In short: BaselineZero is business software for IT service providers. You own your data, we run the service, AI output is a draft until a person approves it, Vault is information and not financial advice, and this agreement is governed by Michigan law. This summary is for convenience and is not part of the agreement.
1. The agreement
These Terms of Service (the “Terms”) are a binding agreement between BaselineZero, LLC, a Michigan limited liability company (“BaselineZero”, “we”, “us”), and the business that creates an account or signs an order form referencing these Terms (“Customer”, “you”). They govern access to and use of our products and services, including Debut, Discovery, Vault, and Debrief (together, the “Service”).
The Service is offered for business use only. The person accepting these Terms represents that they have authority to bind the Customer. If you and we sign a separate written agreement covering the Service, that agreement controls where it conflicts with these Terms.
The Service is offered from the United States, for business use, and is operated under U.S. law only. We do not represent that the Service or these Terms meet the requirements of any non-U.S. jurisdiction. Anyone accessing the Service from outside the United States does so at their own risk and remains bound by these Terms and U.S. law.
2. Definitions
“Customer Data” means data submitted to the Service by or for the Customer, including data imported from Connected Services, Client records, files, and messages.
“Client” means a customer of the Customer whose onboarding, discovery, or records the Customer manages through the Service.
“Portal Recipient” means an individual who accesses a Customer-branded page through a link issued by the Service at the Customer’s direction.
“Connected Service” means a third-party product the Customer connects to the Service under the Customer’s own agreement with that third party (for example a PSA, RMM, documentation vault, accounting system, bank data provider, payroll provider, or e-signature service).
“Order” means an ordering document, online purchase flow, or plan selection that references these Terms.
3. The Service; beta features
We will provide the Service materially as described on our site and in the applicable Order, and will not materially degrade a paid plan during a subscription term. We may improve or modify the Service, provided the changes do not materially reduce its core functionality.
Features identified as beta, preview, or early access are provided for evaluation, may change or be withdrawn at any time, may be subject to separate limits, and are provided without warranties or service commitments of any kind, notwithstanding anything else in these Terms.
4. Accounts and seats
You are responsible for provisioning your users, maintaining the accuracy of account information, and all activity under your accounts. Seats are for identified individuals and may be reassigned, but not shared concurrently. You will promptly disable access for personnel who leave your organization and will notify us of any suspected unauthorized access.
5. Fees and billing
Paid plans are billed per user per month unless the Order says otherwise. Fees are payable in U.S. dollars, are exclusive of taxes (which you are responsible for, other than taxes on our income), and except as stated in these Terms are non-refundable. We may suspend the Service for amounts more than 30 days overdue after notice.
We may change prices with at least 30 days’ notice, effective at your next renewal. Free plans may carry usage limits shown in the product, and we may modify free-plan limits on notice.
6. Customer Data
As between the parties, you own Customer Data. You grant us a non-exclusive license to host, process, transmit, and display Customer Data solely to provide and support the Service, to comply with law, and as otherwise instructed by you. We claim no other rights in Customer Data.
You are responsible for the accuracy and lawfulness of Customer Data, including having a lawful basis to submit personal information about your personnel, your Clients’ personnel, and Portal Recipients. Data protection terms are set out in the Data Processing Addendum, which is incorporated into these Terms.
7. Client portals and link access
The Service can issue individually scoped, expiring links that allow Portal Recipients to view pages and complete actions without an account. Links are issued at your direction, are attributable to a single person, can be revoked by you at any time, and their use is logged. You are responsible for directing links to appropriate recipients and for the content you publish to portal pages.
Portal Recipients are not parties to these Terms, but you will not permit their use of the Service in a way that would violate Section 11 (Acceptable use).
8. Connected Services
You decide which Connected Services to link. You represent that you are authorized to connect each one, including where the underlying tenant or account belongs to a Client. Connected Services are governed by their own terms and privacy policies; we are not responsible for their acts, omissions, availability, or data practices, and a Connected Service’s failure does not excuse fees but will not be counted against us as a Service failure beyond our reasonable control.
