Coilvault legal

Contributor & Data Rights Agreement

Version 1.0 · Effective date: July 30, 2026

This Contributor & Data Rights Agreement (the “Agreement”) is between COILVAULT LLC, a Florida limited liability company (“CoilVault,” “we,” “us,” or “our”), and the business entity accepting this Agreement (“Customer,” “Company,” “you,” or “your”). This Agreement governs rights and responsibilities relating to data submitted to or generated through the CoilVault platform. It is incorporated into the CoilVault Terms of Service.

1. Electronic Acceptance and Authority

By selecting “I Agree,” “Create Account,” or a similarly designated acceptance control, Customer agrees to this Agreement, the Terms of Service, and the Privacy Policy. The individual accepting represents that the individual is at least eighteen years old and has authority to bind Customer. Access to the Platform is conditioned on acceptance. CoilVault may retain an electronic record of the accepting user, Customer account, agreement version, language presented, date and time, IP address or device information where reasonably available, and related audit information.

2. Relationship to Other Documents

This Agreement controls with respect to ownership, licensing, aggregation, de-identification, retention, deletion, and use of Customer Data and Derived Data. The Terms of Service control subscriptions, billing, acceptable use, service availability, disclaimers, and other commercial matters. The Privacy Policy describes CoilVault’s handling of personal information. If there is a conflict on a data-rights matter, this Agreement controls.

3. Definitions

“Account Data” information relating to Customer and its Authorized Users, including registration, authentication, role, consent, subscription, billing-status, and support information.

“Aggregate Data” statistical, analytical, benchmarking, reliability, trend, operational, or similar information created by combining or analyzing information from multiple records or lawful sources and processed so that it does not reasonably identify a natural person, household, specific property, or Customer.

“Authorized User” an owner, employee, contractor, technician, or other person Customer authorizes to use the Platform under its account.

“Customer Data” information submitted, uploaded, imported, synchronized, photographed, signed, or otherwise made available by or for Customer through the Platform, including customer and homeowner information, property addresses, equipment information, service histories, notes, estimates, invoices, electronic signatures, photographs, and documents. Customer Data excludes Derived Data and CoilVault technology.

“De-Identification Standard” the documented technical and administrative controls described in Section 7.3.

“Derived Data” Aggregate Data and other analytics, statistical models, trends, reliability analyses, failure-rate information, quality metrics, metadata, and insights created by CoilVault through processing Customer Data, provided the resulting information does not reasonably identify a natural person, household, specific property, or Customer.

“Personal Information” information defined as personal data, personal information, personally identifiable information, or a similar term under applicable law.

“Platform” CoilVault’s software, applications, websites, databases, APIs, hosted services, documentation, and related technology.

4. Customer Ownership

As between the parties, Customer retains all right, title, and interest in Customer Data. CoilVault does not acquire ownership of Customer’s customer lists, homeowner information, service records, photographs, signatures, or documents merely because they are stored or processed through the Platform. Customer remains responsible for the legality, accuracy, integrity, and completeness of Customer Data and for its relationships with the persons described in Customer Data.

5. Operational License

During the term, Customer grants CoilVault a worldwide, non-exclusive, royalty-free license, sublicensable only to service providers acting for CoilVault and transferable in connection with a merger, acquisition, financing, reorganization, or sale of substantially all relevant assets, to host, store, reproduce, transmit, display, organize, index, back up, archive, convert, process, secure, troubleshoot, support, and otherwise use Customer Data as reasonably necessary to provide, maintain, improve, and protect the Platform; respond to support requests; prevent fraud and abuse; conduct testing, migration, disaster recovery, auditing, and quality assurance; and comply with law.

6. Analytics and Product Improvement

Customer authorizes CoilVault to analyze Customer Data to improve software functionality, search, recommendations, equipment guidance, reporting, system performance, quality assurance, fraud prevention, and internal research and development. Identifiable Customer Data may be used for these purposes only to the extent reasonably necessary, subject to the Privacy Policy, access controls, confidentiality obligations, and applicable law.

7. Aggregation, De-Identification, and Derived Data

7.1 Right to Create Derived Data

Customer grants CoilVault a perpetual, irrevocable, worldwide, royalty-free right to create Derived Data from Customer Data received before termination by aggregating, combining, analyzing, modeling, benchmarking, anonymizing, de-identifying, generalizing, suppressing, or otherwise processing that Customer Data with other records or lawful data sources.

7.2 Ownership and Permitted Use

As between the parties, CoilVault owns Derived Data and may use it to operate, secure, improve, and develop the Platform; provide de-identified equipment guidance, reliability statistics, trends, and benchmarking to Platform users; conduct internal research and product development; and prepare research or business analyses that do not reasonably identify a natural person, household, specific property, or Customer. CoilVault will not sell or license Customer Data or Derived Data to third parties as a standalone data product under this Version 1.0. Any future external data-licensing program requires an updated agreement and affirmative acceptance by affected Customers before newly contributed Customer Data is used for that program.

