← All legal documents
Version 1.0Effective July 24, 2026sha256 5ad2288dfecdcfd47baea6eed8e4255831966de8a74314e4c06f741ea1103de6

Dion Health — Master Subscription Agreement

Version: 1.0 Effective Date: July 24, 2026 Last Updated: July 24, 2026

This Master Subscription Agreement (this "Agreement") is entered into between Dion Health Management Company LLC, a California limited liability company with offices at 450 Sutter Street, Suite 1519, San Francisco, CA 94108 ("Dion," "we," "us," or "our"), and the entity that accepts this Agreement ("Customer," "you," or "your").

This Agreement governs Customer's access to and use of all Dion software, platforms, applications, and services (collectively, the "Services" or the "Dion Suite").

BY CLICKING "I AGREE," EXECUTING AN ORDER FORM THAT REFERENCES THIS AGREEMENT, OR ACCESSING OR USING THE SERVICES, CUSTOMER AGREES TO BE BOUND BY THIS AGREEMENT. IF YOU ARE ACCEPTING ON BEHALF OF AN ORGANIZATION, YOU REPRESENT AND WARRANT THAT YOU HAVE THE AUTHORITY TO BIND THAT ORGANIZATION, AND "CUSTOMER" REFERS TO THAT ORGANIZATION. IF YOU DO NOT HAVE SUCH AUTHORITY, OR DO NOT AGREE, DO NOT ACCESS OR USE THE SERVICES.

SECTION 13 (LIMITATION OF LIABILITY) LIMITS DION'S LIABILITY. SECTION 16 CONTAINS A BINDING ARBITRATION PROVISION AND A CLASS ACTION WAIVER, WHICH AFFECT HOW DISPUTES ARE RESOLVED. PLEASE READ THEM CAREFULLY.


1. Definitions

"Affiliate" means any entity that directly or indirectly controls, is controlled by, or is under common control with a party, where "control" means ownership of more than fifty percent (50%) of the voting interests.

"Authorized User" means an individual whom Customer permits to access the Services under Customer's account, including Customer's employees, contractors, and Affiliates' personnel, in each case acting within the scope of Customer's internal business operations.

"Business Associate Agreement" or "BAA" means the HIPAA Business Associate Agreement executed between the parties, as described in Section 10.3.

"Confidential Information" has the meaning given in Section 9.1.

"Customer Data" means data, records, content, and information submitted to, or collected by, the Services by or on behalf of Customer or its Authorized Users, including Protected Health Information and data ingested from Customer's practice management, clinical, financial, or payroll systems.

"De-Identified Data" means Customer Data that has been de-identified in accordance with 45 C.F.R. § 164.514(a)–(c) — by expert determination or safe harbor — such that it is no longer Protected Health Information and does not identify, and provides no reasonable basis to identify, any individual, practice, or provider.

"Documentation" means the user guides, technical specifications, and other materials Dion makes generally available describing the Services.

"Feedback" means suggestions, enhancement requests, recommendations, comments, ideas, or other feedback regarding the Services.

"Order Form" means an ordering document, quote, statement of work, or online subscription flow executed or accepted by the parties that specifies the Services purchased, applicable fees, subscription term, and any negotiated terms.

"PHI" or "Protected Health Information" has the meaning given under HIPAA, 45 C.F.R. § 160.103.

"Schedule" means a product-specific schedule of terms published by Dion at /legal/product-schedules and applicable to a particular Service, as described in Section 2.2.

"Service Data" means data generated by Dion in connection with operating the Services that does not contain PHI or Customer Confidential Information, including configuration data, telemetry, log data, usage statistics, performance metrics, error reports, and aggregate operational measurements.

"Dion Technology" means the Services, the Dion Suite software and source code, APIs, data models, event contracts, algorithms, machine-learning models and model weights, user interfaces, designs, know-how, trade secrets, Documentation, and all other technology and intellectual property made available or used by Dion in providing the Services, together with all improvements, modifications, and derivative works thereof.


2. The Services

2.1 Provision of the Services

Subject to this Agreement and payment of applicable fees, Dion will make the Services identified in each Order Form available to Customer and its Authorized Users during the applicable subscription term.

