Master Service Agreement

This Master Services Agreement (“MSA”) governs all services provided by Keystone Business Solutions, LLC (“Keystone”) to any customer (“Customer”).

By engaging Keystone for any services, signing any service agreement, or continuing to use Keystone’s services, Customer agrees to be bound by this MSA. This MSA applies to and supersedes any conflicting terms in individual service agreements unless explicitly stated otherwise in writing.

Keystone Business Solutions Master Services Agreement

Effective Version Date: 8/1/2026

This Master Services Agreement is entered into by and between Keystone Business Solutions, LLC, a Tennessee limited liability company with offices located at 3050 Business Park Circle, Suite 301, Goodlettsville, Tennessee 37072, and the customer identified in an applicable quote, proposal, service agreement, statement of work, invoice, order form, or other written ordering document that references this Master Services Agreement.

Keystone Business Solutions, LLC may be referred to in this Agreement as “Keystone,” “Provider,” “we,” “us,” or “our.” The customer may be referred to as “Customer,” “you,” or “your.” Keystone and Customer may each be referred to as a “Party” and collectively as the “Parties.”

By signing, approving, accepting, paying, or otherwise proceeding with any quote, proposal, service agreement, statement of work, invoice, order form, or other document that references this Master Services Agreement, Customer agrees that all services, products, software, hardware, licenses, subscriptions, consulting, support, procurement, project work, and related deliverables provided by Keystone are governed by this Master Services Agreement, together with the applicable service agreement, quote, proposal, statement of work, invoice, or order form.

Purpose and Scope of Agreement

This Master Services Agreement establishes the general terms and conditions that apply to all services and offerings provided by Keystone to Customer. This Agreement is intended to serve as the master legal framework for Keystone’s relationship with Customer and may apply to managed IT services, cybersecurity services, Microsoft 365 services, cloud services, backup and disaster recovery services, hardware and software procurement, licensing, consulting, compliance support, project services, vendor coordination, network services, VoIP support, and any other services or products provided, resold, facilitated, or managed by Keystone.

Specific services, pricing, included support, exclusions, quantities, locations, covered users, covered devices, service levels, and special terms will be described in the applicable service agreement, quote, proposal, statement of work, invoice, or order form. If there is a conflict between this Master Services Agreement and a signed service agreement or statement of work, the signed service agreement or statement of work will control only as to the specific conflicting term. All other provisions of this Master Services Agreement will continue to apply.

Services

Keystone will provide the services described in the applicable quote, proposal, service agreement, statement of work, invoice, or order form. Services may include remote support, onsite support, monitoring, patch management, endpoint protection, cybersecurity tools, Microsoft 365 administration, licensing support, vendor coordination, hardware procurement, software procurement, network support, server support, workstation support, backup and disaster recovery services, consulting, project work, and other technology-related services.

Keystone will use commercially reasonable efforts to perform services in a professional and workmanlike manner. Customer understands and agrees that managed IT services and cybersecurity services are risk management services, not absolute guarantees of uninterrupted operation, perfect security, complete data recovery, or prevention of every technical issue.

Unless specifically stated in a signed service agreement, quote, proposal, or statement of work, services do not include hardware, software, licensing, subscriptions, cloud services, carrier services, internet service, third-party vendor fees, regulatory filings, legal services, data recovery beyond standard restoration efforts, major infrastructure changes, new system implementations, or project work.

Service Agreements, Quotes, and Statements of Work

Customer may enter into one or more service agreements, quotes, proposals, statements of work, order forms, or invoices with Keystone. Each such document will be governed by this Master Services Agreement, whether signed electronically, signed in hard copy, approved by email, approved through a procurement system, paid by Customer, or otherwise accepted by Customer.

Project work, including but not limited to server replacements, network upgrades, office moves, security remediation projects, cloud migrations, cabling coordination, major software deployments, workstation refreshes, and new site deployments, will be quoted separately. Project work will be governed by this Master Services Agreement and the applicable quote, proposal, or statement of work.

Keystone is not obligated to begin work on any project, procurement request, or out-of-scope service until Customer has approved the applicable quote or statement of work and satisfied any required deposit, prepayment, or authorization requirement.

