Terms of Service

Effective date: 3 September 2026

 

These Terms of Service govern access to and use of the Collective Minds platform and CM's services. They are
entered into between Collective Minds Radiology AB ("CM"), a company registered in Sweden under number
559120-7187, and the Customer identified in the applicable Service Order. Certain provisions also apply directly to
Authorized Users and Session Viewers as expressly stated in these Terms.

The General Terms apply to everyone, including Customers, Authorized Users, and Session Viewers. Additional
Policies apply according to your role and the service or use concerned. More than one Additional Policy may apply
at the same time. The table that follows tells you which ones apply to you.

General Terms: Apply to everyone who uses the Platform (1-24).

Additional policies: Apply according to your role based on the information provided on item 25

For each Customer, the General Terms and applicable Additional Policies form part of the same agreement.
Opening or closing a section changes only what is shown on screen. Every provision applies according to its terms
whether or not you open it.

General Terms

These apply to everyone who uses the Platform, according to their terms.

1. Parties and how to read these Terms

1.1 These Terms are entered into between Collective Minds Radiology AB, company number 559120-7187, registered at Svärdvägen 5, 182 33 Danderyd, Sweden, and the Customer. In these Terms, CM, we and us mean Collective Minds Radiology AB. You means the Customer or, where the context requires, an Authorized User or Session Viewer.

1.2 The CM Group. Collective Minds Radiology AB belongs to a group of companies. Collective Minds Radiology AB is the CM entity that contracts with you under these Terms and is responsible to you for performance. CM may perform parts of the services through CM Group companies and remains responsible for that performance as provided in these Terms. Where a CM Group company processes personal data on the Customer's behalf, it does so as a subprocessor and is identified in the Subprocessor List.

1.3 Customer Affiliates. A Customer Affiliate may place a Service Order under these Terms, in which case that Affiliate is the Customer for that Service Order and is separately responsible for it. A Customer may permit its Affiliates' personnel to be Authorized Users, and the Customer remains responsible for them under clause 4.4.

1.4 How obligations are stated. Obligations are stated in ordinary language. Where an obligation depends on a technical standard, legal provision or specific data element, additional detail may follow in a passage marked Note. An introductory paragraph at the beginning of a section or of an Additional Policy is part of these Terms and binds the parties to the same extent as a numbered clause in that section or policy.

Note. A passage marked Note is an operative part of these Terms and binds the parties to the same extent as the clause it follows. A Note supplements, and must be read together with, the clause it follows. "Must" and "will" state obligations; "may" states a right.

1.5 Scope. These Terms govern access to and use of the Platform and the public CM website, which may be subject to separate terms of use. CM makes the Platform available only in territories in which it has determined it may lawfully do so. The description of a service does not constitute a representation that it is available in every territory.

1.6 Relationship with the Privacy Policy/Notice. These Terms allocate rights and obligations between the parties. Beyond matters described in these Terms of Service, the Privacy Policy/Privacy Notice describes how CM processes personal data for its own purposes in more detail; it is addressed to individuals, is not a contract, and is not incorporated into these Terms. Processing carried out by CM on the Customer's behalf is governed by the Data Processing Agreement, which prevails over these Terms on matters concerning personal data. Where CM acts as a business associate, the Business Associate Agreement prevails on matters concerning Protected Health Information (PHI).

1.7 Ownership. The Platform is CM's. Ownership of Content and Results is governed by clause 13. CM claims no ownership of, license over, or interest in either beyond the limited operating right in clause 13.6 needed to provide the services. Restrictions on export under clause 8 concern identifiability and permitted egress and do not determine ownership.

1.8 Acceptance. The Customer accepts these Terms by signing or otherwise accepting a Service Order or by completing a subscription. An Authorized User accepts the obligations in these Terms that expressly apply to Authorized Users by confirmation of these Terms before access to the Platform and by using the Platform. A Session Viewer accepts the obligations applicable to Session Viewers on the screen presented before Teaching Content opens and by using the Platform. An Authorized User or Session Viewer does not necessarily become the Customer or assume the Customer's obligation to pay Fees. Where the Customer has a signed master agreement with CM, the MSA and the Service Order will take precedence over any specific conditions agreed upon.

1.9 Eligibility and permitted use. The Platform is a professional medical imaging platform made available solely for healthcare, clinical trial, research, education and related professional purposes supported by CM's services. Access is limited to Customers, Authorized Users, and Session Viewers who are authorized to use the Platform for such purposes. The Platform is not made available to the general public and must not be accessed or used for personal use, general browsing, curiosity, exploration, competitive intelligence, unauthorized testing or any other purpose not permitted by these Terms or the applicable Service Order. Nothing in these Terms grants any person a right to access or use the Platform without authorization from CM or the applicable Customer.

1.10 Filtering. The Platform interface and this document may allow you to display only the provisions relevant to your role. Filtering affects display only. These Terms constitute one agreement and every provision applies according to its terms.

2. What capitalized words mean

Capitalized terms have the meanings below. Other words carry their ordinary meaning.

