Legal/Master Services Agreement

Master Services Agreement

Last updated: August 11, 2026

This Master Services Agreement (“MSA”) is between the CPA Retain provider identified in an Order Form (“CPA Retain”) and the customer identified in that Order Form (“Customer”). The MSA, each Order Form, and each incorporated addendum form the “Agreement.”

1. Definitions

1.1 “Authorized User” means an employee or contractor whom Customer authorizes to use the Services for Customer’s internal business and who is assigned a unique account.

1.2 “Customer Data” means information, records, document content, Personal Data, and other material submitted to, accessed through, or processed by the Services on Customer’s behalf. Customer Data excludes Usage Data.

1.3 “Documentation” means CPA Retain’s then-current user instructions and technical materials made available for the Services.

1.4 “Microsoft Environment” means Customer’s Microsoft 365 tenant and its SharePoint, Microsoft Entra ID, Microsoft Graph, and related Microsoft services.

1.5 “Personal Data” means information relating to an identified or identifiable natural person, or any similar term under applicable privacy law.

1.6 “Services” means the hosted CPA Retain platform, features, integrations, support, and implementation services ordered by Customer.

1.7 “Usage Data” means telemetry and analytical information about operation and use of the Services that does not identify Customer, an Authorized User, Customer’s client, or any other individual.

2. Access and Use

2.1 Subject to the Agreement and payment of fees, CPA Retain grants Customer a limited, non-exclusive, non-transferable, non-sublicensable right during the applicable term for Authorized Users to access and use the Services for Customer’s internal business.

2.2 Customer is responsible for Authorized Users, account administration, unique credentials, and promptly disabling access when no longer authorized. Customer will notify CPA Retain promptly of suspected unauthorized access.

2.3 Customer and Authorized Users will not: (a) reverse engineer, decompile, or seek source code except to the limited extent a restriction is prohibited by law; (b) copy, resell, sublicense, time-share, or provide the Services to third parties as a service bureau; (c) bypass access controls or usage limits; (d) interfere with or disrupt the Services; (e) introduce malicious code; (f) access the Services to develop or benchmark a competing offering for publication without consent; or (g) use the Services unlawfully or in violation of third-party rights.

2.4 CPA Retain may update the Services during the term. It will not materially reduce the core functionality purchased in an Order Form during the then-current paid term.

3. Customer Responsibilities and Microsoft Access

3.1 Customer is responsible for its Microsoft Environment, Microsoft licenses, network and endpoint security, data classification, retention settings, backup and recovery choices, and compliance obligations. Customer determines which sites, libraries, folders, and users CPA Retain may access.

3.2 Customer authorizes CPA Retain to access the Microsoft Environment solely through Microsoft-supported authentication and APIs and only to the extent reasonably necessary to provide the Services. Customer or its Microsoft 365 administrator must grant the requested permissions and may revoke them, but revocation may impair or disable affected functions.

3.3 CPA Retain will use commercially reasonable efforts to request permissions consistent with least-privilege principles. Customer is responsible for reviewing and approving the permissions displayed by Microsoft during installation and for maintaining appropriate Microsoft access policies.

3.4 Customer represents that it has all rights, notices, consents, and lawful bases needed for CPA Retain to process Customer Data under the Agreement, including data concerning Customer’s clients, personnel, and tax or financial matters.

4. Fees, Invoicing, and Taxes

4.1 Customer will pay the fees and on the schedule in each Order Form. Unless an Order Form states otherwise, invoices are due 30 days after the invoice date, without setoff or deduction.

4.2 Undisputed overdue amounts may accrue interest at 1.0% per month or the maximum lawful rate, whichever is less. Customer will reimburse reasonable collection costs. Before suspending for nonpayment, CPA Retain will give at least 10 days’ written notice and a reasonable opportunity to cure.

4.3 Customer must dispute an invoice in reasonable detail within 30 days after its date and timely pay all undisputed amounts. The parties will work in good faith to resolve the dispute.