2.2 Product Schedules

The Dion Suite comprises multiple products with materially different functions and risk profiles. Each Service is additionally governed by its applicable Schedule, which is incorporated into this Agreement by reference. In the event of a conflict, the order of precedence is: (a) the Order Form; (b) the applicable Schedule; (c) this Agreement; (d) all other policies incorporated by reference.

2.3 Incorporated Policies

The following are incorporated into this Agreement by reference: the Acceptable Use Policy, the Service Level Agreement, the Privacy Policy, and the applicable Schedules. Dion may update the Acceptable Use Policy and Documentation from time to time, provided such updates do not materially diminish the Services or materially expand Customer's obligations during a paid subscription term.

2.4 Affiliates and Authorized Users

Customer's Affiliates may use the Services where identified in an Order Form. Customer is responsible for all acts and omissions of its Authorized Users and Affiliates as though they were Customer's own, and for ensuring their compliance with this Agreement. Access is licensed per Authorized User or per the metric stated in the Order Form; Customer may not exceed the licensed quantity.

2.5 Changes to the Services

Dion may modify, enhance, or discontinue features of the Services. Dion will not materially degrade the core functionality of a Service during a paid subscription term without providing Customer at least thirty (30) days' notice and, where Dion discontinues a Service entirely, a pro-rata refund of prepaid, unused fees for that Service.

2.6 Beta and Preview Features

Dion may offer features designated as beta, preview, early access, or evaluation ("Beta Features"). Beta Features are provided "AS IS" without warranty or support, are excluded from the Service Level Agreement, and may be modified or withdrawn at any time. Customer's use of Beta Features is at Customer's sole risk.


3. License Grant

3.1 Grant

Subject to Customer's compliance with this Agreement and payment of applicable fees, Dion grants Customer a limited, non-exclusive, non-transferable, non-sublicensable, revocable right during the subscription term to access and use the Services and Documentation solely for Customer's own internal business operations in the operation of dental or healthcare practices that Customer owns, manages, or is contractually engaged to support.

3.2 Reservation of Rights

All rights not expressly granted in this Agreement are reserved by Dion and its licensors. No license, right, title, or interest in or to any Dion Technology is granted by implication, estoppel, exhaustion, or otherwise. This Agreement conveys a limited right of access only; it does not effect a sale, assignment, or transfer of any Dion Technology or any copy thereof.


4. Use Restrictions

Customer will not, and will not permit, authorize, assist, or enable any Authorized User or third party to:

(a) Reverse engineering. Reverse engineer, decompile, disassemble, decrypt, translate, or otherwise attempt to discover or derive the source code, object code, underlying structure, architecture, algorithms, data models, or ideas of the Services, except and solely to the extent that such restriction is expressly prohibited by applicable law and Customer has first given Dion written notice and a reasonable opportunity to provide the required interoperability information;

(b) Copying and derivative works. Copy, reproduce, modify, adapt, translate, or create derivative works of the Services, the Documentation, or any Dion Technology;

(c) Competing products. Use the Services, any output of the Services, or any information gained through access to the Services to design, develop, train, market, or offer any product or service that competes with the Services, or to train, fine-tune, or otherwise improve any machine-learning model other than as expressly permitted in an Order Form;

(d) Service bureau. Sell, resell, rent, lease, sublicense, distribute, white-label, or otherwise make the Services available to any third party, or use the Services on a service-bureau, timeshare, outsourcing, or managed-service basis for the benefit of any practice, entity, or organization that Customer does not own, manage, or serve under a written agreement disclosed to Dion;

(e) Benchmarking. Conduct or publish any benchmark, competitive analysis, or performance test of the Services, or disclose the results of any such test, without Dion's prior written consent;

(f) Automated extraction. Scrape, crawl, spider, harvest, or use any automated means to access the Services or extract data from them, or perform any bulk export designed to circumvent the Services' intended interfaces, rate limits, or export controls;

(g) Circumvention. Circumvent, disable, or interfere with any access control, license limitation, rate limit, security feature, usage metering, or technical protection measure of the Services;

(h) Security testing. Conduct any penetration test, vulnerability scan, load test, denial-of-service test, or other security or performance assessment of the Services without Dion's prior written authorization and subject to a mutually agreed scope and rules of engagement;

(i) Proprietary notices. Remove, obscure, or alter any copyright, trademark, patent, or other proprietary notice, watermark, or attribution appearing in or on the Services or Documentation;