7.3 De-Identification Standard

Before displaying or disclosing Derived Data outside CoilVault’s restricted internal environment, CoilVault will apply documented, risk-based de-identification controls reasonably designed to prevent the output from being linked to a natural person, household, specific property, or Customer. At a minimum, the controls will include:

  • a minimum publication threshold of ten independent service records for each displayed model-by-geography-by-failure or comparable cell;

  • a minimum of three contributing Customer accounts where the identity of one contributing Customer could otherwise be inferred;

  • suppression, combination, or geographic generalization of sparse cells, rare events, outliers, and differencing queries;

  • prohibition on displaying names, contact details, street addresses, unit numbers, serial numbers, free-text notes, photographs, signatures, invoice references, or other direct identifiers;

  • controls against repeated querying or filtering that could isolate a record or property; and

  • periodic review and adjustment of thresholds and controls based on data density, foreseeable re-identification risk, changes in technology, and applicable law.

The numerical thresholds above are minimum launch safeguards, not a representation that every dataset meeting them is automatically safe. CoilVault may use a higher threshold, withhold an output, broaden the geography, round or bucket values, or apply additional statistical disclosure controls whenever reasonably necessary. When the threshold is not met, the Platform will use non-network baseline guidance or display that insufficient data is available.

7.4 No Record-Level Opt-Out

Because the de-identified network statistics are an integral feature of the Services, Customer may not opt individual records out of lawful creation of Derived Data. CoilVault may exclude or quarantine records for data-quality, legal, safety, fraud-prevention, or de-identification reasons. This section does not limit a person’s rights in identifiable Personal Information under applicable law.

8. Survival and Durability of Aggregation Rights

Sections 6 and 7 survive termination solely with respect to Customer Data received before termination. CoilVault may continue to retain and use Derived Data lawfully created before or after termination from such previously received Customer Data, provided the resulting Derived Data continues to satisfy the De-Identification Standard. Termination does not require CoilVault to reconstruct, recalculate, or remove a historical de-identified statistic merely because a contributing Customer later leaves the Platform.

9. Deletion, Return, and Backups

Upon a valid request and to the extent required by law or CoilVault’s published retention practices, CoilVault will delete or return identifiable Customer Data within a commercially reasonable period, subject to legal holds, fraud prevention, billing and consent records, security logs, dispute records, backup cycles, and other lawful retention needs. Deletion from active systems does not require immediate deletion from encrypted or access-restricted backups, which may remain until overwritten in the ordinary backup cycle and may not be restored except for disaster recovery, security, or legal necessity.

A deletion request concerning identifiable Customer Data does not require deletion, reconstruction, or recalculation of Derived Data that was previously created in compliance with Section 7 and no longer reasonably identifies the requesting person, household, property, or Customer. If an output no longer satisfies the De-Identification Standard after deletion or changed circumstances, CoilVault will suppress or re-generalize that output before further display.

10. Customer Representations and Responsibilities

  1. Customer has all rights, permissions, licenses, notices, and lawful authority necessary to collect and submit Customer Data and authorize the processing described in this Agreement.

  2. Customer will not upload information it is prohibited from collecting or disclosing and will comply with applicable privacy, consumer-protection, employment, recording, intellectual-property, and professional laws.

  3. Customer will provide required notices to homeowners, tenants, customers, employees, and other individuals and will cooperate with verified privacy requests.

  4. Customer will ensure that Authorized Users use unique credentials, follow reasonable security practices, and access only information needed for legitimate business purposes.

  5. Customer will not use equipment guidance or statistics as a substitute for professional judgment, code compliance, manufacturer instructions, safety requirements, or legally required inspection.

11. Public Records and Other Data Sources

CoilVault may obtain and commercially use lawfully available government records and public datasets, including county permit, property-appraiser, and public address data, subject to applicable access terms, fees, exemptions, accuracy limitations, and restrictions imposed by the source. Public availability does not eliminate privacy, intellectual-property, contractual, or use restrictions that may apply to a particular source. CoilVault will not ingest MLS data, broker-restricted listing content, privately owned inspection reports, or other contract-restricted content without a separate rights review and documented authorization.

12. Homeowner and Customer Information

Customer is primarily responsible for notices and permissions relating to Customer Data it collects. CoilVault may provide standardized disclosures or authorization tools, but Customer remains responsible for using them appropriately and for not entering false or misleading information. CoilVault may require identity or authority verification before honoring a request or authorization.

