Skip to content
VisitWeave
  • Product
  • Who it's for
  • Company
  • Contact

Legal

Terms of Service

Version
1.0
Last updated
August 12, 2026
Provider
Tawny Dog Software, LLC, doing business as VisitWeave
Provider address
7901 4th St N #34331, St. Petersburg, FL 33702
Legal and account notice email
support@visitweave.com
Important: Do not send Protected Health Information or other patient information to any VisitWeave email address. Email is not an approved channel for PHI. Use an approved secure support channel when patient information is necessary.

These Terms of Service (the "Terms") govern access to and use of VisitWeave's software-as-a-service offering, including its website, web application, desktop application, mobile application, support, and related services (collectively, the "Service"). These Terms form a binding agreement between Tawny Dog Software, LLC, a Florida limited liability company doing business as VisitWeave ("VisitWeave," "we," "us," or "our"), and the legal entity that accepts these Terms, creates a VisitWeave organization, subscribes to or pays for the Service, or otherwise uses the Service ("Customer"). A person who accesses the Service on Customer's behalf is an "Authorized User."

The person accepting these Terms for Customer represents that the person has authority to bind Customer. If the person lacks that authority, the person must not accept these Terms or create a Customer organization.

1. Agreement Structure and Order of Precedence

1.1 Contract Documents

The agreement governing Customer's use of the Service may include:

  • these Terms;
  • the plan, fees, billing cadence, renewal terms, cancellation terms, usage limits, and other subscription information stated in an order form, invoice, payment confirmation, or other written commercial terms accepted by Customer (the "Subscription Details");
  • the VisitWeave Business Associate Agreement (the "BAA"), when Customer uses the Service with Protected Health Information;
  • an applicable state health-information, consumer-health-data, or privacy addendum;
  • a 42 C.F.R. Part 2 addendum, if expressly executed;
  • any feature-specific addendum, including a future artificial-intelligence addendum;
  • the VisitWeave Privacy Policy; and
  • policies or product documentation that these Terms expressly incorporate.

1.2 Order of Precedence

If the contract documents conflict:

  1. an applicable state or subject-matter addendum controls only to the extent necessary to satisfy the law or subject matter it addresses;
  2. the BAA controls concerning the privacy, security, use, disclosure, return, or destruction of Customer PHI;
  3. the Subscription Details control concerning the selected plan, fees, billing cadence, renewal terms, cancellation terms, and usage limits displayed to Customer;
  4. these Terms control concerning the remaining use of the Service; and
  5. product documentation controls only where it does not conflict with the documents above.

The BAA is a standalone agreement. Nothing in these Terms reduces an obligation that the BAA or applicable law imposes concerning Customer PHI.

1.3 Electronic Contracting

The parties may accept these Terms, the BAA, and required addenda electronically or in another written form made available by VisitWeave. Electronic acceptance and electronic records have the same effect as paper signatures and records to the extent permitted by law.

2. Definitions

"Applicable Law" means law that applies to a party, the Service, or the applicable data, including privacy, data-security, health-information, breach-notification, records-retention, export-control, and sanctions laws.

"Customer Data" means information, content, records, and configuration submitted to, stored in, or generated through the Service for Customer, including Customer PHI. Customer Data does not include VisitWeave technology, Service telemetry that does not identify a patient or reveal Customer PHI, or information VisitWeave receives outside its role providing the Service.

"Customer PHI" has the meaning stated in the BAA and generally means Protected Health Information that VisitWeave creates, receives, maintains, or transmits for Customer through the Service.

"Documentation" means VisitWeave's then-current user, administrator, security, and support documentation made available to Customer.

"Organization Administrator" means an Authorized User whom Customer designates as an organization owner or administrator in the Service.

"Protected Health Information" or "PHI" has the meaning assigned under the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations, as amended ("HIPAA").

"Subprocessor" means a third party that VisitWeave engages to process Customer Data on VisitWeave's behalf. A Subprocessor that creates, receives, maintains, or transmits Customer PHI is also subject to the requirements stated in the BAA.

"Subscription Details" means the plan, fees, billing cadence, renewal terms, cancellation terms, usage limits, and other subscription information stated in an order form, invoice, payment confirmation, or other written commercial terms accepted by Customer.

3. Business Use and United States Scope

3.1 Business Service

The Service is offered for business and professional use by healthcare organizations and their authorized workforce members. It is not a consumer or patient self-service application. Customer must ensure that each Authorized User is legally and professionally authorized to perform the activities assigned to that user.

