Confidentiality and Beta Testing Agreement (NDA)
Joining the early access as a tester → this NDA. It is about keeping beta details confidential — not about pricing, refunds, or how your personal data is handled (those are other pages).
This Confidentiality and Beta Testing Agreement (NDA) — short title for the agreement covering confidentiality, non-disclosure, non-use, non-reverse-engineering, and software beta testing (the "Agreement") — is a contract of adhesion accepted electronically. It takes effect on the Effective Date, meaning the UTC date and time when the Tester checks the acceptance box for this Agreement and submits an application to the private tester program on the Pulsatrix site (or otherwise accepts the Agreement through an equivalent electronic mechanism provided by the Provider).
It binds:
- the Provider: Pulsatrix Technologies Inc., a business corporation under the *Business Corporations Act* (CQLR, c. S-31.1), with its registered office at 3354 Bellefeuille Street, Trois-Rivières, Québec, Canada, G9A 3Z3 (the "Provider"); and
- the Tester: the natural person and, where applicable, the organization for which they act, as identified by the information provided at electronic acceptance (including first name, last name, work email, and company / MSP name) (the "Tester").
No handwritten signature is required. Electronic acceptance described in the "Electronic Acceptance" section is proof of the Tester's commitment. Access to the Beta Software is conditional on that acceptance.
01Context and purpose
- The Provider develops, owns, operates, or commercializes software, an application, a platform, a module, an interface, a technology, or a software solution currently in test, beta, pilot, demonstration, or pre-commercial version, further described in Schedule A (the "Beta Software").
- The Tester wishes to obtain strictly limited access to the Beta Software to evaluate it and provide comments, bug reports, observations, and suggestions solely within the test contemplated by this Agreement.
- The purpose of this Agreement is to protect the Beta Software, Confidential Information, the Provider's intellectual property rights, trade secrets, non-public elements, features, interfaces, business logic, architecture, ideas, concepts, methods, workflows, data, outputs, and any feedback related to the Beta Software.
- The Tester acknowledges that access to the Beta Software is granted only because the Tester accepts the strict obligations of confidentiality, non-disclosure, non-use, non-copying, non-reverse-engineering, and non-development set out in this Agreement.
- The Beta Software is offered only to persons or organizations acting for professional, commercial, institutional, or authorized research purposes. No access is granted for personal, household, or consumer purposes. The Tester represents that they act exclusively for professional or commercial purposes and not as a consumer.
- In case of conflict between the body of the Agreement and a schedule, the body prevails unless the schedule expressly states that it derogates from a specific provision. In case of conflict among schedules, the order of priority is: Schedule A, Schedule B, Schedule E, Schedule D, Schedule C, Schedule F, and Schedule G. However, any data-processing schedule or provision relating to personal information protection prevails for matters of personal information, data transfers, processors, confidentiality incidents, and rights of data subjects.
02Definitions
- "Authorized Access" means individual, named, revocable, and limited access granted by the Provider to the Tester or Authorized Users, under the parameters described in Schedule B.
- "Related Entity" means an affiliate, controlled entity, entity under common control, significant shareholder, officer, director, consultant, or agent.
- "Permitted Purpose" means exclusively the Tester's use of the Beta Software to test, evaluate, and comment on its operation for the Provider's benefit, under scenarios, limits, durations, and terms expressly approved in writing by the Provider.
- "Feedback" means any comment, suggestion, idea, recommendation, bug report, fix, improvement, feature request, observation, concept, test result, UX comment, diagram, note, annotated screenshot, or other contribution transmitted, formulated, or generated by the Tester or Authorized Users relating to the Beta Software.
- "Confidential Information" means any information, data, document, access, knowledge, or element, tangible or intangible, communicated, made accessible, observed, inferred, or obtained by the Tester under this Agreement, including without limitation:
- the Beta Software, its modules, interfaces, screens, features, workflows, user journeys, settings, methods, business rules, algorithms, architecture, APIs, data models, structures, databases, integrations, outputs, and results;
- any source code, object code, script, query, model, technical documentation, user documentation, mock-up, prototype, roadmap, development plan, bug, vulnerability, limitation, performance, or test result;
- trade secrets broadly, whether or not patentable or protectable by copyright;
- commercial information, prices, strategies, customers, prospects, markets, partners, suppliers, metrics, financial data, contractual terms, and go-to-market plans;
- the very existence of the test, participant identities, identifiers, passwords, access links, environments, test data, datasets, and screenshots;
- any information that, by its nature or the circumstances of its communication, should reasonably be considered confidential, non-public, strategic, or sensitive.
- "Test Materials" means the Beta Software, access credentials, links, identifiers, documents, examples, data, files, mock-ups, captures, instructions, communications, and any other element provided or made accessible by the Provider.
- "Authorized User" means only a natural person identified in writing in Schedule B or otherwise approved in writing by the Provider, who has a legitimate need to access the Beta Software for the Permitted Purpose, acts for the Tester, and is bound by obligations at least as protective as this Agreement.