4.4 Fees exclude sales, use, excise, value-added, and similar taxes. Customer is responsible for those taxes other than taxes based on CPA Retain’s net income, property, or employees.

5. Customer Data

5.1 As between the parties, Customer retains all right, title, and interest in Customer Data. CPA Retain receives no ownership interest in Customer Data.

5.2 Customer grants CPA Retain a limited, non-exclusive right to access, use, transmit, and otherwise process Customer Data only to provide, secure, support, and improve the Services for Customer, comply with law, and exercise rights under the Agreement. CPA Retain will not sell Customer Data, use it for targeted advertising, or use Customer document content to train a general-purpose artificial-intelligence model.

5.3 At rest, Customer document files remain in Customer’s SharePoint environment. CPA Retain will not create or maintain a separate persistent repository of Customer document files outside that environment. The Services may transmit document content through Microsoft services and process it as necessary to perform Customer-requested functions.

5.4 Customer controls retention, legal hold, export, and deletion of document files in its Microsoft Environment. Customer remains able to access those files directly through Microsoft 365 independent of CPA Retain, subject to Customer’s Microsoft subscription and configuration.

5.5 CPA Retain may create and use Usage Data for security, capacity planning, support, analytics, and improvement, provided that it remains de-identified and is not used to identify Customer, its clients, or individuals.

6. Privacy and Security

6.1 Each party will comply with privacy and data-protection laws applicable to its performance. To the extent CPA Retain processes Personal Data for Customer, Customer acts as controller or business and CPA Retain acts as processor or service provider, as those terms are used under applicable law.

6.2 CPA Retain will maintain a written information-security program with administrative, technical, and physical safeguards appropriate to the nature of the Services and the sensitivity of Customer Data it processes. The Data & Security Addendum states the minimum contractual safeguards.

6.3 If processing subject to the GDPR, UK GDPR, or another law requires additional terms or a cross-border transfer mechanism, the parties will execute an appropriate data-processing addendum before that processing. Nothing in the Agreement represents that CPA Retain is Customer’s compliance officer or guarantees Customer’s compliance.

7. Confidentiality

7.1 “Confidential Information” means nonpublic information disclosed by or for a party that is marked confidential or reasonably should be understood as confidential. Customer Data is Customer’s Confidential Information. The Services, Documentation, security materials, pricing, and nonpublic product information are CPA Retain’s Confidential Information.

7.2 The receiving party will: (a) use Confidential Information only to perform or exercise rights under the Agreement; (b) protect it with at least reasonable care and no less than the care used for its own similar information; and (c) disclose it only to personnel, professional advisers, and subcontractors who need to know it and are bound by confidentiality obligations.

7.3 Confidential Information excludes information the receiving party can document: (a) is public without breach; (b) was lawfully known without restriction; (c) was received lawfully from a third party without duty; or (d) was independently developed without use of the Confidential Information.

7.4 A receiving party may disclose Confidential Information when legally required if, to the extent permitted, it gives prompt notice and reasonable assistance so the disclosing party may seek protection. The receiving party will disclose only what is legally required.

7.5 Unauthorized use or disclosure may cause irreparable harm for which monetary damages are inadequate; the disclosing party may seek appropriate equitable relief without waiving other remedies.

8. Intellectual Property

8.1 CPA Retain and its licensors retain all rights in the Services, Documentation, designs, software, workflows, know-how, and improvements. No rights are granted except those expressly stated.

8.2 If Customer voluntarily provides suggestions or feedback, Customer grants CPA Retain a perpetual, worldwide, irrevocable, royalty-free right to use it without restriction, provided CPA Retain does not identify Customer as its source without permission.

8.3 No party may use the other party’s name, logo, or marks in publicity without prior written consent. CPA Retain may identify Customer privately to service providers and advisers as needed to perform the Agreement.

