Master Subscription Services Agreement | Nowsta

Master Subscription Services Agreement

EXHIBIT A MASTER SUBSCRIPTION SERVICES AGREEMENT (Revised May 18, 2026)

This Master Subscription Services Agreement, including all documents referenced herein (this “ Agreement”) is between Nowsta, Inc., (“ Nowsta”) (“ Nowsta” “ we,” “ us,” or “ our”) and you or the entity on behalf of whom you are purchasing or using the Services as specified in an Order (“ you” or “ your” or “ Subscriber”). This Agreement sets forth the terms and conditions that govern all Orders placed by you. Your use of the Marketplace is subject to additional terms and conditions found at www.nowsta.com/marketplace-terms-of-use/ (“ Marketplace TOU”) and any Integration Services ordered by you are subject to additional terms set forth in our Integration Services Addendum found at www.nowsta.com/integration-addendum/ (“ Integration Addendum”).

YOUR USE OF ANY PART OF THE SERVICES OR RECEIPT OF ANY SERVICES INDICATES THAT YOU ACCEPT THE TERMS OF THIS AGREEMENT. YOU REPRESENT THAT YOU HAVE THE AUTHORITY TO BIND SUCH ENTITY TO THIS AGREEMENT AND THAT “YOU” AND “YOUR” WILL REFER TO THAT COMPANY OR ORGANIZATION. IF YOU DO NOT AGREE TO THIS AGREEMENT OR DO NOT HAVE THE AUTHORITY SPECIFIED ABOVE, DO NOT USE SERVICES OR RECEIVE THE SERVICES. NOTE THAT ALL REFERENCES TO THE WORD “PURCHASE” OR “SELL” IN THESE TERMS MEANS “LICENSE” WITH RESPECT TO THE PLATFORM SERVICES AND MARKETPLACE.

NOW THEREFORE, the parties agree as follows:

1. DEFINITIONS.

For purposes of this Agreement, the following terms have the following meanings:

1.1 “Affiliate” means any entity which directly or indirectly, through one or more intermediaries, controls, or is controlled by, or is under common control with a party to this Agreement, by way of majority voting stock ownership or the ability to otherwise direct or cause the direction of the management and policies of such party, for as long as such control exists.

1.2 “Anonymized Data” means Subscriber Data that is de-identified in such a fashion that it cannot be re-identified with any known or reasonably anticipated technology. Without limiting the foregoing, “Anonymized Data” shall meet the definitions of “Aggregated consumer information” and “de-identified” under the California Consumer Protection Act (substituting “data subject” for “consumer” where applicable”).

1.3 “Confidential Information” means non-public information which one party (“ Discloser”) may disclose to the other party (“ Recipient”) in connection with this Agreement including: (a) Subscriber Data, (b) all software and technical information used to provide the Platform Services, Marketplace, and/or Integration Services; (c) the terms of this Agreement, (d) any commercial, financial, marketing, business, technical or other data, security measures and procedures, know-how, trade secrets or other information that: (i) in the case of information in tangible form, is marked “confidential” or “proprietary;” (ii) in the case of information disclosed orally, visually or any other intangible form, is designated confidential or proprietary at the time of disclosure; or (iii) under the circumstances, a person exercising reasonable business judgment would understand to be confidential or proprietary; and (e) any reproduction of such information in any form or medium, or any part of such information.

1.4 “Documentation” means the online documentation describing the use and/or operation of the Services which may be updated from time to time at our sole discretion (subject to Section 2.2).

1.5 “Integration Services” means the integration services to be provided to you pursuant to an Order and the additional provisions of the Integration Addendum.

1.6 “Marks” means Nowsta’s and its Affiliates’ logos, trademarks, trade names, slogans, designs, service marks and other identifying symbols that are or have been used by us or our Affiliates anywhere in the world.

1.7 “Marketplace” means the Nowsta Talent Marketplace where Subscribers can interact in order to provide or receive staffing services as further described in the Marketplace TOU.

1.8 “Order(s)” means (a) an order which specifies the Services to be provided by us and (b) any renewal thereof.

1.9 “Platform Services” means Nowsta’s cloud-based, SaaS solutions as described in the Documentation, excluding all Third-Party Applications, which are specified in your Order.

1.10 “Portal Addendum” means the addendum found at https://nowsta.com/portal-addendum/, pursuant to which Subscriber may request that certain of their customers/vendors, be provided access to a subset of the Platform Services (as described therein) for use solely in connection with such customers’/vendors’ relationship with Subscriber.

1.11 “Services” means (a) the Platform Services, (b) Integration Services, (c) the Marketplace, and (d) Documentation.

1.12 “Service Term” means the time period that the Platform Services and Marketplace are authorized for use as set forth in the applicable Order.

1.13 “Setup Services” means basic provisioning of the Platform Services for Subscriber.

1.14 “Statistical Data” means statistical and other information related to the operation, provision, use, and performance of the Services and related systems and technologies (including, without limitation, information extrapolated, concerning or derived from Subscriber Data).

1.15 “Subscriber Data” means all electronic data or information submitted to and stored in the Platform Services and Marketplace by you and/or you Users or that we collect from you or from any other person on your behalf and process via the Services (excluding Anonymized Data and Statistical Data).

1.16 “Third-Party Applications” means other products and services which are licensed or manufactured by a party other than us that are made available via the Services, but which do not form a part of the Services.

1.17 “Users” means individuals who are authorized by you to use the Platform Services and Marketplace pursuant to this Agreement. Users may include you and your employees, consultants, contractors, and agents. Subscriber’s Users who also provide staffing services to Subscriber or its customers/vendors are able to access certain portions of the Platform Services (such as time-keeping and scheduling) subject to the Nowsta Terms of Service for Workers found at www.nowsta.com/worker-terms-of-service/ (“ Terms”), as may be updated from time to time.

2. ACCESS TO THE SERVICES.

2.1 General. During the applicable Service Term, we will use commercially reasonable efforts to make the Services available to you consistent with the terms of this Agreement. We will also provide you with technical support services in accordance with our standard practices. Subject to your compliance with this Agreement and your User’s compliance with the Terms, you are granted a nonexclusive, worldwide, limited right to have your Users use the Platform Services, Documentation, and, as applicable, the Marketplace, during the applicable Service Term (unless earlier terminated in accordance with this Agreement) solely for your internal business operations. You are responsible for your Users’ compliance with this Agreement, the Terms, and your Order. Orders are non-cancellable once placed and all sums paid are nonrefundable except as provided in this Agreement. To initiate the registration process, you will identify an administrative username and password for your Nowsta account. You will provide us with information that is reasonably necessary for us to provide the Services to you. We reserve the right to refuse registration of any User or cancel passwords we deem inappropriate. You are responsible for: (a) obtaining and maintaining any equipment and ancillary services needed to connect to, access or otherwise use the Services, including, without limitation, modems, hardware, servers, software, operating systems, networking, web servers and the like (“ Equipment”); and (b) maintaining the security of the Equipment, your account, passwords (including but not limited to administrative and User passwords) and files, and for all uses of your account. If an Affiliate or yours wishes to use the Services, it must submit a separate Order to us for such use unless otherwise expressly specified in the Order. The Services are controlled and operated from facilities in the United States. We make no representations that the Services are appropriate or available for use in other locations. Subscribers and Users who access or use the Services from other jurisdictions do so at their own volition and are entirely responsible for compliance with all applicable United States and foreign laws and regulations, including export and import regulations.

2.2 Modifications. During the Service Term, we or our hosting providers may update the Services to reflect changes in, among other things, laws, regulations, rules, technology, industry practices, patterns of system use, and availability of Third-Party Applications. Updates to the Services will not materially reduce the level of performance, functionality, security or availability of the Services during the applicable Service Term. We may also modify this Agreement (including all documents referenced herein) provided that such changes to not adversely affect your use of the Services. We will notify the Subscriber point of contact contained in your Orders via email or in the log-in to the Services of any such changes and your continued use of the Services reflects your acceptance of such changes.

