Master SaaS Agreement (MSA) / Terms of Service
Effective Date: August 13, 2026
Version: 1.0
Operator: ARYX LLC (aryx.pro). The contracting party named on an Order Form controls for that transaction.
This Master SaaS Agreement (this "Agreement") is entered into by and between ARYX LLC, a limited liability company organized under the laws of the United States ("ARYX", "we", "us"), and the customer entity identified on an Order Form ("Customer", "Tenant", "you"). This Agreement governs Customer's access to and use of the ARYX platform and related services (the "Services"). By executing an Order Form, clicking to accept, or accessing or using the Services, Customer agrees to be bound by this Agreement as of August 13, 2026 (the "Effective Date").
ARYX operates a multi-tenant, business-to-business software-as-a-service platform for health-plan enrollment, administration, and billing. ARYX is a software and workflow-orchestration provider only. ARYX is not a bank, card network, payment processor, money transmitter, merchant of record, insurer, health plan, or third-party administrator. The responsibility boundaries in Sections 9, 11, and 12 are material to this Agreement and to the pricing of the Services.
1. Definitions
Capitalized terms have the meanings given below or where first defined in this Agreement.
1.1 "ARYX" means ARYX LLC and its permitted successors and assigns.
1.2 "Services" means the ARYX platform applications and functionality made available under an Order Form, which may include: EnrollFlow (member enrollment, which processes PHI and initiates and schedules payment activity); ARYX CRM (lead and member relationship management for Tenant staff); ARYX Accounts (identity, single sign-on, org/tenant provisioning, and the subscription/billing engine at aryx.pro / app.aryx.pro); AdvisorIQ; and the IT Ticketing / Support application, together with related APIs, documentation, and updates.
1.3 "Order Form" means an ordering document, online sign-up, or subscription record executed or accepted by the parties that references this Agreement and specifies the Services, subscription tier/bundle, term, fees, and quantities.
1.4 "Authorized User" means an individual (such as Tenant staff, an agent, broker, or administrator) whom Customer authorizes to access the Services under Customer's account, and for whose acts and omissions Customer is responsible.
1.5 "Member" means an end-user enrollee, applicant, or beneficiary whose information is submitted to or processed within the Services by or on behalf of Customer.
1.6 "Member Data" means data submitted to, stored in, or processed by the Services by or on behalf of Customer or its Authorized Users or Members, including member PII, enrollment data, and financial/transaction data, but excluding ARYX Technology and aggregated/de-identified data.
1.7 "PHI" means Protected Health Information as defined under the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations ("HIPAA"), to the extent processed within the Services (primarily via EnrollFlow).
1.8 "Processor" means Authorize.Net, the third-party payment gateway used in connection with the Services, and any acquiring bank, card network, or issuing bank in the payment chain.
1.9 "Subprocessor" means a third party engaged by ARYX to process Member Data in connection with delivering the Services, as further described in Section 8 and the DPA. Current Subprocessors include Supabase (database/auth/storage), Vercel (hosting), Authorize.Net (payments), Resend (email), and GoTo (SMS/voice).
1.10 "ARYX Technology" means the Services, the underlying software, models, algorithms, user interfaces, APIs, documentation, and all improvements, and all Intellectual Property Rights therein.
1.11 "Intellectual Property Rights" means all patent, copyright, trademark, trade secret, and other intellectual property or proprietary rights worldwide.
1.12 "Confidential Information" has the meaning in Section 7.
1.13 "Framework Documents" means this Agreement together with the sibling policy and contract documents referenced herein, including the Data Processing Agreement (/legal/dpa), Business Associate Agreement (/legal/baa), Service Level Agreement (/legal/sla), fee/billing terms (/legal/billing, /legal/billing), the payment-responsibility disclosure (/legal/funds-flow), refund/settlement policy (ARYX's refund and settlement standards (see also /legal/billing)), third-party dependency disclaimer (ARYX's third-party dependency standards), and data export/retention terms (ARYX's data ownership and retention terms). Exact titles and numbering are subject to the order-of-precedence clause in Section 18.
2. The Services and Order Forms
2.1 Provision of Services. Subject to this Agreement, ARYX will make the Services described in each applicable Order Form available to Customer during the Subscription Term for Customer's internal business purposes.
2.2 Order Forms. Each Order Form is incorporated into and governed by this Agreement. In the event of conflict between an Order Form and the body of this Agreement, the Order Form controls for that transaction only, subject to Section 18.
