Legal

Business Associate Agreement.

The standard terms under which RowFold acts as a business associate, published in full so your counsel can read exactly what they would be signing — before anyone signs anything.

Standard terms v1.0 · Published July 31, 2026 · Questions · security@rowfold.com
This is a reading copy, not a signed agreement. Nothing on this page creates a business associate relationship, and viewing, saving or printing it does not put a BAA in place. A BAA covers you only when it has been executed by both parties through our request process — start one from Settings → Compliance in your account, or email support@rowfold.com. Until yours is signed, do not store protected health information in RowFold.

01How this works

We publish our standard BAA text because the people who evaluate one — counsel, privacy officers, compliance teams — should not need a sales call to read it. The process is deliberate, because a BAA is a contract we take on direct legal obligations under, and we are careful about who we sign with:

1. You request an agreement from Settings or by email, telling us the legal entity to be named as Covered Entity and where the paperwork should go.
2. We review the request and come back to you on scope and timing. We decline requests where we do not believe RowFold can lawfully or practically support the intended use.
3. The agreement is sent for signature and executed by authorized signatories of both parties, out of band — there is intentionally no in-app checkbox that "accepts" a BAA.
4. Only once both signatures are in place does the agreement operate. Your account's compliance card will show the request's status at each step, and it will never say "covered" before that point.

The version your counsel receives for signature is the operative text; this page may be revised between requests. If the executed copy and this page ever differ, the executed copy governs.

02Definitions

Terms used and not otherwise defined in this Agreement have the meanings given in the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations at 45 C.F.R. Parts 160 and 164, as amended, including by the Health Information Technology for Economic and Clinical Health (HITECH) Act (together, "HIPAA").

"Agreement" means this Business Associate Agreement, once executed by both parties. "Business Associate" means RowFold Inc. "Covered Entity" means the customer legal entity named in the executed copy. "Services" means the RowFold hosted software service provided under the parties' underlying subscription terms (the "Underlying Agreement"), as scoped by Exhibit A. "PHI" means Protected Health Information as defined at 45 C.F.R. § 160.103, limited to the information Business Associate creates, receives, maintains or transmits on behalf of Covered Entity in the course of providing the Services. "Breach", "Designated Record Set", "Individual", "Required by Law", "Secretary", "Security Incident", "Subcontractor" and "Unsecured PHI" have the meanings given at 45 C.F.R. §§ 160.103, 164.402 and 164.501.

03Permitted uses & disclosures

Business Associate may use or disclose PHI only:

(a) to provide, maintain and support the Services for Covered Entity, consistent with the minimum-necessary standard;
(b) as Required by Law;
(c) for the proper management and administration of Business Associate and to carry out its legal responsibilities, provided that any disclosure for those purposes is either Required by Law or made under reasonable written assurances from the recipient that the PHI will be held confidentially, used only as disclosed, and that breaches of confidentiality will be reported to Business Associate; and
(d) as otherwise permitted by the executed copy of this Agreement or directed by Covered Entity in writing, to the extent such use or disclosure would be permissible under HIPAA if made by Covered Entity.

Business Associate will not use or disclose PHI in any manner that would violate Subpart E of 45 C.F.R. Part 164 if done by Covered Entity, except as expressly permitted by paragraph (c).

04Prohibited uses

For the avoidance of doubt, Business Associate will not:

(a) sell PHI, or receive remuneration in exchange for PHI, within the meaning of 45 C.F.R. § 164.502(a)(5)(ii);
(b) use or disclose PHI for marketing purposes;
(c) use PHI to train, fine-tune or improve any artificial-intelligence or machine-learning model, whether Business Associate's own or a third party's; or
(d) de-identify PHI or create limited data sets from it, except at Covered Entity's written direction.

05Safeguards

Business Associate will use appropriate administrative, physical and technical safeguards to prevent use or disclosure of PHI other than as provided for by this Agreement, and will comply with Subpart C of 45 C.F.R. Part 164 (the Security Rule) with respect to electronic PHI. Without limiting that obligation, Business Associate maintains the controls described on its security page, including encryption of data in transit and at rest, role- and field-level access controls, optional two-factor authentication and single sign-on for workforce and customer access, and an audit trail of changes to customer content. The security page is a self-reported description of implemented controls and is incorporated by reference for description only; the obligations of this section are those of the Security Rule.

06Incidents & breach notification

Security Incidents. Business Associate will report to Covered Entity any successful Security Incident involving PHI of which it becomes aware within ten (10) business days. The parties acknowledge the ongoing existence of unsuccessful attempts — pings, port scans, denied log-in attempts and comparable events that do not result in unauthorized access, use or disclosure — and agree that this paragraph constitutes notice of them, with no further reporting required.

Breaches of Unsecured PHI. Business Associate will notify Covered Entity of a Breach of Unsecured PHI without unreasonable delay and in no event later than fifteen (15) business days after discovery, in accordance with 45 C.F.R. § 164.410. The notice will include, to the extent known or subsequently learned: the identity of each Individual whose Unsecured PHI was or is reasonably believed to have been involved; a description of what happened, the dates of the Breach and its discovery; the types of information involved; steps Individuals should take to protect themselves; and what Business Associate is doing to investigate, mitigate and prevent recurrence. Business Associate will supplement the notice as new information becomes available and will cooperate with Covered Entity's own notification obligations under 45 C.F.R. §§ 164.404–164.408.

07Subcontractors

In accordance with 45 C.F.R. §§ 164.502(e)(1)(ii) and 164.308(b)(2), Business Associate will ensure that any Subcontractor that creates, receives, maintains or transmits PHI on its behalf agrees in writing to restrictions and conditions at least as protective as those that apply to Business Associate under this Agreement, including compliance with the Security Rule for electronic PHI.