3.2 United States Customers Only

VisitWeave currently supports only organizations operating in the United States. An organization established or principally operating outside the United States is not eligible to use the Service unless VisitWeave agrees in a written amendment.

3.3 Access Outside the United States

VisitWeave does not promise to block an Authorized User who attempts to access the Service while outside the United States, but such access is not supported. Customer is responsible for restricting user access based on Customer policy, professional obligations, and Applicable Law. VisitWeave's own hosting, workforce access, and PHI-handling Subprocessors will remain in the United States as stated in the BAA unless the parties sign a written amendment.

3.4 Export Controls and Sanctions

Customer and Authorized Users must not use the Service in violation of United States export-control, sanctions, or anti-boycott laws. Customer represents that it is not organized in, ordinarily resident in, or controlled by a prohibited jurisdiction or sanctioned person.

4. Customer Onboarding and Organization Administration

4.1 Required Information

Customer must provide accurate and current onboarding information, including:

  • Customer's exact legal entity name;
  • entity type and principal state;
  • whether Customer acts as a HIPAA Covered Entity, Business Associate, or both;
  • the name and contact information of Customer's privacy or security contact;
  • the states in which Customer expects to use the Service or process regulated health information;
  • the accepting representative's authority attestation; and
  • any other information reasonably needed to determine required legal documents or configure the Service.

4.2 Customer Agreement Obligations

By creating or using a VisitWeave organization for Customer, the representative accepts these Terms for Customer and represents that the representative has authority to bind Customer. Customer must execute the standard BAA before submitting PHI and must accept each addendum that VisitWeave identifies as required before using the affected Service. Customer-specific BAA templates are not supported unless VisitWeave later offers a separately negotiated enterprise service.

4.3 Administrator Responsibility

Customer controls its Organization Administrators and Authorized Users. Customer is responsible for:

  • granting only the access each user needs;
  • maintaining accurate roles, permissions, and contact information;
  • promptly disabling accounts when access is no longer required;
  • reviewing user access periodically;
  • ensuring that users comply with these Terms and Customer policy; and
  • maintaining at least one current Organization Administrator and one current privacy or security contact.

An action taken through an Authorized User's account is treated as Customer's action unless Customer promptly reports unauthorized use and demonstrates that the action did not result from Customer's failure to protect the account.

5. The Service and Product Boundaries

5.1 Current Service

VisitWeave is an operational healthcare scheduling software-as-a-service offering made available through web, desktop, and mobile applications. The current Service is designed to support:

  • referral intake;
  • agency and service configuration;
  • clinician eligibility and assignment;
  • referral invitations and staffing workflows;
  • visit scheduling, rescheduling, completion, and cancellation status;
  • clinician schedule views;
  • operational reports and exports; and
  • related organization administration and audit activity.

5.2 Not a Clinical Record System

The current Service is not designed or offered as:

  • an electronic health record or comprehensive medical record;
  • a diagnostic or clinical decision-support system;
  • a medication-management system;
  • a treatment-plan repository;
  • a laboratory or test-result system;
  • a psychotherapy-note repository;
  • an insurance, claims, eligibility, or billing platform; or
  • a patient document or file-storage service.

Customer must maintain any legally required medical, billing, or clinical records in an appropriate system of record.

5.3 No Medical Advice or Emergency Use

VisitWeave does not provide medical advice, diagnosis, treatment, clinical judgment, or emergency services. The Service does not replace a healthcare professional's judgment or Customer's emergency procedures. Customer must not rely on VisitWeave to contact emergency responders, monitor a patient, or detect a medical emergency.

5.4 Product Changes

VisitWeave may improve, modify, replace, or discontinue features. VisitWeave will not materially reduce core paid functionality during Customer's then-current paid subscription period without reasonable notice, except where a change is needed for security, legal compliance, third-party dependency changes, or prevention of harm. Any specific service-level commitment applies only if VisitWeave expressly agrees to it in a separate written service-level agreement.

6. Customer Data and Instructions

6.1 Customer Ownership

As between the parties, Customer retains its rights in Customer Data. VisitWeave retains all rights in the Service, software, Documentation, interfaces, workflows, designs, and underlying technology.

6.2 Limited License to Process Customer Data

Customer grants VisitWeave a nonexclusive, limited license to host, copy, transmit, display, transform, and otherwise process Customer Data only as reasonably necessary to:

  • provide, operate, secure, maintain, and support the Service;
  • carry out Customer's documented instructions;
  • prevent fraud, abuse, or security threats;
  • create Customer-requested reports or exports;
  • comply with the BAA and Applicable Law; and
  • enforce the agreement.

