Exhibit 10.3

 

 

CERTAIN IDENTIFIED INFORMATION HAS BEEN EXCLUDED FROM THIS EXHIBIT BECAUSE IT IS BOTH (I) NOT MATERIAL AND (II) THE TYPE THAT THE REGISTRANT TREATS AS PRIVATE OR CONFIDENTIAL. INFORMATION THAT HAS BEEN OMITTED IS NOTED IN THIS EXHIBIT WITH A PLACEHOLDER IDENTIFIED BY THE MARK "[***]".

 

Master Service Agreement

 

 

This Master Service Agreement, including any Order Forms, Schedules and/or Product Specific Terms attached hereto or incorporated by reference (collectively, the “Agreement”), is entered into and effective as of the date of the final signature below (“Effective Date”), by and among NovaBay Pharmaceuticals, Inc., located at 2000 Powell Street suite 1150, Emeryville, California 94608, United States and its Affiliates (as defined below), (“Client”), and Fireblocks, Inc., a Delaware corporation, located at 5 Pennsylvania Plaza, Floor 2, New York, NY 10001 (“Fireblocks”); and (each, a “Party” and collectively, the “Parties”).

 

Capitalized terms not defined herein shall have the meaning assigned to them in Schedule A (Definitions).

 

 

1.

Service; Usage Restrictions.

 

 

1.1.

Service. The Fireblocks software as a service platform gives Client the ability to securely store, manage and administer its holdings of digital assets. Client may access certain Platform Services, Premium Features and Add-On Features (individually and collectively, the “Service(s)”), as well as Third Party Services, as defined in and subject to: (i) the product specific terms as set forth at https://www.fireblocks.com/product-specific-terms/ (the “Product Specific Terms”); and (ii) the terms and conditions of this Agreement.

 

 

1.2.

Usage Rights. Subject to the terms and conditions of this Agreement (including payment obligations) and any Order Form(s), Fireblocks grants to Client a subscription to access and use the Service on a non-exclusive, non-sublicensable, non-transferable basis for the Term, and as set out in the applicable Order Form(s). Client may authorize individual users to use or otherwise have access to the Service (“Users”) provided that Client shall be responsible for any such use.

 

 

1.3.

Usage Restrictions. Client shall not, shall not attempt to, and shall ensure it does not authorize or assist anyone to:

 

 

(a)

circumvent, disable or otherwise interfere with security-related features of the Service(s) or features that enforce limitations on use of the Service(s);

 

(b)

disassemble, reverse engineer, modify, translate, alter or decompile all or any portion of the Service(s) or otherwise discern the source code of the Service(s), except and solely to the extent permitted under applicable law;

 

(c)

use the Service(s): (i) on a service bureau or time-sharing basis; or (ii) to provide Service(s) to any Third Party not in accordance with this Agreement;

 

(d)

distribute, copy, modify, duplicate, rent, lease, sublicense, assign, transmit, sell or otherwise transfer the Service(s) or any of Client’s rights therein;

 

(e)

violate or abuse password protections governing access and usage of the Service(s);

 

(f)

interfere with the integrity or proper working of the Service(s);

 

(g)

use the Service(s) in any unlawful manner or otherwise in breach of this Agreement or the instructions in the Help Center;

 

(h)

delete, remove, obscure or in any manner alter any Fireblocks’ or Third Party copyright, trademark, or other intellectual proprietary rights notices appearing on or in the Service(s) or any component thereof;

 

(i)

use the Service(s) in order to conduct any penetration testing, vulnerability assessment, aimed identified security vulnerability, or other benchmarking activities, either alone or in connection with any other Service(s) or hardware without the prior written consent of the Fireblocks;

 

 

 

 

(j)

disclose or provide to any of Fireblocks’ competitors the results of any comparisons, competitive analysis, benchmark testing, technical results or other performance data relating to the Service(s);

 

(k)

use the Service(s) other than as permitted herein; and/or,

 

(l)

use Fireblocks’ name and logo without Fireblocks prior written approval.

 

 

1.4.

Access and Users. Client shall:

 

 

(a)

promptly notify Fireblocks of any Security Incident;

 

(b)

cooperate in good faith with Fireblocks in the investigation of any Security Incident;

 

(c)

ensure that all Users comply with the terms and conditions of this Agreement;

 

(d)

be solely responsible for its internal policies and procedures with respect to delegating use of the Service to Users, including ensuring that Users keep any Account login details secure; and,

 

(e)

be bound by, and responsible for, all actions taken on the Fireblocks platform.

 

 

1.5.

Without derogating from the above, Fireblocks will not be responsible or liable in any way for any damages, including but not limited to any loss of digital assets, arising from or related to: (i) any instance of unauthorized access or use of the Service by Users; (ii) any loss or damages arising due to Client’s implementation of the Service which does not comply with Fireblocks’ instructions; and/or (iii) any other Third Party using the Workspace to access to the Service (including in case of theft, embezzlement, or similar cases).

 

 

1.6.

Security. Fireblocks Information Security Schedule as attached as Schedule B to this Agreement, is incorporated into this Agreement.

 

 

2.

Service Level Agreement; Customer Support Terms. Fireblocks will provide the Service in accordance with the service level agreement set forth at www.fireblocks.com/sla (the “SLA”); and, any Support Services acquired by Client are provided pursuant to the Global Support Services terms set out at: www.fireblocks.com/fireblocks-global-support (“Support Terms”). Both the SLA and the Support Terms may be amended by Fireblocks from time-to-time and are incorporated by reference into this Agreement.

 

 

3.

Usage Data.

 

 

3.1.

Usage Data. Through its use of the Services, Client may provide, upload, import, transmit, post, or make accessible to Fireblocks certain data (“Usage Data”). Client hereby grants Fireblocks a royalty-free, fully paid, revocable, non-exclusive license to use, process, display, copy, make derivative works of, and store (“Process”) the Usage Data solely to: (i) provide the Services to Client; (ii) administer and make improvements to the Service; and (iii) analyze aggregated anonymous information. Client acknowledges that the Services do not operate as an archive or file storage system. Client is solely responsible for the backup of any Usage Data and Client alone must implement any backup plans and safeguards it deems appropriate for its requirements.

 

 

3.2.

Client, on its own behalf and on behalf of its Users acknowledges that to the extent that Client provides any data to Fireblocks, Client warrants that Client will be responsible for the legality, integrity and accuracy of such data.

 

 

3.3.

Processing of Personal Data. To the extent that Fireblocks processes the Client's Personal Data under applicable privacy laws, it shall do so only in accordance with the Data Processing Addendum available at: https://www.fireblocks.com/data-processing-agreement/ (the “DPA”) and the Privacy Policy, available at https://www.fireblocks.com/privacy-policy/, both of which may be amended by Fireblocks from time-to-time and which are incorporated by reference into this Agreement.

 

 

 

 

4.

Pricing and Payment.

 

 

4.1.

Subscription Fee. Client shall pay Fireblocks the subscription Fees as set out in the relevant Order Form. Unless otherwise set forth in an applicable Order Form, the Fees are payable in full and non-refundable upon execution of the Order Form.

 

 

4.2.

Payment Terms. Any applicable payment terms approved by Fireblocks shall be as set out in the relevant Order Form. Unless otherwise specified in the Order Form, all Fees shall be due and payable within thirty (30) days from the date of the invoice, and Client shall affect payment of all Fees by wire transfer, credit card or as otherwise specified in the Order Form. If Client does not pay the Fees in full by the due date, the overdue amount shall be subject to a late fee equal to the lesser of 1.5% per month or the maximum amount allowed by applicable law. Additionally, Fireblocks may cease providing the Service(s) in the event of a failure to pay undisputed invoices in accordance with the Agreement.

 

 

4.3.

Taxes. All amounts and Fees payable under this agreement are due in full and are not subject to any set-off or deduction. All Fees exclude any applicable indirect taxes, duties, and similar governmental charges. Except for Fireblocks' net income taxes, Client is responsible for paying all such amounts, including sales and use tax, value-added tax (VAT), gross basis withholding taxes the Client determines to be due, export, import, and other duties imposed by any governmental agency in connection with this Agreement and/or the use of the Service. 