03Limited evaluation licence
- Subject to full compliance with this Agreement, the Provider grants the Tester a personal, limited, revocable, non-exclusive, non-transferable, non-assignable licence without sublicensing rights to access the Beta Software solely for the Permitted Purpose during the Test Period in Schedule A.
- No rights are granted except expressly. All rights not expressly granted are reserved by the Provider.
- The Tester may not use the Beta Software for production, commercial, internal operational, training, system integration, third-party service delivery, competitive analysis, product development, public comparison, research, demonstration, or marketing purposes, except with the Provider's prior written authorization.
- The Provider may suspend, limit, modify, or revoke access to the Beta Software at any time without notice, including for security risk, breach of this Agreement, or end of the test.
- If the Provider reasonably suspects a breach, it may request information, attestations, logs, destruction evidence, segregation evidence, independent-development evidence, or other elements reasonably necessary to verify compliance, subject to appropriate confidentiality measures. Access to evidence may be by attestation, summary documentation, or an independent expert under confidentiality.
04Confidentiality and non-use obligations
- The Tester must keep Confidential Information strictly confidential and may not disclose, communicate, publish, transfer, make accessible, or allow anyone to consult it, except Authorized Users and only as necessary for the Permitted Purpose.
- The Tester may use Confidential Information only for the Permitted Purpose. Use for the Tester's own benefit, for a third party's benefit, or to develop, improve, compare, train, document, sell, promote, or exploit any product, service, software, method, or solution other than the Beta Software for the Provider's benefit is expressly forbidden.
- The Tester must protect Confidential Information with measures at least as rigorous as those applied to its own highly confidential information, and never less than reasonable measures given the sensitivity of the information. At all times the Tester must comply with applicable law, internal policies, confidentiality obligations, and data-subject rights.
- The Tester must immediately notify the Provider of any loss, unauthorized access, disclosure, unauthorized use, security incident, suspected incident, or request for communication concerning Confidential Information.
- If the Tester is legally compelled to disclose Confidential Information, the Tester must, to the extent permitted by law, give prior written notice to the Provider, cooperate to limit disclosure, and disclose only the portion strictly required.
05Enhanced restrictions
- Except with the Provider's prior written authorization, the Tester shall not, directly or indirectly:
- copy, reproduce, download, extract, record, export, archive, print, or retain the Beta Software, Test Materials, or any Confidential Information, except to the extent strictly necessary and expressly authorized for the Permitted Purpose, or where strictly necessary to produce Feedback, transmitted only to the Provider through authorized channels, and deleted upon transmission or at the end of the test;
- make or keep screenshots, videos, recordings, transcripts, extractions data, printouts, data exports, result copies, or demonstrations of the Beta Software, except where strictly necessary to produce Feedback, transmitted only to the Provider through authorized channels, and deleted upon transmission or at the end of the test;
- Subject to the exceptions for Feedback production above, the prohibition on copying and retention also covers handwritten or digital notes, diagrams, summaries, partial captures, screen photographs, indirect reproductions, meeting minutes, meeting transcripts, prompts, outputs, structured observations, or any document enabling reconstitution of the Beta Software, its operation, architecture, features, or business logic;
- share, lend, transfer, or reuse identifiers, passwords, links, API keys, tokens, access, or environments;
- allow any unauthorized person, including an employee, consultant, subcontractor, affiliate, customer, supplier, investor, or partner, to access the Beta Software or Confidential Information;
- The Tester is responsible for any act or omission of its officers, employees, consultants, subcontractors, affiliates, agents, representatives, investors, partners, and Authorized Users who obtained, directly or indirectly, access to the Beta Software, Test Materials, or Confidential Information, whether that access was authorized or not;
- disassemble, decompile, de-obfuscate, decode, analyze, probe, perform intrusive security testing, circumvent, scrape, automate, extract, index, mass-query, or reverse-engineer the Beta Software;
- The Tester shall not reverse-engineer to the fullest extent permitted by applicable law, subject only to non-waivable mandatory rights;
- attempt to discover the source code, structure, logic, algorithms, models, methods, business rules, parameters, or architecture of the Beta Software;
- modify, translate, adapt, create a derivative work, integrate, wrap, encapsulate, reproduce look-and-feel or behaviour, imitate features, or prepare a solution inspired by the Beta Software;
- publish or communicate any analysis, review, benchmark, comparison, critique, performance measure, capture, demonstration, or public mention of the Beta Software;
- use the Beta Software, Test Materials, Confidential Information, or Beta Software outputs to train, fine-tune, validate, test, enrich, or feed an AI system, model, agent, knowledge base, assistant, search engine, or automated tool; provided that this prohibition does not apply to the Tester's interaction with third-party AI models or agents when that interaction is an integral part of the normal intended operation of the Beta Software (including via MCP connectors), and remains strictly within the Permitted Purpose;