This license ends when VisitWeave no longer retains the applicable Customer Data, subject to the retention provisions in these Terms and the BAA.

6.3 Customer Authority and Lawful Instructions

Customer represents that it has all rights, notices, consents, authorizations, and other legal bases necessary to submit Customer Data and instruct VisitWeave to process it. Customer is responsible for determining whether a proposed use of the Service is lawful and appropriate for Customer's organization, patients, workforce, and jurisdiction.

VisitWeave is not required to follow an instruction that VisitWeave reasonably believes is unlawful, technically unsafe, outside the Service, or inconsistent with the BAA.

6.4 Accuracy and Minimum Necessary Information

Customer is responsible for the accuracy and completeness of Customer Data. Customer must enter only information reasonably necessary for referral staffing and scheduling. Customer should correct inaccurate operational information through the Service when authorized and appropriate.

6.5 No Independent Use of Customer PHI

VisitWeave will not sell Customer PHI, use it for targeted advertising or data brokerage, or use it to build unrelated products. VisitWeave does not use de-identified Customer Data for general analytics, benchmarking, or product improvement unless Customer signs a separate addendum that expressly permits that use.

6.6 Artificial Intelligence

VisitWeave does not currently offer an artificial-intelligence or machine-learning feature that processes Customer PHI. VisitWeave will not use Customer Data to train, fine-tune, or improve a generalized AI or machine-learning model.

Any future AI feature that processes Customer Data must be optional, require Customer's affirmative opt-in, and be governed by a separate addendum and feature-specific notice. A provider used for such a feature must be contractually obligated, as applicable, to comply with HIPAA, retain prompts and outputs for no longer than necessary to complete the requested processing, and not use Customer Data for model training.

7. HIPAA, State Health Laws, and Part 2

7.1 Business Associate Agreement

Customer must execute the VisitWeave BAA before submitting PHI. The BAA governs VisitWeave's processing of Customer PHI and Customer's HIPAA relationship with VisitWeave. Customer is responsible for confirming that the BAA is in effect and must not submit PHI until then.

7.2 Customer HIPAA Responsibilities

Customer remains responsible for obligations that apply to Customer as a Covered Entity or Business Associate, including:

  • providing required privacy notices;
  • determining permitted uses and disclosures;
  • responding to individuals and personal representatives;
  • maintaining required authorizations and consents;
  • configuring user access;
  • applying the minimum-necessary standard;
  • determining whether information belongs in a Designated Record Set; and
  • making breach and regulatory notifications for which Customer is responsible.

VisitWeave will provide the assistance stated in the BAA.

7.3 State Addenda

HIPAA is a federal baseline and may not displace a more protective state requirement. Customer must accurately identify its principal state and the states in which it will use the Service. If VisitWeave determines that a state-specific addendum is required, Customer must accept that addendum before using the affected Service for information subject to that law.

7.4 42 C.F.R. Part 2 Records

Customer must not submit records governed by 42 C.F.R. Part 2 unless:

  1. Customer gives VisitWeave prior written notice;
  2. VisitWeave confirms that the proposed use is supported; and
  3. the parties execute a Part 2 addendum.

Ordinary HIPAA-regulated information that references substance-use history is not automatically a Part 2 record. Customer is responsible for determining whether a record is governed by Part 2.

8. Acceptable Use

Customer and Authorized Users must not:

  • use the Service unlawfully or in a way that infringes another person's rights;
  • submit Customer Data without a lawful basis or required authorization;
  • use the Service for patient monitoring, emergencies, medical diagnosis, or clinical decision-making;
  • enter clinical narratives, diagnostic notes, medication details, test results, treatment plans, psychotherapy notes, or other unsupported clinical records into free-text fields;
  • upload or attempt to store patient documents or files in fields not designed for that purpose;
  • submit insurance, claims, or payment-card data to unsupported fields;
  • submit Part 2 records without the required addendum;
  • send PHI to a VisitWeave email address or include PHI in an email subject line;
  • place PHI in SMS or push-notification content;
  • share credentials, defeat authentication controls, or allow unauthorized account use;
  • probe, scan, test, or exploit a vulnerability without VisitWeave's prior written authorization;
  • disrupt the Service, introduce malicious code, or bypass rate limits or technical controls;
  • access another customer's organization or data;
  • reverse engineer, decompile, or attempt to derive source code except where Applicable Law prohibits restricting that activity;
  • scrape, bulk extract, or automate access except through a supported interface and within documented limits;
  • use the Service to develop or benchmark a competing service without VisitWeave's prior written consent;
  • remove proprietary notices; or
  • assist another person in doing any prohibited act.