Term

The term of each service relationship will be stated in the applicable service agreement, quote, proposal, statement of work, invoice, or order form. For new managed services clients, Keystone may require an initial commitment term as stated in the applicable service agreement.

If no specific term is stated, services will continue on a month-to-month basis until terminated in accordance with this Agreement or the applicable service agreement.

At the end of any initial term, managed services may automatically renew for successive renewal terms as stated in the applicable service agreement. If the applicable service agreement does not specify a renewal term, services will renew on a month-to-month basis unless either Party gives written notice of non-renewal or termination as required by this Agreement.

Fees, Invoicing, and Payment

Customer agrees to pay all fees, charges, expenses, taxes, and other amounts described in the applicable service agreement, quote, proposal, statement of work, invoice, or order form. Unless otherwise stated in writing, recurring services are billed monthly, and additional billable services, products, licenses, subscriptions, hardware, software, project work, after-hours work, emergency support, travel, and other charges may be billed separately.

Invoices are sent by email to the billing contact designated by Customer. Customer is responsible for keeping billing contact information current. Payment is due within ten days of receipt of invoice unless a different payment term is stated in writing.

Undisputed balances more than twenty days overdue may incur interest at the rate of 1.75 percent per month or the maximum amount permitted by law, whichever is less. Customer is responsible for all reasonable costs of collection, including attorney’s fees, court costs, collection agency fees, and administrative costs incurred by Keystone in collecting unpaid amounts.

If Customer disputes any portion of an invoice, Customer must provide written notice of the dispute within ten days of receipt of the invoice. The notice must describe the disputed amount and the basis for the dispute in reasonable detail. All undisputed amounts remain due by the original due date. Failure to dispute an invoice within the stated period will be deemed acceptance of the invoice.

Keystone may require prepayment, deposits, stored payment methods, ACH authorization, or other payment arrangements for certain services, projects, hardware, software, licensing, subscriptions, or customers based on credit history, scope of work, vendor requirements, or other reasonable business considerations.

Taxes

Customer is responsible for all applicable sales, use, excise, privilege, gross receipts, value-added, and other taxes, duties, fees, or governmental charges arising from the services, products, licenses, hardware, software, subscriptions, or other items provided under this Agreement, except for taxes based solely on Keystone’s net income.

If Customer is tax exempt, Customer must provide a valid tax exemption certificate to Keystone before the applicable invoice is issued. Tax exemption certificates should be sent to accounting@wearekeystone.com. Keystone is not responsible for refunding taxes after invoicing if Customer fails to timely provide valid exemption documentation.

Rate Changes and Vendor Price Changes

Keystone may adjust service rates, recurring charges, hourly rates, security fees, infrastructure fees, license fees, subscription fees, and other charges by providing at least thirty days’ written notice to Customer unless the applicable service agreement states otherwise. Continued use of services after the effective date of the rate change constitutes acceptance of the revised rates.

Third-party vendor pricing may change with limited or no advance notice. Customer agrees that Keystone may pass through vendor price increases, licensing changes, subscription changes, currency adjustments, shipping charges, taxes, and other third-party cost changes. Keystone will use reasonable efforts to provide notice of material vendor price changes when practicable, but Keystone is not responsible for absorbing vendor increases.

Customer Responsibilities

Customer agrees to cooperate with Keystone and to provide timely access to personnel, systems, facilities, accounts, licenses, credentials, documentation, vendors, data, and information reasonably necessary for Keystone to perform services. Customer is responsible for the accuracy and completeness of information provided to Keystone.

Customer agrees to maintain valid software licenses, supported hardware, supported operating systems, active vendor subscriptions, current warranties when applicable, and appropriate administrative access. Customer must promptly notify Keystone of material changes to Customer’s environment, including new users, terminated users, new devices, removed devices, new locations, vendor changes, software changes, internet changes, security incidents, suspected compromise, regulatory concerns, or business changes that may affect services.

Customer agrees to follow reasonable security, operational, and technical recommendations issued by Keystone. If Customer declines, delays, disables, bypasses, or fails to implement recommended controls, Customer accepts the risk associated with that decision and Keystone will not be responsible for resulting outages, incidents, data loss, security events, compliance failures, or business impacts.

