These Terms of Service (the "Terms") govern the use of the TestLedger™ Documentation Platform and related services (the "Services") provided by TestLedger LLC, a California limited liability company ("TestLedger," "we," "us," or "our"), by the entity or person accessing or using the Services ("Customer" or "you"). By accessing or using the Services, Customer agrees to be bound by these Terms.
Customer-controlled documentation platform provider. TestLedger maintains system-generated timestamps, completed record reference data, and supported export-comparison workflows for records entered by customer personnel. TestLedger does not create, select, validate, judge, or approve the underlying record content, and does not participate in employment decisions, program design, disciplinary decisions, regulatory submissions, or legal strategy.
These Terms are effective as of the date Customer first accesses the Services or the date of subscription, whichever is earlier (the "Effective Date"). These Terms, together with any applicable Business Associate Agreement and Order Form, constitute the agreement between TestLedger and Customer (the "Agreement").
1. Relationship to Business Associate Agreement
1.1 PHI and Business Associate Agreement. To the extent Customer uses the Services to create, receive, maintain, transmit, upload, store, process, access, or compare supported files containing Protected Health Information ("PHI") as defined under the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations ("HIPAA"), Customer's use of PHI-related functionality is governed by the applicable TestLedger Business Associate Agreement (the "BAA"), if executed by the parties. An eligible active paid Customer may select its contracting role in the authenticated application and electronically execute either the posted Standard Business Associate Agreement as a HIPAA Covered Entity or the posted Standard Subcontractor Business Associate Agreement as a Business Associate authorized to engage TestLedger downstream. A Customer using TestLedger only for non-PHI information does not execute a BAA and PHI-capable fields remain blocked. Requested language changes, customer paper, riders, additional terms, and Part 2 records require separate review. PHI/ePHI-capable workflows require an active paid subscription, active organization membership, an active agreement appropriate to the Customer's role, and backend account enablement.
1.2 Conflict and Order of Precedence. In the event of conflict regarding PHI, ePHI, HIPAA, Security Incidents, Breach notification, access to PHI, return or destruction, production deletion, backup remnants, infeasibility, or post-termination PHI obligations, the applicable BAA controls over these Terms, an Order Form, and this Privacy Policy. A later amendment or rider controls only to the extent it expressly identifies and modifies the applicable BAA provision. An Order Form controls service scope and commercial terms but does not reduce obligations under the HIPAA Rules unless it expressly identifies the BAA and modified provision and is executed by authorized representatives of both parties.
1.3 Defined Terms. HIPAA-related capitalized terms used in these Terms and not otherwise defined have the meanings assigned in the applicable BAA or HIPAA Rules. Other capitalized terms, including "Client Access Code," "Decryption Capability," "Encrypted Customer Data," and "Production PHI," have the meanings stated in these Terms or an applicable Order Form and are not incorporated into the BAA unless expressly stated there.
2. Customer-Controlled Protection Architecture
2.1 Supported Protection Features. Certain supported fields and workflows may use customer-controlled credentials, hashing, or encryption designed to reduce unnecessary exposure of sensitive information. TestLedger does not store the Customer's Client Access Code, known in the TestLedger platform as the Identity Protection Key, in the ordinary course of operations.
2.2 Operational Access Scope. TestLedger may process encrypted customer data, metadata, audit logs, system records, support information, and customer-authorized access pathways as necessary to provide, secure, maintain, support, or comply with legal obligations relating to the Services. Supported protection features do not mean that all Customer Data, metadata, logs, support records, backups, or administrative workflows are inaccessible to TestLedger in all circumstances.
3. Client Access Code Responsibility
3.1 Customer Control. Customer is solely responsible for maintaining, safeguarding, backing up, distributing, rotating, and managing the Client Access Code. TestLedger cannot recover the Client Access Code if lost. Loss, mismanagement, disclosure, or compromise of the Client Access Code may result in loss of access to encrypted or identity-protected Customer Data.
3.2 Customer Indemnification. TestLedger is not responsible for Customer's loss, disclosure, compromise, or mismanagement of the Client Access Code except to the extent directly caused by TestLedger's breach of its express obligations under the Agreement. Customer indemnification obligations relating to the Client Access Code are set forth in the applicable BAA, if executed by the parties.
4. No System of Record
4.1 No System of Record. Customer acknowledges that the Services are not Customer's designated record set, medical-record archive, laboratory record-retention system, employee medical-record repository, or legally required system of record.