VisitWeave may investigate suspected abuse using information reasonably necessary for that purpose and consistent with the BAA.

9. Accounts, Authentication, and Security Responsibilities

9.1 Account Protection

Customer and each Authorized User must:

  • use a unique account;
  • protect passwords, passkeys, recovery codes, devices, and sessions;
  • use security features required by Customer or VisitWeave;
  • not permit shared or generic user accounts unless VisitWeave expressly supports them;
  • sign out of unattended devices where appropriate; and
  • promptly notify VisitWeave of suspected compromise.

Customer is responsible for ensuring that its devices, networks, email accounts, and identity systems are appropriately secured.

9.2 Customer Security Contacts

Customer must maintain accurate contact information for its Organization Administrators and designated privacy or security contact. VisitWeave may rely on those contacts for legal notices, security notices, Subprocessor notices, and requests for Customer action.

9.3 Security Safeguards

VisitWeave will maintain safeguards as stated in the BAA and applicable Documentation, including encryption of Customer PHI at rest and in transit. No security control eliminates all risk, and VisitWeave does not warrant that unauthorized access can never occur.

9.4 Security Incident Cooperation

Each party will reasonably cooperate regarding a suspected security event and preserve information reasonably relevant to investigation, mitigation, and legally required notification.

Reportable incidents involving Customer PHI are governed by the BAA. Routine unsuccessful security events may be treated as described in the BAA without separate individual notice.

10. Support and PHI Access

10.1 Ordinary Support Channels

Customer may use the support channels VisitWeave makes available. The support email address is for non-PHI account, billing, legal, and technical communications only.

Customer must not send patient information, referral details, visit details, screenshots containing PHI, report contents, or other PHI by ordinary email. VisitWeave may delete, quarantine, or decline to process an email that appears to contain PHI and may direct Customer to a secure channel.

10.2 Secure Support

When support requires PHI, Customer must use a VisitWeave-approved secure channel, such as secure in-application messaging when available or verified telephone support.

10.3 Identity Verification for Telephone Support

Before discussing PHI by telephone, VisitWeave may require a one-time code sent only to the email address already associated with the Authorized User's VisitWeave account. VisitWeave will not ask an Authorized User to provide a password, passkey secret, recovery code, or complete patient record by email.

10.4 Support Personnel Access

VisitWeave support personnel do not have application access to Customer PHI. When troubleshooting requires PHI access through controlled operational tools, including direct database access, an Organization Administrator must request and authorize that access. Authorization:

  • must identify the support purpose;
  • will be limited to the least access reasonably necessary;
  • will be logged;
  • expires when the support case closes or twenty-four hours after authorization, whichever occurs first; and
  • must be renewed for additional access.

VisitWeave may access Customer PHI without prior Customer authorization only when reasonably necessary to investigate or contain a security incident, prevent imminent harm to the Service or Customer PHI, or comply with law, as permitted by the BAA.

11. Email, SMS, and Push Notifications

11.1 Email

VisitWeave may send account verification, password-reset, invitation, legal, billing, security, and service emails. VisitWeave designs automated email to avoid Customer PHI. Customer must keep account email addresses current and secure.

11.2 SMS and Push Notifications

If Customer or an Authorized User enables SMS or mobile push notifications, the notification will contain only a generic indication that an item requires attention and a link or prompt to open the authenticated Service. VisitWeave does not intentionally place patient identity, address, service, visit time, referral details, or other PHI in the notification body.

The recipient is responsible for device and carrier security. Carrier charges may apply. Notification delivery is not guaranteed and must not be relied on for emergencies or time-critical clinical action.

12. Reports and Exports

12.1 Authorized Exports

The Service may permit authorized users to preview or export referral and visit information in formats such as CSV or XLSX. Customer is responsible for configuring roles and determining who may export Customer Data.

12.2 In-Memory Generation

VisitWeave generates report files in volatile server memory and sends the file directly in the authenticated HTTPS response. VisitWeave does not intentionally write generated report contents to disk, object storage, or the application database. VisitWeave may retain non-content audit metadata, such as the actor, organization, template identifier, export format, row count, and masking notices.

12.3 Customer Responsibility After Download

Once an export reaches the Authorized User's browser or device, Customer is solely responsible for its storage, encryption, transmission, access control, retention, and deletion. Customer should download exports only to secured devices and should not transmit them through ordinary email.