2.3 Use Restrictions. You will use the Services consistent with the terms of this Agreement, our Privacy Policy found at www.nowsta.com/privacy-policy/ (“ Privacy Policy”), and all applicable laws and regulations. If you allow Users who provide staffing services for you to also access the Platform Services, they must agree to the Terms. You may authorize your customers/vendors to be Users pursuant to this Agreement solely in order to allow them to manage and track staffing services provided by or for you subject to the provisions of the Portal Addendum (including the Portal Customer Terms of Use found at https://nowsta.com/portal-terms-of-use). You remain responsible for all acts or omissions of Users as if performed by you. Additionally, you and your Users may not, and may not cause or permit others to: (a) use the Services to harass or stalk any person; cause damage or injury to any person or property; publish any material that is false, defamatory, harassing or obscene; violate privacy rights; promote bigotry, racism, hatred or harm; send unsolicited bulk e-mail, junk mail, spam or chain letters; infringe intellectual or other property rights; sell, manufacture, market and/or distribute any product or service in violation of applicable laws; or otherwise violate applicable laws, ordinances or regulations; (b) perform or disclose any benchmarking or availability testing of the Services; (c) perform or disclose any performance or vulnerability testing of the Services, or perform or disclose network discovery, port and service identification, vulnerability scanning, password cracking or remote access testing of the Services; (d) reverse engineer, decompile, disassemble or otherwise attempt to discover the source code, object code or underlying structure, ideas, know how or algorithms relevant to the Services or any software, documentation or data related thereto; (e) access or use the Services to build or support, directly or indirectly, products or services competitive to the Services; (f) introduce viruses, malware, trojan horses, etc. into the Platform Services and Marketplace; (g) modify, translate, or create derivative works based on the Services; (h) license, sell, transfer, assign, distribute, outsource, permit timesharing or service bureau use of, commercially exploit, or make available the Services to any third party other than your Users; (i) access or use the Services to circumvent or exceed service account limitations or requirements or attempt to bypass measures we use to prevent or restrict access to the Services; (j) remove any proprietary notices or labels found in the Services; (k) copy, distribute, or disclose any part of the Services in any medium, including by any automated or non-automated “scraping”; (l) use any automated system, including “robots,” “spiders,” “offline readers,” etc., to access the Services in a manner that sends more request messages to our servers than a human can reasonably produce in the same period of time by using a conventional on-line web browser; (m) collect or harvest any personally identifiable information, including account names, from the Services; (n) use the Services for any commercial solicitation purposes other than as permitted pursuant to this Agreement; (o) impersonate another person or otherwise misrepresent your affiliation with a person or entity, conduct fraud, hide or attempt to hide your identity or (p) otherwise use the Services in violation of our terms or policies. In addition to other rights that we have in this Agreement and your Order, we have the right to take remedial action which may include removing or disabling access to the Services. Although we have no obligation to monitor your use of the Services, we may do so and may prohibit any use of the Services we reasonably believe may be in violation of the foregoing.

2.4 Government Rights. The Platform Services and Marketplace are “Commercial Cloud Services” and the Documentation is “Commercial Computer Software Documentation”. Consistent with 48 C.F.R. §12.211, §12.212 or §227-7202-1 through 227.7202-4 and DFAR Subpart 239.76 and DFAR §227.7202, §227.7203 and §252.227-7015, as applicable, the Commercial Cloud Services and Commercial Computer Software Documentation are being licensed to U.S. Government end users (a) only as commercial Items and (b) with only those rights as are granted to all other end users as described in this Agreement.

2.5 Anonymized and Statistical Data. Notwithstanding anything to the contrary in this Agreement or any related agreement or policy, Nowsta shall have the right to collect, analyze and use Anonymized Data and Statistical Data. Anonymized Data and Statistical Data are not Subscriber Data irrespective of the means by which Anonymized Data or Statistical Data is generated. Nowsta will be free (during and after the term of this Agreement) to (a) use such Anonymized Data and Statistical Data to operate, improve and enhance the Services and for other development, diagnostic and corrective purposes in connection with the Services and other Nowsta offerings; (b) disclose such Anonymized Data and Statistical Data in connection with its business; (c) use Anonymized Data and Statistical Data to train, test, or otherwise enhance our machine learning algorithms, for the purposes of operating, providing, and improving the Services; and (d) use Subscriber Data, Anonymized Data and Statistical Data for security and operations management, to create statistical analyses for research and development, and other lawful purposes We may make services analyses publicly available or commercialize such analysis; however, services analyses will not incorporate Subscriber Data, personal information or Confidential Information in a form that could serve to identify you or any individual. We retain all intellectual property rights in such services analyses, Statistical Data and Anonymized Data.

2.6 Monitoring Tools. We continuously monitor the Platform Services and Marketplace to facilitate our operation of the Platform Services and Marketplace; to help resolve Subscriber service requests; to detect and address threats to the functionality, security, integrity, and availability of the Platform Services and Marketplace as well as any content, data, or applications in the Platform Services and Marketplace; and to detect and address illegal acts or violations of this Agreement. Our monitoring tools do not collect or store any Subscriber Data residing in the Platform Services or Marketplace, except as needed for the above purposes. Information collected by our monitoring tools (excluding Subscriber Data) may also be used to assist in managing the Services, to help us address deficiencies in our product and service offerings, and for license management purposes.

2.7 Discontinuation of Services. We reserve the right to discontinue offering Services (or portions of the Services) at the conclusion of your then current Service Term for such Service on thirty (30) days prior written notice. We shall not be liable to you nor to any third party for any discontinuation of the Services as described in this Section.

3. OWNERSHIP RIGHTS AND RESTRICTIONS.

3.1 Ownership of Subscriber Data. You or your licensors and Users retain all ownership and intellectual property rights in and to your Subscriber Data and nothing in this Agreement gives us any right, title, or interest in such Subscriber Data other than the limited license to use the Subscriber Data to provide the Services or to create Anonymized Data or Statistical Data.

3.2 Our Ownership. We and our licensors retain all ownership and intellectual property rights in and to the Services, Documentation, technology used to provide the Services, derivative works thereof, and anything developed or delivered by or on behalf of us under this Agreement (including under an Integration Addendum), and nothing contained in this Agreement gives you any right, title or interest in any of them, except for the limited license to use them during the Service Term consistent with the terms of this Agreement and the Order. Any rights not expressly granted herein by us are reserved by us.

3.3 Feedback. You grant us a royalty free, worldwide, perpetual, irrevocable, transferable right to use, modify, distribute, and incorporate into the Services (without attribution of any kind) any suggestions, enhancement requests, recommendations, proposals, corrections or other feedback or information provided by you or any Users related to the operation or functionality of the Services.

3.4 Limited License to Subscriber Data. You have the authority to and do grant us the right to host, use, process, display and transmit Subscriber Data (including to our subprocessors) to provide the Services pursuant to and in accordance with this Agreement (which incorporates our Privacy Policy) and your Order, and to train, test, or otherwise enhance our machine learning algorithms, for the purposes of operating, providing, and improving the Services. Our current subprocessors are listed at https://www.nowsta.com/subprocessor/ and may be updated from time to time. We maintain agreements with our subprocessors sufficient to ensure our compliance with our obligations hereunder. You have sole responsibility for the accuracy, quality, integrity, legality, reliability, and appropriateness of the Subscriber Data, and for obtaining all rights and consents related to Subscriber Data as necessary for us to process such Subscriber Data as specified herein. We are not responsible for any electronic communications and/or Subscriber Data which are delayed, lost, altered, intercepted, or stored during the transmission of any data whatsoever across networks not owned and/or operated by us or our subprocessors, including, but not limited to, the internet and your local network. We may store and maintain Subscriber Data for a period consistent with our standard business processes for the Services subject to our continued compliance with our obligations related to confidentiality hereunder.

4. DATA SECURITY.

4.1 Security. We shall maintain reasonable and appropriate security measures to protect Subscriber Data in accordance with commercially reasonable industry standards which shall not be less protective of Subscriber Data than those set forth in Exhibit 1 (“ Security Requirements”). We shall promptly notify Subscriber of any security incidents involving Subscriber Data. We will use Subscriber Data only as specified in this Agreement (including our Privacy Policy).