- That exception does not allow the Tester to transmit, retain, reuse, train, fine-tune, index, or expose Confidential Information, Test Materials, Beta Software outputs, or data from MCP connectors to a third-party model, agent, assistant, or provider, except where such transmission is expressly part of the Beta Software's operation, authorized by the Provider, limited to the Permitted Purpose, and performed under settings that prevent unauthorized training, reuse, or retention by that third party when available;
- remove, obscure, or alter any intellectual-property notice, copyright, trademark, confidentiality notice, watermark, tracer, identifier, or technical measure of the Provider;
- The Tester may not use ideas, concepts, features, workflows, interfaces, methods, screens, sequences, results, or observations from the Beta Software as inspiration, reference, template, specification, proof of concept, architecture, benchmark, or input to develop, have developed, purchase, improve, or recommend a competing or derivative product or service — meaning a product or service aimed at the same target market and reusing essential non-public features of the Beta Software;
- During this Agreement and for 24 months after it ends, the Tester shall not, directly or indirectly, use Confidential Information, Test Materials, confidential observations, non-public specifications, workflows, architecture, interfaces, connectors, prompts, business rules, tool schemas, test results, or Feedback to design, develop, fund, acquire, recommend, or have developed a competing or derivative product or service as defined above. This does not prohibit independent development without access to, use of, reference to, or benefit from Confidential Information, if the Tester can demonstrate independence with contemporaneous documentary evidence (design notebooks, development logs, code repositories, specifications, team-segregation evidence). Trade secrets remain protected while they remain secret;
- If during the Agreement or within 24 months after it ends the Tester develops, funds, acquires, recommends, or participates in a competing or derivative product or service as defined above, the Tester must be able to show, on the Provider's reasonable request and under appropriate confidentiality measures, that the solution was designed and developed independently. This obligation applies only if the Provider's request is reasonably based on objective indicators of breach;
- Where the Tester or a Related Entity develops or participates in developing a competing or derivative product or service during the Agreement or within 24 months after it ends, the Tester must, on the Provider's request, implement reasonable segregation measures including team separation, restricted access to Confidential Information, development logs, source documentation, and design-decision traceability;
- Restrictions in this section target use of Confidential Information, Test Materials, confidential observations, and non-public elements of the Beta Software. They do not prevent use of general knowledge, general professional skills, or public information, provided those are not used together with Confidential Information and the Tester can demonstrate independent development. For certainty, non-public features, sequences, workflows, prompts, tool schemas, MCP architectures, routing mechanisms, interfaces, methods, and design choices of the Beta Software are not mere general knowledge when observed, inferred, or obtained during the test;
- During the Agreement and for 24 months after it ends, the Tester shall not, directly or indirectly, solicit, recruit, hire, or engage a key employee, consultant, developer, supplier, or subcontractor of the Provider who worked on the Beta Software, except with the Provider's prior written authorization, excluding general advertising, unsolicited approach by the person, or a documented pre-existing relationship.
06Access, security, and test conduct
- The Tester must comply with access parameters, scenarios, limits, security instructions, and test rules in Schedules A to D or communicated by the Provider.
- The Tester must use only individual accounts, strong passwords, multi-factor authentication when available, and secured devices, and must prevent unauthorized access to the Beta Software.
- The Provider may log, monitor, and analyze use of the Beta Software, including connections, activities, events, errors, exports, API calls, IP addresses, devices, and other metadata reasonably necessary for security, support, product improvement, proof of use, and enforcement of this Agreement.
- The Tester must not perform load testing, penetration testing, vulnerability scanning, unauthorized automation, scripts, mass queries, or unplanned manipulations without the Provider's prior written authorization.
- The Tester must immediately stop any activity and notify the Provider upon discovering a flaw, critical bug, data exposure, vulnerability, or unexpected behaviour that may compromise security, confidentiality, integrity, or availability of the Beta Software.
- The Tester must not publicly disclose, exploit, demonstrate, publish, sell, share, or retain any vulnerability, flaw, bypass method, unexpected behaviour, or security information relating to the Beta Software or its connectors. Any vulnerability must be reported exclusively to the Provider at the notice address in the Notices section, and the Tester must reasonably cooperate to limit effects.
07MCP connectors and third-party system integrations
- The Tester acknowledges that the Beta Software may use or enable Model Context Protocol ("MCP") connectors, including MCP clients, MCP servers, tools, resources, API calls, agents, access tokens, OAuth authorizations, permissions, scopes, prompts, metadata, and integrations with third-party systems.
