Public reading copy. Bracketed company and representative names and example.invalid company emails are illustrative, not customer data. This page is not a completed signature or acceptance. Company signup supplies a private, populated copy for review.

OFFDUTY HQ SOFTWARE SERVICES AGREEMENT

Agreement version: 2026-09-05.1

Provider legal name and capacity: Lukas Thorneycroft, an individual doing business as OffDuty HQ ("Provider").
Provider notice address: 8516 Smithfield Lane, Indianapolis, IN 46237
Provider notice email: admin@offdutyhq.com

Company legal name: [Company legal name] ("Company").
Company business address: [Company business address]
Company notice email: company-notice@example.invalid
Authorized representative: [Authorized representative]
Representative title: [Representative title]

This Agreement takes effect when Company's authorized representative electronically accepts it and Provider records the acceptance, or when both Parties sign a written counterpart. The actual acceptance date and time appear in the execution record, not the agreement version date. Provider and Company are the "Parties."

1. Purpose and scope

Provider supplies access to OffDuty HQ, a hosted software platform (the "Platform") for participating companies to manage their own personnel and assignments. Available functions may include availability, schedules, open-shift requests, company-controlled access, limited opportunity discovery, time records, location capture at check-in and checkout, post orders, notifications, incident reports, attachments, and exports. Only functionality actually made available under Company's selected resources is included.

Provider supplies software access, not officers, guards, staffing, security services, law-enforcement services, payroll processing, or emergency response. Company contracts with its own clients and independently manages its personnel. This Agreement does not appoint Provider as Company's employer, agent, dispatcher, security contractor, payroll vendor, or representative in any work arrangement. The Parties remain responsible for obligations the law places on their actual conduct.

2. Access license and authorized users

During the Agreement and subject to its terms, Provider grants Company a limited, nonexclusive, nontransferable right to use the Platform for Company's own legitimate business operations through authorized users. Company may allow approved personnel and administrators to use the functions intended for their roles. This permission is not a right to resell, sublicense, white-label, or operate the Platform for unaffiliated companies outside the permitted workspace structure.

Company shall designate authorized administrators, provide accurate information, protect credentials, assign appropriate permissions, and promptly revoke access when no longer authorized. Users must use their own accounts. Company is responsible for its users' conduct within its workspace to the extent within Company's control, but does not assume responsibility for a compromise caused by Provider's breach of this Agreement. Each Party shall promptly report suspected unauthorized access relevant to the other Party.

3. Individual accounts and company separation

An individual may have one Platform account and relationships with multiple participating companies. Company does not acquire ownership or exclusive control of that individual's account, general profile, personal availability, or relationships with other companies. Company controls access to its own private operational information, subject to applicable law and the Platform's role permissions.

Company must not seek or disclose another company's confidential schedules, clients, reports, or assignments without authorization. Cross-company availability or conflict indicators do not grant a right to discover the other company's identity or assignment details. Provider's authorized personnel and service providers may access information as permitted by Sections 10 through 13.

4. Opportunity discovery and company onboarding

The Platform may show non-onboarded individuals limited opportunity information that Company elects to publish, such as company identity, general area, work type, date, time, and optional compensation information. An individual may express interest and authorize transmission of contact or profile information to Company. Company authorizes this limited publication when it uses the discovery feature; its private site details and other restricted information remain subject to the Platform's access controls.

An expression of interest, profile, invitation, approval status, or shift request is not Provider's verification, recommendation, hiring, placement, assignment, or guarantee. Company independently decides whether to contact, vet, onboard, approve, engage, schedule, or reject a person. Company must verify a person's eligibility before allowing access to restricted calendars or assignments. Company-controlled automatic approvals are Company's decisions, not Provider's selection of personnel.

5. Company's operational and personnel responsibilities

Company is responsible for its security-service contracts; personnel selection and supervision; lawful post orders; identity and background review; law-enforcement status and authority; licenses, certifications, training, equipment, and insurance; departmental permission for off-duty work; client-specific requirements; and all other qualifications applicable to each assignment. Company must promptly revoke access or stop scheduling anyone who is no longer eligible. A claimed credential or status displayed on the Platform is not proof that Provider has verified it.