(j) Credential sharing. Share, transfer, or permit the use of any account credential by more than one individual, permit access by more individuals than the licensed quantity, or fail to maintain the confidentiality of credentials;

(k) Unlawful and harmful use. Use the Services in violation of any applicable law or regulation, in violation of the Acceptable Use Policy, to store or transmit infringing or unlawful material, to transmit malicious code, or to interfere with the integrity or performance of the Services or any third party's data contained therein;

(l) Out-of-scope data. Submit PHI to any Service, module, or field not designated in the Documentation as intended to receive PHI, or submit any data category (including payment card data or government identifiers) that the applicable Schedule states the Service is not designed to process.

Customer will promptly notify Dion of any actual or suspected violation of this Section 4 and will cooperate with Dion to remediate it.


5. Customer Responsibilities

5.1 Accounts and Security

Customer is responsible for: (a) maintaining the confidentiality of account credentials and API keys; (b) all activity occurring under its accounts; (c) promptly notifying Dion at security@dionhealth.com of any suspected unauthorized access or credential compromise; and (d) provisioning and de-provisioning Authorized Users promptly, including upon termination of an individual's employment or engagement.

5.2 Customer Systems and Authorizations

Customer is responsible for its own systems, networks, devices, and third-party services used to access the Services. Where Customer connects a practice management, clinical, financial, or payroll system to the Services, Customer represents and warrants that it has all rights, consents, and authority necessary to grant Dion access to that system and the data within it, and that such access does not violate any agreement between Customer and any third party.

5.3 Legal and Professional Compliance

Customer is solely responsible for: (a) its own compliance with HIPAA, state privacy and medical-information laws, professional licensure requirements, wage and hour laws, billing and coding regulations, and all other laws applicable to its practice; (b) obtaining all patient consents, notices of privacy practices, and authorizations required by law; (c) the accuracy, quality, legality, and appropriateness of Customer Data; and (d) all clinical, billing, employment, and financial decisions made by Customer or its personnel.


6. Fees, Payment, and Taxes

6.1 Fees

Customer will pay the fees stated in each Order Form. Except as expressly stated in this Agreement, fees are non-refundable and payment obligations are non-cancelable.

6.2 Invoicing and Payment

Unless the Order Form states otherwise, fees are invoiced in advance and due net thirty (30) days from the invoice date. Amounts not paid when due accrue interest at the lesser of 1.5% per month or the maximum rate permitted by law.

6.3 Suspension for Non-Payment

If any undisputed amount is more than fifteen (15) days past due, Dion may, after providing written notice, suspend access to the Services until the amount is paid. Suspension does not relieve Customer of its payment obligations. Accounts not brought current within thirty (30) days of suspension may be terminated under Section 14.3.

6.4 Taxes

Fees are exclusive of taxes. Customer is responsible for all sales, use, VAT, GST, excise, and similar taxes, excluding taxes based on Dion's net income.

6.5 Usage Verification

Dion may audit Customer's use of the Services to verify compliance with licensed quantities and Section 4, using usage data available to Dion. If an audit reveals under-licensing, Customer will promptly purchase the additional licenses at Dion's then-current rates, retroactive to the date the excess use began.


7. Intellectual Property and Ownership

7.1 Dion Technology

As between the parties, Dion exclusively owns all right, title, and interest in and to the Dion Technology, including all intellectual property rights therein. The Services are licensed, not sold.

7.2 Machine-Learning Models

Dion exclusively owns all machine-learning models, model weights, embeddings, training methodologies, features, heuristics, statistical parameters, and derived insights developed by or for Dion, including any developed using De-Identified Data or Service Data as permitted under Section 8. Such models and their outputs are Dion Technology and do not constitute Customer Data, notwithstanding that De-Identified Data derived from Customer Data may have contributed to their development.

7.3 Customer Data

As between the parties, Customer exclusively owns all right, title, and interest in and to Customer Data. Customer grants Dion a limited, non-exclusive, worldwide license to host, copy, process, transmit, display, and otherwise use Customer Data solely as necessary to provide, secure, and support the Services for Customer, and as otherwise permitted in Section 8 and the BAA.