 

To avoid doubt, Client agrees to classify all payments made under this Agreement as payments for services, and Client shall not characterize these payments as royalties at any time. Client also agrees to hold Fireblocks harmless from all claims and liability arising from Client's failure to report or pay such taxes, duties, or other governmental charges.

 

 

5.

Term and Termination.

 

 

5.1.

Term. Unless terminated earlier in accordance with the terms of this Agreement, this Agreement and the access and usage rights granted under Section 1 is effective for the period set forth in the applicable Order Form (the “Initial Term”). Unless otherwise specified in the Order Form, upon expiry of the Initial Term (or a Renewal Term as the case may be), this Agreement shall automatically renew for consecutive and successive one (1) year periods (each such period a “Renewal Term”), unless either Party provides the other with written notice that the Agreement should not automatically renew, at least thirty (30) days prior to the expiry of the Initial Term or the then-current Renewal Term (as the case may be). Collectively, each and every Renewal Term together with the Initial Term, the “Term”. For the avoidance of doubt, Fireblocks may update the applicable Fees for a Renewal Term by providing Client with notice of such changes at least forty-five (45) days prior to the commencement of such Renewal Term.

 

 

5.2.

Termination. This Agreement and/or an applicable Order Form may be terminated by either Party at any time by giving notice in writing: (i) if the other Party commits a material breach of this Agreement, and, if curable, fails to cure the breach, within thirty (30) days after being given written notice, specifying details of the breach, and requiring the same to be remedied; or (ii) if the other Party ceases to carry on business in the ordinary course, becomes insolvent or the subject of voluntary or involuntary bankruptcy or liquidation proceedings, has a receiver, trustee or similar officer appointed with respect to the whole or substantial part of its assets, or is the subject of any creditor protection or proposal or similar arrangement under applicable law.

 

 

5.3.

Suspension of Service(s). If Client does not pay the Fees in accordance with the terms of this Agreement and the applicable Order Form, Fireblocks, in its sole discretion, and upon ten (10) days written notice to Client, may suspend, block and/or restrict Client’s access to and usage of the Service.

 

 

5.4.

Effect of Termination. Upon termination of the Agreement and/or an applicable Order Form, Client shall: (i) immediately stop access and cease use of the Service; (ii) transfer and remove all the amounts deposited or transferred to its Workspace(s) and ensure that no amounts will be transferred to the Workspace following termination; and (iii) return to Fireblocks or destroy all Fireblocks Confidential Information in its possession, except as otherwise provided herein. Following notice of termination or of non-renewal of this Agreement, Client has the sole responsibility to remove all digital assets from its Workspace(s) and acknowledges that Fireblocks is not liable for any digital assets in Client’s Workspace following termination of the Agreement.

 

 

 

 

5.5.

Survival. All provisions of this Agreement which may reasonably be interpreted or construed as surviving the non-renewal or termination of this Agreement including, but not limited to, Sections 1, 3, 5, 6, 7, 8, 10, and 13 shall survive any expiry or termination of this Agreement.

 

 

6.

Proprietary Rights.

 

 

6.1.

Intellectual Property Rights. All rights, titles, and interests, including any Intellectual Property rights evidenced by or embodied in, attached, connected, and/or related to the Service(s) and any and all improvements and derivative works thereof, are and shall remain owned solely by Fireblocks. This Agreement does not in any manner whether directly or indirectly convey to Client any rights, interest, or license in or to the Service(s) other than as the right to access and use the Service(s) as expressly stated herein or in any Order Form. Nothing herein constitutes a waiver of Fireblocks’ Intellectual Property rights under any applicable law. Nothing in this Agreement excludes the liability of Client for any breach, infringement or misappropriation of Fireblocks’ Intellectual Property rights.

 

 

6.2.

Feedback. Client hereby grants to Fireblocks a royalty-free, fully-paid up, transferrable, non-exclusive, irrevocable, worldwide license to use, copy, modify, distribute, perform, display, create derivatives of, make, or have made any Feedback provided by Client to Fireblocks. Any improvements made to the Service due to any Feedback shall belong exclusively to Fireblocks and shall be considered Fireblocks’ Intellectual Property. Client hereby irrevocably and unconditionally transfers and assigns to Fireblocks all Intellectual Property rights it may have in any developments made as a result of such Feedback and waives any and all moral rights that Client may have in respect thereto. It is further understood that use of Feedback, if any, may be made by Fireblocks at its sole discretion, and that Fireblocks in no way shall be obliged to make use of any kind of the Feedback or part thereof.

 

 

6.3.

Intellectual Property. Except for rights expressly granted under this Agreement, nothing in this Agreement will transfer any of either Party's Intellectual Property rights to the other Party, and each Party will retain exclusive interest in, and ownership of, its Intellectual Property developed prior to this Agreement or developed outside the scope of this Agreement.

 

 

7.

Confidential Information.

 

 

7.1.

Where there is an existing nondisclosure agreement (“NDA”) between them, the Parties agree that:

 

 

(a)

the terms of the NDA are hereby incorporated by reference and will continue to apply to Confidential Information (as defined in the NDA) disclosed pursuant to this Agreement, notwithstanding any expiry of the NDA;

 

(b)

the purpose of this Agreement shall be deemed to be included in the definition of Purpose under the NDA; and,

 

(c)

the termination of this Agreement will not affect the validity or effect of the NDA.

 

 

7.2.

Where there is no existing NDA between them, the Parties agree that:

 

 

(a)

each Party shall take reasonable measures, at least as protective as those taken to protect its own Confidential Information, but in no event less than reasonable care, to protect the disclosing Party’s Confidential Information from disclosure to a Third Party. The receiving Party’s obligations, with respect to any Confidential Information of the disclosing Party, shall not apply to and/or shall terminate if such information: (a) was already lawfully known to the receiving Party at the time of disclosure by the disclosing Party; (b) was disclosed to the receiving Party by a Third Party who had the right to make such disclosure without any confidentiality restrictions; (c) is, or through no fault of the receiving Party has become, generally available to the public; or (d) was independently developed by the receiving Party without access to, or use of, the disclosing Party’s Confidential Information. Neither Party shall use or disclose the Confidential Information of the other Party except for performance of its obligations under this Agreement. The receiving Party shall only permit access to the disclosing Party's Confidential Information to its respective employees, consultants, Affiliates, agents, and subcontractors having a need to know such information;

 

 

 

 

(b)

the receiving Party may also disclose Confidential Information to the minimum extent required by an order of any court of competent jurisdiction or any regulatory, judicial, governmental, or similar body or any taxation authority of competent jurisdiction. Before the receiving Party makes any such disclosure of any Confidential Information it shall, to the extent permitted by law, use reasonable endeavors to give the disclosing Party as much notice of this disclosure as possible; and,

 

(c)

upon any termination of this Agreement, each Party shall delete or, upon reasonable request, return to the other Party all Confidential Information of the other Party, and all copies thereof, in the possession, custody or control of the Party unless otherwise expressly provided in this Agreement. All right, title and interest in and to Confidential Information are and shall remain the sole and exclusive property of the disclosing Party.

 

 

8.

Limited Warranties; Disclaimer of Warranties.

 

 

8.1.

Mutual Representations. Each Party warrants that: (i) it has the power and authority, and has taken all corporate action required, to enter into and fully perform this Agreement; and (ii) its entry into and performance of this Agreement does not, and will not, violate any agreement to which it is bound.

 

 

8.2.

Fireblocks' Limited Warranty. Fireblocks further warrants: (a) the Service will perform materially in accordance with the applicable Documentation; and (b) it will use commercially reasonable efforts to ensure that the use of the Service in accordance with the terms of this Agreement will not introduce any Malicious Code into Client's systems. In case of failure of the abovementioned warranties, Client will immediately notify Fireblocks of such failure, and Fireblocks will make commercially reasonable efforts to repair or replace the non-conforming Service.

 

 

8.3.

Client's Representations. Client further represents and warrants that it: (i) will comply with all applicable laws, including any laws and regulations applicable to its digital asset activities, including but not limited to consumer protection, money transmission, e-money licenses, privacy, anti-bribery, anti-corruption, money laundering, economic or trade-based sanctions, or terrorist financing laws and regulations; and (ii) is solely responsible for ensuring that its activities on the Fireblocks platform are in compliance with all applicable regulatory obligations, notwithstanding any use-cases proposed by Fireblocks.

