarded or agreed in a settlement approved by Company. For a regulatory inquiry or governmental investigation arising from the same circumstances, Company will provide reasonable cooperation and information but is not obligated to assume the Institution’s defense. This obligation does not apply to the extent the matter arose from the Institution’s systems, instructions, configuration, delay, violation of these Terms, or failure to take reasonable mitigation steps. Company’s obligations under this Section are subject to the enhanced cap in Section 26.4(b) and the procedure in Section 27.5.
27.4 Institution Indemnity. To the extent permitted by applicable law, the Institution will defend and indemnify Company against third-party claims to the extent arising from the Institution’s material breach of these Terms, negligence, willful misconduct, or unlawful use of the Service, including: (a) Institution Data or PHI submitted in breach of Section 10; (b) failure to provide notice or obtain consent as required by Section 8; (c) failure to perform the human review required by Section 15.2 or 18.3; (d) a Consequential Decision made by the Institution independently of any representation by Company that the Service could replace required human judgment; (e) a claim, submission, or attestation made by the Institution to a payer or program in connection with the Documentation Support Features; or (f) the Institution’s breach of Section 7 or Schedule A. This Section does not require the Institution to indemnify Company for a claim to the extent caused by Company’s breach, negligence, willful misconduct, or violation of law.
27.5 Procedure. The party seeking indemnity will promptly notify the indemnifying party in writing, give the indemnifying party sole control of the defense and settlement (except that no settlement imposing a non-monetary obligation or admission on the indemnified party may be made without its consent, not to be unreasonably withheld), and provide reasonable cooperation at the indemnifying party’s expense. The indemnified party may participate with its own counsel at its own expense. Failure to give prompt notice reduces the indemnity only to the extent of resulting prejudice.
28. Insurance
Company will maintain, at its own expense, insurance appropriate to its size and the nature of the Service, which may include commercial general liability, technology errors and omissions, and cyber liability coverage. Company will provide certificates of insurance on reasonable request, subject to applicable confidentiality restrictions.
PART VII — GENERAL PROVISIONS
29. Compliance and Trainee Rights
29.1 Compliance with Law. Each party will comply with all laws applicable to its performance, including privacy, data protection, education records, employment, anti-discrimination, and, where applicable, health care laws.
29.2 No Waiver of Trainee Rights. Nothing in these Terms limits, waives, or modifies any right a Trainee has under FERPA, an institutional grievance or due process policy, a house-staff agreement, a collective bargaining agreement, ACGME institutional or program requirements, or applicable law. In the event of a conflict between these Terms and any such right, the right controls.
29.3 Accessibility. Company will use commercially reasonable efforts to design and maintain the Service with accessibility in mind and to address reported accessibility barriers. Any specific accessibility standard, conformance representation, remediation commitment, or accessibility report will apply only if stated in an Institutional Agreement or then-current Company documentation.
30. Governing Law and Dispute Resolution
30.1 Governing Law. This agreement is governed by the laws of the State of Colorado, excluding its conflict-of-law rules and the United Nations Convention on Contracts for the International Sale of Goods.
30.2 Escalation. Before initiating a formal proceeding, the parties will attempt in good faith to resolve the dispute through negotiation between executives with settlement authority for thirty (30) days after written notice of the dispute.
30.3 Arbitration. If the dispute is not resolved under Section 30.2, it will be finally resolved by binding arbitration administered by JAMS under its then-current Comprehensive Arbitration Rules and Procedures, before a single arbitrator, seated in Denver, Colorado. The arbitrator may award any remedy available in court. Judgment on the award may be entered in any court of competent jurisdiction. Each party bears its own costs and an equal share of the arbitrator’s fees unless the arbitrator determines otherwise.
30.4 Exceptions. Either party may seek injunctive or equitable relief in a court of competent jurisdiction to protect its intellectual property or Confidential Information, and either party may bring a claim in small claims court where jurisdictionally appropriate.
30.5 Carve-Out for Public Entities. Sections 30.1 and 30.3 do not apply to a public or state Institution whose governing law requires that disputes be governed by the law of, and resolved in the courts of, its own jurisdiction. For such an Institution, this agreement is governed by the law of that jurisdiction and disputes will be resolved in its courts, without waiver of any immunity.
