| Provider | Thirtysix Solutions, LLC, a Virginia limited liability company |
| Version | 1.0 (draft for counsel approval) |
| Version date | 2026-08-24 |
| Notice address | Thirtysix Solutions, LLC, 43450 Interval St., Chantilly, VA 20152 |
| Notice email | legal@fieldscroll.com |
These Terms of Service (the "Terms") govern business access to and use of the FieldScroll platform, including its web, mobile, API, document-generation, export, routing, and related support surfaces (collectively, the "Service"). FieldScroll is offered by Thirtysix Solutions, LLC ("Provider").
1. Agreement and contract structure
1.1 Acceptance and authority
A company or other organization that signs or accepts an Order Form is the "Customer." The individual accepting for Customer represents that the individual has authority to bind Customer. The Agreement is between Provider and Customer. Customer may authorize its personnel and contractors to use the Service as "Authorized Users" and is responsible for their compliance with the applicable use restrictions. Unless an Order Form expressly states otherwise, an Authorized User is not required to separately sign the Agreement.
1.2 Agreement documents
The agreement consists of the applicable Order Form, these Terms, the EULA, any signed Data Processing Addendum ("DPA"), and any other attachment expressly incorporated by a signed Order Form (collectively, the "Agreement"). A separately signed master services agreement applies only if the Order Form identifies it by title and date.
1.3 Order of precedence
For a conflict, the following order controls: (a) the DPA for processing personal data; (b) the Order Form for customer-specific scope, fees, term, usage limits, support, and expressly identified changes; (c) a specifically identified master services agreement; (d) these Terms; and (e) the EULA. A purchase order, vendor portal, Customer policy, or click-through term does not modify the Agreement unless Provider expressly signs the modification.
1.4 Business use only
The Service is offered for business use and is not intended for personal, household, or consumer use. Customer may not permit a person under 18 to use the Service without Provider's prior written approval and a documented legal basis.
2. Orders, access, and accounts
2.1 Order Forms
Each Order Form states the plan or pilot, term, authorized footprint, fees, retention, support, and permitted use. Provider has no obligation to provision access until the Order Form and all required attachments are signed or accepted and any onboarding conditions are satisfied.
2.2 Customer administrator
Customer will designate at least one administrator who may invite users, assign roles, approve configurations, receive operational notices, and request exports or deletion. Customer will also identify an authorized contract contact for Agreement notices and changes. Provider may rely on instructions from a designated administrator or contract contact within that person's stated authority until Customer gives written notice of a change.
2.3 Account security
Customer and Authorized Users must use unique accounts, maintain accurate registration information, protect credentials and devices, comply with account-security controls that Provider actually makes available and expressly requires for the applicable role, promptly remove departed users, and notify Provider without unreasonable delay of suspected unauthorized access. Shared accounts are prohibited unless an Order Form expressly permits a controlled service account. These Terms do not represent that multi-factor authentication is currently available or required. Customer may remove an Authorized User's access at any time through the administrator controls. Removing access ends the user's ability to read or write Customer Data in the Service; Customer is responsible for directing the user to sign out and delete unsynchronized data from any personal device.
2.4 Organizational acceptance and user notices
Provider may require Customer's authorized representative to sign or electronically accept versioned Agreement documents before access is provisioned. Provider may preserve reasonable evidence of organizational assent, including the Customer, signer, authority, document version, timestamp, and signature audit record. Authorized Users are not required to execute the Agreement individually unless a specific Order Form or applicable law expressly requires it. Provider may deliver concise operational, privacy, security, or policy notices within the Service; an in-product notice does not make an Authorized User a separate signatory unless it expressly says so.
3. Service and license
3.1 Limited access right
During the applicable Order Term and subject to the Agreement, Provider grants Customer a limited, nonexclusive, nontransferable, non-sublicensable right for authorized users to access and use the Service for Customer's internal business purpose and the use case stated in the Order Form.
3.2 Platform role
FieldScroll is a managed capture, review, document, export, and routing layer. Unless an Order Form expressly says otherwise, it is not Customer's long-term system of record, backup system, disaster-recovery system, legal archive, regulatory filing service, or source of professional advice.