Mandatory Security Standards

Keystone may establish and update mandatory security standards for customers receiving managed services, cybersecurity services, Microsoft 365 administration, monitoring, endpoint support, or related technology services. These standards may include, without limitation, endpoint detection and response, antivirus or endpoint protection, patch management, monitoring and alerting, multi-factor authentication, DNS filtering, supported operating systems, supported software, secure administrative access, vendor-supported hardware, encryption, password standards, firewall standards, backup standards, and other security controls Keystone determines are reasonably necessary.

Customer agrees that Keystone’s security suite and baseline controls may be mandatory for certain service levels. Keystone may require Customer to implement or maintain endpoint detection and response, patch management, monitoring and alerting, multi-factor authentication, Windows 11 Pro or another supported business-grade operating system, and other controls as a condition of receiving service.

Keystone may decline to support, limit support for, or require remediation of unsupported systems, end-of-life operating systems, consumer-grade equipment, unlicensed software, unsupported software, insecure configurations, unmanaged devices, devices outside of Keystone’s approved toolset, or environments that do not meet Keystone’s minimum security standards.

If Customer refuses or fails to implement required security controls, Keystone may suspend services, exclude affected systems from support, require Customer to sign a written risk acceptance, terminate the applicable service agreement, or continue providing services only on a limited or best-effort basis. Keystone will not be liable for any incident, loss, outage, breach, data loss, or business impact arising from Customer’s refusal or failure to implement required or recommended controls.

Cybersecurity Disclaimer

Customer acknowledges that no technology provider, managed services provider, cybersecurity platform, firewall, endpoint tool, monitoring system, backup solution, user training program, security policy, or combination of controls can guarantee complete protection against all threats. Keystone does not warrant or represent that Customer’s systems, data, users, network, email, cloud services, or business operations will be immune from cyberattacks, ransomware, malware, phishing, business email compromise, wire fraud, credential theft, insider threats, social engineering, zero-day vulnerabilities, supply-chain attacks, nation-state attacks, unauthorized access, data loss, or other security incidents.

Keystone’s services are designed to reduce risk, improve manageability, and support Customer’s technology environment. They are not a guarantee of security, compliance, uptime, recoverability, or uninterrupted operations. Customer remains responsible for its business decisions, user behavior, internal policies, financial controls, regulatory obligations, insurance coverage, vendor relationships, and risk tolerance.

Keystone will not be liable for cyber incidents, security breaches, data loss, unauthorized access, fraudulent transfers, business interruption, reputational harm, regulatory claims, or other losses except to the extent directly caused by Keystone’s gross negligence or willful misconduct.

Backup and Disaster Recovery

Backup, disaster recovery, business continuity, retention, recovery testing, and restoration services are included only if specifically stated in the applicable service agreement, quote, proposal, statement of work, or invoice. Customer understands that not every service plan includes backup services, full image backups, server backups, cloud backups, disaster recovery testing, or business continuity planning.

If backup services are included, Keystone will provide those services according to the scope, retention settings, systems, platforms, and service level described in the applicable service agreement or quote. Unless expressly stated in writing, backup services do not guarantee restoration of every file, system, application, configuration, database, or business function.

Customer is responsible for communicating its recovery requirements, retention obligations, compliance requirements, critical systems, acceptable downtime, acceptable data loss, and business continuity needs. Keystone is not responsible for unmet recovery expectations, regulatory retention obligations, or business continuity requirements that were not disclosed to Keystone in writing and included in the applicable service scope.

Customer acknowledges that backups may fail due to factors outside Keystone’s reasonable control, including hardware failure, software defects, vendor outages, internet failure, cloud platform issues, data corruption, ransomware, encryption events, customer changes, insufficient storage, deleted data, unsupported systems, misconfigured third-party applications, or Customer’s failure to follow Keystone’s recommendations.

Support Availability

Keystone’s standard business hours are Monday through Friday, 7:00 a.m. to 6:00 p.m. Central Time, excluding holidays observed by Keystone, unless otherwise stated in the applicable service agreement.

After-hours support, emergency support, weekend support, holiday support, and expedited response may be billed separately at Keystone’s then-current rates unless specifically included in the applicable service agreement. Keystone may determine whether a request qualifies as an emergency based on the nature of the issue, business impact, security risk, staffing availability, and service plan.

