Master Services Agreement

Hey, Lexxi LLC

This Master Services Agreement (this “Agreement” or “MSA”) is entered into as of the Effective Date set forth above (or, if later, the effective date of the first Order Form referencing this Agreement) by and between Hey, Lexxi LLC, a California limited liability company (“Hey, Lexxi,” “we,” “us,” or “our”), and the law firm or other organization identified on the applicable Order Form (“Client,” “you,” or “your”). Hey, Lexxi and Client are each a “Party” and together the “Parties.”

This Agreement governs Client’s access to and use of the Hey, Lexxi platform, websites, applications, and related services (collectively, the “Services”). It is a negotiated master agreement that coexists with Hey, Lexxi’s online Terms of Service. Where a signed Order Form references this Agreement, this Agreement—together with that Order Form, the Data Processing Agreement described in Section 8, and any executed Business Associate Agreement—governs the Parties’ relationship for that order, and supersedes the click-through Terms of Service with respect to its subject matter. Absent a signed Order Form referencing this Agreement, the online Terms of Service continue to govern Client’s use of the Services.

1. Definitions

“Client Data” means the case materials, documents, and other data (including any personal, medical, or other protected information of Client’s clients, patients, or third parties) that Client or its Users submit to the Services, together with the reports and other output generated from them, including any Hey, Lexxi-generated report (“HLGR”).

“Order Form” means an ordering document (in the form of Exhibit A or another form the Parties sign or otherwise accept) that identifies the Services, subscription tier, HLGR allotment, fees, term, and other commercial terms, and that references this Agreement.

“User” means an individual—such as an attorney, partner, or employee of Client—whom Client authorizes to access and use the Services under Client’s account.

“DPA” means Hey, Lexxi’s Data Processing Agreement, available at https://heylexxi.com/dpa and incorporated into this Agreement as described in Section 8.

2. The Services; Order Forms

Hey, Lexxi provides a software platform that assists legal professionals in generating, organizing, and managing case-related work product, including HLGRs, based on Client Data that Client submits to the Services. The Services are intended solely for use by licensed attorneys, law firms, and their authorized personnel in the course of their professional practice.

Order Forms. The specific Services, subscription tier, HLGR allotment, fees, and term are set out in one or more Order Forms. Each Order Form is governed by and incorporated into this Agreement, and must set forth the commercial terms of the order. In the event of a conflict between an Order Form and the body of this Agreement, the Order Form controls for the transaction it describes.

No legal advice. The Services are a productivity and document-generation tool. Hey, Lexxi is not a law firm, does not practice law, and does not provide legal advice. Output generated by the Services, including any HLGR, does not constitute legal advice and is not a substitute for the independent professional judgment of a licensed attorney.

3. Users and Access

This Agreement is between Hey, Lexxi and Client (the firm). Client’s Users may access the Services under Client’s account as follows:

  • Initial user. Client will first be set up with sign-in credentials for an initial User. It is the responsibility of that initial User to provide Hey, Lexxi with a list of the email addresses of the individuals who will need access to the Services.

  • Adding and removing Users. Hey, Lexxi will provision access for the identified Users. Client is responsible for keeping the User list current and for promptly notifying Hey, Lexxi to deactivate access for any individual who no longer needs it.

  • Credential security. Client and its Users will not share passwords or other account credentials, and will follow generally accepted security best practices in safeguarding them. Where multi-factor authentication (MFA) is made available, Client will require its Users to use it. Client is responsible for all activity that occurs under its account and its Users’ credentials.

  • Users bound; Client responsible. All Users are bound by this Agreement and the applicable Acceptable Use terms, and Client is responsible for its Users’ compliance. Any misuse of the Services by a User is not the fault of Hey, Lexxi, and Client remains fully responsible for such misuse as set forth in Sections 4 and 14.

4. Acceptable Use

Client will ensure that it and its Users do not use the Services for any illegal purpose. In addition, no User may post inappropriate, unlawful, defamatory, harassing, or infringing materials on the Services, or on any Hey, Lexxi website, forum, or community feature.

Client will not, and will not permit any User or third party to: (a) use the Services in violation of any law or third-party right; (b) upload malicious code or attempt to gain unauthorized access to the Services or other accounts; (c) reverse engineer, scrape, or build a competing product from the Services; (d) resell or provide the Services to third parties except to Client’s own clients in the ordinary course of Client’s legal practice; or (e) use the Services to harass, defraud, or harm others.