3.3 Changes
Provider may improve, update, replace, or discontinue features. Provider will use commercially reasonable efforts to give advance notice of a material reduction to a paid committed Service. Pilot, beta, preview, and evaluation features may change or end at any time and may not receive all production support commitments.
3.4 Usage limits
The organizations, users, workflows, records, storage, retention, API, export, and integration figures in an Order Form are scope and capacity guardrails. Provider will not automatically suspend ordinary pilot use solely because of a modest inadvertent overage. Provider may notify Customer and request a written scope adjustment when actual use materially exceeds the agreed footprint, and may take proportionate action when necessary to protect security, availability, or material third-party costs. Provider does not currently enforce user or record limits automatically; the figures are monitored and any material overage is handled by notice and written scope adjustment under this Section.
3.5 Environment
Unless the Order Form states that Customer receives a dedicated environment, the Service is delivered from a shared FieldScroll environment in which each customer organization is isolated by database row-level access controls. Customer's data is not accessible to other customers' users.
4. Customer responsibilities and acceptable use
4.1 Customer responsibility
Customer is responsible for its workflows, forms, instructions, users, devices, data, approvals, downstream systems, business decisions, regulatory obligations, and use of Service output. Customer will test configurations and outputs before relying on them.
4.2 Prohibited conduct
Customer and users may not: violate law or third-party rights; upload malicious code; attempt unauthorized access; defeat security or usage controls; interfere with other customers; probe, scan, or test the Service without written permission; scrape or resell the Service except as an Order Form allows; reverse engineer except where law forbids the restriction; use the Service to build a competing product using nonpublic features; or use output to make an unlawful discriminatory decision.
4.3 High-risk and restricted uses
Unless a signed Order Form or addendum expressly authorizes the use, Customer will not use the Service for emergency response, life-support or life-safety decisions, autonomous employment or credit decisions, regulatory filing, payroll or payment processing, medical diagnosis, or another activity where failure could reasonably cause death, bodily injury, material property damage, loss of legal rights, or severe financial harm.
4.4 Restricted Data
Customer will not submit protected health information, payment-card data, government-classified or export-controlled data, biometric identifiers, Social Security numbers, student education records, criminal-history data, precise location used for sensitive profiling, special-category personal data, or another regulated or highly sensitive category ("Restricted Data") unless the Order Form identifies it and Provider accepts it in writing.
5. Customer Data
5.1 Ownership
As between the parties, Customer owns data, content, forms, files, images, signatures, records, and other materials Customer or its users submit to the Service ("Customer Data"). Provider does not acquire ownership of Customer Data.
5.2 Processing license
Customer grants Provider and its approved subprocessors a limited right to host, copy, transmit, transform, render, display, back up, and otherwise process Customer Data only to provide, secure, support, and improve the Service, comply with law, and perform the Agreement.
5.3 Customer warranties
Customer represents that it has all rights, notices, consents, instructions, and legal bases needed to provide Customer Data and permit its processing. Customer is responsible for data accuracy, lawful collection, records retention, disclosure to its personnel and customers, and the consequences of Customer's workflow design.
5.4 Service Data and de-identified data
Provider may collect technical logs, telemetry, usage metrics, and support records needed to operate and secure the Service ("Service Data"). Provider may use data that has been aggregated or de-identified so that it does not identify Customer, a user, or a person, and will not attempt to re-identify it. Each record submitted from the mobile application carries the submitting device's model, operating system and version, and application version. This device metadata is part of the record and is delivered with it to any integration or destination Customer configures.
5.5 AI and model training
Provider will not use Customer Data to train a machine-learning model. The Service's optional AI assistant for building forms, reports, and integrations sends the user's messages, the relevant form and report definitions, and any images the user attaches to Anthropic, PBC, a subprocessor listed in the DPA, to generate proposed changes. Anthropic processes that content under its commercial API terms, does not train models on it, and deletes it within 30 days of receipt. The AI assistant is enabled per environment by Provider and is off unless the Order Form states otherwise. Customer will instruct its users not to attach images or paste content containing Restricted Data or personal data into the AI assistant.
6. Privacy, security, and subprocessors
6.1 Privacy
Provider's Privacy Notice is available at https://www.fieldscroll.com/privacy. Privacy requests may be sent to privacy@fieldscroll.com and account-deletion requests to account-deletion@fieldscroll.com. The Privacy Notice describes Provider's own data practices and does not replace Customer's notices to its workforce, customers, or other data subjects.