Company and its personnel remain responsible for lawful conduct and applicable agency policies. Provider does not direct police action, exercise law-enforcement authority, supply personnel, promise coverage, or assume Company's duties merely because records or communication tools are available on the Platform.

6. Compensation, payroll, and work records

Company determines lawful compensation, employment or contractor classification, and work arrangements, and pays personnel through its own vendors or systems. Company is responsible for wages, overtime, benefits, taxes, withholding, reporting, workers' compensation, unemployment obligations, and required employment records. Software charges are not a share of personnel compensation.

Time exports, pay settings, holiday calculations, conflict warnings, and hours alerts are administrative aids, not legal or payroll advice. Company must verify and correct records before relying on them for payment, billing, discipline, or compliance. Company must maintain the records it is legally required to keep independently of the Platform's retention practices.

7. Scheduling, notifications, and continuity

Company controls schedules, approvals, available automation, calloff handling, and contingency coverage. Availability and interest do not guarantee acceptance or attendance. Provider does not guarantee that any person will qualify, accept, arrive, remain available, or complete an assignment, or that any shift will be filled.

Notifications can be delayed, blocked, or missed. Company and its personnel must review current assignments and maintain appropriate alternate communication and continuity procedures. The Platform is not an emergency communication service; emergencies must be handled through 911 or the appropriate agency. Provider does not promise continuous availability or a service-level credit unless separately agreed in writing.

8. Timekeeping and location capture

The Platform requests device location when a user performs a check-in or checkout action. Check-in requires available device coordinates. Checkout may be recorded without location when the user provides an explanation. The Platform may retain returned coordinates and related time and accuracy information. Location access depends on the device, browser, permissions, connectivity, and other technical conditions. Location may be unavailable, inaccurate, manipulated, or inconsistent with the actual assignment location.

Company may select location recording or geofenced check-in. When geofenced check-in is enabled, the Platform checks the submitted coordinates against the configured assignment radius and rejects check-in outside that radius. Checkout may be recorded outside the radius so actual worked time can still be recorded. These controls do not continuously track users between check-in and checkout, independently establish identity, prove physical presence or work performed, or determine hours legally payable. They cannot guarantee that inaccurate or manipulated location information will be detected.

Company shall review location and time information appropriately and provide notices and obtain permissions legally required for its own use. Provider remains responsible for its own legally required notices and permissions. Company must not treat failed or unavailable location capture, by itself, as a waiver of payment for time actually worked. Time corrections must be handled through authorized Platform functions where available.

9. Incident reports, attachments, and restricted information

Incident-report functions support Company's administrative documentation. They are not an official police-report system, evidence repository, or replacement for a required governmental or company recordkeeping system. Company and its users must submit accurate, relevant information they are authorized to possess and disclose and avoid unnecessary sensitive information.

Company must not upload NCIC or IDACS returns, restricted criminal-history records, or other protected criminal-justice database information. Any exception requires Provider's prior written agreement, applicable agency authorization, and satisfaction of all legally required safeguards before upload. Merely accepting this Agreement does not establish CJIS authorization or compliance. Company must not submit other specially regulated information where required agreements, permissions, or safeguards are absent.

Incident reports and attachments are retained for 60 days after submission and are then scheduled for deletion under the published retention policy. Company must download and preserve needed records before that period ends. Edits, account cancellation, or a later export request do not promise a new 60-day period. Legally required preservation controls over routine deletion; secured backup copies may persist through normal backup cycles. Company remains responsible for its own preservation and retention duties. Provider is not promising that 60 days satisfies those duties or that deleted records can be recovered.

10. Customer Data and processing permission

"Customer Data" means Company's workspace-specific schedules, sites, post orders, reports, attachments, time records, and other information submitted by or for Company or generated from its use of the Platform. As between the Parties, Company retains its rights in Customer Data, subject to the rights of individual users, clients, and other third parties. This Agreement does not transfer an individual's general account or another company's data to Company.

Company authorizes Provider and its contracted service providers to host, reproduce, transmit, display to authorized recipients, process, secure, back up, and export Customer Data only as reasonably necessary to provide and support the Platform, troubleshoot and maintain its operation, prevent misuse, carry out Company's authorized instructions, or comply with law. Provider may analyze service operation to maintain and improve the Platform, but this does not authorize sale of Customer Data, disclosure of identifiable customer operations to competitors, third-party behavioral advertising, or training a general-purpose AI model on Company reports or attachments.