13. Subprocessors and Hosting

13.1 Subprocessor Register

VisitWeave maintains an authenticated in-application list of Subprocessors used for Customer Data. The list is not public. Customer may access it through an authorized organization account.

13.2 New PHI-Handling Subprocessors

VisitWeave will provide at least thirty calendar days' advance notice before authorizing a new Subprocessor to create, receive, maintain, or transmit Customer PHI. Notice will be sent to Customer's registered Organization Administrators. Customer must submit any reasonable objection during that notice period. If Customer does not object before the period expires, Customer is deemed to have accepted the Subprocessor.

13.3 Objection Procedure

An objection must explain the specific, reasonable privacy or security concern. VisitWeave will consider commercially reasonable alternatives. If the parties cannot resolve the objection, Customer may terminate the affected Service without an early-termination penalty before the Subprocessor begins the disputed processing. Customer remains responsible for fees incurred before termination.

13.4 United States Processing

VisitWeave may move processing between United States regions without Customer notice or approval. VisitWeave will not move Customer PHI outside the United States without a written amendment accepted by Customer.

14. Fees, Billing, Taxes, and Renewal

14.1 Commercial Terms

The Subscription Details accepted by Customer state the selected plan, fees, billing cadence, renewal terms, cancellation terms, usage limits, and any applicable subscription period. Customer must pay all undisputed fees when due.

14.2 Taxes

Fees exclude taxes, duties, and governmental assessments. Customer is responsible for taxes arising from its purchase or use of the Service, excluding taxes based on VisitWeave's net income. If Customer claims an exemption, Customer must provide valid documentation before the charge is due.

14.3 Payment Disputes

Customer must notify VisitWeave of a good-faith billing dispute within thirty calendar days after the disputed charge or invoice. The parties will work in good faith to resolve the dispute. Customer must timely pay undisputed amounts.

14.4 Suspension for Nonpayment

VisitWeave may suspend the Service for material nonpayment after providing reasonable notice and an opportunity to cure, except where immediate action is reasonably necessary to prevent fraud or financial abuse. Suspension does not relieve Customer of payment obligations.

14.5 Refunds

Fees are nonrefundable except as expressly stated in the Subscription Details, these Terms, the Subprocessor-objection provision, or Applicable Law.

15. Intellectual Property and Feedback

15.1 VisitWeave Technology

VisitWeave and its licensors own the Service, software, Documentation, designs, APIs, workflows, trademarks, and all improvements and derivative works. No rights are granted except the limited right to use the Service during the applicable subscription term in accordance with the agreement.

15.2 Customer Materials

Customer retains ownership of Customer Data and Customer's names, marks, and materials. Customer grants VisitWeave a limited right to use Customer's organization name and marks only as necessary to identify Customer within the Service, provide support, and perform the agreement. VisitWeave will not publicly identify Customer as a customer without permission.

15.3 Feedback

If Customer provides suggestions or feedback, Customer grants VisitWeave a perpetual, irrevocable, worldwide, royalty-free right to use that feedback without identifying Customer or using Customer PHI. VisitWeave is not required to implement feedback.

16. Confidentiality

16.1 Confidential Information

"Confidential Information" means nonpublic information disclosed by one party ("Discloser") to the other ("Recipient") that should reasonably be understood as confidential. Customer Data is Customer Confidential Information. VisitWeave source code, security architecture, pricing not publicly offered, and nonpublic product plans are VisitWeave Confidential Information. Customer PHI is also governed by the BAA.

16.2 Protection and Use

Recipient will:

  • use Confidential Information only to perform or exercise rights under the agreement;
  • protect it using at least reasonable care;
  • disclose it only to personnel, professional advisers, and contractors who need to know it and are bound by confidentiality obligations; and
  • be responsible for unauthorized disclosure by persons to whom Recipient discloses it.

16.3 Exclusions

Confidential Information does not include information that Recipient can document was lawfully known without restriction, becomes public without Recipient's breach, is received lawfully from another source without duty, or is independently developed without use of the Confidential Information.

16.4 Compelled Disclosure

Recipient may disclose Confidential Information when legally required, but will provide advance notice and reasonable assistance seeking protective treatment unless notice is prohibited. Recipient will disclose only the information legally required.

16.5 Duration

These confidentiality duties continue while the information remains confidential. Duties concerning trade secrets continue while protected as trade secrets. Duties concerning Customer PHI continue as required by the BAA and Applicable Law.

17. Service Availability, Maintenance, and Beta Features

17.1 Availability

VisitWeave will use commercially reasonable efforts to operate the Service. Specific uptime, support-response, recovery-time, or recovery-point commitments apply only if VisitWeave expressly agrees to them in a separate written service-level agreement.