6.2 DPA
If Provider processes personal data for Customer as a processor or service provider, the parties will execute the DPA before that data is submitted. Customer is the controller or business unless applicable law assigns a different role.
6.3 Security
Provider will maintain commercially reasonable administrative, technical, and organizational safeguards appropriate to the Service and the data identified in the Order Form. No service can guarantee security, uninterrupted operation, or recovery of every record. Customer must use the security controls available to it.
6.4 Security incidents
Provider will notify Customer without unreasonable delay after confirming unauthorized access to Customer Data in Provider's possession or control, provide reasonably available information, and take commercially reasonable containment and remediation steps. Customer is responsible for notices to its users, customers, regulators, insurers, and other parties unless law or a signed DPA states otherwise.
6.5 Subprocessors
Provider may use subprocessors to deliver the Service. The current subprocessor schedule is Attachment 2 to the DPA and is also published at https://www.fieldscroll.com/legal/subprocessors. Provider will follow the change process in the DPA.
7. Third-party services and mobile stores
7.1 Third-party dependencies
The Service may interoperate with cloud hosts, app stores, identity providers, analytics, monitoring, email, document rendering, APIs, mobile operating systems, and Customer systems. Those services are governed by their own terms and may change, suspend, or fail. Provider is not responsible for third-party acts or outages outside its reasonable control.
7.2 Customer integrations
Customer authorizes Provider to transmit Customer Data to an integration or destination configured or approved by Customer. Customer is responsible for credentials, permissions, destination security, data mapping, and third-party fees.
7.3 App stores
Apple, Google, and other distributors are not parties to the Agreement and do not provide Provider's support. Mobile use is also subject to the applicable store rules and the store-specific terms in the EULA.
8. Fees, taxes, and pilots
8.1 Fees
Customer will pay the fees, taxes, and approved third-party charges in the Order Form. Unless the Order Form says otherwise, invoices are due within 15 days. Overdue undisputed amounts may accrue interest at 1.5% per month or the maximum lawful rate, whichever is less.
8.2 No implied free use
A no-fee pilot applies only for the period and footprint in its signed Order Form. It does not create a right to future free access, support, custom development, or production use.
8.3 No automatic pilot conversion
A pilot does not automatically renew, convert, or create a charge unless its Order Form expressly states otherwise. Continued access requires a new signed Order Form for one of Provider's then-current published plans, or a written extension of the pilot.
8.4 Taxes
Fees exclude taxes other than taxes on Provider's net income. Customer is responsible for applicable sales, use, value-added, withholding, and similar taxes, subject to valid exemption documentation.
9. Intellectual property and feedback
9.1 Provider Materials
Provider and its licensors own the Service, software, interfaces, designs, documentation, forms and templates supplied by Provider, methods, workflows, APIs, know-how, updates, and all related intellectual property ("Provider Materials"). Except for the limited rights expressly granted, Provider reserves all rights.
9.2 Customer Materials
Customer retains ownership of Customer's pre-existing trademarks, instructions, documents, workflow content, and other materials. Customer grants Provider the limited rights necessary to perform the Agreement.
9.3 Feedback
Customer may provide suggestions or feedback. Provider may use feedback without restriction or obligation, provided it does not identify Customer or disclose Customer Confidential Information without approval.
9.4 Publicity
Provider may not use Customer's name, logo, testimonial, screenshots, or public case study without Customer's prior approval of the specific use.
10. Confidentiality
10.1 Confidential Information
Confidential Information means nonpublic business, technical, security, financial, customer, employee, product, and operational information that is marked confidential or reasonably should be understood as confidential. Customer Data and nonpublic Provider Materials are Confidential Information.
10.2 Protection and use
Each party will use the other party's Confidential Information only to perform or receive the Agreement, protect it with at least reasonable care, and disclose it only to personnel, contractors, advisors, and subprocessors who need to know it and are bound by confidentiality obligations.
10.3 Exclusions and compelled disclosure
Confidential Information excludes information lawfully public, already known without restriction, independently developed without use of the other party's information, or lawfully received from a third party. A party may disclose information when legally required, with notice and protective cooperation when legally permitted.
