Draft — pending legal review. This document is a template and has not yet been reviewed or approved by qualified legal counsel. Bracketed placeholders must be completed before publication. It does not constitute legal advice.
1. Acceptance and Authorized Use
These Terms of Service (the “Terms”) govern access to and use of the DODD Agency Pro platform, websites, and related services (collectively, the “Service”). By creating an account, accessing, or using the Service, the customer organization (the “Customer”) and each individual user agree to these Terms. If you do not agree, do not use the Service.
The Service is intended solely for authorized use by Ohio DODD provider agencies and their authorized workforce members in the course of their compliance and operational duties. Access is licensed, not sold, and is limited to the scope described in these Terms and any applicable order or subscription.
2. Account Security and Credentials
Each user is responsible for safeguarding their login credentials and for all activity that occurs under their account. Users must use strong, unique passwords and enable any additional authentication controls the Service makes available.
Credentials must not be shared. Each individual accessing the Service must have their own distinct account. Sharing logins, using another person's credentials, or allowing an unauthorized person to use the Service under your account is prohibited. Customers must promptly deactivate accounts for workforce members who no longer require access.
3. Customer Responsibility for Access, Lawful Use, and Minimum Necessary
The Customer is solely responsible for:
- Access and permissions. Determining who within its organization may access the Service, assigning appropriate roles, and reviewing those permissions on a regular basis. The Customer is responsible for the actions of its authorized users.
- Lawful use. Using the Service in compliance with all applicable federal and state laws and regulations, including the HIPAA Privacy, Security, and Breach Notification Rules and current guidance from the U.S. Department of Health and Human Services Office for Civil Rights, as well as applicable Ohio DODD requirements.
- Minimum necessary. Limiting the information it enters and accesses to the minimum necessary to accomplish the intended purpose, consistent with the HIPAA minimum necessary standard and the data-entry limitations in Section 4.
4. Data-Entry Limitations and Prohibited Information
Client-related features expose defined fields for specific operational workflows. Client Compliance Tracking encrypts client names at rest; its other bounded fields and other enabled client modules may rely on tenant and role-based access controls. Customers must not attempt to enter information a feature is not designed to hold.
Customers may enter client information only into the fields expressly provided for that purpose. Do not place medical, diagnostic, Medicaid, billing, contact, service-documentation, incident, or other sensitive details into unrelated names, notes, attachments, or free-text fields.
This limitation applies to every field of the Service. Do not place prohibited information in name fields, notes, attachments, or any other input. Entering prohibited information violates these Terms and may constitute an impermissible use or disclosure for which the Customer is responsible.
5. Business Associate Agreement Precedence
Where DODD Agency Pro and a Customer execute a Business Associate Agreement (“BAA”), that agreement governs the permitted uses and disclosures of that information and the safeguards each party must maintain.
To the extent any term of these Terms conflicts with the executed BAA between the Customer and DODD Agency Pro regarding the handling of protected health information, the terms of the BAA control. All other terms of these Terms remain in full force and effect.
6. Security Responsibilities
Security is a shared responsibility. DODD Agency Pro maintains administrative, physical, and technical safeguards for the portions of the Service it operates, including encryption of the stored client name. The Customer remains responsible for the security of everything within its own control, including but not limited to:
- Device and endpoint security for computers and mobile devices used to access the Service.
- Network security, screen-lock, and physical safeguards at Customer locations.
- Workforce training on privacy, security, and appropriate use of the Service.
- Account provisioning, role assignment, and timely deactivation of access.
The Customer's designated security and privacy personnel are responsible for the Customer's risk analysis, policies, and safeguard decisions.
7. Incident Reporting
Customers must promptly report any suspected or actual security incident, unauthorized access, lost or stolen device, or improper use or disclosure involving the Service to DODD Agency Pro at support@doddagencypro.com with “Security” in the subject line. Reporting timelines and obligations related to protected health information are further governed by the BAA.
Customers must not use the reporting channel to transmit prohibited information described in Section 4; describe incidents without including protected health information.
8. Acceptable Use
Customers and users must not:
- Enter information prohibited under Section 4 or use the Service for any unlawful purpose.
- Attempt to access data, accounts, or organizations other than their own, or circumvent access controls.
- Probe, scan, or test the vulnerability of the Service, or interfere with or disrupt its integrity or performance, except under a written authorization from DODD Agency Pro.
- Reverse engineer, copy, resell, or create derivative works from the Service except as permitted by law.
- Upload malicious code or use the Service to transmit unlawful, infringing, or harmful content.
9. Suspension for Threats
DODD Agency Pro may suspend or restrict access, in whole or in part, without prior notice where it reasonably believes doing so is necessary to protect the security, integrity, or availability of the Service or the data of other customers — for example, in response to a suspected compromise, active attack, or entry of prohibited information. We will endeavor to limit the scope and duration of any suspension to what is reasonably necessary and to notify the affected Customer.
10. Data Ownership
As between the parties, the Customer owns the data it enters into the Service. DODD Agency Pro claims no ownership of Customer data and processes it only to provide the Service, as permitted by these Terms and the BAA, and as required by law.
11. Data Export
During an active subscription, the Customer may export its data through the export functionality the Service provides. Customers are responsible for handling exported data securely and in accordance with their own obligations, including the HIPAA minimum necessary standard.
12. Retention and Deletion
The Service retains active and archived operational records to provide the product and preserve review history. Post-termination retention, return, deletion, and any certification or timeline are governed by the applicable order, BAA, or other written agreement.
13. Termination
Either party may terminate a subscription in accordance with the applicable order or subscription terms. DODD Agency Pro may suspend or terminate access for a material breach of these Terms, including entry of prohibited information or unlawful use, subject to the security suspension provisions in Section 9.
Upon termination, the Customer's right to access the Service ends. Data handling after termination is governed by Sections 11 and 12 and the BAA.
14. Subprocessors
DODD Agency Pro uses third-party providers for hosting, communications, AI-assisted features, and payment processing. The current providers and their application-supported data paths are described on the Subprocessors page. Applicable written agreements govern additional obligations.
15. No Automatic Compliance Guarantee
The Service is designed to support HIPAA-compliant operations, and HIPAA compliance is a shared responsibility between DODD Agency Pro and the Customer. Use of the Service does not, by itself, make any organization compliant with HIPAA, DODD requirements, or any other legal obligation.
DODD Agency Pro does not automatically make a customer HIPAA compliant. Each customer remains responsible for its own risk analysis, policies, workforce training, device security, access decisions, legal obligations, and appropriate use of the platform.
The Service is provided without any representation, certification, or guarantee of compliance. The Customer is responsible for determining whether its use of the Service meets its own legal and regulatory obligations and should consult qualified counsel as needed.
Questions about these Terms can be directed to your account contact or through our contact page. Reports of security incidents should be sent to support@doddagencypro.com with “Security” in the subject line.