9. Third-Party Services and Integrations

9.1 The Services interoperate with third-party products, including Microsoft 365, SharePoint, ShareFile, SafeSend, and e-signature services. Customer’s use of third-party products is governed by Customer’s agreements with those providers.

9.2 CPA Retain is not responsible for a third-party service’s acts, omissions, security, availability, changes, or discontinuation. CPA Retain will use commercially reasonable efforts to maintain supported integrations but does not guarantee uninterrupted interoperability.

9.3 A failure caused by Customer’s systems, the Microsoft Environment, an integration provider, internet or utility service, or another circumstance outside CPA Retain’s reasonable control is not a breach of an availability or support commitment.

10. Support and Availability

10.1 CPA Retain will provide the support level in the Order Form. Response times are targets for initial response, not guaranteed resolution times, unless the Order Form expressly states a service credit.

10.2 CPA Retain will use commercially reasonable efforts to keep the Services available and to give advance notice of planned maintenance when practicable. Services may be unavailable for maintenance, emergency work, security response, or third-party outages.

10.3 Customer will provide information and cooperation reasonably needed to reproduce and resolve an issue. Support does not include custom development, data remediation, Microsoft administration, legal advice, or professional accounting services unless separately ordered.

11. Warranties and Disclaimers

11.1 Each party warrants that it has authority to enter into the Agreement. CPA Retain warrants that it will perform implementation and support services professionally and that the hosted Services will operate in material conformity with the Documentation under normal authorized use.

11.2 If Customer gives reasonably detailed notice of a breach of Section 11.1, CPA Retain will use commercially reasonable efforts to correct the nonconformity. If CPA Retain cannot do so within a reasonable period, Customer may terminate the affected Service and receive a prorated refund of prepaid unused fees for it. This is Customer’s exclusive remedy for breach of Section 11.1.

11.3 CPA Retain provides technology tools, not legal, tax, accounting, audit, records-management, or compliance advice. Customer is solely responsible for professional judgments, client deliverables, filing and retention duties, supervision, and verifying outputs before reliance.

11.4 EXCEPT FOR THE EXPRESS WARRANTIES IN THIS SECTION, THE SERVICES ARE PROVIDED “AS IS” AND “AS AVAILABLE.” TO THE MAXIMUM EXTENT PERMITTED BY LAW, CPA RETAIN DISCLAIMS ALL IMPLIED WARRANTIES, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, NON-INFRINGEMENT, AND ANY WARRANTY THAT THE SERVICES WILL BE UNINTERRUPTED, ERROR-FREE, OR MEET CUSTOMER’S PARTICULAR REQUIREMENTS.

12. Suspension, Termination, and Effect

12.1 Either party may terminate an Order Form or the MSA for material breach if the breach remains uncured 30 days after written notice. The cure period for nonpayment is 10 days after written notice. Either party may terminate immediately if the other enters liquidation, makes a general assignment for creditors, or becomes subject to an insolvency proceeding not dismissed within 60 days.

12.2 CPA Retain may suspend affected access to prevent or address a security threat, unlawful use, material prohibited use, or nonpayment after the applicable notice. When practicable, CPA Retain will limit the suspension, give advance notice, and restore access after the issue is resolved.

12.3 Upon expiration or termination: (a) Customer’s right to use the Services ends; (b) each party will return or destroy the other’s Confidential Information on request, subject to legal retention and routine backups; (c) Customer remains responsible for accrued fees; and (d) document files remain in Customer’s Microsoft Environment.

12.4 If Customer terminates for CPA Retain’s uncured material breach, CPA Retain will refund prepaid fees allocable to the unused period after termination. If CPA Retain terminates for Customer’s breach, or Customer stops using the Services without a contractual termination right, remaining committed fees become due to the extent permitted by law.

12.5 Sections that by their nature should survive will survive, including payment obligations, Customer Data ownership, confidentiality, intellectual property, disclaimers, indemnification, limitations of liability, effect of termination, and general terms.