- Except with the Provider's prior written authorization, the Tester may not:
- connect the Beta Software to an account, system, repository, database, environment, CRM, ERP, messaging system, calendar, cloud storage, or third-party tool containing real, personal, confidential, regulated, or third-party data;
- connect or expose the Beta Software to an MCP server, MCP tool, agent, assistant, or model not approved by the Provider;
- modify, publish, expose, wrap, replicate, clone, or document an MCP connector, tool, schema, resource, prompt, workflow, integration architecture, or authorization mechanism of the Beta Software;
- use the Beta Software or its MCP connectors to extract, infer, reconstruct, or document system prompts, internal rules, tool schemas, permissions, authorization flows, routing mechanisms, access policies, or orchestration logic;
- use MCP connectors for scraping, exfiltration, unauthorized automation, unauthorized security testing, permission bypass, privilege escalation, prompt injection, tool poisoning, or tool manipulation;
- transmit to the Beta Software credentials, API keys, OAuth tokens, secrets, certificates, private keys, or other access without the Provider's written authorization;
- directly or indirectly use, configure, cause, allow, or attempt unauthorized transfer, reuse, or transmission of tokens, keys, secrets, credentials, certificates, or authorizations between an MCP client, MCP server, third-party service, or external API (including token passthrough, cross-audience token reuse, scope bypass, privilege escalation, or use of a token intended for another service);
- The parties agree that any authorized MCP connector must use tokens, scopes, and authorizations specific to the target resource and must not reuse a token intended for another service except as strictly allowed by an architecture expressly approved in writing by the Provider;
- invoke tools or connectors that write, delete, send, publish, modify, transact, or execute in a third-party system, unless expressly authorized in Schedule A;
- Any Beta Software or MCP action that writes, modifies, deletes, transmits, publishes, sends, executes a transaction, creates a commitment, changes permissions, or affects a third-party system must be expressly authorized in writing and, when available, confirmed by explicit consent of the Authorized User before execution;
- Any MCP server, tool, connector, script, agent, model, resource, prompt, schema, or service provided, configured, or controlled by the Tester must be pre-approved in writing by the Provider. The Tester warrants that such elements contain no malware, exfiltration mechanism, hidden instruction, prompt injection, tool poisoning, permission bypass, unauthorized telemetry, excessive collection, backdoor, or functionality that may compromise the Beta Software, its data, secrets, users, or environments;
- The Beta Software may integrate with, interact with, or depend on components, libraries, services, APIs, models, MCP connectors, open-source software, or third-party services. No rights are granted to the Tester in those elements except as strictly necessary for the Permitted Purpose. The Tester must respect applicable third-party terms and may not use those elements to extract, reproduce, bypass, or reconstruct the Beta Software or its features.
08Data, personal information, and prohibited data
- Except with the Provider's prior written authorization, the Tester must not enter, upload, process, import, connect, or transmit to the Beta Software personal information, sensitive data, real customer data, confidential financial data, third-party trade secrets, regulated data, health data, children's data, payment data, or other data whose use in a test environment could create legal, contractual, or security risk. The Tester must at all times comply with applicable law, internal policies, confidentiality obligations, and data-subject rights. Without limiting the foregoing, the Tester acknowledges that the Provider is subject to Québec's Act respecting the protection of personal information in the private sector (Law 25) and that, for Authorized Users in the EU/EEA, the GDPR may also apply to personal information transmitted in the test.
- Authorized processing of personal information:
- Except for metadata, access logs, IP addresses, user identifiers, device data, and other information strictly necessary for access management, security, support, proof of acceptance, Beta Software improvement, and enforcement of this Agreement (governed by the access/logging section and Schedule F), no personal information may be entered, uploaded, imported, synchronized, connected, consulted, transmitted, processed, or otherwise made accessible through the Beta Software, including via MCP connectors, without the Provider's prior written authorization;
- Such written authorization is deemed given only if the parties have first entered into a data-processing schedule or separate data-processing agreement specifying roles, purposes, categories of personal information and data subjects, data sources, processing locations, authorized processors, transfers outside Québec or the applicable territory, contractual/organizational/technical safeguards, retention, return/deletion/anonymization, incident management, data-subject rights, audit mechanisms, and any requirements under personal-information laws;
- The Tester must never use the Beta Software to process sensitive personal information, health data, children's data, payment data, regulated data, real customer data, or personal information belonging to a third party unless expressly authorized in writing by the Provider and covered by the applicable data-processing schedule or agreement;
- The Tester represents and warrants that it holds all rights, consents, authorizations, legal bases, and powers necessary for any personal information whose processing the Provider authorizes. The Tester remains responsible for ensuring that any data it provides, connects, or makes accessible to the Beta Software complies with this Agreement, the Provider's instructions, applicable law, and data-subject rights;
- The Provider may delete, anonymize, isolate, or refuse any data it deems non-compliant with this Agreement or test instructions.
09Intellectual property and reserved rights
- The Provider retains all right, title, and interest in the Beta Software, Test Materials, Confidential Information, inventions, technologies, ideas, concepts, know-how, methods, algorithms, interfaces, designs, documentation, trademarks, trade secrets, copyrights, patents, patent applications, industrial designs, trade names, data, outputs, improvements, and derivatives related to the Beta Software, subject to the Tester's pre-existing rights in its authorized data.
- The Tester acquires no ownership, implied licence, exploitation right, reuse right, moral right, copyright, trade-secret right, trademark right, data right, or other right in the Beta Software or Confidential Information, except the limited licence expressly granted above.
- The Tester must not challenge, assist in challenging, register, attempt to register, claim, or assert any right incompatible with the Provider's rights in the Beta Software, Test Materials, Confidential Information, or Feedback.
- The Tester acknowledges that components of the Beta Software may be subject to patent applications, copyrights, industrial designs, trademarks, trade secrets, or other rights, registered or not. The Tester must not take any act, disclosure, publication, demonstration, filing, registration, or claim that may compromise the novelty, confidentiality, registration, protection, or commercialization of those rights.