7.4 Feedback

Customer grants Dion a perpetual, irrevocable, worldwide, royalty-free, fully paid-up, sublicensable, and transferable license to use, reproduce, modify, and exploit all Feedback for any purpose, including incorporating it into the Services, without attribution, accounting, or compensation to Customer. Dion is not obligated to implement any Feedback, and Customer acquires no right in any Dion Technology by virtue of providing Feedback.

7.5 Trademarks

Neither party may use the other's name, logo, or trademarks without prior written consent, except that Dion may identify Customer as a customer in customer lists and on its website unless Customer notifies Dion in writing that it opts out.


8. Customer Data, PHI, and De-Identified Data

8.1 Use to Provide the Services

Dion will access, use, and disclose Customer Data only: (a) as necessary to provide, maintain, secure, troubleshoot, and support the Services for Customer; (b) as permitted by the BAA with respect to PHI; (c) as directed or authorized by Customer; and (d) as required by law.

8.2 De-Identification

Customer authorizes Dion to de-identify Customer Data, including PHI, in accordance with 45 C.F.R. § 164.514(a)–(c). This authorization is granted under 45 C.F.R. § 164.504(e)(2)(i) and is restated in the BAA. De-identification is performed by Dion or a qualified expert engaged by Dion, using expert determination or safe harbor, and is subject to Dion's documented de-identification methodology, which Dion will make available to Customer on request.

8.3 Rights in De-Identified Data

Once de-identified, De-Identified Data is not Protected Health Information and is not subject to HIPAA. As between the parties, Dion owns De-Identified Data and may use, reproduce, modify, distribute, commercialize, and otherwise exploit it for any lawful purpose without restriction, obligation, or compensation to Customer, including to:

  • develop, train, fine-tune, evaluate, and improve machine-learning models and artificial-intelligence features;
  • produce industry benchmarks, comparative analytics, indices, and research;
  • develop, improve, and market new and existing products and services; and
  • publish aggregate findings, provided no publication identifies Customer, any practice, any provider, or any individual.

8.4 Service Data

Dion may collect and use Service Data for any lawful business purpose, including operating, securing, analyzing, and improving the Services, capacity planning, and product development.

8.5 No Re-Identification

Dion covenants that it will not attempt to re-identify De-Identified Data or to contact any individual whose information contributed to it, and will contractually require the same of any recipient of De-Identified Data. Dion will maintain De-Identified Data in de-identified form and will publicly commit to these obligations as required by applicable law, including the California Consumer Privacy Act as amended.

8.6 No Sale of Personal Information

Dion does not sell Customer Data or personal information, and does not share personal information for cross-context behavioral advertising.

8.7 State Law

Where applicable state law — including the California Confidentiality of Medical Information Act, Texas HB 300, or other state medical-information or artificial-intelligence statutes — imposes requirements stricter than HIPAA on de-identification or secondary use, Dion will comply with the stricter standard, and the rights granted in Section 8.3 apply only to the extent permitted by that standard.

8.8 Order Form Variation

Customer may negotiate limitations on Section 8.3 in an Order Form. Absent such a negotiated limitation, Section 8.3 applies in full.


9. Confidentiality

9.1 Definition

"Confidential Information" means non-public information disclosed by a party ("Discloser") to the other ("Recipient") that is designated confidential or that a reasonable person would understand to be confidential given its nature and the circumstances of disclosure. Dion's Confidential Information includes the Dion Technology, source code, algorithms, architecture, security practices, product roadmaps, and pricing. Customer's Confidential Information includes Customer Data and Customer's non-public business and financial information.

9.2 Obligations

Recipient will: (a) use Discloser's Confidential Information solely to perform under this Agreement; (b) protect it using at least the degree of care it uses for its own confidential information of like importance, and no less than reasonable care; and (c) not disclose it except to its employees, Affiliates, contractors, and advisors who have a need to know and are bound by confidentiality obligations no less protective than these.

9.3 Exclusions

Confidential Information does not include information that: (a) is or becomes publicly available without breach; (b) was rightfully known to Recipient without confidentiality obligation before disclosure; (c) is rightfully received from a third party without restriction; or (d) is independently developed without use of or reference to Discloser's Confidential Information.

9.4 Compelled Disclosure

Recipient may disclose Confidential Information to the extent required by law or court order, provided it gives Discloser prompt notice (where legally permitted) and reasonable cooperation to seek protective treatment.