Provider may use aggregate or de-identified operational statistics only where they do not reasonably identify Company, its clients, individual personnel, or incident subjects. Provider shall not attempt re-identification. Company represents that it has the rights and authority necessary for the permitted processing. This section does not create ownership rights in facts or materials that are not legally ownable.

11. Privacy, safeguards, and incidents

Each Party shall comply with privacy, security, and breach-notification laws applicable to its activities. Where Company determines the purposes of processing its operational personal data, Provider processes that data to perform this Agreement; Provider may separately determine the purposes of its own account, billing, fraud-prevention, and legal-compliance records. A legally required data-processing addendum must be completed before processing that requires it.

Provider shall maintain reasonable administrative, technical, and organizational safeguards appropriate to the data and service, including access controls intended to separate company workspaces and restrict administrative access. No guarantee of perfect security is made. Provider shall notify Company without undue delay after becoming aware of unauthorized access to or disclosure of Customer Data in Provider's custody, subject to applicable law and lawful law-enforcement restrictions, and provide reasonably available information and cooperation relevant to Company's obligations. Unsuccessful probes alone are not a confirmed disclosure incident.

The Privacy Policy explains personal-data practices. It does not silently expand the processing permission in this Agreement or override its express protections. Neither Party may use the other's name, logo, client information, or identifiable incident content in public marketing without prior permission.

12. Confidentiality

Nonpublic business, technical, client, operational, personnel, and security information disclosed under this Agreement is confidential when designated as such or reasonably understood to be confidential. The recipient shall use it only to perform or exercise rights under this Agreement, apply at least reasonable care, and disclose it only to persons who need it for that purpose and are subject to appropriate confidentiality obligations.

Confidential information excludes information demonstrably known without restriction, lawfully obtained from another source, made public without breach, or independently developed without use of protected information. Required legal disclosure is permitted to the legally necessary extent; the recipient shall provide notice when lawful and reasonably practicable. Confidentiality continues while information remains confidential, and trade secrets remain protected for as long as applicable law recognizes them.

13. Service providers and third-party systems

Provider may use hosting, identity, storage, payment, email, notification, and other service providers. Provider shall use appropriate contractual protections for Customer Data and remains responsible for its own obligations under this Agreement when using subcontractors. A third-party outage does not by itself create a guarantee of uninterrupted service or eliminate Provider's express duties.

Company is responsible for its independently selected payroll vendors, devices, connectivity, and external integrations. Provider does not receive authority to initiate payroll or pay personnel merely because an export or integration is available.

14. Platform ownership and feedback

Provider and its licensors retain their respective rights in the Platform's software, copyrightable designs and documentation, trademarks, and other proprietary materials, including improvements. Company obtains only the access rights granted here. This Agreement does not claim exclusive ownership of general ideas, scheduling concepts, public information, or materials belonging to others; it does not override applicable third-party license rights.

Company may provide voluntary product feedback. Provider may use that feedback to improve its products without compensation, but that permission does not transfer Customer Data, third-party rights, or unrelated Company confidential information.

15. Copying, access abuse, and competitive misuse

Except as expressly authorized or permitted by applicable law notwithstanding this restriction, Company shall not copy or redistribute protected Platform materials; reverse engineer, decompile, or disassemble the software; derive nonpublic source code or implementation; bypass access controls; scrape or harvest other users' information; resell access; remove proprietary notices; or use malicious code or deceptive accounts.

Company shall not use restricted Platform access or Provider's confidential information to copy protectable implementation, commission a clone based on that material, or assist another person in doing so. It shall not provide access to a competitor for those prohibited purposes. This is not a prohibition on independent lawful competition, use of general experience or public ideas, lawful reporting, rights that applicable law does not allow to be waived, or use of another scheduling service.

Company may make reasonable internal training materials and copies of its own records using permitted functions. The restrictions do not prohibit authorized data exports, preservation of Company's evidence, or ordinary internal evaluation. Security testing requires Provider's permission except where applicable law permits it notwithstanding this provision.