 

 

8.4.

DISCLAIMER OF WARRANTY. EXCEPT AS EXPRESSLY PROVIDED IN THIS AGREEMENT, THE SERVICE PROVIDED BY FIREBLOCKS TO CLIENT ARE PROVIDED "AS IS" AND FIREBLOCKS AND ITS SUPPLIERS, IF ANY, MAKE NO WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, REGARDING THE SERVICE, AND SPECIFICALLY DISCLAIM THE WARRANTIES OF MERCHANTABILITY FITNESS FOR A PARTICULAR PURPOSE, TO THE MAXIMUM EXTENT POSSIBLE BY LAW. FIREBLOCKS DOES NOT WARRANT THAT THE SERVICE WILL MEET CLIENT'S REQUIREMENTS, OPERATE WITHOUT INTERRUPTION OR BE ERROR FREE.

 

 

8.5.

NO LIABILITY FOR CLIENT MODIFICATIONS. THE WARRANTY SETOUT HEREIN DOES NOT APPLY, AND FIREBLOCKS HAS NO RESPONSIBILITY FOR ANY DAMAGE, INCLUDING ANY LOSS OF DIGITAL ASSETS AND/OR OTHER DAMAGE TO THE WORKSPACE, IN THE EVENT OF ANY SECURITY BREACH RESULTING FROM: (i) ANY MODIFICATIONS OR ALTERATION OF THE SERVICE, ITS FUNCTIONALITY, OR CAPABILITIES THAT IS NOT MADE BY FIREBLOCKS OR ITS AGENTS; (ii) CLIENT’S FAILURE TO FOLLOW FIREBLOCKS INSTRUCTIONS FOR USE OF THE SERVICE AS SET OUT IN HELP CENTER AND/OR DOCUMENTATION; AND/OR (ii) BY MALICIOUS CODE OR OTHER MECHANISMS TO DISABLE SECURITY OR CONTENT PROTECTION THAT IS INTRODUCED BY, OR RESULTING FROM, CLIENT'S NETWORK, SYSTEM, AND/OR ITS ACT OR OMISSION.

 

 

 

 

9.

Indemnities.

 

 

9.1.

Indemnification by Fireblocks. Fireblocks agrees to indemnify, defend, and hold harmless Client from and against Third Party IP Infringement Claims arising out of Client’s use of the Service and Fireblocks will pay any damages or judgments awarded in a final judgment against Client that are attributable to such claim, provided Client complies with the Indemnification Process set forth herein. Notwithstanding the foregoing, Fireblocks shall have no responsibility for Excluded Claims. If the Service becomes, or in Fireblocks' opinion is likely to become, the subject of an IP Infringement Claim, then Fireblocks may, at its sole discretion: (a) procure for Client the right to continue using the Service; (b) replace or modify the Service to avoid the IP Infringement Claim; or (c) if options (a) and (b) cannot be accomplished despite Fireblocks' reasonable efforts, then Fireblocks may terminate this Agreement and provide a refund for any amount prepaid by Client for the remaining unused period of the Term.

 

 

9.2.

Indemnification by Client. Client agrees to indemnify, defend, and hold harmless Fireblocks from and against any Third Party Claims arising from: (i) any Excluded Claims; or (ii) Client’s breach of the Product Specific Terms, and Client will pay any damages or judgments awarded in a final judgment against Fireblocks that are attributable to any such claim, provided that Fireblocks complies with the Indemnification Process set forth herein.

 

 

9.3.

Indemnification Process. The Party seeking indemnification shall: (i) promptly notify the indemnifying Party of any claim in writing; (ii) grant the indemnifying Party the sole authority to conduct the defense or settlement of such claim, provided that the indemnifying Party shall not settle any claim that requires the indemnified Party to pay monetary damages or is subject to injunctive relief without the indemnified Party’s written consent; and (iii) provide the indemnifying Party all reasonable information and assistance at the indemnifying Party’s expense. Notwithstanding the foregoing, the Indemnified Party shall be able to participate in any defense at its own expense.

 

 

9.4.

Sole and Exclusive Remedy. This Section 9 states Fireblocks’ entire liability, and Client’s exclusive remedy, for claims of alleged or actual Intellectual Property infringement.

 

 

10.

Limitation of Liability.

 

 

10.1.

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, EXCEPT FOR CLIENT'S MISAPPROPRIATION OR OTHER VIOLATION OF FIREBLOCKS' INTELLECTUAL PROPERTY RIGHTS INCLUDING MISUSE OF THE RIGHTS GRANTED HEREUNDER (“LIABILITY EXCLUSIONS”), NEITHER PARTY SHALL BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, PUNITIVE, OR CONSEQUENTIAL DAMAGES, OR ANY LOSS OF REVENUE, REPUTATION, OR PROFITS, DATA, OR DATA USE.

 

 

10.2.

NOTWITHSTANDING ANYTHING TO THE CONTRARY AND EXCEPT FOR THE LIABILITY EXCLUSIONS, EITHER PARTY’S MAXIMUM LIABILITY ARISING OUT OF OR RESULTING DIRECTLY FROM THIS AGREEMENT, WHETHER IN CONTRACT OR TORT, OR OTHERWISE, SHALL IN NO EVENT EXCEED, IN THE AGGREGATE, THE TOTAL AMOUNTS ACTUALLY PAID TO FIREBLOCKS PURSUANT TO THE APPLICABLE ORDER FORM(S) IN THE TWELVE (12) MONTH PERIOD IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO SUCH CLAIM. THIS LIMITATION OF LIABILITY IS CUMULATIVE TO THE TERM OF THE AGREEMENT (AS EXTENDED OR OTHERWISE) AND NOT PER INCIDENT; PROVIDED, HOWEVER, THE LIMITATIONS IN THIS SECTION DO NOT APPLY TO PAYMENTS DUE TO FIREBLOCKS UNDER THIS AGREEMENT.

 

 

 

 

10.3.

THE LIMITATIONS SET FORTH IN THIS SECTION SHALL APPLY EVEN IF CLIENT’S REMEDIES UNDER THIS AGREEMENT FAIL THEIR ESSENTIAL PURPOSE.

 

 

11.

Force Majeure.

 

   

Neither Party shall be liable to the other for any performance delay or failure to perform hereunder, due to Force Majeure Event, provided the affected Party gives prompt notice to the other and makes reasonable efforts to resume performance as soon as possible. The Party not affected by such act, omission or condition may terminate this Agreement upon written notice if the other Party remains unable to perform because of any circumstances described in this Section for a period of more than sixty (60) days. It is hereby clarified that neither an occurrence of a Force Majeure Event or the termination of this Agreement in connection therewith shall relieve either Party from its obligations to pay the other any outstanding payments due under this Agreement.

 

 

12.

Export Controls and Trade Sanctions Compliance.

 

   

Client represents and warrants that: (i) Client is not a citizen or resident of, or located within, a country or territory that is subject to comprehensive U.S. trade sanctions or other significant trade restrictions (including without limitation Crimea, Cuba, Iran, North Korea, and Syria); (ii) neither Client nor its ultimate beneficial owners, if applicable, are identified on any U.S. government restricted party lists (including without limitation lists administered by OFAC such as the Specially Designated Nationals and Blocked Persons List, Foreign Sanctions Evaders List, and Sectoral Sanctions Identifications List, or lists administered by BIS such as the Denied Party List, Entity List and Unverified List); and (iii) that no content created or submitted by Client is subject to any restriction on disclosure, transfer, download, export or re-export under the Export Control Laws. Client agrees that Client will not use the Service to disclose, transfer, download, export, or re-export, directly or indirectly, any content to any country, entity or other party which is ineligible to receive such items under the Export Control Laws or under other laws or regulations to which Client may be subject. Client agrees that Client will not use the Service to circumvent Export Control Laws. Client acknowledges that the Service may not be available in all jurisdictions and that Client is solely responsible for complying with the applicable laws associated with its business and services. Fireblocks may immediately suspend the provisions of the Service and/or terminate this Agreement upon written notice to Client if Fireblocks reasonably believes that Client is in violation of this Section.