13. Cross-Company Property History Feature

13.1 Disabled Until Approved

The feature allowing one Customer to view service history created by another Customer for the same property is disabled at launch. CoilVault will not activate the feature until it has implemented the authorization, verification, access-control, audit, revocation, and retention measures in this Section and updated the Privacy Policy as appropriate.

13.2 Required Homeowner Authorization

Cross-company access may be granted only after CoilVault obtains or records an affirmative authorization from the property owner, homeowner, tenant with documented authority, property manager, or other person legally authorized to grant access. The authorization must identify the property, the company receiving access, the categories of history disclosed, the purpose, the effective date, the expiration date, the right to revoke, and the fact that revocation does not undo access or disclosures that lawfully occurred before revocation.

13.3 Scope and Expiration

Authorization will be property-specific, recipient-specific, and time-limited. Unless a shorter period is selected, authorization expires ninety days after grant. It will not permit bulk access, marketing use, disclosure outside the requesting Customer, access to payment-card information, access to electronic signature images, or access to photographs unless photographs are expressly included and necessary for the stated service purpose.

13.4 Audit and Revocation

CoilVault will record the authorization language and version, language presented, authorizing person, verification method, recipient Customer, scope, grant and expiration timestamps, revocation timestamp, and access events. Revocation will block future access promptly after processing. CoilVault may suspend or terminate access if authorization is disputed, appears invalid, or presents a privacy or security risk.

13.5 Authorization Form

The following form is the minimum required language and may be adapted for the interface without changing its substance:

“I authorize CoilVault to make the service-history categories I select for [PROPERTY ADDRESS] available to [REQUESTING COMPANY] for the purpose of evaluating, servicing, repairing, or maintaining equipment at that property. I understand that the history may include dates of service, equipment details, diagnoses, repairs, and parts replaced. It will not include payment-card information or electronic signature images. Photographs will be included only if I separately select that option. This authorization expires on [DATE] unless I revoke it sooner. I may revoke future access through [METHOD], but revocation will not undo access or use that occurred before CoilVault processed my revocation. I confirm that I am authorized to grant access for this property.”

14. Photographs, Signature Images, and Uploaded Files

Photographs and signature images are Customer Data and may contain Personal Information. They will be stored in private, access-controlled storage, with database records holding references where practical. Access will be limited by role and business need. Signature images will not be included in Derived Data, cross-company history, general exports to other Customers, or equipment guidance. CoilVault may preserve a signature image or associated audit record for the period reasonably necessary to evidence the transaction, resolve disputes, satisfy legal requirements, and enforce agreements.

Unless a longer period is required by law, contract, litigation hold, or documented Customer instruction, CoilVault’s launch retention schedule will be: active-account photographs and signature images retained while the related record and account remain active; export availability for thirty days after termination; deletion from active storage within ninety days after the export window; encrypted backup expiration within one hundred eighty days after active deletion; consent, signature-audit, billing, and agreement-acceptance records retained for at least five years after the relevant transaction or account closure. CoilVault may adopt shorter periods or provide Customer-controlled deletion where operationally feasible.

15. Privacy and Security

CoilVault will maintain reasonable administrative, technical, and physical safeguards appropriate to the volume, sensitivity, and nature of Customer Data. Safeguards will include access controls, least-privilege permissions, authentication protections, encryption in transit, encryption at rest where supported and appropriate, private file storage, logging of privileged and cross-company access, vendor review, backups, vulnerability and patch management, incident-response procedures, and periodic access review. CoilVault does not guarantee that security incidents will never occur.

16. Security Incidents

CoilVault will investigate suspected security incidents and provide notices required by applicable law. Customer will promptly notify CoilVault of suspected credential compromise or unauthorized use and reasonably cooperate in investigation and remediation. Where CoilVault acts as Customer’s service provider and a confirmed incident affects Customer Data, CoilVault will notify Customer without unreasonable delay after confirmation and provide information reasonably available for Customer’s legal assessment, subject to law-enforcement restrictions and security needs.

17. Confidentiality

Each party will protect the other party’s nonpublic business, technical, security, and customer information using at least reasonable care; use it only to perform or enforce the agreements; and disclose it only to personnel, advisors, and service providers with a legitimate need to know and appropriate confidentiality duties. Exclusions apply to information lawfully public, previously known without restriction, independently developed, or lawfully received from a third party. Required disclosures may be made by law, with notice where legally permitted.

18. Platform Intellectual Property

Except for Customer Data, CoilVault and its licensors own the Platform, software, documentation, databases, interfaces, designs, workflows, algorithms, models, trademarks, trade secrets, and related intellectual property. Customer receives only the limited right to use the Services during its subscription. Customer may not copy, reverse engineer, decompile, create derivative works from, scrape, or use the Platform to develop a competing product except where a restriction is prohibited by law.