30.6 Carve-Out for Individual Authorized Users. Where an individual Authorized User is a party to a dispute in that individual’s personal capacity, and applicable law limits the enforceability of a pre-dispute arbitration agreement, mandatory venue provision, or class action waiver against that individual, those provisions do not apply to that individual and the dispute will be resolved in a court of competent jurisdiction.
30.7 No Class Actions. To the extent permitted by law and subject to Sections 30.5 and 30.6, disputes will be resolved only on an individual basis, and neither party may bring a claim as a plaintiff or class member in a class, consolidated, or representative proceeding.
31. Publicity and References
Company may identify an Institution as a customer, and use the Institution’s name and logo, only with the Institution’s prior written consent, which may be given in the Order Form and may be revoked on thirty (30) days’ written notice. Company will comply with the Institution’s brand guidelines. Neither party will issue a press release referring to the other without prior written approval. Nothing in this Section prevents Company from disclosing the existence of the relationship where required by law or to a prospective acquirer, investor, or lender under confidentiality obligations.
32. Notices
32.1 To Company. Legal notices to Company must be sent to Medicus Tiro Inc., 8996 Mountain View Lane, Boulder, CO 80303, with a copy by email to [email protected].
32.2 To You. Notices to an Institution will be sent to the administrative and legal contacts the Institution has designated in the Order Form or in the Service. Notices to an Authorized User may be given by email to the address associated with the account or by in-product notice.
32.3 Effectiveness. Notice is effective on personal delivery, on the business day after deposit with a nationally recognized overnight courier, on the third business day after mailing by certified mail, or on transmission if sent by email during business hours to a designated address.
32.4 Operational Contacts. Operational, security, privacy, and support contact addresses are listed in Section 37 and may be updated by Company by posting.
33. General
33.1 Assignment. Neither party may assign this agreement without the other’s prior written consent, except that either party may assign it in its entirety, on notice, to a successor in connection with a merger, acquisition, corporate reorganization, or sale of substantially all assets. Any other attempted assignment is void. If Company assigns this agreement, Company will notify affected Institutions and the assignee will be bound by all obligations in Part III, including Sections 9.5, 11, 12, and 17.1.
33.2 Force Majeure. Neither party is liable for a failure or delay caused by an event beyond its reasonable control, including natural disaster, epidemic, war, terrorism, civil unrest, labor dispute, governmental action, utility or telecommunications failure, or failure of a third-party infrastructure provider, provided the affected party gives prompt notice and uses reasonable efforts to resume performance. This Section does not excuse payment obligations or obligations under Section 12.
33.3 Independent Contractors. The parties are independent contractors. This agreement creates no partnership, joint venture, agency, fiduciary, or employment relationship.
33.4 No Third-Party Beneficiaries. Except as stated in Section 35.9 with respect to Apple Inc., and except for Trainees with respect to Sections 9.4 and 29.2, this agreement creates no third-party beneficiary rights.
33.5 Severability. If a provision is held unenforceable, it will be modified to the minimum extent necessary to make it enforceable, or severed if modification is not possible, and the remainder will remain in effect.
33.6 Waiver. A failure or delay in exercising a right is not a waiver. A waiver is effective only if in writing and signed by the waiving party.
33.7 Entire Agreement. This agreement, together with the documents identified in Section 3.1, is the entire agreement between the parties on its subject matter and supersedes all prior and contemporaneous proposals, representations, demonstrations, marketing statements, and understandings, whether oral or written.
33.8 Interpretation. Headings are for convenience only. “Including” means “including without limitation.” A reference to a statute includes its implementing regulations and successors. Nothing in this agreement will be construed against a party as drafter.
33.9 Counterparts and Electronic Signature. This agreement may be executed in counterparts and by electronic signature, each of which is an original.
