TAX ALPHA SUBSCRIPTION AGREEMENT
Full Access + AI Copilot Plan — $299/month (14-day free trial)
Effective Date: the date you complete checkout and accept this Agreement.
Please read this Agreement in full before completing your purchase. By clicking "Accept Terms" and completing checkout, you agree to these terms on behalf of your firm. If you do not agree, do not proceed.
This Subscription Agreement (the "Agreement") is entered into between Tax Alpha Solutions LLC ("Tax Alpha," "Company," "we," "us") and the accounting or tax advisory firm that accepts it at checkout ("Customer," "Firm," "you"). It governs your access to and use of the Tax Alpha software platform (the "Service").
1. DEFINITIONS - "Service" means the Tax Alpha web application, including its document extraction, tax calculation, scenario planning, AI chat assistant (the "AI Copilot"), and proposal generation features, together with any related documentation, as made available under your subscription plan. - "Client Data" means any information you or your Authorized Users submit to the Service relating to your firm's clients, including uploaded tax returns, tax return information, planning inputs, goals, and notes. - "Authorized Users" means your employees and contractors whom you permit to access the Service under your account. - "Outputs" means any analysis, strategy suggestion, projection, calculation, proposal, chat response, or other material generated by the Service. - "DPA" means the Tax Alpha Data Processing Agreement attached as Exhibit A and incorporated into this Agreement. - "Tax Return Information" has the meaning given in Treasury Regulation section 301.7216-1(b)(3).
2. LICENSE AND ACCESS 2.1 License. Subject to this Agreement and your payment of the applicable fees, Company grants you a limited, non-exclusive, non-transferable, revocable license to access and use the Service during your subscription term, solely for your internal business purpose of providing tax advisory services to your own clients. 2.2 Accounts. You are responsible for all activity under your account and your Authorized Users' accounts, and for keeping credentials confidential. You will notify Company promptly of any suspected unauthorized access. 2.3 Restrictions. You will not, and will not permit anyone to: (a) resell, sublicense, or provide the Service to any third party; (b) reverse engineer, decompile, or attempt to extract the source code, models, or prompts of the Service except where such restriction is prohibited by law; (c) use the Service to build a competing product; (d) probe, scan, or test the vulnerability of the Service without prior written authorization; (e) attempt to access data belonging to another firm; (f) upload data for individuals or entities that are not clients or prospective clients of your firm; or (g) use the Service to provide tax advice directly to consumers without professional review as described in Section 4.
3. THE SERVICE, YOUR PLAN, AND FEES 3.1 Actively developed software. The Service is production software that is under continual improvement and active development. We regularly add, change, and refine features, tax-year configurations, and strategy content. Because tax law and the Service both evolve, Outputs may not always reflect the most recent changes in law or in the Service, and features may be modified or removed as the Service develops. We will make reasonable efforts to keep the Service available and accurate, but you remain responsible for the professional review described in Section 4. 3.2 Support. We will make commercially reasonable efforts to respond to support requests and to keep the Service available, but we do not commit to a specific uptime or response-time service level under this Agreement. 3.3 Free trial; plan and fees. Your subscription is the Full Access + AI Copilot plan at $299 per month per firm. The first fourteen (14) days are a free trial; no fees accrue during the trial, and you may cancel at any time before it ends without charge. Unless you cancel before the trial ends, billing begins automatically on the first day after the trial and recurs monthly in advance. This plan includes full access to the Service, including the AI Copilot. Fees are exclusive of any applicable taxes, which are your responsibility. Fees are nonrefundable except as required by law or as expressly stated in this Agreement. 3.4 AI Copilot. Your plan includes the AI Copilot, an AI chat assistant that can answer questions about an uploaded return, look up tax guidance, and suggest strategies in conversation. AI Copilot responses are Outputs and are subject to the professional-review requirements in Section 4. AI-generated content may be incomplete, outdated, or incorrect and must be independently verified before you rely on it or communicate it to any client. 3.5 Renewal; price changes. Your subscription renews automatically each month until cancelled. Company may change its fees or plan structure on at least 30 days' notice; changes take effect at your next renewal, and your continued use after that date constitutes acceptance of the new fees. If you do not agree to a fee change, you may cancel before it takes effect as described in Section 9. 3.6 Payment processing. Payments are processed by our third-party payment processor. You authorize us and our processor to charge your designated payment method for the recurring fees. If a charge fails, we may suspend access until payment is resolved.