16. Orders, resource fees, and pricing

An "Order" is a resource selection or written purchase confirmation accepted by an authorized Company representative that identifies paid sites, venues, events, prices, included capacity, and any express exceptions. Provider shall display applicable charges before activation and retain a record of the accepted selection. Merely creating a company account does not itself create a paid site, venue, or event.

Charges are for software resources, not the number of people on Company's roster, hours worked, placement of personnel, or a percentage of compensation. Resource plans may have disclosed limits on simultaneous positions or event duration; those limits are not per-person payroll or staffing charges. Additional paid capacity must be disclosed and accepted, not silently purchased by an administrator action whose billing effect is undisclosed.

17. Monthly billing in arrears; no proration

Recurring site and venue subscriptions renew month-to-month by calendar month. The billing calendar uses America/New_York time unless an accepted Order expressly states a different billing timezone.

The full applicable monthly rate is incurred for each recurring resource active for any part of a calendar month. Fees are not prorated for activation, cancellation, partial-month access, limited usage, unfilled shifts, roster size, or early deactivation. Activating a resource on the final day of a month still incurs that month's full rate. An expressly accepted credit, complimentary arrangement, or legally required remedy is an exception.

Charges for a service month are billed on the first day of the following month and are due when billed. For example, a recurring site activated September 17 incurs its full September rate, billed October 1; if it remains active in October, October's full rate is billed November 1. The first invoice is not an advance charge or a free introductory month.

18. Events, payment authorization, and taxes

One-time events are separately purchased software resources, not monthly renewals. Their price, included capacity, any extra capacity, and payment timing must be expressly displayed and accepted when ordered. This Agreement does not impose advance payment or arrears billing on an event where the accepted Order does not specify it. An event cannot be purchased under undisclosed payment terms.

Company shall maintain an approved payment method where required and authorizes Provider and its payment processor to collect amounts properly due under accepted Orders. Provider may retry failed payments with reasonable notice. No authorization to pay officers or initiate payroll is granted. Only separately disclosed and lawfully imposed taxes or payment fees may be added. Company is not responsible for taxes on Provider's net income.

Except for a billing error, an express written credit, a remedy in this Agreement, or a legal requirement, properly incurred fees are nonrefundable. Company should report billing errors promptly; failure to object within an arbitrary short deadline does not waive a nonwaivable legal right. Provider shall review good-faith disputes and correct verified errors. No late-interest rate or collection surcharge is imposed by this Agreement.

19. Cancellation, price changes, and service changes

An authorized administrator may cancel a recurring resource or the account through available account controls or by written notice to Provider's notice email. A cancellation received before the next service month begins is effective at the end of the current calendar month. Company owes that month's full fee, billed on the next month's first day, but no fee for a later service month solely because a final invoice is outstanding. Disabling a resource immediately at Company's request does not prorate a charge already incurred. A confirmed cancellation does not require a phone call or negotiation.

Provider shall give at least 30 days' advance notice of increased recurring rates for already active resources, with the change effective no earlier than a subsequent calendar month after that notice period. Company may cancel before the increase. Prices for newly ordered resources are those expressly accepted at activation.

Provider may maintain and improve the service, but will give reasonable advance notice of a material reduction in core paid functionality when practicable. If Provider discontinues a paid resource for its convenience before the end of a paid service month and cannot provide a substantially equivalent service, Company is entitled to an appropriate credit for the unavailable period; the no-proration rule is not permission to charge for an intentionally withdrawn service. Unaccepted future features are not part of this Agreement.

20. Suspension, term, and termination

This Agreement continues until terminated; active recurring resources renew as stated above. Either Party may terminate for convenience at the end of a calendar month by notice before that month ends. Company cancellation is governed by Section 19. Provider may suspend access proportionately to address overdue undisputed charges, material misuse, fraud, a serious security threat, or a legal requirement. Provider will give notice and a reasonable opportunity to cure when practicable and safe.

Either Party may terminate for a material breach not cured within 15 days after written notice, where curable. Immediate suspension or termination is permitted where reasonably necessary for unlawful conduct, deliberate access abuse, a serious security threat, or misuse of confidential or proprietary information. Provider will not characterize a genuine billing dispute alone as misconduct. Charges properly incurred before termination remain due; a suspension is not itself authorization to renew a resource Company has already canceled.