4.2 Customer Retention Responsibility. Customer is solely responsible for exporting, preserving, and maintaining any records Customer is required to retain under HIPAA, the Clinical Laboratory Improvement Amendments (CLIA), employment law, state medical-record laws, laboratory regulations, tax law, contract, litigation hold obligations, or other applicable law. TestLedger is not Customer's long-term statutory record custodian unless a written agreement expressly states otherwise.
4.3 Limited Role. TestLedger's role is limited to secure hosting, workflow, transmission, reporting, cryptographic record completion, supported export-comparison functionality, and access during the active subscription term and applicable post-termination Export Period.
5. Prohibited Identifiers
5.1 Prohibited Data. Customer shall not upload, submit, store, or transmit through the Services any Social Security Numbers, taxpayer identification numbers, driver's license numbers, passport numbers, financial account numbers, payment-card numbers, biometric identifiers, biometric templates, genetic information, account passwords, authentication secrets, or other identifiers expressly prohibited by TestLedger's published acceptable use guidelines or applicable agreement. Photos and videos may be uploaded only as customer-provided supporting materials where Customer has determined collection, upload, retention, and disclosure are lawful. TestLedger does not perform facial recognition, biometric template creation, biometric identification, or identity matching unless expressly agreed in a separate written order.
5.2 Technical Controls. TestLedger may implement technical controls to detect and reject prohibited identifier formats, including without limitation client-side detection of nine-digit number patterns. Customer is solely responsible for ensuring that Customer Data does not include prohibited identifiers.
5.3 Indemnification. Customer indemnifies TestLedger for claims, losses, regulatory inquiries, or damages directly arising from Customer's violation of this Section 5, subject to the BAA's applicable limitations and carve-outs.
5.4 Drug, Alcohol, Cannabis, THC, and Workplace-Testing Records. Customer is solely responsible for determining whether any drug, alcohol, cannabis, THC, controlled-substance, prescription-medication, or workplace-testing test, panel, specimen type, collection process, result interpretation, documentation practice, disclosure, retention practice, accommodation process, safety-sensitive classification, or employment-related use is permitted under applicable federal, state, and local law. TestLedger does not determine impairment, drug-test validity, medical explanation, donor identity, specimen integrity, chain of custody, legal sufficiency, evidentiary admissibility, or whether any employment action is lawful. Customer shall not use TestLedger to make, automate, recommend, or justify an employment decision in violation of applicable law. Customer is solely responsible for all notices, consents, authorizations, employee communications, adverse-action procedures, MRO review, laboratory review, disability or medical-use accommodation processes, FCRA obligations, privacy obligations, and record-retention requirements applicable to Customer's use of the platform.
5.5 Prohibited Regulated-Use Shortcuts. Customer may not use TestLedger to evade cannabis or other employment protections, infer impairment from a THC-related or other workplace-testing result where not legally permitted, bypass required MRO or laboratory procedures, bypass accommodation obligations, replace DOT-required documentation, or create records for a testing program that Customer has not determined to be lawful.
5.6 No Advice or Employment-Decision Services. TestLedger does not provide legal, medical, human resources, compliance, regulatory, HIPAA, DOT, laboratory, MRO, consumer-reporting, background-screening, employment-decision, or adverse-action services. Customer is solely responsible for determining whether the Services are appropriate for Customer's intended use and for obtaining any required professional review.
6. PHI Feature Activation
6.1 PHI Features Disabled by Default. Features intended to handle PHI, including donor identity fields and supporting-file upload functionality, are disabled by default. Trial accounts are for evaluation with fictitious, synthetic, or non-PHI data only. Customer shall not upload, enter, transmit, paste, attach, or store PHI or ePHI in a trial account.
6.2 BAA and Backend Enablement Required. Customer shall not attempt to circumvent technical or contractual controls designed to prevent PHI use before applicable Business Associate Agreement execution and backend account enablement. Customer shall not upload PHI unless Customer has an active paid subscription, active organization membership, an active agreement appropriate to Customer's contracting role, and the relevant server-side PHI entitlement. Self-service execution of the posted BAA does not mean TestLedger has determined that HIPAA applies to Customer or that Customer Data is PHI.
7. Customer Sovereignty and Export Rights
7.1 Customer Data Ownership. Customer Data is owned by Customer. TestLedger's role is limited to secure hosting, workflow tools, access controls, and supported export-comparison functionality. Customer retains all right, title, and interest in and to Customer Data.
7.2 Export Rights. During the active subscription term and any applicable post-termination Export Period, Customer may export available Customer Data through the Services' export functionality. Exported records may include cryptographic signatures, timestamps, hashes, or other comparison artifacts designed to support comparison through the TestLedger Record Check Portal.