10.4 Duration
Confidentiality obligations continue for three years after termination, except trade secrets remain protected while they qualify as trade secrets and personal data remains protected as required by law and the DPA.
11. Support, suspension, and availability
11.1 Support
Support hours, channels, response targets, maintenance, and service levels are only those stated in the Order Form or in a master services agreement expressly identified there. When an existing MSA governs support for a no-fee pilot, those applicable support terms may apply without an additional platform support charge unless the Order Form says otherwise. A Customer without a governing MSA receives only the included and paid support expressly described in the Order Form. Response targets are not guaranteed resolution times, and no service-level credit applies unless the controlling document expressly creates one.
11.2 Maintenance
Provider may perform planned or emergency maintenance. Provider will use commercially reasonable efforts to give advance notice of planned maintenance expected to materially affect a paid production Service.
11.3 Suspension
Provider may suspend affected access for a security risk, unlawful use, material breach, nonpayment, usage that threatens the Service, Customer's failure to maintain safe access controls, or an emergency. Provider will limit a suspension to what is reasonably necessary and give notice when practicable.
12. Term, termination, and data transition
12.1 Term
These Terms begin when Customer first accepts an Order Form and continue while any Order Form remains active. Each Order Form states its own Order Term.
12.2 Termination for cause
Either party may terminate an affected Order Form for material breach not cured within 10 business days after written notice. Provider may terminate or suspend immediately for unlawful conduct, a material security threat, or a breach that cannot reasonably be cured.
12.3 Effect
At termination, Customer's access ends and unpaid amounts become due. During the 30-day export window following termination (or a longer window stated in the Order Form), Customer may request an export of then-available Customer Data. Provider will deliver submitted records in CSV or JSON format and attached media as a per-organization archive within ten business days of the request. After the export window, Provider will delete Customer Data from active systems and from Provider-managed media backups under the DPA, subject to legal retention and the provider-managed database backup cycle.
12.4 Pilot end
A no-fee pilot ends automatically on its stated end date. Customer Data remains available for the full pilot term and for the export window in Section 12.3; the Service does not delete Customer Data automatically during or at the end of the pilot. Provider may disable access at the pilot end date. Within the export window Customer will elect in writing one of: export and deletion; extension under a new signed Order Form; or conversion to a paid plan under a new signed Order Form. If Customer makes no election, Provider will proceed with deletion under Section 12.3 after the export window.
13. Warranties and disclaimers
13.1 Mutual authority
Each party warrants that it has authority to enter the Agreement.
13.2 Professional performance
Provider warrants that any services expressly included in an Order Form will be performed in a professional and workmanlike manner. Customer's exclusive remedy is re-performance if Customer gives specific written notice within 10 business days after the affected service.
13.3 Disclaimer
EXCEPT FOR THE EXPRESS WARRANTY ABOVE, THE SERVICE, PILOT, BETA, OR PREVIEW FEATURES, PILOT ENVIRONMENTS, OUTPUT, DOCUMENTS, AND SUPPORT ARE PROVIDED "AS IS" AND "AS AVAILABLE." TO THE FULLEST EXTENT PERMITTED BY LAW, PROVIDER DISCLAIMS IMPLIED OR STATUTORY WARRANTIES, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, NON-INFRINGEMENT, ACCURACY, DATA RECOVERY, UNINTERRUPTED OPERATION, ERROR-FREE OPERATION, AND ANY GUARANTEED BUSINESS, REVENUE, REGULATORY, OR COMPLIANCE OUTCOME.
14. Indemnification
14.1 Customer indemnity
Customer will defend, indemnify, and hold harmless Provider and its personnel from third-party claims arising from Customer Data, Customer's workflow or business operations, Customer's violation of law or third-party rights, Customer's instructions, or unauthorized use of the Service.
14.2 Provider IP indemnity
Provider will defend Customer against a third-party claim alleging that the unmodified Service, when used as authorized, infringes a United States copyright. Provider may modify or replace the affected item, obtain rights, or terminate the affected Order Form. This obligation does not cover Customer Data, Customer instructions, combinations not supplied by Provider, open-source or third-party materials, use outside the Agreement, or continued use after notice of an alleged claim.