Term Meaning
Acceptable Use Policy The contract document setting out detailed conduct rules for use of the Platform.
Additional Policy A policy identified in the applicability table above that supplements the General Terms for a particular Customer, role, service or use.
Affiliate An entity that controls, is controlled by, or is under common control with a party.
Authorized User An individual to whom the Customer grants access to the Platform.
Business Associate Agreement The agreement required by 45 CFR 164.504(e) where CM handles Protected Health Information on behalf of a Covered Entity or another business associate.
Clinical Trial A clinical trial or clinical investigation recorded as such in the applicable Service Order and governed by the Clinical Trials Policy.
CM Group Collective Minds Radiology AB and its Affiliates.
CM-Connect The CM ingestion gateway described in clause 5, installed within the Customer's network and designed principally for DICOM Content. It may support other file types where the relevant functionality and configuration are enabled.
CM Security Commitments The technical and organizational security measures and other security obligations expressly undertaken by CM under these Terms, the Data Processing Agreement, the applicable Service Order, or any other contract document expressly agreed between CM and the Customer.
Content Health Data and any other data, document, annotation, response or file uploaded to or created within the Platform by or for the Customer or an Authorized User.
Cookie Policy CM's published policy describing cookies and similar technologies used on CM's websites. It is addressed to individuals and is not a contract document.
Covered Entity A health plan, health care clearinghouse or health care provider within the meaning of 45 CFR 160.103.
Customer The entity or individual that enters into the applicable Service Order or subscription and is responsible for the Fees and its Authorized Users.
Data Processing Agreement The agreement governing CM's processing of personal data on behalf of a controller or processor.
Data Specification The published specification with which Content must comply, comprising a baseline standard and an enhanced standard for releases for a teaching session (Release State 4 terms).
De-identified Treated so that the information is not individually identifiable under 45 CFR 164.514(b), by the Safe Harbor method or Expert Determination. Validly De-identified information is outside HIPAA. It does not follow that the information is anonymous under the GDPR.
Documentation The user, technical, API and operating documentation made available by CM for the Platform.
Fees The amounts payable under the applicable Service Order or subscription.
GDPR The General Data Protection Regulation, Regulation (EU) 2016/679, as amended or replaced.
General Terms The provisions of these Terms under the heading General Terms, which apply according to their terms to Customers, Authorized Users and Session Viewers.
Health Data Data relating to health held on the Platform, including DICOM imaging from radiology, cardiology, nuclear medicine and digital pathology; whole slide images in vendor formats; laboratory results; reports and other free text; structured study data; waveforms and signals; and data derived from any of these. Health Data is data concerning health within the meaning of Article 4(15) GDPR and, where HIPAA applies to it, may constitute Protected Health Information.
HIPAA The Health Insurance Portability and Accountability Act of 1996 and its implementing regulations at 45 CFR Parts 160 and 164, as amended.
Intended Purpose and Component Notice The contract document stating the intended purpose of the Platform and identifying the Viewer, its manufacturer and the version made available.
Lead Party The organization named in a Service Order as speaking for a Project involving more than one organization.
Limited Data Set Protected Health Information from which the identifiers listed in 45 CFR 164.514(e)(2) have been removed. A Limited Data Set remains Protected Health Information under HIPAA. Its status under the GDPR must be assessed separately and it is Pseudonymized within the meaning of Article 4(5) GDPR only where the requirements of that provision are satisfied.
Non-Conforming Content Content that does not comply with the applicable Data Specification, including Content containing direct identifiable identifiers, text rendered as image data, a visible slide label, or identifying information in a free-text field or burned-in pixels.
Platform The CM software-as-a-service platform and the services provided through it.
Privacy Notice CM's published notice describing how CM processes personal data for its own purposes. It is addressed to individuals and is not a contract document.
Project The workspace for a single body of work, including a Clinical Trial, research study, development activity, collaboration or course.
Project record An operational record of Project configuration, participants, Release States, permitted purposes and other Project facts authorized by the applicable Service Order. A Project record does not amend Fees, liability, warranties, term or other commercial terms unless the applicable Service Order expressly authorizes it.
Protected Health Information Individually identifiable health information within the meaning of 45 CFR 160.103, held or transmitted by a Covered Entity or its business associate.
Pseudonymized Processed so that the data can no longer be attributed to a specific person without additional information kept separately, within the meaning of Article 4(5) GDPR. Pseudonymized data remain personal data where the GDPR applies. Pseudonymization under the GDPR does not by itself constitute De-identification under 45 CFR 164.514(b) or take information outside HIPAA.
Release State One of the states in clause 7 determining who may access an item of Content.
Results Datasets, annotations, segmentations, measurements, statistics, figures and trained models produced from Content in a Customer's Project.
Service Level Agreement CM's published service level agreement for the Platform, addressing availability, support coverage, severity levels, response and resolution targets, service metrics and the responsibilities of each party in relation to support.
Service Order The order form, subscription record or other ordering document accepted by the parties that records the services ordered, Project details, plan, limits, Fees, term, hosting region, retention and any professional services.
Session Viewer A person who accesses Teaching Content under a release for a teaching session (Release State 4 terms) with or without holding an account, under the specific teaching session.
Subprocessor List The list published by CM identifying the subprocessors engaged in providing the Platform.
Teaching Content Content made available for teaching under releases for a teaching session (Release State 4).
Viewer The third-party medical image viewing component described in clause 9.

2.1 "Including" means "including without limitation." A reference to legislation or a standard is to that instrument as amended or replaced. Headings do not affect interpretation.

3. Prohibited conduct

The prohibitions and reporting obligations below apply, according to their terms, to every Customer, Authorized User, and Session Viewer.

4. Access, accounts and Customer responsibility

4.1 Accounts and access. Access to the Platform requires an account or other access method authorized by CM or the applicable Customer. Accounts may be provisioned by CM at the Customer's request, through an invitation or activation process, or by another account setup method made available by CM. For an individual subscription, an account may be provisioned on completion of the applicable subscription and verification process. Where single sign-on is enabled for a Customer, Authorized Users may authenticate through the Customer's identity provider. The availability of a registration page, login page, invitation link or other technical means of reaching the Platform does not by itself authorize access or use.

4.2 Customer administrator. The Customer must maintain at least one administrator, who is an Authorized User, able to act on its behalf in relation to user access, disposition of Content and matters reserved to the Customer under these Terms.

4.3 Authentication and single sign-on. Each Authorized User must use the authentication method made available for that account. Where single sign-on or another Customer-controlled identity provider is configured for the Customer, the Customer is responsible for the security and administration of that identity provider, including determining which of its users are entitled to authenticate through it and withdrawing that entitlement when appropriate. CM remains responsible for authentication and access controls operated by CM as part of the Platform in accordance with the CM Security Commitments.

4.4 Customer responsibility for Authorized Users. The Customer is responsible for the acts and omissions of its Authorized Users in relation to the Platform as if they were its own, including ensuring that each Authorized User is authorized to use the Platform, is aware of and complies with these Terms and the applicable Data Specification, withdrawing access promptly when an individual ceases to be entitled to it, and reporting incidents, as required under clause 3.13.

4.5 Multiple Customers. If an individual is an Authorized User of more than one Customer. Access, Content and audit records are maintained separately by Customer. Content held for one Customer is not available in another Customer's environment except through a permitted transfer under clause 7.5.

4.6 Deactivated Authorized Users. Where an Authorized User is deactivated, Content that person placed in a shared area remains available to the Customer. Content in that person's private area is dealt with under clause 15.6.

5. Ingestion: CM-Connect, web upload and preparation of Content

Content reaches the Platform through CM-Connect or web upload. The Service Order or the agreed Terms to which the route applies; however, if CM-Connect has not been explicitly agreed, web upload will be the available method.

Unless disabled by the Customer or otherwise configured, either route may apply CM's standard pseudonymization functionality. The availability or application of that technical functionality does not, by itself, mean that the Customer has procured a CM pseudonymization, de-identification, or anonymization service. CM pseudonymization, de-identification, or anonymization services need to be explicitly agreed upon and will generally entail costs to be borne by the Customer/User unless the costs are assumed by other means (e.g., an EU-funded consortium).

5.1 CM-Connect. CM-Connect is software installed by the Customer on a server within the Customer's network, on an operating system supported by CM. CM does not host it. It is designed principally for DICOM Content. It may support other file types where the relevant functionality and configuration are enabled. Separate channels may be configured, each with its own treatment rules and destination.

Note. For DICOM Content, channel rules may be expressed against the attribute confidentiality profiles in the DICOM Standard, PS3.15 Annex E, and the per-attribute actions in Table E.1-1. The configured channel records the base profile and applicable options. Private attributes may be enumerated by group and private creator and removed unless retained by recorded decision. Where pixel inspection or masking is configured, the Burned In Annotation attribute is not relied upon as conclusive evidence that no text is present.

5.2 Where CM-Connect pseudonymization functionality is enabled, the configured treatment is applied before transmission from the Customer's network to CM. CM-Connect establishes outbound connections and records the technical actions performed.

5.3 Replacement identifiers. Where CM-Connect replaces source identifiers, any mapping or additional information specifically enabling those replacement identifiers to be related to originating identifiers may be retained at the originating site and is not transmitted to CM. CM does not possess or access that additional information. This does not guarantee that no other identifying information remains in the Content and does not make the Content anonymous by default (requires specific configurations and other separate assessments to be agreed).

5.4 CM-Connect may apply the rules configured for a channel and record the treatment applied. The technical availability, configuration or application of those rules does not itself transfer responsibility for preparation of Content to CM. Responsibility is allocated under clauses 5.12 to 5.18.