9.5 Survival

The obligations in this Section 9 survive termination of this Agreement for a period of five (5) years, except that obligations with respect to any Confidential Information that constitutes a trade secret survive for as long as such information remains a trade secret under applicable law, and obligations with respect to PHI survive in accordance with the BAA and applicable law.

9.6 Injunctive Relief

Each party acknowledges that a breach or threatened breach of Section 4 (Use Restrictions), Section 7 (Intellectual Property), or this Section 9 would cause irreparable harm for which monetary damages would be an inadequate remedy. Accordingly, the non-breaching party is entitled to seek injunctive and other equitable relief without the necessity of posting a bond or proving actual damages, in addition to all other remedies available at law or in equity.


10. Security, Privacy, and Regulatory Compliance

10.1 Security Program

Dion will maintain a written information security program with administrative, physical, and technical safeguards designed to protect Customer Data against unauthorized access, use, disclosure, alteration, and destruction, consistent with the HIPAA Security Rule and Dion's published Information Security Policy.

10.2 Security Incidents

Dion will notify Customer without undue delay, and in any event within the timeframes required by the BAA and applicable law, upon becoming aware of a breach of unsecured PHI or unauthorized access to Customer Data, and will provide information reasonably necessary for Customer to meet its own notification obligations.

10.3 HIPAA

To the extent Dion creates, receives, maintains, or transmits PHI on Customer's behalf, Dion acts as a Business Associate and Customer acts as a Covered Entity or Business Associate under HIPAA. The parties will execute a Business Associate Agreement before Customer transmits any PHI to the Services. The BAA is incorporated into this Agreement by reference. In the event of a conflict between the BAA and this Agreement with respect to PHI, the BAA controls.

10.4 Subprocessors

Dion may engage subprocessors to provide the Services. Dion maintains a current list of subprocessors and will impose data protection obligations on each subprocessor no less protective than those in this Agreement and the BAA. Dion remains responsible for its subprocessors' performance.


11. Warranties and Disclaimers

11.1 Mutual Warranties

Each party warrants that it has the legal power and authority to enter into this Agreement.

11.2 Dion Warranties

Dion warrants that: (a) the Services will perform materially in accordance with the Documentation; (b) Dion will provide the Services in a professional and workmanlike manner consistent with generally accepted industry standards; and (c) Dion will not materially decrease the security protections of the Services during a subscription term. Customer's exclusive remedy for breach of subsection (a) is for Dion to use commercially reasonable efforts to correct the non-conformity, and if Dion cannot do so within thirty (30) days of written notice, Customer may terminate the affected Service and receive a pro-rata refund of prepaid, unused fees.

11.3 Uptime

Availability commitments and service credits are set out in the Service Level Agreement. Service credits are Customer's sole and exclusive remedy for any failure of the Services to meet the availability commitment.

11.4 Disclaimer

EXCEPT AS EXPRESSLY SET FORTH IN THIS SECTION 11, THE SERVICES AND ALL RELATED MATERIALS ARE PROVIDED "AS IS" AND "AS AVAILABLE." DION AND ITS LICENSORS DISCLAIM ALL OTHER WARRANTIES, EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE, INCLUDING ANY IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, NON-INFRINGEMENT, AND ANY WARRANTIES ARISING FROM COURSE OF DEALING OR USAGE OF TRADE. DION DOES NOT WARRANT THAT THE SERVICES WILL BE UNINTERRUPTED, ERROR-FREE, OR SECURE, THAT DEFECTS WILL BE CORRECTED, OR THAT ANY OUTPUT, ANALYTIC, PREDICTION, OR RECOMMENDATION WILL BE ACCURATE, COMPLETE, OR SUITABLE FOR ANY PARTICULAR PURPOSE.

11.5 Third-Party Systems

The Services integrate with third-party systems, including practice management systems, clearinghouses, payment processors, and payroll providers. Dion is not responsible for the availability, accuracy, or performance of any third-party system, or for any act or omission of a third-party provider. Analytics and outputs derived from inaccurate, incomplete, or misconfigured third-party data will reflect those deficiencies.


12. Clinical, Professional, and AI Disclaimers

12.1 Not Medical Advice

The Services do not provide medical, dental, diagnostic, or treatment advice and are not a substitute for professional clinical judgment. The Services are not intended to diagnose, treat, cure, or prevent any disease or condition.

