Recover by Civaren Customer Agreement
Version: 2026-08-10-v1
Effective date: August 10, 2026
This Recover by Civaren Customer Agreement (the "Agreement") is between Civaren, meaning the person or legal entity offering the Recover by Civaren service and identified as the merchant or service provider on the applicable checkout page, invoice, receipt, or order record ("Civaren," "we," "us," or "our"), and the person or legal entity identified by the subscribing user during acceptance or in the applicable order record ("Customer," "you," or "your").
If an individual accepts this Agreement on behalf of a company, healthcare provider, health plan, business associate, or other organization, that individual represents and warrants that they have authority to bind that organization, and Customer means that organization.
1. Acceptance; paid customers are bound by both agreements
By creating or using an account, Customer agrees that use of the Service is subject to this Agreement. Before a paid subscription can begin, Customer must affirmatively accept both this Customer Agreement and the Recover by Civaren Business Associate Agreement (the "BAA") and attest that the accepting user is authorized to bind Customer.
Payment for, activation of, or continued use of a paid subscription after that acceptance confirms Customer's agreement to be bound by both documents. The BAA is incorporated into this Agreement by reference. If the BAA and this Agreement conflict with respect to Protected Health Information, the BAA controls.
The BAA is accepted by every paying Customer. Its HIPAA-specific obligations apply to the extent the parties' activities create a covered entity-business associate or business associate-subcontractor relationship under HIPAA.
2. Service
Recover by Civaren is a healthcare-operations software service designed to support administrative workflows such as appointment-capacity analysis, cancellation recovery, referral follow-up, patient-access operations, operational simulations, and related revenue-recovery workflows (the "Service").
The Service is not a medical device, does not provide medical diagnosis or treatment, and is not a substitute for professional clinical judgment. Customer is responsible for all clinical decisions, patient-care decisions, legal determinations, coding decisions, billing decisions, and other professional judgments made in connection with Customer's operations.
Civaren may modify and improve the Service over time. Material reductions in purchased core functionality will not apply retroactively during a prepaid subscription term except where reasonably necessary for security, legal compliance, abuse prevention, or third-party service changes outside Civaren's reasonable control.
3. Accounts and authorized users
Customer is responsible for maintaining accurate account information and for all activity occurring under its accounts. Customer will ensure that credentials are assigned only to authorized users, are not shared improperly, and are promptly disabled when access is no longer appropriate.
Customer must promptly notify Civaren of suspected unauthorized account access or compromise.
4. Fees, recurring billing, renewal, taxes, and cancellation
Paid subscriptions are billed in advance at the price and billing interval presented at checkout or in an applicable order form. Unless otherwise stated, subscriptions automatically renew for successive periods of the same length until canceled.
Customer authorizes Civaren and its payment processor to charge the payment method on file for recurring subscription fees, applicable taxes, and other amounts Customer has expressly authorized.
Customer may cancel through the Service or the designated billing portal. Unless an order form states otherwise, cancellation takes effect at the end of the then-current paid billing period. Customer remains responsible for charges incurred before the effective cancellation date. Fees are non-refundable except where required by law or expressly stated in an order form.
Customer is responsible for taxes, duties, and governmental assessments associated with its purchase, other than taxes based on Civaren's net income.
5. Customer Data
Customer Data means data, files, content, instructions, and other information submitted to the Service by or for Customer, including Protected Health Information where applicable.
As between the parties, Customer retains its rights in Customer Data. Customer grants Civaren a limited, non-exclusive right to host, copy, transmit, process, modify, and otherwise use Customer Data only as reasonably necessary to provide, secure, support, improve, and administer the Service, to comply with law, and as otherwise expressly permitted by this Agreement and the BAA.
Customer represents that it has all rights, permissions, consents, authorizations, and other lawful bases necessary to provide Customer Data to Civaren and to instruct Civaren to process it for the Service.
6. PHI and designated PHI workflows
Where Customer Data includes Protected Health Information ("PHI") subject to HIPAA, the BAA governs Civaren's handling of that PHI.
Customer will submit PHI only through features that Civaren expressly designates as PHI-enabled. Customer will not place PHI into general support requests, unapproved AI prompts, billing fields, account-profile fields, or other features that Civaren has not designated for PHI.