21. Export, deletion, and surviving records

Company should export needed Customer Data before cancellation and before any applicable deletion deadline. After termination, Company may request an export of Customer Data Provider still retains; Provider will use commercially reasonable efforts to assist an authenticated, authorized representative, subject to legal and security limits. An export request does not extend ordinary retention or require restoration of deleted information. Unpaid fees alone do not transfer data ownership or authorize withholding a legally required disclosure.

Provider may delete data under its applicable retention practices except where preservation is legally required. Incident reports remain subject to Section 9, not a new retention period triggered by termination. Billing, agreement-execution, audit, security, and legal-compliance records may be kept as reasonably necessary for their separate purposes and legal obligations. A company's operational-data deletion request does not automatically erase evidence of its agreement or outstanding obligations.

22. Warranties and disclaimers

Each Party represents that it has authority to enter this Agreement. Provider represents that it has the rights necessary to provide the access license granted here. Company represents that its use and submitted materials will comply with this Agreement and applicable law.

EXCEPT FOR EXPRESS COMMITMENTS IN THIS AGREEMENT AND RIGHTS THAT CANNOT LAWFULLY BE EXCLUDED, THE PLATFORM IS PROVIDED "AS IS" AND "AS AVAILABLE." PROVIDER DISCLAIMS IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, AND NON-INFRINGEMENT TO THE EXTENT PERMITTED BY LAW. PROVIDER DOES NOT GUARANTEE UNINTERRUPTED OR ERROR-FREE OPERATION, ACCURATE GPS, PERSONNEL QUALIFICATIONS, FILLED SHIFTS, OR COMPANY'S LEGAL COMPLIANCE. THESE DISCLAIMERS DO NOT CANCEL PROVIDER'S EXPRESS DATA, CONFIDENTIALITY, SECURITY, OR OTHER OBLIGATIONS.

23. Limitation of liability

TO THE MAXIMUM EXTENT PERMITTED BY LAW, PROVIDER IS NOT LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, INCLUDING LOST PROFITS, REVENUE, BUSINESS OPPORTUNITIES, OR GOODWILL ARISING FROM THIS AGREEMENT OR THE PLATFORM. DIRECT DAMAGES DO NOT BECOME INDIRECT MERELY BECAUSE THEY INVOLVE DATA OR SERVICE REPAIR.

PROVIDER'S TOTAL AGGREGATE LIABILITY ARISING FROM OR RELATED TO THIS AGREEMENT WILL NOT EXCEED THE FEES PAID OR PAYABLE BY COMPANY UNDER THIS AGREEMENT FOR THE SIX MONTHS IMMEDIATELY PRECEDING THE FIRST EVENT GIVING RISE TO THE CLAIM. RELATED EVENTS CONSTITUTE ONE CLAIM FOR THIS PURPOSE. "PAYABLE" INCLUDES FEES ALREADY INCURRED BUT NOT YET INVOICED UNDER ARREARS BILLING.

THESE EXCLUSIONS AND LIMITS DO NOT APPLY TO PROVIDER'S FRAUD, WILLFUL MISCONDUCT, GROSS NEGLIGENCE, OR LIABILITY THAT APPLICABLE LAW DOES NOT ALLOW TO BE LIMITED. THEY DO NOT EXCUSE PERFORMANCE OF EXPRESS OBLIGATIONS OR LIMIT A REGULATOR'S AUTHORITY. NOTHING LIMITS A PERSON'S RIGHTS WHO IS NOT BOUND BY THIS AGREEMENT.

24. Third-party claims and indemnification

Company shall defend and indemnify Provider and its personnel against third-party claims, resulting damages, and reasonable defense costs to the extent caused by Company's security services or personnel management, failure to pay or lawfully classify its personnel, unlawful or infringing Customer Data, or Company's material violation of this Agreement or law. This obligation does not apply to the extent a claim is caused by Provider's breach, negligence, or other wrongful conduct. It is not an agreement to indemnify Provider for its own wrongdoing.

Provider must give prompt notice of a claim, with delayed notice relieving Company only to the extent materially prejudiced; permit Company to control a reasonable defense with qualified counsel; and provide reasonable cooperation at Company's expense. No settlement may admit Provider's fault, impose nonmonetary duties on it, or fail to release it without Provider's written consent, not unreasonably withheld. Provider may participate with its own counsel at its own expense unless a conflict of interest reasonably requires separate defense counsel.