5.5 File types. CM-Connect is designed principally for DICOM Content. Other file types may be accepted where relevant functionality is enabled. Acceptance of a file by CM-Connect or the Platform does not mean that the file type is supported for pseudonymization, that an applicable treatment has been successfully performed, or that the file is Pseudonymized, De-identified or anonymous. Unless expressly covered by the applicable Service Order, the Customer must verify non-DICOM and non-standard files separately.

5.6 Whole slide images. Where the Customer uploads whole slide images, embedded labels and macro images must be addressed in accordance with the applicable Data Specification and verified separately from metadata treatment. Removal of metadata does not by itself remove information rendered into those images.

5.7 The Customer is responsible for the server on which CM-Connect runs, including its security, patching, availability, backup and physical protection, and for the network configuration permitting it to operate. This general principle applies unless otherwise expressly agreed, in which case it will be subject to charges and additional agreements. The classes of data CM-Connect may query and retrieve are limited to those stated in the Service Order, and neither party may configure it to retrieve data outside that scope.

5.8 Web upload. Where Content is uploaded through the web interface, standard technical pseudonymization functionality may apply according to the applicable configuration. Web upload does not create the same technical and physical pre-transmission barrier as CM-Connect. Content uploaded through the web interface may reach CM infrastructure before or as that functionality is applied. The Customer must therefore satisfy its obligations under clauses 5.10 and 5.13 independently of the availability of that functionality.

5.9 CM-Connect is not available on an individual-user subscription. An individual subscriber uploads through the web interface unless expressly agreed otherwise, and normally this transforms an individual subscription into a customer that requires the signature of specific separate agreements, such as a master services agreement.

5.10 Upload warranty by the User. On each upload you warrant that, at that time: the Content complies with the applicable Data Specification; the Customer is authorized to upload and use the Content for the purpose for which it is being uploaded; the processing is lawfully authorized as required by clause 18.5; you have not entered identifying information into a field contrary to these Terms (specially clause 3); and you are not aware of a circumstance rendering the Content Non-Conforming Content.

5.11 CM records the identity of the person giving the warranty in clause 5.10, the time, the item concerned and the version of the text accepted.

Responsibility for preparation

5.12 Where CM is expressly engaged to prepare Content. Where the applicable Service Order expressly records that the Customer procures a CM pseudonymization or de-identification service in respect of a category of Content, whether through CM-Connect or another agreed method, CM is responsible for applying the treatment expressly described in that Service Order. That responsibility is limited to the agreed treatment and scope. The availability, configuration, or use of CM-Connect or web upload does not by itself constitute procurement of that service. Unless the Service Order expressly provides otherwise, CM does not represent that the resulting Content is pseudonymized, anonymous, validly De-identified under HIPAA, or outside applicable data protection law.

5.13 Where CM is not expressly engaged to prepare Content. Where the Service Order does not expressly record a CM pseudonymization, anonymization, or de-identification service, the Customer remains responsible for preparation, treatment, and verification of the Content. Any standard technical functionality available through CM-Connect or web upload is an additional technical control and does not transfer that responsibility to CM or constitute a warranty of its legal outcome. If that functionality is disabled or does not apply to the relevant file type, the Customer remains responsible for ensuring that the Content has been lawfully prepared before transmission.

5.14 Individual subscriptions. Unless the applicable Service Order expressly records a CM pseudonymization or de-identification service for an individual subscription, the clause above applies. The Individual Account Policy states the additional requirements applying to an individual subscription and the warranties on which CM relies.

5.15 Anonymization is a separate service. CM performs anonymization only where the applicable Service Order expressly records anonymization as a service and identifies its scope, method, assessment and agreed deliverables. Standard pseudonymization functionality and a pseudonymization service are not, by themselves, an anonymization service. Clause 12.9 applies except to the extent that an applicable Service Order expressly provides otherwise.

5.16 Identifying information received contrary to these Terms. Where Content transmitted to CM contains identifying information contrary to these Terms or the applicable Data Specification, that Content is Non-Conforming Content. Except to the extent the event results from CM's failure to perform a specific treatment expressly undertaken in the applicable Service Order, responsibility for the upload remains with the Customer, including where the Content was uploaded by an Authorized User.

5.17 CM's receipt, acceptance, storage or processing of Content, the application of standard technical functionality, the ability of CM-Connect or web upload to accept the file type, or the failure of an automated control to detect identifying information does not transfer responsibility for the upload to CM.

5.18 If CM becomes aware of, or reasonably suspects, that such Content has been received, CM will treat the matter as an information security and data protection incident and may take the investigation, containment, restriction, quarantine and remediation measures provided for in these Terms. Nothing in this clause limits an obligation imposed directly on CM under applicable law, the Data Processing Agreement or the Business Associate Agreement.

6. Ingestion controls

6.1 CM operates automated and non-automated ingestion controls. Those controls may inspect Content on and after ingestion for indications of Non-Conforming Content and may reject, flag or quarantine Content.

6.2 The Customer must not transmit to CM any key, code, mapping table or other additional information that would enable replacement identifiers to be linked to the corresponding source identifiers, unless the applicable Service Order expressly permits it. Where CM-Connect is used, clause 5 describes how that additional information is kept separate from the Content transmitted to CM. Where Content is uploaded through the web upload/interface, standard technical pseudonymization functionality may be applied, but the Content may reach CM infrastructure before or while that functionality is applied, and the functionality may be disabled, differently configured or unavailable for a particular file type.

6.3 The controls in this clause cannot detect every instance of Non-Conforming Content. Acceptance of Content by the Platform is not a confirmation that the Content complies with the Data Specification, is not a warranty, and is not evidence that a warranty was correctly given. Operation or failure of a control does not transfer the Customer's responsibility for preparation, treatment or verification except to the extent CM expressly undertook a specific treatment in the applicable Service Order.

6.4 On identifying Content that CM reasonably believes to be Non-Conforming Content, CM may immediately restrict access to it, place it in quarantine, suspend a Release State applying to it, invalidate an access link or code, and require the Customer to remediate or delete it. CM may reject Content before ingestion or isolate it where reasonably necessary to protect individuals, the Customer, other customers, the Platform or CM's compliance with applicable law. CM will not permanently delete Customer Content solely under this clause except on the Customer's documented instruction, where required by applicable law, or where expressly permitted by the Data Processing Agreement or Business Associate Agreement.

6.5 CM will notify the Customer promptly. Each party must provide the other with information within its control reasonably required to investigate, contain and remediate the incident and determine whether a notification obligation arises.

Note. The presence of identifying information or Non-Conforming Content does not by itself establish that a "personal data breach" within the meaning of the GDPR or a "breach" within the meaning of HIPAA has occurred. Where CM acts as processor, the Data Processing Agreement governs notification to the controller. Where CM acts as a business associate, the Business Associate Agreement governs applicable HIPAA notification. Nothing in this Note limits a mandatory obligation imposed by law.

7. Release States and Sharing

7.1 Every item of Content is in one of the Release States below. The Release State determines who may access the Content and the Data Specification with which it must comply.

Release State Permitted access Conditions
1. Private area The uploading Authorized User only Default on upload. Baseline Data Specification.
2. Project Authorized Users admitted to the Project, who may belong to more than one organization Baseline Data Specification. The Lead Party controls admission. Normal state for Clinical Trials, studies and collaborations.
3. Customer All Authorized Users of the Customer Baseline Data Specification.
4. Teaching session Persons holding the access link and code during the validity period Enhanced Data Specification, the Education and Teaching Policy, and acceptance by each Session Viewer.
5. Transfer to another Customer The receiving Customer within its own Customer environment Available only where the applicable Service Order permits it and subject to clause 7.5.
6. Public Not offered The Platform provides no public Release State.