10Feedback, assignment, and waiver
- The Tester acknowledges that all Feedback is provided voluntarily, without restriction and without expectation of compensation, attribution, royalty, participation, approval right, or future use right.
- The Tester irrevocably assigns to the Provider, on an exclusive, worldwide, perpetual, royalty-free basis, all right, title, and interest the Tester holds or may hold in Feedback, including copyrights, neighbouring rights, database rights, contractual rights, intellectual-property rights, and exploitation rights, to the extent permitted by law.
- The Provider may use, reproduce, modify, combine, adapt, translate, integrate, commercialize, exploit, publish, protect, assign, license, or ignore any Feedback without restriction and without obligation to the Tester.
- To the extent moral rights may exist in Feedback, the Tester waives them in whole or in part to the extent permitted by law in favour of the Provider and any person authorized by the Provider.
- If assignment is invalid in a jurisdiction, the Tester grants a worldwide, irrevocable, perpetual, transferable, sublicensable, royalty-free licence.
- The Tester represents that Feedback does not infringe third-party rights and that the Tester will not incorporate any third-party confidential information, proprietary data, code, content, trade secret, or intellectual property without the Provider's prior written authorization.
11Limited exceptions to confidentiality
- Confidentiality obligations do not apply to information the Tester can demonstrate with contemporaneous, reliable documentary evidence:
- was generally known to the public without breach of this Agreement;
- was lawfully in the Tester's possession before disclosure by the Provider, without confidentiality obligation;
- was lawfully received from a third party not bound by confidentiality to the Provider;
- was independently developed by the Tester without access to, use of, reference to, or benefit from Confidential Information.
- No combination of features, methods, or elements will be treated as public or non-confidential merely because some individual elements are separately known.
- The burden of proving an exception lies with the Tester.
12No warranty — beta nature
- The Tester acknowledges that the Beta Software is provided for testing only; that it may be incomplete, unstable, unavailable, modified, interrupted, or contain bugs, errors, vulnerabilities, data loss, or limitations; and that it must not be used in a critical or production environment.
- To the extent permitted by law, the Beta Software, Test Materials, and any Confidential Information are provided "as is" and "as available", without express or implied warranty, including of quality, operation, availability, accuracy, error-free operation, security, compliance, fitness for a particular purpose, non-infringement, or results.
- The Provider has no obligation to fix an error, maintain the Beta Software, provide support, continue development, commercialize the Beta Software, integrate Feedback, or deliver a final version.
13Limitation of liability
- To the extent permitted by law, the Provider will not be liable to the Tester for indirect, special, punitive, exemplary, incidental, or consequential damages, nor for any loss of profits, revenue, data, goodwill, business opportunity, anticipated savings, or business interruption arising from the test or use of the Beta Software.
- To the extent permitted by law, the Provider's total liability under this Agreement is limited to the greater of CAD 100 or amounts actually paid by the Tester to the Provider for the beta test in the three months preceding the event giving rise to the claim.
- These limitations do not limit the Provider's remedies for the Tester's breach of confidentiality, non-use, intellectual property, security, use restrictions, Feedback assignment, or indemnification obligations.
- Limitations and exclusions in this section do not apply where prohibited by mandatory applicable law, including intentional fault, gross negligence, bodily injury, or moral injury where such exclusions cannot validly be stipulated.
14Force majeure
- Neither party is liable to the other for delay or failure to perform resulting from an event reasonably beyond its control, including natural disaster, major cloud or telecommunications outage, cyberattack, armed conflict, pandemic, or government decision, provided the affected party notifies the other within a reasonable time and makes reasonable efforts to mitigate effects.
15Term, termination, and survival
- This Agreement takes effect on the Effective Date and remains in force until the end of the Test Period, unless terminated earlier, which does not release the Tester from confidentiality, non-use, return, destruction, intellectual-property, remedies, and survival obligations.
- The Provider may terminate this Agreement and revoke access to the Beta Software at any time, with or without cause, by written notice to the Tester.
- The Tester may stop participating by written notice to the Provider, but that does not release the Tester from confidentiality, non-use, return, destruction, intellectual-property, remedies, and survival obligations.
- Obligations relating to confidentiality, non-use, intellectual property, Feedback, restrictions, remedies, indemnification, notices, governing law, and general clauses survive the end of this Agreement according to their nature. Special non-development restrictions survive for the period stated in that section.
- Confidential Information must remain protected as long as it has not become public without the Tester's fault. Trade secrets remain protected as long as they retain secrecy or commercial value linked to confidentiality.
16Return, destruction, and attestation
- On the Provider's first request or at the end of this Agreement, the Tester must immediately stop all use of the Beta Software and Confidential Information, return or destroy all Test Materials, remove all access, copies, captures, exports, notes, files, documents, reports, extracts, or data, and confirm that destruction or return in writing.