4. PROFESSIONAL RESPONSIBILITY; NO TAX ADVICE 4.1 The Service is a tool, not an advisor. The Service performs document extraction, deterministic tax calculations, and analysis to support your professional work. The Service does not provide tax, legal, accounting, or investment advice, and no Output constitutes such advice. 4.2 Professional review and verification required. You acknowledge that Outputs may be incomplete, outdated, or incorrect. You agree that a qualified professional at your firm will review and independently verify every Output, including every calculation, projected number, and strategy suggestion, before relying on it or communicating it, in whole or in part, to any client or using it for any sale or consumer-facing purpose. You retain sole professional responsibility for all advice and deliverables you provide to your clients. 4.3 Your client relationships. Nothing in this Agreement creates any relationship between Company and your clients. You are solely responsible for compliance with professional standards applicable to your practice, including AICPA standards, Treasury Circular 230, and state board of accountancy rules. 4.4 AI disclosure. You are responsible for determining whether and how to disclose your use of AI-assisted tools to your clients, consistent with your professional obligations and applicable law.
5. CLIENT DATA; CONSENTS; COMPLIANCE 5.1 Your data, our processing. As between the parties, you own all Client Data. Company processes Client Data only as your service provider, as described in this Agreement and the DPA. If this Agreement and the DPA conflict regarding data protection, the DPA controls. 5.2 Authority and consents. You represent and warrant that you have all rights, authority, and consents required to submit Client Data to the Service, including, where required, written consents under Internal Revenue Code section 7216 and Treasury Regulation sections 301.7216-1 through -3 for the disclosure and use of Tax Return Information. You are solely responsible for your own section 7216 compliance, including determining whether consents are required and obtaining them in the form the law prescribes, and you will not upload a client's Tax Return Information until any required consent from that client has been obtained. 5.3 No training on Client Data. Company will not use Client Data to train or fine-tune any machine learning model. AI processing is performed through AWS Bedrock under terms that prohibit the model provider from using inputs or outputs for model training. 5.4 Safeguards. Company will maintain the administrative, technical, and physical safeguards described in the DPA. You remain responsible for your own obligations under the Gramm-Leach-Bliley Act, the FTC Safeguards Rule, and IRS Publication 4557, including maintaining your firm's Written Information Security Plan. 5.5 Redaction limitations. Before Client Data is analyzed by an AI model, the Service runs an automated redaction step designed to remove Social Security numbers, account numbers, and similar identifiers. You acknowledge that this redaction is automated and best-effort: it may not identify and remove every identifier in every document format, and occasional identifiers may reach the AI models. Data sent to the AI models remains protected by the safeguards in Section 5.3 and the DPA (United States processing, no retention by the model provider, and no use for model training) even when redaction is incomplete.
6. CONFIDENTIALITY 6.1 Definition. "Confidential Information" means non-public information disclosed by one party to the other in connection with this Agreement that is designated confidential or that reasonably should be understood to be confidential, including Client Data, the Service's design and prompts, pricing, and the terms of this Agreement. 6.2 Obligations. The receiving party will: (a) use Confidential Information only to perform under or exercise rights granted by this Agreement; (b) protect it with at least the same care it uses for its own similar information, and no less than reasonable care; and (c) not disclose it to any third party except to employees, contractors, and advisors who need to know it and are bound by obligations at least as protective. 6.3 Exclusions. Confidential Information does not include information that: (a) is or becomes publicly available without breach; (b) was known to the receiving party without restriction before disclosure; (c) is independently developed without use of the disclosing party's Confidential Information; or (d) is rightfully received from a third party without restriction. 6.4 Compelled disclosure. A party may disclose Confidential Information to the extent required by law, provided it gives prompt notice (where legally permitted) and reasonable cooperation to seek protective treatment.
7. FEEDBACK You may, but are not required to, provide suggestions, ideas, bug reports, or other feedback about the Service ("Feedback"). You grant Company a perpetual, irrevocable, worldwide, royalty-free license to use Feedback for any purpose without restriction or compensation. Feedback excludes Client Data.