7.2
A Release State may be changed or withdrawn at any time by the originating Authorized User or Customer administrator. Withdrawal removes prospective access only and does not undo access already exercised or alter records already created. It does not authorize continued access, use, or disclosure after access has been withdrawn except as otherwise permitted by these Terms, the applicable Service Order, or applicable law.

7.3 Content prepared only for the baseline Data Specification must not be placed in releases for a teaching session (Release State 4) and must first satisfy the enhanced Data Specification.

7.4 In a Project involving more than one organization, each participating organization remains responsible for its own Authorized Users and the Content it contributes.

7.5 A transfer to another Customer requires authorization by the originating Customer and acceptance by the receiving Customer, a stated purpose, and a record of the transfer identifying the Content, both Customers, the purpose, date, and authorizing persons. Replacement identifiers must not be carried across where doing so would preserve an unnecessary link between the two Customer environments.

8. Egress

8.1 Any assessment of identifiability or anonymity is contextual and is reached by reference to the environment in which information is held, the persons who may access it, and the means reasonably likely to be available to them. A copy removed from the Platform does not carry that conclusion with it.

8.2 Content. Export of a limited number of static images for a lecture or conference is permitted only where the applicable Service Order provides for it, up to the applicable limit, and only from material prepared to the enhanced Data Specification. Export in a consumer image format may discard file attributes while preserving information rendered into the image and therefore does not itself address text rendered into image data or a visible slide label. Export under this clause is an exception to clause 3.5. The other restrictions in these Terms continue to apply.

8.3 Results other than models and datasets. Tables, measurements, statistics and figures may be removed from the Platform, and CM does not restrict publication. They must not contain identifying information, incorporate another Customer's Content, or be presented in a manner that permits an individual to be identified or singled out. Small subgroups and extreme values may create such a risk even where no direct identifier is present. Any publication remains the responsibility of the party publishing or authoring it, and unless otherwise explicitly agreed, CM assumes no responsibility for publications made using data on CM’s Platform.

8.4 Derived datasets. A dataset constructed within a Project may be removed following an assessment, performed or accepted by CM, appropriate to the derived dataset and the environment into which it will be released, taking the assessment of the source Content into account. CM will not unreasonably withhold agreement. Agreement is not required where the applicable Service Order already expressly provides for delivery of that dataset. This clause manages identifiability and does not determine ownership.

8.5 Trained models. Export of model weights, or making a trained model available outside the Project, requires CM's prior written agreement and an assessment appropriate to the model and target environment. CM will not unreasonably withhold agreement. CM acquires no ownership interest in the model by reason of this clause.

Note. The assessment addresses relevant risks including memorization and membership inference. Both risks may increase where a model is trained on a small or distinctive cohort. CM's agreement or assessment under this clause is an egress and identifiability control. It does not establish that the Customer has a legal basis, authorization or other right to export or use the model.

8.6 Nothing in this clause permits screen capture, photography of a display or screen recording, which are prohibited in every Release State and for every category of Content and Results.

9. The Viewer

9.1 Except for the Viewer described in this clause, the Platform is not placed on the market by CM as a medical device. CM does not represent that the Platform as a whole holds a medical device approval, marking or certification. Medical images are displayed using the Viewer, which is a separate medical device component.

9.2 The Viewer and its manufacturer. The Viewer is MedDream. Current manufacturer documentation identifies MedDream UAB, K. Petrausko st. 26, LT-44156 Kaunas, Lithuania, as the manufacturer. CM is not the manufacturer and did not design the Viewer. The version of the Viewer made available through the Platform is identified by CM in the Platform or applicable Documentation.

9.3 Regulatory status. Current manufacturer documentation identifies MedDream as a Class IIb medical device under Regulation (EU) 2017/745, with notified body identification number 0197, and as FDA cleared under K222320. The regulatory certification and clearance relate to the Viewer and do not extend to the Platform as a whole or constitute a CM certification.

9.4 Intended purpose. The intended purpose of the Viewer is determined by its manufacturer. The Customer and Authorized Users must use the Viewer consistently with the manufacturer's applicable instructions for use. Use outside the manufacturer's intended purpose falls outside the manufacturer's conformity assessment.

9.5 Who may use it. The Customer is responsible for ensuring that use of the Viewer is limited to persons who satisfy the qualifications and user requirements stated in the manufacturer's documentation.

9.6 Mammography. Where the Viewer is used for mammography or another use subject to specific manufacturer conditions, the Customer and Authorized User must comply with those conditions. CM does not independently verify whether the Customer's source images, display or local environment satisfy them.

9.7 Mobile and other displays. The Customer and each Authorized User must comply with manufacturer requirements applicable to the display on which images are viewed. CM does not warrant that a device, browser, monitor or network controlled by the Customer satisfies those requirements.

9.8 No modification by CM. CM does not change the intended purpose of the Viewer or modify it in a manner intended to affect its compliance as placed on the market. Where a requested configuration would require CM to assume obligations of a manufacturer, CM may decline that configuration.

Note. Article 16 of Regulation (EU) 2017/745 provides circumstances in which a distributor, importer or other person may assume obligations incumbent on a manufacturer, including where it makes a device available under its own name or trademark subject to the applicable exception, changes the intended purpose, or modifies a device in a way that may affect compliance.

9.9 Version and manufacturer support. CM will use a Viewer version within the manufacturer's applicable supported lifecycle and will manage updates in accordance with CM's change-management processes. CM identifies the Viewer version currently made available through the Platform and will make that information available to the Customer on request.

9.10 Documentation on request. CM will identify the manufacturer and make applicable manufacturer documentation available to the Customer where reasonably required.

9.11 Incidents and field safety notices. The Customer and Authorized Users must notify CM without delay of a suspected malfunction, deterioration in performance or other safety issue concerning the Viewer. CM will transmit information to the manufacturer where appropriate and will communicate relevant field safety notices or corrective actions received from the manufacturer to affected Customers. Nothing in this clause replaces a reporting obligation imposed directly on a Customer or Authorized User by applicable law.

9.12 Teaching material. Teaching Content made available under releases for a teaching session (Release State 4) is for teaching only and must not be used for diagnosis, treatment or a clinical decision.

9.13 The rest of the Platform. Apart from the Viewer, no other part of the Platform is intended by CM to perform a diagnostic function or is placed on the market by CM as a medical device. An opinion, measurement or annotation recorded by an Authorized User is that person's own. CM does not review or endorse it.

10. Service levels, support and professional services

10.1 Availability, support coverage, severity levels, response and resolution targets, service metrics, and the responsibilities of CM and the Customer in relation to support are set out in the Service Level Agreement. The Service Level Agreement applies by default unless the applicable Service Order expressly provides otherwise.

10.2 CM may suspend access for planned maintenance and, where necessary to protect the Platform or Content, for emergency maintenance. CM will use reasonable efforts to give advance notice of planned maintenance where practicable.

10.3 The Platform is not a system of record and must not be relied on as the sole authoritative repository of Content. The Customer is responsible for retaining any source or other authoritative record required for its purposes and obligations.