17.2 Maintenance

VisitWeave may perform scheduled or emergency maintenance. VisitWeave will use reasonable efforts to provide advance notice of planned maintenance that is expected to materially affect availability, but advance notice may not be possible for emergency work.

17.3 Beta or Preview Features

VisitWeave may offer optional beta, pilot, or preview features. Unless VisitWeave expressly states otherwise in the applicable feature description or a feature-specific addendum, those features are provided for evaluation, may change or end at any time, and are excluded from service-level commitments. Customer must not use a beta feature with PHI unless VisitWeave expressly identifies the feature as approved for PHI and the applicable legal documents cover that feature.

18. Suspension and Corrective Action

18.1 Ordinary Process

If VisitWeave reasonably believes Customer has violated the agreement or created a serious privacy or security risk, VisitWeave will ordinarily provide written notice and a reasonable opportunity to correct the issue, generally up to thirty calendar days.

18.2 Suspension After Failure to Correct

If Customer does not respond or correct the issue within the stated period, VisitWeave may suspend affected users, functionality, integrations, or the Service. VisitWeave will limit the suspension where reasonably practicable.

18.3 Immediate Action

VisitWeave may act without a cure period when reasonably necessary to:

  • prevent an imminent serious risk to Customer Data, another customer, or the Service;
  • contain an active security incident;
  • stop unlawful activity;
  • comply with law or a binding governmental order;
  • prevent unauthorized access; or
  • address intentional, repeated, or incurable misconduct.

VisitWeave will notify Customer as soon as reasonably practicable unless prohibited by law or doing so would increase the risk.

19. Term and Termination

19.1 Term

These Terms begin when Customer accepts them or first uses the Service, whichever occurs first, and continue until Customer's subscriptions and organizations have ended and VisitWeave no longer retains Customer Data except as legally required or expressly permitted by the BAA or these Terms.

19.2 Termination for Material Breach

Either party may terminate the affected subscription or Service if the other party materially breaches the agreement and does not cure the breach within thirty calendar days after written notice, or within a shorter period if the breach creates an imminent serious risk. A party may terminate immediately if the breach is incurable, intentional, repeated, or requires immediate termination by law.

19.3 Other Termination Rights

Customer may request cancellation by sending notice to support@visitweave.com from an Organization Administrator's registered email address, subject to the cancellation terms shown in the Subscription Details, and may terminate an affected Service following an unresolved Subprocessor objection as stated in Section 13. Customer must not include PHI in a cancellation request. VisitWeave may discontinue a paid plan or Service at the end of Customer's then-current billing or subscription period with reasonable notice.

19.4 Effect of Termination

Upon termination:

  • Customer's right to use the Service ends, subject to any limited transition access VisitWeave provides;
  • outstanding fees become due;
  • Customer may request or download a commercially reasonable machine-readable export during the thirty-day transition period;
  • VisitWeave will delete Customer PHI from active production systems by the end of that period, unless Applicable Law requires earlier deletion or continued retention;
  • after deletion from active production systems, Customer PHI may remain in protected backup copies until those copies are overwritten or deleted under VisitWeave's then-current backup retention practices, subject to the BAA and Applicable Law; and
  • provisions that by their nature should survive will survive, including payment, ownership, confidentiality, warranty disclaimers, liability, dispute, and data-retention provisions.

The BAA controls if it imposes a more protective requirement concerning Customer PHI.

20. Data Export, Deletion, and Retained Records

20.1 Customer-Controlled Deletion

Authorized Users may use available Service functionality to delete supported records, currently eligible scheduled visits and report templates. Underlying patient and referral records cannot currently be deleted through Service functionality. Customer is responsible for confirming that an Authorized User has authority to delete the applicable record.

20.2 Special Legal Deletion Requests

If Customer identifies a legal requirement for deletion that cannot be completed through the Service, VisitWeave will reasonably assist after receiving a valid written request through an approved secure channel. Active deletion may require operational processing time. If backup copies contain deleted data, that data may remain protected until the copies are overwritten or deleted under VisitWeave's then-current backup retention practices, subject to the BAA and Applicable Law.

20.3 Retained Records

VisitWeave may retain:

  • BAA and Terms acceptance records;
  • records required for an accounting of disclosures;
  • required compliance documentation;
  • compact legal-audit records;
  • ordinary logs for the standard retention period;
  • billing and tax records;
  • records under a valid legal hold; and
  • information otherwise required by law.