19. Disclaimers

THE PLATFORM, EQUIPMENT GUIDANCE, FAILURE STATISTICS, AND DERIVED DATA ARE PROVIDED “AS IS” AND “AS AVAILABLE.” TO THE MAXIMUM EXTENT PERMITTED BY LAW, COILVAULT DISCLAIMS IMPLIED WARRANTIES, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT. INFORMATIONAL OUTPUTS MAY BE INCOMPLETE, DELAYED, OR INACCURATE AND ARE NOT ENGINEERING ADVICE, A SAFETY CERTIFICATION, A WARRANTY DETERMINATION, A CODE-COMPLIANCE OPINION, OR A SUBSTITUTE FOR QUALIFIED PROFESSIONAL JUDGMENT.

20. Limitation of Liability

TO THE MAXIMUM EXTENT PERMITTED BY LAW, NEITHER PARTY WILL BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR FOR LOST PROFITS, REVENUE, BUSINESS, GOODWILL, OR DATA. COILVAULT’S TOTAL AGGREGATE LIABILITY ARISING FROM THIS AGREEMENT WILL NOT EXCEED THE FEES PAID OR PAYABLE BY CUSTOMER FOR THE SERVICES DURING THE TWELVE MONTHS BEFORE THE EVENT GIVING RISE TO LIABILITY. THESE LIMITATIONS DO NOT APPLY TO LIABILITY THAT CANNOT LAWFULLY BE LIMITED.

21. Indemnification

Customer will defend and indemnify CoilVault and its personnel from third-party claims arising from Customer Data, Customer’s collection or submission of Customer Data, Customer’s violation of law or third-party rights, or misuse of the Platform by Customer or its Authorized Users, except to the extent caused by CoilVault’s gross negligence or willful misconduct. CoilVault will provide prompt notice and reasonable cooperation; Customer may not settle a claim in a manner admitting CoilVault wrongdoing or imposing nonmonetary obligations without consent.

22. Term and Termination

This Agreement begins upon electronic acceptance and continues while Customer uses the Services. Termination of a subscription ends access but does not affect accrued obligations or provisions that survive, including Sections 7 through 9, 14, 17 through 21, and 25 through 29.

23. Data Processing Addendum

A separate data processing addendum is not required for the initial small-business Florida launch. CoilVault may offer a DPA to enterprise customers or where required by applicable law, procurement terms, or expansion into jurisdictions imposing controller-processor contract requirements. No Customer may impose a DPA unilaterally.

CoilVault may update this Agreement. Nonmaterial changes may be communicated by posting or notice. Material changes affecting Customer Data rights, Derived Data use, external data licensing, cross-company disclosure, dispute resolution, or Customer obligations will be presented for affirmative click-through acceptance before the changed terms apply to continued use or newly submitted Customer Data. CoilVault will record the accepted version and timestamp.

25. Governing Law and Venue

Florida law governs without regard to conflict-of-law rules. Exclusive venue for disputes lies in the state courts located in Broward County, Florida, or the federal court having jurisdiction over Broward County, and each party consents to personal jurisdiction there. Before filing suit, the parties will attempt in good faith for thirty days to resolve the dispute through executive-level discussion. This does not prevent temporary injunctive relief for security, confidentiality, or intellectual-property harm.

26. Notices

Legal notices to CoilVault must be sent to COILVAULT LLC, 17479 SW 21 Ct, Miramar, FL 33029, and coilvault.app@gmail.com. Notices to Customer may be sent to the account email or through the Platform and are effective when sent, except where law requires another method.

27. Assignment

Customer may not assign this Agreement without CoilVault’s written consent. CoilVault may assign it in connection with a merger, financing, reorganization, change of control, or sale of substantially all relevant assets, provided the assignee assumes applicable obligations.

28. General Provisions

The agreements constitute the entire agreement concerning their subject matter and supersede prior discussions. Failure to enforce a provision is not a waiver. Invalid provisions will be enforced to the maximum lawful extent and the remainder will continue. Headings are for convenience. Neither party is the other’s agent, partner, joint venturer, fiduciary, or employee. Neither party is liable for delay caused by events beyond reasonable control, except payment obligations. Electronic records and signatures are permitted.

29. Language

The English and Spanish versions are intended to convey the same terms. Customer may review and accept either language version. The acceptance record will identify the language presented. If an inconsistency exists, the English version controls to the maximum extent permitted by law; however, CoilVault will not rely on the controlling-language clause to enforce a materially different term that was not fairly disclosed in the language presented to the accepting user.

30. Contact

COILVAULT LLC
17479 SW 21 Ct
Miramar, Florida 33029
coilvault.app@gmail.com