25. Disputes and governing law

Indiana law governs, excluding conflict-of-law rules, except where controlling law requires otherwise. Before ordinary litigation, the Parties shall attempt in good faith to resolve a dispute for 30 days after written notice reasonably describing it. This requirement does not delay urgent protective relief or require a Party to miss a legal filing deadline.

Subject to subject-matter jurisdiction and controlling law, proceedings must be brought in state courts in Marion County, Indiana, or the United States District Court for the Southern District of Indiana, Indianapolis Division. The Parties consent to personal jurisdiction there. No mandatory arbitration, class-action waiver, or jury-trial waiver is created by this Agreement. Each Party bears its own litigation fees unless a statute, enforceable court award, or Section 24 provides otherwise. A Party may seek appropriate protective relief for misuse of data, confidential information, or intellectual property, subject to ordinary legal standards.

26. Notices and electronic execution

Company's notice email and Provider's legal identity and notice details are recorded above. Each Party shall keep its notice contact current. Operational notices may use in-app messages or email; material legal or pricing notices shall be sent to the notice email, with an in-app copy when available. An undeliverable email is not deemed received merely because an automated system attempted to send it. A Party shall use a reasonable alternative after learning delivery failed.

An authorized representative may bind Company by typing their name, affirmatively agreeing to this Agreement and its billing disclosures, and selecting the electronic acceptance button. Company consents to conducting this transaction electronically and may retain or print the Agreement and execution record. The acceptance record shall identify the legal company, accepting representative, agreement version, and actual acceptance date and time. The representative's signature is on behalf of Company and is not a personal guaranty.

27. Changes, order of precedence, and complete agreement

This Agreement and accepted Orders form the complete agreement for Company's software subscription. An Order varies this Agreement only where it identifies the specific exception and is accepted by both Parties; ordinary resource selection sets price and capacity, not unrelated legal changes. This Agreement controls over conflicting general website terms for the Company subscription. Separate terms applicable to individual user accounts continue to govern those accounts without giving Company ownership of them.

Material legal amendments require notice and an authorized representative's affirmative acceptance for the amended terms to bind Company. A revised webpage or a changed company profile does not rewrite a previously accepted agreement. Changes do not apply retroactively to accrued charges or claims. If agreement on future terms cannot be reached, either Party may use the ordinary termination provisions. Legally necessary changes apply to the extent the law requires without expanding unrelated rights.

28. Assignment and general provisions

Neither Party may assign this Agreement without the other's written consent, not unreasonably withheld, except to a successor in a merger or transfer of substantially all of the relevant business where the successor assumes the obligations and the other Party is notified. A brand-name change alone does not silently substitute a different contracting party. No assignment releases already accrued obligations without agreement.

Failure to enforce a provision is not a waiver. If a provision is unenforceable, the remainder continues to the extent legally possible; no automatic expansion of a restriction is intended. Events beyond a Party's reasonable control may excuse affected performance while that Party reasonably mitigates the effects, but do not excuse already accrued payment obligations or reasonable security and preservation duties. Provisions concerning accrued fees, data rights, retention, confidentiality, intellectual property, liability, disputes, and matters intended to continue survive termination. No third-party beneficiary rights are created.

29. Company's acknowledgement and signature

By signing below or completing the electronic acceptance process, the representative confirms authority to act for Company, accepts this Agreement on Company's behalf, and acknowledges the month-to-month renewal, billing in arrears on the first of the following month, full monthly rates without proration, Company's personnel and payroll responsibilities, and the 60-day incident-report retention policy.

Company legal name: [Company legal name]
Representative's typed full name: [Authorized representative]
Title: [Representative title]
Representative email: representative@example.invalid
Signature for paper execution: ________________________________________
Acceptance date and time: recorded upon electronic acceptance, or __________________ for paper execution.

For paper execution only, Provider signature: ______________________________
Provider's printed name: Lukas Thorneycroft
Capacity: Owner, individual doing business as OffDuty HQ
Date: __________________

For electronic execution, Provider makes this offer through the configured signup process and records Company's acceptance; a separate handwritten Provider signature is not required. The company-specific execution receipt accompanies the retained agreement and is not a new set of terms.

Company signup