- The Tester must also delete Confidential Information from systems, devices, accessible backups, collaboration tools, cloud platforms, AI tools, messaging, repositories, notebooks, histories, captures, and storage media, to the extent reasonably possible. Residual copies in automatic backups may remain until normal rotation but stay confidential, inaccessible, and unrestored except for technical necessity.
- The Provider may require a destruction/return attestation under Schedule G.
17Remedies, injunction, liquidated damages, and indemnification
- The Tester acknowledges that a breach of this Agreement may cause the Provider serious, hard-to-quantify, and potentially irreparable harm, including disclosure of trade secrets, loss of competitive advantage, loss of confidentiality, intellectual-property injury, or development of a competing product.
- The Provider may seek any available remedy, including injunction, specific performance, seizure or surrender of materials, cessation of use, restitution, damages, profits realized, reasonable investigation costs, expert fees, and legal fees, to the extent permitted by law.
- Without limiting the Provider's right to seek an injunction, safeguard order, conservatory measure, or other urgent relief (primary remedy for trade secrets and Confidential Information), the Tester agrees that where harm is difficult to quantify precisely, a substantial breach of confidentiality, non-use, non-copying, non-reverse-engineering, non-circumvention, security, access-protection, or intellectual-property obligations may give rise to liquidated damages of five thousand Canadian dollars (CAD 5,000) per substantial breach. That amount is a reasonable pre-contractual estimate of harm (not a punitive fine). The Provider may claim a higher amount if it proves greater actual harm. No automatic daily penalty applies; damages for continuing breach after written notice are assessed based on actual harm and equitable remedies.
- The Tester must indemnify and hold the Provider harmless from any claim, loss, liability, damage, cost, fine, sanction, expense, or fee arising from a breach of this Agreement, unauthorized use, unauthorized disclosure, intellectual-property infringement, data incident, or use of data provided by the Tester.
18Tester representations and warranties
- The Tester represents and warrants that it:
- has capacity and authority to enter into this Agreement;
- If the person who electronically accepts this Agreement does so on behalf of an organization, that person has legal, contractual, and organizational authority to bind that organization and its Authorized Users; otherwise they are personally liable for accepted obligations and any access obtained;
- is not subject to an obligation incompatible with this Agreement;
- is not accessing the Beta Software to develop, improve, compare, purchase, recommend, or have developed a competing or derivative product or service within the meaning of the enhanced restrictions;
- has informed every Authorized User of this Agreement's obligations and is responsible for their acts and omissions;
- will not use third-party data or personal information in the Beta Software without authorization and an appropriate legal basis;
- will not transmit Test Materials or Confidential Information to public tools, AI systems, unapproved cloud services, code repositories, collaboration platforms, or unauthorized third parties;
- is not, and no Authorized User is, directly or indirectly employed by, consulting for, agent of, significant shareholder of, officer of, director of, strategic supplier of, or representative of a business developing or commercializing a competing or derivative product or service, except with prior written disclosure and acceptance by the Provider;
- is not located in a country or territory subject to applicable sanctions or commercial embargo, is not a designated person or controlled by a designated person, and will not use the Beta Software in violation of sanctions, export-control, trade-restriction, or prohibited-use laws. The Provider may refuse, suspend, or revoke access if the Tester, country, owners, officers, users, or intended use present sanctions, export, or compliance risk;
- The Tester must provide, on request, information reasonably necessary for sanctions, export-control, beneficial-owner, officer, residence, use-country, and end-use checks. The Provider may suspend or refuse access if information is insufficient.
19Assignment, transfer, and subcontracting
- The Tester may not assign, transfer, delegate, or subcontract rights or obligations under this Agreement without the Provider's prior written consent.
- The Provider may assign this Agreement to an affiliate, successor, acquirer, or other entity in a restructuring, merger, acquisition, asset sale, or substantial transfer of activities related to the Beta Software, subject to applicable law. The Provider may also disclose this Agreement and relevant Confidential Information to an investor, lender, potential acquirer, strategic partner, or professional adviser solely as reasonably necessary for due diligence, financing, a transaction, or commercialization of the Beta Software, under appropriate confidentiality obligations.
20Notices
- Any notice must be given in writing (email is sufficient) to the following coordinates, or any coordinates later communicated in writing:
Provider (notices, beta support, security, privacy)
Pulsatrix Technologies Inc.
3354 Bellefeuille Street, Trois-Rivières, Québec G9A 3Z3, Canada
Sole email: privacy@pulsatrix.ca
(Privacy Policy: /#/privacy. For a vulnerability, prefix the subject with "SECURITY" — never publish publicly.)
Tester
Coordinates provided in the tester application (work email and, where applicable, company).
21Governing law and forum
- This Agreement is governed by the laws of the Province of Québec and the federal laws of Canada applicable therein, without regard to conflict-of-laws rules.
- The parties submit any dispute relating to this Agreement to the exclusive jurisdiction of the courts of Québec sitting in the judicial district of Trois-Rivières, subject to the Provider's right to seek an injunction or urgent measure before any competent court when necessary to protect Confidential Information, intellectual property, or the security of the Beta Software.
22Language
- This Agreement is prepared in French and in English. Both language versions are made available on the Provider's site.