2.3 Updates. ARYX may modify, enhance, or deprecate features of the Services from time to time, provided that ARYX will not materially degrade the core functionality of a purchased Service during a paid Subscription Term. Beta or early-access features are provided "AS IS" and are excluded from the SLA (/legal/sla).
2.4 Multi-Tenancy. The Services are multi-tenant. Tenant isolation of Member Data is enforced in Postgres via Row-Level Security ("RLS"), org-scoped per Tenant, on Supabase infrastructure. Customer acknowledges that the Services operate on shared infrastructure and agrees not to attempt to access data of any other tenant.
3. Account Provisioning and Authorized Users
3.1 Provisioning. Tenant accounts, organizations, and single sign-on are provisioned through ARYX Accounts. Customer is responsible for designating administrators and for the accuracy of provisioning information.
3.2 Credentials and Security. Customer is responsible for maintaining the confidentiality of account credentials and for all activity occurring under its account and its Authorized Users' credentials, whether or not authorized by Customer. Customer will use commercially reasonable efforts to prevent unauthorized access and will promptly notify ARYX at legal@aryx.pro of any suspected compromise.
3.3 Authorized Users. Customer is responsible for its Authorized Users' compliance with this Agreement. Access is per-named-user unless the Order Form states otherwise; credential sharing is prohibited.
4. License Grant and Restrictions
4.1 License Grant. Subject to this Agreement and payment of applicable Fees, ARYX grants Customer a limited, non-exclusive, non-transferable, non-sublicensable right during the Subscription Term to access and use the Services for Customer's internal business operations and for the benefit of its Members.
4.2 Restrictions. Customer will not, and will not permit any Authorized User or third party to: (a) copy, modify, translate, or create derivative works of the Services or ARYX Technology; (b) reverse engineer, decompile, or attempt to derive source code, except to the extent this restriction is prohibited by law; (c) resell, sublicense, rent, or provide the Services on a service-bureau basis to any party who is not an Authorized User or Member; (d) circumvent RLS, tenant isolation, rate limits, or other technical or security controls; (e) access the Services to build a competing product; (f) upload malicious code or interfere with the integrity or performance of the Services; (g) use the Services in violation of applicable law, card-network rules, or Processor requirements; or (h) submit card Primary Account Numbers ("PAN") or CVV directly to ARYX servers outside the Accept.js tokenization flow described in Section 9.
4.3 Reservation of Rights. All rights not expressly granted are reserved by ARYX and its licensors.
5. Customer / Tenant Obligations
5.1 Lawful Use and Consents. Customer represents and warrants that it has all necessary rights, consents, and authorizations to submit Member Data (including PHI and payment data) to the Services and to authorize ARYX's processing of it for the purposes of the Agreement, the DPA (/legal/dpa), and, where applicable, the BAA (/legal/baa).
5.2 Merchant Account and Processor Relationship. Customer (the Tenant) holds and controls the Authorize.Net merchant account used with the Services. Funds settle Processor → Tenant and do not flow through ARYX. Customer is solely responsible for its merchant agreement, underwriting, chargeback obligations, reserves, and compliance with card-network rules. See Sections 9 and 11 and /legal/funds-flow.
5.3 Regulatory Compliance. Customer is responsible for the regulatory compliance of its own health-plan, insurance, agency/brokerage, or benefit-administration business, including licensing, disclosures to Members, marketing/TCPA compliance for SMS/voice sent via GoTo, and email compliance for communications sent via Resend.
5.4 Content Responsibility. Customer is responsible for the accuracy, quality, and legality of Member Data and of any content, templates, or communications it configures within the Services.
6. Fees and Payment
6.1 Fees. Customer will pay the fees set out in each Order Form and the applicable fee schedules (/legal/billing, /legal/billing) ("Fees"). Except as expressly stated, Fees are non-cancelable and non-refundable.
6.2 Billing Engine. Subscription Fees are billed through the ARYX Accounts billing engine, which uses Authorize.Net CIM stored payment profiles and a schedule-driven recurring charge engine. Customer authorizes ARYX to initiate recurring charges to the payment method on file for the subscription in accordance with the Order Form and /legal/billing.
6.3 Financial-State Disclaimer. The parties acknowledge that a charge or refund is not "completed" or "settled" merely because an API returned an HTTP 200 or because ARYX displays a status. Posting and settlement timing are controlled by the Processor, card networks, and financial institutions and are outside ARYX's control. Charge and refund lifecycle states are governed by ARYX's refund and settlement standards (see also /legal/billing).
6.4 Taxes. Fees are exclusive of taxes. Customer is responsible for all sales, use, VAT, and similar taxes, excluding taxes on ARYX's net income.