12.2 Not a Medical Device

The Services are provided as practice-management, administrative, analytic, and operational tools. Dion does not represent that the Services are, or are intended to function as, a medical device requiring clearance or approval by the U.S. Food and Drug Administration.

12.3 Professional Responsibility

All clinical, diagnostic, treatment, billing, coding, employment, compensation, and financial decisions remain the sole responsibility of Customer and its licensed professionals. Customer is responsible for exercising independent professional judgment and for verifying the accuracy and appropriateness of any output before acting on it.

12.4 Artificial Intelligence Features

Certain Services use artificial intelligence and machine learning, including features that draft communications, summarize records, suggest codes, prioritize work, or automate routine tasks ("AI Features"). Customer acknowledges that:

  • AI Features are assistive and probabilistic. Outputs may be inaccurate, incomplete, outdated, or inappropriate for a given situation, and may reflect biases present in underlying data.
  • Human review is required. Customer will maintain meaningful human review of AI Feature outputs before any output is relied upon for a clinical, billing, employment, or financial decision, or is transmitted to a patient, payer, or regulator.
  • Customer is responsible for outputs it adopts. Once Customer or its personnel accept, transmit, submit, or act upon an output, Customer is responsible for it as if Customer had created it.
  • No guarantee of regulatory outcome. Dion does not warrant that any output will result in claim acceptance, payment, regulatory approval, or compliance with any law.

12.5 Not a Compliance Determination

The Services may surface compliance-related information, reminders, or indicators. These are informational aids only and do not constitute legal, regulatory, tax, accounting, or compliance advice, and do not establish that Customer is in compliance with any law.


13. Limitation of Liability

13.1 Exclusion of Indirect Damages

TO THE MAXIMUM EXTENT PERMITTED BY LAW, NEITHER PARTY WILL BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR FOR ANY LOSS OF PROFITS, REVENUE, GOODWILL, BUSINESS OPPORTUNITY, OR DATA, ARISING OUT OF OR RELATED TO THIS AGREEMENT, REGARDLESS OF THE THEORY OF LIABILITY AND EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.

13.2 Liability Cap

TO THE MAXIMUM EXTENT PERMITTED BY LAW, EACH PARTY'S TOTAL CUMULATIVE LIABILITY ARISING OUT OF OR RELATED TO THIS AGREEMENT WILL NOT EXCEED THE TOTAL FEES PAID OR PAYABLE BY CUSTOMER TO DION UNDER THE APPLICABLE ORDER FORM IN THE TWELVE (12) MONTHS IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO THE CLAIM.

13.3 Exclusions from the Cap

The limitations in Sections 13.1 and 13.2 do not apply to: (a) Customer's payment obligations; (b) either party's indemnification obligations under Section 15; (c) Customer's breach of Section 4 (Use Restrictions) or infringement or misappropriation of Dion's intellectual property; (d) either party's breach of Section 9 (Confidentiality), other than with respect to Customer Data; or (e) a party's gross negligence, willful misconduct, or fraud.

13.4 Enhanced Cap for Data Incidents

Notwithstanding Section 13.2, Dion's liability for a breach of Section 10 (Security) or of the BAA caused by Dion's failure to implement the safeguards it committed to will not exceed three (3) times the fees paid or payable in the twelve (12) months preceding the event.

13.5 Basis of the Bargain

The parties agree that the limitations in this Section 13 are an essential element of the basis of the bargain, that the fees reflect this allocation of risk, and that these limitations apply notwithstanding the failure of essential purpose of any limited remedy.


14. Term and Termination

14.1 Term

This Agreement begins on the earlier of Customer's acceptance or first access to the Services and continues until all Order Forms have expired or been terminated. Each subscription term is stated in the applicable Order Form and, unless the Order Form states otherwise, renews for successive periods equal to the then-expiring term unless either party gives written notice of non-renewal at least thirty (30) days before the end of the current term.

14.2 Termination for Cause

Either party may terminate this Agreement or an affected Order Form upon written notice if the other party materially breaches and fails to cure within thirty (30) days of written notice describing the breach. Dion may terminate immediately upon notice for Customer's breach of Section 4 (Use Restrictions), Section 9 (Confidentiality), or infringement of Dion's intellectual property.