 

 

13.

Miscellaneous.

 

 

13.1.

Governing Law & Jurisdiction. This Agreement shall be governed by and construed under the laws of Delaware, USA, without reference to principles and laws relating to the conflict of laws. The competent courts of Delaware shall have the exclusive jurisdiction with respect to any dispute and action arising under or in relation to this Agreement.

 

 

13.2.

Entire Agreement and Order of Precedence. This Agreement, including the Order Form, any Product Specific Terms, the SLA and the Documentation, represents the complete agreement concerning the subject matter hereof and supersedes any prior or contemporaneous agreements between the Parties with respect to the subject of this Agreement. In the event of a conflict between the terms of any such documents, the controlling term shall be that set forth in the Order Form, except for Section 5.1, then the Product Specific Terms, then this Agreement, then any Schedules, and finally the SLA.

 

 

13.3.

Severance and Amendment. If any provision of this Agreement shall be declared invalid, illegal, or unenforceable, then such provision shall be deemed modified or excluded to the extent necessary so that it is no longer invalid, in violation of law or unenforceable and all remaining provisions shall continue in full force and effect. Except where explicitly stated otherwise, the Agreement may be amended only by a written agreement executed by both Parties.

 

 

 

 

13.4.

Relationship of the Parties. This Agreement does not, and shall not be construed to create any relationship, partnership, joint venture, employer-employee or agency relationship between the Parties, or authorize either Party to act as an agent for the other, and neither Party shall have authority to act in the name or on behalf of or otherwise to bind the other in any way (including, but not limited to, the making of any representation or warranty the assumption of any obligation or liability and the exercise of any right of power).

 

 

13.5.

Insurance. Client shall be responsible for maintaining its own insurance policies. Fireblocks will provide Client with a copy of its certificate of insurance upon written request.

 

 

13.6.

Waiver. Any failure or delay by a Party to require compliance by the other Party with any of the terms, or exercise any right or remedy, provisions, warranties, covenants or conditions of this Agreement will in no way affect such Party's right to enforce the same, nor will any waiver by a Party of any breach of any term, provision, warranty, covenant or condition of this Agreement constitute a waiver of any succeeding breach.

 

 

13.7.

Rights and Remedies. Except as expressly provided in this Agreement, the rights and remedies provided under this Agreement are in addition to, and not exclusive of, any rights or remedies provided by law.

 

 

13.8.

Assignment. Neither Party may assign its rights or obligations under this Agreement without the prior written consent of the other Party, whose consent may not be unreasonably withheld or delayed. Notwithstanding the foregoing, this Agreement may be assigned by written notice, by either Party in connection with a merger, consolidation, sale of all of the equity interests of the assigning Party, or a sale of all or substantially all of the assets of the assigning Party to which this Agreement relates; provided that Fireblocks may terminate this Agreement immediately if it determines it cannot do business with the purported assignee due to its internal policies or due to any obligations under applicable law.

 

 

13.9.

Affiliates. Fireblocks may perform its obligations under this Agreement directly, or may have some or all of its obligations performed by any Affiliate and/or subcontractor. In doing so, Fireblocks is not relieved of its obligations to the Client under this Agreement, and remains responsible and liable for the performance of such obligations

 

 

13.10.

Notices. Any notice, request, demand, consent or other communication required or permitted to be given by this Agreement to a Party is to be given in writing, in English, and may be (i) delivered by hand or by pre-paid first-class post or other next working day delivery service and addressed to the address set out on the first page of this Agreement or to a Party’s registered office (if different) or (ii) sent by email to the following addresses (or an address substituted in writing by the party to be served):

 

Fireblocks:  Email Address: legal@fireblocks.com Attention: The Legal Department

 

Client:         To the email address provided by the Client from time to time.

 

 

13.11.

Counterparts. This Agreement may be executed in any number of counterparts, each of which shall constitute a duplicate original, but all the counterparts shall together constitute the one agreement. No counterpart shall be effective until each Party has provided to the other at least one executed counterpart.

 

[Signature page follows]

 

 

 

IN WITNESS WHEREOF, the Parties have executed this Agreement as of the Effective Date.

 

Fireblocks NovaBay Pharmaceuticals, Inc.
   
By: /s/ Dominic Wong By: /s/ Michael Kazley
   
Name: Dominic Wong Name: Michael Kazley
   
Title: VP, Revenue Operations Title: Chief Executive Officer
   
Date: Jan 6, 2026 Date: Jan 6, 2026

         

 

 

Schedule A Definitions

 

 

1.1

“Add-On Features” are those Services described in Section III of the Product Specific Terms.

 

1.2

“Affiliate” shall mean any entity, individual, agent, employee, firm, or corporation, directly or indirectly, through one or more intermediaries, controlling, controlled by, or under common control with the respective Party.

 

1.3

“Agreement” shall have the meaning prescribed to it in the preamble.

 

1.4

“BIS” means the U.S. Department of Commerce’s Bureau of Industry and Security.

 

1.5

“Client” shall have the meaning prescribed to it in the preamble.

 

1.6

“Confidential Information” means all knowledge, information, or materials of whatever nature and in whatever form (whether provided in writing or orally) relating to the disclosing party and made available or provided by or on behalf of the disclosing party to the recipient whether before, on or after the Effective Date. It specifically includes the terms of this Agreement and information relating to: (i) any and all proprietary technology and products, including technical data, data record layouts, trade secrets, know-how, research, prototypes, improvements, processes, plans, calculations, designs, requirements, architecture, structures, models, methods, product plans, databases and database tables, ideas or concepts, opinions, reports, Service(s), software, inventions, techniques, developments, algorithms, formulas, technology, designs, schematics, drawings, engineering and hardware configuration information; (ii) the operations and business or financial statements and projections, product pricing and marketing, financial or other strategic business plans or affairs, accounting matters, tax matters, subscriber numbers and forecasts, content providers identity and business models; (iii) all summaries, notes, memoranda, analyses, compilations, studies or other documents prepared by or on behalf of the recipient to the extent that they contain or are derived from Confidential Information; (iv) information collected or developed by a party regarding its customers; (v) any actual or perceived system vulnerability, whether identified by Fireblocks or Client; and (vi) all other information which would reasonably be considered to be proprietary or confidential in nature.

 

1.7

“Documentation” means the applicable SLA and each of the SOC 2 Type 2, ISO 27001, ISO 27017, and ISO 27018 attestation(s) of certification.

 

1.8

“Effective Date” shall have the meaning prescribed to it in the preamble.

 

1.9

“Excluded Claim” means any and all Third Party claims, actions, suits, liabilities, costs, and expenses alleging that the Service infringes Intellectual Property rights of a Third Party and that such infringement is resulting from or based on: (i) modifications to the Service made by Client or its representatives or designees, or at their direction; (ii) Client's failure to implement software updates provided by Fireblocks specifically to avoid infringement; or (iii) combination or use of the Service with equipment, devices or software not supported or provided by Fireblocks or not in accordance with the terms of this Agreement.

 

1.10

“Export Control Laws” mean applicable export control and trade sanctions laws, rules, and regulations, including without limitation the regulations administered by BIS and OFAC.

 

1.11

“Fee” means any fees set forth in an applicable Order Form.

 

1.12

“Feedback” is any input or suggestions (including, but not limited to, questions, comments, feature improvement requests, or the like) regarding the Service made by, or for and on behalf of, Client to Fireblocks.

 

1.13

“Fireblocks shall have the meaning prescribed to it in the preamble.

 

1.14

“Force Majeure Event” means any act, omission or condition beyond the reasonable control of the affected party including, but not limited to the following events: acts of God, flood, draught, earthquake or other natural disaster, epidemic or pandemic, terrorist attack, civil war, armed conflict, nuclear, chemical or biological contamination, any law or any action taken by a government or public authority, including without limitation imposing an export or import restriction, quota or prohibition, interruption or failure of utility service(s).

 

1.15

“Initial Term” shall have the meaning prescribed to it in Section 5.1.