7.3 Customer Storage Responsibility. Customer is solely responsible for downloading, storing, securing, and retaining exported records on Customer-controlled infrastructure. TestLedger does not warrant that exported records will remain accessible through the Services after termination of the subscription beyond the Export Period.
8. Public Record Check Portal
8.1 Record Check Functionality. TestLedger may provide a public Record Check Portal that permits supported comparison of cryptographic artifacts associated with completed records. The Record Check Portal is intended to compare supported export data, signatures, timestamps, or hash relationships to a recorded reference state. A comparison result is not legal, medical, compliance, employment, testing, laboratory, MRO, evidentiary, or admissibility review.
8.2 Not a Storage System. The Record Check Portal is not a storage system, medical-record repository, laboratory archive, or source of substantive record content. The Record Check Portal does not replace Customer's obligation to retain original or exported records required by law, contract, investigation, audit, subpoena, or litigation hold.
8.3 Comparison Mechanism. The Record Check Portal relies on cryptographic artifacts and public key infrastructure, including applicable certificate chains and public key comparison mechanisms, designed to support comparison of exported records to completed-record reference artifacts. Use of the Record Check Portal does not require an active customer relationship with TestLedger. TestLedger does not warrant the perpetual continued operation of the Record Check Portal.
9. Post-Termination Export Period
9.1 Export Period Duration. Following cancellation, expiration, or termination of Customer's subscription, TestLedger will make Customer Data available to Customer through applicable Platform export functions for thirty (30) calendar days (the "Export Period"), unless a different period is stated in an applicable signed agreement or required by law. If a BAA applies, TestLedger will not block Customer's legally required access to PHI maintained on Customer's behalf solely to resolve a payment dispute.
9.2 Notification Cadence. TestLedger shall send notification reminders to Customer at days 7, 14, 21, and 28 of the Export Period, advising Customer of the upcoming production deletion and reminding Customer of the bulk download facility.
9.3 Customer Responsibility. During this Export Period, Customer may access the Services solely to download, export, or retrieve Customer Data. Customer is solely responsible for completing all desired exports before the Export Period concludes. Failure to export Customer Data during the Export Period constitutes Customer's authorization for TestLedger to proceed with production deletion in accordance with the Agreement and, where applicable, the BAA.
10. Production Deletion
10.1 Deletion at Export Period End. At the conclusion of the Export Period, TestLedger may delete or render inaccessible production Encrypted Customer Data maintained in primary storage and access systems.
10.2 Encrypted Data Scope. Production deletion applies to Encrypted Customer Data maintained by TestLedger in primary storage and access systems and does not imply that TestLedger has viewed or decrypted Customer PHI. Metadata, audit logs, system records, support information, backups, legal holds, and other exception records may be handled separately as described in these Terms and the BAA.
10.3 Exceptions. Production deletion does not constitute deletion of compliance documentation, audit/security records, backup remnants, or records retained under an infeasibility exception, legal hold, subpoena, regulatory inquiry, security incident investigation, disaster recovery restoration, or other legally required preservation condition. If a BAA applies, infeasibility exceptions for PHI are governed by the applicable BAA and any applicable Order Form.
11. Backup Remnant Lifecycle
11.1 Backup Remnant Lifecycle. Routine encrypted backup copies containing Customer Data may persist after production deletion. Backup remnants expire through ordinary backup lifecycle and are targeted to become unrecoverable by approximately day 95 after subscription access ends, except where preservation is required by law, legal process, litigation hold, regulatory inquiry, security incident investigation, disaster recovery restoration, or another documented infeasibility condition. A payment dispute alone does not authorize retention, use, disclosure, or denial of access to PHI contrary to an applicable BAA or the HIPAA Rules.
11.2 Continued Protection. Backup remnants retained under such conditions remain protected under applicable safeguards until purged or otherwise rendered unrecoverable.
12. Litigation Hold and Preservation Fees
12.1 Hold Notice. If Customer becomes subject to or reasonably anticipates litigation, regulatory inquiry, governmental investigation, subpoena, or other legal process requiring preservation of Customer Data, Customer may invoke a litigation hold by providing written notice to legal@testledger.io. The notice must identify the scope of Customer Data subject to the hold, affected individuals or matters, relevant date range, legal basis, and designated Customer contact.
12.2 Hold Mechanism. TestLedger may suspend scheduled deletion only for scoped data reasonably identified in the hold notice. Customer is solely responsible for determining when a litigation hold is required, issuing legally sufficient hold instructions, and releasing the hold when no longer required.