5. FEES AND PAYMENT.

5.1 Fees and Taxes. All fees are specified in your Order and are exclusive of any taxes, duties or similar fees which may be collectable or withheld pursuant to law. You will pay any sales, value-added or other similar taxes imposed by applicable law that we must pay based on the Services you ordered, except for taxes based on our income (“ Taxes”). All fees are in U.S. Dollars. Fees for any renewal of the Service Term shall be based on our then-current rates for the Services or as otherwise specified in the Order. If we have the legal obligation to pay or collect Taxes for which you are responsible, the appropriate amount shall be invoiced to and paid by you unless you provide us with a valid tax exemption certificate authorized by the appropriate taxing authority. If applicable law requires you to withhold any Taxes levied by any country on payments to be made pursuant to this Agreement, you shall (a) effect such withholding, remit such amounts to the appropriate taxing authorities and promptly furnish us with tax receipts evidencing the payments of such amounts, and (b) ensure that the sum payable by you upon which the deduction or withholding is based is increased to the extent necessary to ensure that, after such deduction or withholding, we receive and retain, free from liability for such deduction or withholding, a net amount equal to the amount we would have received and retained in the absence of such required deduction or withholding.

5.2 Payment Terms. All fees are due and payable at the time of Order unless otherwise specified in the Order. If you have chosen a monthly billing frequency, payment will be made in advance, you must be enrolled in our automatic payment program and agree to submit and maintain an active credit card on file with us at all times during the term of this Agreement. Your credit card on file will be automatically charged for all billing intervals. If you choose an annual billing frequency, you may elect to be invoiced by us and may pay via ACH or with the credit card you have on file. If Fees are to be invoiced to Subscriber, such invoice will be provided electronically and will be due upon receipt unless otherwise specified in the Payment Terms portion of each Order. A 3% fee will be applied to any credit card payments. In the event your form of payment is denied, you agree to pay a fixed late penalty of $120 and further agree that interest will immediately begin to accrue monthly on all unpaid amounts at a rate of 1.0% per month or the maximum amount permitted by law, plus all expenses of collection (including attorney fees). In addition, late payment may result in immediate termination or suspension of the Services.

5.3 Additional Fees. The fees for additional Services and other items procured during an existing Service Term will co-terminate with and be prorated through the end date of the Service Term for the original Services so that all licenses end on the same date. Fees for use of the Marketplace are specified in the Marketplace TOU. If the fees for a feature or functionality of the Services are based on usage of the Service or any other pricing metric, then we may access and use Subscriber Data as reasonably necessary to determine the fees for the applicable feature, functionality or consumption, and you will be charged for any such fees at the rates set forth in the Order (if specified) or at our then current rates.

6. NONDISCLOSURE.

6.1 General. By virtue of this Agreement, Discloser may disclose to Recipient Confidential Information of Discloser. Recipient agrees not to disclose the Discloser’s Confidential Information to any third party other than as set forth in the following sentence for a period of five (5) years from the date of termination or expiration of this Agreement, provided, (a) that trade secret information will be held in confidence until such information no longer qualifies as a trade secret under applicable law; (b) personally identifiable information will be held in confidence as required by applicable laws; and (c) we will protect the confidentiality of Subscriber Data residing in the Platform Services for as long as such information resides in the Platform Services. Each party may disclose Confidential Information only to those employees, agents or subcontractors (including our subprocessors) with a need to know such information to comply with its obligations under this Agreement and who are required to protect it against unauthorized disclosure in a manner no less protective than required under this Agreement. In addition, Recipient may disclose Discloser’s Confidential Information in any legal proceeding or to a governmental entity as required by law provided that Recipient provides prompt written notice thereof to Discloser (to the extent legally permitted) and assistance (at Discloser’s expense) to enable Discloser to seek a protective order or otherwise prevent or restrict such disclosure.

6.2 Exceptions. Notwithstanding Section 6.1, the following shall not be deemed Confidential Information: (a) information that was in the public domain at the time of its disclosure, or which becomes public domain property through no fault of Recipient; (b) information that was rightfully in Recipient’s possession without restriction prior to disclosure; (c) information that was rightfully disclosed to Recipient by a third party without restriction; (d) information that was independently developed by employees and/or contractors of Recipient without access to, use of, or reference to Discloser’s Confidential Information; and (e) Anonymized Data or Statistical Data collected or generated by us or on behalf of us.

6.3 Injunctive Relief. It is understood and agreed that notwithstanding any other provision of this Agreement, a breach by either party of this Section 6 may cause the other party irreparable damage for which recovery of money damages might be inadequate, and that the other party shall therefore be entitled to seek timely injunctive relief, without posting bond, to protect such party’s rights under this Agreement, in addition to all remedies available at law or equity.

6.4 Return of Confidential Information. On Discloser’s written request or upon expiration or termination of this Agreement for any reason, Recipient will promptly return or securely destroy, at Discloser’s option, all of Discloser’s Confidential Information in any form or media and provide a written statement to Discloser certifying the return or destruction of such Confidential Information. Subscriber Data will be made available to you or returned and/or destroyed as described in Section 10.4.

7. WARRANTIES AND DISCLAIMERS.

7.1 Services Warranty. Each party represents and warrants that it has validly entered into this Agreement and that it has the power and authority to do so. We warrant that during the Service Term, we will provide the Platform Services and Marketplace using commercially reasonable care and skill and in all material respects as described in the Documentation (the “ Services Warranty”). If the Platform Services or Marketplace provided to you fail to conform to the Services Warranty, you must promptly provide us with a written notice that describes the deficiency in the Platform Services and/or Marketplace (including, as applicable, the service request number notifying us of the deficiency). The Services Warranty shall not apply, and we shall not be responsible for our inability to provide the Platform Services and/or Marketplace to the extent such failure is due to: (a) third party software, hardware, or network infrastructure, including but not limited to any Third-Party Applications; (b) failure of the external internet beyond our network; (c) electrical or internet access disruptions not due to us or our systems; (d) any actions or inactions of you and/or your Users in violation of this Agreement; (e) caused by your Equipment; (f) attacks (i.e. hacks, malicious introduction of viruses and disabling devices) caused by third parties or (g) any other Force Majeure event as described in Section 12 of this Agreement.

7.2 Disclaimer. WE DO NOT WARRANT THAT THE SERVICES WILL BE ERROR-FREE OR UNINTERRUPTED, THAT WE WILL CORRECT ALL ERRORS, OR THAT THE SERVICES WILL MEET YOUR REQUIREMENTS OR EXPECTATIONS. WE ARE NOT RESPONSIBLE FOR ANY ISSUES RELATED TO THE PERFORMANCE, OPERATION OR SECURITY OF THE SERVICES THAT ARISE FROM SUBSCRIBER DATA OR THIRD-PARTY APPLICATIONS.

7.3 Remedies. FOR ANY BREACH OF THE SERVICES WARRANTY AS DEFINED IN SECTION 7.1, YOUR EXCLUSIVE REMEDY AND OUR ENTIRE LIABILITY SHALL BE TO CORRECT THE DEFICIENT SERVICES AT OUR COST SO THAT THE SERVICE CONFORMS TO THE SERVICES WARRANTY, OR, IF WE CANNOT SUBSTANTIALLY CORRECT THE DEFICIENCY IN A COMMERCICOMMERCIALLY REASONABLE MANNER, YOU MAY END THE DEFICIENT SERVICES AND WE WILL REFUND TO YOU THE FEES FOR THE TERMINATED SERVICES THAT YOU PRE-PAID TO US FOR THE PERIOD FOLLOWING THE EFFECTIVE DATE OF TERMINATION.

7.4 EXCLUSIVE WARRANTIES. TO THE EXTENT NOT PROHIBITED BY LAW, THESE WARRANTIES AND SUCH WARRANTIES AS ELSEWHERE EXPRESSED IN THIS AGREEMENT ARE EXCLUSIVE AND THERE ARE NO OTHER WARRANTIES, TERMS OR CONDITIONS, EXPRESS OR IMPLIED, STATUTORY OR OTHERWISE, INCLUDING WITHOUT LIMITATION, ANY WARRANTIES, TERMS, OR CONDITIONS OF MERCHANTABILITY, SATISFACTORY QUALITY, NON-INFRINGEMENT, OR FITNESS FOR A PARTICULAR PURPOSE.