- In case of conflict or divergence between language versions, the French version prevails, except where a mandatory rule of law requires otherwise.
- For Testers in Québec offered this Agreement as a contract of adhesion, the French version is available first and accessible in accordance with applicable language requirements.
- A Tester who chooses the English interface still accepts the Agreement under the rules above; electronic acceptance records the Agreement version identifier and does not require a handwritten signature.
23General provisions
- This Agreement is the entire agreement between the parties on its subject and supersedes any prior or contemporaneous discussion, communication, or agreement concerning the Beta Software, Confidential Information, or the test.
- Any amendment must be in writing and accepted by the parties, except operational instructions, access parameters, and security rules that the Provider may reasonably modify to protect the Beta Software or administer the test.
- The Provider may unilaterally amend Schedules C, D, E, and G to restrict, suspend, or secure authorized access, connectors, scopes, data, or actions. Any amendment that expands access rights, authorizes personal data, adds write actions, or increases the Tester's permissions must be accepted in writing by the parties.
- If a provision is held invalid, illegal, or unenforceable, it will be interpreted or modified to the extent necessary to achieve its original purpose as far as possible, and the remaining provisions continue in force.
- Failure to exercise a right or remedy is not a waiver of that right or remedy.
- Headings are for convenience only and do not affect interpretation.
- This Agreement is formed and proven solely by electronic acceptance (checkbox + submission on the site, or an equivalent mechanism provided by the Provider). No paper counterpart or handwritten signature is required for validity between the parties, subject to mandatory applicable provisions.
- When this Agreement is accepted electronically, the Provider retains acceptance evidence that may include: the Tester's declared identity, email, organization, submission IP address, UTC date and time of acceptance, Agreement version identifier (e.g.
nda-v2.2-2026-07), acceptance mechanism, and related technical logs. The Tester acknowledges that such evidence is admissible to establish acceptance and access to the Beta Software.
24Electronic acceptance
- By checking the acceptance box for this Agreement and submitting an application to the private tester program (or using any other electronic acceptance mechanism provided by the Provider), the Tester acknowledges having read, understood, and accepted all terms of this Agreement before any access to the Beta Software.
- Access to the Beta Software is conditional on that prior acceptance. Any use of the Beta Software after acceptance confirms the Tester's ongoing obligations.
- The Effective Date is the UTC timestamp of electronic acceptance recorded by the Provider.
- The binding version is the version displayed on the site at acceptance and recorded under the version identifier associated with the application (electronic evidence). Material updates to the Agreement may require a new acceptance before continued access.
- No "Signed at [place], on …" line or handwritten signature block is required; this mechanism fully replaces a paper signature.
25Schedule A – Description of the Beta Software and the test
- Name of Beta Software: Pulsatrix — MCP server for the ConnectWise platform and ecosystem (npm package
@pulsatrix/connectwise-mcp). - Version / environment: pre-commercial beta. Local MCP host (STDIO transport) running on the Tester's machine and registering with the Tester's MCP client (e.g. Claude Desktop). Functional domains load dynamically per the Tester's licence.
- Features in scope: MSP operations automation across six domains of the ConnectWise stack and ecosystem — PSA (tickets, companies, sales, time, projects), CPQ (quotes), RMM (monitoring, alerts, patches), ScreenConnect (endpoint execution), SentinelOne (EDR/MDR), Axcient x360 (backup). Rationalized tool surface per domain (discovery via
pulsatrix_meta), with risk-class gated approvals (READ / WRITE / INTENSE). Exact exposed action counts depend on licence and installed version. - Features in product: only tools granted by the Tester's licence and installed version. Non-GET raw API access is locked (preview only, fail-closed allowlist).
- Test Period: indeterminate - test access continues until the Software is offered in a final commercial version (GA), or until revocation / end of participation by the Provider or the Tester, under this Agreement. No minimum duration is guaranteed.
- Test objectives: validate real MSP flows (support ticket lifecycle, sales ticket lifecycle, technical need identification and mitigation, customer approver management), stability, and usability.
- Authorized scenarios: READ and WRITE / INTENSE according to licence and the Tester's approval policy. A dedicated test tenant is recommended. Use of real customer or production systems is at the Tester's own risk (see Schedule E and data section).
- Volume / usage limits: those imposed by the test licence, MCP host technical quotas, and the Tester's configured approval policies. Without prior written authorization: load tests, fuzzing, intrusion scans, mass automation, and any use intended to saturate or abuse third-party APIs (ConnectWise, etc.) are forbidden.
- Support: bug reports via the designated channel (e.g. GitHub templates). Security vulnerabilities exclusively via the private security channel (Notices) and never in a public issue.
- Planned deactivation: at commercial GA release, licence/token revocation, or end of participation — whichever occurs first.
26Schedule B – Authorized Users and access
- Default Authorized User: the natural person identified in the tester application (first name, last name, email) is the sole Authorized User, for the organization indicated (company / MSP name), if any.
- Access: individual, named, revocable; granted via test licence/token and configuration of the Tester's local MCP host.