33.10 Language. The English-language version of this agreement controls.
PART VIII — CONTEXT-SPECIFIC TERMS
34. Mobile Applications
34.1 Scope. This Section applies to the GME Manager mobile applications in addition to the rest of these Terms.
34.2 Device Permissions. The mobile applications may request access to the microphone for voice capture, and, where enabled, to the camera and photo library. Access is requested at the point of use and may be declined or revoked in device settings. Declining a permission may disable the associated feature but does not otherwise limit access to the Service.
34.3 Voice Capture. Voice capture is user-initiated. Audio is transmitted for transcription and structured extraction. Company configures applicable providers to prohibit provider model training and to minimize retention consistent with the applicable service configuration; material provider retention is disclosed in the then-current Subprocessor information. The No-PHI obligations in Section 10 apply in full to anything spoken into the Service. In-product warnings are displayed at capture surfaces; those warnings do not reduce the Authorized User’s obligation under Section 10.2.
34.4 Images. Where profile photo, camera, optical character recognition, or image enhancement features are enabled, Authorized Users must not upload clinical imagery, patient photographs, electronic health record screenshots, or any image containing patient-identifying information.
34.5 Account Deletion. Section 13.6 governs in-application account deletion.
34.6 Platform Terms. Use of a mobile application is also subject to the terms of the platform from which it was obtained. Where those terms conflict with these Terms as to the platform relationship, the platform terms control as to that relationship.
35. Apple App Store Terms
The following apply to a mobile application obtained from the Apple App Store and are included to satisfy Apple’s minimum end-user license terms.
35.1 Acknowledgment. These Terms are between you and Medicus Tiro Inc. only, and not with Apple Inc. (“Apple”). Medicus Tiro Inc., not Apple, is solely responsible for the application and its content.
35.2 Scope of License. The license granted for the application is a non-transferable license to use the application on any Apple-branded product that you own or control, as permitted by the Usage Rules in the Apple Media Services Terms and Conditions, except that the application may be accessed and used by other accounts associated with you via Family Sharing or volume purchasing only where such use is also authorized by your Institution under Section 6.
35.3 Maintenance and Support. Medicus Tiro Inc. is solely responsible for maintenance and support of the application. Apple has no obligation to furnish any maintenance or support services.
35.4 Warranty. In the event of any failure of the application to conform to any applicable warranty, you may notify Apple, and Apple will refund the purchase price, if any, for the application. To the maximum extent permitted by law, Apple has no other warranty obligation with respect to the application. Any other claims, losses, liabilities, damages, costs, or expenses attributable to a failure to conform to a warranty are Medicus Tiro Inc.’s sole responsibility.
35.5 Product Claims. Medicus Tiro Inc., not Apple, is responsible for addressing any claims relating to the application or your possession and use of it, including product liability claims, any claim that the application fails to conform to a legal or regulatory requirement, and claims arising under consumer protection, privacy, or similar legislation, subject to the limitations in these Terms.
35.6 Intellectual Property Claims. In the event of a third-party claim that the application or your possession and use of it infringes that third party’s intellectual property rights, Medicus Tiro Inc., not Apple, is solely responsible for the investigation, defense, settlement, and discharge of the claim.
35.7 Legal Compliance. You represent and warrant that you are not located in a country subject to a United States Government embargo or designated as a “terrorist supporting” country, and that you are not listed on any United States Government list of prohibited or restricted parties.
35.8 Developer Contact. Questions, complaints, and claims regarding the application should be directed to Medicus Tiro Inc., 8996 Mountain View Lane, Boulder, CO 80303, [email protected].
35.9 Third-Party Beneficiary. Apple and its subsidiaries are third-party beneficiaries of these Terms as they apply to your license of the application, and upon your acceptance Apple will have the right, and is deemed to have accepted the right, to enforce these Terms against you as a third-party beneficiary.
35.10 App Store Custom Terms. Where Company submits a custom license agreement in App Store Connect, that submission must be plain text and must be kept consistent with the version published at gmemanager.ai/legal/terms, in accordance with Section 3.4.
36. Third-Party Services and Integrations
36.1 Integrations. The Service may support import from and export to third-party systems, including an Institution’s existing residency management platform. Where an Institution enables an integration, the Institution authorizes the resulting transfer of Institution Data and is responsible for the configuration, accuracy, and cadence of that transfer, and for its agreement with the third-party provider.