8. INDEMNIFICATION.

8.1 Infringement. Subject to the terms and conditions set forth in this Section 8, we shall, at our own expense, defend you from and against any and all allegations, threats, claims, suits, and proceedings brought by third parties (collectively “ Claims”) alleging that the Services, as used in accordance with this Agreement, infringes such third party’s copyrights or trademarks, or misappropriates such third party’s trade secrets and we shall indemnify you from and against liability, damages, and costs finally awarded or entered into in settlement (including, without limitation, reasonable attorneys’ fees) (collectively, “ Losses”) to the extent based upon such Claim(s).

8.2 Exclusions. We will have no liability for Claims or Losses to the extent arising from: (a) use of the Services in violation of this Agreement or applicable law; (b) use of the Services after we notify you to discontinue use because of an infringement claim; (c) modifications to the Services not made by us or made by us based on your specifications or requirements; (d) use of the Services in combination with any non-Nowsta software, application or service, including Third-Party Applications; or (e) our use of Subscriber Data consistent with the provisions of this Agreement.

8.3 Remedies. If a Claim of infringement as set forth above is brought or threatened, we shall, at our sole option and expense, use commercially reasonable efforts either: (a) to procure a license that will protect you against such Claim without cost; (b) to modify or replace all or portions of the Services as needed to avoid infringement, such update or replacement having substantially similar or better capabilities; or (c) if (a) and (b) are not commercially feasible, terminate the Agreement or your Order and refund to you a pro-rata refund of the prepaid, unused subscription fees for the terminated portion of the Service Term. The rights and remedies granted to you under this Section 8.3 state our entire liability, and your exclusive remedy, with respect to any claim of infringement of the intellectual property rights of a third party.

8.4 Subscriber’s Indemnity. Subject to the terms and conditions set forth in this Section 8.4 you shall, at you own expense, defend us and our Affiliates, officers, directors, employees, attorneys and agents (“ Nowsta Parties”) from and against any and all Claims alleging that: (a) our use of the Subscriber Data as permitted by this Agreement infringes the intellectual property, proprietary rights, or privacy rights of any third party; (b) your use of Third-Party Applications is outside the scope of the licenses granted with respect to such Third-Party Applications; (c) you failed to obtain proper consents for your collection of Subscriber Data or for our use and processing of Subscriber Data as provided herein; or (d) your use of the Services or your actions violate any applicable laws or the provisions of Section 2.3 of this Agreement. In addition, You shall indemnify, defend and hold harmless all Nowsta Parties for any Claim arising out of any relationship established between you and another person or entity via the Marketplace, and you shall indemnify us from and against liability for any Losses to the extent based upon such Claims. In addition, you agree that your workers, employees, contractors, and other personnel shall neither be considered employees or personnel of Nowsta nor shall we be deemed to be a supervisor of, or responsible for, any such personnel. You shall indemnify, defend and hold harmless all Nowsta Parties for any action that may be raised against Nowsta Parties alleging violation of any federal or state wage and hour, tax, workplace safety laws or other federal or state law, or for property damage, bodily injury, or death caused by you or your workers, employees, contractors and personnel or for any other action in which a claim is made that Nowsta is a co-employer or joint employer. You will have no liability under this Section 8.4 to the extent such Losses result from our gross negligence, willful misconduct or fraud.

8.5 Indemnification Procedures and Survival. In the event of a potential indemnity obligation under this Section 8, the indemnified party shall: (a) promptly notify the indemnifying party in writing of such Claim; (b) allow the indemnifying party to have sole control of its defense and settlement; and (c) upon request of the indemnifying party, cooperate in all reasonable respects, at the indemnifying party’s cost and expense, with the indemnifying party in the investigation, trial, and defense of such Claim and any appeal arising therefrom. The indemnification obligations under this Section 8 are expressly conditioned upon the indemnified party’s compliance with this Section 8.5 except that failure to notify the indemnifying party of such Claim shall not relieve that party of its obligations under this Section 8 but such obligations shall be reduced to the extent of any damages attributable to such failure. The indemnification obligations contained in this Section 8 shall survive termination or expiration of this Agreement.

9. LIMITATION OF LIABILITY.

9.1 EXCLUSION OF CERTAIN DAMAGES. IN NO EVENT WILL EITHER PARTY OR ITS AFFILIATES BE LIABLE FOR ANY INDIRECT, CONSEQUENTIAL, INCIDENTAL, SPECIAL, PUNITIVE, OR EXEMPLARY DAMAGES, OR ANY LOSS OF REVENUE, PROFITS (EXCLUDING FEES UNDER THIS AGREEMENT), SALES, DATA, DATA USE, GOODWILL, OR REPUTATION. CERTAIN STATES AND/OR JURISDICTIONS DO NOT ALLOW THE EXCLUSION OF INCIDENTAL OR CONSEQUENTIAL DAMAGES, IN WHICH CASE SUCH DAMAGES SHALL BE SUBJECT TO THE LIMITATIONS SET FORTH IN SECTION 9.2 BELOW.

9.2 LIMITATION OF LIABILITY. THE MAXIMUM AGGREGATE LIABILITY OF NOWSTA AND ITS AFFILIATES ARISING OUT OF OR IN CONNECTION WITH THIS AGREEMENT, WHETHER SUCH LIABILITY ARISES FROM ANY CLAIM BASED ON BREACH OR REPUDIATION OF CONTRACT, BREACH OF WARRANTY, NEGLIGENCE, OR OTHERWISE, SHALL NOT EXCEED THE TOTAL FEES PAID OR PAYABLE BY SUBSCRIBER UNDER THIS AGREEMENT FOR THE APPLICABLE SERVICES DURING THE TWELVE (12) MONTH PERIOD IMMEDIATELY PRECEDING THE EVENT OUT OF WHICH THE LIABILITY AROSE. NOTWITHSTANDING THE FOREGOING, IN THE EVENT OF LIABILITY ARISING IN CONNECTION WITH AN INDEMNIFICATION OBLIGATION PURSUANT TO SECTION 8, THE CAP SET FORTH IN THIS SECTION 9.2 SHALL NOT APPLY.

9.3 Acknowledgement. BOTH PARTIES ACKNOWLEDGE THAT THE FEES REFLECT THE ALLOCATION OF RISK SET FORTH IN THIS AGREEMENT AND THAT THE PARTIES WOULD NOT ENTER INTO THIS AGREEMENT WITHOUT THESE LIMITATIONS ON THEIR LIABILITY. NOTWITHSTANDING ANYTHING TO THE CONTRARY IN THIS SECTION 9, NEITHER PARTY SHALL BE LIABLE TO THE OTHER PARTY TO THE EXTENT SUCH LIABILITY WOULD NOT HAVE OCCURRED BUT FOR THE OTHER PARTY’S FAILURE TO COMPLY WITH THE TERMS OF THIS AGREEMENT.

10. TERM AND TERMINATION.

10.1 Term. This Agreement is valid for the Service Term (and any renewals thereof) of the Order which references this Agreement unless terminated as specified in this Agreement. The initial Service Term for a Service shall be as specified in the Order. Thereafter, except as specified in Section 2.7, the Service Term of the applicable Service shall be automatically renewed for additional twelve (12) month terms at our then-current prices (or such other price as specified in the Order) unless you notify us of your intention not to renew at least thirty (30) days prior to the expiration of your then-current Service Term.

10.2 Suspension. We may suspend your and/or your Users’ access to, or use of, the Platform Services, Marketplace and/or performance of Integration Services if we believe that: (a) such use presents a significant threat to the functionality, security, integrity, or availability of the Services or any content, data, or applications in the Services; (b) you or your Users are accessing or using the Services to commit an illegal act; (c) there is a violation of Section 2.3; (d) you provided false account or payment information or your payment method is refused; or (e) in connection with a Payment Failure (as defined in Section 10.3). When reasonably practicable and lawfully permitted, we will provide you with advance notice of any such suspension. We will use reasonable efforts to limit any suspension only to the portion of the Services related to the issue causing suspension. We will use reasonable efforts to re-establish the Services promptly after we determine that the issue causing the suspension has been resolved. Any suspension under this Section shall not excuse you from your payment obligations.