 

 

 

 

1.16

“Intellectual Property” means patents (including patent for software and business methodology), rights to apply for patents, trademarks, trade names, service marks, domain names, copyrights and all applications and registration of such worldwide, schematics, industrial models, inventions, know-how, trade secrets, computer software programs, and other intangible proprietary information.

 

1.17

“IP Infringement Claim” means any and all Third Party claims, actions, suits, liabilities, costs, and expenses alleging that the Service, when used as permitted under this Agreement, infringes Intellectual Property rights of a Third Party.

 

1.18

“Liability Exclusions” shall have the meaning prescribed to it in Section 10.

 

1.19

“Malicious Code” means any “back door,” “drop dead device,” “time bomb,” “Trojan horse,” “virus,” “ransomware,” or “worm” (as such terms are commonly understood in the software industry) or any other code designed or intended to have, or capable of performing, any of the following functions: (a) disrupting, disabling, harming, interfering with or otherwise impeding in any manner the operation of, or providing unauthorized access to, a computer system or network or other device on which such code is stored or installed; or (b) damaging or destroying any data or file without the User’s consent.

 

1.20

“NDA” shall have the meaning prescribed to it in Section 7.1.

 

1.21

“OFAC” means the U.S. Department of the Treasury’s Office of Foreign Assets Control.

 

1.22

“Order Form” means a document executed by the Parties setting forth the terms of the Service, including the Fees and any Product Specific Terms.

 

1.23

“Personal Data” means any information relating to, or reasonably capable of identifying a consumer or an identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

 

1.24

“Platform Services” are those Services described in Section I of the Product Specific Terms.

 

1.25

“Premium Features” are those Services described in Section II of the Product Specific Terms.

 

1.26

“Process” shall have the meaning prescribed to it in Section 3.1.

 

1.27

“Product Specific Terms” shall have the meaning prescribed to it in Section 1.1.

 

1.28

“Renewal Term” shall have the meaning prescribed to it in Section 5.1.

 

1.29

“Service” shall have the meaning prescribed to it in Section 1.1.

 

1.30

“Security Incident” means any unauthorized access to, or the use of the Service(s).

 

1.31

“Term” shall have the meaning prescribed to it in Section 5.1.

 

1.32

“Third Party” means any entity that is not a Party to this Agreement, nor an Affiliate of a Party to this Agreement.

 

1.33

“Usage Data” shall have the meaning prescribed to it in Section 3.1.

 

1.34

“Workspace” means an administrative environment on the Fireblocks platform that enables Client to securely store, manage and administer its own holdings of digital assets directly on various blockchains.

 

 

 

Schedule B

 

Fireblocks Information Security Schedule (the Security Schedule)

 

THE PARTIES AGREE AS FOLLOWS:

 

1.

Interpretation

 

 

(a)

Terms defined in the Agreement shall have the same meaning when used in this Security Schedule.

 

 

(b)

Unless expressly stated otherwise, any reference in this Security Schedule to recitals, clauses, paragraphs or schedules is to recitals, clauses or paragraphs of or schedules to the Agreement.

 

 

(c)

In the event of any conflict between the terms of this Security Schedule and the terms of the Agreement, the terms of the Agreement shall prevail.

 

2.

Information Security

 

 

(a)

General. Fireblocks maintains and enforces policies, standards and processes designed to secure the Service and the Client data. This document describes the security measures that are taken by Fireblocks.

 

 

(b)

Client Data. Fireblocks has implemented and documented appropriate administrative, technical and physical measures to protect the Client data against accidental or unlawful destruction, alteration, and unauthorized access, disclosure or use. Fireblocks regularly tests and monitors the effectiveness of its safeguards, controls, systems and procedures and conducts periodic risk assessments to identify reasonably foreseeable internal and external risks to the security, confidentiality and integrity of the Client data. Fireblocks assess its information security practices on an ongoing basis and at least annually or whenever there is a material change in either Fireblocks’ business practices or the environment that may affect the security, confidentiality or integrity of the Client data, provided that Fireblocks will not modify its information security practices in a manner that will weaken its controls.

 

 

(c)

Fireblocks Obligations. Fireblocks have implemented and will maintain:

 

 

(i)

A patch management process, which ensures patches are appropriately tested and deployed to rectify security vulnerabilities in a reasonable timeframe with critical or urgent patches deployed as soon as possible, but in any case, within thirty (30) days of release;

 

 

(ii)

Processes to promptly return and/or erase all data in Fireblocks’ possession or control, at the request and option of Client, in a manner that maintains its confidentiality and integrity, as agreed between the Parties;

 

 

(iii)

Secure development lifecycle processes based on good industry practice (such as the OWASP or similar standards); and,

 

 

(iv)

Automated and manual analysis of the security of any code developed and subsequent remediation of vulnerabilities pursuant to Fireblocks' vulnerability management policy, as may be amended from time to time.

 

3.

Certifications

 

 

(a)

Fireblocks will, at its own cost, engage accredited and reputable third-party auditors to conduct the required audits to maintain the Certifications (as defined below), and shall provide such third-party auditor with access, facilities, and records sufficient to allow the third-party auditor to ensure that Fireblocks is complying or has complied with the applicable Certifications requirements. Without limiting the foregoing, in the event that the relevant report identifies a failure by Fireblocks to comply with the Certification requirements or any of its obligations under this Agreement, Fireblocks will promptly take reasonable steps to remedy the failure. Furthermore, Fireblocks will reasonably cooperate with an audit performed and required by an applicable regulatory agency.

 

 

 

 

(b)

Certifications. Fireblocks has obtained and will use reasonable endeavors to maintain during the Term its ISO 27001 (Information Security) and SOC 2, Type 2 Certification (collectively the “Certifications”). Upon Client’s written request, Fireblocks will provide Client with copies of the then-current Certification and/or the executive summary reports of the corresponding audit.

 

4.

Organizational Security; Client Data.

 

 

(a)

In its provision of the Services, Fireblocks has taken reasonable steps to maintain the information security of the Services and the Client data by:

 

 

(i)

logically segregating Client data from the data of other Fireblocks’ clients;

 

 

(ii)

implementing network, device application, database and platform security;

 

 

(iii)

securing information and data during transmission, processing, storage and disposal;

 

 

(iv)

implementing authentication and access controls within media, applications, operating systems and equipment;

 

 

(v)

implementing adequate administrative, physical and technical safeguards to protect the Client data that are no less rigorous than accepted industry standards; and,

 

 

(vi)

encrypting the Client data in transit and at rest.

 

 

(b)

Fireblocks will notify Client no later than 72 hours of a confirmed information security breach affecting the Client data or Client’s usage of the Services. In the event of such an information security breach, the Parties will reasonably cooperate with each other in the investigation of the incident and Fireblocks will share such relevant information as is reasonably requested by Client.

 

 

(c)

Fireblocks shall ensure that the Service has been tested in accordance with the Open Web Application Security Project (OWASP) Top 10 vulnerabilities for web application security.

 

5.

Network Security.

 

 

Fireblocks maintains network security using commercially-available best technologies and industry standard techniques, including firewalls, intrusion detection and prevention systems, access control lists and routing protocols.

 

6.

Access Control.

 

 

(a)

Fireblocks maintains appropriate access controls, including, but not limited to, restricting access to Client data to the Fireblocks Personnel on a need-to-know basis only; including using single sign-on technology.

 

 

(b)

Only authorized staff can grant, modify or revoke access to an information system that uses or houses Client data. Fireblocks monitors and maintains an audit trail of all Client data access to document whether and by whom Client data have been accessed, entered into, modified, transferred or removed. Fireblocks uses SIEM technology to aggregate all log monitoring.

 

 

(c)

User administration procedures and change management defines user roles and their privileges and how access is granted, changed and terminated; address appropriate segregation of duties; and define the logging/monitoring requirements and mechanisms.

 

 

(d)

All employees and contractors of Fireblocks are assigned unique user identifiers and require multi factor authentication to access the Service and Client data.

 

 

(e)

Access rights are implemented adhering to the “least privilege” approach.

 

 

 

 

(f)

Fireblocks implements commercially-reasonable physical and electronic security controls to create and protect passwords and Fireblocks has implemented and maintains a strong-password policy.