36.2 No Endorsement or Responsibility. Company does not control third-party systems and is not responsible for their availability, security, accuracy, or data practices. Company’s obligations under Part III apply to Institution Data in Company’s possession or control and do not extend to data after it has been delivered to a third-party system at the Institution’s direction.
36.3 Non-Affiliation. GME Manager is an independent product. Company is not affiliated with, sponsored by, endorsed by, certified by, or accredited by the Accreditation Council for Graduate Medical Education, the American Board of Family Medicine, any other accrediting or certifying body, Apple Inc., or any residency management platform provider. Third-party names and marks are used for identification only and remain the property of their owners. No representation by Company should be understood as a statement that any output will satisfy the requirements of any accrediting or certifying body.
37. Contact
Questions about these Terms may be directed to:
Medicus Tiro Inc. d/b/a GME Manager
8996 Mountain View Lane, Boulder, CO 80303
General: [email protected]
Legal notices: [email protected]
Privacy: [email protected]
Security incidents: [email protected]
Support: [email protected]
Public website: https://gmemanager.ai
Production application: https://app.gmemanager.ai
Terms: https://gmemanager.ai/legal/terms
Privacy Policy: https://gmemanager.ai/legal/privacy
Subprocessor Register: https://gmemanager.ai/legal/subprocessors
Schedule A — Acceptable Use Policy
This Schedule is incorporated into and forms part of the Terms of Service.
A.1 Patient Information. You must not enter, upload, dictate, record, transmit, paste, or store Protected Health Information or any patient-identifying information in the Service. This includes patient names, initials in combination with other identifiers, medical record numbers, account numbers, dates of birth, dates of service, addresses, telephone numbers, email addresses, device or implant identifiers, biometric identifiers, full-face or identifying photographs, diagnoses tied to an identifiable patient, clinical notes, electronic health record extracts or screenshots, clinical images, and any other information that identifies a patient or provides a reasonable basis to identify one.
A.2 Clinical Use. You must not use the Service, or any output of it, for diagnosis, treatment, triage, clinical decision-making, prescribing, care planning, real-time supervision decisions, or any other clinical purpose.
A.3 Access and Identity.
- Do not access another person’s account or data without authorization.
- Do not share credentials, sessions, tokens, or devices, or permit another person to use your account.
- Do not attempt to circumvent authentication, role-based access controls, permission boundaries, autonomy configurations, or institutional governance controls.
- Do not use the Service after your authorization has ended.
A.4 Integrity of the Record.
- Do not submit AI-generated content without the human review required by Section 15.2.
- Do not present AI-drafted content as independently authored where disclosure is required.
- Do not backdate, falsify, or misattribute an evaluation, observation, attestation, procedure log, or work-hour record.
- Do not use the Service to make an automated determination about a Trainee’s advancement without faculty or committee review.
- Do not enter content that is knowingly false, defamatory, harassing, or retaliatory.
A.5 Security and Technical Integrity.
- Do not upload malicious code or attempt to introduce a vulnerability.
- Do not probe, scan, or test the vulnerability of the Service without prior written authorization and an agreed protocol.
- Do not interfere with, overload, or disrupt the Service or its infrastructure.
- Do not use automated means to access the Service other than through documented interfaces.
- Do not circumvent rate limits, usage limits, or licensing controls.
A.6 Intellectual Property.
- Do not copy, scrape, reverse engineer, decompile, disassemble, or attempt to derive source code, model weights, prompts, or prompt architecture from the Service, except to the extent that restriction is unenforceable under applicable law.
- Do not extract, redistribute, sublicense, or use curated data sets outside the Service.
- Do not use the Service to build, train, or benchmark a competing product or service.
- Do not remove or obscure proprietary notices.
A.7 Legal and Institutional Compliance.
- Do not use the Service in violation of applicable law, institutional policy, professional obligation, accreditation requirement, or a Trainee’s due process rights.
- Do not use the Service in a manner that discriminates unlawfully against any individual.
- Do not use the Service to circumvent a records retention, litigation hold, or public records obligation.