10.3 Termination for Breach. This Agreement and any or all Orders may be terminated at any time: (a) by us, effective on written notice to you if you fail to pay the fees payable hereunder when due, (“ Payment Failure“); (b) by either party, effective on written notice to the other party, if the other party materially breaches this Agreement and the breach remains uncured thirty (30) days after the non-breaching party provides the breaching party with written notice of such breach; or (c) by either party, effective immediately, if the other party: (i) is dissolved or liquidated or takes any corporate action for such purpose; (ii) becomes insolvent or is generally unable to pay its debts as they become due; (iii) becomes the subject of any voluntary or involuntary bankruptcy proceeding under any domestic or foreign bankruptcy or insolvency law which remains undismissed after sixty (60) days; (iv) makes or seeks to make a general assignment for the benefit of its creditors; or (v) applies for, or consents to, the appointment of a trustee, receiver or custodian for a substantial part of its property. If we terminate your Orders or this Agreement pursuant to this Section 10.3, you must pay within 10 days, all amounts that have accrued prior to such termination, as well as all sums remaining unpaid for the terminated Order(s) plus related Taxes and expenses. If you terminate this Agreement or your Orders pursuant to this Section 10.3, then you shall be entitled to a refund of the pro-rata portion of any prepaid, unused fees for the terminated portion of the Service Term or for Integration Services not rendered. Except for nonpayment of fees, the non-breaching party may agree in its sole discretion to extend the 30 day period for so long as the breaching party continues reasonable efforts to cure the breach. You agree that if you are in default under this Agreement and/or your Order, you may not use the Services ordered.

10.4 Effect of Termination. At the end of the Service Term (including any renewals thereof) or upon termination of this Agreement, you shall have no further right to use or access the applicable Services, and we will make your Subscriber Data (as it existed at the end of the Service Term) available for retrieval by you for thirty (30) days. Following the retrieval period, and except as may be required by law, we will deactivate your accounts and securely delete all Subscriber Data that remains in the Services except to the extent, and only for so long as, retention is mandated under applicable law (e.g., a litigation hold). It is Subscriber’s responsibility to export all Subscriber Data from the Services and Nowsta shall have no liability to Subscriber or any third party for Subscriber’s failure to do so or Nowsta’s inability to provide Subscriber Data to Subscriber after such thirty (30) day period.

10.5 Survival. Provisions that survive termination or expiration of this Agreement are those relating to limitation of liability, confidentiality, indemnification, payment, ownership of data, and others which by their nature are intended to survive.

11. COMPLIANCE WITH LAWS.

11.1 Export. Export control and economic sanctions laws and regulations (“export laws”) of the United States and any other relevant local export laws apply to the Services. Such export laws govern use of the Services (including technical data) and deliverables provided under this Agreement, and you and we each agree to comply with all such export laws (including “deemed export” and “deemed re-export” regulations). We each agree that no data, information, software programs and/or materials resulting from the Services (or direct product thereof) will be exported, directly or indirectly, in violation of these laws, or will be used for any purpose prohibited by these laws. You are solely responsible for the authorization and management of User accounts across geographic locations, as well as export control and geographic transfer of Subscriber Data.

11.2 Laws. The parties shall both comply with all applicable local, state, provincial, national and foreign laws, treaties and regulations in connection with the use and performance of the Services.

12. FORCE MAJEURE.

Neither you nor we shall be responsible for failure or delay of performance to the extent caused by: an act of war, hostility, or sabotage; act of God; pandemic; electrical, internet, or telecommunication outage that is not caused by the obligated party; government restrictions (including, without limitation, an embargo, economic sanction or the denial or cancellation of any export, import or other license); or other event outside the reasonable control of the obligated party. Both you and we will use reasonable efforts to mitigate the effect of a force majeure event. If such event continues for more than 30 days, either party may cancel unperformed Services and the applicable Order upon written notice. If you terminate the Service under such circumstances, we will refund the unused portion of any pre-paid Fees. This Section does not excuse either party’s obligation to take reasonable steps to follow its normal disaster recovery procedures or your obligation to pay for the Services previously incurred.

13. DISPUTE RESOLUTION AND ARBITRATION.

The parties agree that in the event any dispute arises between us, we agree to first attempt to resolve any dispute or disagreement collegially and in good faith. If that is not successful, then either party may choose to engage in voluntary mediation. The parties agree that if any dispute cannot be resolved informally or through mediation, any controversy or claim arising out of or relating to this Agreement, shall be mandatorily settled by arbitration administered by the Judicial Arbitration and Mediation Service, Inc. (“ JAMS”), under the Streamlined Arbitration Rules and Procedures. This arbitration agreement and these provisions shall be governed by, and construed and interpreted, in accordance with the Federal Arbitration Act. The arbitrator may not award consequential, special, punitive or exemplary damages. Judgment on the award rendered by the arbitrator may be entered in any court having jurisdiction thereof. Regardless of the amount of money at issue in any arbitration, and notwithstanding JAMS Rules to the contrary, the arbitration shall be decided by a single arbitrator who is a neutral, retired state or federal judge. The costs of any arbitration shall be equally divided, with no shifting of attorneys’ fees to the non-prevailing Party. No class action or collective claims may be submitted for arbitration or considered by the Arbitrator. Arbitration proceedings shall be conducted in New York, New York. The arbitration proceedings and results therein shall be kept confidential, unless it becomes necessary for a party to seek court action and assistance to enforce any award. The arbitrator and not a court shall be authorized to determine arbitrability. In the event any dispute is determined not arbitrable by the arbitrator, each Party agrees that any proceeding (in contract, tort or otherwise) arising out of or relating to this Agreement, involves complicated and difficult issues. Therefore, each party irrevocably and unconditionally waives any right it may have to a trial by jury in respect of any such proceeding. Notwithstanding the foregoing, each party reserves the right to file suit or action in any court of competent jurisdiction as such party deems necessary to protect its intellectual property rights and to recoup any payments due.

14. GOVERNING LAW AND JURISDICTION.

This Agreement is governed by the substantive and procedural laws of the State of New York excluding its conflict of laws rules, and the parties both agree to submit to the exclusive jurisdiction of, and venue in, the courts located in New York, New York in connection with any dispute arising out of or relating to this Agreement other than as specified in Section 13. The Uniform Computer Information Transactions Act does not apply to this Agreement or to Orders placed under it.

15. NOTICE.

Any notice required under this Agreement shall be provided to the other party in writing. If you have a legal dispute with us or if you wish to provide a notice under the Indemnification Section of this Agreement, or if you become subject to insolvency or other similar legal proceedings, you will promptly send written notice to us at: Nowsta, Inc., 228 Park Ave South, PMB 62909, New York, NY 10003-1502, Attention: Legal Department with a copy to legal2@nowsta.com. Notices to you will go to the point of contact specified in your Order. Notices shall be deemed delivered as follows: (a) by personal delivery when delivered by hand, (b) by registered or certified mail, postage prepaid, return receipt requested, five (5) days after deposit in the mail, (c) by overnight courier upon written verification of receipt, or (d) by confirmed fax or email upon receipt. In addition, we may give general notices applicable to our Subscribers by means of a general notice on our Subscriber portal for the Services or via email to Subscriber’s point of contact on the Order.

16. ASSIGNMENT.

This Agreement shall inure to benefit and bind the parties hereto, their successors and assigns, but neither party may assign this Agreement without written consent of the other, except that we may assign without consent to an Affiliate or the successor of all or substantially all of our business or assets to which this Agreement relates.

17. GENERAL PROVISIONS.

17.1 Independent Contractors. We are an independent contractor, and each party agrees that no partnership, joint venture, or agency relationship exists between the parties, and no party has the ability to contractually bind the other.

17.2 Third Parties. Our business partners and other third parties, including any third parties with which the Services have integrations, that are provided via the Marketplace or that are retained by you to provide consulting services, implementation services or applications that interact with the Services, are independent of us and are not our agents. Even if recommended by us, we are not liable for, bound by, or responsible for any problems with the Services or Subscriber Data arising due to any acts or omissions of any business partner or third party, unless the business partner or third party is providing Services as our subcontractor or is otherwise engaged by us in connection with performance of our obligations under this Agreement, and, if so, then only to the same extent as we would be responsible for our resources under this Agreement.