The categories of subprocessor engaged in providing the Services, and what each processes, are published on the compliance page and updated before a new category is added. Exhibit A limits which Service features may touch PHI precisely so that this flow-down obligation is real rather than aspirational: features whose subprocessors do not hold an appropriate written commitment are excluded from PHI scope until they do.

08Individual rights

Access. To the extent Business Associate holds PHI in a Designated Record Set, it will make that PHI available to Covered Entity within fifteen (15) business days of a written request, so that Covered Entity can meet its obligations under 45 C.F.R. § 164.524. The Services also provide self-service export, which Covered Entity may use directly at any time.

Amendment. Business Associate will make PHI in a Designated Record Set available for amendment, and incorporate amendments Covered Entity directs, in accordance with 45 C.F.R. § 164.526. The Services allow Covered Entity to make such corrections directly.

Accounting of disclosures. Business Associate will document disclosures of PHI, and make that documentation available to Covered Entity within fifteen (15) business days of a written request, as required for Covered Entity to respond to an accounting request under 45 C.F.R. § 164.528.

Restrictions and confidential communications. Business Associate will comply with any restriction on use or disclosure, or any confidential-communication requirement, that Covered Entity has agreed to under 45 C.F.R. § 164.522 and notified to Business Associate in writing.

09Access by HHS

Business Associate will make its internal practices, books and records relating to the use and disclosure of PHI received from, or created or received on behalf of, Covered Entity available to the Secretary for purposes of determining compliance with HIPAA, in accordance with 45 C.F.R. § 164.504(e)(2)(ii)(I).

10Term, termination & data return

Term. The Agreement takes effect on the date of the second signature and continues until the Underlying Agreement ends or the Agreement is terminated under this section, whichever is first.

Termination for cause. Either party may terminate the Agreement, and Covered Entity may additionally terminate the Underlying Agreement, if the other party materially breaches this Agreement and fails to cure within thirty (30) days of written notice. Where cure is impossible, the non-breaching party may terminate on notice.

Return or destruction. On termination, Business Associate will, at Covered Entity's election, return or destroy all PHI it maintains, within thirty (30) days. Return is available self-service through the Services' export tools for the whole of that period; destruction follows the deletion and backup-expiry timelines published in the Privacy Policy, and Business Associate will certify destruction in writing on request. If return or destruction of particular PHI is infeasible, Business Associate will say so in writing, and the protections of this Agreement will continue to apply to that PHI for as long as it is retained, with uses and disclosures limited to the purposes that make return or destruction infeasible.

11Exhibit A — scope of services

PHI may be stored and processed in: workspace records and field values, file attachments, and the revision, trash and audit history the Services keep of them, together with the hosted infrastructure (compute, database, file storage, backups) that serves them.

Excluded from PHI scope unless the parties agree otherwise in writing:

(a) Optional AI features. AI assistance is invoked per request and sends the content relevant to that request to the AI subprocessor listed on the compliance page. Unless AI coverage is expressly included in the executed copy, Covered Entity will not direct AI features at PHI, and Business Associate provides workspace-level controls to restrict their use.
(b) Customer-configured outbound email. The content of emails Covered Entity itself configures the Services to send (automation emails, scheduled digests, notifications) is chosen by Covered Entity and processed by the email-delivery subprocessor. Covered Entity will not place PHI in the body or subject of such messages.
(c) Support channels. Support tickets, emails to support addresses and sales conversations are not part of the Services. Covered Entity will not include PHI in them; Business Associate will delete PHI received that way on discovery and notify Covered Entity.

Reader's note — why the exclusions exist: each excluded path hands data to a subprocessor under terms that differ from hosted storage, or (for support) to channels outside the product entirely. Scoping them out keeps every sentence of section 07 true. If you need AI features under your BAA, raise it in your request and we will tell you honestly whether we can extend scope yet.

12Exhibit B — your responsibilities

Covered Entity will: (a) store no PHI in the Services before the Agreement is executed, and none outside the scope of Exhibit A after it; (b) configure and use the access controls the Services provide — workspace membership, roles, table privacy, field-level permissions, and two-factor authentication or single sign-on for its workforce — as appropriate to the sensitivity of what it stores; (c) not request any use or disclosure of PHI that would be impermissible under HIPAA if made by Covered Entity; (d) notify Business Associate in writing of any restriction, revocation or confidential-communication arrangement under 45 C.F.R. §§ 164.508, 164.510 or 164.522 that affects Business Associate's permitted handling of PHI; and (e) be responsible for the lawfulness of the PHI it collects and places in the Services.

13Miscellaneous

Regulatory references mean the provision as amended or its successor. Interpretation: any ambiguity is resolved to permit the parties to comply with HIPAA. Amendment: the parties will amend the Agreement as necessary to maintain compliance with changes in law; Business Associate may propose updated standard terms, which bind only when executed. No third-party beneficiaries: nothing in the Agreement confers rights on any person other than the parties. Independent contractors: the Agreement does not create an agency, partnership or joint venture. Precedence: for PHI, the executed Agreement controls over any conflicting term of the Underlying Agreement; for everything else, the Underlying Agreement controls. Survival: sections 06, 09 and 10 survive termination. Notices go to the signatories' stated addresses, with a copy to security@rowfold.com for Business Associate. Governing law follows the Underlying Agreement.

14Execution

The executed copy carries the legal names of both parties, their authorized signatories, and the effective date, and is exchanged for signature by counsel — it is not signed on this website. Once both parties have signed, the compliance card in Settings shows the agreement as executed, and only then should PHI enter the Services.

To begin: Settings → Compliance in your account, or support@rowfold.com with the legal entity to be named and the right contact for paperwork — often your legal or privacy team rather than the person writing in.

Related: Compliance · Security · Privacy Policy · Terms of Service