To execute: print this page, complete the details, sign, and email the scan to info@chartvoyant.com.

ChartVoyant API Use Agreement

Version 1.0
Effective on signature
chartvoyant.com/developers

This Agreement governs the issuance and use of a production ChartVoyant API key. It is entered into between Geach Medical PLLC, doing business as ChartVoyant ("ChartVoyant", "we"), and the organization identified below (the "Integrator", "you"). A key is issued only after a signed copy is on file. Sandbox keys are covered by the separate Sandbox Terms and do not require this Agreement.

Integration details

☐ Read-only    ☐ Full (read and write)
☐ 90 days    ☐ 1 year    ☐ Other:  
☐ Yes — profit share applies (see §8)    ☐ No
☐ Executed    ☐ In progress    Date:  

Terms

  1. Definitions

    API means the ChartVoyant application programming interface. Key means a credential issued by ChartVoyant in the form cvk_…. Practice means the medical office the Key is bound to. PHI means protected health information as defined by HIPAA. Data means information reached through the API using the Key.

  2. Grant of access

    ChartVoyant grants you a limited, non-exclusive, non-transferable, revocable right to access the API using the Key, solely to operate the integration described above, solely for the Practice named above, and solely for the term of the Key. No other right is granted. The Key is bound to one Practice and confers no access to any other office's data.

  3. One key, one integration

    The Key identifies a single system. You will not share it with, or use it on behalf of, any other organization, product, subcontractor, or practice. A second integration requires a second Key. You will request a separate Key for each environment you operate.

  4. Credential security

    You will:

    • store the Key in a secrets manager or equivalent encrypted store, protected at least as well as a production database credential;
    • use the Key only from servers you control, never in browser JavaScript, a mobile or desktop application, or any client an end user can inspect;
    • keep the Key out of source control, container images, build and CI logs, screenshots, support tickets, chat messages, and AI assistant transcripts;
    • limit access to the Key to personnel who need it, and revoke that access on their departure;
    • transmit all API requests over TLS.
  5. Permitted use and minimum necessary

    You will request and use the minimum data necessary for the integration's stated purpose, and you will request the lowest access level that accomplishes it. You will not use the Key to enumerate, bulk-extract, or systematically harvest records beyond what the integration requires.

  6. Prohibited uses

    You will not, without the Practice's prior written authorization:

    • create or maintain a persistent parallel copy of the Practice's clinical record;
    • use Data to train, fine-tune, evaluate, or ground any machine learning or artificial intelligence model;
    • use Data for research, benchmarking, product development, or any purpose other than delivering the described integration;
    • sell, license, broker, or otherwise disclose Data to any third party;
    • re-identify, combine, or enrich Data with outside data sets.

    You will not attempt to circumvent access controls, rate limits, tenant scoping, or authentication, and you will not use the Key to probe endpoints outside the integration's stated purpose.

  7. Rate limits and availability

    You will respect published rate limits and honor 429 responses with exponential backoff. You will notify ChartVoyant in advance of any bulk migration or backfill. The API is provided on a commercially reasonable basis; no uptime commitment is made in this Agreement.

  8. Commercial use and profit share

    If the API is used in or in connection with a product or service that you sell, license, offer by subscription, or otherwise commercialize, you will pay Geach Medical PLLC thirty-five percent (35%) of all profits derived from that product or service. Within thirty (30) days after the end of each calendar quarter you will remit the amount due together with a statement showing how it was calculated, and you will keep records sufficient to verify it, which ChartVoyant may review on reasonable notice. ChartVoyant may change this section, including the percentage, at any time by written notice to the technical contact on file; continued use of the Key after notice constitutes acceptance of the change. The Practice's use of the API for its own operations is not commercial use under this section.

  9. HIPAA and business associate obligations

    You acknowledge that Data includes PHI, that the Practice is a covered entity, and that your handling of PHI makes you a business associate of the Practice. You represent that a business associate agreement between you and the Practice is or will be in effect before you access PHI, and that you will comply with it and with the HIPAA Privacy, Security, and Breach Notification Rules. This Agreement does not itself constitute a business associate agreement and does not modify any BAA between ChartVoyant and the Practice.