8. INTELLECTUAL PROPERTY 8.1 Company retains all right, title, and interest in and to the Service, including all software, models, prompts, tax calculation logic, strategy content, and documentation, and all improvements to them. No rights are granted except as expressly stated in this Agreement. 8.2 As between the parties, you retain all right, title, and interest in Client Data and in the professional advice and deliverables you prepare for your clients, including deliverables that incorporate Outputs you have reviewed and adopted.
9. TERM AND TERMINATION 9.1 Term. This Agreement begins on the Effective Date and continues for successive monthly terms until cancelled or terminated as described in this Section. 9.2 Cancellation by you. You may cancel your subscription at any time, effective at the end of the then-current term (or before the end of the free trial to avoid all charges). You will retain access through the period you have paid for. Fees already paid are nonrefundable except as required by law or as expressly stated in this Agreement. 9.3 Termination by Company. Company may terminate or suspend this Agreement or your access: (a) if you breach this Agreement and, for a curable breach, fail to cure it within 10 days of notice; (b) immediately where reasonably necessary to address a security risk or a suspected violation of Section 2.3; or (c) for convenience on 30 days' notice, in which case Company will refund the prorated unused portion of any prepaid fees. 9.4 Effect of termination. On termination or expiration: (a) your license ends and you will stop using the Service; (b) on your written request made within 30 days, Company will provide an export of your Client Data in a reasonable machine-readable format; and (c) Company will delete Client Data within 60 days as described in the DPA. Sections 4, 5.2, 6, 7, 8, 9.4, 10, 11, and 12 survive.
10. DISCLAIMERS EXCEPT AS EXPRESSLY STATED IN THIS AGREEMENT, THE SERVICE AND ALL OUTPUTS ARE PROVIDED "AS IS" AND "AS AVAILABLE" WITHOUT WARRANTY OF ANY KIND. COMPANY DISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, NON-INFRINGEMENT, ACCURACY, AND ANY WARRANTY ARISING FROM COURSE OF DEALING OR USAGE OF TRADE. COMPANY DOES NOT WARRANT THAT THE SERVICE WILL BE UNINTERRUPTED, ERROR-FREE, OR SECURE; THAT OUTPUTS WILL BE ACCURATE, COMPLETE, OR CURRENT WITH RESPECT TO TAX LAW; OR THAT THE AUTOMATED PII REDACTION DESCRIBED IN SECTION 5.5 WILL REMOVE EVERY IDENTIFIER FROM EVERY DOCUMENT. TAX LAW CHANGES FREQUENTLY, AND THE SERVICE IS UNDER CONTINUAL DEVELOPMENT; OUTPUTS REFLECT THE TAX YEAR CONFIGURATIONS DESCRIBED IN THE SERVICE'S DOCUMENTATION AND MAY NOT REFLECT RECENT CHANGES.
11. LIMITATION OF LIABILITY; INDEMNITY 11.1 Exclusion of damages. TO THE MAXIMUM EXTENT PERMITTED BY LAW, NEITHER PARTY WILL BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, OR FOR LOST PROFITS, LOST REVENUE, OR LOSS OF DATA, ARISING OUT OF OR RELATED TO THIS AGREEMENT, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. 11.2 Cap. TO THE MAXIMUM EXTENT PERMITTED BY LAW, EACH PARTY'S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATED TO THIS AGREEMENT WILL NOT EXCEED THE TOTAL FEES PAID OR PAYABLE BY CUSTOMER TO COMPANY IN THE TWELVE (12) MONTHS PRECEDING THE EVENT GIVING RISE TO LIABILITY. 11.3 Exceptions. The limitations in Sections 11.1 and 11.2 do not apply to: (a) a party's breach of Section 6 (Confidentiality); (b) Customer's breach of Sections 2.3 (Restrictions) or 5.2 (Authority and Consents); (c) a party's indemnification obligations under Section 11.4; or (d) liability that cannot be limited under applicable law. 11.4 Customer indemnity. You will defend and indemnify Company against third-party claims, including claims by your clients or regulators, to the extent arising from: (a) your or your Authorized Users' use of Outputs without the professional review and verification required by Section 4.2; (b) your breach of Section 5.2, including any failure to obtain required section 7216 consents; or (c) your violation of professional standards or applicable law.