13. Indemnification

13.1 CPA Retain will defend Customer against a third-party claim alleging that Customer’s authorized use of the Services infringes a United States patent, copyright, or trademark or misappropriates a trade secret, and will pay damages and reasonable costs finally awarded or agreed in a settlement approved by CPA Retain.

13.2 CPA Retain has no obligation for a claim arising from Customer Data, Customer instructions, unauthorized use, modification not made by CPA Retain, or combination with items not supplied or approved by CPA Retain where the claim would not otherwise arise. If an infringement claim is likely, CPA Retain may procure continued use, modify or replace the affected Service, or terminate it and refund prepaid unused fees.

13.3 Customer will defend CPA Retain against a third-party claim arising from Customer Data, Customer’s violation of law or third-party rights, or Customer’s prohibited or unauthorized use of the Services, and will pay damages and reasonable costs finally awarded or agreed in a settlement approved by Customer.

13.4 The indemnified party must give prompt notice, reasonable cooperation at the indemnifying party’s expense, and control of defense and settlement. Delay in notice relieves obligations only to the extent materially prejudicial. No settlement may admit fault by or impose nonmonetary obligations on the indemnified party without its written consent.

14. Limitation of Liability

14.1 TO THE MAXIMUM EXTENT PERMITTED BY LAW, NEITHER PARTY WILL BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, PUNITIVE, OR CONSEQUENTIAL DAMAGES; LOST PROFITS, REVENUE, GOODWILL, OR BUSINESS; OR COSTS OF SUBSTITUTE SERVICES, EVEN IF ADVISED OF THEIR POSSIBILITY.

14.2 EXCEPT FOR THE ENHANCED CAP IN SECTION 14.3 AND EXCLUDED CLAIMS IN SECTION 14.4, EACH PARTY’S TOTAL AGGREGATE LIABILITY ARISING OUT OF THE AGREEMENT WILL NOT EXCEED THE FEES PAID OR PAYABLE UNDER THE AFFECTED ORDER FORM DURING THE 12 MONTHS BEFORE THE FIRST EVENT GIVING RISE TO LIABILITY.

14.3 Each party’s total aggregate liability for breach of confidentiality, its indemnification obligations, or a Security Incident caused by its failure to comply with the Data & Security Addendum will not exceed two times the amount stated in Section 14.2.

14.4 The exclusions and caps do not apply to: (a) Customer’s payment obligations; (b) a party’s fraud, willful misconduct, or gross negligence; (c) Customer’s violation of Section 2.3; or (d) liability that law does not permit the parties to limit.

14.5 The limitations apply to the aggregate of all claims and regardless of legal theory or failure of an exclusive remedy’s essential purpose. The parties agree that the fees reflect this allocation of risk.

15. Compliance

15.1 Each party will comply with laws applicable to its performance. Customer remains responsible for laws, professional standards, engagement terms, and ethical duties applicable to its practice and Customer Data, including requirements concerning taxpayer and other confidential client information.

15.2 Customer will not use or permit access to the Services in violation of U.S. export-control or economic-sanctions laws. Each party will comply with applicable anti-bribery and anti-corruption laws.

16. General

16.1 Governing Law; Venue. The Agreement is governed by the laws of the State of Texas, without regard to conflict-of-law rules. The state and federal courts located in [COUNTY, TEXAS] have exclusive jurisdiction, and each party consents to personal jurisdiction and venue there. The United Nations Convention on Contracts for the International Sale of Goods does not apply.

16.2 Notices. Formal notices must be in writing and delivered by personal delivery, nationally recognized overnight courier, certified U.S. mail, or email with confirmation of receipt. Notices to CPA Retain must be sent to [CPA RETAIN NOTICE ADDRESS] and [LEGAL NOTICE EMAIL]. Notices to Customer must be sent to the address and primary contact in the Order Form. Notices are effective on receipt.