Keystone does not guarantee immediate response, onsite availability, resolution time, or uninterrupted access unless a specific service level agreement is expressly included in a signed service agreement.

Out-of-Scope Services

Unless specifically included in the applicable service agreement, out-of-scope services will be billed separately. Out-of-scope services may include major infrastructure changes, new system implementations, server replacements, office moves, cloud migrations, specialized consulting, compliance documentation, security remediation projects, cabling, extensive vendor coordination, data recovery, litigation support, forensic investigation, custom reporting, unsupported system work, and any work Keystone identifies as project work.

Keystone may provide an estimate, quote, or statement of work for out-of-scope services before beginning work. Keystone’s determination of whether a request is included, excluded, recurring, project-based, emergency, or otherwise billable will be final and binding.

Hardware, Software, Licensing, and Third-Party Products

Customer is solely responsible for the cost of all hardware, software, licenses, subscriptions, cloud services, carrier services, warranties, vendor support, renewals, and third-party products required for Customer’s environment. This includes items purchased directly by Customer and items procured, resold, facilitated, or managed by Keystone on Customer’s behalf.

From time to time, Keystone may resell, provide access to, recommend, configure, support, or facilitate Customer’s use of third-party software, hardware, cloud services, telecommunications services, cybersecurity tools, backup platforms, or other products. Keystone is not the manufacturer, developer, publisher, carrier, or provider of third-party products and does not make warranties, express or implied, regarding those products.

Customer’s use of third-party products is subject to the terms, conditions, licensing requirements, service limitations, warranty terms, support policies, and pricing rules of the applicable vendor or service provider. Those terms may change from time to time. Keystone is not responsible for downtime, defects, feature changes, discontinuation, price changes, security vulnerabilities, licensing changes, support limitations, or other actions or omissions of third-party vendors.

Keystone’s sole obligation regarding third-party products is to pass through any manufacturer, vendor, or provider warranties or remedies to the extent they are available and transferable. If Customer fails to pay for third-party products, Keystone may suspend or terminate access to those products without liability.

Procurement

If Customer asks Keystone to procure hardware, software, licensing, subscriptions, equipment, or other products, Keystone may do so as a convenience and as part of Keystone’s managed services or project support. Customer understands that procurement requires administrative time, vendor coordination, quoting, ordering, shipping, receiving, configuration, and support.

Unless otherwise stated in writing, all procurement is subject to vendor availability, shipping timelines, vendor terms, manufacturer warranties, return limitations, restocking fees, taxes, tariffs, freight charges, and price changes. Special-order items, opened items, configured devices, software licenses, subscriptions, and custom equipment may be non-cancelable and non-refundable.

Keystone may require payment before ordering hardware, software, licenses, subscriptions, or project materials. Title to hardware and equipment passes to Customer after Keystone has received full payment unless otherwise stated in writing.

Suspension of Services

Keystone may suspend services, in whole or in part, without liability if Customer fails to pay undisputed amounts when due, fails to maintain required security controls, refuses reasonable security recommendations, creates a security risk, misuses services, engages in unlawful activity, interferes with Keystone’s ability to provide services, fails to provide required access or cooperation, abuses or harasses Keystone staff, or otherwise materially breaches this Agreement.

Keystone may also suspend services if continuing to provide services would create a security, legal, operational, ethical, or financial risk to Keystone, Customer, another Keystone customer, a third-party vendor, or any other party.

Suspension of services does not relieve Customer of its payment obligations. Keystone will use reasonable efforts to provide notice before suspension when practicable, but Keystone may suspend services immediately if Keystone determines that immediate action is necessary to protect systems, data, personnel, customers, vendors, or third parties.

Termination

Customer may terminate managed services by providing at least sixty days’ written notice unless the applicable service agreement requires a longer notice period. Keystone does not intend to hold Customer hostage, but Customer acknowledges that technology services cannot be responsibly turned off overnight. The sixty-day notice period allows Keystone to transition access, remove tools, coordinate vendors, document the environment, return Customer-owned information, address open items, and reduce security and operational risk.