6.5 Late Payment. Overdue amounts may accrue interest at 1.5% per month, or the maximum permitted by law, and ARYX may suspend the Services for non-payment per Section 13.
7. Confidentiality
7.1 Definition. "Confidential Information" means non-public information disclosed by one party ("Discloser") to the other ("Recipient") that is designated as confidential or that reasonably should be understood to be confidential, including the Services, ARYX Technology, pricing, security practices, Member Data, and business plans.
7.2 Obligations. Recipient will (a) use Confidential Information only to perform under this Agreement, (b) protect it with at least reasonable care, and (c) not disclose it except to representatives with a need to know who are bound by confidentiality obligations no less protective than these.
7.3 Exclusions. Confidential Information excludes information that is or becomes public without breach, was rightfully known without duty of confidentiality, is independently developed, or is rightfully received from a third party.
7.4 Compelled Disclosure. Recipient may disclose Confidential Information as required by law, provided it gives reasonable prior notice where legally permitted.
7.5 Relationship to Data Protection. Member Data, PHI, and payment data are additionally governed by Section 8, the DPA, and the BAA, which control in the event of conflict with this Section.
8. Data Protection; PHI; Subprocessors
8.1 Data Processing Agreement. ARYX processes Member Data as Customer's processor/service provider under the Data Processing Agreement (/legal/dpa), which is incorporated by reference. The DPA governs privacy obligations, data-subject rights, and international transfers.
8.2 Business Associate Agreement. To the extent EnrollFlow or other Services create, receive, maintain, or transmit PHI on Customer's behalf, the parties will execute the Business Associate Agreement (/legal/baa), which governs HIPAA obligations and controls over this Agreement as to PHI.
8.3 Security. ARYX maintains administrative, technical, and organizational safeguards designed to protect Member Data, including RLS-based tenant isolation, in-browser tokenization of card data, and encryption in transit. Additional detail is set out in the security documentation and the DPA.
8.4 Subprocessors. Customer authorizes ARYX to engage the Subprocessors listed in Section 1.9 and the DPA. ARYX remains responsible for its Subprocessors' performance of the obligations delegated to them.
8.5 Aggregated/De-Identified Data. ARYX may collect and use aggregated and de-identified data (that does not identify Customer, any Member, or any individual) to operate, improve, and secure the Services, subject to the DPA and, where applicable, HIPAA de-identification standards.
9. Payments Architecture and Responsibility Boundaries
9.1 Software Orchestration Only. ARYX provides software that initiates and schedules payment activity on Customer's behalf through the Processor. ARYX does not hold funds, is not a party to the payment transaction between the Member and the Tenant, and does not act as merchant of record.
9.2 Tokenization; PCI Posture. Card data is tokenized in-browser via Authorize.Net Accept.js (opaqueData). PAN and CVV are designed never to reach ARYX servers or database, supporting a PCI-DSS SAQ-A posture. Recurring charges use Authorize.Net CIM stored payment profiles and ARYX's schedule-driven charge engine (not gateway-native ARB). Customer remains responsible for its own PCI obligations as a merchant.
9.3 Webhooks. Inbound Authorize.Net webhooks are (to be) verified via Processor-specified signature verification to authenticate payment event notifications.
9.4 Chain of Responsibility. Customer acknowledges the distinct roles and responsibilities of ARYX (software/orchestration), the Tenant (merchant of record, holder of the Authorize.Net account), the Processor/gateway, the acquiring bank, the card networks, and the issuing banks. ARYX is not responsible for the acts, omissions, availability, decisions (including authorization declines, holds, or settlement timing), fees, or rule changes of the Processor, acquiring bank, card networks, or issuing banks. See /legal/funds-flow and ARYX's refund and settlement standards (see also /legal/billing).
10. Intellectual Property Ownership
10.1 ARYX Technology. As between the parties, ARYX and its licensors own all right, title, and interest in and to the ARYX Technology and all Intellectual Property Rights therein.
10.2 Customer Data. As between the parties, Customer owns all right, title, and interest in and to Member Data. Customer grants ARYX a non-exclusive, worldwide license to host, copy, process, transmit, and display Member Data solely to provide and support the Services and as permitted by the DPA/BAA.
10.3 Feedback. Customer grants ARYX a perpetual, irrevocable, royalty-free license to use any feedback or suggestions about the Services without restriction or obligation.