16.3 Assignment. Neither party may assign the Agreement without the other’s consent, not to be unreasonably withheld, except to an affiliate or in connection with a merger, reorganization, change of control, or sale of substantially all assets relating to the Agreement, upon written notice and assumption by the assignee. An assignment to a direct competitor of the nonassigning party requires consent.

16.4 Force Majeure. Neither party is liable for delay or failure caused by events beyond its reasonable control, except for payment obligations. The affected party will give prompt notice and use reasonable efforts to mitigate. If a material failure continues more than 60 days, either party may terminate the affected Service without penalty and Customer will receive a prorated refund of prepaid unused fees.

16.5 The parties are independent contractors. The Agreement creates no partnership, agency, fiduciary, employment, franchise, or joint venture relationship. There are no third-party beneficiaries.

16.6 The Agreement is the entire agreement on its subject and supersedes prior proposals and discussions. Purchase-order terms do not apply. An amendment or waiver must be in a writing signed by authorized representatives, except that an Order Form may expressly authorize an operational change by email.

16.7 If a provision is unenforceable, it will be enforced to the maximum lawful extent and the remainder will continue. A waiver on one occasion is not a waiver on another. Headings are for convenience. “Including” means “including without limitation.”

16.8 The Agreement may be executed electronically and in counterparts, each of which is deemed an original and all of which form one instrument.

16.9 Attorneys' Fees. In any action or proceeding to enforce rights under the Agreement, the prevailing party will be entitled to recover its reasonable attorneys' fees and costs, in addition to any other relief to which it may be entitled.

Exhibit A — Data & Security Addendum

This Addendum forms part of the Agreement and applies to Customer Data processed by CPA Retain.

A1. Processing Scope and Instructions

1.1 CPA Retain will process Customer Data only on Customer’s documented instructions embodied in the Agreement, Customer’s configuration and use of the Services, and other written instructions consistent with the Agreement. If CPA Retain believes an instruction violates applicable law, it may suspend that instruction and notify Customer unless prohibited.

1.2 The subject matter is provision of the Services; the duration is the applicable term plus the limited deletion period below; the purpose is document management, workflow, PDF, e-signature, integration, support, security, and related administration. Data subjects may include Customer personnel, clients, prospects, vendors, and other persons represented in Customer Data.

1.3 Customer Data may include identity, contact, financial, tax, payroll, employment, signature, authentication, professional, and other information selected by Customer. Customer will not provide data that the Services are not designed to process without first confirming appropriate safeguards in writing.

A2. Microsoft-Centered Data Architecture

2.1 Customer document files and their content at rest remain in Customer’s SharePoint environment within Customer’s Microsoft 365 tenant. CPA Retain does not maintain a separate persistent document repository.

2.2 The Services use Microsoft Entra authentication and Microsoft Graph or other Microsoft-supported interfaces. Access is limited by the permissions Customer grants and by Customer’s Microsoft configuration. Depending on the integration mode, Microsoft may require tenant-administrator consent.

2.3 CPA Retain may maintain limited operational records outside Customer’s SharePoint libraries, such as tenant and user identifiers, configuration, workflow status, document references, audit events, support records, telemetry, billing records, and security logs. CPA Retain will minimize those records to what is reasonably necessary.

2.4 Customer is responsible for selecting Microsoft licensing, geography, retention, encryption, backup, legal hold, access, and compliance settings appropriate to its obligations. Microsoft’s processing is governed by Customer’s agreement with Microsoft.

A3. Security Program

3.1 CPA Retain will maintain reasonable safeguards designed to protect the confidentiality, integrity, and availability of Customer Data it processes, including: access controls based on least privilege; multi-factor authentication for privileged access; encryption in transit using current industry-standard protocols; encryption at rest for operational Customer Data; logging and monitoring; vulnerability and patch management; secure development and change controls; malware protection where appropriate; personnel security and confidentiality obligations; business continuity; and a written incident-response process.