Customer remains responsible for all recurring fees, licenses, subscriptions, security tools, support charges, and other applicable amounts during the sixty-day termination period. If Customer requests transition assistance, documentation, vendor coordination, data migration, tool removal, credential transfer, or post-termination support, such work may be billed at Keystone’s then-current rates unless specifically included in the applicable service agreement.

Either Party may terminate a service agreement for material breach if the breaching Party fails to cure the breach within thirty days after receiving written notice describing the breach in reasonable detail. Keystone may terminate immediately upon written notice if Customer fails to pay undisputed amounts more than thirty days after the due date, refuses required security controls, creates an unacceptable security risk, engages in unlawful activity, abuses Keystone personnel, becomes insolvent, files for bankruptcy, ceases normal business operations, or materially breaches this Agreement in a manner that cannot reasonably be cured.

Termination of one service agreement does not automatically terminate other service agreements unless stated in writing.

Effect of Termination

Upon termination or expiration of services, all outstanding fees and charges become immediately due. Keystone may remove its software agents, monitoring tools, endpoint tools, security tools, administrative access, remote access tools, backup tools, documentation access, and other systems used to provide services.

Keystone will return Customer-owned equipment, credentials, documentation, or data in Keystone’s possession, subject to payment of all outstanding invoices and reasonable security verification. Keystone is not required to provide transition services, migration assistance, vendor coordination, documentation creation, or post-termination support unless Customer pays Keystone’s then-current rates or the applicable service agreement states otherwise.

Customer is responsible for arranging replacement IT support, vendor access, security tools, licensing administration, backup administration, monitoring, patching, and cybersecurity coverage after termination. Keystone is not responsible for outages, security incidents, data loss, licensing issues, vendor issues, or business impacts occurring after services are terminated or after Customer directs Keystone to remove tools or access.

Confidentiality

Each Party may receive non-public information from the other Party that is designated as confidential or that reasonably should be understood to be confidential based on the nature of the information and the circumstances of disclosure. Confidential information may include business plans, financial information, client information, employee information, technical data, credentials, system configurations, security information, network documentation, vendor information, pricing, trade secrets, and other non-public information.

The receiving Party agrees to use confidential information only for purposes of performing or receiving services under this Agreement and will not disclose confidential information to any third party except to employees, contractors, vendors, agents, advisors, or representatives who have a legitimate need to know and who are bound by confidentiality obligations or professional duties.

Confidential information does not include information that is publicly available without breach of this Agreement, already lawfully known without confidentiality obligations, independently developed without reference to the confidential information, or lawfully obtained from a third party without confidentiality obligations.

The Parties agree that unauthorized disclosure of confidential information may cause irreparable harm. The non-breaching Party may seek injunctive relief in addition to any other remedies available at law or equity. Confidentiality obligations survive termination of this Agreement for three years, except for trade secrets, which remain protected for as long as they qualify as trade secrets under applicable law.

Data Security

Keystone will use commercially reasonable measures to safeguard Customer data while it is in Keystone’s possession or control. Customer understands that Keystone’s access to data is generally incidental to providing managed services, support, cybersecurity services, backup services, cloud administration, or project work.

Keystone is not responsible for security breaches, data loss, unauthorized access, ransomware, business email compromise, vendor compromise, cloud platform compromise, deleted data, corrupted data, or other incidents caused by circumstances outside Keystone’s reasonable control, Customer’s failure to follow Keystone’s recommendations, Customer-managed systems, third-party vendors, unsupported systems, user error, credential compromise, social engineering, malicious insiders, or Customer’s refusal to implement required or recommended security controls.

Customer remains responsible for determining whether its business is subject to specific legal, regulatory, contractual, industry, privacy, data retention, or cybersecurity obligations. Unless Keystone expressly agrees in a signed statement of work to provide specific compliance services, Keystone does not provide legal, regulatory, audit, or compliance opinions.

Compliance Support

Keystone may provide technical assistance, documentation support, security recommendations, reporting, or consulting related to compliance frameworks when specifically included in a service agreement, quote, proposal, or statement of work. Such services are technical and operational in nature.