 

 

(g)

Fireblocks has established systems to prevent Client data processing systems from being used accidentally or without authorization, such as through logical access controls.

 

7.

Virus and Malware Control.

 

 

Fireblocks installs and maintains:

 

 

(a)

centrally-managed, industry-standard vulnerability management tools and processes, including the latest anti-virus and malware protection software on its systems; and,

 

 

(b)

malware monitoring and system scanning to reduce all Services-related vulnerabilities and to protect Client data and the Services from the effects of vulnerabilities or virus infections.

 

8.

Vulnerability Management.

 

 

(a)

Fireblocks maintains a vulnerability management program in accordance with the requirements of its Certifications; and as part of such program, Fireblocks will assess and remediate vulnerabilities that could compromise the Services or Client data. Vulnerabilities are classified by Fireblocks based on severity and risk and will be addressed in accordance with the following:

 

 

(i)

Critical findings with active exploits must be remediated within forty-eight (48) hours; critical findings with inactive exploits must be remediated within five (5) days;

 

 

(ii)

High priority findings must be remediated within thirty (30) calendar days;

 

 

(iii)

Medium severity findings must be remedied within ninety (90) calendar days; and,

 

 

(iv)

Low severity and very low severity findings will be remediated on a best effort basis as they are not business impacting.

 

 

(b)

Fireblocks will actively monitor industry resources (e.g., www.cert.org, pertinent software vendor mailing lists and websites and information from subscriptions to automated notification services) for applicable security alerts.

 

9.

Penetration Testing.

 

 

(a)

Upon written request, Fireblocks will provide Client with an executive report of its third-party penetration tests (“PenTests”) results of its applications and infrastructure. Web, application, and mobile PenTests will each be performed at least annually or if there is any material change in the environment following an industry-standard methodology.

 

 

(b)

Only when the foregoing is deemed insufficient by a regulator (a copy of such communication shall be provided to Fireblocks on reasonable request) or the Client, and if Fireblocks is unable to provide Client a satisfactory report of previously conducted threat-led penetration tests (“TLPT”), Fireblocks will participate in Pooled or Individual TLPTs, no more than once annually, as outlined below.

 

 

(c)

Pooled TLPTs. To use testing resources more efficiently and to decrease the organizational burden on both the Client and Fireblocks, the Parties will agree on jointly organized TLPTs (“Pooled TLPTs”) between Fireblocks, the Client and other clients of Fireblocks. A Pooled TLPT may be performed by the Client, one client or an appointed third party as mutually agreed by the parties.

 

 

(d)

Client TLPTs. If the Pooled TLPTs are deemed to be insufficient by a national competent authority or the Client, then Fireblocks shall participate in individual TLPTs with Client.

 

 

 

 

(e)

For either Pooled or Individual TLPTs (in either case a “TLPT”):

 

 

(i)

The parties shall mutually agree the scope (i.e. processes, applications, infrastructure), relevant key controls and timeline of the TLPT, which will be based on Fireblocks’ Security Assessment and Resilience Policy and will require approval by Fireblocks’ CISO. The TLPT shall be performed in “black box” mode.

 

 

(ii)

Any parts of the TLPTs which require active Fireblocks participation or other type of support, shall be performed during normal business hours (9.00 - 17.00) of the appropriate Fireblocks stakeholders or during periods prearranged and agreed between Fireblocks and clients.

 

 

(iii)

The parties will take steps to ensure the TLPT does not pose any risks to other Fireblocks’ client data or environment, Fireblocks confidentiality obligations to its other clients, service partners and/or employees, or to the operation of Fireblocks’ systems (e.g. impact on service levels, availability of data, confidentiality and privacy aspects).

 

 

(iv)

Notwithstanding anything to the contrary, Client assumes full responsibility and liability for any damage or harm that may result directly or indirectly from the TLPTs, including any damage to the Services provided to the Client, to any other Fireblocks Client, to Fireblocks’ systems, or to any Fireblocks’ partner, employee or any other third party.

 

 

(v)

Fireblocks shall have at least ninety (90) days’ notice, unless otherwise agreed between Fireblocks.

 

 

(f)

Costs. Clients shall fully indemnify Fireblocks in relation to its costs for any TLPTs conducted pursuant to this Schedule (including any third party legal or advisory fees). In addition, Client bears its full cost and expenses as well as full cost and expenses of third parties commissioned by the Client for providing and exercising such rights.

 

 

(g)

Right to Comment. Fireblocks shall receive and be entitled to comment on any and every report about TLPT prepared by or on behalf of Client(s) prior to that report being finalized, published or disseminated (such report to be Fireblocks’ Confidential Information except to the extent it relates to the business or affairs of Client(s), which information will be Client(s) Confidential Information), which publication or dissemination shall be done only pursuant to the confidentiality provisions of this Agreement. Client agrees that any TLPT report will be in English and Client will bear the cost of any required translation.

 

 

(h)

Right to Share. Client agrees that executive summaries and full versions of the reports arising from any TLPTs will be shared with Fireblocks, which Fireblocks may use for its own purposes, including sharing with external parties, as long as any Client Confidential Information is redacted.

 

10.

Disaster Recovery & Business Continuity.

 

 

Fireblocks will take appropriate and effective contingency measures to ensure the timely provision of the Services, including replacement solutions, as may be required, for business continuity purposes and to provide for a return to normal operations within a reasonable timeframe. The contingency measures taken by Fireblocks shall comply with the applicable legal requirements and any additional requirements or service standards as expressed in the SLA and as provided to the Licensee during the due diligence process. The contingency measures to be taken by Fireblocks are described in a contingency plan (hereinafter referred to as “Contingency Plan”). Fireblocks shall regularly review its Contingency Plan for appropriateness and potential for improvement and, if necessary, revise it in order to adapt it to changes in case of threat situations. In the event of a change of the Contingency Plan, Fireblocks shall make all necessary changes to the IT systems and IT processes used to perform the Service. Such adaptations shall not result in the level of the contingency measures falling below the level of the previous emergency measures, unless such falling below is due to requirements by mandatory law. Upon Client’s written request, Fireblocks will provide a redacted version of its business continuity plan and disaster recovery plan.

 

 

 

11.

Security Incident Reporting.

 

 

Fireblocks shall notify the Client in writing of any confirmed security incident that materially compromises the security of the Client’s data or its use of the Service (“Confirmed Material Security Incident”), no later than seventy-two (72) hours upon confirmation of the Confirmed Material Security Incident.

 

12.

Audit Rights.

 

 

(a)

If requested by Client or by a regulator (a copy of such communication shall be provided to Fireblocks on reasonable request), and if Fireblocks is unable to provide Client a satisfactory previously conducted audit report, the Parties shall discuss Fireblocks participation in any additional Pooled Audit or Individual Audits (defined below) in relation to Services provided to the Client.

 

 

(b)

Pooled Audit. To use testing resources more efficiently and to decrease the organizational burden on both the Client and Fireblocks, the Parties will agree on jointly organized audits (“Pooled Audit”) between Fireblocks, the Client and other clients of Fireblocks. A Pooled Audit may be performed by the Client, one client or an appointed third party as mutually agreed by the parties.

 

 

(c)

Individual Audit. If the Pooled Audit is deemed to be insufficient by the regulator (a copy of such communication shall be provided to Fireblocks on reasonable request) or Client, then Fireblocks shall participate in audits conducted by the Client, the regulator, and/or an appointed third party mutually agreed by the Parties (“Individual Audit”). Client’s request for an Individual Audit shall detail the applicable legal requirement upon which such audit request is based, including the relevant regulation or regulatory obligation.

 

 

(d)

For either Pooled or Individual Audits (in either case an “Audit”):

 

 

(i)

The rights described under this clause 12(d) shall be limited to Client data and will not violate the privacy or confidentiality of other Fireblocks customers' or employees' data. Where the rights of other customers of Fireblocks are affected by the Client’s proposed exercise of its rights under clause 12, the Parties will agree other methods for Fireblocks to provide necessary assurance to the Client regarding its provision of Services.