5. Client Responsibilities and Compliance

Because the Services process sensitive case materials, Client bears important responsibilities. Client agrees that it will, at its own expense:

  • Maintain legal authority and consent for all data it submits—obtain and maintain all rights, consents, authorizations, and lawful bases (including any required affirmative consent) necessary for Hey, Lexxi to receive and process the Client Data, including any personal, medical, or other protected information of Client’s clients, patients, or third parties;

  • Comply with its own legal and ethical obligations—including the rules of professional conduct, attorney-client privilege and confidentiality obligations, and all privacy and data-protection laws applicable to Client;

  • Minimize unnecessary sensitive data—refrain from submitting protected health information, government identifiers, financial account numbers, or other sensitive data that is not reasonably necessary for the requested HLGR;

  • Maintain its own security—implement and maintain appropriate administrative, technical, and physical security measures to protect its own systems, devices, networks, accounts, and any output it downloads, stores, or transmits outside the Services. The security of Client’s own environment is solely Client’s responsibility;

  • Conduct its own due diligence and ensure its own compliance—independently determine, through its own due diligence, whether the Services meet Client’s legal, regulatory, ethical, and professional-responsibility obligations in every jurisdiction in which Client operates. Client, and not Hey, Lexxi, is responsible for Client’s own compliance with all applicable laws, rules, and professional obligations; and

  • Notify us promptly, in writing—inform Hey, Lexxi as soon as reasonably possible if Client requires any agreement, documentation, configuration, or other accommodation (such as a BAA or DPA) for its compliance, and notify Hey, Lexxi in writing right away upon becoming aware of any issue, error, security concern, suspected unauthorized access, or potential non-compliance that Hey, Lexxi should reasonably know about.

5.1 No Responsibility for Third-Party Arrangements

Hey, Lexxi is not a party to, and is not responsible or liable for, any agreement, contract, retainer, policy, or understanding between Client and Client’s own clients or any other third party, including employers, insurance carriers, third-party administrators (TPAs), insurance groups, insurance administrators, or claims administrators. Client is solely responsible for its relationships, obligations, and communications with such parties, including any representations Client makes to them and any work product Client delivers to them based on output of the Services.

5.2 Client’s Independent Review of Output

Although Hey, Lexxi aims for accuracy, it does not guarantee that any HLGR or other output is accurate, complete, or fit for any particular purpose. It is ultimately Client’s responsibility to check, verify, proofread, and edit all output before relying on it or providing any information based on it to Client’s own clients or any third party. Output of the Services does not replace an attorney’s expertise, strategy, judgment, or advice, and Hey, Lexxi expects that a licensed attorney will review, proofread, and edit any output before it is used to produce a deliverable for Client’s own clients.

6. Fees, Billing, and Taxes

Access to the Services requires an active subscription as set out in the applicable Order Form. Subscriptions are offered in tiers, each with a designated monthly allotment of HLGRs and a corresponding fee.

Usage allotments and overages. Each tier includes a soft monthly HLGR allotment. Hey, Lexxi may permit usage beyond the allotment and bill the excess as additional HLGRs, one-time top-up charges, or an automatic upgrade to a higher tier, as described in the Order Form or at the point of purchase.

Billing. Fees are billed through Hey, Lexxi’s third-party payment processor, and Client authorizes Hey, Lexxi and its processor to charge Client’s designated payment method. Except as required by law or expressly stated in an Order Form, fees are non-refundable. Fees are exclusive of taxes, which are Client’s responsibility other than taxes on Hey, Lexxi’s income.

Changes to pricing. Hey, Lexxi may change pricing or tier features on prospective notice, effective upon renewal. Continued use after a change takes effect constitutes acceptance of the new pricing.

7. Term and Termination

Term. This Agreement begins on the Effective Date and continues for an initial term of one (1) year, and will automatically renew for successive one (1) year periods unless either Party gives written notice of non-renewal at least thirty (30) days before the end of the then-current term. Each Order Form has the term stated in it (defaulting to the same one-year, auto-renewing term if not otherwise specified).

Termination. Either Party may terminate this Agreement or an Order Form for material breach that remains uncured thirty (30) days after written notice. Hey, Lexxi may suspend or terminate access immediately for non-payment, for conduct that risks harm to the Services or others, or as required by law.

Effect of termination; data export and deletion. Upon termination, Client may request export of its Client Data within thirty (30) days. After that period, or earlier on Client’s written request, Hey, Lexxi will delete or de-identify Client Data in its possession, except for copies retained in routine backups (deleted on their ordinary cycle) or as required by law. Provisions that by their nature should survive termination will survive, including Sections 5, 8–14, and 15.

8. Data Protection, Privacy, and No Training

8.1 Ownership and License

As between the Parties, Client owns all right, title, and interest in Client Data and the HLGRs generated from it. Client grants Hey, Lexxi a limited, non-exclusive, worldwide, royalty-free license to host, copy, transmit, process, and display Client Data solely as necessary to provide, maintain, secure, and improve the Services and to comply with law.