10.4 Professional services. Implementation, site onboarding, channel configuration, integration, migration and training are provided only where an applicable Service Order provides for them. A Service Order is subject to these Terms and varies them only where it expressly says so.

11. Security, processors and subprocessors and hosting

11.1 CM security commitments. CM will implement and maintain the technical and organizational security measures and other security obligations constituting the applicable CM Security Commitments.

11.2 11.2 Customer-side security and connectivity. The Customer is responsible for procuring and maintaining suitable internet and telecommunications connectivity for access to the Platform and for the security, configuration and operation of the systems, local networks and devices under its control that are used to access the Platform. The Customer is also responsible for any identity provider or single sign-on environment under its control, including the administration and withdrawal of user access through that environment, and for the infrastructure on which CM-Connect runs under clause 5.7.

11.3 CM engages subprocessors identified in the Subprocessor List. Notification of changes and the Customer's right to object are governed by the Data Processing Agreement.

11.4 Content is hosted in the region stated in the Service Order and, where none is stated, in a region within the European Union (Standard: Germany, Frankfurt).

11.5 Certifications and attestations held by CM's hosting provider relate to infrastructure operated by that provider and do not evidence CM's own certification. CM holds ISO/IEC 27001:2022 certification in respect of its information security management system.

11.6 CM does not represent that Content is beyond the reach of a lawful access request made to CM or a subprocessor by a public authority. On receipt of a request affecting Content, CM will, so far as lawfully permitted, notify the Customer, challenge a request that appears unlawful or excessive where appropriate, and disclose only what CM is legally required to disclose.

11.7 Audit. The Customer may verify CM's compliance with the applicable CM Security Commitments and its obligations under the Data Processing Agreement by written questionnaire and review of relevant reports and certifications. Except where a greater audit or verification right is required by the Data Processing Agreement, applicable law or a competent supervisory authority, or where additional verification is reasonably required following a material security or data protection incident, Customer-initiated verification may be exercised once in any twelve-month period on reasonable advance notice.

12. Warranties

12.1 CM undertakes that the services will be performed substantially in accordance with the applicable Service Order, these Terms, the applicable CM Security Commitments and Service Level Agreement, and with reasonable skill and care.

12.2 CM warrants that it holds and will maintain the licenses, consents and permissions necessary to perform its obligations under these Terms and the applicable Service Order and that it has the right to make the Platform available.

12.3 The undertaking in clause 12.1 does not apply to a non-conformity caused by use contrary to CM's instructions or Documentation, or by modification of the services by a person other than CM or a person authorized by CM.

12.4 Remedy for service non-conformity. Where the services do not conform to clause 12.1, CM will at its own expense use reasonable commercial efforts promptly to correct the non-conformity or provide an alternative means of achieving the intended performance. That correction or alternative is the Customer's remedy for the functional service non-conformity itself. It does not limit remedies arising from a separate breach of the CM Security Commitments, Data Processing Agreement, Business Associate Agreement or another independently applicable obligation.

12.5 Loss of Content. In the event of loss of or damage to Content, CM will use reasonable commercial efforts to restore affected Content from an available backup maintained by CM where restoration is technically possible. This clause does not limit liability arising from a separate breach of CM's obligations under the CM Security Commitments, Master Services Agreement, Service Orders, Data Processing Agreement, Business Associate Agreement or applicable law. CM remains responsible for subprocessors as provided in the Data Processing Agreement and these Terms.

12.6 The Customer, and not CM, is responsible for the results obtained from its use of the Platform and for conclusions it draws from that use. CM is not responsible for loss to the extent caused by inaccurate or incomplete information, instructions, configurations or scripts supplied by the Customer or action taken by CM on the Customer's documented instructions.

12.7 CM is not responsible for delay, unavailability, degradation or failure of the services to the extent caused by the Customer's systems, devices, local network or internet connectivity, or by telecommunications networks, internet service providers or other systems outside CM's reasonable control

12.8 Nothing in these Terms prevents CM from entering into similar agreements with other parties or independently developing, using, selling or licensing products or services similar to those provided under these Terms, provided that CM complies with clause 13 and its confidentiality and data protection obligations.

12.9 Warranties not given. Except to the extent expressly stated in an applicable Service Order, CM does not warrant that: Content is anonymous or has ceased to be personal data; data protection law no longer applies to Content; identification is impossible or the risk of identification is zero; a transformation removes every item from which an individual could be identified; the controls in clause 6 will detect every instance of Non-Conforming Content; an identifiability conclusion will remain valid over time or apply in another environment; a trained model contains no information derived from its training data; Content is De-identified under 45 CFR 164.514(b) or outside HIPAA; compliance with the GDPR constitutes compliance with HIPAA or vice versa; Content supplied by a user is accurate or clinically correct; use of the Platform will be uninterrupted or error-free; or the Platform is free from all vulnerabilities or malicious code.

12.10 Except as expressly stated in these Terms, the applicable Service Order, CM Security Commitments, Service Level Agreement, Data Processing Agreement or Business Associate Agreement, the Platform and Documentation are provided on an "as is" basis to the maximum extent permitted by law.

12.11 No statement made in a proposal, presentation, questionnaire response or other communication constitutes a warranty or representation unless expressly stated as such in these Terms, a Service Order, or another document signed or accepted by CM as containing that warranty or representation. This clause does not exclude liability for fraudulent misrepresentation.

12.12 Except as expressly stated in these Terms or an applicable Service Order, warranties, conditions and terms implied by law are excluded to the maximum extent permitted by applicable law.

13. Content, Ownership, Intellectual Property, Results and machine learning

13.1 Content. Ownership of Content remains with the person or organization entitled to it under the arrangements applicable to the relevant Project. Nothing in these Terms transfers ownership of Content to CM.

13.2 Results. Results belong to the Customer or such other person as the Customer's applicable arrangements provide. CM claims no ownership of or share in the exploitation of Results.

13.3 Export and portability. Export of Results is subject to clause 8. Export of Content is permitted only to the extent clause 8, the applicable Service Order and applicable data protection documentation allow. Return of Content on termination is governed by clause 15.4 and the Data Processing Agreement. Where CM provides an export, it will use a structured, commonly used and machine-readable format where reasonably available.

13.4 CM does not restrict publication of Results. Clause 8.3 governs what a publication must not contain. CM does not require sight of approval of or attribution in a publication unless expressly agreed for a specific service.

13.5 Consortiums. Where a Project is conducted by a consortium, ownership, access, publication and exploitation between participants are governed by the Consortium Agreement or equivalent applicable policy and any applicable consortium agreement. The Research Consortium Policy regulates this in more detail.

13.6 Operating right. The Customer grants CM a non-exclusive right to host, store, copy, transmit, render, index and otherwise process Content solely to the extent necessary to provide the services, comply with lawful instructions and perform CM's obligations. CM may exercise that right through CM Group companies and subprocessors engaged consistently with the Data Processing Agreement.

13.7 The right in clause 13.6 does not permit CM to publish Content, use Content for marketing, license Content for an independent purpose, or disclose Content to a person not entitled to receive it. This does not prevent disclosure to CM Group companies, subprocessors or other service providers solely to the extent necessary to provide the services and subject to applicable confidentiality and data protection obligations.

13.8 CM may use Content in marketing or promotional material only with written consent identifying the material and intended use. A general consent is not sufficient and may be withdrawn prospectively.