 

 

(ii)

The parties shall mutually agree the scope (i.e. processes, applications, infrastructure), relevant key controls and timeline of the Audit, taking into account Fireblocks’ specific risk parameters, including the rules of engagement and the qualifications of the auditors and approval by Fireblocks’ CISO.

 

 

(iii)

The Audits shall be performed remotely and during normal business hours (9.00 - 17.00) of the appropriate Fireblocks stakeholders or during periods prearranged and agreed between Fireblocks and Client(s).

 

 

(iv)

The parties will take steps to ensure the Audit does not pose any material risks to other Fireblocks’ client data or environment, Fireblocks confidentiality obligations to its other clients, service partners and/or employees, or to the operation of Fireblocks’ systems (e.g. impact on service levels, availability of data, confidentiality and privacy aspects).

 

 

(v)

Fireblocks shall have at least one hundred and eighty (180) days’ notice, unless otherwise agreed between Fireblocks and the Client(s).

 

 

(e)

Costs. Client shall fully indemnify Fireblocks in relation to Fireblocks costs for any Audits conducted pursuant to this Schedule (including any third party legal or advisory fees). In addition, Client bears its full cost and expenses as well as full cost and expenses of third parties commissioned by the Client for providing and exercising such Pooled Audit rights.

 

 

(f)

Right to Comment. Fireblocks shall receive and be entitled to comment on any and every Audit report prior to that report being finalized, published or disseminated (such report to be Fireblocks’ Confidential Information except to the extent it relates to the business or affairs of Client(s), which information will be Client(s) Confidential Information), which publication or dissemination shall be done only pursuant to the confidentiality provisions of this Agreement. Client agrees that any Audit report will be in English and Client will bear the cost of any required translation.

 

 

(g)

Right to Share. Client agrees that executive summaries and full versions of the Audit reports will be shared with Fireblocks, which Fireblocks may use for its own purposes, including sharing with external parties, as long as any Client Confidential Information is redacted.

 

 

 

f01.jpg

Fireblocks, Inc.

441 Ninth Ave, 15 Floor

New York, NY 10001

United States

 

 

BILL TO SHIP TO CONTRACT DETAILS
NovaBay Pharmaceuticals, Inc. NovaBay Pharmaceuticals, Inc. Start Date: January 06, 2026
2000 Powell Street suite 1150 2000 Powell Street suite 1150 End Date: January 05, 2027
Emeryville, California 94608 United States Emeryville, California 94608 United States Billing Frequency: Quarterly Payment Terms: Net 30
Bill to Email: [***] Workspace Owner Email: [***] Order Form Number: Q-30350 Expiration Date: February 05, 2026
    Currency: USD
     
  Prepared For: Prepared By:
     
  [***] [***]

 

Please ensure accuracy of the Bill to and Ship to information above. The welcome email with service activation information will be sent to the Workspace Owner Email provided above.

 

ORDER DETAILS

 

SUBSCRIPTION

Product Name

Product Description

Date

Quantity

Price

Fireblocks

Platform

Subscription --

Pro

Workspaces: 4

Workspace Users: 15

Monthly Transactions: 2,500

Annual Outgoing Transfer Volume - in Millions: 50

06 Jan, 2026 -

05 Jan, 2027

1

[***]

Station70 Bunker

- Starter

Workspaces: 1; Recovery Quorum Members: 3; Recovery SLA: 1 hour; Check-Ins: Yearly; Soft Recovery: Included

06 Jan, 2026 -

05 Jan, 2027

1

[***]

 

Total Contract Amount: [***]

OVERAGES

Start Date

End Date

Product

Code

Product Name

Overage

Rate

Measurement

Frequency

06 Jan,

2026

05 Jan,

2027

VOLM

Annual Outgoing Transfer Volume - in Millions

[***]

Annual

 

ORDER TERMS

This Order Form is incorporated into and governed by the master agreement (the “Agreement”) executed between the Parties. All Capitalized terms not defined herein shall have the meaning assigned to them in the Agreement.

 

The term of subscriptions included in this Order Form shall commence on the later of the Subscription Start Date listed above or the execution date, as determined by the date listed in the Signature section below.

 

PAYMENT TERMS

Fees associated with this Order Form shall be invoiced upon the Subscription Start Date and are payable in accordance with the Payment Terms stated above unless expressly stated otherwise below. Fees stated in this Order Form are

non-cancellable and non-refundable except as set forth in the Agreement.

 

OTHER PURCHASE TERMS

Assets Under Custody (AUC) is subject to fair use guidelines. If monthly average AUC on a recurring basis is greater than 1 times the included Outgoing Transfer Volume (on an annualized basis), Client may be required to upgrade its subscription entitlements to align with recurring usage levels.

 

Page 1 of 2

 

At the end of each period determined by the Measurement Frequency stated above during the subscription term set forth in the Order Form, if Client's cumulative consumption exceeds the amounts included in its subscription, such excess shall constitute an Overage. Fireblocks shall invoice for such Overages based on the rates prescribed herein, which will be due in accordance with the Payment Terms stated in this Order Form.

 

For avoidance of doubt, amounts to be invoiced for the Overage shall be calculated as follows:

 

(Actual Amount - Subscription Amount) x Overage Rate

 

The subscription to the Fireblocks Platform is subject to fair use guidelines. If the monthly number of billable transactions exceeds the amount listed on a recurring basis, continued use of the platform will require upgrade to a higher platform tier.

 

Valuation of Assets Under Custody shall be measured daily at 00:00 UTC. Monthly average Assets Under Custody shall be calculated using the average of daily valuations during a monthly period.

 

Customer's use of Station70 Services are subject to, and governed by, the terms of the Station70 End User License Agreement accessible at: www.station70.com/eula

 

 

SIGNATURE

 

By signing below, I affirm that I am authorized to execute this Order Form and agree to the terms set forth herein. Accepted by:

 

Signature /s/ Michael Kazley  
Name Michael Kazley  
Title Chief Executive Officer  
Date Jan 6, 2026  

 

Page 2 of 2

 

DISASTER RECOVERY SERVICES

LETTER AGREEMENT

 

This Letter Agreement (“Letter”) is by and between NovaBay Pharmaceuticals, Inc., with its principal address at 2000 Powell Street suite 1150, Emeryville, California 94608, United States (the “Client”) and and Fireblocks, Inc., a Delaware corporation, located at 5 Pennsylvania Avenue, 2nd Floor, New York, NY 10001 (“Fireblocks”);, entered into and effective as of the date the last Party executes this Letter (“Letter Effective Date”). Capitalized terms not defined herein shall have the meaning assigned to them in the Agreement.

 

 

INTRODUCTION

 

A.    The Parties entered into a Master Service Agreement, dated (“Agreement”) for the provision of Services as described in the Agreement.

 

B.    Client has one or more Workspaces as further described under Appendix A”) in order to use the Service. Each Workspace has a wallet in the Fireblocks vault which the Client can utilize to store their digital assets.

 

C.    Client authorized and appointed the Owner indicated in Appendix A of this Letter and further defined under the Workspace settings, to exclusively act, in its name and on its behalf for each Workspace. The Owner holds a Client Private Key Share, which together with corresponding Fireblocks Private Key Shares allows the Client to sign transactions on the Blockchain and withdraw digital assets from the Workspace’s vault;

 

D.    Client acknowledges that in the event that the Client Device is stolen or damaged, or Client loses access to their Recovery Passphrase or Full Key Recovery Package; it can lead to permanent damage and complete loss of control over the Client’s digital assets, and the inability to recover the digital assets therein;

 

E.    Client wishes to enter into a disaster recovery services agreement with the Service Provider (as defined below) for provision of certain disaster recovery services (“DRS”);

 

The Parties agree as follows:

 

01. 

Definitions. In this Letter:

 

 

a.

“Backup Recovery Passphrase” means the auto-generated backup of the recovery passphrase, which serves as an additional passphrase that is held by the Service Provider, and that allows the Client to undergo a Soft Key Recovery DRS.

 

 

b.

“Company DRS ID” means the Client’s exclusive identifiable number to be provided by Fireblocks and listed under Appendix A to be used for further identification of the Client by the Service Provider.

 

 

c.

“Disaster Recovery Plan” means either Soft Key Recovery DRS or Hard Key Recovery DRS.