Bank account connections used by Vault are read-only and are established through a dedicated bank data provider. The Service cannot initiate money movement.
9. Credentials and secrets
The Service is designed to track the lifecycle of credentials by reference. Secret values (passwords, keys, and similar material) are intended to be stored in your documentation vault of record, not in the Service, and the Service is designed to retain zero bytes of secret material. You agree not to paste secret values into free-text fields. Where the Service holds integration tokens needed to operate a Connected Service, they are stored in isolated, per-customer key storage.
10. AI features
Parts of the Service generate drafts using machine learning models, including onboarding plans, client letters, escalation notices, wrap-up reports, and answers about your data. AI output is a draft: it may be inaccurate or incomplete, it is presented for review, and consequential actions require human approval within the product. You are responsible for reviewing AI output before relying on it or sending it to a Client.
AI features are metered. If your plan’s usage allowance is reached, AI features pause and the rest of the Service continues to work.
Vault is not advice. Vault presents information derived from data sources you connect, and states the limits of what it can see. It is not financial, investment, tax, accounting, or legal advice; no fiduciary, advisory, or professional relationship is created; and decisions you make in reliance on the Service are your own. Figures can be wrong when source data is wrong, delayed, or incomplete.
11. Acceptable use
You will not: (a) use the Service to violate law or the rights of others; (b) probe, disrupt, or circumvent its security or usage limits; (c) access it to build a competing product; (d) resell or provide the Service to third parties except to Clients as contemplated by the product; (e) upload malicious code; (f) use it to send spam or unlawful communications; or (g) attempt to extract source code or, except where permitted by law, reverse engineer it.
12. Confidentiality
Each party will protect the other’s non-public information disclosed under this agreement with at least reasonable care, use it only to perform under these Terms, and disclose it only to personnel and advisors bound by comparable obligations, or where required by law with reasonable advance notice where lawful. Confidentiality obligations survive for five years after disclosure; trade secrets are protected for as long as they remain trade secrets.
13. Intellectual property; feedback
We and our licensors own the Service, including software, designs, and documentation. You receive a limited, non-exclusive, non-transferable right to use the Service during your subscription. If you provide feedback, we may use it without restriction or obligation; feedback does not include Customer Data.
14. Privacy
Our Privacy Policy describes how we handle personal information for which we are the controller. Processing of personal information contained in Customer Data is governed by the Data Processing Addendum.
15. Security
We maintain administrative, technical, and organizational safeguards designed to protect Customer Data, as described in Annex II of the Data Processing Addendum, including encryption in transit and at rest, tenant isolation enforced at the database layer, per-customer key storage, least-privilege access, and audit logging. No system is perfectly secure, and we do not promise that security incidents will never occur; we do promise the notification and response obligations in the DPA. You are responsible for your own account configurations, user access decisions, the recipients you issue links to, and the security of Connected Services and of your vault of record.
16. Disclaimers
EXCEPT AS EXPRESSLY STATED IN THESE TERMS, THE SERVICE IS PROVIDED “AS IS” AND WE DISCLAIM ALL OTHER WARRANTIES, EXPRESS OR IMPLIED, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT, AND ANY WARRANTY THAT THE SERVICE WILL BE UNINTERRUPTED, ERROR-FREE, OR SECURE, THAT DATA WILL NOT BE LOST OR ALTERED, OR THAT OUTPUTS (INCLUDING AI OUTPUTS AND FINANCIAL FIGURES) WILL BE ACCURATE OR COMPLETE. USE OF THE SERVICE AND RELIANCE ON ITS OUTPUT ARE AT YOUR OWN RISK.