Retained records remain subject to applicable confidentiality, security, and use restrictions.

21. Warranties

21.1 Mutual Authority

Each party warrants that it has authority to enter into the agreement.

21.2 VisitWeave Service Warranty

VisitWeave warrants that, during a paid subscription term, it will provide the Service using commercially reasonable care and substantially in accordance with the Documentation. Customer's exclusive remedy for a verified material breach of this warranty is for VisitWeave to use commercially reasonable efforts to correct the nonconformity. If VisitWeave cannot do so within a reasonable period, Customer may terminate the affected Service and receive a refund of prepaid fees covering the unused terminated period.

21.3 Customer Warranty

Customer warrants that its Customer Data, instructions, configuration, and use of the Service comply with Applicable Law and the agreement.

22. Disclaimers

Except for the express warranties in these Terms and to the maximum extent permitted by law, the Service is provided "as is" and "as available." VisitWeave disclaims implied warranties of merchantability, fitness for a particular purpose, title, noninfringement, and any warranty arising from course of dealing or usage of trade.

VisitWeave does not warrant that the Service will be uninterrupted, error-free, immune from all security threats, or suitable for every legal or professional requirement. VisitWeave does not warrant the accuracy of Customer Data or decisions made by Customer or its users. The Service is not medical advice and is not an emergency, clinical-monitoring, insurance, claims, or comprehensive medical-record system.

Some jurisdictions do not allow certain disclaimers, so these disclaimers apply only to the extent permitted by law.

23. Indemnification

23.1 Customer Indemnification

Customer will defend VisitWeave and its officers, employees, and affiliates against a third-party claim arising from:

  • Customer Data that Customer lacked the right or lawful basis to submit;
  • Customer's unlawful use or disclosure of data;
  • Customer's violation of Sections 3, 6, 7, 8, 9, 10, or 12;
  • Customer's medical, employment, or professional decision; or
  • Customer's use of the Service in violation of Applicable Law.

Customer will pay damages, costs, and reasonable attorneys' fees finally awarded or agreed in a settlement approved by Customer.

23.2 VisitWeave Intellectual Property Indemnification

VisitWeave will defend Customer against a third-party claim that Customer's authorized use of the paid Service directly infringes a United States patent, copyright, or trademark, and will pay damages, costs, and reasonable attorneys' fees finally awarded or agreed in a settlement approved by VisitWeave.

VisitWeave has no obligation for a claim arising from Customer Data, Customer instructions, modification not made by VisitWeave, combination with an item not supplied by VisitWeave, continued use after notice, or use outside the agreement. VisitWeave may modify or replace the affected Service, obtain a right to continue use, or terminate the affected Service and refund prepaid fees for the unused period. This Section states Customer's exclusive remedy for an intellectual-property infringement claim.

23.3 Procedure

The indemnified party must promptly notify the indemnifying party, permit the indemnifying party to control the defense and settlement, and provide reasonable cooperation at the indemnifying party's expense. A delay in notice relieves the indemnifying party only to the extent materially prejudiced. A settlement may not admit fault or impose a nonmonetary obligation on the indemnified party without consent.

24. Limitation of Liability

24.1 Excluded Damages

To the maximum extent permitted by law, neither party will be liable for indirect, incidental, special, exemplary, punitive, or consequential damages; loss of profits, revenue, goodwill, or business opportunity; or loss or corruption of data that could have been avoided through reasonable backup practices, even if advised of the possibility.

24.2 Aggregate Cap

Except for payment obligations and liability that cannot lawfully be limited, each party's aggregate liability arising out of or relating to the Service, these Terms, the BAA, the Subscription Details, and applicable addenda will not exceed the fees paid or payable by Customer for the affected Service during the twelve months immediately preceding the event giving rise to liability.

24.3 Allocation of Risk

The fees reflect the allocation of risk in these Terms. Each limitation applies regardless of the legal theory and even if a remedy fails of its essential purpose, to the maximum extent permitted by law.

25. Privacy

The VisitWeave Privacy Policy describes how VisitWeave handles personal information in its role as a business, such as account, organization-contact, device, security, and support information. Customer PHI is governed by the BAA and Customer's own privacy obligations, not solely by the Privacy Policy.

Customer is responsible for providing any privacy notice required for Customer's collection and use of personal information through the Service. VisitWeave's Privacy Policy is not Customer's HIPAA Notice of Privacy Practices.