 

 

d.

“Deposit Materials” means the Full Key Recovery Package and or the Backup Recovery Passphrase, as the case may be.

 

 

 

 

e.

“DRS Client Private Key Share means an additional Client Private Key Share of the Workspace Owner, that is encrypted with the Backup Recovery Passphrase.

 

 

f.

“Enrollment in DRS” means the process in which the Owner triggers the auto-generation and encryption of the Backup Recovery Passphrase.

 

 

g.

“Full Private Key means the Fireblocks Private Key Share and the Client Private Key Share of the Workspace Owner, as they relate to their collective ability to sign a transaction directly on the Blockchain.

 

 

h.

“Full Key Recovery Package'' notwithstanding the defined term in the Agreement, means the Client Private Key Share encrypted with the Recovery Passphrase that is in effect at the time the backup is created , as well as the Fireblocks Private Key Shares, encrypted with the Service Provider’s encryption method.

 

 

i.

“Hard Key Recovery DRS'' means the ability of the Client together with the Service Provider to recover the Fireblocks Private Key Shares and the Client Private Key Share of the Workspace Owner, in order to compile and have full access to the Full Private Key of the Workspace vault.

 

 

j.

“Service Provider” means the respective service provider specified in Appendix A which the Client enters into a direct DRS with.

 

 

k.

“Soft Key Recovery DRS'' means a process by which the Client can recover its Client Private Key Share with Fireblocks Support using a Backup Recovery Passphrase, in case that the Client lost its Recovery Passphrase, and incurred damage or any loss of access to the Owner’s Device.

 

 

l.

“Temporary Owner Swap means a process by which the Client recovered access to [Client Device / Service] with the assistance of Fireblocks Support, and not by using the Recovery Passphrase or the Backup Recovery Passphrase, but by having Support temporarily change the Workspace Owner, following which the temporary Owner (“Temporary Workspace Owner”) re-enrolled the Owner using the self-service feature in the Workspace, following which the Owner was reinstated as such by Support, and the effect of this process is that the Client Private Key Share has changed.

 

 

m.

“Material Key Changes” means any changes to the Full Private Key, lost or compromised Recovery Passphrase, and Temporary Owner Swap.

 

 

02.

DRS Setup Process

 

 

a.

The Client acknowledges and authorizes Fireblocks for the purpose of the performance of the DRS, to deposit with the Service Provider:

 

 

i.

The Full Key Recovery Package which can be used to undergo a Hard Key Recovery DRS;

 

 

ii.

an encrypted file containing the Backup Recovery Passphrase, which can be used to undergo a Soft Key Recovery DRS.

 

 

 

 

b.

Appendix A specifies the Disaster Recovery Plan selected by the Client. Client hereby agrees that following the execution of this Letter, Fireblocks will deposit with the applicable Service Provider the Deposit Materials.

 

 

c.

Client hereby acknowledges that the following process needs to be completed, and requires the full cooperation and participation by all the parties (including the Service Provider), in order for Fireblocks to deposit the applicable Deposit Materials and for the Service Provider to be able to provide the DRS under the selected Disaster Recovery Plan:

 

 

i.

Client will need to provide the Service Provider the Company DRS ID;

 

 

ii.

Fireblocks will accept a unique encryption method from the Service Provider per each individual Workspace in order to complete generation of the Full Key Recovery Package, , and in order to share the material securely and in accordance with the Client knowledge and approval.

 

 

iii.

Fireblocks will set up the Owner’s Device to be ready for Enrollment in DRS, per each individual Workspace, unless otherwise requested by Client and agreed by the Parties in writing;

 

 

iv.

the Owner will need to complete Enrollment in DRS for each Workspace on their Fireblocks mobile app;

 

 

d.

It is the Client’s sole responsibility to securely store the Recovery Passphrase and keep track of any changes to the Passphrase following the Effective Date, and contact Fireblocks immediately in the event that the Passphrase is lost or compromised in any way.

 

 

e.

Fireblocks will hold the DRS Client Private Key Share for the duration of this Letter; and

 

 

f.

It is the Client’s sole responsibility to contact Fireblocks immediately in writing in the event of Material Key Changes, and request creation of a new Full Key Recovery Package to be sent to the Service Provider. The Parties will comply with the process specified in this Section 2.

 

 

g.

Client provides Fireblocks with its consent to share with the Service Provider the Deposit Materials.

 

03.

Relationship of the Parties. This Letter does not, and shall not be construed to create any relationship, partnership, joint venture, employer-employee or agency relationship between the Parties, and shall not impose any liability on Fireblocks. Client hereby agrees and acknowledges that that the DRS engagement will only be with the Service Provider, and that it is the Client’s sole and absolute responsibility to perform its duties as will be agreed between Client and Service Provider.

 

04.

No Warranty, No Liability and Disclaimers

 

 

a.

CLIENT IS SOLELY RESPONSIBLE FOR ITS CHOICE AND USE OF THIRD PARTY DRS SERVICES OFFERED THROUGH THE SERVICE PROVIDER AND NOTWITHSTANDING CLAUSES 12 (LIMITED WARRANTIES AND DISCLAIMER OF WARRANTIES) AND 14 (LIMITATION OF LIABILITY) OF THE AGREEMENT, FIREBLOCKS AND ITS AFFILIATES MAKE NO WARRANTIES, WHETHER EXPRESS OR IMPLIED (BY LAW OR OTHERWISE), AND HEREBY DISCLAIM ALL LIABILITY, WITH RESPECT TO SUCH THIRD PARTY SERVICE. Client acknowledges that Fireblocks shall assume no responsibility and will not have any liability with respect to any unauthorized access or use of the applicable Deposit Materials, Recovery Passphrase, Owner’s Device and/or any Workspace. Client further agrees and hereby acknowledges that Fireblocks has no responsibility for ensuring that following the deposit of all the applicable Deposit Materials, Service Provider is able to provide the DRS according to the selected Disaster Recovery Plan.

 

 

 

 

b.

Client agrees and acknowledges that Fireblocks has provided and that Client has received the necessary and appropriate information and training to make an informed decision to enter into the disaster recovery services agreement with the Service Provider to provide the DRS.

 

 

c.

Client agrees to, releases and forever discharges Fireblocks and its respective predecessor, successor and affiliate corporations or entities, assigns, officers, directors, owners, attorneys, agents, servants and employees, as well as all other persons or entities named or unnamed, from all claims, demands, damages, costs, expenses, liens, actions or causes of action, whether known or unknown, that arise from or are in any way related to this Letter and/or with regard to unauthorized use of or release of the Owner’s Device, Client Private Key Share, Recovery Passphrase or the applicable Deposit Materials by the Service Provider or Client and/or Client’s instructions.

 

 

d.

Fireblocks is not responsible for any act and/or omission of the Service Provider (including, without limitation, in compliance with applicable law, the Service Provider’s vendors’, breaches and misuse of any data provided hereunder).

 

05.

Effect of Termination. Client shall notify Fireblocks immediately in writing in the event the engagement between Client and the Service Provider is terminated or expired for any reason. In the event that Client fails to inform Fireblocks that the engagement with Service Provider is terminated, and Fireblocks continues to provide information to Service Provider in accordance with the terms under this Letter and/or Client’s requests/instructions, then, Firelocks shall have no liability with respect to any information transferred and any losses or liabilities resulting from such failure by the Client.

 

 

[Signature page follows]

 

 

 

IN WITNESS WHEREOF, the Parties have executed this Agreement as of the Letter Effective Date.

 

Fireblocks Client
   
By: /s/ Dominic Wong By: /s/ Michael Kazley
   
Name: Dominic Wong Name: Michael Kazley
   
Date: Jan 6, 2026 Date: Jan 6, 2026

         

 

 

Appendix A

Company DRS ID:                         

 

Service Provider: Station 70 Inc.

 

Disaster Recovery Plan: X Hard Key Recovery DRS | X Soft Key Recovery DRS

 

 

Workspace DRS ID

Workspace Name

Workspace Owner

At time of setup

     
     

 

 

By initialing here, Client hereby represents and warrants that the Recovery Passphrase, per each Workspace, is in their possession as of the Letter Effective Date: [         ]