14.3 Suspension

Dion may suspend Customer's access, in whole or in part, where Dion reasonably determines that continued access presents a security risk, is causing material harm to the Services or another customer, violates law, or where fees are past due under Section 6.3. Dion will provide notice and, where practicable, an opportunity to remediate before suspending.

14.4 Effect of Termination

Upon expiration or termination: (a) all licenses granted to Customer terminate and Customer will cease all use of the Services; (b) Customer will pay all amounts accrued through the effective date; and (c) each party will return or destroy the other's Confidential Information, except for archival copies retained in routine backups (which remain subject to Section 9) and as required by law.

14.5 Data Export and Deletion

For ninety (90) days following termination, Dion will make Customer Data available for export in a commercially reasonable format upon Customer's written request. After that period, Dion will delete or de-identify Customer Data in accordance with its retention practices, the BAA, and applicable law. De-Identified Data and Service Data already created are not subject to deletion, consistent with Section 8.

14.6 Survival

Sections 1, 4, 6 (as to accrued amounts), 7, 8, 9, 11.4, 12, 13, 14.4–14.6, 15, 16, and 17 survive termination.


15. Indemnification

15.1 Dion Indemnity

Dion will defend Customer against any third-party claim alleging that the Services, as provided by Dion and used in accordance with this Agreement, infringe or misappropriate that third party's patent, copyright, trademark, or trade secret, and will indemnify Customer for damages and reasonable attorneys' fees finally awarded or agreed in settlement.

If the Services become, or Dion believes they may become, the subject of such a claim, Dion may at its option: (a) procure the right for Customer to continue using the Services; (b) modify or replace the Services to be non-infringing while materially preserving functionality; or (c) terminate the affected Service and refund prepaid, unused fees.

Dion has no obligation under this Section to the extent a claim arises from: (i) Customer Data; (ii) modification of the Services by anyone other than Dion; (iii) combination of the Services with products or data not provided by Dion, where the claim would not have arisen but for the combination; (iv) use in violation of this Agreement or applicable law; or (v) Beta Features.

15.2 Customer Indemnity

Customer will defend Dion against any third-party claim arising from: (a) Customer Data, including any claim that Customer Data infringes a third party's rights or was collected, used, or disclosed in violation of law; (b) Customer's breach of Section 4, Section 5, or Section 10; (c) Customer's violation of applicable law; or (d) any clinical, billing, employment, or financial decision made by Customer or its personnel — and will indemnify Dion for damages and reasonable attorneys' fees finally awarded or agreed in settlement.

15.3 Procedure

The indemnified party will: (a) promptly notify the indemnifying party of the claim (delay excuses the indemnitor only to the extent it is prejudiced); (b) give the indemnifying party sole control of the defense and settlement, provided no settlement imposing a non-monetary obligation or admission on the indemnified party may be made without its consent, not unreasonably withheld; and (c) provide reasonable cooperation at the indemnifying party's expense.

15.4 Exclusive Remedy

This Section 15 states each party's sole liability and exclusive remedy for third-party claims of the types described.


16. Dispute Resolution and Governing Law

16.1 Governing Law

This Agreement is governed by the laws of the State of California, excluding its conflict-of-laws rules and the U.N. Convention on Contracts for the International Sale of Goods.

16.2 Informal Resolution

Before initiating arbitration, the parties will attempt in good faith to resolve any dispute through discussion between executives with authority to settle, for a period of thirty (30) days after written notice of the dispute.

16.3 Binding Arbitration

Any dispute not resolved under Section 16.2 will be finally settled by binding arbitration administered by the American Arbitration Association under its Commercial Arbitration Rules, before a single arbitrator, seated in San Francisco, California. Judgment on the award may be entered in any court of competent jurisdiction. Each party bears its own attorneys' fees unless the arbitrator determines a claim was frivolous.

16.4 Exception for Equitable Relief

Notwithstanding Section 16.3, either party may seek injunctive or other equitable relief in a court of competent jurisdiction to protect its intellectual property or Confidential Information, without first proceeding to arbitration, consistent with Section 9.6.