A.8 Reporting. Report suspected privacy, security, data-quality, or misuse issues promptly to your Institution and to Company at [email protected] and the applicable address in Section 37.
Schedule B — Subprocessor Register
The following register identifies the principal Subprocessors used in the current production environment. The authoritative, current version is published at gmemanager.ai/legal/subprocessors and will identify its effective date. An applicable Institutional Agreement may further restrict or supplement this register. Company will provide notice of material changes as described in Section 14.
- Amazon Web Services (AWS): Cloud infrastructure, compute, database, object storage, encryption, backups, and related platform services. Institution Data and Service Data necessary to host and operate the Service. AWS us-west-1 (United States). Retention follows Service configuration, institutional requirements, and the deletion periods in Section 13.
- Cloudflare: Content delivery, DNS, TLS termination, web application firewall, DDoS protection, and edge security. Network, device, request, and security metadata; encrypted application traffic in transit. Cloudflare edge network; production origin remains in AWS us-west-1 (United States). Configured as a proxied security and delivery layer; retention follows the applicable service configuration.
- Groq Cloud: Large-language-model inference and speech-to-text transcription for user-initiated AI-Assisted Features. User-requested text, prompts, audio, and generated outputs necessary to complete the requested inference. Configured so AI request bodies, prompts, audio, and completions are not used to train third-party foundation models; material retention terms follow the approved provider configuration.
- Resend: Transactional email delivery. Recipient email address, delivery metadata, and the minimum notification content needed to send the message. Retention follows the provider configuration and Company operational requirements; sensitive record content should not be included in email unless expressly approved.
- hStream: Identity provider and single sign-on, when enabled for an Institution. User identity, work email address, authentication attributes, and role-related claims necessary for sign-in. Credential lifecycle and authentication retention are governed by the approved identity-provider configuration and applicable institutional terms.
- Replicate (optional; disabled unless separately enabled): Optional image enhancement or OCR functionality. Only images or documents intentionally submitted to an expressly enabled feature. Not used for an Institution unless expressly enabled and approved; applicable retention and data-handling terms must be documented before use.
Schedule C — Support and Service Levels
C.1 Support Channels. Support is available through in-product help, the Insight Rail Help and Support mode, in-application ticket submission, and email at [email protected]. Standard support hours are Monday through Friday, 8:00 a.m. to 8:00 p.m. Eastern Time (ET), excluding Company holidays.
C.2 Severity Levels and Target Response Times.
- Severity 1 — Critical: Service unavailable or a core workflow is unusable for all users at an Institution, with no workaround. Target initial response: 4 business hours. Status cadence: Every 4 business hours during support hours.
- Severity 2 — High: A core workflow is materially degraded or unavailable for a group of users, or a deadline-driven workflow is blocked. Target initial response: 1 business day. Status cadence: Daily during support hours.
- Severity 3 — Normal: A non-core function is impaired, or a core function has a workaround. Target initial response: 3 business days. Status cadence: Weekly.
- Severity 4 — Low: Question, documentation issue, or enhancement request. Target initial response: 5 business days. Status cadence: As appropriate.
C.3 Operational Availability Target. Company uses commercially reasonable efforts to maintain the availability of the production environment. Unless an Order Form or Institutional Agreement states otherwise, Company does not make a binding uptime commitment and does not provide service credits under these Terms. Preview Features are excluded from any availability target.
C.4 Negotiated Service Levels. If an Order Form or Institutional Agreement includes a binding availability commitment, that document must state the measurement period, monitoring source, downtime definition, exclusions, claim procedure, service-credit calculation, and any termination right for repeated failure. The negotiated terms control over this Schedule.
C.5 Deadline-Sensitive Periods. Company acknowledges that graduate medical education workflows are concentrated around recurring deadlines, including Clinical Competency Committee cycles, semiannual review periods, Annual Program Evaluation, board attestation windows, and the academic year transition. Company will use commercially reasonable efforts to avoid scheduled maintenance during periods an Institution has identified in advance as deadline-critical.
© 2026 Medicus Tiro Inc., doing business as GME Manager. The authoritative version of these Terms is published at gmemanager.ai/legal/terms.