8.2 No Training on Client Data

Hey, Lexxi does not train on Client’s data. Hey, Lexxi will not use the contents of Client Data to train or fine-tune any machine-learning model, and does not train or fine-tune models at all; it uses frozen, hosted models as shipped. The model providers Hey, Lexxi accesses through its cloud infrastructure are contractually prohibited from using Client Data to train or improve their models and do not receive it for that purpose. Hey, Lexxi may use aggregated and de-identified data that does not identify Client or any individual to operate, analyze, and improve the Services.

8.3 Data Processing Agreement

Hey, Lexxi’s processing of personal information on Client’s behalf is governed by the DPA, available at https://heylexxi.com/dpa, which is incorporated into this Agreement by reference. Where applicable data-protection law requires a signed data processing agreement, Client may request an executable copy at legal@heylexxi.com, and once executed it forms part of this Agreement. To the extent of any conflict regarding the processing of personal information, the DPA controls.

8.4 Business Associate Agreement (Client’s Request)

Hey, Lexxi is a technology vendor and is not itself a covered entity under HIPAA. Whether Hey, Lexxi acts as a “business associate” depends on Client’s role and the matter at issue. The onus is on Client to determine whether a Business Associate Agreement (“BAA”) is necessary for its practice or a specific matter and, if so, to request one from Hey, Lexxi by contacting legal@heylexxi.com. Hey, Lexxi will evaluate each request on a case-by-case basis and, where appropriate, will enter into a mutually acceptable BAA before Client submits protected health information for which a BAA is required. Absent a fully executed BAA, Client agrees not to submit protected health information to the Services in any context that would require Hey, Lexxi to act as a business associate under HIPAA.

8.5 Details of Processing

The Parties acknowledge the following details of Hey, Lexxi’s processing of Client Data (supplemented by the DPA):

  • Nature and purpose. Receiving Client-submitted case materials and using automated and AI-assisted processing to generate HLGRs and related work product, and to provide, secure, and support the Services.

  • Frequency. Continuous, for the duration of the subscription term and as Client submits materials.

  • Categories of data subjects. Client’s own clients, patients, claimants, and other individuals referenced in the case materials Client submits, and Client’s Users.

  • Categories of personal information. Identifiers (names, contact details); professional, employment, and claim-related information; and case-file content contained in submitted documents. Account, billing, and aggregate usage data are collected for Users.

  • Sensitive personal information. May include medical and health information and other categories treated as sensitive under applicable law, to the extent contained in the case materials Client chooses to submit. Client is responsible for having a lawful basis and any required affirmative consent to provide such information.

  • What is stored. Sensitive case content and extracted text are stored only on Hey, Lexxi’s HIPAA/BAA-covered cloud environment, encrypted at rest; the finished HLGR (and an auto-redacted copy) is written back to that same encrypted store. Hey, Lexxi’s application database holds metadata only (job status, timestamps, file size, pipeline type)—no document content, extracted text, or patient data. Files pass only briefly through the web host on upload and download and are not persisted there.

9. Security

Hey, Lexxi maintains a written information security program with administrative, technical, and physical safeguards designed to protect Client Data against unauthorized access, use, alteration, or destruction, appropriate to the nature of the data and the risks involved. These measures include:

  • encryption of Client Data in transit and at rest using industry-standard protocols, with sensitive content encrypted at rest under Hey, Lexxi’s own managed key;

  • role-based access controls, authentication requirements (including support for multi-factor authentication), and least-privilege access for personnel;

  • logical separation of customer data and hardening of production environments;

  • logging and monitoring designed to detect and respond to security events; and

  • vendor diligence and contractual security commitments from subprocessors that handle Client Data.

Compliance status. Hey, Lexxi is a startup and continues to mature its security program. Hey, Lexxi does not currently represent that it holds SOC 2 or any other third-party security certification or attestation, and nothing in this Agreement should be read as such a representation.

Security incident notification. If Hey, Lexxi becomes aware of a confirmed breach of security leading to the unauthorized access to or disclosure of Client Data in Hey, Lexxi’s possession, Hey, Lexxi will notify the affected Client without undue delay and consistent with applicable law and any executed BAA or DPA, and will take reasonable steps to investigate and mitigate the incident. Client is responsible for any notifications it is required to make to its own clients, regulators, or affected individuals.

10. Confidentiality

Each Party may receive confidential information of the other. The receiving Party will use the disclosing Party’s confidential information only to perform under this Agreement and will protect it using at least reasonable care. Client Data is the confidential information of Client. These obligations do not apply to information that is or becomes public through no fault of the receiving Party, was lawfully known without obligation of confidence, or is independently developed, and do not prevent disclosure required by law (with notice where permitted).