16.5 Class Action Waiver

THE PARTIES WAIVE ANY RIGHT TO BRING OR PARTICIPATE IN ANY CLASS, COLLECTIVE, OR REPRESENTATIVE ACTION. THE ARBITRATOR MAY NOT CONSOLIDATE CLAIMS OF MORE THAN ONE PARTY OR PRESIDE OVER ANY CLASS OR REPRESENTATIVE PROCEEDING. If this Section 16.5 is found unenforceable, Section 16.3 is void as to the claim in question and that claim will proceed in the courts identified in Section 16.6.

16.6 Venue

For any matter not subject to arbitration, the parties consent to the exclusive jurisdiction and venue of the state and federal courts located in San Francisco County, California.

16.7 Jury Trial Waiver

TO THE EXTENT ANY DISPUTE PROCEEDS IN COURT, EACH PARTY KNOWINGLY AND IRREVOCABLY WAIVES ANY RIGHT TO TRIAL BY JURY.

16.8 Time Limitation

Any claim arising out of this Agreement must be brought within one (1) year after the claim accrues, except for claims for non-payment.


17. General

17.1 Changes to this Agreement

Dion may update this Agreement from time to time. For material changes, Dion will provide at least thirty (30) days' notice by email to Customer's designated contact or by in-product notice, and will require affirmative acceptance of the updated Agreement upon next sign-in. Changes do not apply retroactively and will not take effect during a paid subscription term with respect to that term's Order Form unless Customer accepts them, except where required by law. If Customer does not accept a material change, Customer's sole remedy is to terminate the affected Order Form as of the end of the then-current term.

17.2 Entire Agreement

This Agreement, together with all Order Forms, Schedules, the BAA, and incorporated policies, constitutes the entire agreement between the parties regarding its subject matter and supersedes all prior and contemporaneous agreements, proposals, and communications, whether written or oral, including any prior terms of service. Any pre-printed or click-through terms in a Customer purchase order or vendor portal are of no force or effect.

17.3 Order of Precedence

Where a negotiated, executed Order Form or amendment expressly modifies a provision of this Agreement, the Order Form or amendment controls for that Order Form only.

17.4 Assignment

Neither party may assign this Agreement without the other's prior written consent, except that either party may assign it in its entirety, upon notice, to a successor in connection with a merger, acquisition, corporate reorganization, or sale of substantially all assets. Any other attempted assignment is void.

17.5 Independent Contractors

The parties are independent contractors. This Agreement creates no partnership, joint venture, agency, fiduciary, or employment relationship.

17.6 No Third-Party Beneficiaries

There are no third-party beneficiaries to this Agreement.

17.7 Force Majeure

Neither party is liable for any delay or failure to perform (excluding payment obligations) due to causes beyond its reasonable control, including acts of God, natural disaster, epidemic, war, terrorism, labor dispute, governmental action, internet or utility failure, or third-party provider outage.

17.8 Notices

Notices to Dion must be sent to legal@dionhealth.com and to Dion Health Management Company LLC, 450 Sutter Street, Suite 1519, San Francisco, CA 94108. Notices to Customer may be sent to the email address on Customer's account. Notices are effective upon receipt, or upon confirmed email delivery.

17.9 Severability

If any provision is held unenforceable, it will be modified to the minimum extent necessary to make it enforceable, and the remaining provisions continue in full force.

17.10 Waiver

No waiver is effective unless in writing. Failure to enforce a provision is not a waiver of the right to enforce it later.

17.11 Export and Sanctions

Customer will comply with all applicable export control and economic sanctions laws and represents that it is not located in, or organized under the laws of, any embargoed jurisdiction, and is not on any restricted-party list.

17.12 U.S. Government Rights

The Services are "commercial computer software" under FAR 12.212 and DFARS 227.7202. Government use is subject to the rights granted in this Agreement.

17.13 Counterparts and Electronic Acceptance

This Agreement may be executed in counterparts and accepted electronically. The parties agree that electronic acceptance, including clicking "I agree," constitutes a legally binding signature, and that records of such acceptance maintained by Dion — including the document version, content hash, timestamp, and originating network address — are admissible evidence of assent.


Contact

Dion Health Management Company LLC 450 Sutter Street, Suite 1519 San Francisco, CA 94108

  • Legal: legal@dionhealth.com
  • Privacy: privacy@dionhealth.com
  • Security: security@dionhealth.com

All legal documents · legal@dionhealth.com

Dion Health Management Company LLC · 450 Sutter Street, Suite 1519 · San Francisco, CA 94108