12. GENERAL 12.1 Governing law; venue. This Agreement is governed by the laws of the State of California, without regard to conflict-of-laws rules. The parties consent to exclusive jurisdiction and venue in the state and federal courts located in San Francisco County, California. 12.2 Assignment. Neither party may assign this Agreement without the other party's prior written consent, except Company may assign it in connection with a merger, acquisition, or sale of substantially all assets. 12.3 Notices. Notices to Company must be in writing and sent to support@taxalpha.us. Notices to you may be sent to the email associated with your account. Notices are deemed given one business day after email transmission with no bounce. 12.4 Independent contractors; no third-party beneficiaries. The parties are independent contractors. There are no third-party beneficiaries to this Agreement; in particular, your clients are not third-party beneficiaries. 12.5 Force majeure. Neither party is liable for delay or failure caused by events beyond its reasonable control. 12.6 Entire agreement; amendments. This Agreement, together with the DPA (Exhibit A), is the entire agreement between the parties regarding the Service and supersedes all prior or contemporaneous agreements on that subject. Company may update this Agreement on notice; material changes take effect at your next renewal, and your continued use after that date constitutes acceptance. 12.7 Severability; waiver. If any provision is unenforceable, it will be modified to the minimum extent necessary, and the remainder will remain in effect. A waiver is effective only if in writing.
ACCEPTANCE
By clicking "Accept Terms" for the Full Access + AI Copilot plan ($299/month after a 14-day free trial), you acknowledge that you have read, understood, and agree to this Agreement and the Data Processing Agreement (Exhibit A) on behalf of your firm.
EXHIBIT A — TAX ALPHA DATA PROCESSING AGREEMENT
This Data Processing Agreement ("DPA") is entered into between Tax Alpha Solutions LLC ("Tax Alpha" or "Company") and the firm that accepts the Subscription Agreement ("Customer" or "Firm"). It is attached as Exhibit A to, and incorporated into, the Subscription Agreement (the "Agreement"). It governs Company's processing of Customer Data in connection with the Service.
1. DEFINITIONS - "Customer Data" means all data Customer or its authorized users submit to the Service, including Client Personal Information. - "Client Personal Information" means information within Customer Data that identifies or relates to an identifiable individual, including Customer's clients and their dependents, and includes "nonpublic personal information" as defined under GLBA and "tax return information" as defined in Treasury Regulation section 301.7216-1(b)(3). - "Process" / "Processing" means any operation performed on Customer Data, including collection, storage, analysis, disclosure, and deletion. - "Subprocessor" means a third party engaged by Company to Process Customer Data on Company's behalf. - "Security Incident" means a confirmed unauthorized access to, or acquisition, use, disclosure, alteration, or destruction of, Customer Data on systems managed by Company or its Subprocessors. Good-faith access by Company personnel, and unsuccessful attempts such as blocked attacks, port scans, or failed logins, are not Security Incidents.