13.9 Machine learning by CM. CM will not use Content to develop, train, fine-tune, validate or evaluate a machine learning model for CM's own purposes, will not retain Content or a representation derived from Content in the parameters of a model for CM's own purposes, and will not sell, license or make Content available to another person for those purposes, except as clause 13.10 expressly permits.

13.10 Clause 13.9 does not prevent processing necessary to provide the services, operate security and ingestion controls, prevent abuse, or operate a model within a Customer's Project at the instruction of the Customer or other person entitled to instruct CM. Where such processing involves training or adaptation on Content, it must fall within the agreed Project purpose and applicable Service Order.

13.11 Machine learning by the Customer. The Customer may develop, train, fine-tune, validate and evaluate models on Content within its own Project where it is entitled to use that Content for that purpose. Clause 8.5 applies to a model leaving the Project.

13.12 Clause 13.9 is a material term for the purposes of clause 15.3.

13.13 CM owns the Platform and all rights in it other than rights in third-party components. The Customer receives no right in the Platform other than the right to use it under these Terms. CM may use feedback provided by the Customer without acquiring any right in Content or Results.

13.14 CM may generate and use aggregated statistics concerning use and performance of the Platform where those statistics contain no Content and do not identify a Customer, Authorized User, Session Viewer, patient or participant.

14. Fees

14.1 Fees, plan, billing period and limits are stated in the applicable Service Order. Limits apply in aggregate across the Customer unless the Service Order provides otherwise.

14.2 Where usage exceeds a contractual limit, and the Service Order provides an overage rate, the applicable overage charge may be invoiced at that rate.

14.3 Before invoicing an overage charge, CM will notify the Customer's administrator and give the Customer a reasonable opportunity to address the excess where the nature of the service permits it.

14.4 CM may introduce a new category of usage metric for a future renewal term on at least sixty days' notice before the end of the then-current term. The Customer may elect not to renew before the new metric takes effect.

14.5 Invoices are generally payable within thirty days of the invoice date unless the Service Order provides otherwise. CM may suspend access for an overdue invoice after giving reasonable written notice. Suspension does not relieve the Customer of the obligation to pay. Fees are exclusive of applicable taxes and duties.

15. Term, suspension and termination

15.1 The term is stated in the Service Order. Unless the Service Order provides otherwise, an institutional subscription has a term of twelve months and renews for successive twelve-month terms unless either party gives notice not to renew at least thirty days before the end of the then-current term.

15.2 CM may suspend access, in whole or in part, immediately where it reasonably believes that Non-Conforming Content has been uploaded, clause 3 has been breached, continued access presents a material risk to Content or the Platform, or continued access would cause either party to act unlawfully. CM will notify the Customer promptly where legally and operationally practicable and restore access when the ground for suspension has been resolved.

15.3 Either party may terminate for material breach not remedied within thirty days after written notice where the breach is capable of remedy. A breach identified in clause 3.15 may be treated as incapable of remedy where its nature justifies immediate termination.

15.4 Return and deletion. On termination, return or deletion of personal data is governed by the Data Processing Agreement and, where applicable, the Business Associate Agreement. CM will follow the Customer's documented instruction and any retention expressly agreed in the applicable Service Order, subject to applicable law. A return required under this clause or the Data Processing Agreement is not prohibited by clause 8.

Note. Article 28(3)(g) GDPR requires the processor, at the controller's choice, to delete or return personal data after the end of the provision of services unless applicable law requires storage. The Data Processing Agreement prevails on that matter.

15.5 Where Content has been removed from the Platform under a permission that requires its return or destruction, the Customer must comply with that requirement on termination.

15.6 Where an Authorized User is deactivated, the Customer administrator may direct that Content in that person's private area be transferred to another Authorized User, transferred to the Customer administrator or deleted. CM will not treat deactivation of the individual as authority to delete Customer Content unless the Customer so instructs.

15.7 Clauses 3.14, 5.17 to 5.19, 6.4, 6.5, 8, 12, 13, 16, 17, 20, 22 and 23, and any provision which by its nature is intended to survive, survive termination.

16. Liability and indemnities

16.1 Subject to clause 16.2, neither party is liable for loss of profit, revenue, anticipated saving, business or goodwill, or for indirect or consequential loss.

16.2 Customer liabilities not excluded. Clause 16.1 does not limit or exclude the Customer's liability for death or personal injury caused by its negligence or the negligence of its Authorized Users, fraud or fraudulent misrepresentation, gross negligence or willful misconduct, the Customer's obligation to pay Fees, or any liability of the Customer that cannot lawfully be limited or excluded. The Customer remains responsible for its Authorized Users as provided in clause 4.4. Nothing in these Terms excludes or limits any liability of the parties that cannot lawfully be excluded or limited.

16.3 Customer indemnity. To the extent permitted by law, the Customer will indemnify CM against a third-party claim, lawfully recoverable regulatory fine, loss, cost or expense to the extent arising from: Non-Conforming Content uploaded by the Customer or its Authorized Users; breach of clause 3 by the Customer or its Authorized Users; absence of the legal authority required for Content uploaded or instructions given; or a third-party claim that Content supplied by the Customer infringes that person's rights. The indemnity does not apply to the extent the claim, fine, loss, cost or expense was caused or contributed to by CM's breach of these Terms, the Data Processing Agreement, Business Associate Agreement or applicable law. The Customer will also reimburse reasonable and documented incident-response costs actually incurred by CM to the extent caused by a matter for which the Customer is responsible under this clause.

16.4 CM intellectual property indemnity. CM will indemnify the Customer against a third-party claim that the Platform, as provided by CM and used in accordance with these Terms, infringes that third party's intellectual property rights. This does not apply to a claim arising from Content or Results, a modification not made or authorized by CM, or use outside these Terms. CM may, at its option, obtain the right for continued use, modify or replace the affected element with a substantially equivalent non-infringing element, or terminate the affected service and refund prepaid Fees attributable to the unused terminated period.

16.5 Time limit for contractual claims. A party asserting a contractual claim must notify the other in writing, identifying the event and grounds in reasonable detail, within six months after it became or reasonably should have become aware of the event, and commence proceedings within one year after that date. For a third-party indemnity claim, the notification period starts when the indemnified party receives or becomes aware of that claim. This clause does not apply to liability within clause 16.2 or where mandatory law provides otherwise.

16.6 Indemnity procedure. An indemnity is conditional on the indemnified party notifying the other promptly, not admitting liability or settling without consent, and providing reasonable cooperation. Control of a defense by the indemnifying party applies only to the extent legally permissible and must not prevent the indemnified party from complying with an obligation to a court, regulator, supervisory authority or other competent authority. Each party must take reasonable steps to mitigate loss.

17. Enforcement

17.1 Where CM reasonably believes these Terms have been breached, it may take one or more proportionate steps, in any order and without first exhausting another remedy.

Step Trigger
Requirement to remediate by a stated date A breach capable of remedy
Restriction of an individual account Breach by an identified individual
Immediate suspension A ground in clause 15.2
Invalidation of access links or codes Non-Conforming Content has been released or access credentials have been compromised
Prevention of an export An export contrary to clause 8
Termination for cause A ground in clause 15.3
Recovery of costs A matter within clause 16.3
Notification to the Customer A breach by an Authorized User
Report to a professional or supervisory body Conduct that reasonably appears to constitute a serious breach of professional obligations or applicable law. Regarding Privacy and Data Protection, when acting as Processor, no communication is directly made to the supervisory body unless expressly agreed and/or required by law.
Injunctive relief A threatened or continuing breach of a provision identified in clause 3.15


17.2
Before making a report to a professional or supervisory body, CM will consider whether a less intrusive step would adequately address the matter, record its reasons, and inform the individual concerned unless doing so would prejudice an investigation, contravene law or place data at further risk.