17. Limitation of liability
NEITHER PARTY WILL BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, OR FOR LOST PROFITS, REVENUE, GOODWILL, OR DATA, EVEN IF ADVISED OF THE POSSIBILITY. EACH PARTY’S TOTAL LIABILITY ARISING OUT OF OR RELATING TO THESE TERMS IS LIMITED TO THE AMOUNTS PAID OR PAYABLE BY CUSTOMER FOR THE SERVICE IN THE 12 MONTHS BEFORE THE EVENT GIVING RISE TO LIABILITY. FOR CLARITY, THIS SECTION APPLIES TO CLAIMS ARISING FROM UNAUTHORIZED ACCESS TO OR DISCLOSURE OF CUSTOMER DATA, AND BASELINEZERO HAS NO LIABILITY FOR INCIDENTS TO THE EXTENT CAUSED BY CUSTOMER’S CREDENTIALS, CONFIGURATIONS, CONNECTED SERVICES, OR PORTAL RECIPIENTS.
These limits do not apply to: a party’s indemnification obligations under Section 18; Customer’s payment obligations; either party’s breach of Section 12 (Confidentiality); or liability that cannot be limited by law. Nothing in these Terms limits liability for a party’s fraud, gross negligence, or willful misconduct.
18. Indemnification
We will defend Customer against third-party claims alleging that the Service, as provided by us and used as permitted, infringes a U.S. patent, copyright, or trademark, or misappropriates a trade secret, and will pay resulting damages finally awarded or agreed in settlement. If such a claim arises, we may modify the Service, procure rights, or terminate the affected portion with a pro-rata refund. This section does not cover claims arising from Customer Data, Connected Services, combinations we did not supply, or use in violation of these Terms.
Customer will defend us against third-party claims arising from Customer Data, Customer’s Client relationships, or Customer’s use of the Service in violation of law or these Terms, and will pay resulting damages finally awarded or agreed in settlement. The indemnified party must give prompt notice, reasonable cooperation, and sole control of the defense to the indemnifying party.
19. Term and termination
Subscriptions renew automatically for successive terms unless either party gives notice of non-renewal before renewal. Either party may terminate for material breach not cured within 30 days of notice, or immediately if the other party becomes insolvent. You may cancel a free plan at any time in the product.
The Service does not include bulk data export. Following termination or expiration, we will delete Customer Data as described in the DPA, except for minimal records we must retain by law. Sections that by their nature should survive (including 6, 10, 12, 13, 16, 17, 18, 21, and 22) survive termination.
20. Suspension
We may suspend access immediately, with notice as soon as practicable, if reasonably necessary to address a security risk, unlawful use, harm to the Service or others, or non-payment under Section 5. We will limit suspension to what is reasonably necessary and restore access promptly once the cause is resolved.
21. Governing law and venue
These Terms are governed by the laws of the State of Michigan, without regard to conflict-of-laws rules, and not by the U.N. Convention on Contracts for the International Sale of Goods. The state and federal courts located in Michigan have exclusive jurisdiction over disputes arising out of or relating to these Terms, and each party consents to venue and personal jurisdiction there. EACH PARTY WAIVES ITS RIGHT TO A JURY TRIAL to the extent permitted by law.
22. General
Notices must be in writing; we may notify you through the product or the email on your account, and you may notify us at legal@baselinezero.com and BaselineZero, LLC, P.O. Box 511002, Livonia, Michigan 48151. Neither party may assign this agreement without the other’s consent, except to a successor in a merger, acquisition, or sale of substantially all assets, on notice. Neither party is liable for delay or failure caused by events beyond its reasonable control. The parties are independent contractors. You will comply with applicable export and sanctions laws. If a provision is unenforceable it will be modified to the minimum extent necessary, and the rest remains in effect. A waiver must be in writing. These Terms, the Order, the Privacy Policy, and the DPA are the entire agreement about the Service and supersede prior discussions. We may update these Terms with at least 30 days’ notice for material changes, effective at your next renewal or, for free plans, on the stated effective date; continued use after the effective date is acceptance.