11. Intellectual Property

As between the Parties, Hey, Lexxi owns all right, title, and interest in and to the Services and all related software, technology, and documentation, excluding Client Data. Client retains ownership of Client Data and HLGRs as set forth in Section 8.1. If Client provides suggestions or feedback, Hey, Lexxi may use it to improve the Services without restriction or obligation.

12. Warranties and Disclaimers

The Services are provided “AS IS” and “AS AVAILABLE.” To the fullest extent permitted by law, Hey, Lexxi disclaims all warranties, whether express, implied, or statutory, including the implied warranties of merchantability, fitness for a particular purpose, title, and non-infringement.

AI and accuracy. Output generated by the Services may rely on automated and artificial-intelligence processing and can contain errors, omissions, or inaccuracies. Hey, Lexxi does not warrant that any HLGR or other output is accurate, complete, current, or fit for any particular legal use, or that the Services will be uninterrupted, secure, or error-free. Client must independently review and verify all output before relying on it.

Hey, Lexxi cannot guarantee security beyond what we can control; we adhere to modern practices to ensure security. We make efforts to continuously update security according to best practices and based upon addressing ever-changing technologies, including hacking technologies.

13. Limitation of Liability

To the fullest extent permitted by law, neither Party will be liable for any indirect, incidental, special, consequential, exemplary, or punitive damages, or for lost profits, revenue, data, or goodwill, arising out of or related to the Services or this Agreement, even if advised of the possibility of such damages. Hey, Lexxi’s total aggregate liability arising out of or related to this Agreement will not exceed the amounts paid by Client to Hey, Lexxi for the Services during the twelve (12) months immediately preceding the event giving rise to the claim. These limitations do not apply to liability that cannot be limited under applicable law, or to Client’s indemnification and payment obligations.

14. Indemnification

Client will defend, indemnify, and hold harmless Hey, Lexxi and its officers, members, employees, and agents from and against any third-party claims, losses, liabilities, and expenses (including reasonable attorneys’ fees), and any potential criminal prosecution or civil liability, arising out of or related to: (a) Client Data, including Hey, Lexxi’s authorized processing of it; (b) Client’s failure to obtain required consents or authorizations; (c) Client’s or any User’s violation of law, professional-responsibility rules, this Agreement, or the Acceptable Use terms, including any misuse of the Services by a User; or (d) Client’s use of any output of the Services. Client’s responsibility under this Section applies whether the violation is committed by Client or by any of its Users.

Hey, Lexxi will defend and indemnify Client against third-party claims that the Services, as provided and used in accordance with this Agreement, infringe such third party’s intellectual-property rights. This is Client’s sole remedy for infringement claims.

15. Governing Law and Dispute Resolution

This Agreement is governed by the laws of the State of California, without regard to its conflict-of-laws rules. Subject to the arbitration provision below, the Parties consent to the exclusive jurisdiction of the state and federal courts located in Riverside County, California.

Informal resolution; arbitration. The Parties will first attempt in good faith to resolve any dispute informally by contacting legal@heylexxi.com. Any dispute not resolved within sixty (60) days may, at either Party’s election, be resolved by binding arbitration administered by JAMS under its applicable rules, seated in Riverside County, California. Each Party waives any right to a jury trial and to participate in a class action, to the extent permitted by law. Either Party may seek injunctive relief in court for misuse of intellectual property or confidential information.

16. General

Entire agreement; order of precedence. This Agreement, together with any Order Form, the DPA, any executed BAA, and Exhibit A, is the entire agreement between the Parties regarding the Services for orders that reference it, and supersedes prior agreements on that subject. In case of conflict, the following order of precedence applies: (1) an executed BAA (as to PHI), (2) the DPA (as to personal information), (3) the applicable Order Form, and (4) this Agreement.

Assignment. Client may not assign this Agreement without Hey, Lexxi’s consent; Hey, Lexxi may assign to an affiliate or in connection with a merger or sale of assets.

Notices. Legal notices to Hey, Lexxi must be sent to legal@heylexxi.com; notices to Client may be sent to the contact on the Order Form.

Miscellaneous. If any provision is held unenforceable, the remaining provisions remain in effect. Failure to enforce a provision is not a waiver. Neither Party is liable for delays caused by events beyond its reasonable control. The Parties are independent contractors.

Signatures

Signatures are waived. Each Party authorized representative who signs up for Hey, Lexxi products/services agrees to this Master Services Agreement, unless/until a specific MSA is entered into between You and Hey, Lexxi LLC in writing, signed by both Parties.

By agreeing to the MSA terms within the Order Form, Client agrees to the MSA(including the DPA at https://heylexxi.com/dpa) and confirms it has determined whether a Business Associate Agreement is required for its use; if so, Client will request one at legal@heylexxi.com before submitting protected health information that requires a BAA.

This MSA is a starting position and not legal advice. Have it reviewed by counsel against your actual commercial terms and insurance before use.