Civaren may technically block PHI intake until applicable contractual and operational requirements are enabled. A technical setting alone is not a representation that Customer or Civaren has satisfied every legal obligation applicable to a particular use case.
7. De-identification and aggregated information
To the extent permitted by the BAA and applicable law, Customer authorizes Civaren to de-identify PHI in accordance with 45 C.F.R. § 164.514(a)-(c) for purposes of providing the Service. Civaren will not attempt to re-identify information that has been de-identified under those standards except as permitted by law and agreed in writing.
Civaren may use information that is de-identified in accordance with applicable law, and aggregated information that does not identify Customer or any individual, to operate, secure, analyze, benchmark, and improve the Service. Civaren will not sell PHI.
8. Security and privacy
Civaren will maintain commercially reasonable administrative, technical, and physical safeguards appropriate to the nature of the Service and the information processed. Where the BAA applies, Civaren will comply with the security obligations stated in the BAA.
Customer acknowledges that no system can be guaranteed completely secure. Customer is responsible for configuring its use of the Service appropriately, limiting user access, maintaining endpoint security, and following applicable organizational security policies.
9. Artificial intelligence features
Some Service features may use artificial intelligence or machine-learning systems. AI-generated content may be incomplete, inaccurate, or unsuitable for a particular purpose. Customer must independently review outputs before relying on them for operational decisions.
Unless Civaren expressly enables a PHI-capable AI workflow under an applicable BAA and related controls, Customer will not submit PHI to an AI feature. AI features are not intended to diagnose, treat, prescribe, or make autonomous clinical decisions.
10. Acceptable use
Customer will not use the Service to violate law, infringe the rights of others, interfere with the Service, bypass security controls, introduce malicious code, attempt unauthorized access, conduct unlawful surveillance, or use the Service in a manner that materially increases risk to patients or individuals.
Customer will not use the Service to make solely automated decisions that produce legal or similarly significant effects on an individual where applicable law requires human involvement or other safeguards, unless Customer has independently implemented the legally required process.
11. Intellectual property
Civaren and its licensors own the Service, software, designs, documentation, models, workflows, and other technology provided by Civaren, including improvements and derivative works, excluding Customer Data.
Subject to this Agreement and payment of applicable fees, Civaren grants Customer a limited, non-exclusive, non-transferable, revocable right during the subscription term to access and use the Service for Customer's internal business operations.
Customer may provide feedback. Customer grants Civaren a perpetual, irrevocable, worldwide, royalty-free right to use feedback without restriction, provided Civaren does not identify Customer publicly as the source without permission.
12. Confidentiality
Each party may receive non-public information that is designated confidential or that reasonably should be understood to be confidential ("Confidential Information"). The receiving party will use Confidential Information only to perform or exercise rights under the parties' agreements and will protect it using at least reasonable care.
Confidential Information does not include information that the receiving party can demonstrate was lawfully known without restriction, becomes public through no breach, is independently developed without use of the other party's Confidential Information, or is lawfully received from a third party without a confidentiality duty.
If disclosure is legally required, the receiving party may disclose the required information and, where legally permitted, will provide reasonable prior notice.
PHI is governed by the BAA in addition to this Section.
13. Third-party services and subprocessors
The Service may depend on third-party cloud, communications, payment, identity, analytics, AI, or integration providers. Civaren may use subprocessors to provide the Service. Where a subprocessor creates, receives, maintains, or transmits PHI on Civaren's behalf, Civaren will require the subprocessor to agree to applicable HIPAA restrictions and conditions as required by law and the BAA.
Third-party products that Customer separately elects to connect may be governed by their own terms.
14. Suspension
Civaren may suspend access where reasonably necessary to address a security risk, suspected unlawful activity, material breach of this Agreement, nonpayment, threat to the Service or other customers, or legal requirement. Where practicable, Civaren will provide notice and a reasonable opportunity to cure before suspension.
15. Term and termination
This Agreement begins when Customer first accepts it or uses the Service, whichever occurs first, and continues until all Customer subscriptions and accounts are terminated, except for provisions that by their nature survive.
Either party may terminate for material breach if the breach is not cured within thirty (30) days after written notice, unless a shorter period is reasonably necessary for security, confidentiality, HIPAA compliance, or unlawful activity.
Termination does not relieve either party of obligations accrued before termination. Customer's access to Customer Data following termination may be limited by the Service's retention schedule, the BAA, law, and any applicable order form.