2. ROLES AND SCOPE OF PROCESSING 2.1 Roles. Customer is the controller of (and, under the CCPA, the "business" with respect to) Client Personal Information; Company Processes it solely as Customer's service provider and processor. Customer is responsible for the accuracy and lawfulness of the Customer Data it submits, including obtaining any consents required by IRC section 7216 and applicable privacy laws. 2.2 Permitted purposes. Company will Process Customer Data only: (a) to provide, maintain, secure, and support the Service; (b) to improve and develop the Service, including diagnosing and fixing errors, testing, and evaluating and improving the accuracy of the Service's document extraction, redaction, and tax calculation features; (c) as instructed by Customer through the Service's features; (d) as required by law (in which case, where legally permitted, Company will notify Customer before disclosure); and (e) as otherwise documented in the Agreement. When Processing for the improvement purposes in clause (b), Company will use redacted or de-identified data wherever practicable; limit access to personnel who need it; never disclose Client Personal Information to any third party (other than the Subprocessors in Annex C acting on Company's behalf); and never expose one customer's Customer Data to another customer. Company will not sell Customer Data; use it for advertising or marketing; or disclose it except as described in this DPA. 2.3 No model training. Company will not use Customer Data to train or fine-tune any machine learning model. Company will use AI infrastructure only under terms that prohibit the infrastructure provider from retaining Customer Data beyond transient processing or using it for model training. As of the Effective Date, AI inference is performed via AWS Bedrock, whose service terms provide these protections. 2.4 De-identified data. Company may use data that has been aggregated or de-identified such that it cannot reasonably identify Customer, any client, or any individual, for purposes of operating and improving the Service. Company will not attempt to re-identify such data and will require the same of any recipient. 2.5 GLBA service-provider status. The parties acknowledge that Customer may be a "financial institution" under GLBA and the FTC Safeguards Rule (16 C.F.R. Part 314) and that Company receives Client Personal Information as Customer's service provider. Company agrees to: (a) maintain the safeguards described in Section 4 and Annex B; (b) use Client Personal Information only as described in Section 2.2, consistent with the exceptions in 16 C.F.R. sections 313.14 and 313.15; and (c) on Customer's reasonable request (no more than annually), provide written confirmation or summaries sufficient for Customer to meet its service-provider oversight obligations under 16 C.F.R. section 314.4(f).
3. CONFIDENTIALITY OF PROCESSING Company will ensure that personnel authorized to Process Customer Data are bound by written confidentiality obligations, are trained on data handling, and access Customer Data only as needed for the purposes in Section 2.2. Company restricts production data access to a need-to-know basis and logs administrative access.
4. SECURITY MEASURES 4.1 Company will maintain administrative, technical, and physical safeguards appropriate to the sensitivity of tax return information, including no less than the measures described in Annex B. Company may update Annex B from time to time, provided the updates do not materially reduce the overall protection of Customer Data during the term. 4.2 Customer is responsible for: maintaining the confidentiality of its users' credentials; appropriately managing which personnel have access; the security of its own systems and networks; and its own regulatory programs, including its Written Information Security Plan under IRS Publication 4557 and the FTC Safeguards Rule.
5. SUBPROCESSORS 5.1 Authorization. Customer authorizes the Subprocessors listed in Annex C. Company will impose data protection obligations on each Subprocessor that are no less protective than this DPA and remains responsible for Subprocessors' performance. 5.2 Changes. Company will give Customer at least 15 days' written notice (email suffices) before adding or replacing a Subprocessor that will Process Client Personal Information. If Customer reasonably objects on data protection grounds and the parties cannot resolve the objection, Customer may terminate the Agreement and this DPA without penalty.
6. SECURITY INCIDENT NOTIFICATION 6.1 Company will use best efforts to notify Customer of a Security Incident promptly, and without undue delay, after confirming it. Notification will be sent to the Customer email designated in the Agreement and will include, to the extent known: the nature and scope of the incident, the categories and approximate volume of affected data and clients, measures taken or planned, and a Company contact. 6.2 Company will investigate the incident; take reasonable steps to mitigate and remediate; provide timely updates as material information develops; and reasonably cooperate with Customer's own notification obligations. Customer acknowledges that it, as the tax professional, is responsible for any notifications it must make to its clients, the IRS (including IRS Stakeholder Liaison reporting for tax professionals), state tax agencies, and state regulators; Company will provide information reasonably needed for those reports. 6.3 Company's notification of a Security Incident is not an admission of fault or liability.
7. ASSISTANCE WITH INDIVIDUAL RIGHTS REQUESTS If Company receives a request from an individual (for example, a firm client) seeking access to, correction of, or deletion of their personal information, Company will not respond substantively (except to direct the individual to the Customer) and will promptly forward the request to Customer. Company will provide reasonable assistance, through the Service's features or otherwise, to help Customer respond to such requests where Customer cannot fulfill them on its own.
8. AUDITS AND INFORMATION REQUESTS No more than once per year (or following a Security Incident), Customer may submit a reasonable written security questionnaire or request for documentation about Company's safeguards, and Company will respond within 30 days. On-site or technical audits are not provided.