Keystone is not a law firm, CPA firm, auditor, regulator, or compliance certifying body. Customer is responsible for obtaining legal, regulatory, accounting, audit, and compliance advice from qualified professionals. Keystone does not guarantee that Customer will achieve or maintain compliance with any law, regulation, contract, insurance requirement, industry standard, audit framework, or certification.

Insurance

Keystone maintains general liability and cyber liability insurance with coverage limits of at least two million dollars, subject to applicable policy terms, exclusions, deductibles, and carrier requirements. Upon reasonable written request, Keystone may provide a certificate of insurance.

Customer acknowledges that insurance policies do not expand Keystone’s liability under this Agreement. Keystone’s liability remains limited as stated in this Agreement regardless of available insurance coverage.

Customer is responsible for maintaining its own insurance coverage appropriate for its business, including cyber liability insurance, crime coverage, business interruption coverage, errors and omissions coverage, property coverage, and any other coverage Customer determines necessary.

Disclaimer of Warranties

Except as expressly stated in this Agreement, Keystone makes no warranties, express or implied, including warranties of merchantability, fitness for a particular purpose, non-infringement, uninterrupted operation, error-free service, complete security, complete recovery, regulatory compliance, or achievement of any specific business outcome.

Keystone does not guarantee that all issues will be resolved, that all vulnerabilities will be discovered, that all attacks will be prevented, that all data will be recoverable, that all systems will remain available, or that Customer will avoid downtime, breach, financial loss, regulatory inquiry, business interruption, or other harm.

Limitation of Liability

Neither Party will be liable for indirect, incidental, special, consequential, exemplary, or punitive damages, including lost profits, lost revenue, lost business opportunity, loss of goodwill, business interruption, loss of data, cost of substitute services, or reputational harm, even if advised of the possibility of such damages.

Keystone’s total liability for any claim arising out of or relating to this Agreement, any service agreement, any quote, any statement of work, any invoice, any product, or any services provided to Customer will not exceed the total amount paid by Customer to Keystone for services during the twelve months preceding the event giving rise to the claim, excluding hardware, software, licensing, subscriptions, taxes, shipping, travel, pass-through vendor charges, and third-party products.

The limitations in this section apply to all claims, whether based in contract, tort, negligence, strict liability, statute, equity, or any other legal theory, except to the extent prohibited by law.

Indemnification

Customer will indemnify, defend, and hold harmless Keystone and its owners, officers, employees, contractors, agents, representatives, vendors, and affiliates from and against any claims, damages, losses, liabilities, penalties, costs, and expenses, including reasonable attorney’s fees, arising out of or related to Customer’s misuse of services, Customer’s breach of this Agreement, Customer’s negligence or willful misconduct, Customer’s violation of law, Customer’s failure to follow Keystone’s recommendations, Customer’s refusal to implement required security controls, Customer-managed systems, Customer’s third-party vendors, or claims brought by Customer’s employees, customers, vendors, or other third parties.

Keystone will indemnify and hold harmless Customer from third-party claims, damages, or expenses arising from Keystone’s gross negligence, willful misconduct, or material breach of this Agreement, subject to the limitations of liability stated in this Agreement.

Acceptable Use

Customer agrees not to use Keystone’s services, systems, access, tools, products, or vendor relationships for unlawful, abusive, fraudulent, harmful, or unauthorized purposes. Customer will not use services to transmit malware, engage in unauthorized access, violate third-party rights, send unlawful communications, store illegal content, evade security controls, interfere with networks, or engage in activity that could harm Keystone, Customer, vendors, third parties, or the public.

Keystone may suspend or terminate services immediately if Keystone reasonably believes Customer is using services in a manner that violates this Agreement, applicable law, vendor terms, security requirements, or acceptable use standards.

Staffing and Subcontractors

Keystone will determine the personnel assigned to provide services and retains sole discretion regarding staffing, scheduling, escalation, subcontractors, vendors, and internal work allocation. Keystone may use employees, contractors, vendors, distributors, and service providers to perform or support services.

If Customer reasonably believes that assigned personnel are not meeting professional expectations, Customer may provide written notice to Keystone. Keystone will review the concern and take commercially reasonable steps it deems appropriate.