16. Warranties and disclaimers
Each party represents that it has authority to enter into this Agreement.
Except as expressly stated in this Agreement, and to the maximum extent permitted by law, the Service is provided "as is" and "as available." Civaren disclaims implied warranties of merchantability, fitness for a particular purpose, non-infringement, and any warranty that the Service will be uninterrupted or error-free.
Civaren does not warrant that projected revenue, simulated appointment recovery, operational recommendations, or AI outputs will result in actual revenue or patient outcomes.
17. Limitation of liability
To the maximum extent permitted by law, neither party will be liable for indirect, incidental, special, exemplary, punitive, or consequential damages, or for lost profits, revenues, goodwill, or business interruption, arising out of or related to the parties' agreements, even if advised of the possibility.
Except for excluded claims below, each party's aggregate liability arising out of or related to the parties' agreements will not exceed the fees paid or payable by Customer to Civaren for the Service during the twelve (12) months preceding the event giving rise to the claim.
The limitations in the preceding paragraph do not apply to Customer's payment obligations, either party's fraud or willful misconduct, infringement or misappropriation of the other party's intellectual property, or liability that cannot lawfully be limited. Obligations specifically imposed by the BAA remain subject to applicable law and any limitations enforceable under that law.
18. Indemnification
Customer will defend and indemnify Civaren from third-party claims arising from Customer's unlawful use of the Service, Customer Data supplied without required rights or authorization, or Customer's violation of this Agreement, except to the extent caused by Civaren.
Civaren will defend and indemnify Customer from third-party claims alleging that Customer's authorized use of the unmodified Service infringes a United States patent, copyright, or trademark, subject to customary exclusions for Customer Data, combinations not supplied by Civaren, modifications not made by Civaren, and continued use after notice of an available non-infringing replacement.
The indemnified party will provide prompt notice, reasonable cooperation, and control of the defense to the indemnifying party, subject to the indemnified party's right to participate with its own counsel at its own expense.
19. Changes to terms
Civaren may update these terms from time to time. Material changes will be presented through the Service or another reasonable notice mechanism. Where a change materially affects Customer's rights or obligations, Civaren may require renewed affirmative acceptance before continued paid use.
A version identifier and effective date will be displayed with each posted agreement. Civaren's acceptance records may include the version and cryptographic hash of the accepted text.
20. Governing law and disputes
Unless an applicable order form states otherwise, this Agreement is governed by the laws of the Commonwealth of Massachusetts, without regard to conflict-of-law principles. The parties consent to exclusive jurisdiction and venue in the state and federal courts located in Massachusetts, except that either party may seek injunctive relief in any court of competent jurisdiction for misuse of intellectual property, Confidential Information, or PHI.
21. Notices
Operational notices may be provided through the Service or to the email address associated with Customer's account. Legal notices to Customer may be sent to Customer's account administrator or other legal contact on file. Legal notices to Civaren may be sent using the legal-contact information identified in the Service, invoice, receipt, or applicable order form.
22. Miscellaneous
Neither party may assign this Agreement without the other party's consent, except in connection with a merger, reorganization, sale of substantially all assets, or transfer to an affiliate, provided the assignee assumes the assigning party's obligations. Customer may not assign to a direct competitor of Civaren without Civaren's consent.
Neither party is liable for delay caused by events beyond its reasonable control, except for payment obligations and obligations concerning protection of Confidential Information or PHI.
The parties are independent contractors. This Agreement does not create a partnership, agency, fiduciary, or employment relationship.
If a provision is unenforceable, it will be modified to the minimum extent necessary and the remainder will remain effective. Waiver of one breach is not waiver of another. Headings are for convenience only.
This Agreement, the BAA, applicable order forms, and any incorporated policies are the entire agreement concerning the Service and supersede prior discussions on that subject. An order form controls over this Agreement for commercial terms expressly stated in that order form; the BAA controls for PHI-related terms.
23. Electronic acceptance record
Customer agrees that electronic acceptance, including clicking an acceptance control and completing or maintaining a paid subscription, is intended to constitute Customer's signature and agreement to this Agreement and the BAA. Civaren may retain records of acceptance, including the accepting user's identity, organization name, timestamp, source IP address, user agent, agreement versions, document hashes, Stripe checkout or subscription identifiers, and related audit metadata.