17.3 Severability. If any term of this Agreement is found to be invalid or unenforceable, the remaining provisions will remain effective and such term shall be replaced with another term consistent with the purpose and intent of this Agreement.

17.4 Amendment and Waiver. This Agreement shall not be modified or amended, except as expressly set forth herein, or in writing and signed or accepted electronically by the party against whom the modification, amendment or waiver is to be asserted, however, we may update the Documentation and policies referenced in this Agreement, including by posting updated documents on our website, provided that such updated Documentation and policies shall apply only to Orders placed after such updates are provided.

17.5 Use of Name. You grant us the right to use your name and logo on our website, in our marketing materials, and as part of our Subscriber list, consistent with usage instructions provided by you, during the Service Term.

18. ENTIRE AGREEMENT

18.1 Entire Agreement. You agree that this Agreement and the information which is incorporated into this Agreement by written reference (including reference to information contained in a URL or referenced policy), together with the Order, is the complete agreement for Services ordered by you and supersedes all prior or contemporaneous agreements, proposals, negotiations, demonstrations or representations, written or oral, regarding such Service.

18.2 Order of Precedence. It is expressly agreed that the terms of this Agreement and the Order shall supersede the terms in any purchase order or non-Nowsta document, and no terms included in any such purchase order or other non-Nowsta document shall apply to your Order. In the event of any inconsistencies between the terms of the Order and the Agreement, the non-preprinted terms of the Order shall take precedence, unless expressly stated otherwise in the Order. The Marketplace TOU and Integration Addendum supersede any provisions of this Agreement in the event of any conflict with respect to the Marketplace Services and Integration Services. No third party beneficiary relationships are created by this Agreement.

Exhibit 1 – SECURITY REQUIREMENTS

These Security Requirements describe how Nowsta works to protect the security of its customer’s data in connection with their use of the Services. For purposes of these Security Requirements: the word “including” means “including, without limitation”; “ Malicious Code” means any harmful, malicious, or hidden code, programs, procedures, routines, or mechanisms, including malware, Trojan horses, viruses, worms, time bombs, time locks, devices, traps, access codes, or drop dead, or trap door devices; “ Subscriber Systems” means any Subscriber or third-party infrastructure, systems, or applications that access, process, or store Subscriber Data; “ Nowsta Personnel” means the employees and contractors providing Nowsta Services or accessing or using Nowsta Systems; and “ Nowsta Systems” means the infrastructure, systems and applications that access or support Nowsta Services or that access, process, or store Subscriber Data. Capitalized terms not otherwise defined herein shall have the meanings ascribed to them in the Agreement.

1. Endpoint Controls

1.1. Nowsta Personnel shall only use endpoints that comply with these Security Requirements to:

1.1.1. access, process, or store Subscriber Data;

1.1.2. access any Subscriber Systems; or

1.1.3. access any Nowsta Systems.

1.2. Nowsta shall not transmit Subscriber Data from such endpoints to any infrastructure, systems, or applications other than Subscriber Systems or other infrastructure, systems or applications authorized by Subscriber. Notwithstanding the foregoing, Subscriber acknowledges that Nowsta is permitted to transmit such Subscriber Data to its subprocessors as described in the Agreement and that by using certain features and functionality in the Nowsta Services, that it will permit Nowsta to transmit Subscriber Data as required to provide those services.

1.3. Nowsta Personnel shall only (a) access Subscriber Systems, Subscriber Data or Nowsta Systems or (b) process or store Subscriber Data, using endpoints that: (1) utilize security controls that include (i) disk encryption, (ii) endpoint detection and response (EDR) tools to monitor and alert for suspicious activities and Malicious Code, and (iii) vulnerability scanning and management in accordance with Section 1.4, and (2) are configured to automatically activate a password protected screensaver after 15 minutes of inactivity and run up-to-date host-based firewall software.

1.4. Nowsta shall ensure that vulnerabilities meeting defined risk criteria set forth below will trigger alerts and that such vulnerabilities are prioritized for remediation based on their potential impact to Subscriber Data, Subscriber Systems, and Nowsta Systems. Upon becoming aware of such vulnerabilities, Nowsta shall remediate private and public “critical” and “high”’ vulnerabilities within thirty (30) calendar days, and “medium” vulnerabilities t within ninety (90) calendar days To assess whether a vulnerability is “critical”, “high”, or “medium”, Nowsta shall use the National Vulnerability Database’s (NVD) Common Vulnerability Scoring System (CVSS) ( NVD Site).

1.5. Nowsta Personnel may permanently delete in a secure fashion all Subscriber Data on all endpoints and Nowsta Systems within thirty (30) days after the expiration or termination of the Agreement except as may be required by law. Anonymized Data and Statistical Data may be retained and used by Nowsta as specified in the Agreement.

2. Encryption

2.1. Encryption of Subscriber Data. Nowsta must encrypt all Subscriber Data containing PII (as defined NIST ( NIST Site)) or PCI (as defined by Payment Card Industry Security Standards Council ( PCI SSC Site)) at-rest using AES 256-bit (or better) encryption. Nowsta shall use Transport Layer Security (TLS) 1.2 (or better) for all Subscriber Data in-transit over untrusted networks.

3. Administrative Controls

3.1. Personnel Security. Nowsta shall conduct the following background screening on its employee and contractor candidates that Nowsta proposes assigning as Nowsta Personnel, to the extent permitted by applicable law, and Nowsta shall not assign any employee or contractor as Nowsta Personnel if such individual has any unfavorable or non-standard results:

3.2. Personnel Training. Nowsta shall maintain a documented security awareness and training program for Nowsta Personnel, including onboarding and on-going training.

3.3. Personnel Agreements. Nowsta shall require Nowsta Personnel to sign confidentiality agreements and a policy that includes acknowledging responsibility for reporting Security Incidents (as defined below).

3.4. Personnel Access Reviews & Separation. Nowsta shall review the access privileges of Nowsta Personnel to the endpoints and Nowsta Systems at least quarterly, and promptly remove access privileges for Nowsta Personnel who no longer need such access privileges. Nowsta shall promptly remove access privileges for all separated Nowsta Personnel. If Subscriber has granted any Nowsta Personnel access privileges to Subscriber Systems or Subscriber Data, Nowsta shall notify Subscriber promptly if any such Nowsta Personnel are separated or no longer need such access privileges.

3.5. Change Management. Nowsta shall maintain a documented change management program for Nowsta Systems.

3.6. Third Party Risk Management. For Nowsta’s vendors that (a) access Subscriber Systems or Nowsta Systems, or (b) access, process, or store Subscriber Data, Nowsta shall maintain a Nowsta risk management program designed to ensure each such Nowsta vendor maintains security measures consistent with, and complies with, Nowsta’s obligations described in these Security Requirements.

4. Incident Detection & Response

4.1. Security Incident Reporting. If Nowsta becomes aware of any (a) accidental, unauthorized, or unlawful destruction, loss, alteration, or disclosure of, or access to Subscriber Data, or (b) any accidental, unauthorized or unlawful access to or alteration of Subscriber Systems or Nowsta Systems (“ Security Incident”), then, in each such case Nowsta shall notify Subscriber thereof without undue delay, and in any case within 72 hours, after becoming aware of the Security Incident.

4.2. Investigation. If a Security Incident occurs, Nowsta shall promptly take reasonable steps to contain, mitigate, and investigate the Security Incident. Any logs determined to be relevant to the Security Incident, shall be preserved for at least one year, and made available to Subscriber upon its request.

4.3 Communication and Cooperation. If a Security Incident occurs, Nowsta shall provide Subscriber timely information about the Security Incident, including the nature and consequences of the Security Incident, the measures taken or proposed by Nowsta to contain and mitigate the Security Incident, the status of Nowsta’s investigation, a contact person from which additional information may be obtained, and the categories and approximate number of data records concerned.

5. Subscriber Rights

5.1 Audit Rights. At no additional cost to Subscriber, Nowsta shall provide Subscriber, or its appropriately qualified third-party representative, access to appropriate Nowsta Personnel and reasonably requested documentation, logs, and data evidencing Nowsta’s compliance with its obligations under these Security Requirements.