12.3 Preservation Fees. Customer shall pay TestLedger's then-current preservation fees for held Customer Data, prorated by storage volume preserved, beginning thirty (30) days after the litigation hold takes effect unless otherwise stated in an applicable Order Form or hold-specific addendum. If a hold persists for more than twelve (12) months, TestLedger may require migration of held Customer Data to long-term cold storage or a preservation-specific arrangement with adjusted fees.
12.4 BAA Reference. If a BAA applies, litigation hold obligations for PHI are governed by the applicable BAA and any applicable Order Form. In the event of conflict between this Section 12 and the applicable BAA regarding PHI, the BAA controls.
13. Production Deletion Statement
13.1 Statement Availability. Upon written request, TestLedger may provide one production deletion statement at no additional charge following completion of production deletion. The production deletion statement states, based on TestLedger system records, the production deletion completed in primary storage and access systems.
13.2 Statement Scope. The production deletion statement does not state or certify deletion of compliance documentation, audit/security records, routine backup remnants, or Customer Data retained under an infeasibility exception, litigation hold, subpoena, regulatory inquiry, security incident investigation, disaster recovery restoration, or other legally required preservation condition.
13.3 Additional Statements. Additional production deletion statements or supplementary documentation may be provided at TestLedger's then-current rates.
14. Risk Allocation and Limitation of Liability
14.1 Risk Allocation Acknowledgment. The limitation of liability, exclusions, indemnification obligations, and carve-outs applicable to the Services are set forth in these Terms, the BAA where applicable, and any applicable Order Form. Customer acknowledges that TestLedger's pricing reflects the limited platform-service role, supported customer-controlled protection features, Customer's control of the Client Access Code, Customer's responsibility for record retention, and the allocation of risk stated in the Agreement.
14.2 Limitation of Liability. Subject to applicable carve-outs, TestLedger's total cumulative liability under these Terms, the BAA, any Order Form, and the Services, in the aggregate across all claims, events, incidents, breaches, causes of action, theories of liability, and forms of relief, shall not exceed the aggregate Fees actually paid by Customer to TestLedger for the Services during the twelve (12) months immediately preceding the event giving rise to the claim. If Customer has used the Services for fewer than twelve (12) months as of the event giving rise to the claim, TestLedger's total cumulative liability shall not exceed the aggregate Fees actually paid by Customer to TestLedger through the date of the event giving rise to the claim. If a BAA applies, PHI-related liability terms are governed by the applicable BAA and any applicable Order Form.
14.3 Exclusion of Indirect Damages. Subject to applicable carve-outs, neither party shall be liable to the other for any indirect, incidental, special, consequential, exemplary, or punitive damages, or for lost profits, lost revenue, lost business opportunity, loss of goodwill, business interruption, loss of data, cost of substitute services, or reputational harm, regardless of the theory of liability.
14.4 Carve-outs. The limitations in Sections 14.2 and 14.3 do not apply to: (a) Customer's payment obligations; (b) Customer's indemnification obligations under Section 5.3 or the applicable BAA; (c) Customer's breach of Section 5, Prohibited Identifiers; (d) Customer's breach of Section 3, Client Access Code Responsibility; (e) Customer's breach of Section 4, No System of Record; (f) either party's willful misconduct or fraud; (g) liability that cannot be limited under applicable law; or (h) equitable relief sought to protect intellectual property, confidential information, PHI, security credentials, or platform integrity.
15. Subscription, Fees, and Billing
15.1 Subscription Tiers. TestLedger offers the Services through published subscription tiers, currently including Essentials and Professional, with capacity limits, feature availability, and pricing as specified in the applicable subscription plan or Order Form.
15.2 Fees. Customer shall pay all Fees applicable to the selected subscription plan as published or as set forth in the applicable Order Form. Fees are stated in United States Dollars and exclude applicable taxes, which Customer shall pay or reimburse TestLedger for as required by applicable law.
15.3 Billing and Renewal Consent. Subscription Fees are billed in advance on a monthly or annual basis according to the selected plan. Annual subscription Fees are paid in full at subscription start. Customer authorizes recurring charges for the selected plan and billing cadence when Customer accepts the renewal consent presented during checkout or account activation. Subscription access begins when Stripe confirms successful payment and TestLedger activates the workspace entitlement. TestLedger may suspend or terminate the Services for non-payment subject to reasonable notice and cure opportunity.
15.4 Refunds. Monthly subscriptions are billed in advance and are non-refundable except for duplicate charges, platform billing errors, or legally required refunds. Annual subscriptions are non-refundable after the initial thirty (30) day onboarding refund window unless TestLedger states otherwise in writing. Refund policies for custom subscriptions or separately signed Order Forms may be specified separately.