9. DATA RETURN AND DELETION 9.1 During the term. Customer can delete clients, returns, and individual records through the Service. Deleted records are removed from the production database; residual copies in encrypted backups are purged in the ordinary course of backup rotation, and in no event later than 90 days after deletion. 9.2 End of term. On termination or expiration of the Agreement: (a) on Customer's written request made within 30 days, Company will provide an export of Customer Data in a reasonable machine-readable format; and (b) Company will delete Customer Data within 60 days of termination, except to the extent retention is required by law, in which case the retained data remains protected by this DPA for as long as it is retained. 9.3 Certification. On written request, Company will confirm completion of deletion in writing.
10. TERM, PRECEDENCE, AND MISCELLANEOUS 10.1 This DPA takes effect on the effective date of the Agreement and continues for as long as Company Processes Customer Data. 10.2 If this DPA conflicts with the Agreement regarding the protection of Customer Data, this DPA controls. 10.3 Liability under this DPA is subject to the limitations of liability in the Agreement, except as the Agreement expressly provides otherwise. 10.4 This DPA is governed by the same law and venue as the Agreement.
ANNEX A — DESCRIPTION OF PROCESSING
Subject matter: Tax return analysis, tax planning scenario modeling, and proposal generation for Customer's clients. Duration: Term of the Agreement plus the wind-down period in Section 9. Nature and purpose: Document text extraction and OCR; PII redaction; AI-assisted analysis of redacted text; deterministic tax calculation; storage and display of results to Customer's authorized users; diagnosis and improvement of the Service per Section 2.2(b). Categories of individuals: Customer's clients and prospective clients; their spouses and dependents; Customer's authorized users. Categories of data: Tax return information (income, deductions, credits, filing status, entity ownership); identifiers appearing on tax documents (names, SSNs, EINs, addresses, dates of birth, account numbers), field-encrypted at rest, with identifiers such as SSNs and account numbers also redacted before AI processing; planning inputs, goals, and advisor notes; account and usage data for Customer's users. Sensitive data: Social Security numbers and financial data inherent in tax returns; handled per Annex B.
ANNEX B — SECURITY MEASURES
- Access control. Single sign-on enforced via Cloudflare Access (identity-provider-backed) in production, with the application refusing to start if authentication is misconfigured; per-firm data isolation enforced in the application layer on every data route; no cross-firm data access paths. - Encryption in transit. TLS for all connections between users and the Service and between the Service and Subprocessors. - Encryption at rest. Database-level encryption at rest via hosting provider; additional field-level encryption (Fernet, AES-128-CBC with HMAC) for sensitive columns, including extracted tax data, notes, and client identifiers. - PII redaction. Automated redaction of SSNs, EINs, emails, phone numbers, bank routing and account numbers, dates of birth, and similar identifiers before any text is sent to an AI model. Raw unredacted text is not persisted. Redaction is automated and may not catch every identifier in every document format; any residual identifiers remain protected by the encryption, access controls, United States processing, and no-training commitments described in this DPA. - Document handling. Upload validation (file type and size checks), randomized storage filenames, original unredacted PDFs deleted after extraction; the copy retained for in-app preview is visually redacted, with identifiers masked, including in the hidden form-field layer of fillable PDFs. - AI processing boundaries. AI inference via AWS Bedrock; no Customer Data used for model training; OCR for scanned documents via AWS Textract within Company's AWS account; all Processing within the United States. - Logging and monitoring. Application audit logging of data access and modification events; rate limiting; standard security headers (HSTS, CSP, X-Frame-Options, and others). - Software lifecycle. Changes are reviewed and run through an automated test suite covering security-relevant behaviors (authentication, per-firm scoping, encryption) before deployment. - Personnel. Confidentiality obligations for all personnel with production access; production access restricted to a small number of named individuals. - Backups and recovery. Managed, encrypted database backups through the hosting provider, purged on the rotation schedule described in Section 9.1.
ANNEX C — AUTHORIZED SUBPROCESSORS
- Amazon Web Services, Inc. — AI model inference (Bedrock), OCR for scanned documents (Textract), knowledge-base document storage (S3) — United States. - Railway Corp. — Application and database hosting — United States. - Cloudflare, Inc. — Authentication (Cloudflare Access), network security — United States.