17.3 Records. CM records information reasonably necessary to establish relevant activity on the Platform, including who uploaded Content and when, the version of contractual text accepted where recorded, the outcome of applicable controls, Release State changes, exports and access events. CM may rely on those records in support of enforcement or compliance activity.

17.4 The Customer must cooperate with a reasonable investigation by CM into a suspected breach affecting patient or participant data and provide information within its control reasonably required for that investigation. This does not require disclosure of additional identifying information to CM unless lawfully necessary.

17.5 Nothing in this clause limits obligations imposed directly by applicable law, the Data Processing Agreement, Business Associate Agreement, or a competent supervisory or regulatory authority.

18. Compliance with laws

18.1 Each party will comply with laws applicable to it in connection with these Terms.

18.2 Export control and sanctions. Each party will comply with applicable export-control and sanctions laws. The Customer must not knowingly permit access to the Platform where doing so would breach those laws.

18.3 Anti-bribery. Each party will comply with applicable anti-bribery and anti-corruption laws and will not offer or accept an improper payment or advantage in connection with these Terms.

18.4 Approvals and regulatory responsibilities. The Customer must ensure that the authorizations, permits, approvals and ethics opinions required for its use of the Platform are in place and that it is authorized to instruct CM in reliance on them. Where the Customer acts as processor on behalf of another controller, this does not transfer to the Customer a responsibility that applicable law assigns to the controller, sponsor or another party. CM is responsible for regulatory requirements applicable to CM in providing the Platform and for the matters expressly allocated to CM under clause 9.

Legal basis and permitted use

18.5 Lawful processing. The Customer must ensure that processing it initiates or instructs on the Platform is lawfully authorized for each Project and purpose. Where the Customer acts as controller, it is responsible for determining, documenting and being able to demonstrate the applicable Article 6 GDPR basis and, for Health Data, the applicable Article 9 GDPR condition. Where the Customer acts as processor on behalf of another controller, the Customer must be authorized to instruct CM and must ensure that its instructions are consistent with its obligations to that controller. Where HIPAA applies, the Customer is responsible for ensuring that the relevant use or disclosure is permitted under HIPAA or supported by any authorization required by HIPAA. CM does not select or verify the Customer's legal basis merely by accepting Content.

18.6 Illustrative common legal frameworks. The table below is provided solely for general orientation and is not exhaustive. It does not determine, establish or confirm the legal basis, Article 9 condition, HIPAA permission, authorization, waiver or other legal requirement applicable to any particular Project or use of the Platform. The Customer and, where different, the relevant controller remain responsible under clause 18.5 for determining and documenting the applicable legal basis and other legal requirements. CM does not select, determine or verify those requirements merely because a use case is described below.

Use of the Platform GDPR HIPAA where applicable
Clinical Trial The applicable Article 6 basis and Article 9 condition depend on the controller's role, the purpose of the processing and applicable Union and Member State law. Depending on the circumstances, Article 6(1)(c), (e) or (f), and Article 9(2)(i) or (j), may be relevant where their respective requirements are met. Informed consent to participate in a Clinical Trial is distinct from the GDPR legal basis for processing personal data and does not by itself establish that basis. Depending on the circumstances, a HIPAA authorization, a waiver or alteration of authorization under 45 CFR 164.512(i), or the use or disclosure of a Limited Data Set under 45 CFR 164.514(e) with an appropriate data use agreement may be relevant.
Consultation or second opinion The controller must determine the applicable Article 6 basis. Article 9(2)(h), read together with Article 9(3), may be relevant where the processing is necessary for medical diagnosis, the provision of healthcare or another purpose falling within that provision and its requirements are met. Disclosure of Protected Health Information to another healthcare provider for treatment may be permitted under 45 CFR 164.506(c)(2), subject to the applicable requirements of HIPAA.
Research outside a Clinical Trial The controller must determine the applicable Article 6 basis and Article 9 condition. Article 9(2)(j) may be relevant where the processing is necessary for scientific research in accordance with applicable Union or Member State law and the safeguards required by Article 89(1) are satisfied. Other bases or conditions may apply depending on the circumstances. Depending on the circumstances, a HIPAA authorization, a waiver or alteration under 45 CFR 164.512(i), or the use or disclosure of a Limited Data Set under 45 CFR 164.514(e) with an appropriate data use agreement may be relevant.
Teaching and professional education The applicable Article 6 basis and Article 9 condition must be determined specifically for the teaching use. Article 9(2)(a) may be relevant where valid explicit consent has been obtained. In limited circumstances, Article 9(2)(h), read together with Article 9(3), may be relevant where the teaching activity forms part of healthcare provision or another activity falling within that provision and all applicable requirements are met. A legal basis or Article 9 condition applicable to research does not by itself authorize a teaching use. Certain supervised healthcare training activities may qualify as healthcare operations under 45 CFR 164.501 and may be permitted under 45 CFR 164.506. Other teaching uses may require an authorization or another applicable HIPAA permission.


18.7 GDPR and HIPAA are not interchangeable.
Valid De-identification under 45 CFR 164.514(b) takes information outside HIPAA but does not by itself establish that information is anonymous under the GDPR. A Limited Data Set remains Protected Health Information under HIPAA, and its status under the GDPR must be assessed independently. Pseudonymized data remain personal data where the GDPR applies. Compliance with one regime does not establish compliance with the other.

18.8 Where CM is a business associate. Where the Customer is a Covered Entity, or a business associate acting on behalf of one, and CM processes Protected Health Information on its behalf, the parties must have a Business Associate Agreement in place before that Protected Health Information is uploaded. The Business Associate Agreement governs matters required by HIPAA and prevails on those matters.

18.9 Vulnerability reporting. A vulnerability affecting the Platform should be reported to CM with sufficient detail to allow investigation. A reporter must not access, alter, copy or disclose data belonging to another person and must not disclose the vulnerability publicly before CM has had a reasonable opportunity to address it. CM will not pursue a person who reports a vulnerability in good faith within those limits.

19. Evaluation features, components and APIs

19.1 Evaluation features. A feature identified as beta, preview, pilot or evaluation is provided on an evaluation basis, may be modified or withdrawn, and is excluded from the functional undertaking in clause 12.1 and from the Service Level Agreement unless otherwise stated. Health Data may be used with an evaluation feature only where the Service Order expressly permits it. Where Health Data is permitted, the CM Security Commitments, Data Processing Agreement and Business Associate Agreement continue to apply according to their terms.

19.2 Third-party and open-source components. The Platform incorporates third-party and open-source components. License terms applicable to a component apply to the extent legally required. They do not reduce CM's obligations under the Data Processing Agreement, Business Associate Agreement, CM Security Commitments, or confidentiality provisions unless expressly agreed with the Customer to the extent legally permissible. Clause 9 governs the Viewer.

19.3 Interfaces. Where CM makes an application programming interface available, it must be used in accordance with its Documentation and applicable rate limits. CM may modify an interface on reasonable notice and will provide a reasonable transition period for a materially non-backward-compatible change where practicable.