14.3 Procedure
The indemnified party must promptly notify the indemnifying party, provide reasonable cooperation, and allow control of the defense. A settlement may not admit fault by or impose non-monetary obligations on the indemnified party without written consent.
15. Limitation of liability
15.1 Excluded damages
TO THE FULLEST EXTENT PERMITTED BY LAW, NEITHER PARTY IS LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, PUNITIVE, OR LOST-PROFIT DAMAGES, OR FOR LOSS OF GOODWILL, BUSINESS INTERRUPTION, LOSS OF DATA, OR COST OF SUBSTITUTE SERVICES, EVEN IF ADVISED OF THE POSSIBILITY.
15.2 General cap
TO THE FULLEST EXTENT PERMITTED BY LAW, PROVIDER'S AGGREGATE LIABILITY ARISING FROM THE AGREEMENT WILL NOT EXCEED THE GREATER OF (A) FEES PAID BY CUSTOMER UNDER THE AFFECTED ORDER FORM DURING THE SIX MONTHS BEFORE THE EVENT, OR (B) $2,500.
15.3 Enhanced cap
For claims relating to confidentiality, data security, indemnification, or intellectual property that may legally be limited, Provider's aggregate liability will not exceed the greater of (a) two times the fees paid under the affected Order Form during the 12 months before the event, or (b) $10,000. The caps do not limit Customer's payment obligations or liability that cannot legally be limited.
15.4 Allocation
The disclaimers, exclusions, and caps apply in the aggregate, regardless of the legal theory, and are a material basis of the parties' bargain, including a no-fee pilot.
16. Governing law and disputes
16.1 Escalation and mediation
The parties will first try in good faith to resolve a dispute through authorized business representatives. Either party may then request mediation in Virginia.
16.2 Arbitration
Except for collection of undisputed amounts, injunctive relief, or a claim that cannot legally be arbitrated, a dispute arising from the Agreement will be resolved by binding arbitration administered by the American Arbitration Association under its Commercial Arbitration Rules by one arbitrator in Virginia. Judgment may be entered in any court with jurisdiction.
16.3 Law
The laws of the Commonwealth of Virginia govern without regard to conflict-of-law rules. The United Nations Convention on Contracts for the International Sale of Goods does not apply.
16.4 Fees
The prevailing party in an action to enforce the Agreement may recover reasonable attorneys' fees and costs to the extent permitted by law.
17. General terms
17.1 Notices
Legal notices must be in writing and delivered by personal delivery, nationally recognized courier, certified mail, or email with confirmation of receipt. Notices to Provider go to Thirtysix Solutions, LLC, 43450 Interval St., Chantilly, VA 20152, and legal@fieldscroll.com. Customer notices go to the address and contract contact stated in the Order Form. Either party may change its notice address by written notice.
17.2 Assignment
Customer may not assign the Agreement without Provider's prior written consent. Provider may assign it to an affiliate or successor in a merger, reorganization, financing, or sale of substantially all relevant assets.
17.3 Export and sanctions
Customer and users will comply with applicable export-control and sanctions laws and represent that they are not prohibited from receiving the Service.
17.4 Changes to Terms
Provider may update these Terms. Provider will direct material Agreement notices to Customer's designated contract contact, not require routine acceptance from each Authorized User. A material adverse change will not apply to a signed fixed-term Order Form until renewal or a signed amendment, except when required by law or reasonably necessary to address security or abuse. Provider will preserve prior versions reasonably needed to establish the terms accepted by Customer.
17.5 Miscellaneous
If a provision is unenforceable, it will be reformed to the maximum lawful extent and the rest remains effective. Waiver must be in writing. The Agreement does not create employment, partnership, joint venture, agency, or fiduciary duties. Provider may use qualified contractors and remains responsible for their obligations under the Agreement.
17.6 Electronic signatures; entire agreement
Electronic signatures, scanned signatures, and counterparts executed by authorized representatives are valid. An Authorized User's receipt of an in-product notice does not make that user a separate party to the Agreement. The Agreement is the entire agreement about the Service and supersedes prior statements on that subject, without superseding a separate confidentiality agreement unless a signed writing expressly says so.
17.7 Survival
Payment, confidentiality, ownership, data transition, disclaimers, limitations, indemnification, disputes, and provisions that by their nature should survive will survive termination.