  10. Security incidents

    You will notify ChartVoyant at info@chartvoyant.com without unreasonable delay, and in any event within twenty-four (24) hours, of any actual or suspected exposure, compromise, loss, or unauthorized use of the Key, and of any security incident affecting Data. Your notice will include the Key prefix and the facts known at the time. ChartVoyant may revoke the Key immediately on such notice. Prompt reporting is expected and will not by itself disqualify you from a replacement Key.

  11. Monitoring and audit

    ChartVoyant records each Key-authenticated request — method, route, response status, source IP, correlation identifier, and duration — and retains that record. Requests against the Practice's records are additionally written to the Practice's own audit trail, which the Practice may review. You consent to this monitoring. On reasonable request you will describe to ChartVoyant or the Practice how Data is stored, secured, and retained by your systems.

  12. Suspension and revocation

    API access is not an entitlement. ChartVoyant may suspend or revoke the Key at any time, with or without cause and without prior notice — including, without limitation, where the Key is implicated in a security incident, is used in breach of this Agreement, or threatens the stability of the platform, or where the Practice requests it. The Practice may likewise direct revocation of any Key bound to it at any time and for any reason. Revocation takes effect on the next request, and no revocation gives rise to any liability of ChartVoyant or the Practice to you.

  13. Term, expiry, and termination

    This Agreement begins on signature and continues while any Key issued under it is active. Each Key carries its own expiry and stops authenticating on that date; a replacement requires a request from the technical contact on file. Either party may terminate this Agreement on thirty (30) days' written notice, or immediately for material breach.

    On termination or revocation you will stop accessing the API, and you will delete or return Data in your possession as directed by the Practice, except where retention is required by law. You will confirm completion in writing on request.

  14. Confidentiality

    Each party will protect the other's non-public information disclosed in connection with this Agreement, using at least reasonable care, and will use it only to perform under this Agreement. Data is the Practice's confidential information. These obligations survive termination.

  15. Changes to the API

    ChartVoyant may change, deprecate, or withdraw API endpoints. We will give the technical contact on file reasonable advance notice of a breaking change except where a shorter timeline is required for security. You are responsible for keeping that contact current.

  16. No warranty

    The API and the sandbox are provided "as is" and "as available", without warranty of any kind, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. Nothing returned by the API is medical advice, and you will not present it as such.

  17. Limitation of liability

    To the maximum extent permitted by law, neither party is liable to the other for indirect, incidental, special, consequential, or punitive damages, or for lost profits or lost data, arising out of this Agreement. ChartVoyant's aggregate liability under this Agreement will not exceed the amounts you paid ChartVoyant for API access in the twelve (12) months preceding the claim, or one hundred dollars ($100) if no amounts were paid. Nothing in this section limits either party's liability for gross negligence, willful misconduct, or breach of confidentiality or HIPAA obligations.

  18. Indemnity

    You will indemnify and hold harmless ChartVoyant and the Practice against claims, losses, and expenses arising from your breach of this Agreement, your misuse of the Key, or your handling of Data in violation of applicable law.

  19. Assignment

    You may not assign this Agreement or transfer a Key, including by merger or change of control, without ChartVoyant's prior written consent. A Key is not an asset that survives a sale of your business.

  20. Governing law

    This Agreement is governed by the laws of the State of Tennessee, without regard to its conflict-of-laws rules. The parties consent to the exclusive jurisdiction of the state and federal courts located in Hamilton County, Tennessee.

  21. Entire agreement

    This Agreement, together with the usage policy published at chartvoyant.com/developers, is the entire agreement between the parties on this subject and supersedes prior discussions. Where the two conflict, this Agreement controls. Amendments must be in writing and signed by both parties. If any provision is held unenforceable, the rest remains in effect.

Signatures

The person signing for the Integrator represents that they are authorized to bind it.

For the Integrator

Signature

Printed name

Title

Organization

Date

For ChartVoyant

Signature

Printed name

Title

Key prefix issued

Date

Return this signed agreement to info@chartvoyant.com. We countersign, file it against the key in our admin console, and issue the credential to the technical contact named above. Questions before you sign are welcome — email the same address.