3.2 CPA Retain will periodically assess material risks to Customer Data and adjust safeguards in light of material changes, known threats, and the nature and scale of processing. CPA Retain will train personnel with access to Customer Data on relevant security and privacy responsibilities.

3.3 CPA Retain will not materially weaken the safeguards in this Addendum during a paid term.

A4. Security Incidents

4.1 A “Security Incident” means confirmed unauthorized access to, acquisition of, or disclosure, alteration, or destruction of Customer Data in CPA Retain’s control. It excludes unsuccessful attempts, Customer-caused events, and incidents confined to Customer’s Microsoft Environment unless caused by CPA Retain’s breach.

4.2 CPA Retain will notify Customer without undue delay and, where feasible, within 72 hours after confirming a Security Incident. Notice will include information reasonably available about the nature, affected data and persons, likely consequences, containment and remediation, and a contact for follow-up. CPA Retain may provide information in phases and will not delay initial notice solely because an investigation is incomplete.

4.3 CPA Retain will promptly investigate, contain, mitigate, remediate, and reasonably cooperate with Customer. CPA Retain will not notify Customer’s clients, regulators, or the public on Customer’s behalf unless legally required or Customer authorizes it. Customer is responsible for determining its own notification duties.

4.4 Notice of a Security Incident is not an admission of fault or liability.

A5. Service Providers and Personnel

5.1 CPA Retain may use affiliates and service providers to perform the Services. It will conduct risk-based diligence, require written confidentiality and security obligations appropriate to their services, limit access to need, and remain responsible for their performance to the same extent as for its own.

5.2 Upon reasonable request, CPA Retain will provide a current list of material service providers that process Customer Data. If Customer reasonably objects to a new provider on documented data-protection grounds, the parties will work in good faith on a commercially reasonable alternative; if none is available, either party may terminate the affected Service and CPA Retain will refund prepaid unused fees.

A6. Return, Deletion, and Retention

6.1 Because document files remain in Customer’s Microsoft Environment, Customer is responsible for preserving and exporting them before revoking CPA Retain access. At termination, CPA Retain will revoke or disable its access to Customer’s Microsoft Environment.

6.2 On written request or within 60 days after termination, CPA Retain will delete operational Customer Data in its active systems, except information it must retain by law, for billing or dispute records, or in secure backups. Retained data remains protected and will be deleted under ordinary backup cycles or isolated from further use.

A7. Verification and Assistance

7.1 No more than once annually, and additionally after a material Security Incident, CPA Retain will respond to a reasonable written security questionnaire and provide available summaries of relevant independent assessments or policies, subject to confidentiality and security restrictions.

7.2 Customer will not conduct penetration testing or scan the Services without prior written authorization. If legally required verification cannot reasonably be satisfied by documentation, the parties will agree on a scoped independent assessment during normal business hours, avoiding disruption and exposure of other customers’ information. Customer bears its costs unless the assessment identifies a material uncured breach by CPA Retain.

7.3 Taking into account the nature of processing and information available, CPA Retain will provide reasonable assistance with Customer’s legally required security assessments, data-subject requests, and regulatory inquiries. Material assistance beyond standard Services may be billed at agreed rates if caused by Customer’s configuration, instructions, or obligations rather than CPA Retain’s breach.

A8. Customer Security Duties

8.1 Customer will maintain appropriate Microsoft 365 security, including administrator controls, strong authentication, prompt deprovisioning, endpoint and network safeguards, permission reviews, retention and backup settings, and monitoring appropriate to the sensitivity of its data.

8.2 Customer will promptly notify CPA Retain of suspected compromise affecting the Services or granted Microsoft permissions and will cooperate in containment. Customer is responsible for Security Incidents caused by Customer’s credentials, configuration, users, systems, or failure to follow reasonable security instructions, except to the extent caused by CPA Retain.

A9. Addendum Priority

9.1 If this Addendum conflicts with the MSA on privacy, security, or Customer Data handling, this Addendum controls. Liability remains subject to the MSA unless this Addendum expressly states otherwise.