- Adding Authorized Users: only with the Provider's prior written approval (email privacy@pulsatrix.ca). Anyone not listed here or not approved in writing is unauthorized.
- Revocation: immediate on Provider decision, end of Test Period, or Tester request; the token/licence may be revoked without notice for security risk or breach of this Agreement.
- Country of residence / use: those declared or reasonably inferable from information provided; the Tester must inform the Provider of any material change.
27Schedule C – Operational test rules
- Do not use real, sensitive, or personal data except under a separate written authorization.
- Do not run automated, load, or intrusion tests without written authorization.
- Do not export, capture, or retain data without written authorization.
- Report any bug, flaw, or incident to privacy@pulsatrix.ca (subject "SECURITY" for a vulnerability — private channel only).
- Do not share access or allow access by anyone not listed in Schedule B.
28Schedule D – Minimum security measures
General:
- Individual account for each Authorized User.
- Multi-factor authentication when available.
- Strong, non-reused password.
- Access from controlled, up-to-date, protected devices.
- No sharing in public tools, AI systems, code repositories, or unapproved collaboration spaces.
- Deletion of copies, notes, captures, and exports at the end of the test.
- Immediate notice on lost access, compromised device, or suspected disclosure.
Regarding MCP:
- only listed connectors are authorized;
- read-only access by default;
- no write rights without authorization;
- no use of real personal accounts unless the Tester accepts the risk;
- production environments only at the Tester's own risk;
- automatic token revocation at end of test;
- MCP call logging;
- scope limitation;
- environment separation;
- prohibition of prompt injection, tool poisoning, prompt extraction, exfiltration;
- obligation to report immediately any unexpected agent or connector behaviour.
29Schedule E – MCP connectors, accounts, and data scope
| Item | Allowed? | Notes |
|---|---|---|
| Local Pulsatrix MCP host (STDIO) + Tester MCP client | Yes | On Tester infrastructure |
| PSA, RMM, CPQ, ScreenConnect, SentinelOne, Axcient x360 domains | Yes, per licence | Loaded dynamically per entitlements |
| READ actions | Yes | Prefer a designated test tenant/environment |
| WRITE / INTENSE actions | Yes if licence and Tester approval policy allow | Human approval as configured; prefer a test tenant |
| Unauthorized raw write API | No | Fail-closed / preview per product |
| Real customer / production data | At your own risk | Tester assumes all risk; a written data-processing agreement is recommended when processing third-party personal information |
| Secrets, API keys, tokens | Local storage | OS keychain / Tester local config; no sharing outside Permitted Purpose |
30Schedule F – Privacy notice applicable to testers and Authorized Users
The Provider may log connections, IP addresses, devices, activities, and other metadata related to the site, application, acceptance of this Agreement, licensing, and support. Those logs may constitute personal information.
| Item | Description |
|---|---|
| Data | Name, email, organization, country if provided, IP address, device / technical logs, NDA acceptance (version, timestamp), licence metadata, pseudonymous / aggregated product telemetry when enabled, bug reports you send |
| Purposes | Security, proof of acceptance, access and licence management, support, product improvement, Agreement enforcement |
| Basis | Performance of the Agreement / pre-contractual steps; legitimate interests (security, abuse); consent where required (e.g. optional analytics) |
| Retention | As long as needed for purposes, legal obligations, and dispute resolution; then deletion or anonymization |
| Locations | Provider site and cloud services (e.g. Azure hosting depending on deployment); the MCP host runs locally at the Tester |
| Processors | Cloud hosting, transactional email, payment processor (Stripe) where applicable — see Privacy Policy |
| Transfers outside Québec | Appropriate contractual and organizational measures; PIA when required by Law 25 |
| Rights | Access, correction, deletion, withdrawal of consent where applicable — privacy@pulsatrix.ca; CAI in Québec |
| Controller contact | Pulsatrix Technologies Inc. — Privacy Officer — privacy@pulsatrix.ca |
| Incidents | Confidentiality-incident process; notification under Law 25 and other applicable laws |
| Measures | Access controls, encryption in transit on public services, minimization, local secrets (OS keychain) |
Public detail: Privacy Policy.
31Schedule G – Destruction / return attestation (electronic form)
When the Provider requires a destruction or return attestation, the Tester sends it by email to privacy@pulsatrix.ca, stating:
- Full name and organization of the Tester
- Email used for the application / licence
- Access end date
- The following declaration (copy-paste):
I confirm, on behalf of the Tester, that in accordance with the Pulsatrix Confidentiality and Beta Testing Agreement (NDA), the Tester and its Authorized Users have ceased all use of the Beta Software and have returned or destroyed, to the extent reasonably possible, all copies, notes, captures, exports, documents, identifiers, access, files, data, and other elements containing or reflecting the Provider's Confidential Information. Residual copies in automatic backups will remain confidential and will not be restored except for technical necessity.
No paper form is required unless the Provider expressly requires it in writing.
Accept and apply
The NDA checkbox on the registration form is required. It records version, UTC timestamp, identity, and IP with your application.
PULSATRIX