Cookie Consent

We use tools on this site to collect and record your data (e.g., your searches), which we and our vendors may use to provide, improve, and personalize our offerings, make recommendations, and for analytics and marketing. By continuing, you agree to these terms.

PreferencesRejectAccept All

Cookie Preferences

×

Manage your cookie preferences below:

Toggle EssentialEssential

Essential cookies enable basic functions and are necessary for the proper function of the website.

Name

Description

Duration

Cookie Preferences

This cookie is used to store the user's cookie consent preferences.

30 days

Toggle CommentsComments

These cookies are needed for adding comments on this website.

Name

Description

Duration

comment_author

Used to track the user across multiple sessions.

Session

comment_author_email

Used to track the user across multiple sessions.

Session

comment_author_url

Used to track the user across multiple sessions.

Session

Toggle Google Tag ManagerGoogle Tag Manager

Google Tag Manager simplifies the management of marketing tags on your website without code changes.

Name

Description

Duration

cookiePreferences

Registers cookie preferences of a user

2 years

td

Registers statistical data on users' behaviour on the website. Used for internal analytics by Nowsta.

session

Toggle StatisticsStatistics

Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.

Toggle Google AnalyticsGoogle Analytics

Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.

Service URL: policies.google.com (opens in a new window)

Name

Description

Duration

_gat

Used to monitor number of Google Analytics server requests when using Google Tag Manager

1 minute

__utmz

Contains information about the traffic source or campaign that directed user to the website. The cookie is set when the GA.js javascript is loaded and updated when data is sent to the Google Anaytics server

6 months after last activity

__utmv

Contains custom information set by the web developer via the _setCustomVar method in Google Analytics. This cookie is updated every time new data is sent to the Google Analytics server.

2 years after last activity

__utmx

Used to determine whether a user is included in an A / B or Multivariate test.

18 months

_ga

ID used to identify users

2 years

_gali

Used by Google Analytics to determine which links on a page are being clicked

30 seconds

_ga_

ID used to identify users

2 years

_gid

ID used to identify users for 24 hours after last activity

24 hours

_gac_

Contains information related to marketing campaigns of the user. These are shared with Google AdWords / Google Ads when the Google Ads and Google Analytics accounts are linked together.

90 days

__utma

ID used to identify users and sessions

2 years after last activity

__utmt

Used to monitor number of Google Analytics server requests

10 minutes

__utmb

Used to distinguish new sessions and visits. This cookie is set when the GA.js javascript library is loaded and there is no existing __utmb cookie. The cookie is updated every time data is sent to the Google Analytics server.

30 minutes after last activity

__utmc

Used only with old Urchin versions of Google Analytics and not with GA.js. Was used to distinguish between new sessions and visits at the end of a session.

End of session (browser)

Toggle HotjarHotjar

Hotjar is a powerful analytics tool that helps you understand user behavior through heatmaps and session recordings.

Name

Description

Duration

_hjShownFeedbackMessage

This cookie is set when a visitor minimizes or completes Incoming Feedback. This is done so that the Incoming Feedback will load as minimized immediately if they navigate to another page where it is set to show.

365 days

_hjid

Hotjar cookie. This cookie is set when the customer first lands on a page with the Hotjar script. It is used to persist the random user ID, unique to that site on the browser. This ensures that behavior in subsequent visits to the same site will be attributed to the same user ID.

365 days

hj_visitor

hotjar uses cookies to enhance the user’s experience on our website, for example to complete forms, navigating the site, and identify returning users and offer related content. Users can control the use of cookies at the individual browser level.

Session

_hjIncludedInSample

Hotjar cookie. This session cookie is set to let Hotjar know whether that visitor is included in the sample which is used to generate funnels.

365 days

_hjClosedSurveyInvites

Hotjar cookie. This cookie is set once a visitor interacts with a Survey invitation modal popup. It is used to ensure that the same invite does not re-appear if it has already been shown.

365 days

_hjDonePolls

Hotjar cookie. This cookie is set once a visitor completes a poll using the Feedback Poll widget. It is used to ensure that the same poll does not re-appear if it has already been filled in.

365 days

_hjMinimizedPolls

Hotjar cookie. This cookie is set once a visitor minimizes a Feedback Poll widget. It is used to ensure that the widget stays minimizes when the visitor navigates through your site.

365 days

_hjDoneTestersWidgets

Hotjar cookie. This cookie is set once a visitor submits their information in the Recruit User Testers widget. It is used to ensure that the same form does not re-appear if it has already been filled in.

365 days

_hjMinimizedTestersWidgets

Hotjar cookie. This cookie is set once a visitor minimizes a Recruit User Testers widget. It is used to ensure that the widget stays minimizes when the visitor navigates through your site.

365 days

hjViewportId

This cookie stores user viewport details such as size and dimensions.

Session

_hjSessionStorageTest

This cookie checks if the Hotjar Tracking Code can use Session Storage. If it can, a value of 1 is set.

Session

_hjTLDTest

When the Hotjar script executes we try to determine the most generic cookie path we should use, instead of the page hostname. This is done so that cookies can be shared across subdomains (where applicable). To determine this, we try to store the _hjTLDTest cookie for different URL substring alternatives until it fails. After this check, the cookie is removed.

session

_hjCookieTest

This cookie checks to see if the Hotjar Tracking Code can use cookies. If it can, a value of 1 is set.

Session

_hjUserAttributesHash

User Attributes sent through the Hotjar Identify API are cached for the duration of the session in order to know when an attribute has changed and needs to be updated.

session

_hjCachedUserAttributes

This cookie stores User Attributes which are sent through the Hotjar Identify API, whenever the user is not in the sample. These attributes will only be saved if the user interacts with a Hotjar Feedback tool.

session

_hjLocalStorageTest

This cookie is used to check if the Hotjar Tracking Script can use local storage. If it can, a value of 1 is set in this cookie. The data stored in_hjLocalStorageTest has no expiration time, but it is deleted immediately after creating it so the expected storage time is under 100ms.

_hjHasCachedUserAttributes

This cookie sets when a user first lands on a page. Persists the Hotjar User ID which is unique to that site. Hotjar does not track users across different sites. Ensures data from subsequent visits to the same site are attributed to the same user ID.

365 days

_hjFirstSeen

The cookie is set so Hotjar can track the beginning of the user's journey for a total session count. It does not contain any identifiable information.

30 minutes

_hjIncludedInPageviewSample

This cookie is set to let Hotjar know whether that visitor is included in the data sampling defined by your site's page view limit.

30 minutes

_hjIncludedInSessionSample

This cookie is set to let Hotjar know whether that visitor is included in the data sampling defined by your site's daily session limit

30 minutes

_hjSession_

A cookie that holds the current session data. This ensues that subsequent requests within the session window will be attributed to the same Hotjar session.

30 minutes

_hjSessionUser_

Hotjar cookie that is set when a user first lands on a page with the Hotjar script. It is used to persist the Hotjar User ID, unique to that site on the browser. This ensures that behavior in subsequent visits to the same site will be attributed to the same user ID.

365 days

_hjSessionTooLarge

Causes Hotjar to stop collecting data if a session becomes too large. This is determined automatically by a signal from the WebSocket server if the session size exceeds the limit.

session

_hjSessionRejected

If present, this cookie will be set to 1 for the duration of a user’s session, if Hotjar rejected the session from connecting to our WebSocket due to server overload. This cookie is only applied in extremely rare situations to prevent severe performance issues.

session

_hjSessionResumed

A cookie that is set when a session/recording is reconnected to Hotjar servers after a break in connection.

session

_hjptid

This cookie is set for logged in users of Hotjar, who have Admin Team Member permissions. It is used during pricing experiments to show the Admin consistent pricing across the site.

session

_hjAbsoluteSessionInProgress

The cookie is set so Hotjar can track the beginning of the user's journey for a total session count. It does not contain any identifiable information.

30 minutes

Toggle HubSpotHubSpot

HubSpot is an all-in-one marketing, sales, and customer service platform that streamlines business growth.

Name

Description

Duration

cookietest

The cookietest cookie is a session-based cookie used to determine if a visitor's web browser is configured to accept cookies.

Session

hubspotutk

6 months

first_page_seen

4 weeks

__hstc

The main tracking cookie for visitors. It tracks unique visitors, domains, timestamps, and session counts.