19.4 Non-production environments. A sandbox, test or training environment must not contain Health Data relating to an identifiable individual unless the applicable Service Order expressly permits it. Where Health Data is expressly permitted, applicable security, data protection and Business Associate Agreement obligations continue to apply.

20. Confidentiality and publicity

20.1 Each party will keep confidential the other's non-public information disclosed in connection with these Terms, use it only for purposes connected with these Terms, and disclose it only to Affiliates, personnel, contractors, subprocessors, professional advisers and service providers who need it for those purposes and are subject to appropriate confidentiality obligations. This does not apply to information that becomes public without breach, was lawfully known without an obligation of confidence, is independently developed, or must be disclosed by law or a competent authority. Where lawfully permitted, the disclosing party will give appropriate notice of a compelled disclosure.

20.2 Confidentiality obligations concerning Content are additional to, and do not replace, clause 3 or the Data Processing Agreement. A contractual permission to disclose is not itself a GDPR legal basis.

20.3 Publicity. Neither party may use the other's name, logo or trademarks in publicity without prior written consent. Consent to identify the Customer as a customer may be given in a Service Order and may be withdrawn prospectively on reasonable notice. No consent to publicity extends to Content.

21. Changes to these Terms

21.1 CM may amend these Terms. Where an amendment is material and adverse to the Customer, CM will give at least sixty days' notice and, for an institutional subscription, the amendment will take effect at the start of the next renewal term. An amendment required by law or reasonably necessary to address a security or safety risk may take effect on shorter notice where the circumstances require.

21.2 CM will notify the Customer's administrator and publish the amended Terms with a revision or effective date. Superseded versions are available on request.

21.3 Where a material and adverse amendment is not required by law or an urgent security or safety risk, the Customer may elect not to renew before it takes effect.

21.4 Data Specification changes. A more demanding Data Specification applies prospectively to Content uploaded after its effective date unless the applicable Service Order expressly provides that existing Content must be reprocessed.

22. General

22.1 Assignment. The Customer may not assign or transfer these Terms without CM's written consent, not to be unreasonably withheld in connection with a legitimate corporate reorganization. CM may assign or transfer its rights and obligations to a CM Group company or in connection with a merger, reorganization or sale of the relevant business or assets, provided the assignee assumes CM's applicable obligations.

22.2 Force majeure. Neither party is liable for failure to perform caused by an event beyond its reasonable control, provided it takes reasonable steps to mitigate and resume performance. This does not apply to an obligation to pay amounts already due.

22.3 Notices. Contractual notices must be in writing. Notices to CM may be sent to its registered address and the address published for legal notices. Notices to the Customer may be sent to the administrator contact recorded for the Customer.

22.4 If a provision is invalid or unenforceable, it will be read down to the minimum extent necessary where legally possible and the remaining provisions continue in force. Failure or delay in enforcing a provision is not a waiver.

22.5 Entire agreement. These Terms together with the contract documents identified in clause 24 constitute the agreement between the parties on their subject matter and supersede prior understandings on that subject matter. This does not exclude liability for fraudulent misrepresentation.

22.6 Authorized Users and Session Viewers. An Authorized User or Session Viewer does not acquire the Customer's commercial rights under these Terms and is not responsible for Customer Fees or other commercial obligations. CM may enforce directly against an Authorized User or Session Viewer the provisions of these Terms and the applicable Additional Policy that expressly impose obligations on that person and that the person has accepted in accordance with clause 1.8.

22.7 The parties are independent contractors. Nothing in these Terms creates a partnership, employment relationship or general agency between them. An individual's authority to act for a controller under the Individual Account Policy is governed by that policy and does not make CM an agent of that controller.

22.8 These Terms are issued in English, and the English version governs unless mandatory law requires otherwise.

23. Governing law and disputes

23.1 These Terms and any dispute or claim arising out of or in connection with them are governed by Swedish law, excluding its conflict-of-laws rules and the United Nations Convention on Contracts for the International Sale of Goods.

23.2 Organizational Customers. For a Customer that is an organization rather than an individual, any dispute, controversy or claim arising out of or in connection with these Terms, or the breach, termination or invalidity thereof, shall be finally settled by arbitration in accordance with the Arbitration Rules of the SCC Arbitration Institute. The seat of arbitration shall be Stockholm, Sweden. The language of the arbitration shall be English. Either party may seek interim or injunctive relief from a competent court.

23.3 Individuals. For an individual subscriber, Authorized User or Session Viewer, the courts of Sweden have jurisdiction, with Stockholm District Court as the court of first instance, except to the extent mandatory law provides otherwise. Where such person acts as a consumer, nothing in these Terms deprives that person of mandatory protections or jurisdictional rights applicable in their country of habitual residence.

23.4 Nothing in this clause prevents a person from making a complaint to or cooperating with a competent supervisory or regulatory authority.

24. Contract documents

24.1 The Data Processing Agreement and, where applicable, the Business Associate Agreement prevail over every other contract document on matters concerning processing of personal data or Protected Health Information, respectively.

24.2 Summary of contractual obligations and documents:

Document Subject matter
Service Order Services, Project purpose, controller and sponsor identification, approvals, Lead Party, plan, limits, Fees, term, hosting region, retention and expressly agreed variations
Project record Operational Project configuration, participants, Release States, permitted purposes and Project facts authorized by the Service Order. A Project record does not amend Fees, liability, warranties, term or other commercial terms unless the Service Order expressly authorizes it.
Consortium agreement, where one exists Ownership of and access to Content and Results, publication and exploitation as between consortium participants. CM is bound by a consortium agreement only to the extent CM expressly agrees to a provision or the applicable Service Order or Project record requires CM to implement an authorized configuration.
Signed master agreement, where one exists The general negotiated commercial relationship and negotiated variations
Terms of Service General Terms applicable to all matters within their scope.
Data Specification and CM-Connect rule specification Content requirements and agreed technical treatment or configuration
Service Level Agreement and Acceptable Use Policy Service levels, support and detailed conduct rules within their respective subject matter
Intended Purpose/Use Intended purpose and information concerning the Platform and Viewer

24.3 The Privacy Policy/Notice and Cookie Policy are addressed to individuals and are not contract documents. The terms of use of the public CM website govern that website only.

25. Additional policies

These policies apply in addition to the General Terms, depending on your role.

If this describes you Then you are also covered by
A hospital, clinic, university, academic medical center or other research institution holds the account Hospitals, Clinics and Universities Policy
A biotech or pharmaceutical company, a contract research organization, or a medical device or software company holds the account Biotech, Pharma, CRO and MedTech Policy
You hold an account in your own name rather than through an organization Individual Account Policy
You use the Platform for a clinical trial Clinical Trials Policy
You use the Platform for research that is not a clinical trial Research Services Policy
You use the Platform for teaching, courses, conferences or examination Education and Teaching Policy
Two or more organizations run a Project together in a research consortium Research Consortium Policy
Your organization gave you access and you do not hold the account Authorized User Terms
You are shown material in a teaching session and have no account Session Viewer Terms

More than one may apply to you at the same time. The applicable policy is set out below.

Hospitals, Clinics and Universities Policy

Biotech, Pharma, CRO and MedTech Policy

Individual Account Policy

Clinical Trials Policy

Research Services Policy

Education and Teaching Policy

Research Consortium Policy

Authorized User Terms

Session Viewer Terms