15.5 Tax Allocation. Customer is responsible for all applicable sales, use, value-added, withholding, and other taxes attributable to the Services, excluding taxes based on TestLedger's net income. Tax-exempt customers must provide valid exemption certificates.
15.6 Failed Payment and Dunning. If payment fails, TestLedger may provide a payment grace period of up to seven (7) days. If non-payment continues, TestLedger may restrict the account to export-only access or suspend paid workspace features by approximately day 14, subject to law, agreement terms, security needs, and operational feasibility.
16. Term and Termination
16.1 Term. These Terms remain in effect for the duration of Customer's subscription, including any renewals, until terminated as provided herein.
16.2 Termination by Customer. Customer may cancel the subscription at any time through the Services account management functions. Cancellation stops future renewal and takes effect at the end of the current paid billing period unless otherwise specified. Cancellation does not automatically refund fees already paid, except where required by law or expressly stated by TestLedger.
16.3 Termination by TestLedger. TestLedger may terminate the Agreement upon thirty (30) days written notice for material breach by Customer that remains uncured during the notice period, or immediately upon written notice if cure is not feasible or Customer's breach involves prohibited use of the Services or upload of prohibited identifiers.
16.4 Effect of Termination. Upon termination, Customer's access to the Services will be limited to the Export Period as set forth in Section 9, unless otherwise required by applicable law, Order Form, litigation hold, or the BAA. New uploads, new PHI/ePHI creation, and paid workspace features are disabled during export-only mode. Production customer content is targeted for deletion or de-identification by approximately day 60 after subscription access ends, subject to legal hold, security incident preservation, payment dispute, or technical infeasibility. Customer's obligations under Sections 3, 4, 5, 9, 10, 11, 12, 13, 14, 17, and 18, together with any accrued payment obligations, survive termination to the extent necessary to give effect to their terms. For PHI-related matters, the survival provisions of the BAA control.
17. Dispute Resolution
17.1 Informal Resolution. The parties shall attempt to resolve any dispute arising out of or relating to the Agreement through good faith negotiation. If the dispute is not resolved within thirty (30) days after written notice, either party may proceed to arbitration.
17.2 Binding Arbitration. Any dispute, controversy, or claim arising out of or relating to the Agreement shall be resolved by final and binding arbitration administered by JAMS in San Diego, California, before a single arbitrator, except as provided in Section 17.4.
17.3 Class Action Waiver. THE PARTIES AGREE THAT EACH MAY BRING CLAIMS AGAINST THE OTHER ONLY IN ITS INDIVIDUAL CAPACITY AND NOT AS A PLAINTIFF OR CLASS MEMBER IN ANY PURPORTED CLASS OR REPRESENTATIVE PROCEEDING.
17.4 Carve-outs. Either party may seek injunctive or equitable relief in court of competent jurisdiction to protect intellectual property, confidential information, PHI, security credentials, or platform integrity, or to collect unpaid Fees in small claims court.
17.5 Governing Law. The Agreement is governed by California law, without regard to its conflict of laws principles, except that HIPAA and other federal law shall control to the extent applicable.
18. General Provisions
18.1 Amendment. TestLedger may modify these Terms upon thirty (30) days notice to Customer. Continued use of the Services after the effective date of modifications constitutes acceptance of the modified Terms. Customer may terminate the subscription if Customer does not agree to the modified Terms.
18.2 Conflict. In the event of conflict between these Terms and the BAA regarding PHI matters, the BAA controls.
18.3 Entire Agreement. These Terms, together with the BAA and any applicable Order Form, constitute the entire agreement between the parties regarding the Services. The Privacy Policy describes TestLedger's privacy practices and applies as stated therein.
18.4 Independent Contractors. The parties are independent contractors. Nothing herein creates a partnership, joint venture, employment, or agency relationship.
18.5 Severability. If any provision is held invalid or unenforceable, the remaining provisions continue in full force and effect.
18.6 Assignment. Customer may not assign these Terms without TestLedger's prior written consent. TestLedger may assign these Terms in connection with a merger, acquisition, or sale of all or substantially all of its assets.
18.7 Notices. Notices to TestLedger shall be sent to legal@testledger.io. Notices to Customer shall be sent to the email address on file with the Services.
18.8 Force Majeure. Neither party shall be liable for delays or failures caused by events beyond reasonable control, including without limitation natural disasters, war, terrorism, civil unrest, governmental action, internet outages, or pandemics.
18.9 No Third-Party Beneficiaries. These Terms confer rights only on the parties and their permitted successors and assigns.
18.10 Construction. These Terms shall not be construed against either party as the drafter.