6 months

__hssc

Keeps track of sessions. It determines if session numbers should be incremented.

30 minutes

__hssrc

Whenever HubSpot changes the session cookie, this cookie is also set to determine if the visitor has restarted their browser.

session

messagesUtk

This cookie is used to recognize visitors who chat with you via the chatflows tool. If the visitor leaves your site before they're added as a contact, they will have this cookie associated with their browser.

13 months

hs_ab_test

This cookie is used to consistently serve visitors the same version of an A/B test page they’ve seen before.

session

__hs_notify_banner_dismiss

This cookie is used when the website uses a Notify consent banner type.

180 days

hs-messages-is-open

This cookie is used to determine and save whether the chat widget is open for future visits.

30 minutes

hs-messages-hide-welcome-message

This cookie is used to prevent the chat widget welcome message from appearing again for one day after it is dismissed.

1 day

__hsmem

This cookie is set when visitors log in to a HubSpot-hosted site.

1 year

hs-membership-csrf

This cookie is used to ensure that content membership logins cannot be forged.

session

hs_langswitcher_choice

This cookie is used to save the visitor's selected language choice when viewing pages in multiple languages.

2 years

__hstc

The main cookie for tracking visitors.

13 months

hubspotutk

This cookie keeps track of a visitor's identity. It is passed to HubSpot on form submission and used when deduplicating contacts.

13 months

hubspotapi

This cookie allows the user to access the app with the correct permissions.

7 days

hubspotapi-prefs

This is used with the hubspotapi cookie to remember whether the user checked the 'remember me' box (controls the expiration of the main cookie's authentication).

1 Year

__hs_opt_out

This cookie is used by the opt-in privacy policy to remember not to ask the visitor to accept cookies again.

13 months

hubspotapi-csrf

This is used for CSRF prevention - preventing third party websites from accessing your data. Expires after a year.

1 year

__hs_do_not_track

This cookie can be set to prevent the tracking code from sending any information to HubSpot.

13 months

__hs_cookie_cat_pref

This cookie is used to record the categories a visitor consented to.

6 months

__hs_initial_opt_in

This cookie is used to prevent the banner from always displaying when visitors are browsing in strict mode.

7 days

__hs_gpc_banner_dismiss

This cookie is used when the Global Privacy Control banner is dismissed.

180 days

Toggle IntercomIntercom

Intercom is a customer messaging platform that facilitates communication through chat, email, and support tools.

Name

Description

Duration

intercom-device-id-xiq0khc6

Used by Intercom Messenger to store identifier for each unique device that interacts with the Messenger. Intercom uses this cookie to determine the unique devices interacting with the Intercom Messenger to prevent abuse.

1 day

intercom-id-

Anonymous visitor identifier cookie. As people visit your site they get this cookie.

9 months

intercom-session-

Identifier for each unique browser session. This session cookie is refreshed on each successful logged-in ping, extending it one week from that moment. The user can access their conversations and have data communicated on logged-out pages for 1 week, as long as the session isn't intentionally terminated with Intercom('shutdown');, which usually happens on logout.

1 week

intercom-device-id-

Identifier for each unique device that interacts with the Messenger. It is refreshed on each successful ping, extending it another 9 months. We use this cookie to determine the unique devices interacting with the Intercom Messenger to prevent abuse.

9 months

Toggle Microsoft ClarityMicrosoft Clarity

Clarity is a web analytics service that tracks and reports website traffic.

Service URL: clarity.microsoft.com (opens in a new window)

Name

Description

Duration

ANONCHK

Indicates whether MUID is transferred to ANID, a cookie used for advertising. Clarity doesn't use ANID and so this is always set to 0.

Session

CLID

Identifies the first-time Clarity saw this user on any site using Clarity.

12 months

_clsk

Connects multiple page views by a user into a single Clarity session recording.

12 months

_clck

Persists the Clarity User ID and preferences, unique to that site is attributed to the same user ID.

12 months

Toggle PostHogPostHog

Service URL: posthog.com (opens in a new window)

Name

Description

Duration

ph_phc_MFsKQ695a8sLxfEAUmgNaqlHwz3C2tzY7KFPuvmiuNO_posthog

12 months

ph_phc

These cookies are primarily used to assign your visit to the optimal web server for load balancing.

12 months

dmn_chk

These cookies are primarily used to assign your visit to the optimal web server for load balancing.

session

Toggle StorylaneStorylane

Storylane tracks the original source of a visitor's traffic when they view an interactive product demo.

Service URL: www.storylane.io (opens in a new window)

Name

Description

Duration

slReferer

This cookie captures the referring URL when a user navigates to a landing page with an embedded demo.

session

Toggle MarketingMarketing

Marketing cookies are used to follow visitors to websites. The intention is to show ads that are relevant and engaging to the individual user.

Toggle 6sense6sense

6sense cookie that collects visitor data related to the user’s visit to the website, such as number of visits, average time spent on the website and which pages have been loaded, for the purpose of serving targeted advertisements.

Service URL: 6sense.com (opens in a new window)

Name

Description

Duration

_gd_svisitor

2 years

6suuid

This cookie allows 6sense to recognize individual browsers, track their return visits, and connect their behavior

2yr 12hr

_gd_session

This is associated with analytics, diagnostic, or affiliate tracking platforms (like Impact Radius). Its primary function is to collect visitor data—such as session duration, page loads, and visits—to track referral commissions or serve targeted advertisements.

4hr

_gd_visitor

A first-party unique identifier used to recognize you and to track which pages you load across multiple visits.

2yr 12hr

_an_uid

A unique identifier for the purposes of running 6sense creative ads.

1wk

Toggle DS360DS360

DS360 is a third-party marketing and analytics tracking platform by the B2B visitor tracking platform Lead Onion (often referred to as DS360). It is used to track business-to-business website traffic and analyze user journeys across

Service URL: www.dsp360.io (opens in a new window)

Toggle Google AdsGoogle Ads

Google Ads is an online advertising platform that enables businesses to create targeted ads displayed on Google search results and partner sites.

Service URL: policies.google.com (opens in a new window)

Name

Description

Duration

_gcl_au

This cookie is used for conversion tracking and cross-domain linking. Its primary purpose is to store a unique identifier that links an ad click to a subsequent action

3 weeks

FPGCLGB

Google uses cookies for advertising, including serving and rendering ads, personalizing ads (depending on your ad settings at g.co/adsettings), limiting the number of times an ad is shown to a user, muting ads you have chosen to stop seeing, and measuring the effectiveness of ads.

90 Days

FPGCLAW

90 Days

__Secure-3PSIDTS

Targeting cookie. Used to create a user profile and display relevant and personalised Google Ads to the user.

2 years

__Secure-1PSIDTS

Targeting cookie. Used to create a user profile and display relevant and personalised Google Ads to the user.

2 years

__Secure-1PAPISID

Targeting cookie. Used to create a user profile and display relevant and personalised Google Ads to the user.

2 years

__Secure-3PSID

Targeting cookie. Used to profile the interests of website visitors and display relevant and personalised Google ads.

2 years

Conversion

90 days

_gcl_aw

90 Days

_gcl_gs

90 Days

_gcl_gb

90 Days

_gac_gb_

90 Days

__Secure-1PSID

Targeting cookie. Used to create a user profile and display relevant and personalised Google Ads to the user.

2 years

__Secure-1PSIDCC

Targeting cookie. Used to create a user profile and display relevant and personalised Google Ads to the user.

2 years

__Secure-3PAPISID

Profiles the interests of website visitors to serve relevant and personalised ads through retargeting.

2 years

AEC

AEC cookies ensure that requests within a browsing session are made by the user, and not by other sites. These cookies prevent malicious sites from acting on behalf of a user without that user's knowledge.

6 months

ADS_VISITOR_ID

Cookie required to use the options and on-site web services

2 months

__Secure-3PSIDCC

Targeting cookie. Used to create a user profile and display relevant and personalised Google Ads to the user.

2 years

Toggle Cookie PolicyCookie Policy

You can find more information in our Cookie Policy and Privacy Policy.

I understand GPC will be overwritten and want to allow this site to sell or share my personal information anyway

Accept AllClose

Save and Close

GPC Signal Honored×