Independent Contractor Relationship

The Parties are independent contractors. Nothing in this Agreement creates a partnership, joint venture, employment relationship, agency relationship, fiduciary relationship, or franchise. Neither Party has authority to bind the other Party except as expressly stated in writing.

Assignment

Neither Party may assign this Agreement without the prior written consent of the other Party, except that either Party may assign this Agreement without consent in connection with a merger, acquisition, reorganization, change of control, or sale of substantially all assets. This Agreement will bind and benefit the Parties and their permitted successors and assigns.

Force Majeure

Neither Party will be liable for delay or failure to perform caused by events beyond its reasonable control, including acts of God, natural disasters, severe weather, fire, flood, war, terrorism, civil unrest, labor disputes, pandemics, epidemics, government actions, internet outages, utility failures, vendor outages, supply-chain disruptions, cyberattacks not caused by the affected Party’s gross negligence or willful misconduct, or other events beyond reasonable control.

The affected Party will use reasonable efforts to resume performance as soon as practicable. Payment obligations for services already performed, products already ordered, licenses already procured, subscriptions already activated, and amounts already due are not excused by force majeure.

Notices

Notices under this Agreement must be in writing and may be delivered by email, certified mail, nationally recognized courier, or other method reasonably designed to provide proof of delivery. Notices to Keystone must be sent to Keystone Business Solutions, LLC, 3050 Business Park Circle, Suite 301, Goodlettsville, Tennessee 37072, with a copy by email to accounting@wearekeystone.com for billing matters or to another notice address Keystone designates in writing.

Notices to Customer may be sent to the billing contact, primary contact, executive contact, or other address or email provided by Customer. Customer is responsible for keeping notice and billing information current.

Governing Law and Venue

This Agreement will be governed by the laws of the State of Tennessee, without regard to conflict of law principles. Any dispute arising out of or relating to this Agreement, the services, any service agreement, any quote, any statement of work, any invoice, or the relationship between the Parties must be brought in the state or federal courts located in Sumner County, Tennessee. Each Party consents to the exclusive jurisdiction and venue of those courts.

Updates to this Agreement

Keystone may modify this Master Services Agreement by posting an updated version on its website and providing at least thirty days’ notice to Customer. Notice may be provided by email, invoice message, customer portal notice, service agreement notice, website notice, or other reasonable method.

Continued use of services after the effective date of the updated Master Services Agreement constitutes acceptance of the updated terms. If Customer does not agree to the updated terms, Customer must provide written notice before the effective date and terminate services in accordance with the termination provisions of this Agreement and any applicable service agreement.

The version of this Master Services Agreement posted on Keystone’s website as of the applicable effective date will govern the services unless otherwise stated in a signed written agreement.

Electronic Signatures and Acceptance

This Agreement and any related quote, proposal, service agreement, statement of work, invoice, order form, or amendment may be accepted electronically, by electronic signature, by email approval, by payment, by continued use of services, or by other conduct indicating acceptance. Electronic signatures and electronic records will have the same legal effect as original handwritten signatures and paper records.

Severability

If any provision of this Agreement is held invalid, illegal, or unenforceable, the remaining provisions will continue in full force and effect. The invalid, illegal, or unenforceable provision will be modified to the minimum extent necessary to make it valid, legal, and enforceable while preserving the intent of the Parties as closely as possible.

Waiver

A Party’s failure to enforce any provision of this Agreement does not waive that provision or any other provision. Any waiver must be in writing and signed by the Party granting the waiver.

Entire Agreement

This Master Services Agreement, together with the applicable service agreement, quote, proposal, statement of work, invoice, order form, and any written amendments, constitutes the entire agreement between the Parties regarding the services and supersedes all prior or contemporaneous discussions, proposals, understandings, representations, and agreements regarding the same subject matter.

No amendment to a signed service agreement or statement of work will be effective unless made in writing and accepted by both Parties. Keystone may update this Master Services Agreement as provided in the section titled “Updates to this Agreement.”Survival

The provisions relating to payment, taxes, confidentiality, data security, cybersecurity disclaimer, third-party products, procurement obligations, limitation of liability, indemnification, insurance, governing law, venue, effect of termination, and any other provisions that by their nature should survive will survive termination or expiration of this Agreement.

Table of Contents