11. Warranties and Disclaimers
11.1 Mutual Authority. Each party warrants that it has the legal power and authority to enter into this Agreement.
11.2 Limited Services Warranty. ARYX warrants that the Services will perform materially in accordance with the applicable documentation. Customer's exclusive remedy for breach of this warranty is ARYX's re-performance or, if ARYX cannot materially correct the non-conformity, termination of the affected Service and a pro-rata refund of prepaid, unused Fees for that Service.
11.3 DISCLAIMER. EXCEPT AS EXPRESSLY STATED, THE SERVICES ARE PROVIDED "AS IS" AND "AS AVAILABLE", AND ARYX DISCLAIMS ALL OTHER WARRANTIES, EXPRESS, IMPLIED, OR STATUTORY, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT. ARYX DOES NOT WARRANT THAT THE SERVICES WILL BE UNINTERRUPTED, ERROR-FREE, OR SECURE, OR THAT ANY CHARGE, REFUND, OR SETTLEMENT WILL BE PROCESSED, POSTED, OR SETTLED WITHIN ANY PARTICULAR TIME. ARYX IS NOT A BANK, CARD NETWORK, PAYMENT PROCESSOR, MONEY TRANSMITTER, MERCHANT OF RECORD, INSURER, OR HEALTH PLAN, AND MAKES NO WARRANTY REGARDING THE ACTS OR OMISSIONS OF ANY PROCESSOR, BANK, CARD NETWORK, OR THIRD-PARTY DEPENDENCY (SEE SECTIONS 9 AND 14 AND /legal/funds-flow).
12. Limitation of Liability
12.1 Exclusion of Indirect Damages. To the maximum extent permitted by law, neither party will be liable for any indirect, incidental, special, consequential, exemplary, or punitive damages, or for lost profits, revenue, goodwill, or data, arising out of or related to this Agreement, even if advised of the possibility.
12.2 Liability Cap. Except for the Excluded Claims in Section 12.3, each party's aggregate liability arising out of or related to this Agreement will not exceed the total Fees paid or payable by Customer to ARYX under the applicable Order Form(s) during the twelve (12) months preceding the event giving rise to the claim.
12.3 Exclusions from Cap. The limitations in Section 12.2 do not apply to: (a) Customer's payment obligations; (b) either party's indemnification obligations under Section 13; (c) Customer's breach of the license restrictions in Section 4.2 or of Section 5.2; or (d) a party's liability for its own gross negligence, willful misconduct, or, where applicable, breach of confidentiality or data-protection obligations, which may be subject to a separate super-cap — for counsel decision. Nothing limits liability that cannot be limited by law.
12.4 Allocation of Risk. The parties agree that the limitations in this Section reflect an agreed allocation of risk and are a fundamental basis of the bargain.
13. Indemnification
13.1 By ARYX. ARYX will defend Customer against any third-party claim alleging that the Services, as provided by ARYX and used in accordance with this Agreement, infringe such third party's Intellectual Property Rights, and will indemnify Customer for damages finally awarded or agreed in settlement. ARYX has no obligation for claims arising from Member Data, Customer's configurations, combinations with non-ARYX products, or use in violation of this Agreement.
13.2 By Customer. Customer will defend and indemnify ARYX against any third-party claim arising from or relating to: (a) Member Data and Customer content, including claims that it infringes rights or violates law; (b) disputes with or by Members or other end users, including enrollment, coverage, billing, and communications disputes; (c) chargebacks, payment disputes, refunds, reversals, and any acquiring-bank, card-network, or Processor claims or fines relating to Customer's transactions; (d) Customer's breach of Section 5 or of applicable law (including HIPAA obligations for which Customer is responsible, TCPA, and card-network rules); and (e) Customer's or its Authorized Users' unauthorized use of the Services.
13.3 Procedure. The indemnified party will give prompt notice, tender control of the defense (with the indemnifying party not settling in a way that imposes obligations on the indemnified party without consent), and provide reasonable cooperation.
14. Third-Party Dependencies
14.1 The Services depend on third-party platforms and services, including Supabase, Vercel, Authorize.Net, Resend, and GoTo. ARYX does not control and is not responsible for the availability, performance, security, pricing, terms, or acts/omissions of these third parties. Interruptions or changes by a third-party dependency may affect the Services and are addressed in ARYX's third-party dependency standards and excluded from ARYX's SLA obligations to the extent set out in /legal/sla.
15. Service Levels
15.1 ARYX will provide the Services in accordance with the Service Level Agreement (/legal/sla), which sets out uptime commitments 99.9%, support response targets, and service-credit remedies. Service credits are Customer's sole and exclusive remedy for failure to meet the SLA, except where the SLA expressly provides a termination right.