26. Legal Demands and Government Requests

If VisitWeave receives a subpoena, court order, or government demand for Customer Data, VisitWeave will notify Customer before disclosure and reasonably cooperate with Customer's efforts to seek protection, unless notice is legally prohibited or emergency circumstances make prior notice impracticable. VisitWeave will disclose only the information legally required. The BAA controls requests involving Customer PHI.

27. Governing Law and Disputes

27.1 Governing Law

Federal law governs federal HIPAA and HITECH matters. Florida law governs other matters arising from the agreement, without regard to conflict-of-law principles, unless an applicable state addendum or a separate written agreement signed by both parties expressly requires otherwise.

27.2 Courts

The state courts located in Pinellas County, Florida, and the United States District Court serving that county have exclusive jurisdiction over a dispute arising from the agreement. Each party consents to personal jurisdiction and venue in those courts. Either party may seek temporary or equitable relief in another court with jurisdiction when necessary to protect Confidential Information, intellectual property, or data.

27.3 Informal Resolution

Before filing a lawsuit, a party will provide written notice describing the dispute and allow at least thirty calendar days for good-faith executive-level discussions, unless immediate relief is reasonably necessary.

28. Notices

28.1 Notices to VisitWeave

Legal notices to VisitWeave must be sent to:

Tawny Dog Software, LLC dba VisitWeave 7901 4th St N #34331 St. Petersburg, FL 33702 Email: support@visitweave.com

Do not include PHI in email notices. VisitWeave may provide a secure channel when PHI is necessary.

28.2 Notices to Customer

VisitWeave may send notices to Customer's designated legal, billing, privacy/security, organization-owner, or administrator contact; through the Service; or through another contact method Customer provides in its account. Customer must keep those contacts current.

28.3 Effective Delivery

Email or in-application notice is effective when sent unless the sender receives a delivery-failure notice. Postal notice is effective upon confirmed delivery. A security notice may direct Customer to an authenticated location for details.

29. Changes to These Terms

VisitWeave may update these Terms for legal, security, operational, or product reasons. VisitWeave will present a material change that meaningfully reduces Customer rights or increases Customer obligations for affirmative acceptance by an authorized representative before it applies, unless Applicable Law requires an earlier effective date. Nonmaterial changes may be posted with reasonable notice.

An update to the BAA is governed by the BAA. A change to pricing or other commercial subscription terms applies only at renewal, upon Customer's affirmative acceptance, or as otherwise stated in the Subscription Details.

30. Miscellaneous

30.1 Assignment

Customer may not assign the agreement without VisitWeave's prior written consent, except to a successor in a merger or sale of substantially all Customer assets that is not a competitor of VisitWeave and agrees in writing to the agreement. VisitWeave may assign the agreement in connection with a merger, reorganization, financing, or sale of all or substantially all of its business or assets. An assignment does not reduce obligations concerning Customer PHI.

30.2 No Partnership or Agency

The agreement does not create a partnership, joint venture, agency, fiduciary, franchise, or employment relationship between the parties. Neither party may bind the other or incur obligations on the other party's behalf unless the agreement expressly permits it.

30.3 Force Majeure

Neither party is liable for delay or failure caused by events beyond its reasonable control, except payment obligations and obligations to protect Confidential Information and Customer PHI. The affected party will use reasonable efforts to mitigate the impact.

30.4 No Third-Party Beneficiaries

The agreement benefits only the parties and their permitted successors and assigns, except where Applicable Law expressly provides otherwise.

30.5 Severability

If a provision is unenforceable, it will be modified to the minimum extent necessary or severed, and the remaining provisions will remain effective.

30.6 Waiver

A waiver must be in writing and applies only to the specific instance. Delay in exercising a right is not a waiver.

30.7 Entire Agreement

The contract documents listed in Section 1 constitute the entire agreement concerning the Service and supersede prior or contemporaneous proposals, representations, and agreements on that subject. A purchase-order term does not amend the agreement unless VisitWeave expressly signs it.

30.8 Interpretation

Headings are for convenience. "Including" means "including without limitation." A reference to law includes successor provisions. An ambiguity will not be interpreted against a party solely because that party drafted the language.

30.9 Counterparts and Electronic Records

The agreement may be accepted in counterparts and electronically. Electronic acceptance and records have the same effect as paper signatures and records to the extent permitted by law. Customer may retain an accurate copy for later reference.

Provider Information

Tawny Dog Software, LLC dba VisitWeave Florida limited liability company 7901 4th St N #34331 St. Petersburg, FL 33702 support@visitweave.com

VisitWeave

From referral to completed visit.

PrivacyTerms of ServiceContact support
VisitWeavehello@visitweave.com