16. Suspension and Termination
16.1 Term. This Agreement begins on the Effective Date and continues while any Order Form is in effect. Each Order Form's Subscription Term and renewal are as stated therein auto-renewing annual terms unless either party gives 30 days' notice.
16.2 Suspension. ARYX may suspend Customer's or an Authorized User's access, in whole or in part, if (a) Fees are overdue after notice, (b) Customer's use poses a security risk, may harm ARYX or others, or violates Section 4.2 or law, or (c) suspension is required by a Processor, Subprocessor, or legal authority. ARYX will use reasonable efforts to give prior notice and to limit the scope and duration of suspension.
16.3 Termination for Cause. Either party may terminate this Agreement or an affected Order Form for the other party's material breach that remains uncured 30 days after written notice, or immediately upon the other party's insolvency or bankruptcy.
16.4 Termination for Convenience. Termination for convenience, if any, is as stated in the applicable Order Form.
17. Effect of Termination; Data Export
17.1 Cessation. Upon expiration or termination, Customer's right to access the Services ends, and each party will return or destroy the other's Confidential Information except as required for legal retention.
17.2 Data Export. For a period of 30 days following termination, ARYX will make Member Data available for export as described in ARYX's data ownership and retention terms. Thereafter, ARYX may delete Member Data in accordance with that policy, the DPA, and applicable HIPAA retention obligations, unless legally required to retain it.
17.3 Survival. Sections 1, 4.2–4.3, 6 (as to accrued amounts), 7, 8, 9, 10, 11.3, 12, 13, 17, 18, and 19 survive termination.
18. Order of Precedence
18.1 In the event of a conflict among the Framework Documents, the following order of precedence controls (higher prevails), except that a document expressly stated to control on a specific subject prevails as to that subject:
- The Business Associate Agreement (/legal/baa), to the extent of PHI and HIPAA matters;
- The Data Processing Agreement (/legal/dpa), to the extent of data-protection and privacy matters;
- The applicable Order Form, as to its specific transaction terms;
- This Master SaaS Agreement;
- The Service Level Agreement (/legal/sla);
- The billing, fee, payments, and refund documents (
06-,07-,10-,11-); - Other referenced policies and the third-party dependencies disclaimer (ARYX's third-party dependency standards) and data export/retention policy (ARYX's data ownership and retention terms).
18.2 Notwithstanding the general order above, the DPA and BAA control over this Agreement on privacy/security and PHI matters respectively, and ARYX's refund and settlement standards (see also /legal/billing) controls on charge/refund lifecycle definitions.
19. General
19.1 Governing Law and Venue. This Agreement is governed by the laws of the laws of the United States, without regard to conflict-of-laws rules. The parties submit to the exclusive jurisdiction and venue of the courts located in the courts designated on the applicable Order Form. consider an arbitration and class-action-waiver clause — for counsel decision.
19.2 Force Majeure. Neither party is liable for delay or failure (other than payment obligations) caused by events beyond its reasonable control, including acts of God, war, terrorism, labor disputes, internet or utility failures, and failures or actions of Processors, banks, card networks, or third-party dependencies.
19.3 Notices. Legal notices must be in writing and sent to the notice address designated on the applicable Order Form (ARYX) and to Customer's account/administrative contact, with operational notices permitted by email to hello@aryx.pro. Notices are effective on receipt.
19.4 Assignment. Neither party may assign this Agreement without the other's prior written consent, except that either party may assign to a successor in a merger, acquisition, or sale of substantially all assets on written notice. Any other purported assignment is void.
19.5 Independent Contractors. The parties are independent contractors; nothing creates a partnership, agency, joint venture, or fiduciary relationship.
19.6 No Third-Party Beneficiaries. There are no third-party beneficiaries, except that Members and Authorized Users create no rights against ARYX under this Agreement.
19.7 Severability; Waiver. If any provision is unenforceable, the remainder remains in effect. No waiver is effective unless in writing.
19.8 Publicity. Neither party will use the other's name or marks without prior written consent, except ARYX may list Customer as a customer in a factual customer list subject to Customer's opt-out.
19.9 Entire Agreement; Amendment. This Agreement, together with the Framework Documents and Order Forms, is the entire agreement and supersedes prior proposals and agreements on its subject matter. ARYX may update the online Terms of Service on notice; material changes take effect at the next renewal unless Customer accepts them earlier. Order Forms may be amended only by mutual written agreement.
19.10 Counterparts; Electronic Acceptance. This Agreement may be executed in counterparts and accepted electronically, each of which is an original.
Questions about this document? Contact legal@aryx.pro. Related: all legal documents · Privacy Policy.